You need verifiable node identity and integrity, nodes must not be internet-accessible, and you want low operational overhead following Google best practices. Which GKE deployment should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy a private autopilot cluster..
Why this is the answer
A private Autopilot cluster is the best choice because it meets all requirements. Private clusters ensure nodes are not internet-accessible by removing external IP addresses and using private IP ranges. Autopilot clusters offer low operational overhead as Google manages the underlying infrastructure, including node provisioning and scaling. Autopilot also inherently uses Shielded GKE Nodes, providing verifiable node identity and integrity through features like secure boot and integrity monitoring. A public Autopilot cluster is incorrect because its nodes would be internet-accessible. Standard public and private clusters require more operational overhead for node management, and while enabling shielded nodes addresses identity and integrity, it doesn't meet the low operational overhead requirement as effectively as Autopilot.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed