← All COA Flashcard Decks

Security & Access Management Flashcards

7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. Which Keystone token format is the default in modern OpenStack deployments and does not require a persistence backend?

    Answer: Fernet tokens

    Fernet tokens are lightweight, non-persistent tokens that use symmetric encryption and require no database storage.

  2. An administrator needs to restrict a user so they can only manage resources within a single project. Which Keystone concept enforces this boundary?

    Answer: Scope

    Token scope in Keystone limits the user's effective permissions to a specific project, domain, or system.

  3. Which command lists all role assignments for a specific user across all projects?

    Answer: openstack role assignment list --user

    The 'openstack role assignment list --user ' command shows all role assignments for a given user.

  4. In OpenStack, what is the purpose of the 'default' domain in Keystone?

    Answer: It is used for backward compatibility with v2 API users and projects

    The default domain provides backward compatibility for OpenStack Identity v2 API clients that are unaware of domains.

  5. A security audit requires that all OpenStack API calls be logged with user identity details. Which service should be configured to meet this requirement?

    Answer: Keystone audit middleware (cadf)

    Keystone's CADF (Cloud Audit Data Federation) audit middleware logs all API requests with identity context.

  6. Which command would you use to prevent a compromised user's existing tokens from being used?

    Answer: openstack user disable

    Disabling a user in Keystone invalidates all of their existing tokens immediately.

  7. What is the function of the Keystone credential store?

    Answer: Stores EC2-style access key pairs and other user credentials

    Keystone's credential store holds EC2-compatible access/secret key pairs and similar per-user credentials.