Security & Access Management Flashcards
7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Access Management flashcards as text
Which Nova policy action controls whether a user can list all instances across all tenants (not just their own)?
Answer: os_compute_api:servers:detail:get_all_tenants
The 'get_all_tenants' policy governs whether a user can retrieve server listings belonging to all projects.
An operator wants to enforce that only specific CIDR ranges can be used in security group rules. Which OpenStack feature can enforce network-level access policies?
Answer: Neutron RBAC policies
Neutron RBAC (Role-Based Access Control) policies control which projects can access shared networks and resources.
In Barbican, what is a 'Secret Container' used for?
Answer: Grouping related secrets such as a certificate, private key, and intermediates together
A Barbican secret container logically groups related secrets (e.g., TLS cert + private key + CA chain) under a single reference.
Which mechanism does Keystone use to federate identity with an external SAML-based Identity Provider?
Answer: Federated identity mapping rules
Keystone federation uses mapping rules to translate assertions from external IdPs into local Keystone groups and roles.
A project has a security group rule allowing all TCP traffic from 0.0.0.0/0. Which command removes only that specific rule?
Answer: openstack security group rule delete
The 'openstack security group rule delete ' command removes a specific security group rule by its ID.
What does the 'admin' role in OpenStack grant by default, and why is it considered risky?
Answer: Full administrative access across all services system-wide; risky because it bypasses project-level isolation
The admin role provides cross-project, system-wide privileges to all services, making it a high-value target for privilege escalation.
Which Keystone feature allows a user to delegate a subset of their own permissions to another user or service without sharing credentials?
Answer: Trust delegation
Keystone trusts allow a trustor to delegate a subset of roles to a trustee, enabling secure permission delegation.