Courseiva
Server Administration →easyMultiple Choice

C100DBA Server Administration Practice Question

A server has multiple network interfaces including a public IP and a private management IP. How should the 'net.bindIp' configuration be managed to follow security best practices?

⚠ Common exam trap

Candidates often default to binding to 0.0.0.0, which exposes the database to all network interfaces, including public ones, creating a significant security vulnerability by allowing unauthorized remote access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

List only the loopback address and the specific internal IP addresses.

Binding MongoDB to the correct network interfaces is a fundamental security task. By default, older versions might bind to all interfaces, exposing the database to the public internet. Best practices dictate binding only to the loopback address and specific internal management or application network IPs to minimize the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set 'net.bindIp' to '0.0.0.0' to allow connections from any interface.

    Why it's wrong here

    Binding to '0.0.0.0' is highly insecure as it exposes the MongoDB instance to every network interface, including the public internet. This makes the server vulnerable to brute-force attacks and unauthorized access if firewall rules are misconfigured or absent, which is a common cause of data breaches.

  • ✗

    Leave 'net.bindIp' blank to let MongoDB choose the fastest interface.

    Why it's wrong here

    MongoDB does not 'choose' an interface based on speed. If the 'bindIp' setting is missing or blank in newer versions, it defaults to localhost (127.0.0.1). While secure, this would prevent any remote application servers from connecting, rendering the database inaccessible to the rest of the stack.

  • ✗

    Use the 'net.bindIpAll' setting to simplify the configuration.

    Why it's wrong here

    The 'bindIpAll' setting is equivalent to '0.0.0.0' and shares the same security risks. While it simplifies the configuration file, it ignores the principle of least privilege by exposing the database on networks where it is not needed, such as public-facing or untrusted management segments.

  • ✓

    List only the loopback address and the specific internal IP addresses.

    Why this is correct

    Explicitly listing the internal IPs and '127.0.0.1' ensures that the database only listens for traffic on trusted networks. This administrative control prevents external actors on the public interface from even attempting to connect to the database, providing a critical layer of defense-in-depth for the environment.

About these practice questions

One of 222 original C100DBA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official MongoDB exam blueprint

This C100DBA practice question is part of Courseiva's free MongoDB certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C100DBA exam.