You need to ensure that Azure Kubernetes Service (AKS) pods cannot communicate with the Azure Instance Metadata Service (IMDS) endpoint. Which control achieves this?
-
A
Apply a Kubernetes NetworkPolicy blocking 169.254.169.254
-
B
Enable Azure AD workload identity on the cluster
-
C
Disable the system-assigned managed identity on the node pool
-
D
Configure Azure Firewall egress rules