Unit 3: Secure Compute and Storage - Subjective Questions

INT328 — Network Virtualization And Cloud Security • Practice Questions with Detailed Answers

20 questions

1

Define Azure Bastion and explain how it provides secure administrative access to Azure virtual machines.

2

Describe the architecture and connection flow of Azure Bastion when a user connects to a virtual machine.

3

What is Just-in-Time virtual machine access in Microsoft Defender for Cloud? Explain its working process.

4

Compare Azure Bastion and Just-in-Time virtual machine access as methods of protecting administrative access to virtual machines.

5

Define Azure Kubernetes Service (AKS) and identify its major components.

6

Explain how the shared responsibility model applies to the security of an AKS cluster.

7

Describe a defense-in-depth strategy for securing workloads deployed on Azure Kubernetes Service.

8

Explain network isolation in Azure and discuss the controls that can be used to isolate secure compute and storage resources.

9

Distinguish between service endpoints and private endpoints for securing access to Azure platform services.

10

Explain how network security groups, Azure Firewall, and AKS network policies operate at different layers of network protection.

11

Describe the main Azure services used to monitor virtual machines, AKS clusters, networks, and storage resources.

12

Explain the difference among Azure metrics, resource logs, and the Activity Log, giving an appropriate use case for each.

13

Design a monitoring and alerting strategy for a security-sensitive AKS application.

14

Explain how Microsoft Entra ID, managed identities, and role-based access control support authentication and authorization for secure Azure workloads.

15

Distinguish between authentication and authorization in the context of AKS, and explain how they can be implemented securely.

16

What is Azure Container Registry (ACR)? Describe its role in a secure container deployment pipeline.

17

Explain how access to Azure Container Registry should be managed according to the principle of least privilege.

18

Describe the steps required to integrate an AKS cluster securely with Azure Container Registry.

19

Explain image lifecycle management in Azure Container Registry, including tagging, immutability, retention, scanning, and deletion.

20

A company must deploy a private AKS application that uses ACR and Azure Storage, with no direct public administrative access. Propose a secure compute, storage, identity, network, and monitoring architecture.