2V0-71.23 exam dumps

2V0-71.23 practice question 348 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 348

Select 2

An organization is using VMware Tanzu Kubernetes Grid (TKG) to manage their Kubernetes clusters. They want to enforce registry policies to ensure that only images from approved registries can be deployed to the clusters. Which actions should they take to enforce this policy?

  1. A

    Use an admission controller to validate image sources during pod creation.

  2. B

    Enable image scanning within Tanzu Mission Control (TMC) to block unapproved images.

  3. C

    Configure a Kubernetes NetworkPolicy to restrict access to unapproved registries.

  4. D

    Define a PodSecurityPolicy (PSP) to restrict image sources to approved registries.

  5. E

    Implement a custom policy using Open Policy Agent (OPA) and Gatekeeper to validate image registry compliance.

Show answer and explanation

Correct answers: A, E

Explanation

To enforce registry policies for deploying images in VMware Tanzu Kubernetes Grid, the best practices include using an admission controller, such as Open Policy Agent (OPA) with Gatekeeper, to validate the source of container images during pod creation. This ensures that only images from approved registries are allowed. Tanzu Mission Control provides image scanning capabilities, but it does not enforce registry restrictions. NetworkPolicies and PodSecurityPolicies are not directly relevant for enforcing registry compliance.

  • A. Correct.

    Using an admission controller, such as OPA Gatekeeper, is a common practice to validate image sources during pod creation. It allows the enforcement of policies to restrict images to approved registries.

  • B. Incorrect.

    While image scanning in Tanzu Mission Control (TMC) can help identify vulnerabilities, it does not enforce registry restrictions directly.

  • C. Incorrect.

    Kubernetes NetworkPolicies are designed to control network traffic between pods and services, but they cannot enforce image registry policies.

  • D. Incorrect.

    PodSecurityPolicies (PSPs) are used for defining security conditions for pods, such as privilege levels and file system access, but they do not enforce registry-specific restrictions.

  • E. Correct.

    Open Policy Agent (OPA) with Gatekeeper can be used to create custom policies, including enforcing image registry compliance, making it a valid option for this use case.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam