← All ACP Flashcard Decks

Security, Compliance & Vulnerability Management Flashcards

7 cards from real ACP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security, Compliance & Vulnerability Management flashcards as text
  1. Which Anaconda enterprise product provides a private, on-premise package repository with built-in security scanning?

    Answer: Anaconda Team Edition / Anaconda Business

    Anaconda Business (formerly Team Edition) and related enterprise offerings provide private, self-hosted package repositories with integrated vulnerability scanning and access controls.

  2. What does the `--no-default-packages` flag accomplish when creating a new conda environment for security-sensitive work?

    Answer: Creates the environment without the packages listed in `create_default_packages`, reducing the attack surface

    `--no-default-packages` skips installation of packages configured in `create_default_packages`, ensuring only explicitly requested packages are present and reducing unnecessary exposure.

  3. In a compliance-focused deployment, why is it important to set `channel_alias` in the conda configuration?

    Answer: To redirect all channel requests through an approved internal proxy or mirror

    `channel_alias` redirects channel lookups to an internal server, ensuring all package traffic flows through a controlled, monitored endpoint rather than the public internet.

  4. Which practice best mitigates the risk of a typosquatting attack when installing conda packages?

    Answer: Specifying the exact channel alongside the package name (e.g., `conda install -c trusted-mirror scipy`)

    Specifying the trusted channel explicitly prevents conda from resolving to a similarly-named malicious package on a lower-priority or public channel.

  5. What is the purpose of the `.condarc` `allowlist_channels` (formerly `whitelist_channels`) key?

    Answer: Restricts conda to only use the listed channels, blocking any others

    `allowlist_channels` enforces that conda will only communicate with the explicitly listed channels, preventing use of unauthorized or potentially malicious package sources.

  6. When auditing a production conda environment for compliance, which approach provides the most complete record of installed package provenance?

    Answer: Running `conda list --export` and storing the output with build strings and channel URLs

    `conda list --export` outputs exact package names, versions, build strings, and channel URLs, providing full provenance information needed for compliance documentation.

  7. Which security principle is best enforced by using separate conda environments for each project rather than a single shared environment?

    Answer: Principle of least privilege / isolation

    Separate environments enforce isolation and least privilege: a vulnerability or compromised package in one project environment cannot affect others, limiting blast radius.