Security and Access Control Flashcards
7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Access Control flashcards as text
Which Keystone token format is the default in modern OpenStack deployments and does not require a persistent backend for validation?
Answer: Fernet tokens
Fernet tokens are the default in modern OpenStack; they are encrypted, self-contained, and require no token persistence in the backend.
An operator wants to restrict a user so they can only manage resources within a single OpenStack project without accessing any other projects. Which Keystone concept enforces this boundary?
Answer: Scope
Token scope in Keystone restricts what a user can access; a project-scoped token limits actions to that specific project.
Which command lists all roles currently assigned to a user within a specific project?
Answer: openstack role assignment list --user --project
The `openstack role assignment list` command with `--user` and `--project` filters shows role assignments for that user-project combination.
In OpenStack, which security group rule direction controls traffic coming INTO a virtual machine instance?
Answer: Ingress
Ingress rules control traffic entering the instance; egress rules control traffic leaving the instance.
What is the purpose of the `barbican` service in OpenStack?
Answer: Provides key management and secrets storage
Barbican is OpenStack's Key Manager service, used to securely store secrets such as encryption keys, certificates, and passwords.
Which Keystone policy.json rule keyword is used to define a condition that ALWAYS grants access regardless of the requester?
Answer: "@"
The `"@"` rule in Keystone policy files means the action is always allowed with no conditions evaluated.
An administrator needs to allow SSH access (port 22) to instances in the 'web' security group only from a specific subnet 10.0.1.0/24. Which command achieves this?
Answer: openstack security group rule create web --protocol tcp --dst-port 22 --remote-ip 10.0.1.0/24
The `openstack security group rule create` command with `--protocol`, `--dst-port`, and `--remote-ip` correctly creates an ingress TCP rule from a specific CIDR.