NCP-AIO Administration Practice Question
A company runs multiple AI workloads on a shared Kubernetes cluster with NVIDIA GPUs. The administrator needs to enforce that only pods with a specific label can consume GPU resources, while other pods are denied. Which Kubernetes admission control mechanism should be used to implement this policy?
⚠ Common exam trap
The trap here is assuming that ResourceQuota can enforce per-pod label conditions, when it only limits aggregate namespace consumption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ValidatingAdmissionWebhook
A ValidatingAdmissionWebhook allows custom admission logic to be applied to pod creation. By configuring a webhook that checks for a specific label before permitting GPU resource requests, the administrator can enforce label-based access control. This is the correct mechanism because it can inspect pod metadata and resource requests and reject non-compliant pods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy (PSP) controls security-related aspects like privileged mode and volume types, but it does not have the capability to enforce label-based access to specific extended resources such as GPUs. PSP is also deprecated in recent Kubernetes versions. It cannot restrict which pods may request nvidia.com/gpu based on labels, so it is not suitable for this requirement.
- ✓
ValidatingAdmissionWebhook
Why this is correct
A ValidatingAdmissionWebhook can intercept pod creation requests and evaluate custom logic, such as checking for a specific label before allowing the pod to request GPU resources. This provides the flexibility to enforce label-based policies on extended resources. By deploying a webhook that inspects pod labels and resource requests, the administrator can deny non-compliant pods, meeting the requirement.
- ✗
ResourceQuota
Why it's wrong here
ResourceQuota limits the total amount of resources a namespace can consume, including extended resources like GPUs, but it operates at the namespace level and does not enforce label-based restrictions on individual pods. It cannot distinguish between pods with different labels within the same namespace. Therefore, it cannot ensure that only pods with a specific label consume GPUs.
- ✗
LimitRange
Why it's wrong here
LimitRange sets default resource requests and limits for pods in a namespace, but it does not enforce admission policies based on labels. It can constrain the maximum GPU request per pod, but it cannot prevent a pod without the required label from requesting GPUs. Thus, it does not satisfy the need to allow only labeled pods to access GPU resources.
About these practice questions
This NCP-AIO question is part of Courseiva's 309-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official NVIDIA exam blueprint
This NCP-AIO practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-AIO exam.