NCP-AIO Administration Practice Question
An administrator is configuring an NVIDIA AI Enterprise cluster to run multi-tenant inference workloads on Kubernetes. The administrator must ensure that GPU resources are isolated and that tenants cannot access each other's GPU memory. Which two actions should the administrator take? (Choose two.)
⚠ Common exam trap
The trap here is assuming that Kubernetes quotas or time-slicing provide GPU memory isolation, when only MIG creates hardware-partitioned instances with dedicated memory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the NVIDIA GPU Operator with the device plugin configured to advertise MIG resources.
Hardware-level isolation for multi-tenant inference on Kubernetes is achieved by enabling MIG on supported GPUs and having the GPU Operator's device plugin advertise MIG instances as schedulable resources. Together these actions partition the GPU into isolated slices and make those slices available to tenants without memory sharing, satisfying the isolation requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Kubernetes ResourceQuota and LimitRange objects to restrict GPU memory per namespace.
Why it's wrong here
Kubernetes ResourceQuota and LimitRange can limit CPU, memory, and extended resources such as nvidia.com/gpu, but they cannot partition or isolate GPU device memory. A quota controls how many GPUs a namespace may request, not what happens inside the GPU. Tenants sharing a GPU could still access each other's memory, so this action does not meet the isolation requirement.
- ✗
Configure NVIDIA vGPU with different vGPU profiles for each tenant.
Why it's wrong here
NVIDIA vGPU is designed for virtualized environments using a hypervisor and vGPU manager, not for bare-metal Kubernetes clusters. While vGPU profiles can isolate memory, they require a virtualization layer that is not present in a standard containerized Kubernetes deployment. Applying vGPU here would not integrate with the GPU Operator's device plugin model and is architecturally mismatched for this scenario.
- ✓
Deploy the NVIDIA GPU Operator with the device plugin configured to advertise MIG resources.
Why this is correct
For Kubernetes to schedule workloads onto MIG instances, the NVIDIA device plugin must advertise each MIG slice as a schedulable resource, which the GPU Operator configures via its MIG strategy setting. Without this, MIG instances exist on the GPU but are invisible to the scheduler. Enabling the device plugin to expose MIG resources is therefore a necessary action to make tenant isolation effective.
- ✓
Enable Multi-Instance GPU (MIG) mode on supported GPUs and assign separate MIG instances to each tenant.
Why this is correct
MIG partitions a supported GPU into isolated instances with dedicated memory, cache, and compute slices, providing hardware-level isolation between tenants. Assigning distinct MIG instances ensures that one tenant's workloads cannot read or write another tenant's GPU memory. This directly satisfies the isolation requirement and is a correct action for multi-tenant inference on hardware that supports MIG.
- ✗
Enable time-slicing of GPUs so that multiple tenants share the same GPU context.
Why it's wrong here
Time-slicing multiplexes workloads onto a single GPU by switching contexts, but all workloads share the same memory space and there is no hardware isolation between them. A tenant could potentially access another tenant's data in GPU memory. Because the requirement is strict memory isolation, time-slicing is the opposite of what is needed and would undermine the security objective.
About these practice questions
This NCP-AIO question is part of Courseiva's 309-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official NVIDIA exam blueprint
This NCP-AIO practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-AIO exam.