Security & Access Management Flashcards
7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Access Management flashcards as text
Which Keystone token format is the default in modern OpenStack deployments and does not require a persistence backend?
Answer: Fernet tokens
Fernet tokens are lightweight, non-persistent tokens that use symmetric encryption and require no database storage.
An administrator needs to restrict a user so they can only manage resources within a single project. Which Keystone concept enforces this boundary?
Answer: Scope
Token scope in Keystone limits the user's effective permissions to a specific project, domain, or system.
Which command lists all role assignments for a specific user across all projects?
Answer: openstack role assignment list --user
The 'openstack role assignment list --user ' command shows all role assignments for a given user.
In OpenStack, what is the purpose of the 'default' domain in Keystone?
Answer: It is used for backward compatibility with v2 API users and projects
The default domain provides backward compatibility for OpenStack Identity v2 API clients that are unaware of domains.
A security audit requires that all OpenStack API calls be logged with user identity details. Which service should be configured to meet this requirement?
Answer: Keystone audit middleware (cadf)
Keystone's CADF (Cloud Audit Data Federation) audit middleware logs all API requests with identity context.
Which command would you use to prevent a compromised user's existing tokens from being used?
Answer: openstack user disable
Disabling a user in Keystone invalidates all of their existing tokens immediately.
What is the function of the Keystone credential store?
Answer: Stores EC2-style access key pairs and other user credentials
Keystone's credential store holds EC2-compatible access/secret key pairs and similar per-user credentials.