Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Oracle Exam 1Z0-1084-23 Topic 3 Question 36 Discussion

Actual exam question for Oracle's 1Z0-1084-23 exam
Question #: 36
Topic #: 3
[All 1Z0-1084-23 Questions]

Your organization has mandated that all deployed container images used for microservices must be signed by a specified master encryption key (MEK). You have appropriately signed the container images as part of your build process, but must now ensure that they are automatically verified when they are deployed to Oracle Cloud Infrastructure (OCI) Container Engine for Kubemetes (OKE) clusters. Which option should be used to mandate image verification when deploying to OKE clusters, assuming that MEK is already stored in an available OCI Vault? (Choose the best answer.)

Show Suggested Answer Hide Answer
Suggested Answer: C

To mandate image verification when deploying container images to Oracle Cloud Infrastructure (OCI) Container Engine for Kubernetes (OKE) clusters, you should enable image verification policies separately for each OKE cluster. This is enforced at the cluster level. Enabling image verification policies at the cluster level ensures that all container images deployed to the OKE cluster are automatically verified against the specified master encryption key (MEK). This helps maintain the security and integrity of the deployed microservices by ensuring that only signed and trusted container images are used. Enabling image verification policies at the cluster level allows for consistent and centralized enforcement of the verification process across all nodes and node pools within the cluster. It provides a standardized approach to image verification for the entire cluster, simplifying management and ensuring compliance with the organization's mandate. Enabling image verification policies separately for each node pool or at the pod level would introduce complexity and potential inconsistencies in the verification process. Therefore, enforcing image verification at the cluster level is the recommended approach.


Contribute your Thoughts:

Malcom
14 days ago
I'm not sure, but enabling image verification policies for the OKE service control plane seems like a good idea too.
upvoted 0 times
...
Lenita
14 days ago
Haha, I hope the exam doesn't have any trick questions like 'enable image verification for your pet rock' or something. But C does seem like the best choice here.
upvoted 0 times
...
Tamekia
16 days ago
I was leaning towards B, but I can see the logic in C. Enforcing it at the cluster level rather than the node pool level seems like a more robust approach.
upvoted 0 times
...
Delila
20 days ago
I agree with Graciela. Enforcing image verification at the cluster level makes the most sense.
upvoted 0 times
...
Tamekia
22 days ago
Hmm, I think C is the correct answer. Enforcing image verification at the cluster level makes the most sense to ensure consistency across all deployments.
upvoted 0 times
Huey
7 days ago
It's important to have a centralized approach for image verification.
upvoted 0 times
...
Maxima
12 days ago
I agree, enforcing at the cluster level ensures consistency.
upvoted 0 times
...
...
Graciela
26 days ago
I think the best option is to enable image verification policies separately for each OKE cluster.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77