Security, Compliance & Vulnerability Management Flashcards
7 cards from real ACP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security, Compliance & Vulnerability Management flashcards as text
Which command is used to scan a conda environment for known security vulnerabilities?
Answer: conda audit
`conda audit` is the built-in Anaconda tool that scans packages in an environment against known CVE databases.
What does CVE stand for in the context of Anaconda security scanning?
Answer: Common Vulnerabilities and Exposures
CVE stands for Common Vulnerabilities and Exposures, the industry-standard identifier for publicly known security flaws.
In Anaconda Enterprise, which feature restricts users to installing packages only from approved internal channels?
Answer: Package allowlisting via channel configuration
Package allowlisting via channel configuration ensures only vetted, approved packages from internal mirrors can be installed, enforcing compliance.
Which file format does `conda audit` primarily reference to identify vulnerable package versions?
Answer: NIST NVD / OSV database feeds
`conda audit` queries vulnerability databases such as the NIST National Vulnerability Database (NVD) and OSV to match installed packages against known CVEs.
What is the purpose of setting the `ssl_verify` configuration option in conda?
Answer: Verifies SSL certificates when connecting to package repositories
`ssl_verify` controls whether conda validates the SSL/TLS certificate of remote channels, preventing man-in-the-middle attacks during downloads.
Which conda configuration setting allows an organization to mirror Anaconda's default channel on a private server for security compliance?
Answer: default_channels
The `default_channels` setting can be overridden to point to an internal mirror, so all package requests go through a controlled, audited repository.
When running `conda audit` on an environment, what output indicates that a package has a critical severity vulnerability?
Answer: A CRITICAL severity tag with the associated CVE ID
`conda audit` outputs vulnerability entries with severity labels (LOW, MEDIUM, HIGH, CRITICAL) alongside the CVE identifier for traceability.