Courseiva

NCP-AIO Installation and Deployment Practice Question

A cloud operations team is deploying the NVIDIA GPU Operator in an environment where the Kubernetes control plane cannot reach the public internet, but worker nodes can access an internal HTTP registry that mirrors required images. The team wants to avoid manual image pulls on each node. Which two configurations should they implement to enable a successful air-gapped installation? (Choose two.)

⚠ Common exam trap

The trap here is thinking that simply disabling a component or setting a repository path is enough for air-gapped operation, when all images must be mirrored and authentication configured if needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a private image registry and configure image pull secrets in the `gpu-operator` namespace for authentication.

Air-gapped installations require that all container images used by the GPU Operator are available in a reachable registry. Mirroring every component image and updating the ClusterPolicy to reference the internal registry ensures pods can start without internet access. Additionally, if the registry requires authentication, an image pull secret must be configured in the operator's namespace to allow secure pulls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a private image registry and configure image pull secrets in the `gpu-operator` namespace for authentication.

    Why this is correct

    A private registry often requires authentication. Creating an image pull secret in the operator's namespace and referencing it in the ClusterPolicy or service accounts allows nodes to pull images securely. This is a standard requirement for air-gapped installations where the internal registry is not publicly accessible, ensuring components can authenticate and retrieve images.

  • ✗

    Configure the ClusterPolicy with `operator.defaultRuntime: containerd` and set `driver.repository` to the internal registry path.

    Why it's wrong here

    Setting the default runtime and driver repository is necessary for any installation, but it does not address air-gapped image availability. Without mirroring all operator images to the internal registry, the installation will still fail when other components attempt to pull from public registries. This option alone does not solve the air-gap requirement.

  • ✗

    Disable the Node Feature Discovery (NFD) component to reduce the number of images that need to be mirrored.

    Why it's wrong here

    NFD is essential for labeling GPU nodes and enabling the operator to schedule components correctly. Disabling it would break GPU detection and prevent the operator from working properly. While it reduces image count, it is not a valid solution for air-gapped installation because it compromises core functionality.

  • ✓

    Mirror all GPU Operator component images to the internal registry and update the ClusterPolicy to reference that registry for each component.

    Why this is correct

    In an air-gapped environment, every image used by the operator—driver, toolkit, device plugin, DCGM exporter, and so on—must be available in the internal registry. Updating the ClusterPolicy to point to the mirrored images ensures that all pods pull from the reachable registry, enabling a fully offline installation without manual pulls on each node.

  • ✗

    Set `driver.enabled: false` to avoid pulling the driver image from the public registry.

    Why it's wrong here

    Disabling the driver would mean the operator does not manage drivers, which defeats the purpose of using the GPU Operator. While it avoids pulling the driver image, it leaves driver installation to the administrator, complicating the air-gapped setup. This is not a recommended approach for a standard operator deployment.

About these practice questions

This NCP-AIO question is part of Courseiva's 309-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCP-AIO practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-AIO exam.