フリー問題

Kyverno Certified Associate のフリー問題 16 / 20 問目

問題文

A verifyImages rule must read a pull secret that lives in the namespace of the Pod being evaluated. Which capability of Kyverno 1.18 does this rely on, and what does it require?

選択肢

  1. The registryCredentialHelpers flag, which resolves the credentials from the cloud provider.
  2. The imageRegistryCredentials secrets list, which has always accepted a namespace prefix.
  3. Kyverno automatically uses the pod's imagePullSecrets, and the admission and background controllers need get access to secrets in those namespaces.
  4. The allowInsecureRegistry flag, because reading a secret from another namespace needs a certificate.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。