Google Professional Cloud Security Engineer Exam - Topic 3 Question 15 Discussion
For compliance reasons, an organization needs to ensure that in-scope PCI Kubernetes Pods reside on ''in- scope'' Nodes only. These Nodes can only contain the ''in-scope'' Pods.How should the organization achieve this objective?
C) Place a taint on the Nodes with the label inscope: true and effect NoSchedule and a toleration to match in the Pod configuration.
A) Add a nodeSelector field to the pod configuration to only use the Nodes labeled inscope: true.
B) Create a node pool with the label inscope: true and a Pod Security Policy that only allows the Pods to run on Nodes with that label.
D) Run all in-scope Pods in the namespace ''in-scope-pci''.
Lucia
7 months agoMelissia
7 months agoHelaine
8 months agoGlenn
8 months agoKristian
8 months agoFreeman
8 months agoMajor
8 months agoSena
8 months agoMarjory
8 months agoErnie
8 months agoCordelia
8 months agoAngelyn
8 months agoMicaela
8 months agoJuan
8 months agoTimothy
8 months ago