Security and Access Control Flashcards
7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security and Access Control flashcards as text
Which OpenStack service is responsible for auditing and tracking API calls for compliance and security investigation purposes?
Answer: CADF middleware (PyCADF)
PyCADF (Cloud Audit Data Federation) middleware generates CADF-compliant audit events for OpenStack API calls.
A security engineer wants to ensure that all data stored in Swift object storage is encrypted at rest. Which Swift feature handles server-side encryption?
Answer: Swift encryption middleware
Swift's encryption middleware encrypts object data and metadata at rest before writing to disk using keys from Barbican.
In Keystone, what is a 'domain' primarily used for in multi-tenant environments?
Answer: An administrative boundary grouping users and projects
Keystone domains provide administrative boundaries that contain users, groups, and projects, enabling multi-tenant identity management.
Which command would a cloud administrator use to create a new Keystone domain named 'engineering'?
Answer: openstack domain create engineering
The `openstack domain create ` command creates a new Keystone domain.
What is the risk of using 'admin' as a role name in legacy OpenStack policy files with the 'is_admin_project' option disabled?
Answer: Users with admin role in any project gain cloud-wide administrative privileges
Without `is_admin_project` enforcement, having the 'admin' role in any project may grant cloud-wide admin access due to legacy policy rules.
Which Nova feature allows an administrator to isolate specific compute hosts so that only designated tenants can schedule instances on them?
Answer: Host aggregates with metadata filters
Host aggregates with AggregateInstanceExtraSpecsFilter allow administrators to restrict instance scheduling to specific hosts based on tenant metadata.
An operator discovers that a Keystone service account token has been compromised. What is the FASTEST way to immediately invalidate all tokens for that user?
Answer: Revoke the user's tokens with openstack user set --disable
Disabling the user with `openstack user set --disable` immediately prevents new authentications and causes existing tokens to be rejected at validation.