QuestionQ48
Supporting compliance requirementsFor compliance purposes, an organization must ensure that in-scope PCI Kubernetes Pods run only on designated in-scope Nodes, and that these Nodes are restricted to running only the in-scope Pods (no other Pods may be scheduled on them). What should the organization do to meet this requirement?
- A Add a nodeSelector field to the pod configuration to only use the Nodes labeled inscope: true.
- B Create a node pool with the label inscope: true and a Pod Security Policy that only allows the Pods to run on Nodes with that label.
- C Place a taint on the Nodes with the label inscope: true and effect NoSchedule and a toleration to match in the Pod configuration.
- D Run all in-scope Pods in the namespace ג€in-scope-pciג€.
Community Discussion