フリー問題

Kubernetes and Cloud Native Security Associate のフリー問題 5 / 20 問目

問題文

An auditor asks why access to etcd must be restricted even though the cluster has a carefully designed set of RBAC rules. Which explanation is correct?

選択肢

  1. The rules themselves are stored in etcd as objects, so a client with direct access could read them and work out which service account holds the permissions that it needs.
  2. RBAC is evaluated by the API server, so a client that talks to etcd directly reads and writes cluster state without any of those rules being consulted.
  3. The rules simply have no effect there because etcd maintains its own separate set of Roles and RoleBindings, so a direct client is still constrained by whatever those say.
  4. The rules apply there only to write operations, so a direct read of the stored objects needs no permission at all.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。