Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization is deploying a new application on Azure Kubernetes Service (AKS). You need to ensure that only authorized containers can run in the cluster and that any unauthorized containers are automatically blocked. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an Azure Policy that restricts container images to only those from approved registries.

The correct option is B: applying an Azure Policy that restricts container images to only those from approved registries. Azure Policy for AKS uses the Gatekeeper admission controller to evaluate requests against policy definitions at admission time, so any pod or deployment referencing a non-approved image is automatically denied and blocked from running in the cluster. This directly enforces the requirement that only authorized containers can run. Option A does not fit because network policies only control pod-to-pod traffic, not which images are allowed to run. Option C does not fit because Microsoft Entra ID integration handles authentication of users to the cluster, not image authorization. Option D does not fit because Azure RBAC controls who can perform deployment actions, but it does not validate or block unauthorized container images.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement network policies to restrict communication between pods.

    Why it's wrong here

    Network policies in AKS govern pod-to-pod traffic via allow/deny rules on IP/ports, operating at Layer 3/4. They are completely orthogonal to container image authorization—they cannot inspect the source registry of an image, nor prevent a pod from being scheduled if its image comes from an untrusted registry. Thus, while useful for segmentation, they would not stop an attacker from deploying a malicious container in the first place.

  • ✓

    Apply an Azure Policy that restricts container images to only those from approved registries.

    Why this is correct

    Azure Policy for AKS integrates with the Gatekeeper admission controller, enabling enforcement of built-in policies such as 'Ensure only allowed container images'. At pod creation or update time, the admission webhook evaluates each container's image repository and rejects any deployment that references a registry not on the approved list. This is a preventive control at the point of scheduling, directly addressing the requirement to restrict container images to approved registries only.

  • ✗

    Enable Microsoft Entra ID integration for the AKS cluster.

    Why it's wrong here

    Microsoft Entra ID integration for AKS provides authentication for human users and service principals, and its role-based access control (Azure RBAC or Kubernetes RBAC tied to AAD) decides who may call the Kubernetes API. However, it does nothing to examine or validate the contents of a container image. A user with valid credentials and appropriate roles could still deploy a container pulled from an arbitrary, unapproved registry, so this option addresses identity, not image provenance.

  • ✗

    Configure Azure RBAC roles to limit who can deploy containers.

    Why it's wrong here

    Azure RBAC roles are a coarse-grained authorization mechanism that defines which users, groups, or service principals can perform actions like 'Microsoft.ContainerService/managedClusters/agentPools/write' or Kubernetes API operations. They cannot analyze the YAML manifest or the image reference within a deployment request. A user who is legitimately allowed to deploy pods could specify any image name, and RBAC would not block it—only an admission control policy can make that decision.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are designing a secure DevOps pipeline for a critical application using GitHub Actions and Microsoft Defender for Cloud. You need to ensure that container images are scanned for vulnerabilities before being deployed to Azure Kubernetes Service (AKS). What should you implement?

hard
  • ✓ A.Integrate Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry.
  • B.Enable GitHub Advanced Security for the repository.
  • C.Configure Azure Policy to require vulnerability assessment.
  • D.Use Azure Container Registry Tasks to build images.

Why A: The correct option is A: integrating Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry. Defender for Containers provides image vulnerability scanning for ACR, and integrating it into the GitHub Actions pipeline lets you detect vulnerabilities before deployment to AKS, matching the requirement to scan images pre-deployment. Option B, GitHub Advanced Security, focuses on code and secret scanning rather than container image vulnerability assessment. Option C, Azure Policy, can audit or deny deployments based on vulnerability findings but does not itself perform image scanning in the pipeline. Option D, ACR Tasks, builds images but does not provide vulnerability scanning.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.