
合格できるSAP SAP Certified Development Associate - Side-by-Side Extensibility based on SAP BTP, Kyma runtime試験最速合格保証最近更新されたFast2test問題集!
合格できるC_KYMD_01試験の62問題で最適なFast2test出題問題
質問 # 10
What are some characteristics of Kubernetes pods? Note: There are 2 correct Answers to this question.
- A. They can contain deployments.
- B. They are the smallest deployable unit in Kubernetes.
- C. They are permanent units in Kubernetes.
- D. They can be terminated and replaced anytime.
正解:B、D
質問 # 11
What happens when you delete a pod managed by a Replica Set?
- A. The pod is deleted until the redeployment of the Replica Set.
- B. The Replica Set will schedule a new pod.
- C. The Replica Set is deleted as well.
正解:B
解説:
Explanation
When you delete a pod managed by a Replica Set, the Replica Set will schedule a new pod to replace the deleted one. This is because the Replica Set's purpose is to maintain a stable set of replica pods running at any given time. As such, it is often used to guarantee the availability of a specified number of identical pods1. The Replica Set controller monitors the number of pods it owns and creates or deletes pods as needed to reach the desired number. The Replica Set identifies its pods by using a selector that matches the pods' labels2. Therefore, deleting a pod will reduce the number of pods that match the selector, and trigger the Replica Set to create a new pod with the same pod template3.
References:
1: ReplicaSet | Kubernetes
2: Labels and Selectors | Kubernetes
3: Pods, Deployments and Replica Sets: Kubernetes Resources Explained
質問 # 12
Which of the following elements are part of the open-source Kyma project, but not of SAP BTP, Kyma runtime?
Note: There are 2 correct Answers to this question.
- A. Kiali
- B. Jaeger
- C. Istio
- D. Prometheus
正解:A、B
解説:
Explanation
Jaeger and Kiali are part of the open-source Kyma project, but not of SAP BTP, Kyma runtime. Jaeger is a distributed tracing system that provides end-to-end visibility into the performance and behavior of microservices. Kiali is a service mesh observability and configuration tool that provides a graphical view of the topology and health of the services in the mesh. SAP BTP, Kyma runtime does not include these components, but instead relieson SAP BTP Application Logging and SAP BTP Application Monitoring services for observability and tracing. Prometheus and Istio, on the other hand, are both part of the open-source Kyma project and SAP BTP, Kyma runtime. Prometheus is a monitoring system that collects metrics from various sources and stores them in a time-series database. Istio is a service mesh that provides a uniform way to connect, secure, control, and observe services. References:
https://learning.sap.com/learning-journey/deliver-side-by-side-extensibility-based-on-sap-btp-kyma-runtime
https://www.credly.com/org/sap/badge/sap-certified-development-associate-side-by-side-ex
質問 # 13
What is a characteristic of Kubernetes pods managed by deployments?
- A. They have a stable name.
- B. They are stateful.
- C. They are assigned a random hash suffix as part of their name.
正解:C
解説:
Explanation
Kubernetes pods are the smallest and most basic unit of an application in Kubernetes. They are ephemeral and can be created and destroyed at any time. Pods managed by deployments are not meant to be accessed directly, but rather through services that provide load balancing and service discovery. To ensure that pods managed by deployments are unique and identifiable, they are assigned a random hash suffix as part oftheir name. For example, a pod named nginx-deployment-6dd86d77d-ztqvs belongs to a deployment named nginx-deployment and has a hash suffix of 6dd86d77d-ztqvs12. References: Deployments | Kubernetes, Kubernetes Administrator: Managing Pods & Deployments
質問 # 14
What happens when you delete a pod managed by a Replica Set?
- A. The pod is deleted until the redeployment of the Replica Set.
- B. The Replica Set will schedule a new pod.
- C. The Replica Set is deleted as well.
正解:B
質問 # 15
What are some benefits of using the Istio service mesh in SAP BTP, Kyma runtime? Note: There are 3 correct Answers to this question.
- A. Traffic management between services can be controlled.
- B. Mutual TLS is supported for service to service communication.
- C. Networking is coupled to the application logic.
- D. Networking is decoupled from the application logic.
- E. Distributed tracing can be used to trace request flows.
正解:A、B、D
解説:
Explanation
Istio is a service mesh that provides a uniform way to secure, connect, and monitor microservices running on different platforms and environments1. SAP BTP, Kyma runtime uses Istio as the default service mesh solution to enable the following benefits2:
Networking is decoupled from the application logic. Istio handles the network traffic between services using a data plane composed of Envoy proxies that are injected as sidecars to each service Pod. This way, the application code does not need to deal with networking aspects such as routing, load balancing, authentication, or encryption3.
Mutual TLS is supported for service to service communication. Istio enables mutual TLS (mTLS) by default for all services in the mesh, ensuring that the traffic is encrypted and authenticated. Istio also manages the certificates and keys for mTLS using a control plane component called Istiod4.
Traffic management between services can be controlled. Istio allows defining and applying traffic policies, such as timeouts, retries, circuit breakers, fault injection, mirroring, or routing rules, using custom resources such as VirtualServices and DestinationRules. These policies can be dynamically configured and updated without requiring service restarts.
References:
1: Discovering Istio - SAP Learning
2: Upcoming breaking change in SAP BTP, Kyma Runtime: Enabling the Istio CNI plugin | SAP Blogs
3: Istio / The Istio service mesh
4: Istio / Secure your service mesh
[5]: Istio / Traffic management overview
質問 # 16
Which kubectl command updates objects?
- A. apply -f <filename>.yaml
- B. create - <filename> yam
- C. kustomize <filename> yaml
正解:A
解説:
Explanation
Use kubectl apply to create or update resources from a file or stdin. This command does a three-way diff between the previous configuration, the input configuration, and the current configuration of the resource, and then applies the changes.
Use kubectl patch to update Kubernetes API objects in place. Do a strategic merge patch or a JSON merge patch.
Use kubectl replace to delete and re-create the resource. You can use this command to update immutable fields of a resource, such as its kind or name.
References:
Manage Kubernetes Objects
Command line tool (kubectl)
kubectl Quick Reference
質問 # 17
Which of the following are parts of the architecture of the SAP BTP Service Operator for Kubernetes? Note: There are 2 correct Answers to this question.
- A. Service broker
- B. kubelet
- C. Storage system
- D. API server
正解:A、D
質問 # 18
What are some characteristics of stateless workloads? Note: There are 2 correct Answers to this question.
- A. No data is persisted.
- B. Data is shared.
- C. No references to past transactions are stored.
- D. References to past transactions are stored.
正解:A、C
解説:
Explanation
Stateless workloads are workloads that do not store any data or application state on the host that serves the requests. Instead, they rely on the information provided by the client or an external service, such as a database, to process each request independently. Stateless workloads do not keep any references to past transactions or interactions, and they can be handled by any available server. Stateless workloads are more scalable, fault-tolerant, and easier to manage than stateful workloads, which require persistent storage and session management. Some examples of stateless workloads are web servers, print servers, or microservices. References: Stateful vs stateless - Red Hat, Create stateless workloads | Google Distributed Cloud Hosted - Google Cloud, Stateless vs Stateful Kubernetes - WEKA
質問 # 19
When would you use kubect!? Note: There are 3 correct Answers to this question.
- A. To forward ports from remote machines to pods
- B. To run interactive commands
- C. To deploy containers into production clusters
- D. To plot time series data
- E. To view pod logs
正解:B、C、E
質問 # 20
What must you do to pull a container image from a private registry? Note: There are 2 correct Answers to this question.
- A. Create a secret with the type "kubernetes.io/docker configjson".
- B. Provide credentials in the pod manifest via "image Pull Secrets" in spec. template. spec.
- C. Create a secret with the type "Opaque"
- D. Provide credentials in the pod manifest via image Pull Secrets" in "spec template metadata annotations"
正解:A、B
解説:
Explanation
To pull a container image from a private registry, you need to create a secret with the type
"kubernetes.io/dockerconfigjson" and provide the credentials in the pod manifest via "imagePullSecrets" in spec.template.spec. This way, the kubelet can use the secret to authenticate with the private registry and pull the image. The secret type "Opaque" is not suitable for this purpose, as it is a generic type that can store any data. The pod manifest does not support providing credentials via "imagePullSecrets" in spec.template.metadata.annotations, as this is not a valid field. References: Side-by-Side Extensibility Based on SAP BTP, Kyma Runtime - Unit 3 - Lesson 2: Using Secrets, [Kubernetes Documentation - Pull an Image from a Private Registry]
質問 # 21
What does a service mesh in Kyma typically consist of? Note: There are 2 correct Answers to this question.
- A. Worker node
- B. Control plane
- C. Data plane
- D. Master node
正解:B、C
解説:
Explanation
A service mesh in Kyma typically consists of two components: the data plane and the control plane12. The data plane is responsible for handling the communication between the microservices in the cluster. It consists of a set of sidecar proxies (Envoy) that are injected into each pod and intercept the traffic. The control plane is responsible for managing the configuration and policies of the data plane. It consists of a set of components (Istio) that provide features like service discovery, security, traffic management, observability, and more12. References: Discovering the Service Mesh, SAP BTP - KYMA - SERVICE MESH | SAP Blogs
質問 # 22
When do you use a Daemon Set as the main workload type?
- A. To run multiple instances of the same container
- B. To run a workload on every node in the cluster
- C. To run a batch job
正解:B
質問 # 23
What must you do to pull a container image from a private registry? Note: There are 2 correct Answers to this question.
- A. Create a secret with the type "kubernetes.io/docker configjson".
- B. Provide credentials in the pod manifest via "image Pull Secrets" in spec. template. spec.
- C. Create a secret with the type "Opaque"
- D. Provide credentials in the pod manifest via image Pull Secrets" in "spec template metadata annotations"
正解:A、B
質問 # 24
What are some characteristics of the API Gateway? Note: There are 2 correct Answers to this question.
- A. It uses a custom-configured Nginx Ingress Gateway.
- B. It uses Ory Oath keeper to manage access to services.
- C. It is the central point of contact for all internal traffic in the Kyma cluster.
- D. It uses Envoy Proxy to handle traffic and forward it to the correct service
正解:C、D
質問 # 25
What is used to isolate groups of resources in a Kubernetes cluster?
- A. Object groups
- B. Semantic versioning
- C. Organizations and spaces
- D. Namespaces
正解:D
質問 # 26
Where are Kubernetes objects persisted?
- A. The row store
- B. The column store
- C. The key value store
- D. The etod key-value store
正解:D
質問 # 27
Which open-source tool does the SAP BTP use to provision SAP BTP, Kyma runtime?
- A. Nomad
- B. Gardener
- C. Apache Mesos
- D. Rancher
正解:B
質問 # 28
You have deployed a workload through a Kubernetes Deployment to SAP BTP, Kyma runtime. What must you do to expose the workload to the public internet? Note: There are 3 correct Answers to this question.
- A. Add a custom Virtual Service CR to secure the service.
- B. Add a readiness probe for your workload.
- C. Create a service to group your pods.
- D. Create an API Rule CR.
- E. Configure rules and access Strategies.
正解:C、D、E
解説:
Explanation
To expose a workload to the public internet, you need to create a service to group your pods, create an API Rule CR to define the host, path, and access strategies for your service, and configure rules and access strategies to secure your service with authentication and authorization mechanisms. A readiness probe is optional and used to check if your workload is ready to serve traffic. A custom Virtual Service CR is not required, as the API Rule CR creates one automatically. References: https://blogs.sap.com/2021/11/22/hardening-access-to-sap-kyma-runtime-apis-with-jw
https://blogs.sap.com/2023/10/18/sap-btp-kyma-api-rules-with-destinations-and-a-managed-approuter./
質問 # 29
Which kubectl command updates objects?
- A. apply -f <filename>.yaml
- B. create - <filename> yam
- C. kustomize <filename> yaml
正解:A
質問 # 30
Which proxy pattern is used by the service mesh solution in SAP BTP, Kyma runtime?
- A. Shared library
- B. Per-Container
- C. Per-Node
- D. Sidecar
正解:D
質問 # 31
Which proxy pattern is used by the service mesh solution in SAP BTP, Kyma runtime?
- A. Shared library
- B. Per-Container
- C. Per-Node
- D. Sidecar
正解:D
解説:
Explanation
The service mesh solution in SAP BTP, Kyma runtime is based on Istio, which is one of the most popular service mesh solutions. Istio uses the Sidecar proxy pattern, which means that a proxy is deployed as a sidecar container next to each service. This way, the proxy can intercept and manage the traffic between the services, without requiring any changes in the application code. The proxy also communicates with the Istio control plane, whichprovides configuration and policies for the service mesh. The other options are not valid proxy patterns for the service mesh solution in SAP BTP, Kyma runtime. References: Discovering the Service Mesh
- SAP Learning, Istio Documentation - What is Istio?
質問 # 32
If an application requires a persistent state between reboots, what must be done before it can be deployed?
- A. Create a Persistent Volume Claim for a pod.
- B. Create a Persistent Volume in the namespace
- C. Create a new entry in etcd.
正解:A
解説:
Explanation
A Persistent Volume Claim (PVC) is a request for storage by a user. It is similar to a Pod, which is a request for compute resources by a user. A PVC enables a Pod to consume a slice of the available storage in the cluster without knowing the details of the underlying storage infrastructure. A PVC is associated with a StorageClass, which defines the type and characteristics of the storage. A PVC is also bound to a Persistent Volume (PV), which is an abstraction of the physical or cloud-based storage resource. A PV is created by the cluster administrator and has a lifecycle independent of any Pod. A PVC can specify the size, access mode, and storage class of the PV it requires. Before deploying an application that needs persistent state, a user must create a PVC for the Pod that will run the application. The PVC will then be automatically bound to a suitable PV by the cluster, or dynamically provisioned if the storage class supports it. The Pod can then mount the PVC as a volumeand access the persistent storage12345. References: Persistent Volumes | Kubernetes, How Kubernetes Persistent Volume Claims Work - CBT Nuggets, Exploring Kubernetes Storage: Persistent Volumes and Persistent Volume Claims - Atatus, Configure a Pod to Use a PersistentVolume for Storage | Kubernetes, kubernetes - How to mount a persistent volume on a Deployment/Pod using PersistentVolumeClaim? - Stack Overflow.
質問 # 33
What does a service mesh in Kyma typically consist of? Note: There are 2 correct Answers to this question.
- A. Worker node
- B. Control plane
- C. Data plane
- D. Master node
正解:B、C
解説:
Explanation
A service mesh in Kyma typically consists of two components: the data plane and the control plane12. The data plane is responsible for handling the communication between the microservices in the cluster. It consists of a set of sidecar proxies (Envoy) that are injected into each pod and intercept the traffic. The control plane is responsible for managing the configuration and policies of the data plane. It consists of a set of components (Istio) that provide features like service discovery, security, traffic management, observability, and more12. References: Discovering the Service Mesh, SAP BTP - KYMA - SERVICE MESH | SAP Blogs
質問 # 34
Which service does the SAP BTP service operator on SAP BTP, Kyma runtime use to consume services on SAP BTP?
- A. SAP Service Marketplace
- B. SAP Service Manager
- C. SAP API Business Hub
正解:B
解説:
Explanation
The SAP BTP service operator on SAP BTP, Kyma runtime uses the SAP Service Manager to consume services on SAP BTP. The SAP Service Manager is a component that provides a unified way of provisioning, accessing, and managing services from different providers and platforms. The SAP Service Manager implements the Open Service Broker API (OSB API) to communicate with service brokers and expose their services to applications. The SAP BTP service operator on SAP BTP, Kyma runtime leverages the SAP Service Manager to create and manage service instances and bindings for SAP BTP services in the Kyma cluster. The SAP BTP service operator also synchronizes the service catalog from the SAP Service Manager to the Kyma Service Catalog, so that users can discover and consume SAP BTP services through the Kyma Console or the Kubernetes API. References: https://learning.sap.com/learning-journey/deliver-side-by-side-extensibility-based-on-sap-btp-k
https://blogs.sap.com/2022/07/12/the-new-way-to-consume-service-bindings-on-kyma-runtime/
質問 # 35
......
合格突破受験者シミュレーションされたC_KYMD_01試験問題集:https://jp.fast2test.com/C_KYMD_01-premium-file.html