フリー問題

Kyverno Certified Associate のフリー問題 3 / 20 問目

問題文

A platform team must reject any Pod whose image comes from an untrusted registry. They evaluated the built-in ResourceQuota and PodSecurity admission controllers and found neither can express the rule. Which property of dynamic admission control makes Kyverno the right fit here?

選択肢

  1. Dynamic admission controllers are compiled into the API server binary, removing the network hop.
  2. Dynamic admission controllers run after the request has been persisted, so they can inspect the stored object.
  3. Dynamic admission controllers replace Kubernetes RBAC, so one rule set covers both authorization and validation.
  4. Dynamic admission controllers run custom decision logic supplied at runtime, so organization-specific rules can be expressed.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。