Nobody is alerted when a privileged tugboat pod or a suspicious kube-api call appears on AKS. Which product should the security engineer enable for cluster security monitoring?
Select an answer to reveal the explanation.
Short Explanation
Privileged pods and weird kube-api calls shouldn’t be silent. Turn on Defender for Containers so the cluster has a security watch—don’t bolt App Insights into every app and call it cluster defense.
Full Explanation
Microsoft Defender for Containers provides security monitoring for AKS, including visibility into container and Kubernetes-related threats and misconfigurations aligned with the “secure and monitor AKS” skill. Application Insights SDK instrumentation is an application-performance approach (AZ-204) and is not the cluster security-monitoring control. A Domain 4 Secure Score walkthrough or inventing Sentinel rules first does not replace enabling Defender for Containers on the cluster.