โ† All ACP Flashcard Decks

Security, Compliance & Vulnerability Management Flashcards

7 cards from real ACP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security, Compliance & Vulnerability Management flashcards as text
  1. Which conda command verifies the integrity of downloaded packages using cryptographic checksums?

    Answer: conda verify

    `conda verify` checks package archives and installed packages against their expected checksums and metadata to detect tampering or corruption.

  2. What is the role of package signing in Anaconda's security model?

    Answer: It cryptographically authenticates that packages come from a trusted publisher

    Package signing uses cryptographic signatures (e.g., GPG or sigstore) to allow clients to verify that a package was produced and published by a trusted entity without modification.

  3. In Anaconda's role-based access control (RBAC), which role typically has permission to publish packages to a private channel?

    Answer: Contributor or higher (e.g., Owner)

    In Anaconda's RBAC model, Contributor or Owner roles have the necessary permissions to upload and publish packages to private organizational channels.

  4. Which Anaconda feature allows administrators to audit which users installed or updated packages in a shared enterprise environment?

    Answer: Anaconda Nucleus activity logs

    Anaconda Nucleus and enterprise repository solutions maintain activity logs that record user actions such as package installs and updates for compliance auditing.

  5. What is the recommended practice to prevent supply chain attacks when using conda?

    Answer: Pin package versions and restrict channels to trusted internal mirrors

    Pinning exact package versions and sourcing only from vetted internal mirrors reduces the risk of a malicious package being silently introduced into the environment.

  6. Which file in a conda environment records the exact package versions and build strings for full reproducibility and security auditing?

    Answer: conda-lock.yml

    `conda-lock.yml` captures exact package versions, build strings, and hashes, making it the authoritative lockfile for both reproducibility and security auditing.

  7. When configuring a conda channel with `channel_priority: strict`, what is the security benefit?

    Answer: It ensures packages are only resolved from the highest-priority channel, avoiding accidental use of untrusted channels

    With `channel_priority: strict`, conda resolves packages exclusively from the first matching channel in the priority list, preventing lower-priority (potentially untrusted) channels from supplying packages.