โ† All COA Flashcard Decks

Security & Access Management Flashcards

7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. Which command creates an application credential that a user's application can use to authenticate without exposing the user's password?

    Answer: openstack application credential create

    Application credentials are created with 'openstack application credential create' and allow applications to authenticate with limited, revocable tokens.

  2. In OpenStack Identity v3, which endpoint interface is intended for end users to interact with services?

    Answer: public

    The 'public' endpoint interface is exposed to end users, while 'internal' is for inter-service communication and 'admin' is for administrative operations.

  3. A cloud operator needs to ensure that all object storage data at rest is encrypted. Which Swift configuration enables this?

    Answer: Swift encryption middleware (keymaster + encrypter)

    Swift's encryption middleware pipeline (keymaster for key derivation + encrypter for data encryption) provides transparent at-rest encryption.

  4. Which policy rule syntax element in OpenStack policy files is used to check if the requester is the owner of the resource?

    Answer: user_id:%(user_id)s

    The 'user_id:%(user_id)s' rule checks that the authenticated user's ID matches the resource's user_id attribute.

  5. An administrator wants to prevent users from assigning roles that exceed their own role level. Which Keystone feature enforces this?

    Answer: Implied roles (role inference)

    Role inference rules define that assigning one role automatically implies another, and can prevent privilege escalation by controlling role hierarchies.

  6. What is the recommended way to grant a Heat stack the permissions it needs to create resources without storing user credentials in the template?

    Answer: Use a Keystone trust so Heat can act on behalf of the stack owner

    Heat uses Keystone trusts to perform API calls on the stack owner's behalf, eliminating the need to store credentials.

  7. Which command verifies that the Keystone endpoint catalog contains correct entries for a specific service?

    Answer: openstack endpoint list --service

    The 'openstack endpoint list --service ' command filters the endpoint catalog to show only entries for the specified service.