โ† All COA Flashcard Decks

Security and Access Control Flashcards

7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security and Access Control flashcards as text
  1. What is the role of the `oslo.policy` library in OpenStack services?

    Answer: Provides a common framework for parsing and enforcing RBAC policy rules

    oslo.policy is a shared OpenStack library that provides a consistent framework for loading, parsing, and enforcing RBAC policy rules across all services.

  2. A tenant reports that their instance can communicate with other tenants' instances on the same compute node despite being in different projects. What is the MOST likely misconfiguration?

    Answer: Security group rules are too permissive (allowing all traffic)

    Overly permissive security group rules (e.g., allowing all ingress) are the most common cause of unintended inter-tenant traffic at the instance level.

  3. In OpenStack's policy engine, what does the rule `"rule:admin_or_owner"` typically evaluate?

    Answer: Whether the user is a cloud admin OR owns the resource being accessed

    The `admin_or_owner` rule grants access if the requester has the admin role OR is the owner (creator) of the resource.

  4. Which Keystone feature allows an organization to use an external Identity Provider (IdP) such as Okta or Azure AD for OpenStack authentication?

    Answer: Keystone federation with SAML2 or OIDC

    Keystone federation supports SAML2 and OpenID Connect (OIDC) protocols to authenticate users from external Identity Providers.

  5. What are 'application credentials' in Keystone and why are they preferred over user passwords for automated scripts?

    Answer: They allow services to authenticate without exposing the user's password, and can have restricted roles and expiry

    Application credentials let automated tools authenticate as a user without knowing the user's password, and can be scoped to specific roles and set to expire.

  6. Which `openstack` CLI command would you use to rotate Fernet token encryption keys while ensuring existing tokens remain valid during the transition?

    Answer: keystone-manage fernet_rotate

    The `keystone-manage fernet_rotate` command rotates Fernet keys, keeping previous keys staged so existing tokens can still be validated during the transition window.

  7. In a multi-region OpenStack deployment, which Keystone configuration ensures that a single token issued in Region A is also accepted in Region B?

    Answer: Sharing the same Fernet key repository across all regions

    Fernet tokens are cryptographically validated, so sharing the same Fernet key repository (synchronized across regions) allows tokens issued in one region to be validated in another.