Workload & Supply Chain · wrap-up
Cheat sheet & self-check
9 questions across 3 lessons. Each answer links back to the lesson it came from.
Pick an answer to see if you got it, and why.
Q1. Which Pod Security Standard should most application namespaces enforce?
Show answer
B. restricted blocks privileged containers, host namespaces and running as root, and requires dropping capabilities and a seccomp profile. baseline is a minimum.
From lesson 10 · Pod Security & admission controlQ2. What does ValidatingAdmissionPolicy (CEL) add compared to webhooks like Kyverno or Gatekeeper?
Show answer
B. CEL policies run in-process: no webhook latency or availability risk. Webhook engines add features like mutation, generation and richer libraries.
From lesson 10 · Pod Security & admission controlQ3. Why roll out a new policy in audit/warn mode first?
Show answer
B. Enforcing blindly can block deployments or even critical add-ons. Warn/audit shows the impact, so teams can fix manifests first.
From lesson 10 · Pod Security & admission controlQ4. Without encryption at rest, how are Secret values stored in etcd?
Show answer
B. Secrets are only encoded by default. Encryption at rest protects etcd data and backups; RBAC still controls API access.
From lesson 11 · Secrets managementQ5. Why is a KMS provider better than an aescbc key in the config file?
Show answer
B. With a local key file, anyone with the control-plane disk has both the data and the key. KMS separates them.
From lesson 11 · Secrets managementQ6. What does the External Secrets Operator do?
Show answer
B. The source of truth stays in the secret manager; the operator creates or refreshes the in-cluster Secret.
From lesson 11 · Secrets managementQ7. Why deploy images by digest (@sha256:…) rather than by tag?
Show answer
B. Tags are mutable pointers. Digests make deployments reproducible, and make signatures meaningful.
From lesson 12 · Supply chain securityQ8. What does an SBOM give you?
Show answer
B. When a new vulnerability is announced, SBOMs let you search what you run instead of rescanning everything blind.
From lesson 12 · Supply chain securityQ9. What does signature verification at admission protect against?
Show answer
B. Signatures prove origin and integrity. Vulnerability scanning is a separate control, and you need both.
From lesson 12 · Supply chain security