問題文
A platform team is choosing a Pod Security Standards profile for the namespaces where product teams run ordinary web applications. They want to block the known privilege escalations while keeping the default, minimally specified Pod configuration usable. Which profile matches that description?
選択肢
- Restricted, which follows current Pod hardening best practices and is therefore the profile that allows the default Pod configuration to run unchanged.
- Baseline, which is minimally restrictive, prevents known privilege escalations and allows the default Pod configuration.
- Privileged, which is unrestricted and provides the widest possible permissions, and the default Pod configuration would run and every escalation would stay open.
- A profile between Privileged and Baseline, which exists for exactly this case and sits one step below Baseline in the standard.