Courseiva

CCNA Server Administration Questions

26 questions · Server Administration topic · All types, answers revealed

1
MCQmedium

A security audit requires that sensitive document data contained in query parameters must not be written to the MongoDB system logs. Which server configuration setting should be enabled?

A.security.authorization: enabled
B.security.redactClientLogData: true
C.operationProfiling.mode: off
D.storage.wiredTiger.collectionConfig.blockCompressor: zlib
AnswerB

Enabling 'redactClientLogData' ensures that the mongod process removes potentially sensitive information from log messages before they are written to disk. This specifically targets the data within commands, such as query filters or document fields, replacing them with placeholders to prevent data leaks through log files.

Why this answer

Security administration involves protecting data at rest, in transit, and in logs. Log redaction is a feature that prevents sensitive information, like the contents of a 'find' filter or an 'insert' document, from appearing in the server logs. This is essential for compliance with regulations like GDPR, HIPAA, or PCI-DSS.

Exam trap

Candidates often confuse log redaction configuration parameters with general verbosity settings or audit filters, failing to recall the exact setting name.

2
MCQmedium

A DBA executes 'mongodump --oplog' against a primary node in a replica set. What is the specific purpose of the --oplog flag in this administrative context?

A.It exports the entire oplog collection into a separate BSON file.
B.It captures changes during the dump for point-in-time consistency.
C.It speeds up the dump process by reading from the oplog instead of collections.
D.It automatically compresses the output using the oplog's compression ratio.
AnswerB

The --oplog flag is essential for creating a consistent snapshot of a running database. It ensures that the backup reflects a single point in time by including all writes that occurred between the start and end of the dump, which are then applied during restoration to resolve inconsistencies.

Why this answer

When backing up a live database, data changes while the backup is running. The '--oplog' flag tells mongodump to capture all operations that occur during the dump process. This allows the DBA to restore the database to a consistent state by replaying those operations during the 'mongorestore' process, ensuring data integrity.

Exam trap

Candidates often think --oplog is used for performance or speed, failing to understand its primary purpose is ensuring point-in-time data consistency across the backup.

3
MCQmedium

An administrator wants to audit all authentication attempts on a MongoDB Enterprise instance. Which feature should be configured to track these events?

A.Enable 'logLevel' to 5 in the configuration.
B.Set up an 'auditLog' destination in the YAML configuration.
C.Use the 'mongostat' utility.
D.Enable 'net.ssl.mode' to 'requireSSL'.
AnswerB

The 'auditLog' configuration is the designated feature for recording database activities, including authentication successes and failures. By specifying a destination like a file or syslog and defining the filter, administrators can ensure that all relevant security events are recorded in a structured JSON format for easy analysis.

Why this answer

The auditing system in MongoDB Enterprise is essential for compliance and security monitoring. By configuring the audit log to capture events related to authentication and authorization, administrators gain visibility into who is accessing the database and what actions they are performing. This is crucial for forensic analysis, detecting unauthorized access attempts, and satisfying regulatory requirements that mandate detailed record-keeping for all database interactions within a production environment.

Exam trap

Examinees frequently confuse profiling with auditing, incorrectly selecting the database profiler when the question specifically demands tracking security and authentication events.

4
Multi-Selectmedium

Which TWO of the following are valid reasons to use an arbiter in a MongoDB replica set?

Select 2 answers
A.To increase the read throughput of the replica set.
B.To break a tie in elections for replica sets with an even number of nodes.
C.To maintain a copy of the data for disaster recovery.
D.To achieve a majority of votes with minimum hardware costs.
E.To act as a hidden node for analytical queries.
AnswersB, D

In an even-numbered replica set, an arbiter provides the necessary third vote to reach a majority during an election. This prevents the cluster from being unable to elect a primary, ensuring that the system remains highly available even if one of the two data-bearing nodes goes offline unexpectedly.

Why this answer

Arbiters are lightweight processes that participate in elections but do not hold data. They are a cost-effective way to achieve a majority for elections in small replica sets. Understanding when to use an arbiter is crucial for designing a cost-efficient and highly available architecture, especially when deploying in multiple zones where adding a full data-bearing node might be cost-prohibitive or unnecessary due to data redundancy requirements.

Exam trap

Candidates incorrectly assume arbiters store a backup copy of the data or improve read performance, misunderstanding their sole purpose of breaking election ties.

5
MCQeasy

A database is experiencing high latency. You run 'mongotop 5'. What specific insight does this provide compared to 'mongostat' for server administration?

A.Time spent by each collection on read and write operations.
B.A list of the longest-running queries currently in the system.
C.The amount of disk space consumed by each database on the server.
D.The memory distribution between the data and index caches.
AnswerA

The 'mongotop' utility provides a real-time view of the amount of time the mongod instance spends reading from and writing to each collection. This is invaluable for identifying 'hot' collections that may need better indexing, sharding, or schema redesign to alleviate performance bottlenecks on the server.

Why this answer

While mongostat gives a high-level view of server-wide operations and memory, mongotop provides a granular look at where the storage engine is spending its time. It breaks down read and write time by collection, allowing the DBA to identify which specific table is causing the most load on the system.

Exam trap

Examinees often confuse mongotop with mongostat, mistakenly believing mongotop provides system-wide resource utilization metrics like CPU and memory instead of collection-level timing.

6
MCQeasy

A server has multiple network interfaces including a public IP and a private management IP. How should the 'net.bindIp' configuration be managed to follow security best practices?

A.Set 'net.bindIp' to '0.0.0.0' to allow connections from any interface.
B.Leave 'net.bindIp' blank to let MongoDB choose the fastest interface.
C.Use the 'net.bindIpAll' setting to simplify the configuration.
D.List only the loopback address and the specific internal IP addresses.
AnswerD

Explicitly listing the internal IPs and '127.0.0.1' ensures that the database only listens for traffic on trusted networks. This administrative control prevents external actors on the public interface from even attempting to connect to the database, providing a critical layer of defense-in-depth for the environment.

Why this answer

Binding MongoDB to the correct network interfaces is a fundamental security task. By default, older versions might bind to all interfaces, exposing the database to the public internet. Best practices dictate binding only to the loopback address and specific internal management or application network IPs to minimize the attack surface.

Exam trap

Candidates often default to binding to 0.0.0.0, which exposes the database to all network interfaces, including public ones, creating a significant security vulnerability by allowing unauthorized remote access.

7
MCQhard

A DBA is configuring a replica set with three members: one primary and two secondaries. The DBA wants to ensure that a write concern of { w: 'majority' } is acknowledged only after the write has been applied to a majority of voting members and has been written to the on-disk journal on those members. Which write concern should the DBA use?

A.{ w: 'majority' }
B.{ w: 2, j: true }
C.{ w: 'majority', j: true }
D.{ w: 'majority', j: false }
AnswerC

This write concern combines w: 'majority' with j: true. The w: 'majority' ensures that the write is acknowledged by a majority of voting members in the replica set. The j: true option ensures that the write is written to the on-disk journal before acknowledgment. Together, they meet the requirement: the write is acknowledged only after being applied to a majority of voting members and journaled on those members. This is the correct configuration for durability and consistency. (Explanation length: 65 words)

Why this answer

The requirement is for a write concern that ensures acknowledgment after a majority of voting members have applied the write and written it to the on-disk journal. The write concern { w: 'majority', j: true } achieves both: w: 'majority' dynamically requires a majority of voting members, and j: true forces journaling on those members before acknowledgment. Using a fixed w: 2 may not adapt to membership changes, and omitting j: true does not guarantee journaling. (Explanation length: 65 words)

Exam trap

The trap here is assuming that w: 'majority' alone guarantees journaling, or that w: 2 is always equivalent to majority even when replica set membership changes.

8
MCQeasy

A DBA needs to grant a new application service account the ability to read and write data in any database except the admin database on a MongoDB 6.0 replica set. The account should not be able to perform administrative actions such as managing users or shutting down the server. Which built-in role should the DBA assign?

A.root
B.dbOwner on each application database
C.readWriteAnyDatabase
D.readWrite on the admin database
AnswerC

The readWriteAnyDatabase role grants read and write privileges on all databases except the admin, local, and config databases. It does not include administrative privileges such as user management or shutdown. This matches the requirement exactly: the service account can read and write application data but cannot perform administrative actions, and it is restricted from the admin database.

Why this answer

The readWriteAnyDatabase built-in role provides read and write access to all non-system databases without granting administrative privileges. It is the least-privilege role that satisfies the requirement. The other roles either grant excessive privileges, are scoped to a single database, or do not provide the needed access across all application databases.

Exam trap

The trap here is assuming that any read/write role includes administrative rights, or that dbOwner is needed for full access, when readWriteAnyDatabase is sufficient and safer.

9
MCQhard

When enabling access control on a production sharded cluster, what is the most secure method for ensuring internal authentication between cluster components such as mongos and mongod instances?

A.Using a shared keyfile with 600 permissions.
B.Enabling SCRAM-SHA-256 for all administrative users.
C.Configuring LDAP authorization for the __system user.
D.Deploying X.509 certificates for member authentication.
AnswerD

X.509 certificate authentication is the most robust method for internal cluster security. It uses a trusted Certificate Authority to verify the identity of each node. This prevents unauthorized nodes from joining the cluster and allows for easier certificate rotation and better compliance with modern security standards in enterprise environments.

Why this answer

Internal authentication ensures that only trusted components can join the cluster and communicate with each other. While keyfiles are common, X.509 certificates provide a higher level of security by utilizing a Certificate Authority (CA) and providing stronger identity verification. This is standard practice in high-security environments where protecting the internal traffic between nodes is as vital as client-to-server security.

Exam trap

Many candidates default to simpler keyfiles because they are easier to configure, incorrectly assuming keyfiles offer equivalent security to X.509 certificates in high-security production environments.

10
MCQhard

Refer to the exhibit. What is the implication of setting the priority of n2 to 0?

A.n2 will be excluded from the voting process entirely.
B.n2 will never become the primary node.
C.n2 will stop replicating data from the primary.
D.n2 will be removed from the replica set automatically.
AnswerB

Priority 0 members are ineligible to become primary. This configuration is explicitly used to prevent a specific node from becoming the primary, ensuring that only nodes with higher priority values can take on the primary role during an election, which is useful for regional failover or specialized hardware setups.

Why this answer

A priority of 0 designates a member as a 'passive' node. It can never become the primary, even if all other nodes are down. This configuration is often used for nodes in different data centers to prevent them from taking over as primary, which could cause latency issues for applications.

Understanding this is vital for controlling election behavior and ensuring that the primary node is always located in a preferred, low-latency environment for the application workload.

Exam trap

Candidates often mistake a priority of 0 to mean the node cannot be read from or that it is completely offline, forgetting it only prevents it from becoming primary.

11
MCQmedium

In a dedicated server environment, what is the primary reason an administrator would choose to manually decrease the 'storage.wiredTiger.engineConfig.cacheSizeGB' below the default value?

A.To increase the speed of BSON document compression.
B.To allow more memory for the filesystem cache to store indexes.
C.To reduce the size of the oplog on the primary node.
D.To accommodate other processes or containers running on the same host.
AnswerD

The most common reason to decrease the cache size is to ensure that other applications, such as monitoring agents, backup tools, or other database instances, have sufficient RAM to function. Without this adjustment, the mongod process might consume too much memory, leading to OOM (Out of Memory) kills.

Why this answer

Effective memory management is the core of MongoDB server administration. While the default cache size is usually optimal, administrators must adjust it when the server hosts other memory-intensive processes. If the operating system or other tools are starved for RAM, it can lead to excessive swapping and system instability, which harms database performance.

Exam trap

Candidates assume the default cache size is always best, ignoring that on shared hosts, MongoDB's aggressive memory usage can trigger OS-level swapping, severely degrading overall system performance.

12
MCQeasy

A MongoDB DBA is asked to ensure that the mongod process on a Linux server automatically restarts if it crashes. The server uses systemd. Which command should the DBA run to enable this behavior?

A.systemctl enable mongod
B.Run mongod --fork --logpath /var/log/mongodb/mongod.log
C.systemctl restart mongod
D.Edit the mongod.service unit file to include Restart=always, then run systemctl daemon-reload and systemctl restart mongod
AnswerD

This approach correctly modifies the systemd service unit for mongod to include the Restart=always directive, which tells systemd to restart the service if it exits, regardless of the exit status. After editing the unit file, you must run systemctl daemon-reload to reload the systemd manager configuration, and then restart the service to apply the change. This ensures that if mongod crashes, systemd will automatically restart it. This is the recommended method for achieving automatic restart on failure. (Explanation length: 68 words)

Why this answer

To enable automatic restart of mongod on failure when using systemd, you must modify the service unit file to include Restart=always (or Restart=on-failure). After editing, run systemctl daemon-reload to reload the configuration, and then restart the service. The systemctl enable command only ensures start at boot, not restart on crash.

The other commands are either manual restarts or do not provide automatic restart functionality. (Explanation length: 65 words)

Exam trap

The trap here is assuming that systemctl enable mongod also enables automatic restart on failure, when it only enables start at boot.

13
Multi-Selecthard

Which THREE metrics provided by the 'mongostat' utility are most helpful for identifying a performance bottleneck caused by a high volume of concurrent write operations?

Select 3 answers
A.insert
B.getmore
C.qw
D.vsize
E.update
AnswersA, C, E

The 'insert' column shows the number of insert operations per second. A high value in this column directly indicates a high write load. For a DBA, monitoring this metric alongside others helps determine if the current hardware and storage engine configuration are sufficient for the application's write throughput requirements.

Why this answer

Monitoring server health via mongostat is a daily task for a DBA. High write volumes are best identified by looking at the actual operation counts (insert, update, delete) and the state of the write queue. If the 'qw' (queue write) count is high, it indicates that the storage engine cannot keep up with the incoming write requests.

Exam trap

Candidates often select metrics like 'res' or 'faults' which relate to memory rather than the write queue, missing the direct correlation between 'qw' and write congestion.

14
MCQhard

Refer to the exhibit. The MongoDB process has crashed due to a storage engine error. What is the most immediate administrative action required to restore service?

A.Run 'db.repairDatabase()' via the shell to free up space.
B.Clear the 'journal' directory files to recover space.
C.Expand the disk volume and restart the mongod process.
D.Modify the 'storage.wiredTiger.engineConfig.cacheSizeGB' setting in the config file.
AnswerC

Expanding the underlying disk volume provides the necessary storage capacity for the database to function. Once additional space is available, the WiredTiger engine can successfully initialize, perform recovery using the journal, and resume normal operations. This is the only safe way to resolve an 'out of space' failure.

Why this answer

The error 'No space left on device' indicates that the disk partition hosting the 'dbPath' directory is completely full. This prevents WiredTiger from writing data, metadata, or logs, causing an immediate shutdown to prevent data corruption. Administrators must free up space on the disk or extend the partition before restarting the service, as the database cannot recover or accept new writes without sufficient storage capacity to manage its internal files.

Exam trap

Exams often lure candidates into attempting a database repair operation first, failing to realize that full disks require immediate space freeing before any recovery command can execute.

15
MCQmedium

During a peak load period, the 'page faults' metric in mongostat increases significantly. What is the most likely administrative cause related to server resources?

A.The working set exceeds the available physical RAM.
B.The number of concurrent connections has reached the 'maxConns' limit.
C.The CPU is throttled due to excessive BSON serialization.
D.The journaling frequency is set too high for the disk subsystem.
AnswerA

When the data and indexes required for active operations no longer fit in the WiredTiger cache and OS filesystem cache, MongoDB must fetch data from disk. This process is much slower than memory access and is recorded as a page fault, leading to increased latency and decreased throughput.

Why this answer

Page faults occur when the mongod process attempts to access data that is not currently in the physical RAM (resident memory). While some page faults are normal, a sudden spike usually indicates that the 'working set' (the data and indexes accessed most frequently) has grown larger than the available RAM, forcing frequent disk reads.

Exam trap

Candidates often confuse 'page faults' in mongostat with OS-level memory paging to disk swap space, forgetting that in MongoDB it specifically refers to documents read from disk files because they are missing from resident RAM.

16
MCQmedium

A DBA needs to automate log rotation on a Linux-based MongoDB server without restarting the mongod process. Which signal or command should be used to ensure the current log file is archived and a new one is started?

A.Send a SIGHUP signal to the mongod PID.
B.Run the 'rotateLogs' command from the admin database.
C.Send a SIGUSR1 signal to the mongod PID.
D.Update the 'systemLog.path' in the YAML config and run 'mongod --reconfig'.
AnswerC

Sending a SIGUSR1 signal to the mongod process triggers the server to close the current log file, rename it with a timestamp, and open a new log file. This is the standard operational procedure for Linux environments to manage log growth without interrupting database services or requiring a full restart.

Why this answer

Log rotation is a critical administrative task that prevents disk space exhaustion and facilitates log analysis. Using the SIGUSR1 signal on Linux systems allows the administrator to rotate logs without any downtime or server restarts. This ensures continuous availability while maintaining manageable file sizes for diagnostic purposes, which is essential for long-term server health and compliance with retention policies.

Exam trap

Candidates often suggest restarting the service to rotate logs, which is unnecessary and causes avoidable downtime, failing to recognize that signal-based rotation is the standard administrative practice.

17
MCQmedium

You are monitoring a MongoDB replica set and notice that the replication lag on a secondary is increasing steadily. You suspect that the secondary is unable to keep up with the write load. Which administrative action should you take first to diagnose the issue?

A.Check the output of rs.printSlaveReplicationInfo() to see the lag and the time of the last oplog entry.
B.Restart the secondary to see if the lag clears.
C.Run db.currentOp() on the secondary to see long-running operations.
D.Increase the oplog size on the primary to allow more time for the secondary to catch up.
AnswerA

rs.printSlaveReplicationInfo() provides a quick summary of replication lag for each secondary, including how far behind the secondary is in seconds and the timestamp of its last oplog entry. This is the first step to confirm the lag and identify which secondary is affected. It helps determine if the lag is due to network, disk I/O, or other factors.

Why this answer

The first step in diagnosing replication lag is to quantify it and check the secondary's progress. rs.printSlaveReplicationInfo() provides the lag in seconds and the timestamp of the last oplog entry applied, helping you understand the severity and whether the secondary is making progress. Other actions like restarting or resizing the oplog are premature without diagnosis.

Exam trap

The trap here is jumping to corrective actions like restarting the secondary or resizing the oplog before confirming and understanding the replication lag.

18
MCQeasy

Which command is used to verify the current replica set configuration and the state of all members?

A.db.serverStatus()
B.rs.conf()
C.rs.status()
D.db.isMaster()
AnswerC

The 'rs.status()' command returns a document that reports the status of the replica set, including the role of the current node, the status of other members, and critical information such as lag. This is the standard command for monitoring the health and state of a MongoDB cluster.

Why this answer

Checking the replica set status is a routine administrative task to ensure high availability and data consistency. The 'rs.status()' command provides a comprehensive view of the cluster, including the state of every member, the current primary, and the sync lag. This command is the primary diagnostic tool for verifying that the replica set is healthy and that all nodes are correctly communicating with each other.

Exam trap

Test-takers frequently mistake rs.status() for rs.conf(), confusing the runtime state and member health of a replica set with its static configuration document settings.

19
MCQeasy

A developer reports slow queries on a specific collection. You decide to enable the database profiler to capture only queries taking longer than 200ms. Which command configuration achieves this?

A.db.setProfilingLevel(1, { slowms: 200 })
B.db.setProfilingLevel(2, { slowms: 200 })
C.mongod --profile 200 --slowms 1
D.db.adminCommand({ profile: 0, slowms: 200 })
AnswerA

Profiling level 1 instructs MongoDB to log operations that exceed the specified 'slowms' threshold. Setting this to 200 ensures that only queries slower than 200 milliseconds are recorded in the 'system.profile' collection, providing a targeted dataset for performance tuning without overwhelming the server with logging overhead.

Why this answer

The database profiler is an essential administrative tool for diagnosing performance issues. Profiling level 1 is used to capture 'slow' operations without the overhead of capturing every single request (level 2). Setting the 'slowms' threshold to 200 allows the DBA to filter out expected noise and focus on the problematic operations.

Exam trap

Candidates often select the wrong profiling level, confusing level 2 (which captures everything and causes significant performance degradation) with level 1 (the appropriate level for capturing slow queries only).

20
MCQhard

Refer to the exhibit. An administrator attempts to recover a corrupted standalone mongod instance using the --repair flag. Based on the error log output, what is the most appropriate next step for the administrator?

A.Run the --repair command again with the --wiredTigerEngineConfig option.
B.Delete the mongod.lock file and restart the server normally.
C.Restore the data files from the most recent known-good backup.
D.Manually edit the WiredTiger.wt file to fix the offset error.
AnswerC

Since the --repair process failed with a critical WiredTiger read error, the data files are too corrupted for the built-in tools to salvage. The most reliable and standard administrative response is to wipe the corrupted directory and restore the database from a verified backup to ensure consistency.

Why this answer

The --repair flag is a last-resort tool that attempts to salvage data from corrupted files, but it cannot fix severe filesystem or metadata corruption where blocks are missing or unreadable. The 'Short read' error indicates physical or logical corruption that WiredTiger cannot bypass. In this scenario, restoring from a known-good backup is the only reliable way to ensure data integrity.

Exam trap

Candidates often rely on --repair as a 'fix-all' solution, not realizing that severe corruption, such as short reads, indicates physical data loss that repair cannot resolve.

21
Multi-Selecthard

An administrator needs to create a restricted user for a third-party monitoring tool. The user must be able to perform backups and monitor server status but cannot read actual document data. Which TWO built-in roles should be combined?

Select 2 answers
A.readAnyDatabase
B.dbAdmin
C.backup
D.clusterMonitor
E.hostManager
AnswersC, D

The 'backup' role provides the minimal privileges required to use MongoDB backup tools. It allows the user to read the data for the purpose of backing it up but is designed to be used in conjunction with other roles to limit the user's ability to perform standard ad-hoc queries.

Why this answer

MongoDB's Role-Based Access Control (RBAC) allows for granular permission management. The 'backup' role provides the necessary privileges to use tools like mongodump without granting general read access to all collections. The 'clusterMonitor' role allows the user to run commands like 'serverStatus' and 'top', which are essential for monitoring performance.

Exam trap

Candidates often select roles like 'readAnyDatabase' or 'dbAdmin' which grant excessive permissions, failing to realize that 'backup' and 'clusterMonitor' provide sufficient access without exposing sensitive document data.

22
MCQmedium

When adding a new node to an existing replica set, what is the primary factor that determines how quickly the new member will be able to begin participating in elections?

A.The memory limit set in the configuration file.
B.The amount of data in the dataset and network bandwidth.
C.The number of users defined in the admin database.
D.The version of the MongoDB shell used.
AnswerB

The new member must copy the entire dataset from an existing member before it can apply the oplog to catch up. The time taken for this process is directly proportional to the total size of the data and the speed of the network connection between the nodes.

Why this answer

The speed at which a new replica set member becomes 'secondary' and ready to participate depends on the amount of data it must synchronize from an existing member. Initial sync involves cloning data and applying the oplog. Understanding this process is vital for capacity planning, as adding a large member can put significant I/O and network pressure on the current primary or secondaries, potentially impacting performance for existing application traffic during the synchronization process.

Exam trap

Candidates often guess hardware parameters like CPU speed or RAM size as the primary sync factor, ignoring that dataset volume and network transfer rates dictate initial sync duration.

23
MCQmedium

A MongoDB 6.0 replica set is experiencing performance issues during peak hours. The DBA notices that the primary is spending significant time on disk I/O. The DBA wants to identify which collections are generating the most disk reads and writes. Which administrative command should the DBA use?

A.db.currentOp()
B.mongotop
C.db.serverStatus()
D.db.collection.stats()
AnswerB

mongotop reports per-collection read and write activity over time. It shows how much time each collection spends on reads and writes, making it ideal for identifying which collections are causing high disk I/O. By running mongotop during peak hours, the DBA can pinpoint the collections that are the biggest contributors to disk load.

Why this answer

mongotop is designed to provide per-collection read and write statistics, showing how much time each collection spends on these operations. This directly answers the need to find collections generating the most disk I/O. The other tools either provide server-wide metrics, point-in-time operation lists, or static collection statistics that do not reflect active I/O.

Exam trap

The trap here is confusing server-wide I/O metrics with per-collection activity, or assuming that collection stats show real-time I/O when they only show size and structure.

24
MCQeasy

Which configuration file setting is used to specify the network interface and port that a mongod instance listens on?

A.systemLog
B.storage
C.net
D.processManagement
AnswerC

The 'net' section is the standard configuration block for network-related settings. It specifically contains 'port' to define the listening port and 'bindIp' to restrict the interfaces the server listens on, ensuring that the MongoDB instance can be correctly reached by applications and administrative tools in a network.

Why this answer

The 'net' section in the YAML configuration file provides granular control over how the MongoDB instance communicates over the network. Configuring the 'bindIp' and 'port' is a fundamental step in securing and reaching the database. Properly setting these parameters ensures that the server is accessible only on the intended interfaces, which is a critical security practice to prevent unauthorized access from untrusted networks or public interfaces.

Exam trap

Candidates often confuse the 'net' section with 'replication' or 'systemLog' sections, forgetting that network binding and port configuration are strictly under the 'net' header.

25
MCQmedium

What is the consequence of having a replica set with only two nodes and no arbiter?

A.The set will automatically double the voting power of the primary.
B.The replica set will be unable to elect a primary if one node fails.
C.The replica set will function normally, but writes will be slow.
D.The primary will become read-only while the secondary remains idle.
AnswerB

With two nodes, a majority is two. If one node fails, only one node remains, which is not a majority of the set. Consequently, the remaining node cannot become or remain a primary, and no new election can occur, effectively stopping all write operations for the application.

Why this answer

A replica set requires a majority of nodes to elect a primary. In a two-node set, a failure of one node makes it impossible to reach a majority, as one out of two is not greater than half. This design limitation is critical because it leads to the loss of a primary and the inability to elect a new one, resulting in a read-only database and complete outage for write operations.

Exam trap

Candidates assume that two nodes are sufficient for high availability, forgetting that a majority (quorum) of 2 is required, which cannot be achieved if one node fails.

26
MCQmedium

A MongoDB replica set has three members: a primary and two secondaries. The DBA needs to perform maintenance on the primary node without causing an election that could lead to data loss. The maintenance requires stopping the mongod process for 30 minutes. Which step should the DBA take first to ensure the primary steps down gracefully and a secondary takes over?

A.Run `rs.stepDown(600)` on the primary.
B.Run `db.shutdownServer()` on the primary.
C.Run `rs.freeze(600)` on the primary.
D.Run `rs.remove()` to remove the primary from the replica set.
AnswerA

The `rs.stepDown()` command forces the primary to step down and become a secondary, triggering an election. The argument 600 specifies the number of seconds the stepped-down member will remain a secondary before it can be elected primary again. This ensures that during the 30-minute maintenance, the original primary does not reclaim primacy, allowing a stable secondary to serve as primary.

Why this answer

To gracefully transfer primacy before maintenance, the DBA should use `rs.stepDown()`, which forces the primary to become a secondary and triggers an election. The optional argument specifies how long the stepped-down member remains ineligible for election, preventing it from immediately reclaiming primacy. This allows a secondary to take over and provides a stable primary during the maintenance window.

Exam trap

The trap here is confusing `rs.freeze()` with `rs.stepDown()`. Freezing a member prevents it from seeking election but does not force a current primary to step down.

Ready to test yourself?

Try a timed practice session using only Server Administration questions.