Networking and Storage Configuration Flashcards
7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Networking and Storage Configuration flashcards as text
Which Neutron agent is responsible for implementing security groups on compute nodes using iptables?
Answer: neutron-openvswitch-agent
The neutron-openvswitch-agent (or linuxbridge-agent) runs on compute nodes and enforces security group rules via iptables.
What is the purpose of a Neutron floating IP?
Answer: Map a public IP to an instance's private IP via NAT
Floating IPs use NAT on the L3 agent to map an externally routable address to an instance's fixed private IP.
In Cinder, which command creates a volume from an existing bootable volume snapshot?
Answer: cinder create --snapshot-id
cinder create --snapshot-id provisions a new volume pre-populated with the snapshot's data.
Which OpenStack networking object defines allowed IP/MAC pairs on a port to prevent spoofing?
Answer: Allowed address pair
Allowed address pairs let administrators declare additional IP/MAC combinations permitted on a port beyond the primary assignment.
What Swift container ACL grants any authenticated user read access?
Answer: *:*
The ACL value *:* grants read access to any authenticated OpenStack user across all projects.
Which Neutron resource must be created before attaching a router to an external network?
Answer: External network with router:external=True
The network must be marked with router:external=True so the L3 agent recognizes it as an uplink for external connectivity.
Which Cinder volume status indicates that a volume is attached to an instance and in active use?
Answer: in-use
The 'in-use' status means the volume is currently attached to a running instance.