11.12 Self-test
Self-test49 questions
Name the five security procedures and what each establishes.
List the seven guarantees a secure Kafka deployment must provide. Which one includes ZooKeeper, and why?
Draw the 2×2 of transport × authentication and name all four security protocols. Which two are safe on an insecure network?
Why must a broker's config include client-side settings for the inter-broker listener?
A client bootstraps against the EXTERNAL port. Which endpoints will it learn about, and why does that matter?
What principal do unauthenticated connections get, and in which two situations?
What's the CPU cost of SSL, and what Kafka optimization does it defeat?
Which stores does a broker need, and under what two conditions does it need a trust store?
Why must a broker certificate carry the hostname in SAN or CN? What attack does hostname verification prevent?
Contrast
ssl.client.auth=requiredandrequested. What principal does an unauthenticated client get underrequested?What becomes the
KafkaPrincipalby default under SSL client auth, and how do you customize it?When can you omit trust store configuration entirely?
How do you rotate a broker's key store without a restart?
Why are TLS handshakes a DoS vector, and what two controls mitigate it?
List Kafka's four SASL mechanisms. Which two have built-in implementations unsuitable for production, and why each?
Name the three SASL callback handler types and what each is for.
Why is
sasl.jaas.configpreferred over a JAAS config file?Why must a Kerberos broker principal include the hostname? Why may client principals omit it?
Give three Kerberos-specific security considerations beyond "use TLS."
Why is the built-in SASL/PLAIN password store both insecure and inflexible?
How do you support password rotation on the server side? On the client side?
What does declaring a config with the
PASSWORDtype buy you?What does SCRAM improve over PLAIN? What are its three security prerequisites?
You delete a SCRAM user. What immediately stops working, and what doesn't?
What are delegation tokens for? What SASL mechanism carries them, and what's the resulting principal?
What's the master-key rotation procedure for delegation tokens, and why is it disruptive?
What is the default behavior of a long-lived connection when its credentials expire? What config fixes it, and how is session lifetime computed?
A user's credentials are compromised. Give the full playbook in priority order, and explain why the first step is first.
Why doesn't SSL renegotiation help with revoked certificates?
Walk the four steps to migrate PLAINTEXT → SASL_SSL with no downtime. What makes it safe?
Walk the five steps to migrate PLAIN → SCRAM on the same port.
Name the three encryption layers and the specific threat each addresses. What does the third one cover that the first two don't?
In end-to-end encryption, what does the broker see? Why does that matter for cloud deployments?
Why should you compress before encrypting — and then disable Kafka compression?
Why does naively encrypting message keys break Kafka? Give the two things it breaks and the recommended workaround.
What makes key rotation painful on a compacted topic?
List the six components of an ACL binding. Which permission type wins?
State the ACL evaluation rule and both implicit grants.
What ACLs does each of these need: a plain producer; an idempotent non-transactional producer; a transactional producer; a consumer in a group; a broker?
Why is
super.usersdangerous, and what's the separator gotcha?Give both failure modes of
allow.everyone.if.no.acl.found=true.What does the request context give a custom authorizer? Name two things you could build with it.
Which log level records granted operations vs denied ones? What's the practical implication?
What information does a single TRACE/DEBUG request-log line contain? Name three distinct uses for it.
Why must
kerberos.removeHostFromPrincipalandremoveRealmFromPrincipalbe true for ZooKeeper?How does ZooKeeper's combined SASL+SSL authentication differ from Kafka's, and what's the authorization consequence?
What does
zookeeper.set.acl=truedo? What's readable by whom afterward?Describe both mechanisms for keeping passwords out of config files. Where does the chain of trust bottom out in each?
What is a threat model, and which category of threat does the chapter specifically remind you not to forget?
Previous: Chapter 10 — Cross-Cluster Data Mirroring Next: Chapter 12 — Administering Kafka