2V0-71.23 exam dumps

2V0-71.23 practice question 19 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 19

Select 3

An organization is using VMware Tanzu Kubernetes Grid (TKG) to manage their Kubernetes clusters. The platform administrator needs to ensure that developers can deploy workloads without having access to the underlying infrastructure. Which of the following approaches should the platform administrator implement to achieve this goal?

  1. A

    Use Kubernetes Role-Based Access Control (RBAC) to restrict developer permissions to their namespaces only.

  2. B

    Configure Tanzu Mission Control (TMC) policies to enforce workload deployment restrictions based on user roles.

  3. C

    Grant developers cluster-admin permissions so they can manage their own resources independently.

  4. D

    Leverage Kubernetes Network Policies to isolate namespaces and restrict access between workloads.

  5. E

    Implement a GitOps workflow where developers submit workload deployment manifests via a source code repository.

Show answer and explanation

Correct answers: A, B, E

Explanation

To ensure developers can deploy workloads without accessing the underlying infrastructure, the platform administrator should combine tools such as Kubernetes RBAC, Tanzu Mission Control policies, and GitOps workflows. These approaches collectively enforce role-based access control, centralize policy management, and decouple deployment processes from infrastructure-level access, adhering to best practices for secure Kubernetes platform administration.

  • A. Correct.

    This is correct because Kubernetes RBAC allows fine-grained control over who can perform specific actions within a cluster, such as restricting developers to operate only within designated namespaces.

  • B. Correct.

    This is correct because Tanzu Mission Control (TMC) provides centralized policy management and allows administrators to enforce role-based restrictions on workload deployments.

  • C. Incorrect.

    This is incorrect because granting cluster-admin privileges to developers would provide excessive access to the underlying infrastructure, which violates the principle of least privilege.

  • D. Incorrect.

    This is incorrect because while Kubernetes Network Policies help isolate workloads at the network level, they do not directly address access control for workload deployment.

  • E. Correct.

    This is correct because a GitOps workflow decouples deployment processes from direct cluster access, allowing developers to submit manifests without needing infrastructure-level permissions.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam