AZ-500 Secure compute, storage, and databases Practice Question
A Kubernetes workload in AKS needs to pull images from Azure Container Registry without using admin credentials. Which configuration should be used?
⚠ Common exam trap
It's easy for candidates to confuse anonymous pull access (Option B) as a valid alternative, but Azure explicitly recommends using managed identities with AcrPull for secure, credential-free image pulls in AKS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the AKS kubelet identity AcrPull on the registry
The AKS cluster uses a kubelet identity (managed identity) to authenticate with ACR. By granting the AcrPull role to this identity, the kubelet can pull container images without requiring admin credentials, as Azure RBAC handles the authentication via Microsoft Entra ID tokens. This is the recommended secure method for image pull operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant the AKS kubelet identity AcrPull on the registry
Why this is correct
The AKS cluster's kubelet runs on each node and is responsible for pulling container images. Each cluster has a kubelet identity (a managed identity in Microsoft Entra ID) that can be granted the AcrPull role on the container registry, giving that identity permission to authenticate and pull images without any stored secrets. This is the recommended approach because it uses Azure's managed identity-based authentication, follows least privilege, and avoids managing or exposing long-lived credentials.
- ✗
Enable anonymous pull access on the registry
Why it's wrong here
Enabling anonymous pull access would allow any unauthenticated user to pull any image from the registry, including potentially proprietary or sensitive code. This eliminates the authentication barrier that protects your artifacts and violates the principle of least privilege. While the kubelet could then pull without credentials, it exposes the entire registry to the internet, which is a serious security risk and not a secure configuration for an AKS workload.
- ✗
Store the ACR admin password in a ConfigMap
Why it's wrong here
The ACR admin account is a single, shared credential that grants full access to the registry and is not backed by any individual identity, making it poor for auditing. Storing its password in a ConfigMap is especially bad because ConfigMaps are unencrypted by default and may be visible to anyone who can list secrets or access etcd, creating a secret leak path. Even if the password were in a Kubernetes Secret, this approach would still be inferior to managed identity because it requires rotating shared credentials and does not support fine-grained authorization per puller.
- ✗
Expose the registry through a public load balancer
Why it's wrong here
A public load balancer only affects network traffic routing and does nothing to authenticate or authorize image pulls. ACR already exposes HTTPS endpoints publicly by default (unless you have disabled public network access), so placing a load balancer in front doesn't change the fundamental authorization requirement. The kubelet would still need a valid identity or credential to authenticate; simply exposing the registry does not grant any pulling permission.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.