Google Professional Cloud Security Engineer Exam - Topic 3 Question 15 Discussion
For compliance reasons, an organization needs to ensure that in-scope PCI Kubernetes Pods reside on ''in- scope'' Nodes only. These Nodes can only contain the ''in-scope'' Pods.How should the organization achieve this objective?
C) Place a taint on the Nodes with the label inscope: true and effect NoSchedule and a toleration to match in the Pod configuration.
A) Add a nodeSelector field to the pod configuration to only use the Nodes labeled inscope: true.
B) Create a node pool with the label inscope: true and a Pod Security Policy that only allows the Pods to run on Nodes with that label.
D) Run all in-scope Pods in the namespace ''in-scope-pci''.
Lucia
9 months agoMelissia
9 months agoHelaine
9 months agoGlenn
9 months agoKristian
9 months agoFreeman
10 months agoMajor
10 months agoSena
10 months agoMarjory
10 months agoErnie
10 months agoCordelia
10 months agoAngelyn
10 months agoMicaela
10 months agoJuan
10 months agoTimothy
10 months ago