Security & Access Management Flashcards
7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Access Management flashcards as text
Which file in Keystone's Fernet key repository is used to encrypt new tokens?
Answer: Key 0 (the primary key)
Key 0 is the primary Fernet key used for encrypting new tokens; all other keys are used only for decryption.
An operator wants to ensure Nova instances can only communicate with specific external IPs. Which combination of features achieves this?
Answer: Security groups + egress rules
Security groups with egress rules restrict outbound traffic from instances to specific destination IPs or CIDRs.
What is the OpenStack service responsible for managing certificates and secrets as a dedicated key management service?
Answer: Barbican
Barbican is OpenStack's dedicated Key Management Service (KMS) for storing and managing secrets, certificates, and cryptographic keys.
Which policy file format replaced the traditional JSON-based policy files in recent OpenStack releases?
Answer: YAML
OpenStack transitioned from JSON (policy.json) to YAML (policy.yaml) format for service policy files.
A user reports they cannot create volumes despite having the 'member' role in their project. What is the most likely cause?
Answer: The Cinder policy.yaml overrides 'member' role for volume creation
Custom or misconfigured Cinder policy.yaml rules can restrict volume creation permissions beyond what the default 'member' role allows.
Which OpenStack component provides TLS termination and certificate management for load balancer listeners in Octavia?
Answer: Barbican integrated with Octavia
Octavia integrates with Barbican to retrieve and manage TLS certificates for TERMINATED_HTTPS load balancer listeners.
What happens to resources in a project when that project is deleted in Keystone?
Answer: Resources become orphaned and must be manually cleaned up per service
Keystone does not cascade-delete resources; orphaned instances, volumes, and networks must be cleaned up individually in each service.