CompTIA DataSys+ (DS0-001)Database DeploymentMedium
A database administrator is deploying a new PostgreSQL database server on a Linux system. After installation, the administrator needs to ensure that only the database server itself can access the PostgreSQL port (5432) from the local machine, and no external connections are allowed. Which of the following configuration changes would BEST achieve this security requirement?
- AChange the default PostgreSQL port from 5432 to a random high-numbered port.
- BImplement an `iptables` rule to drop all incoming traffic to port 5432.
- CSet `listen_addresses = '*'` in `postgresql.conf` and configure `pg_hba.conf` to deny all remote access.
- DSet `listen_addresses = 'localhost'` in `postgresql.conf`.
Show answer & explanationAnswer & explanation
Correct answer: D. Set `listen_addresses = 'localhost'` in `postgresql.conf`.
Setting `listen_addresses = 'localhost'` in `postgresql.conf` configures the PostgreSQL server to only listen for connections on the loopback interface (127.0.0.1). This effectively prevents any external connections while still allowing local applications or clients on the same machine to connect.
Why the other options are wrong
- A. Changing the default port provides 'security through obscurity' but does not prevent determined attackers from finding the new port and attempting connection, and does not restrict access to local-only.
- B. Implementing an `iptables` rule to drop all incoming traffic to port 5432 would block all connections, including those from local applications on the same server, which is not desired.
- C. Setting `listen_addresses = '*'` allows listening on all interfaces, which is insecure if not paired with very specific `pg_hba.conf` rules that can be complex to get right.
PostgreSQL listen_addresses
A PostgreSQL configuration parameter in `postgresql.conf` that determines which IP addresses the database server listens on for incoming client connections.
- Default is often `localhost` or `*` (all interfaces).
- `localhost` restricts connections to the local machine only.
- Requires a restart to take effect after modification.
Memory trick: Listen addresses control the database's open door.