CCSP Cloud Security Operations Practice Question
A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). A recent audit found that several pods were scheduled onto nodes that do not meet the organization's hardened baseline, and the team wants to enforce that only nodes with specific labels are eligible for certain workloads. Which Kubernetes mechanism should the team implement?
⚠ Common exam trap
A common mix-up: candidates confuse scheduling controls with runtime controls, assuming that a policy or disruption budget can dictate which node a pod lands on.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Node affinity combined with node labels
Node affinity uses node labels as hard or soft match rules in the pod specification, so requiring a specific label ensures the scheduler only places the workload on nodes that carry the hardened baseline. This is the native Kubernetes control for constraining placement without replacing the default scheduler or altering cluster autoscaling behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PodDisruptionBudget
Why it's wrong here
PodDisruptionBudgets control voluntary disruptions such as node drains by limiting how many pods of a workload can be unavailable at once. They do not influence which nodes a pod can be scheduled onto, so they cannot enforce a node-label baseline for workload placement in this GKE scenario.
- ✗
Horizontal Pod Autoscaler
Why it's wrong here
The Horizontal Pod Autoscaler adjusts the number of pod replicas based on metrics such as CPU utilization. It has no role in selecting which nodes run the pods, so it cannot prevent scheduling onto nodes that lack the hardened baseline label in this GKE cluster.
- ✓
Node affinity combined with node labels
Why this is correct
Node affinity rules in the pod spec use node labels as match expressions, so only nodes carrying the required hardened baseline label will be eligible. This directly enforces the placement requirement on GKE without needing a custom scheduler, and it can be made mandatory with requiredDuringSchedulingIgnoredDuringExecution.
- ✗
NetworkPolicy
Why it's wrong here
NetworkPolicies govern ingress and egress traffic between pods and other endpoints at layer 3/4. They restrict connectivity but have no effect on the scheduler's node selection, so they cannot enforce that workloads land only on nodes matching the hardened baseline labels.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.