โ† All PCA Flashcard Decks

PCA Security & Authentication Flashcards

6 cards from real PCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 PCA Security & Authentication flashcards as text
  1. What is the recommended way to add TLS encryption to Prometheus scrape endpoints?

    Answer: Configure tls_config in the scrape job or use a reverse proxy with TLS termination

    Prometheus supports tls_config in scrape_configs to present or verify TLS certificates, or you can terminate TLS at a reverse proxy.

  2. Which Prometheus configuration option allows scraping a target that uses a self-signed TLS certificate without verification?

    Answer: insecure_skip_verify: true

    Setting insecure_skip_verify: true in tls_config disables certificate validation, which is useful for self-signed certs but reduces security.

  3. What is the purpose of the `authorization` section in a Prometheus scrape_config?

    Answer: It configures bearer token or custom header authentication for scraping a target

    The authorization block lets Prometheus send a bearer token or other credentials when scraping targets that require authentication.

  4. How can Prometheus scrape targets that require HTTP Basic Authentication?

    Answer: By specifying basic_auth with username and password in the scrape_config

    The basic_auth block in scrape_configs allows Prometheus to send HTTP Basic Authentication headers to protected targets.

  5. What does the `--web.config.file` flag enable in Prometheus?

    Answer: TLS and basic authentication for the Prometheus HTTP server itself

    The --web.config.file flag loads a YAML file that configures TLS and HTTP Basic Auth for the Prometheus server's own API and UI.

  6. Why is it a best practice to store Prometheus authentication credentials in separate secret files rather than inline in prometheus.yml?

    Answer: Secret files can be mounted from Kubernetes Secrets or Vault, reducing the risk of credentials in version control

    Storing credentials in secret files allows them to be managed by secret managers and keeps sensitive data out of version-controlled config files.