問題文
An operator asks where the configuration of auth methods, secrets engines, and audit devices lives, and why it cannot be specified from outside. What does the documented design say?
選択肢
- It lives in the encryption layer but is exempt from the access rules, because the endpoints that manage it are reached through the system backend rather than through the router.
- It lives in the server's configuration file, which is why the file has to be protected by the operating system's permissions.
- It is security sensitive and is therefore stored inside the encryption layer, which is how changes to it end up protected by the access rules and recorded for audit.
- It lives outside the encryption layer so that it can be read while the cluster is sealed, which is what lets the unseal endpoint work.