ITGSS CERTIFIED PROFESSIONAL; DEVOPS
ENGINEER EXAM, QUESTIONS AND VERIFIED
ANSWERS
A linux _____ limits the ability of a process to see the system resources.
- ANSWER namespace
When you create a Service, it creates a corresponding ___ ___.
<service-name>.<namespace-name>.svc.cluster.local - ANSWER DNS
entry
Unlike _____ IP addresses, which actually route to a fixed destination,
_____ IPs are not actually answered by a single host. Instead, we use
_____ (packet processing logic in Linux) to define _____ IP addresses
which are transparently redirected as needed. When clients connect to
the VIP, their traffic is automatically transported to an appropriate
endpoint. - ANSWER POD service iptables virtual
Each Pod is assigned a unique IP address. Every _____ in a pod gets
the same IP address of the pod. - ANSWER container
A _____ in Kubernetes is an abstraction which defines a logical set of
Pods and a policy by which to access them. The set of Pods targeted by
a Service is usually determined by a LabelSelector. - ANSWER Service
A Service in Kubernetes is an abstraction which defines a logical set of
____ and a policy by which to access them. The set of Pods targeted by
a Service is usually determined by a LabelSelector. - ANSWER Pods
A Service in Kubernetes is an abstraction which defines a logical set of
Pods and a policy by which to access them. The set of Pods targeted by
a Service is usually determined by a _____. - ANSWER LabelSelector
Ansible Roles are basically made up of _____, _____, and _____, -
ANSWER tasks handlers configurations
,Container Security:
______ are designed giving them highest level of access in the
ecosystem. If the access provided to users and groups is not scoped to
their specific needs, a malicious or careless user could affect or subvert
the operation of other containers managed by the orchestrator.
Orchestrators often include their own authentication directory service,
which may be separate from the typical directories already in use within
an organization. This can lead to weaker account management practices
and 'orphaned' accounts in the orchestrator because these systems are
less rigorously managed. - ANSWER Orchestrators
Master Node(s)
Responsible for managing the workload within the cluster. Services
include:
_____: A key-value data store for cluster configuration
API server: A REST service that provides an interface into Kubernetes;
state is stored in etcd
_____: Intelligently determines which nodes workloads should be
assigned to
______ manager: A process that controllers like the DaemonSet and
Replication controller run in; controllers access the API to manage
resources - ANSWER etcd Scheduler Controller
AWS — a "serverless" container compute engine where you only pay for
the resources required to run your containers. Suited for customers who
do not want to worry about managing servers, handling capacity
planning, or figuring out how to isolate container workloads for security. -
ANSWER Fargate
In object-oriented and functional programming, an ____ object is an
object whose state cannot be modified after it is created - ANSWER
immutable
, Comparing Kubernetes to Amazon ECS is not entirely fair. Amazon ECS
provides two elements in one product: a container orchestration
platform, and a managed service that operates it and provisions _____
resources. Kubernetes offers only one of these elements. - ANSWER
hardware
Advantages of Kubernetes include:
Serverless infrastructure: Kubernetes containers can be operated
without direct access to VMs. More than that, there are Kubernetes
solutions that are real serverless and integrate with AWS _____ -
ANSWER Fargate
Built-in security: Kubernetes creates its own _____ network with its own
isolated, secure networking. - ANSWER private
With ECS, ENIs can be allocated to a '_____', and an EC2 instance can
support up to 120 *****.
With EKS, ENIs can be allocated to and shared between Kubernetes
pods, enabling the user to place up to 750 Kubernetes pods per EC2
instance (depends on instance type) which achieves a much higher
container density than ECS. - ANSWER Task
With EKS, ENIs can be allocated to and shared between Kubernetes
pods, enabling the user to place up to 750 Kubernetes ____ per EC2
instance - ANSWER pods
ECS and EKS, both supports IAM roles per _____/______ - ANSWER
task container
_____ are a feature of the Linux kernel that partitions kernel resources
such that one set of processes sees one set of resources while another
set of processes sees a different set of resources. - ANSWER
Namespaces
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller luzlinkuz. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $13.99. You're not tied to anything after your purchase.