← All COA Flashcard Decks

Security and Access Control Flashcards

7 cards from real COA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security and Access Control flashcards as text
  1. Which OpenStack component manages TLS certificates and termination for API endpoints in a production deployment?

    Answer: HAProxy or a load balancer in front of API services

    TLS termination for OpenStack API endpoints is typically handled by HAProxy or another load balancer placed in front of the API services.

  2. In Neutron, what is the purpose of a 'security group' compared to a 'network ACL' (firewall rule)?

    Answer: Security groups are stateful and applied per-port; network ACLs are stateless and applied per-subnet

    Neutron security groups are stateful (track connection state) and apply at the port level, while FWaaS ACLs are stateless and apply at the subnet/router level.

  3. What does the Keystone `trusts` mechanism allow in OpenStack?

    Answer: A user to delegate a subset of their roles to another user or service

    Keystone trusts allow a trustor to delegate specific roles to a trustee, enabling services like Heat to act on behalf of users.

  4. Which file must be modified on a Nova compute node to enable encrypted inter-instance communication using QEMU's built-in encryption?

    Answer: /etc/nova/nova.conf with libvirt encryption settings

    Nova's nova.conf under the [libvirt] section contains settings to configure encrypted storage and communication options for QEMU/KVM instances.

  5. An administrator wants to prevent a specific Keystone user from authenticating entirely without deleting their account. Which command should be used?

    Answer: openstack user set --disable

    Setting a user to disabled with `openstack user set --disable` prevents authentication while preserving the account and its associated resources.

  6. In OpenStack, which service provides Firewall-as-a-Service (FWaaS) capabilities to protect tenant networks at the router level?

    Answer: Neutron FWaaS extension

    The Neutron FWaaS (Firewall as a Service) extension provides L3/L4 firewall rules applied at the router level for tenant networks.

  7. Which mechanism in Keystone enables users from an external LDAP directory to authenticate without manually creating Keystone user accounts?

    Answer: Keystone domain-specific configuration pointing to LDAP

    Keystone supports domain-specific configuration files (e.g., keystone.DOMAIN_NAME.conf) that point to an LDAP server for identity, allowing LDAP users to authenticate directly.