CompTIA DataSys+ (DS0-001)Database DeploymentEasy

A database administrator is planning to deploy a new PostgreSQL database server on a Linux host. The application requires that only connections originating from a specific subnet (192.168.1.0/24) are allowed to access the database. Which configuration file and setting should the administrator modify to enforce this network access control?

  1. Apostgresql.conf; listen_addresses
  2. Bpostgresql.conf; max_connections
  3. Cpg_hba.conf; host
  4. Dpg_ident.conf; map
Show answer & explanation

Correct answer: C. pg_hba.conf; host

The pg_hba.conf file (host-based authentication) is used to control client authentication and access to PostgreSQL databases. The 'host' entry within this file allows specifying allowed IP ranges and authentication methods.

Why the other options are wrong

  • A. listen_addresses in postgresql.conf controls which network interfaces PostgreSQL listens on, not which clients can connect.
  • B. max_connections controls the number of concurrent connections, not network access control.
  • D. pg_ident.conf is used for identity mapping, not for network access control by IP.

PostgreSQL pg_hba.conf

The PostgreSQL Host-Based Authentication (pg_hba.conf) file controls which hosts are allowed to connect to the database, and how they must authenticate.

  • It's a critical security configuration file.
  • Defines connection rules based on host, database, user, and authentication method.
  • Read in order, first match applies.

Memory trick: Host-Based Authentication is the Gatekeeper for PostgreSQL.

More Database Deployment questions