問題文
An administrator wants to see which existing workloads would violate a stricter Pod Security Standard before turning on rejection, so that teams can be told what to fix. Which mode should be applied to the namespace?
選択肢
- The enforce mode combined with the privileged level, because that pairing will accept every Pod and will also write an entry describing each violation.
- The audit mode, which records a violation in the audit log while still allowing the Pod.
- The warn mode combined with the privileged level, so users see a message on every request, and nothing is refused.
- The enforce mode, because rejected Pods appear in the event log, so the administrator can read the list off from there.