AZ-305 Design infrastructure solutions Practice Question
Which THREE of the following are best practices for securing an Azure Kubernetes Service (AKS) cluster? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Azure Policy for Kubernetes to enforce security policies.
Option A is correct because Azure Policy for Kubernetes (via the Azure Policy add-on) enforces governance and security controls at scale, such as restricting privileged containers, hostPath mounts, and allowed registries, and it reports compliance for AKS clusters. Option B is correct because integrating Microsoft Entra ID (Microsoft Entra ID) with AKS enables centralized, identity-based authentication using Microsoft Entra ID credentials and supports Kubernetes RBAC authorization, eliminating static local admin accounts. Option C is correct because managed identities (or workload identity) let pods obtain Microsoft Entra ID tokens without storing credentials, enabling secure, secretless access to Azure resources like Key Vault and Storage. Option D is not a best practice: allowing unrestricted pod-to-pod traffic removes segmentation and increases lateral movement risk; network policies (Calico or Azure NPM) should restrict traffic. Option E is incorrect because disabling Kubernetes RBAC removes fine-grained, namespace-scoped authorization; Azure RBAC alone does not replace Kubernetes RBAC for in-cluster permissions, and both should be used together.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Azure Policy for Kubernetes to enforce security policies.
Why this is correct
Azure Policy for Kubernetes extends Gatekeeper to audit and deny non-compliant workloads at admission time, enforcing pod security standards, resource limits and allowed registries directly inside the cluster. This satisfies the stem's requirement to secure AKS by preventing insecure configurations from being deployed, rather than merely detecting them afterwards.
- ✓
Enable Microsoft Entra ID integration for cluster authentication.
Why this is correct
Integrating Microsoft Entra ID centralises cluster authentication, replacing static local credentials with identity-based access tied to organisational accounts. This satisfies the stem's authentication hardening requirement, enabling RBAC enforcement and conditional access so cluster access is auditable and revocable.
- ✓
Use managed identities for pods to access Azure resources securely.
Why this is correct
Managed identities let pods obtain Microsoft Entra ID tokens without embedding credentials, eliminating secrets in manifests or images. This satisfies secure access to Azure resources such as Key Vault, removing the credential-theft vector that static service principals introduce.
- ✗
Allow all pod-to-pod communication within the cluster without network policies.
Why it's wrong here
Permitting unrestricted pod-to-pod traffic lets a compromised pod reach every other workload, defeating lateral-movement containment; network policies enforce default-deny segmentation. It is tempting because a flat pod network needs no policy authoring and suits single-tenant clusters running trusted, non-regulated workloads where east-west segmentation adds no value.
- ✗
Disable Kubernetes RBAC and use only Azure RBAC for simplicity.
Why it's wrong here
Disabling Kubernetes RBAC removes namespace-scoped authorisation, so Azure RBAC alone cannot grant least-privilege access within the cluster; both layers are required for defence in depth. It appeals because consolidating on one RBAC system appears to reduce administrative overhead, which suits clusters where every user's access maps cleanly to Azure control-plane roles.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.