Microsoft Certified: DevOps Engineer ExpertDevelop a security and compliance planMedium

A DevOps team is deploying an Azure Kubernetes Service (AKS) cluster for a critical production application. They need to ensure that all container images deployed to the cluster originate from trusted sources and have been scanned for vulnerabilities. Which two Azure services should they integrate to enforce this policy?

  1. AAzure Monitor and Azure Application Insights
  2. BAzure Container Registry (ACR) and Azure Policy
  3. CAzure Security Center (now Defender for Cloud) and Azure Active Directory
  4. DAzure Key Vault and Azure Pipelines
Show answer & explanation

Correct answer: B. Azure Container Registry (ACR) and Azure Policy

Azure Container Registry (ACR) provides a secure and private place to store Docker images, and it can be integrated with vulnerability scanning solutions. Azure Policy can then be used to enforce rules, such as disallowing deployments of images that are not from a specific ACR or that fail vulnerability scans, ensuring images come from trusted sources and are scanned.

Why the other options are wrong

  • A. Azure Monitor and Azure Application Insights are for monitoring and observability, not for enforcing image security policies.
  • C. Azure Security Center (Defender for Cloud) provides vulnerability scanning for ACR, but Azure Policy is needed to *enforce* the deployment restriction based on those scans. Azure Active Directory is for identity management, not image policy enforcement.
  • D. Azure Key Vault is for secrets management. Azure Pipelines is for CI/CD. Neither directly enforces image origin and vulnerability scan policies on the cluster.

Container Image Security Enforcement

The process of ensuring that only trusted, scanned, and compliant container images are deployed into an environment, typically enforced through policies and integrated registries.

  • Prevents deployment of vulnerable or untrusted images.
  • Requires a secure container registry.
  • Leverages policy engines for enforcement.

Memory trick: ACR 'Stores Safe Ships', and Azure Policy 'Checks Their Papers'.

More Develop a security and compliance plan questions