AZ-305 Design infrastructure solutions Practice Question
Your organization is designing a secure microservices architecture using Azure Kubernetes Service (AKS). The application must be compliant with PCI DSS, which requires strict network segmentation and encryption of data at rest and in transit. You need to design a solution that meets these requirements while minimizing operational overhead. The AKS cluster will be deployed in a virtual network. The application consists of multiple microservices that need to communicate with each other and with an Azure SQL Database. Some microservices are public-facing. Which design should you recommend?
⚠ Common exam trap
Watch out — candidates often think a private API server alone is sufficient for compliance, but they overlook the need for network policies to enforce micro-segmentation between pods and a private endpoint for Azure SQL Database to meet data-in-transit encryption and isolation requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy AKS with a private API server, enable network policies, and use a service endpoint or private endpoint for Azure SQL Database.
A private API server ensures the AKS control plane is inaccessible from the public internet, satisfying PCI DSS network segmentation. Enabling network policies (e.g., Calico or Azure Network Policy) enforces micro-segmentation between pods, and using a private endpoint for Azure SQL Database encrypts data in transit over the Microsoft backbone and isolates the database to the virtual network, meeting encryption and segmentation requirements with minimal operational overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy AKS with a private API server, enable network policies, and use a service endpoint or private endpoint for Azure SQL Database.
Why this is correct
A private API server removes the Kubernetes control plane from the public internet, so only authorized virtual networks can reach it. Enabling Azure Network Policies provides pod-level microsegmentation, restricting east-west traffic between microservices. Using a private endpoint or service endpoint for Azure SQL Database keeps database traffic on the Microsoft backbone, satisfying PCI DSS requirements that mandate private connectivity and defense in depth.
- ✗
Deploy AKS with a public API server and use Network Security Groups (NSGs) to restrict access.
Why it's wrong here
Exposing the API server publicly places the entire Kubernetes control plane on the internet, greatly expanding the attack surface even if NSGs are applied at the subnet or NIC level. NSGs offer stateful filtering at layer 4 but do not provide pod-level isolation or control over north-south traffic hitting the TLS endpoint. Moreover, NSGs cannot block authenticated or application-layer attacks, and PCI compliance typically requires private access to the control plane rather than relying solely on IP-based restrictions.
- ✗
Deploy AKS with a private API server and use a jump box for administration.
Why it's wrong here
While a jump box does provide a managed entry point to a private API server, it introduces an additional virtual machine that must be patched, hardened, and monitored, and it becomes a potential pivot point for attackers. With Azure VPN Gateway or ExpressRoute, administrators can securely reach the private API server directly from their corporate network without the extra hop. Furthermore, a jump box does not secure the data plane; Azure SQL Database still needs its own private endpoint or service endpoint to avoid public exposure.
- ✗
Deploy AKS with a public API server and disable network policies to simplify management.
Why it's wrong here
Disabling network policies on AKS removes any pod-level traffic restrictions, allowing bidirectional communication between all services and significantly increasing lateral movement risk during a compromise. A public API server compounds this by exposing the control plane to internet access, making the cluster a direct target for unauthorized API calls. While NSGs could provide some subnet-level filtering, they do not substitute for Kubernetes Network Policies, and this combination clearly fails the network isolation and access control requirements for PCI DSS.
Go deeper
Related to this question
About these practice questions
This AZ-305 question is part of Courseiva's 795-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.