問題文
A container flaw can be addressed by rebuilding the image or by replacing the running workload. How do those two relate?
選択肢
- Replacing the workload is sufficient on its own, because the replacement is started from the current content and picks up whatever corrections were published since it was originally deployed.
- Neither helps unless the nodes that carry these workloads and with them the whole of the cluster is replaced.
- Rebuilding fixes what future workloads will start from, and replacing is what removes the flaw from what is running on the node right now, so both are needed.
- Rebuilding the image, and then copying it up to the registry that this one cluster reads from at startup, is sufficient on its own.