CompTIA DataSys+ (DS0-001)Database DeploymentMedium

A database administrator is deploying a new PostgreSQL database server. As part of the post-installation configuration, the administrator needs to ensure that only specific client IP addresses can connect to the database. Which configuration file and parameter should be modified in PostgreSQL?

  1. Apostgresql.conf, by setting `max_connections`
  2. Bpostgresql.conf, by setting `listen_addresses`
  3. Cpg_ident.conf, by mapping `system_user` to `database_user`
  4. Dpg_hba.conf, by adding `host` entries
Show answer & explanation

Correct answer: D. pg_hba.conf, by adding `host` entries

`pg_hba.conf` (host-based authentication) is the primary configuration file in PostgreSQL used to control client authentication and access based on IP address, database, and user.

Why the other options are wrong

  • A. `max_connections` in `postgresql.conf` controls the maximum number of concurrent connections, not client IP access.
  • B. `listen_addresses` in `postgresql.conf` controls which network interfaces PostgreSQL listens on, not which client IPs can connect.
  • C. `pg_ident.conf` is used for user identity mapping, not for restricting client IP addresses.

PostgreSQL Client Authentication

The process by which PostgreSQL verifies the identity of a connecting client and determines if it is allowed to access the database.

  • Controlled primarily by the `pg_hba.conf` file.
  • Entries specify connection type, database, user, IP address/range, and authentication method.
  • Rules are processed in order, with the first matching rule applied.

Memory trick: HBA: Host-Based Access, the bouncer for your database.

More Database Deployment questions