GregLab | Exam Prep

Secure compute

Application Platform Security

Core

Secure container and application platforms by combining posture and runtime signals with platform identity, private networking, registry controls, edge filtering, and back-end API policy.

Aligned to the live SC-500 guide, which publishes no skills-measured date; guide and product behavior verified September 23, 2026.

Why this matters

Managed application services reduce infrastructure work but do not erase identity, image, secret, network, ingress, and API risks. Controls must be placed at build, registry, platform, edge, and runtime layers.

Must Know

  • Defender for Containers combines posture recommendations and supported runtime threat detection for Kubernetes and container environments; verify plan, connector, sensor, and coverage.
  • AKS security includes Microsoft Entra integration, Azure RBAC or Kubernetes authorization, workload identity, network policy, private clusters, image governance, secrets, and node protection.
  • Container Registry can use Microsoft Entra roles, private endpoints, firewall rules, content trust or signing workflows, and Defender image assessment; avoid shared admin credentials.
  • Container Instances and Container Apps have different orchestration, network, identity, ingress, secret, and revision models; select controls for the actual service.
  • Functions, Logic Apps, and App Service each expose authentication and network settings. Managed identity plus private endpoints or access restrictions often remove embedded credentials and public exposure.
  • Azure Web Application Firewall protects supported HTTP/S entry points against web attacks; prevention mode blocks matching requests while detection mode logs them.
  • API Management policy can validate tokens, restrict callers, rate limit, transform, filter, and authenticate to backends; policy scope and order determine effective behavior.

Compare and Distinguish

  • Defender for Containers supplies posture and threat signals; AKS policy, identity, network, and admission controls prevent or constrain activity.
  • WAF filters inbound web traffic at a supported edge; API Management enforces API-specific identity, quota, transformation, and backend policy.
  • A registry private endpoint protects image distribution paths; it does not secure a running container or its workload identity.

Scenario examples

  • Scenario: Pods need to pull from a private registry without an admin password. Think: authorize the cluster or kubelet identity with the required registry role.
  • Scenario: A function must call Key Vault without a secret and accept traffic only through a private path. Think: combine managed identity with network restrictions.
  • Scenario: Internet clients need OWASP filtering and per-client API quotas. Think: use WAF for web attack filtering and API Management policy for API controls.

Exam traps

  • A clean image scan does not prove a container will behave safely at runtime.
  • Disabling public network access before private DNS and integration are ready can break deployment and runtime dependencies.
  • App Service authentication does not automatically authorize a caller to every backend.
  • A WAF rule cannot replace JWT validation or per-subscription API quotas.

Key takeaways

  • Secure artifacts, control planes, workload identities, network paths, ingress, and runtime separately.
  • Prefer managed identities and private connectivity over shared credentials and unrestricted endpoints.
  • Use WAF and API Management together when edge and API requirements differ.
How it works
  • Artifacts are authenticated and pulled from registries, platforms start workloads with identities and network policy, and edge services process inbound requests.
  • Defender observes configuration and runtime signals while service-native controls enforce the intended path.
Objects and administrative surfaces
  • Defender for Cloud container recommendations, inventory, alerts, and plan configuration.
  • AKS cluster and workload identity, network policy, API server access, admission policy, nodes, registries, images, and secrets.
  • Container Apps or Instances networking, Functions, Logic Apps, App Service authentication and access restrictions, WAF policy, and API Management policy scopes.
When to use it
  • Use WAF for web exploit filtering and API Management for protocol, caller, quota, and backend API policy.
  • Use platform authentication plus private or restricted ingress when a managed application should not accept anonymous public traffic.
Security and governance implications
  • Control registry pushes, cluster administration, workload identities, public ingress, application settings, WAF exclusions, and API policy edits.
  • Review images, dependencies, secrets, dormant endpoints, and Defender coverage continuously.
Troubleshooting signals
  • For image pull failure, inspect registry DNS and firewall, identity, role assignment, image name, and tag or digest.
  • For a rejected request, trace WAF logs, API Management policy evaluation, platform authentication, network restrictions, and backend authorization.
More detail
  • Use Defender for Containers findings without confusing posture and runtime protection.
  • Configure AKS identity, authorization, registry, network, and workload controls.
  • Secure Container Apps, Container Instances, Functions, Logic Apps, and App Service according to their models.
  • Apply WAF and API Management policies at the correct request-processing layer.

Ready for the quiz?

  • Which identity should an AKS workload use to reach an Azure resource without a stored secret?
  • What does a registry private endpoint fail to protect?
  • When are both WAF and API Management policy required?

Related objectives

  • D3.3.S1 — Detect misconfigurations and runtime risks in container workloads by using Defender for Containers
  • D3.3.S2 — Implement and configure security controls for Azure Kubernetes Service (AKS)
  • D3.3.S3 — Implement and configure security controls for Azure Container Registry
  • D3.3.S4 — Implement and configure security controls for Azure Container Instances and Azure Container Apps
  • D3.3.S5 — Implement and configure security controls for Azure Functions, including authentication and network access
  • D3.3.S6 — Implement and configure security controls for Azure Logic Apps
  • D3.3.S7 — Implement and configure security controls for Azure App Service
  • D3.3.S8 — Implement and configure Azure Web Application Firewall
  • D3.3.S9 — Implement security policies for back-end API protection by using API Management

Learn more

Free Microsoft Certified: Cloud and AI Security Engineer Associate prep

Build focused SC-500 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-500 at a glance

Level
Intermediate / Associate
Duration
120 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-500. This lane contains multiple-choice and multiple-response exam-style practice. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Intermediate Associate-level cloud and AI security-engineering complexity rather than a Microsoft-published question rating.

Reference

SC-500 topics and reference map

Study links

SC-500 resources