フリー問題

HashiCorp Certified: Vault Associate (003) のフリー問題 4 / 20 問目

問題文

An administrator uploads a policy document that contains no path stanzas at all and attaches it to a token. The administrator expects the token to be usable for reading anything that is not explicitly forbidden. What will the token actually be able to do?

選択肢

  1. Read only the paths under the mount where the token was issued, because the auth mount's own path is implicitly granted to tokens it creates.
  2. Nothing, because policies grant no permission unless a path stanza allows it.
  3. Read every path, because a policy with no stanzas restricts nothing.
  4. Read and write anywhere below the system backend, because an empty policy is treated as an administrative policy and the system backend is where the administrative endpoints live.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。