フリー問題

Kubernetes and Cloud Native Security Associate のフリー問題 14 / 20 問目

問題文

A namespace grants a developer permission to create Pods. Why does that permission need to be reviewed as carefully as a permission to read Secrets in the same namespace?

選択肢

  1. Pod creation implicitly grants the escalate verb on Roles in the namespace, so the developer can widen the grant without further review.
  2. Creating a Pod requires the API server to write a new object into etcd, and each of those writes is replicated to every member of the etcd cluster.
  3. A Pod can mount any Secret in its namespace, so being able to create Pods indirectly gives access to the contents of those Secrets.
  4. Pod creation bypasses the Pod Security Admission controller, so a Pod that violates the namespace profile still starts on a node in the cluster.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。