CompTIA DataSys+ (DS0-001)Database DeploymentMedium
A database administrator is deploying a new PostgreSQL database server. As part of the post-installation configuration, the administrator needs to ensure that only specific client IP addresses can connect to the database. Which configuration file and parameter should be modified in PostgreSQL?
- Apostgresql.conf, by setting `max_connections`
- Bpostgresql.conf, by setting `listen_addresses`
- Cpg_ident.conf, by mapping `system_user` to `database_user`
- Dpg_hba.conf, by adding `host` entries
Show answer & explanationAnswer & explanation
Correct answer: D. pg_hba.conf, by adding `host` entries
`pg_hba.conf` (host-based authentication) is the primary configuration file in PostgreSQL used to control client authentication and access based on IP address, database, and user.
Why the other options are wrong
- A. `max_connections` in `postgresql.conf` controls the maximum number of concurrent connections, not client IP access.
- B. `listen_addresses` in `postgresql.conf` controls which network interfaces PostgreSQL listens on, not which client IPs can connect.
- C. `pg_ident.conf` is used for user identity mapping, not for restricting client IP addresses.
PostgreSQL Client Authentication
The process by which PostgreSQL verifies the identity of a connecting client and determines if it is allowed to access the database.
- Controlled primarily by the `pg_hba.conf` file.
- Entries specify connection type, database, user, IP address/range, and authentication method.
- Rules are processed in order, with the first matching rule applied.
Memory trick: HBA: Host-Based Access, the bouncer for your database.