Courseiva

AZ-305 Design infrastructure solutions Practice Question

Which THREE of the following are best practices for securing an Azure Kubernetes Service (AKS) cluster? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure Policy for Kubernetes to enforce security policies.

Option A is correct because Azure Policy for Kubernetes (via the Azure Policy add-on) enforces governance and security controls at scale, such as restricting privileged containers, hostPath mounts, and allowed registries, and it reports compliance for AKS clusters. Option B is correct because integrating Microsoft Entra ID (Microsoft Entra ID) with AKS enables centralized, identity-based authentication using Microsoft Entra ID credentials and supports Kubernetes RBAC authorization, eliminating static local admin accounts. Option C is correct because managed identities (or workload identity) let pods obtain Microsoft Entra ID tokens without storing credentials, enabling secure, secretless access to Azure resources like Key Vault and Storage. Option D is not a best practice: allowing unrestricted pod-to-pod traffic removes segmentation and increases lateral movement risk; network policies (Calico or Azure NPM) should restrict traffic. Option E is incorrect because disabling Kubernetes RBAC removes fine-grained, namespace-scoped authorization; Azure RBAC alone does not replace Kubernetes RBAC for in-cluster permissions, and both should be used together.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Azure Policy for Kubernetes to enforce security policies.

    Why this is correct

    Azure Policy for Kubernetes extends Gatekeeper to audit and deny non-compliant workloads at admission time, enforcing pod security standards, resource limits and allowed registries directly inside the cluster. This satisfies the stem's requirement to secure AKS by preventing insecure configurations from being deployed, rather than merely detecting them afterwards.

  • ✓

    Enable Microsoft Entra ID integration for cluster authentication.

    Why this is correct

    Integrating Microsoft Entra ID centralises cluster authentication, replacing static local credentials with identity-based access tied to organisational accounts. This satisfies the stem's authentication hardening requirement, enabling RBAC enforcement and conditional access so cluster access is auditable and revocable.

  • ✓

    Use managed identities for pods to access Azure resources securely.

    Why this is correct

    Managed identities let pods obtain Microsoft Entra ID tokens without embedding credentials, eliminating secrets in manifests or images. This satisfies secure access to Azure resources such as Key Vault, removing the credential-theft vector that static service principals introduce.

  • ✗

    Allow all pod-to-pod communication within the cluster without network policies.

    Why it's wrong here

    Permitting unrestricted pod-to-pod traffic lets a compromised pod reach every other workload, defeating lateral-movement containment; network policies enforce default-deny segmentation. It is tempting because a flat pod network needs no policy authoring and suits single-tenant clusters running trusted, non-regulated workloads where east-west segmentation adds no value.

  • ✗

    Disable Kubernetes RBAC and use only Azure RBAC for simplicity.

    Why it's wrong here

    Disabling Kubernetes RBAC removes namespace-scoped authorisation, so Azure RBAC alone cannot grant least-privilege access within the cluster; both layers are required for defence in depth. It appeals because consolidating on one RBAC system appears to reduce administrative overhead, which suits clusters where every user's access maps cleanly to Azure control-plane roles.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 795 original AZ-305 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.