โ† All COA Flashcard Decks

Troubleshooting & Problem Resolution Flashcards

7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Troubleshooting & Problem Resolution flashcards as text
  1. An instance is in 'ACTIVE' state but the user reports it is unreachable over SSH. The security group allows port 22. What should you check next?

    Answer: Check iptables/nftables rules on the compute node for the instance's tap interface

    When security groups look correct, the next step is verifying that iptables rules on the compute node's tap interface correctly implement those security group rules.

  2. A newly deployed Heat stack fails because a Neutron router cannot be attached to an external network. The error is 'External network not found'. What should you verify?

    Answer: The external network has 'router:external' set to True by an admin

    Only networks with the 'router:external' attribute set to True (by an admin) can be used as external gateways for routers.

  3. During a rolling upgrade, some Nova API calls return HTTP 400 with 'microversion not supported'. What causes this and how is it fixed?

    Answer: The client is requesting a microversion higher than what the older Nova API node supports during the mixed-version window

    During a rolling upgrade, old and new Nova API nodes coexist; clients requesting microversions only available in the new version will get 400 from the old node.

  4. The 'openstack token issue' command fails with 'Connection refused' even though Keystone is running. What is the most likely cause?

    Answer: The OS_AUTH_URL environment variable points to an incorrect endpoint or port

    'Connection refused' (not 401 Unauthorized) means the client cannot reach the endpoint at all, pointing to an incorrect URL or firewall blocking the port.

  5. A Barbican secret cannot be retrieved by a Nova instance via the metadata API. The instance uses a config-drive. What is the most likely misconfiguration?

    Answer: The instance's Barbican consumer ACL does not include the Nova service user

    Barbican secrets require explicit ACL entries granting read access to the requesting service user; Nova needs to be in the secret's consumer ACL to retrieve it on behalf of an instance.

  6. After adding a new compute node, instances are still not being scheduled there despite available resources. Which Nova configuration must be verified on the new node?

    Answer: The nova-compute service is running and the host is enabled in 'openstack compute service list'

    A new compute node must have nova-compute running and appear as 'enabled' and 'up' in the compute service list before the scheduler will use it.

  7. An operator receives alerts that the Placement service is returning 404 for resource provider queries. After verifying the service is running, what is the next diagnostic step?

    Answer: Run 'openstack resource provider list' and check for missing or orphaned providers

    'openstack resource provider list' reveals whether compute nodes have successfully registered their resource providers with Placement, identifying missing registrations.