Google Professional Cloud Security Engineer Exam - Topic 3 Question 15 Discussion
For compliance reasons, an organization needs to ensure that in-scope PCI Kubernetes Pods reside on ''in- scope'' Nodes only. These Nodes can only contain the ''in-scope'' Pods.How should the organization achieve this objective?
C) Place a taint on the Nodes with the label inscope: true and effect NoSchedule and a toleration to match in the Pod configuration.
A) Add a nodeSelector field to the pod configuration to only use the Nodes labeled inscope: true.
B) Create a node pool with the label inscope: true and a Pod Security Policy that only allows the Pods to run on Nodes with that label.
D) Run all in-scope Pods in the namespace ''in-scope-pci''.
Lucia
10 months agoMelissia
10 months agoHelaine
11 months agoGlenn
11 months agoKristian
11 months agoFreeman
11 months agoMajor
11 months agoSena
11 months agoMarjory
11 months agoErnie
11 months agoCordelia
11 months agoAngelyn
11 months agoMicaela
11 months agoJuan
11 months agoTimothy
11 months ago