2V0-71.23 exam dumps

2V0-71.23 practice question 345 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 345

Select 2

Your organization is using VMware Tanzu Kubernetes Grid and wants to enforce security and compliance when deploying container images. Specifically, the team wants to ensure only trusted images are used in production by controlling which image registries can be accessed and defining image signing requirements. Which policies can you implement to meet these requirements?

  1. A

    Use an allowlist to specify trusted container image registries.

  2. B

    Implement image vulnerability scanning within Tanzu Mission Control.

  3. C

    Enforce image signing and verification using Notary or Cosign.

  4. D

    Allow unrestricted access to public container registries for faster deployments.

  5. E

    Configure PodSecurityPolicies to block untrusted images.

Show answer and explanation

Correct answers: A, C

Explanation

To enforce secure and compliant image deployments in VMware Tanzu Kubernetes Grid, you can use an allowlist to control trusted registries and implement image signing and verification to ensure only trusted images are used. These methods directly address the need to restrict access to unapproved sources and validate image integrity. Other options, such as vulnerability scanning or PodSecurityPolicies, provide complementary security measures but do not fulfill the specific requirements of registry policies for deploying images.

  • A. Correct.

    Using an allowlist for trusted image registries ensures that Kubernetes clusters can only pull images from approved sources, improving security and compliance.

  • B. Incorrect.

    While vulnerability scanning is a valuable security practice, it does not directly enforce registry policies for deploying images.

  • C. Correct.

    Image signing and verification ensure that only images with valid signatures (from trusted sources) are deployed, aligning with the requirement for secure deployments.

  • D. Incorrect.

    Allowing unrestricted access to public registries exposes the environment to potential risks, such as pulling unverified or malicious images.

  • E. Incorrect.

    PodSecurityPolicies focus on pod-level security configurations but do not directly control registry access or enforce image verification.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam