You deploy an AKS cluster in an Azure subscription with multiple pods using Kubernetes networking. To restrict network traffic between the pods, which network policy should you configure on the AKS cluster?
Choose an answer
Tap an option to check your answer.
Correct answer: the Calico network policy.
Why this is the answer
The Calico network policy is the correct choice because it's a widely used, open-source network policy engine that integrates directly with Kubernetes. It provides robust network segmentation and security features, allowing you to define granular rules for traffic flow between pods within an AKS cluster. The Azure network policy is a built-in Azure solution, but it primarily focuses on network security groups (NSGs) and user-defined routes (UDRs) for virtual networks, not granular pod-to-pod traffic within a Kubernetes cluster. Pod security policies (PSPs) are deprecated in Kubernetes and focus on pod-level security contexts, not network traffic filtering. An application security group (ASG) is an Azure networking construct used to group virtual machines or network interfaces, simplifying NSG rule management, but it doesn't directly manage pod-to-pod traffic within an AKS cluster.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed