Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureHard
A software-as-a-service (SaaS) provider is building a multi-tenant application on Azure Kubernetes Service (AKS). Each tenant's data and workloads must be strictly isolated from one another to meet regulatory compliance and Zero Trust principles. The security architect needs to implement network isolation at the container and pod level within the AKS clusters, ensuring that traffic between tenants is explicitly denied unless absolutely necessary and authorized. Which networking strategy should the architect employ for this level of granular isolation?
- AAzure DDoS Protection Standard
- BNetwork Security Groups (NSGs) at the subnet level
- CIdentity-Based Micro-segmentation with Network Policies
- DAzure Firewall for outbound traffic filtering
Show answer & explanationAnswer & explanation
Correct answer: C. Identity-Based Micro-segmentation with Network Policies
Identity-based micro-segmentation, implemented through Kubernetes Network Policies, provides granular network isolation at the pod and container level within AKS. It allows defining rules based on identities (labels) to explicitly control traffic between tenants, crucial for multi-tenant Zero Trust.
Why the other options are wrong
- A. Azure DDoS Protection Standard protects against denial-of-service attacks, not granular network isolation between tenants within an AKS cluster.
- B. NSGs operate at the subnet level, which is too coarse-grained for isolating individual pods or tenants within a Kubernetes cluster, especially for micro-segmentation.
- D. Azure Firewall controls outbound and inbound traffic at the VNet level, which is not granular enough for intra-cluster, pod-level tenant isolation.
Identity-Based Micro-segmentation (AKS Multi-tenant)
Identity-based micro-segmentation in AKS uses Kubernetes Network Policies to define granular network access rules between pods and namespaces based on their identities (labels), ensuring strict isolation for multi-tenant applications.
- Enforces Zero Trust principle of 'never trust, always verify' at the network level.
- Provides granular control of traffic between individual pods/workloads.
- Essential for multi-tenant environments to prevent lateral movement and data leakage.
Memory trick: Micro-segmentation: 'My Individual Containers Really Optimize Security'.