フリー問題

Kubernetes and Cloud Native Security Associate のフリー問題 11 / 20 問目

問題文

A namespace enforces the restricted Pod Security Standard. A team submits a Pod whose containers do not mention capabilities at all, and the Pod is rejected. Which requirement of that profile accounts for the rejection?

選択肢

  1. Containers must run as user ID 0 and the profile can drop privileges itself once the container has started.
  2. Containers may add whichever capability they need as long as they also declare a seccomp profile of type RuntimeDefault and that profile constrains which system calls are reachable.
  3. Containers must declare a hostPort and the profile can verify the exposure that the workload asks for.
  4. Containers must drop ALL capabilities, and may only add back NET_BIND_SERVICE.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。