SC-100 Private cluster Practice Question
A financial institution, Contoso Bank, is deploying a new application on Azure Kubernetes Service (AKS) that processes credit card transactions (PCI DSS). The application uses Azure SQL Database and Azure Redis Cache. You need to design a security solution that meets PCI DSS requirements. Which THREE of the following should you implement?
⚠ Common exam trap
Candidates may mistakenly believe that enabling Azure RBAC for Kubernetes is sufficient for PCI DSS compliance, but it only addresses authorization, not network isolation. Additionally, disabling TLS may be considered for performance but violates encryption requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy AKS as a private cluster with no public endpoint.
Option A is correct because deploying AKS as a private cluster with no public endpoint removes the API server's public exposure, ensuring all control-plane communication stays on the private network and reducing the PCI DSS attack surface. Option B is correct because Always Encrypted protects sensitive cardholder data columns in Azure SQL Database by keeping encryption keys outside the database engine, so even DBAs or compromised SQL instances cannot read plaintext data. Option D is correct because private endpoints for Azure SQL Database and Azure Cache for Redis route traffic over Azure Private Link, keeping data off the public internet and satisfying PCI DSS network segmentation and encryption-in-transit expectations. Option C is not among the required three because Azure RBAC for Kubernetes authorization is a general access-control hardening measure, not a PCI DSS-specific control for protecting cardholder data in this scenario. Option E is incorrect because disabling TLS on Azure Cache for Redis exposes data in transit and directly violates PCI DSS encryption requirements for cardholder data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy AKS as a private cluster with no public endpoint.
Why this is correct
Deploying AKS as a private cluster with no public endpoint is essential because the Kubernetes API server is placed behind a private IP address on a virtual network, using Azure Private Link. This prevents the control plane from being reachable from the internet, directly satisfying PCI DSS network compartmentalization requirements for cardholder data environments. Unlike merely disabling public access, this design ensures administrative and operational traffic to the API server also traverses the private network.
- ✓
Configure Always Encrypted for sensitive columns in Azure SQL Database.
Why this is correct
Configuring Always Encrypted for sensitive columns in Azure SQL Database protects data by encrypting it client-side before it ever reaches the database, with keys stored in Azure Key Vault or Windows Certificate Store. The database service only sees ciphertext, so even DBAs or threat actors with access to the server cannot read plaintext values. This addresses PCI DSS encryption-at-rest requirements while also preventing data exposure during transit from the application to the database, complementing network-level isolation.
- ✗
Enable Azure RBAC for Kubernetes authorization.
Why it's wrong here
Enabling Azure RBAC for Kubernetes authorization is incorrect as a standalone control because it only governs user and group permissions to perform API actions, not the network traffic or packet-level isolation required by PCI DSS. While RBAC is a good security hygiene practice, it does nothing to prevent an attacker from reaching an exposed API server or pivoting between pods. PCI DSS mandates strict network segmentation, which RBAC cannot deliver; network policies or a private cluster are required for that isolation.
- ✓
Use private endpoints for Azure SQL Database and Azure Cache for Redis.
Why this is correct
Using private endpoints for Azure SQL Database and Azure Cache for Redis ensures each service receives a private IP address inside the virtual network and all traffic to those services flows over the private network backbone rather than the public internet. This removes the need to expose service FQDNs to the internet, reducing the attack surface for cardholder data stores. Unlike service endpoints, private endpoints provide fine-grained access control and prevent data exfiltration through the public endpoint, aligning with PCI DSS network requirements.
- ✗
Disable TLS for Azure Cache for Redis to improve performance.
Why it's wrong here
Disabling TLS for Azure Cache for Redis is explicitly wrong because PCI DSS requires encryption of cardholder data in transit, and Redis without TLS sends all data — including sensitive values or application tokens — as plaintext over the network. This would expose the Redis cache to eavesdropping or man-in-the-middle attacks, especially because Redis is often used for session state or caching sensitive request data. Even if performance improves slightly, the compliance and security risk far outweighs the benefit; TLS 1.2+ is mandatory for production workloads.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.