Security & Access Control Flashcards
9 cards from real CJE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 9 Security & Access Control flashcards as text
Which Jenkins feature controls who can access specific resources?
Answer: Role-Based Access Control
Role-Based Access Control (RBAC) is a crucial security feature in Jenkins that allows administrators to define granular permissions for users and groups based on their assigned roles. This enables precise control over who can access, configure, or execute specific jobs, views, or system settings, ensuring secure and compliant operations within Jenkins.
How can Jenkins secure credentials used in jobs?
Answer: Using the Credentials plugin and encrypted storage.
Jenkins secures sensitive information like passwords, API tokens, and SSH keys using the Credentials plugin, which stores them in an encrypted format. This prevents credentials from being exposed in plain text within job configurations or logs. Jobs can then reference these credentials securely without directly embedding them, enhancing overall security.
What is the purpose of the 'Matrix-based security' in Jenkins?
Answer: To assign permissions to users/groups.
Matrix-based security in Jenkins is a flexible authorization strategy that allows administrators to define specific permissions for individual users and groups across various Jenkins resources. It presents a grid-like interface where permissions (e.g., read, write, build) can be granted or revoked for different entities, providing fine-grained access control.
Which protocol can Jenkins use to encrypt web traffic?
Answer: HTTPS
Jenkins can use HTTPS (Hypertext Transfer Protocol Secure) to encrypt web traffic between the client browser and the Jenkins server. Implementing HTTPS is crucial for securing sensitive data transmitted over the network, such as login credentials, build logs, and configuration details. This protects against eavesdropping, tampering, and man-in-the-middle attacks, ensuring secure communication.
How can you restrict job execution to authorized users?
Answer: Using Role-Based Access Control.
Role-Based Access Control (RBAC) is a security mechanism that assigns permissions to users based on their roles within the system. In Jenkins, implementing RBAC allows administrators to define specific roles with granular permissions, such as the ability to build or configure jobs. This ensures that only authorized individuals can perform specific actions, thereby effectively restricting job execution.
What is CSRF protection in Jenkins?
Answer: Prevents unauthorized command execution.
CSRF (Cross-Site Request Forgery) protection in Jenkins is a crucial security measure designed to prevent malicious websites or scripts from tricking a logged-in user's browser into sending unauthorized requests to the Jenkins server. It safeguards against attackers exploiting a user's authenticated session to execute commands or make changes without their explicit consent. This helps maintain the integrity and security of the Jenkins instance.
Which plugin provides enhanced security and access control in Jenkins?
Answer: Role Strategy Plugin
The Role Strategy Plugin is widely used in Jenkins to implement fine-grained access control and enhance security. it allows administrators to define global roles, item roles (for specific jobs), and agent roles, assigning different permissions to users or groups based on these roles. This provides a robust mechanism for managing who can access and modify various parts of the Jenkins environment.
How do you enforce strong authentication in Jenkins?
Answer: Integrate with LDAP or SSO.
Integrating Jenkins with external authentication systems like LDAP (Lightweight Directory Access Protocol) or SSO (Single Sign-On) providers is the most effective way to enforce strong authentication. This allows Jenkins to leverage existing enterprise user directories and security policies, centralizing user management and often enabling features like multi-factor authentication. It enhances security by avoiding reliance solely on Jenkins's internal user database.
What is the function of API tokens in Jenkins?
Answer: Authenticate users for API access.
API tokens in Jenkins serve as a secure alternative to user passwords for authenticating programmatic access to the Jenkins API. They allow external tools, scripts, or integrations to interact with Jenkins without exposing user credentials directly. Each token is associated with a specific user and inherits their permissions, ensuring secure and controlled automation.