問題文
A reviewer asks which engine feature to use when the requirement is that anyone with the right policy may access the very same database account, rather than getting an account of their own. Which one, and what is the security consequence?
選択肢
- A static role, and the consequence is that the account is shared so the database log cannot distinguish the callers from each other.
- A static role, and there is no security consequence because Vault rotates the password on a schedule.
- The key-value engine holding the account's password, and the consequence is that the password never changes, which is why static roles exist as the better option for a shared account.
- A dynamic role with the maximum number of users set to one, and the consequence is that the second caller has to wait for the first to release the account.