For compliance reasons, an organization needs to ensure that in-scope PCI Kubernetes Pods reside on "in-scope" Nodes only. These Nodes can only contain the "in-scope" Pods. How should the organization achieve this objective?
A) Add a nodeSelector field to the pod configuration to only use the Nodes labeled inscope: true.
B) Create a node pool with the label inscope: true and a Pod Security Policy that only allows the Pods to run on Nodes with that label.
C) Place a taint on the Nodes with the label inscope: true and effect NoSchedule and a toleration to match in the Pod configuration.
D) Run all in-scope Pods in the namespace "in-scope-pci".
Correct Answer:
Verified
Q53: A customer terminates an engineer and needs
Q54: A customer is collaborating with another company
Q55: A patch for a vulnerability has been
Q56: A customer is running an analytics workload
Q57: You are in charge of migrating a
Q59: Your company operates an application instance group
Q60: A customer has an analytics workload running
Q61: A company allows every employee to use
Q62: In order to meet PCI DSS requirements,
Q63: A customer's internal security team must manage
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents