問題文
A platform team is choosing among the three Pod Security Standards profiles for a namespace that will host ordinary business applications written by internal developers. They want to prevent known privilege escalations without forcing every team to rewrite their Pod specifications. Which profile matches that goal?
選択肢
- None of the profiles applies, because they cover only system workloads, and a namespace of business applications falls outside their scope.
- The privileged profile, which is defined by an absence of restrictions, and nothing is blocked.
- The baseline profile, which blocks known privilege escalations while still allowing a minimally specified Pod.
- The restricted profile, the only profile that blocks privileged containers and the only one that prevents this class of escalation.