SC-100 Design security solutions for infrastructure Practice Question
Your organization is deploying a new application on Azure Kubernetes Service (AKS). You need to ensure that only authorized containers can run in the cluster and that any unauthorized containers are automatically blocked. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an Azure Policy that restricts container images to only those from approved registries.
The correct option is B: applying an Azure Policy that restricts container images to only those from approved registries. Azure Policy for AKS uses the Gatekeeper admission controller to evaluate requests against policy definitions at admission time, so any pod or deployment referencing a non-approved image is automatically denied and blocked from running in the cluster. This directly enforces the requirement that only authorized containers can run. Option A does not fit because network policies only control pod-to-pod traffic, not which images are allowed to run. Option C does not fit because Microsoft Entra ID integration handles authentication of users to the cluster, not image authorization. Option D does not fit because Azure RBAC controls who can perform deployment actions, but it does not validate or block unauthorized container images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement network policies to restrict communication between pods.
Why it's wrong here
Network policies in AKS govern pod-to-pod traffic via allow/deny rules on IP/ports, operating at Layer 3/4. They are completely orthogonal to container image authorization—they cannot inspect the source registry of an image, nor prevent a pod from being scheduled if its image comes from an untrusted registry. Thus, while useful for segmentation, they would not stop an attacker from deploying a malicious container in the first place.
- ✓
Apply an Azure Policy that restricts container images to only those from approved registries.
Why this is correct
Azure Policy for AKS integrates with the Gatekeeper admission controller, enabling enforcement of built-in policies such as 'Ensure only allowed container images'. At pod creation or update time, the admission webhook evaluates each container's image repository and rejects any deployment that references a registry not on the approved list. This is a preventive control at the point of scheduling, directly addressing the requirement to restrict container images to approved registries only.
- ✗
Enable Microsoft Entra ID integration for the AKS cluster.
Why it's wrong here
Microsoft Entra ID integration for AKS provides authentication for human users and service principals, and its role-based access control (Azure RBAC or Kubernetes RBAC tied to AAD) decides who may call the Kubernetes API. However, it does nothing to examine or validate the contents of a container image. A user with valid credentials and appropriate roles could still deploy a container pulled from an arbitrary, unapproved registry, so this option addresses identity, not image provenance.
- ✗
Configure Azure RBAC roles to limit who can deploy containers.
Why it's wrong here
Azure RBAC roles are a coarse-grained authorization mechanism that defines which users, groups, or service principals can perform actions like 'Microsoft.ContainerService/managedClusters/agentPools/write' or Kubernetes API operations. They cannot analyze the YAML manifest or the image reference within a deployment request. A user who is legitimately allowed to deploy pods could specify any image name, and RBAC would not block it—only an admission control policy can make that decision.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are designing a secure DevOps pipeline for a critical application using GitHub Actions and Microsoft Defender for Cloud. You need to ensure that container images are scanned for vulnerabilities before being deployed to Azure Kubernetes Service (AKS). What should you implement?
hard- ✓ A.Integrate Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry.
- B.Enable GitHub Advanced Security for the repository.
- C.Configure Azure Policy to require vulnerability assessment.
- D.Use Azure Container Registry Tasks to build images.
Why A: The correct option is A: integrating Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry. Defender for Containers provides image vulnerability scanning for ACR, and integrating it into the GitHub Actions pipeline lets you detect vulnerabilities before deployment to AKS, matching the requirement to scan images pre-deployment. Option B, GitHub Advanced Security, focuses on code and secret scanning rather than container image vulnerability assessment. Option C, Azure Policy, can audit or deny deployments based on vulnerability findings but does not itself perform image scanning in the pipeline. Option D, ACR Tasks, builds images but does not provide vulnerability scanning.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.