Confluent CCDAK Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Confluent CCDAK Exam Dumps and Practice Test Dumps

 

Question 121

Which Kafka setting tells clients the addresses brokers advertise?

  1. socket.address
  2. broker.endpoint
  3. client.route
  4. advertised.listeners

Correct Answer: 4

Explanation:

The advertised.listeners setting defines the addresses and ports that Kafka brokers publish to clients for connections. These advertised endpoints can differ from the addresses used by the broker for binding network interfaces. This distinction is especially important in cloud, containerized, NAT, and load-balanced deployments where clients may need externally reachable addresses rather than internal broker addresses. Kafka can advertise multiple listeners for different client groups, such as internal applications and external consumers. Correctly configuring this property helps clients receive usable broker connection information after obtaining cluster metadata.

Question 122

Which setting selects the listener used for broker-to-broker communication?

  1. inter.broker.listener.name
  2. broker.link.protocol
  3. internal.network.mode
  4. replication.listener.id

Correct Answer: 1

Explanation:

The inter.broker.listener.name property specifies which configured listener Kafka brokers use for communication with one another. This is particularly useful when a broker has separate listeners for clients, replication traffic, and other network paths. The selected listener must correspond to a listener configured on the broker. Separating broker-to-broker traffic from client traffic can simplify network security and routing policies. In deployments with multiple listener configurations, choosing the correct inter-broker listener ensures replication and other broker communication use the intended endpoint and security protocol.

Question 123

Which Kafka client property defines the network authentication and encryption protocol?

  1. connection.mode
  2. listener.security
  3. security.protocol
  4. transport.profile

Correct Answer: 3

Explanation:

The security.protocol property determines how a Kafka client communicates with brokers from a security perspective. Common values include PLAINTEXT, SSL, SASL_PLAINTEXT, and SASL_SSL. The selected protocol determines whether TLS encryption and SASL authentication are involved. For example, SASL_SSL combines authentication through SASL with encryption through TLS. Client configuration must match the broker listener’s expected security setup. Using the appropriate protocol is therefore essential when applications connect to secured Kafka environments, especially when authentication credentials or encrypted network communication are required.

Question 124

Which protocol combines SASL authentication with TLS encryption?

  1. SASL_PLAINTEXT
  2. SASL_SSL
  3. SSL_ONLY
  4. AUTH_TLS

Correct Answer: 2

Explanation:

SASL_SSL combines two security mechanisms: SASL for client authentication and SSL/TLS for encrypted network communication. SASL can use mechanisms such as SCRAM or other supported authentication methods, while TLS protects data transmitted between clients and brokers. This combination is commonly used when Kafka deployments require both identity verification and confidentiality. By comparison, SASL_PLAINTEXT provides SASL authentication without encrypting the connection. Selecting SASL_SSL therefore provides a secured transport while retaining SASL-based authentication capabilities.

Question 125

Which SSL setting controls whether brokers request client certificates?

  1. ssl.certificate.mode
  2. ssl.peer.identity
  3. ssl.authentication.level
  4. ssl.client.auth

Correct Answer: 4

Explanation:

The ssl.client.auth setting controls client certificate authentication behavior for SSL/TLS connections. Depending on its configured value, a broker can require, request, or not request a client certificate. When mutual TLS authentication is required, clients present certificates that allow the broker to authenticate their identities using the TLS certificate infrastructure. This differs from ordinary server-side TLS, where the client verifies the broker but does not necessarily provide its own certificate. Proper configuration of this property is important for Kafka environments using certificate-based client authentication.

Question 126

What Kafka component determines whether authenticated clients are authorized for operations?

  1. protocol parser
  2. authorizer
  3. partition assignor
  4. metadata loader

Correct Answer: 2

Explanation:

Kafka authentication establishes who a client is, while authorization determines what that identity is permitted to do. The Kafka authorizer evaluates authorization requests against configured permissions such as ACLs. For example, an authenticated principal may be permitted to read one topic while being denied permission to alter another. This separation allows security administrators to establish detailed access controls after authentication has occurred. Authorization can cover operations on topics, consumer groups, clusters, and other Kafka resources. A properly configured authorizer is therefore a central part of Kafka access-control enforcement.

Question 127

What Kafka mechanism grants permissions to specific principals?

  1. Access control lists
  2. Listener declarations
  3. Topic partitions
  4. Consumer assignments

Correct Answer: 1

Explanation:

Kafka access control lists, commonly called ACLs, define which principals can perform specific operations on Kafka resources. An ACL can grant or deny permissions involving operations such as reading, writing, creating, deleting, or describing resources. ACLs can be associated with topics, consumer groups, clusters, and other supported resource types. Administrators can create ACLs using Kafka command-line utilities or other supported management methods. By defining permissions at the resource and operation level, ACLs allow organizations to implement least-privilege access rather than giving every authenticated client broad Kafka permissions.

Question 128

Which ACL operation allows a principal to inspect resource metadata?

  1. WRITE
  2. CREATE
  3. DESCRIBE
  4. DELETE

Correct Answer: 3

Explanation:

The DESCRIBE ACL operation controls whether a principal can obtain descriptive information about a Kafka resource. Metadata-related operations can require describe permissions depending on the specific resource and requested action. Other ACL operations have different purposes: WRITE controls writing records, CREATE controls resource creation, and DELETE controls deletion. Understanding these distinctions is important when designing restrictive permissions. An administrator should grant only the operations required by an application rather than assigning unnecessarily broad privileges.

Question 129

What does the Kafka super.users setting identify?

  1. Replication source topics
  2. Controller candidates
  3. Consumer group owners
  4. Administratively privileged users

Correct Answer: 4

Explanation:

The super.users configuration identifies principals that receive elevated authorization privileges in Kafka. These identities are treated as super users by the authorization layer and can bypass ordinary ACL restrictions for supported authorization decisions. Administrators commonly use this capability for trusted operational identities that need broad access to manage or troubleshoot the cluster. Because super-user access is powerful, the configured identities should be carefully controlled. The setting is distinct from ordinary ACL entries, which grant specific permissions to individual principals on particular Kafka resources.

Question 130

Which Kafka CLI manages access-control lists?

  1. kafka-acls
  2. kafka-permissions
  3. kafka-security
  4. kafka-authorize

Correct Answer: 1

Explanation:

The kafka-acls command-line utility is used to manage Kafka access-control lists. Administrators can use it to create, remove, and inspect ACL entries associated with Kafka resources. Typical operations can specify principals, hosts, resources, and permissions. This makes the utility useful for implementing application-specific access policies from the command line. ACL administration should be performed carefully because overly broad permissions can grant applications more access than required. The tool complements Kafka’s authorization system by providing an administrative interface for defining and reviewing access-control rules.

Question 131

Which ACL pattern can apply permissions to matching resource-name prefixes?

  1. Exact
  2. Prefixed
  3. Singular
  4. Literal

Correct Answer: 2

Explanation:

A prefixed ACL pattern applies authorization rules to resources whose names begin with a specified prefix. This can simplify access management when an application owns or uses a family of similarly named topics. For example, a rule associated with a suitable prefix can cover multiple topic names without creating an individual ACL entry for every topic. This approach can reduce administrative overhead in environments with systematic naming conventions. Administrators should nevertheless design prefixes carefully so that permissions do not unintentionally cover unrelated resources.

Question 132

Which KRaft setting specifies the roles performed by a Kafka process?

  1. kafka.roles
  2. node.functions
  3. process.roles
  4. cluster.roles

Correct Answer: 3

Explanation:

The KRaft process.roles property specifies which roles a Kafka process performs. Depending on the deployment architecture, a process can operate as a broker, controller, or both. Role separation is useful for larger environments where controller and broker responsibilities are intentionally deployed on different nodes. Combined roles can also be used in smaller installations. Correctly defining process.roles is an important part of KRaft configuration because it determines how the Kafka process participates in data serving and cluster metadata management.

Question 133

Which KRaft property uniquely identifies a Kafka server node?

  1. node.id
  2. server.identity
  3. cluster.node
  4. process.number

Correct Answer: 1

Explanation:

The node.id property provides the unique identifier for a Kafka server in a KRaft-based deployment. KRaft uses node IDs to distinguish participating servers and to associate processes with their configured roles. This differs from the older ZooKeeper-based configuration model that commonly relied on broker.id for broker identification. Each node participating in a KRaft cluster needs an appropriate unique identifier. Careful node identification helps Kafka maintain a consistent view of cluster membership and role assignments.

Question 134

Which KRaft setting lists the controller quorum voters?

  1. quorum.members
  2. controller.nodes
  3. voter.membership
  4. controller.quorum.voters

Correct Answer: 4

Explanation:

The controller.quorum.voters configuration identifies the controller nodes that participate in the KRaft controller quorum. Its value associates controller node IDs with their network endpoints so participating servers know how to communicate with the configured quorum members. This configuration is important for establishing the controller quorum that manages Kafka cluster metadata. In a correctly configured KRaft deployment, the listed voter identities and endpoints must correspond to the intended controller nodes. Errors in this setting can prevent proper controller-quorum formation or communication.

Question 135

Which KRaft property names listeners dedicated to controller traffic?

  1. controller.endpoints
  2. controller.listener.names
  3. quorum.listener.list
  4. metadata.listeners

Correct Answer: 2

Explanation:

The controller.listener.names property identifies the listener names that KRaft controllers use for controller-to-controller and controller-related communication. Kafka can define multiple listeners for different traffic categories, so explicitly identifying controller listeners helps separate metadata quorum traffic from ordinary client or broker traffic. The named listeners must correspond to configured listener definitions. This separation is especially useful in secured deployments where different traffic types may require distinct network paths or security protocols.

Question 136

What does metadata.log.dir designate in a KRaft broker?

  1. Topic retention directory
  2. Consumer offset folder
  3. Metadata log location
  4. Temporary cache path

Correct Answer: 3

Explanation:

The metadata.log.dir setting specifies the directory used for the KRaft metadata log. KRaft stores cluster metadata in this dedicated log rather than relying on ZooKeeper. Separating metadata storage from ordinary topic data directories can provide administrators with additional control over storage layout. If metadata.log.dir is not explicitly configured, Kafka has defined behavior for locating the metadata log based on the available log directories. Understanding this setting is useful when designing storage layouts, troubleshooting disk usage, or separating metadata storage from regular partition data.

Question 137

Which Kafka setting specifies directories used for partition data?

  1. log.dirs
  2. data.paths
  3. partition.folders
  4. storage.locations

Correct Answer: 1

Explanation:

The log.dirs configuration specifies the directories where Kafka stores partition log data. Kafka can use multiple directories, allowing partition data to be distributed across available storage devices. This is particularly useful when brokers have multiple disks and administrators want to spread storage workloads. Kafka manages partition placement across configured log directories. Storage planning should consider capacity, disk performance, and failure characteristics when selecting these directories. Proper configuration of log.dirs helps brokers use their available local storage efficiently.

Question 138

What does Kafka JBOD configuration allow a broker to use?

  1. One partition disk
  2. Shared remote storage
  3. Controller-only storage
  4. Multiple independent disks

Correct Answer: 4

Explanation:

JBOD, or Just a Bunch Of Disks, allows a Kafka broker to use multiple independent storage devices rather than relying on a single disk. Kafka can configure multiple log directories so partition data is distributed across available disks. This can increase usable storage capacity and allow administrators to manage local disks individually. JBOD is different from RAID because the disks are exposed and managed separately rather than combined into one RAID volume. Careful storage monitoring remains important because a disk failure affects the partitions located on that disk.

Question 139

Which Kafka Connect setting limits the maximum number of tasks for a connector?

  1. worker.task.limit
  2. connector.parallelism
  3. tasks.max
  4. max.connector.instances

Correct Answer: 3

Explanation:

The Kafka Connect tasks.max configuration specifies the maximum number of tasks that a connector may use. The actual number of tasks created can depend on the connector’s implementation and workload, so setting tasks.max does not guarantee that every connector will create that many tasks. Increasing the task limit can allow greater parallelism when the connector supports it and the workload can be divided effectively. Administrators should balance parallelism against source or destination capacity, worker resources, and overall cluster workload.

Question 140

Which Kafka Connect property names the topic used for dead-letter records?

  1. errors.retry.topic
  2. errors.deadletterqueue.topic.name
  3. errors.failure.storage
  4. errors.invalid.records.topic

Correct Answer: 2

Explanation:

The Kafka Connect errors.deadletterqueue.topic.name property identifies the topic where failed records can be sent when dead-letter-queue handling is enabled. A dead-letter queue allows problematic records to be isolated instead of necessarily stopping connector processing. Administrators can then inspect, correct, or replay those records separately. Dead-letter handling is especially useful for data-quality problems, conversion failures, or other record-specific errors. It should be configured alongside the appropriate Connect error-handling settings so the connector’s behavior matches the organization’s operational and recovery requirements.