NCP-AIO Administration Practice Question
An administrator is responsible for an NVIDIA AI Enterprise deployment on Kubernetes. The security team requires that all GPU-accelerated pods run with the least privilege necessary and that GPU device nodes are not exposed to pods that do not request them. Which combination of configurations should the administrator implement to meet these requirements?
⚠ Common exam trap
The trap here is believing that setting the NVIDIA_VISIBLE_DEVICES environment variable alone is sufficient for GPU access in Kubernetes; in reality, the device plugin must allocate the resource via a resource request, and without it the device nodes are not mounted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the NVIDIA GPU Operator with the device plugin and configure a PodSecurityPolicy or OPA Gatekeeper policy that requires pods to request nvidia.com/gpu and forbids privileged mode.
Using the GPU Operator with the device plugin, combined with a policy that mandates explicit nvidia.com/gpu requests and prohibits privileged containers, ensures that GPU device nodes are only injected into pods that request them and that pods run with minimal privileges. This satisfies both the least privilege and isolation requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy the NVIDIA GPU Operator with the device plugin and configure a PodSecurityPolicy or OPA Gatekeeper policy that requires pods to request nvidia.com/gpu and forbids privileged mode.
Why this is correct
The GPU Operator's device plugin exposes GPUs as schedulable resources (nvidia.com/gpu). Enforcing a policy that requires pods to request this resource ensures that only pods explicitly asking for GPUs receive device nodes. Forbidding privileged mode enforces least privilege. Together, these configurations ensure GPU device nodes are not exposed to pods that do not request them and that pods run with minimal privileges.
- ✗
Use the NVIDIA GPU Operator with the device plugin and configure pod security contexts to drop all capabilities and add only the NVIDIA_VISIBLE_DEVICES environment variable.
Why it's wrong here
Dropping all capabilities is good, but adding only the NVIDIA_VISIBLE_DEVICES environment variable is insufficient for GPU access in Kubernetes. The device plugin must also allocate the GPU resource, and the pod must request nvidia.com/gpu. Without the resource request, the device plugin will not inject the necessary device nodes, so the pod cannot access the GPU even if the environment variable is set.
- ✗
Install the NVIDIA k8s-device-plugin standalone and set the --pass-device-specs flag to true, then allow all pods to run as root.
Why it's wrong here
The --pass-device-specs flag is used to pass device specifications to the container runtime, but it does not enforce least privilege or restrict GPU access to only pods that request it. Allowing all pods to run as root violates the principle of least privilege and could lead to security vulnerabilities. This approach does not meet the security team's requirements.
- ✗
Enable the NVIDIA device plugin with the --fail-on-init-error=false flag and set privileged: true in the pod security context.
Why it's wrong here
Setting privileged: true grants the pod full access to all host devices, including GPU device nodes, violating the principle of least privilege. The --fail-on-init-error flag controls plugin behavior on initialization errors, not security. This combination would expose GPU devices to all pods and grant excessive privileges, contrary to the security requirements.
About these practice questions
One of 309 original NCP-AIO practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official NVIDIA exam blueprint
This NCP-AIO practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-AIO exam.