Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). A recent audit found that several pods were scheduled onto nodes that do not meet the organization's hardened baseline, and the team wants to enforce that only nodes with specific labels are eligible for certain workloads. Which Kubernetes mechanism should the team implement?

⚠ Common exam trap

A common mix-up: candidates confuse scheduling controls with runtime controls, assuming that a policy or disruption budget can dictate which node a pod lands on.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Node affinity combined with node labels

Node affinity uses node labels as hard or soft match rules in the pod specification, so requiring a specific label ensures the scheduler only places the workload on nodes that carry the hardened baseline. This is the native Kubernetes control for constraining placement without replacing the default scheduler or altering cluster autoscaling behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PodDisruptionBudget

    Why it's wrong here

    PodDisruptionBudgets control voluntary disruptions such as node drains by limiting how many pods of a workload can be unavailable at once. They do not influence which nodes a pod can be scheduled onto, so they cannot enforce a node-label baseline for workload placement in this GKE scenario.

  • ✗

    Horizontal Pod Autoscaler

    Why it's wrong here

    The Horizontal Pod Autoscaler adjusts the number of pod replicas based on metrics such as CPU utilization. It has no role in selecting which nodes run the pods, so it cannot prevent scheduling onto nodes that lack the hardened baseline label in this GKE cluster.

  • ✓

    Node affinity combined with node labels

    Why this is correct

    Node affinity rules in the pod spec use node labels as match expressions, so only nodes carrying the required hardened baseline label will be eligible. This directly enforces the placement requirement on GKE without needing a custom scheduler, and it can be made mandatory with requiredDuringSchedulingIgnoredDuringExecution.

  • ✗

    NetworkPolicy

    Why it's wrong here

    NetworkPolicies govern ingress and egress traffic between pods and other endpoints at layer 3/4. They restrict connectivity but have no effect on the scheduler's node selection, so they cannot enforce that workloads land only on nodes matching the hardened baseline labels.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.