What is the difference between gVisor and Firecracker?
Given a standard Kubernetes cluster architecture comprising a single control plane node (hosting both etcd and the control plane as Pods) and three worker nodes, which of the following data flows crosses a trust boundary?
By default, in a Kubeadm cluster, which authentication methods are enabled?
An attacker has access to the network segment that the cluster is on.
What happens when a compromised Pod attempts to connect to the API server?
You want to minimize security issues in running Kubernetes Pods. Which of the following actions can help achieve this goal?