Security and Access Control Flashcards
6 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Security and Access Control flashcards as text
Which OpenStack service handles authentication and authorization?
Answer: Keystone
Keystone is the central identity service for OpenStack, responsible for managing user authentication and authorization across all services. It verifies user credentials and determines what resources and actions a user is permitted to access based on their assigned roles and projects.
What are OpenStack roles used for?
Answer: Control user permissions
In OpenStack, roles are used to define a set of permissions that can be assigned to users within specific projects (tenants). By assigning roles, administrators can control what actions users are authorized to perform and what resources they can access, implementing granular access control.
What is the purpose of security groups in OpenStack?
Answer: Control network access
Security groups in OpenStack act as virtual firewalls for instances, controlling inbound and outbound network traffic. They define rules that specify which ports, protocols, and IP addresses are allowed to communicate with an instance, enhancing network security by filtering unwanted connections.
How can you prevent unauthorized API access in OpenStack?
Answer: Require Keystone authentication
Keystone is the identity service that authenticates all API requests to OpenStack services. By requiring Keystone authentication, every interaction with the OpenStack API must be accompanied by a valid token issued by Keystone, ensuring that only authorized users or services can access and manipulate cloud resources.
Which component is used to assign user roles in OpenStack?
Answer: Keystone
Keystone is OpenStack's identity service, responsible for providing authentication and authorization for all OpenStack components. It manages users, projects (tenants), and roles, making it the central component for assigning and controlling user access and permissions within the cloud environment.
What is a project in OpenStack security context?
Answer: An isolated group for user access and resources
In OpenStack, a project (also known as a tenant) serves as a fundamental unit for organizing and isolating resources. It provides a secure container where users can deploy and manage their virtual machines, networks, and storage, ensuring that resources and access are segregated from other projects. This isolation is crucial for multi-tenant cloud environments.