2V0-71.23 exam dumps

2V0-71.23 practice question 347 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 347

Select 3

An organization is deploying applications to Kubernetes clusters managed by VMware Tanzu. The organization wants to ensure only trusted container images are used and that no unauthorized or vulnerable images are pulled from external sources. Which of the following registry policies should the organization implement to achieve this goal?

  1. A

    Configure image registry access control to restrict access to authorized users only.

  2. B

    Enable vulnerability scanning and enforce deployment of only images that pass the scan.

  3. C

    Allow unrestricted access to public container registries for flexibility in image sourcing.

  4. D

    Limit deployments to images signed with a trusted signature using Content Trust or Notary.

  5. E

    Disable image caching on Kubernetes nodes to ensure images are always pulled fresh from registries.

Show answer and explanation

Correct answers: A, B, D

Explanation

To ensure only trusted container images are deployed, organizations should implement registry policies such as access control, vulnerability scanning, and image signing verification. These measures help prevent unauthorized, vulnerable, or tampered images from being used in Kubernetes clusters. Allowing unrestricted access to public registries or disabling caching does not align with best practices for secure image deployment.

  • A. Correct.

    Configuring image registry access control ensures only authorized users can push or pull images, reducing the risk of unauthorized or malicious images being used.

  • B. Correct.

    Enabling vulnerability scanning ensures that only secure, compliant images are deployed, helping to prevent vulnerabilities from being introduced into the environment.

  • C. Incorrect.

    Allowing unrestricted access to public registries introduces security risks, as it permits the use of unverified or malicious images. This is not a best practice.

  • D. Correct.

    Using trusted signatures ensures the integrity and authenticity of container images, preventing tampered or untrusted images from being deployed.

  • E. Incorrect.

    Disabling image caching can lead to performance issues and is not directly related to enforcing trusted image policies. This is not a recommended approach.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam