AZ-500 Secure networking Practice Question
Your company has deployed Azure Kubernetes Service (AKS) in a virtual network. The AKS cluster needs to pull images from a private Azure Container Registry (ACR) that has a private endpoint configured. The virtual network where AKS is deployed is peered to the ACR's virtual network. You have configured the AKS cluster to use managed identity for authentication to ACR. However, the AKS cluster is unable to pull images from the ACR. You need to resolve the connectivity issue without exposing the ACR to the internet. What should you do?
⚠ Common exam trap
Many exam-takers assume peering alone provides full connectivity, but they overlook that private endpoint DNS resolution requires explicit linking of the private DNS zone to the peered virtual network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Link the private DNS zone of the ACR private endpoint to the AKS virtual network.
The AKS cluster cannot pull images from the private ACR because the private endpoint's DNS resolution is not propagated to the AKS virtual network. By linking the private DNS zone of the ACR private endpoint to the AKS virtual network, the AKS nodes can resolve the ACR's private FQDN to the private IP address of the endpoint, enabling connectivity without exposing the ACR to the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Link the private DNS zone of the ACR private endpoint to the AKS virtual network.
Why this is correct
Linking the private DNS zone of the ACR's private endpoint to the AKS virtual network is the required fix. This DNS link enables Azure's DNS resolution to map the ACR's private endpoint FQDN to the private IP address inside the AKS VNet, allowing the kubelet to reach the registry over the private endpoint. Without this link, AKS nodes will attempt to resolve the ACR login server to its public IP, which is blocked when public access is disabled. This is the standard, supported method for private ACR connectivity to AKS.
- ✗
Update the AKS cluster's DNS server to use a custom DNS that can resolve the private endpoint.
Why it's wrong here
Updating the AKS cluster's DNS server to a custom resolver is unnecessary because AKS nodes already use Azure-provided DNS by default. The correct mechanism is to link the private DNS zone to the AKS virtual network so Azure DNS transparently resolves the endpoint's FQDN to the private IP. Adding a custom DNS server introduces an extra configuration layer that can cause split-horizon resolution issues and is not required for private endpoint connectivity.
- ✗
Delete the private endpoint and configure ACR firewall rules to allow the AKS subnet.
Why it's wrong here
Deleting the private endpoint and relying on ACR firewall rules would route AKS pull traffic through the ACR public endpoint over the internet, defeating the purpose of private connectivity. Even if the firewall is scoped to allow only the AKS subnet, the traffic egresses to a public IP, exposing the registry to internet-borne threats and violating a security design that requires private link. This approach also breaks if the ACR is configured to disable public network access, so it is not a valid fix.
- ✗
Recreate the AKS cluster with a different managed identity that has ACR pull permissions.
Why it's wrong here
Recreating the AKS cluster with a different managed identity will not resolve the pull failure because the issue is at the network and DNS layer, not authentication. The currently assigned identity likely already has ACR Pull permissions; the kubelet cannot even reach the registry to present those credentials if the private endpoint's DNS name does not resolve to the private IP in the AKS subnet. Recreating a cluster is a disruptive, unnecessary step that ignores the root cause and would not change the DNS resolution behavior without the private DNS zone link.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.