Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

A Kubernetes workload in AKS needs to pull images from Azure Container Registry without using admin credentials. Which configuration should be used?

⚠ Common exam trap

It's easy for candidates to confuse anonymous pull access (Option B) as a valid alternative, but Azure explicitly recommends using managed identities with AcrPull for secure, credential-free image pulls in AKS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the AKS kubelet identity AcrPull on the registry

The AKS cluster uses a kubelet identity (managed identity) to authenticate with ACR. By granting the AcrPull role to this identity, the kubelet can pull container images without requiring admin credentials, as Azure RBAC handles the authentication via Microsoft Entra ID tokens. This is the recommended secure method for image pull operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant the AKS kubelet identity AcrPull on the registry

    Why this is correct

    The AKS cluster's kubelet runs on each node and is responsible for pulling container images. Each cluster has a kubelet identity (a managed identity in Microsoft Entra ID) that can be granted the AcrPull role on the container registry, giving that identity permission to authenticate and pull images without any stored secrets. This is the recommended approach because it uses Azure's managed identity-based authentication, follows least privilege, and avoids managing or exposing long-lived credentials.

  • ✗

    Enable anonymous pull access on the registry

    Why it's wrong here

    Enabling anonymous pull access would allow any unauthenticated user to pull any image from the registry, including potentially proprietary or sensitive code. This eliminates the authentication barrier that protects your artifacts and violates the principle of least privilege. While the kubelet could then pull without credentials, it exposes the entire registry to the internet, which is a serious security risk and not a secure configuration for an AKS workload.

  • ✗

    Store the ACR admin password in a ConfigMap

    Why it's wrong here

    The ACR admin account is a single, shared credential that grants full access to the registry and is not backed by any individual identity, making it poor for auditing. Storing its password in a ConfigMap is especially bad because ConfigMaps are unencrypted by default and may be visible to anyone who can list secrets or access etcd, creating a secret leak path. Even if the password were in a Kubernetes Secret, this approach would still be inferior to managed identity because it requires rotating shared credentials and does not support fine-grained authorization per puller.

  • ✗

    Expose the registry through a public load balancer

    Why it's wrong here

    A public load balancer only affects network traffic routing and does nothing to authenticate or authorize image pulls. ACR already exposes HTTPS endpoints publicly by default (unless you have disabled public network access), so placing a load balancer in front doesn't change the fundamental authorization requirement. The kubelet would still need a valid identity or credential to authenticate; simply exposing the registry does not grant any pulling permission.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.