DevNet Associate (DEVASC) v1.0 flashcards
165 free flashcards. Tap a card to flip it.
Model-Driven Telemetry (MDT)
Flip cardModel-Driven Telemetry (MDT) is a push-based mechanism that allows network devices to stream operational data to a collector in real-time, using structured data models (YANG) and efficient transport protocols.
- Push-based data streaming.
- Uses YANG models to define data structure.
- Supports various transport protocols (e.g., gRPC, NETCONF).
- Ideal for high-volume, real-time monitoring.
Memory trick: Think of MDT as a live news channel for your network, constantly streaming updates.
JSON Serialization (Python)
Flip cardJSON serialization in Python is the process of converting Python objects (like dictionaries and lists) into a JSON formatted string. This is typically done using the `json.dumps()` function from the built-in `json` module.
- Converts Python object to JSON string
- Uses `json.dumps()` function
- Commonly used for API communication and data storage
- Handles basic Python types (dict, list, str, int, float, bool, None)
Memory trick: Dumps 'dumps' Python data into a JSON string.
Cisco SD-WAN vManage APIs
Flip cardCisco SD-WAN vManage provides a rich set of REST APIs that enable programmatic configuration, monitoring, and troubleshooting of the entire SD-WAN fabric, including VPNs, routing policies, and device management.
- Centralized management for Cisco SD-WAN.
- Offers REST APIs for full programmatic control.
- Manages VPNs, routing, security, and policies.
Memory trick: To steer the SD-WAN ship, vManage is the captain with the API compass.
Dijkstra's Algorithm
Flip cardDijkstra's Algorithm is an algorithm for finding the shortest paths between nodes in a graph, which may represent, for example, road networks. It works for graphs with non-negative edge weights.
- Finds shortest path from a single source to all other nodes
- Works on graphs with non-negative edge weights
- Greedy algorithm approach
- Commonly used in network routing protocols
Memory trick: Dijkstra 'distances' itself from bad paths, always finding the shortest weighted route.
Cisco NX-API REST
Flip cardCisco NX-API REST is a native HTTP/HTTPS-based API on Nexus switches that allows programmatic interaction with the device. It supports sending CLI commands and retrieving operational/configuration data in structured JSON or XML format.
- Directly embedded on the Nexus switch.
- Uses HTTP/HTTPS for communication.
- Supports both configuration and operational commands.
- Returns data in JSON or XML.
Memory trick: NX-OS offers APIs for direct control and structured data.
YAML
Flip cardYAML (YAML Ain't Markup Language) is a human-friendly data serialization standard for all programming languages. It is often used for configuration files and in applications where data is being stored or transmitted.
- Human-readable syntax
- Uses indentation for structure (whitespace significant)
- Supports comments with '#'
- Commonly used for configuration files and data exchange
Memory trick: YAML is the friendly config file, easy to read and comment.
Postman Collection Runner
Flip cardThe Postman Collection Runner is a feature that allows users to automate the execution of all requests within a Postman Collection. It supports iterating through requests, using environment variables, and executing pre-request scripts and test scripts for automated testing.
- Automates sequential execution of requests in a collection.
- Supports iteration over data files.
- Executes pre-request and test scripts.
- Manages environment variables during the run.
Memory trick: Collection Runner Runs Tests, Monitors Watch, Mocks Fake.
HTTP 429 Too Many Requests
Flip cardAn HTTP status code indicating that the user has sent too many requests in a given amount of time (rate limiting).
- Part of HTTP client error (4xx) responses.
- Often accompanied by a 'Retry-After' header.
- Indicates API rate limiting has been triggered.
Memory trick: Clients Fail Regularly, But Often Know Why.
OpenAPI Parameters
Flip cardIn OpenAPI Specification, parameters define the inputs to an API operation, such as path variables, query strings, headers, or cookies.
- Defined with `name`, `in` (path, query, header, cookie), `schema`, and `description`.
- Path parameters (`in: path`) are essential for dynamic URLs.
- Describe how clients should send specific data to the API.
Memory trick: OpenAPI: Paths Have Parameters, Responses Use Schemas, Security Protects.
cURL --config Option
Flip cardA cURL command-line option that reads configuration from a specified file, allowing users to define and reuse common arguments across multiple cURL commands.
- Enhances reusability and reduces command-line length for complex cURL calls.
- Config files can contain any cURL option, one per line or separated by spaces.
- Useful for managing API keys, base URLs, and common headers.
Memory trick: Don't type it again! Put the common parts in a cookbook (config file).
RESTCONF Content-Type
Flip cardFor RESTCONF APIs, especially when using YANG models, the `Content-Type` header for JSON payloads is often `application/yang-data+json` (or `application/yang.data+json`), specifying the data adheres to a YANG model.
- Crucial for server to correctly parse the request body.
- Differs from generic `application/json` for YANG-structured data.
- Incorrect `Content-Type` often leads to `400 Bad Request` or `415 Unsupported Media Type`.
Memory trick: Bad Request? Check Headers First, Then Body, Then Method.
HTTP 415 Unsupported Media Type
Flip cardThe HTTP `415 Unsupported Media Type` client error response code indicates that the server refuses to accept the request because the payload format is not supported by the server for this method and target resource. This is typically due to an incorrect or missing `Content-Type` header in the request.
- Server rejects request due to unsupported payload format.
- Caused by incorrect `Content-Type` header in the request.
- Specific to the request body's media type.
- Often seen with RESTCONF or other specialized APIs expecting specific JSON/XML variants.
Memory trick: 415 means Content-Type is Wrong for the Server's taste.
Basic Authentication Security
Flip cardBasic Authentication transmits credentials as a Base64-encoded string in the `Authorization` header. This encoding is reversible, meaning credentials are sent in cleartext unless protected by an underlying secure transport layer like HTTPS (TLS/SSL).
- Credentials are Base64 encoded, not encrypted.
- Vulnerable to interception if not used over HTTPS.
- Easy to implement, but inherently insecure over plain HTTP.
- Should ALWAYS be combined with HTTPS for production use.
Memory trick: Basic Auth's biggest flaw is Cleartext Credentials.
OpenAPI Specification (OAS)
Flip cardA language-agnostic, human-readable specification for describing RESTful APIs, facilitating API discovery, understanding, and consumption.
- Defines endpoints, operations, parameters, authentication methods, and response structures.
- Enables automated generation of API documentation, client SDKs, and server stubs.
- Formerly known as Swagger Specification.
Memory trick: Open doors to understanding with a clear API map.
REST Statelessness
Flip cardA core principle of REST where each request from client to server contains all the information necessary to understand the request, and the server does not store any client context between requests.
- Each request is independent and self-contained.
- Server does not rely on previous requests or sessions.
- Simplifies server design and improves scalability.
Memory trick: REST: Client-Server, Stateless, Cacheable, Layered, Uniform Interface, Code-on-Demand (optional).
API Contract Testing
Flip cardA testing approach where an explicit 'contract' (often derived from API documentation like OpenAPI) is defined between an API producer and consumer, and both sides are tested to ensure they adhere to this contract.
- Ensures API documentation matches actual implementation.
- Prevents breaking changes between API versions.
- Automated in CI/CD pipelines to catch discrepancies early.
Memory trick: Docs Must Match Code, Contract Testing Makes It So.
HTTP Content-Type Header for JSON
Flip cardThe `Content-Type` HTTP header specifies the media type of the resource sent in the request or response body. For JSON payloads, it must be set to `application/json` for the server to correctly parse the data.
- Indicates the format of the request/response body.
- Crucial for POST, PUT requests with payloads.
- Without it, servers might not process payloads correctly.
- Common values: `application/json`, `application/xml`, `text/plain`.
Memory trick: Content is Key for Correct POSTing.
`curl` Custom Headers
Flip cardThe `curl` command-line tool allows users to specify custom HTTP headers in requests using the `-H` or `--header` option, followed by the header name and value.
- Used to add or override HTTP headers.
- Syntax: `-H "Header-Name: Header-Value"`.
- Essential for authentication tokens, content types, etc.
- Can be used multiple times for multiple headers.
Memory trick: Headers Help HTTP, use -H with colon.
HTTP Accept Header
Flip cardAn HTTP request header that specifies which media types the client is able to understand and process in the server's response.
- Used for content negotiation, allowing clients to request preferred response formats.
- Common values include `application/json`, `application/xml`, `text/html`.
- Servers will try to respond with one of the requested types, or default if no match.
Memory trick: Tell the chef how you like your data served: JSON, XML, or plain text.
OpenAPI Path Parameters
Flip cardIn OpenAPI Specification, path parameters are variables defined within the URL path (e.g., `/items/{itemId}`). They are specified using the `parameters` field, with `in: path` and usually `required: true` for mandatory segments.
- Defined within the `parameters` section of an operation or globally.
- `in: path` indicates it's part of the URL path.
- `required: true` for mandatory path segments.
- Must include a `schema` defining its `type` and optional `format`.
Memory trick: Parameters need Name, In, Required, and Schema to be right.
Secure API Key Storage
Flip cardBest practices for storing and accessing API keys involve methods that prevent hardcoding, exposure in version control, and unauthorized access, typically by externalizing them from the application code.
- Never hardcode API keys directly in source code.
- Avoid committing API keys to version control systems (e.g., Git).
- Environment variables are a common and secure method.
- Secret management services (e.g., HashiCorp Vault, AWS Secrets Manager) provide advanced protection.
Memory trick: Environment variables Keep Secrets Safe Every time.
Token Expiration
Flip cardTokens issued by an authentication server have a limited lifespan and will become invalid after their expiration time, requiring re-authentication or token refresh.
- Common in OAuth 2.0 and other token-based systems.
- Designed to enhance security by limiting exposure of compromised tokens.
- Requires client applications to manage token refresh or re-authentication.
Memory trick: Keys can expire, causing a sudden halt to access.
API Rate Limiting Mitigation (Delay)
Flip cardTo mitigate API rate limiting, applications can introduce deliberate delays between API calls using functions like `time.sleep()` to ensure they do not exceed the allowed request frequency, thus preventing HTTP 429 errors.
- APIs enforce limits on requests per unit of time.
- Exceeding limits results in HTTP 429 Too Many Requests.
- Delays (e.g., `time.sleep()`) space out requests.
- Exponential backoff is a more advanced strategy for retries.
Memory trick: Sleep to Slow, Backoff to Recover.
OAuth 2.0 Client Credentials Grant
Flip cardAn OAuth 2.0 authorization grant type used by clients to obtain an access token directly from the authorization server using only their own 'client_id' and 'client_secret', without user involvement.
- Ideal for machine-to-machine (server-to-server) communication.
- No user interaction or browser redirects involved.
- Client authenticates itself to the authorization server.
Memory trick: OAuth Grants: Codes for Users, Clients for Machines.
OAuth 2.0 Token Expiration
Flip cardOAuth 2.0 access tokens are designed with a limited lifespan for security. Once expired, they are no longer valid for accessing protected resources, leading to an 'Unauthorized' error, and require renewal, often via a refresh token.
- Access tokens have a defined `expires_in` duration.
- Expired tokens result in 401 Unauthorized errors.
- Applications must handle token expiration gracefully.
- Refresh tokens allow obtaining new access tokens without re-authentication.
Memory trick: Expired Tokens Cause Unauthorized Trouble.
XSS and Local Storage
Flip cardCross-Site Scripting (XSS) is a vulnerability that allows attackers to inject client-side scripts into web pages. If sensitive data like access tokens are stored in browser local storage, an XSS attack can steal them.
- Local storage is accessible via JavaScript.
- XSS allows malicious JavaScript injection.
- Stolen tokens can be used to impersonate the user.
Memory trick: OAuth Tokens: Store Safely, Or XSS Steals Easily.
API Rate Limit Calculation
Flip cardDetermining when an API client will exceed a defined request limit within a specific time window.
- Convert all time units to be consistent (e.g., seconds to minutes).
- Calculate total requests within the rate limit window.
- Compare total requests to the allowed limit.
Memory trick: Rate Limits: Calculate Fast, Or Get Blocked Quickly.
cURL GET Request with Accept Header
Flip cardA cURL command to retrieve data from an API endpoint, specifying the desired response media type using the 'Accept' HTTP header.
- Uses `-X GET` for the HTTP method.
- Uses `-H "Accept: <media_type>"` to request a specific response format.
- Essential for APIs that support multiple output formats (e.g., JSON, XML, YANG+JSON).
Memory trick: cURL Commands Make REST Easy, Just Get Headers Right.
Token-based Authentication
Flip cardA method where a client sends an access token (e.g., JWT) in an HTTP header to authenticate and authorize requests to an API.
- Uses a 'Bearer' token in the Authorization header.
- Tokens are often short-lived and obtained after initial login.
- Provides a stateless authentication mechanism.
Memory trick: Many APIs Guard Access, But Only Tokens Really Secure.
Webhooks for Real-time Events
Flip cardA webhook is an HTTP callback: an HTTP POST request triggered by an event, sent from a source application to a destination URL. They enable real-time communication between systems without continuous polling.
- Event-driven mechanism.
- Server-side sends data to client-side.
- Uses HTTP POST requests to a pre-configured URL.
- Eliminates the need for constant polling, reducing overhead.
Memory trick: Webhooks Watch for Events, then Notify.
HTTP Content-Type Header
Flip cardAn HTTP header that indicates the media type of the resource in the request or response body, specifying how the content should be parsed or interpreted.
- Crucial for correct interpretation of data exchanged between client and server.
- Examples include `application/json`, `text/html`, `image/jpeg`.
- Used in both request (for body sent to server) and response (for body sent to client).
Memory trick: Label your package (data) so the post office (server) knows how to handle it.
Secure Coding Practices
Flip cardA set of guidelines and techniques used by developers to write code that is resistant to security vulnerabilities. This includes practices like input validation, proper error handling, and secure API usage.
- Prevents common vulnerabilities (e.g., SQLi, XSS).
- Includes input validation, output encoding, error handling.
- Aims to build security into the application from the start.
Memory trick: Secure code validates, least privilege restricts, defense in depth layers.
Continuous Delivery
Flip cardA software development practice where code changes are automatically built, tested, and prepared for release to production, ensuring the software is always in a deployable state.
- Builds upon Continuous Integration.
- Automates the entire release process up to the point of production deployment.
- Allows for frequent and reliable releases, often with a manual 'go/no-go' decision for production.
Memory trick: CI integrates, CD delivers, CDep deploys to prod.
Service Mesh (mTLS)
Flip cardAn infrastructure layer for handling service-to-service communication in a microservices architecture. When configured with mTLS, it automatically encrypts and authenticates all traffic between services without requiring changes to the application code.
- Automates service-to-service encryption (mTLS).
- Manages traffic, observability, security.
- Transparent to application code.
Memory trick: Mesh encrypts automatically, policies filter traffic, secrets store keys.
Centralized Secrets Management
Flip cardA system or platform designed to securely store, manage, and distribute sensitive information (secrets) like API keys, database credentials, and certificates across applications and environments. It provides features like access control, auditing, and dynamic secret generation.
- Avoids hardcoding secrets.
- Provides audit trails for secret access.
- Enables dynamic and short-lived secrets.
- Offers fine-grained access control.
Memory trick: Centralized secrets mean audit, dynamics, and no hardcoding.
Kubernetes Secret
Flip cardA Kubernetes object used to store and manage sensitive information, such as passwords, OAuth tokens, and SSH keys. Secrets can be mounted as data volumes or exposed as environment variables to pods.
- Stores sensitive data.
- Can be mounted as volumes or env vars.
- Base64 encoded by default (not encrypted at rest without additional setup).
Memory trick: ConfigMaps for general settings, Secrets for sensitive stuff.
Continuous Delivery (CD)
Flip cardContinuous Delivery is a software development practice where code changes are automatically built, tested, and prepared for release to production. It ensures that the software is always in a deployable state, allowing for rapid and reliable releases.
- Extends Continuous Integration.
- Code is always in a deployable state.
- Automated build, test, and release preparation.
- Deployment to production can be manual or automated.
Memory trick: Delivery means ready to ship, Deployment means it's shipped.
JWT Signature
Flip cardThe third part of a JSON Web Token, created by encoding the header and payload and then signing them using a secret key. It's crucial for verifying the token's integrity and authenticity.
- Verifies token integrity.
- Ensures token hasn't been altered.
- Uses a secret key for signing.
Memory trick: Head and Payload tell the story, Signature proves it's true.
Kubernetes NetworkPolicy
Flip cardKubernetes NetworkPolicy is a resource that controls network traffic flow between pods, namespaces, and external network endpoints within a Kubernetes cluster.
- Enforces network segmentation.
- Based on labels, namespaces, IP blocks, ports, protocols.
- Applied to pods.
- Requires a network plugin that supports NetworkPolicy.
Memory trick: NetworkPolicy is the traffic cop for pods.
Input Validation & Sanitization
Flip cardInput validation checks if user-submitted data conforms to expected formats and constraints, while sanitization cleans or neutralizes potentially malicious content to prevent injection attacks.
- Prevents XSS, SQL Injection, Command Injection.
- Validation checks format, type, length, range.
- Sanitization removes or escapes dangerous characters.
- Apply to all untrusted input.
Memory trick: Validate and Sanitize: Filter out the bad stuff.
OAuth 2.0 Access Token
Flip cardA credential that represents an authorization granted by the resource owner to the client. It is typically a string (often a JWT) used by the client to make authenticated requests to a protected resource on behalf of the resource owner.
- Issued after successful authentication.
- Authorizes access to protected resources.
- Often a JWT, digitally signed for integrity.
Memory trick: OAuth is for authorization after login, SAML for SSO, Basic for simple creds.
Docker Security Best Practices
Flip cardDocker security best practices aim to minimize the attack surface of containerized applications by limiting privileges, reducing image size, and securing configuration.
- Use minimal base images.
- Run as a non-root user.
- Implement multi-stage builds.
- Scan images for vulnerabilities.
Memory trick: Small, unprivileged containers are secure containers.
Kubernetes Role
Flip cardA Kubernetes RBAC object that defines a set of permissions within a specific namespace. It specifies allowed verbs (actions) on resources (e.g., pods, deployments) within that namespace.
- Namespace-scoped permissions.
- Defines allowed actions on resources.
- Bound to users/groups/service accounts via RoleBinding.
Memory trick: Roles define permissions, Bindings assign them; Cluster for global, Role for namespace.
Input Validation and Sanitization
Flip cardThe process of checking user-supplied data to ensure it conforms to expected formats and removing or escaping potentially malicious characters to prevent injection attacks.
- Crucial for preventing Cross-Site Scripting (XSS) and SQL Injection.
- Validation ensures data is correct and complete.
- Sanitization cleans or escapes data to remove harmful content.
Memory trick: Verify and clean all incoming data.
Docker Container
Flip cardA lightweight, standalone, executable package of software that includes everything needed to run an application: code, runtime, system tools, system libraries and settings.
- Ensures consistent environments from dev to prod.
- Provides process isolation from the host.
- More lightweight than Virtual Machines.
Memory trick: Containers ship code consistently, VMs virtualize everything.
Continuous Integration (CI)
Flip cardContinuous Integration is a development practice where developers frequently merge their code changes into a central repository, after which automated builds and tests are run.
- Frequent code merges.
- Automated builds.
- Automated tests (unit, integration, static analysis).
- Early detection of defects.
Memory trick: CI integrates and tests, CD delivers, CDep deploys.
Secrets Management Best Practices
Flip cardSecrets management involves securely storing, retrieving, and auditing sensitive information (e.g., API keys, passwords) to prevent exposure and unauthorized access.
- Never commit secrets to source control.
- Use environment variables for simple cases.
- Prefer dedicated secrets management services.
- Rotate secrets regularly.
Memory trick: Keep keys out of code, inject them securely.
Data at Rest Encryption
Flip cardData at rest encryption is the cryptographic protection of data when it is stored on non-volatile media, such as databases, file systems, or storage devices.
- Protects data on disk, in databases, or backups.
- Renders data unreadable without the decryption key.
- Crucial for compliance and data breach mitigation.
- Different from data in transit encryption.
Memory trick: Resting data needs encryption for peace of mind.
Comprehensive Data Encryption
Flip cardComprehensive data encryption involves applying strong cryptographic methods to protect data across all its states: at rest (stored) and in transit (over networks).
- Data at Rest: AES-256 is a strong standard.
- Data in Transit: TLS 1.3 (or 1.2) is the current standard.
- Ensures confidentiality and integrity.
- Critical for regulatory compliance (e.g., PCI DSS, GDPR).
Memory trick: AES rests, TLS travels; together they're strong.
JWT for Authorization
Flip cardJSON Web Tokens (JWTs) can carry claims (e.g., roles, scopes) that an API uses to determine if an authenticated client has permission to access a resource or perform an action.
- Stateless authorization.
- Claims define permissions.
- API validates token signature and claims.
- Issued after successful authentication.
Memory trick: JWT claims access; others are too simple or cumbersome.
Kubernetes Secrets
Flip cardKubernetes Secrets are objects that store sensitive data, such as passwords, OAuth tokens, and SSH keys, securely within a Kubernetes cluster.
- Designed for confidential data.
- Can be mounted as files or environment variables.
- Base64 encoded by default, but can be encrypted at rest with proper configuration.
Memory trick: Secrets secure sensitive stuff, not just plain text maps.
Mutual TLS (mTLS) Handshake
Flip cardMutual TLS (mTLS) is a security protocol where both the client and server authenticate each other using X.509 digital certificates during the TLS handshake.
- Both client and server present certificates.
- Ensures mutual authentication.
- Adds 'Certificate Request' and 'Client Certificate' steps to standard TLS.
- Provides strong identity verification for microservices.
Memory trick: Both sides say 'Hello', then exchange IDs, then verify, then keys.
Data Encryption at Rest
Flip cardThe practice of encrypting data when it is stored on any persistent storage medium (e.g., hard drives, databases, cloud storage). It protects data from unauthorized access if the storage device is compromised.
- Protects data on storage mediums.
- Renders data unreadable without decryption key.
- Crucial for sensitive data compliance.
Memory trick: At rest is on disk, in transit is on wire, in use is in memory.
Service Mesh
Flip cardA service mesh is a dedicated infrastructure layer that handles inter-service communication, providing capabilities like traffic management, observability, security (e.g., mTLS), and policy enforcement without modifying application code.
- Manages inter-service communication.
- Uses sidecar proxies.
- Provides traffic management, security, observability.
- Decouples application logic from network concerns.
Memory trick: Mesh manages all service traffic, like a smart network.
Docker Multi-Stage Builds
Flip cardMulti-stage builds in Dockerfiles allow you to create smaller, more secure images by using separate build stages to compile code and then copying only the essential runtime artifacts to a final, lean image.
- Reduces final image size significantly.
- Improves security by removing build dependencies.
- Optimizes layer caching for faster rebuilds.
- Uses multiple `FROM` instructions.
Memory trick: Multi-stage: build then trim, for a lean, mean image.
OAuth 2.0 Bearer Token Usage
Flip cardAn OAuth 2.0 Bearer token is a security token that grants access to protected resources. It must be included in the HTTP 'Authorization' header in the format `Authorization: Bearer <access_token>`.
- Used for authorization in API requests.
- Must be sent in the `Authorization` HTTP header.
- Uses the `Bearer` scheme.
- API validates token for authenticity and permissions.
Memory trick: Token's fine, but the envelope's wrong.
NETCONF Operational Data
Flip cardNETCONF allows programmatic retrieval of operational state data from network devices, providing structured access to real-time information defined by YANG models.
- Retrieves real-time operational state.
- Uses YANG models for data structure.
- More granular and reliable than CLI parsing.
- Accessible via `get` or `get-config` RPCs depending on data type.
Memory trick: Retrieve operational data with structured protocols, not CLI.
NETCONF <validate> operation
Flip cardA NETCONF operation that checks the syntax and semantics of configuration data in a specified datastore (e.g., candidate) against device rules without applying the changes.
- Requires the ':validate' capability to be advertised by the device.
- Used to preemptively identify configuration errors.
- Does not modify the device's running configuration.
Memory trick: Think of drafting an email and spell-checking it before hitting send.
YANG Data Model
Flip cardYANG (Yet Another Next Generation) is a data modeling language used to define the structure, semantics, and constraints of configuration data, state data, RPCs, and notifications for network devices.
- Defines schema for network configurations.
- Used with NETCONF and RESTCONF.
- Standardized by IETF.
- Language-agnostic.
Memory trick: YANG models the NETwork's CONFiguration structure.
NETCONF <get> Operation
Flip cardThe NETCONF <get> operation is used to retrieve configuration data and/or operational state data from a network device. It queries the device's current state and configuration, typically from the running datastore, without making any changes.
- Retrieves config and operational state.
- Non-modifying operation.
- Queries current device state.
- Uses XPath for filtering.
Memory trick: GET 'GLOBAL' data: config AND state.