โ† All COA Flashcard Decks

Security and Access Control Flashcards

7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Access Control flashcards as text
  1. Which OpenStack service is responsible for auditing and tracking API calls for compliance and security investigation purposes?

    Answer: CADF middleware (PyCADF)

    PyCADF (Cloud Audit Data Federation) middleware generates CADF-compliant audit events for OpenStack API calls.

  2. A security engineer wants to ensure that all data stored in Swift object storage is encrypted at rest. Which Swift feature handles server-side encryption?

    Answer: Swift encryption middleware

    Swift's encryption middleware encrypts object data and metadata at rest before writing to disk using keys from Barbican.

  3. In Keystone, what is a 'domain' primarily used for in multi-tenant environments?

    Answer: An administrative boundary grouping users and projects

    Keystone domains provide administrative boundaries that contain users, groups, and projects, enabling multi-tenant identity management.

  4. Which command would a cloud administrator use to create a new Keystone domain named 'engineering'?

    Answer: openstack domain create engineering

    The `openstack domain create ` command creates a new Keystone domain.

  5. What is the risk of using 'admin' as a role name in legacy OpenStack policy files with the 'is_admin_project' option disabled?

    Answer: Users with admin role in any project gain cloud-wide administrative privileges

    Without `is_admin_project` enforcement, having the 'admin' role in any project may grant cloud-wide admin access due to legacy policy rules.

  6. Which Nova feature allows an administrator to isolate specific compute hosts so that only designated tenants can schedule instances on them?

    Answer: Host aggregates with metadata filters

    Host aggregates with AggregateInstanceExtraSpecsFilter allow administrators to restrict instance scheduling to specific hosts based on tenant metadata.

  7. An operator discovers that a Keystone service account token has been compromised. What is the FASTEST way to immediately invalidate all tokens for that user?

    Answer: Revoke the user's tokens with openstack user set --disable

    Disabling the user with `openstack user set --disable` immediately prevents new authentications and causes existing tokens to be rejected at validation.

Security and Access Control Flashcards โ€” COA Study Cards with Answers