You have an AKS cluster AKS1 and a container registry with images that were pushed by Azure DevOps Microsoft-hosted agents. You need administrators to be able to access AKS1 only from specified networks while minimizing administrative effort. What should you configure for AKS1?
Choose an answer
Tap an option to check your answer.
Correct answer: Authorized IP address ranges.
Why this is the answer
Authorized IP address ranges allow you to define specific CIDR ranges that can access the AKS API server. This directly addresses the requirement to restrict administrative access to AKS1 from specified networks, minimizing administrative effort as it's a built-in AKS feature. An Application Gateway Ingress Controller (AGIC) manages inbound traffic to applications running in the cluster, not administrative access to the cluster itself. A private endpoint would create a private connection to the AKS API server, but doesn't inherently restrict access to specific public IP ranges. A private cluster would make the API server accessible only via a private IP address within a virtual network, which is a different security posture than restricting public access to specific IP ranges.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed