2V0-71.23 exam dumps

2V0-71.23 practice question 152 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 152

Select 3

A Tanzu Kubernetes administrator has been tasked with implementing policies to ensure that development teams can only deploy workloads to specific namespaces and must not utilize more than a certain amount of CPU and memory resources. Which of the following policies should the administrator implement to meet these requirements?

  1. A

    Network policies to restrict communication between namespaces

  2. B

    Resource quotas to limit the total CPU and memory usage

  3. C

    Role-based access control (RBAC) policies to define namespace-level permissions

  4. D

    Pod security policies to enforce workload security configurations

  5. E

    Limit ranges to set constraints on resource requests and limits per pod

Show answer and explanation

Correct answers: B, C, E

Explanation

To meet the requirements of restricting workload deployment to specific namespaces and controlling resource usage, the administrator should use a combination of resource quotas, RBAC policies, and limit ranges. Resource quotas limit the total CPU and memory usage at the namespace level, RBAC ensures only authorized users can deploy workloads to specific namespaces, and limit ranges enforce constraints on resource requests and limits for pods, ensuring resources are appropriately allocated.

  • A. Incorrect.

    Network policies are used to restrict or allow communication between namespaces or pods, but they do not address resource consumption or namespace-specific workload deployment requirements.

  • B. Correct.

    Resource quotas are applied at the namespace level and are used to limit the total amount of CPU, memory, or other resources that can be consumed in a namespace, making them relevant to this scenario.

  • C. Correct.

    RBAC policies are used to define what actions users or groups can perform within a namespace, such as deploying workloads, making them essential for restricting workload deployment to specific namespaces.

  • D. Incorrect.

    Pod security policies are used to enforce security settings for pods, such as restricting privilege escalation or defining user permissions, but they do not directly address resource or namespace restrictions.

  • E. Correct.

    Limit ranges are used to enforce minimum and maximum resource requests and limits for pods or containers within a namespace, helping to control resource usage at a granular level.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam