โ† All PCA Flashcard Decks

PCA Security & Authentication Flashcards

6 cards from real PCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 PCA Security & Authentication flashcards as text
  1. What Kubernetes RBAC resource does a Prometheus service account typically need to perform pod-level service discovery?

    Answer: ClusterRole with get/list/watch on pods, endpoints, and nodes

    Prometheus needs a ClusterRole granting get, list, and watch permissions on pods, services, endpoints, and nodes to perform Kubernetes service discovery.

  2. How does Prometheus handle a bearer token stored in a file for scrape authentication?

    Answer: It reads the token file on each scrape, automatically picking up rotated tokens

    Using bearer_token_file, Prometheus re-reads the token on each scrape interval, supporting dynamic token rotation without restarts.

  3. What is the security benefit of using Prometheus's `--storage.tsdb.no-lockfile` flag in specific deployments?

    Answer: It allows multiple read-only Prometheus instances to share the same TSDB directory safely

    Disabling the lockfile allows secondary read-only replicas (like Thanos sidecars) to open the same TSDB without write conflicts.

  4. Which approach is recommended for securing Prometheus in a production Kubernetes environment when native auth is insufficient?

    Answer: Place Prometheus behind a reverse proxy like nginx or oauth2-proxy that handles authentication

    A reverse proxy (e.g., oauth2-proxy or nginx with auth) provides richer authentication options in front of Prometheus without modifying its binary.

  5. What is a potential security concern with Prometheus's `/api/v1/admin/tsdb/delete_series` endpoint?

    Answer: It allows any unauthenticated caller to permanently delete metric data if the admin API is not protected

    The admin API delete endpoint can irreversibly remove series data, so it must be protected by auth or network controls since Prometheus has no built-in access control by default.

  6. Which flag must be explicitly enabled to allow the Prometheus admin HTTP API (e.g., snapshot, delete_series) to function?

    Answer: --web.enable-admin-api

    Admin API endpoints are disabled by default and require the --web.enable-admin-api flag to be set when starting Prometheus.