โ† All PCA Flashcard Decks

PCA Security & Authentication Flashcards

6 cards from real PCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 PCA Security & Authentication flashcards as text
  1. What OAuth2 configuration capability does Prometheus support natively in scrape_configs?

    Answer: Client credentials flow to obtain a bearer token before scraping

    Prometheus's oauth2 block supports the client credentials grant, allowing it to fetch access tokens to authenticate against protected scrape endpoints.

  2. Which Prometheus web configuration file field specifies the path to the server's TLS certificate?

    Answer: cert_file

    The cert_file field in the web configuration YAML points to the PEM-encoded TLS certificate file for the Prometheus server.

  3. What is the risk of running Prometheus without any authentication on its HTTP API in a shared network environment?

    Answer: Any user with network access can read all metrics, modify configurations, or trigger administrative actions

    Without authentication, the Prometheus HTTP API is fully open, exposing potentially sensitive metrics and admin endpoints to anyone on the network.

  4. Which mutual TLS (mTLS) configuration field in Prometheus scrape_config specifies the client certificate to present to the target?

    Answer: cert_file under tls_config

    In tls_config, cert_file specifies the client certificate Prometheus presents during mutual TLS handshakes with scrape targets.

  5. What is the purpose of `ca_file` in a Prometheus tls_config block?

    Answer: It specifies the CA certificate used to verify the target's TLS certificate

    ca_file provides the CA bundle that Prometheus uses to validate the server certificate presented by scrape targets.

  6. In Prometheus web configuration, what does the `http2` field control?

    Answer: Whether Prometheus serves its own API over HTTP/2

    The http2 field in web config enables or disables HTTP/2 support on the Prometheus server's own HTTP listener.