フリー問題

Oracle Cloud Infrastructure Architect Professional のフリー問題 4 / 20 問目

問題文

A team wants pods in a Kubernetes cluster to call OCI APIs with permissions granted to the Kubernetes service account rather than to the worker node. Which cluster configuration makes that possible?

選択肢

  1. An enhanced cluster, because workload identity is one of the capabilities that only enhanced clusters support.
  2. Any cluster, because the mapping between Kubernetes service accounts and OCI policies is part of the open source Kubernetes distribution and therefore does not depend on which kind of cluster the workload happens to run on.
  3. A basic cluster with an instance principal on each worker node, and every pod that lands on that node cannot be held to a narrower set of permissions.
  4. A basic cluster with a dynamic group that matches the cluster, and the group grants its permissions to every workload, not just to the worker node.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。