Courseiva
Administration →hardMultiple Choice

NCP-AIO Administration Practice Question

Exhibit

{ "policy": "deny", "resources": ["/dev/nvidia*"], "action": "restrict_access" }

Refer to the exhibit. An administrator applies this security policy to a container runtime environment. What is the immediate effect on containerized AI applications within this scope?

⚠ Common exam trap

Candidates often assume that security policies only affect network traffic or file system access, overlooking that blocking character device nodes directly breaks the CUDA runtime's ability to initialize hardware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The container is unable to detect or communicate with the NVIDIA GPU

The policy explicitly denies access to the character device files associated with the NVIDIA GPU. Without access to /dev/nvidia0, /dev/nvidiactl, and /dev/nvidia-uvm, the CUDA runtime cannot interact with the GPU hardware. Consequently, any attempt to initialize a CUDA device will fail, causing the application to crash. This policy is a common restrictive measure in high-security environments where GPU access must be strictly managed or audited.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The container gains elevated privileges to access the host GPU

    Why it's wrong here

    Access to device files does not confer elevated privileges; it simply provides the required interface for the driver library to communicate with the hardware. Restricting these files prevents the container from seeing or using the GPU at all, which is the opposite of providing elevated access or permissions.

  • ✓

    The container is unable to detect or communicate with the NVIDIA GPU

    Why this is correct

    The NVIDIA driver requires access to specific device nodes under /dev/nvidia* to function. By denying access to these files, the runtime prevents the container's CUDA libraries from establishing a connection to the GPU driver, rendering the GPU invisible to the application code executing inside the container environment.

  • ✗

    The container can use the GPU but cannot perform memory mapping

    Why it's wrong here

    GPU communication is binary; the driver either successfully initializes the device or it does not. There is no partial state where a container can use the GPU for logic but fail at memory mapping. If the device nodes are blocked, the entire interface is rendered completely unusable.

  • ✗

    The container experiences increased latency for GPU operations

    Why it's wrong here

    Latency is a measure of performance degradation, not a binary access control outcome. If the policy denies access to the hardware devices, the application will not experience latency; it will encounter a catastrophic failure or segmentation fault immediately upon attempting to query the GPU device drivers.

About these practice questions

Courseiva writes every NCP-AIO question from scratch — 309 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCP-AIO practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-AIO exam.