フリー問題

Kubernetes and Cloud Native Security Associate のフリー問題 12 / 20 問目

問題文

A platform team is choosing among the three Pod Security Standards profiles for a namespace that will host ordinary business applications written by internal developers. They want to prevent known privilege escalations without forcing every team to rewrite their Pod specifications. Which profile matches that goal?

選択肢

  1. None of the profiles applies, because they cover only system workloads, and a namespace of business applications falls outside their scope.
  2. The privileged profile, which is defined by an absence of restrictions, and nothing is blocked.
  3. The baseline profile, which blocks known privilege escalations while still allowing a minimally specified Pod.
  4. The restricted profile, the only profile that blocks privileged containers and the only one that prevents this class of escalation.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。