フリー問題

Kubernetes and Cloud Native Security Associate のフリー問題 15 / 20 問目

問題文

A single namespace creates thousands of Pods and the nodes become unable to schedule anything else. Which combination of objects most directly limits this class of resource exhaustion?

選択肢

  1. An audit policy at the RequestResponse level for Pod creation, so each new Pod is recorded in full.
  2. A NetworkPolicy that denies egress from the namespace, together with a PriorityClass that gives the other namespaces a higher value, and their Pods are placed first when the scheduler has to choose.
  3. A readiness probe on every container in the namespace, so unhealthy Pods stop receiving traffic.
  4. A ResourceQuota that caps the object counts and the aggregate compute resources, together with a LimitRange that gives each container a default and a maximum.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。