CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 88: Google Cloud Professional Cloud Security Engineer

For compliance reasons, an organization needs to ensure that in-scope PCI Kubernetes Pods reside on `in-scope` Nodes only. These Nodes can only contain the`in-scope` Pods. How should the organization achieve this objective?

Nội dung câu hỏi

For compliance reasons, an organization needs to ensure that in-scope PCI Kubernetes Pods reside on `in-scope` Nodes only. These Nodes can only contain the`in-scope` Pods. How should the organization achieve this objective?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Add a nodeSelector field to the pod configuration to only use the Nodes labeled inscope: true.
  2. B. Create a node pool with the label inscope: true and a Pod Security Policy that only allows the Pods to run on Nodes with that label.
  3. C. Place a taint on the Nodes with the label inscope: true and effect NoSchedule and a toleration to match in the Pod configuration. — đáp án hiện tại
  4. D. Run all in-scope Pods in the namespace ג€in-scope-pciג€.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề