C100DBA Server Administration Practice Question
When enabling access control on a production sharded cluster, what is the most secure method for ensuring internal authentication between cluster components such as mongos and mongod instances?
⚠ Common exam trap
Many candidates default to simpler keyfiles because they are easier to configure, incorrectly assuming keyfiles offer equivalent security to X.509 certificates in high-security production environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploying X.509 certificates for member authentication.
Internal authentication ensures that only trusted components can join the cluster and communicate with each other. While keyfiles are common, X.509 certificates provide a higher level of security by utilizing a Certificate Authority (CA) and providing stronger identity verification. This is standard practice in high-security environments where protecting the internal traffic between nodes is as vital as client-to-server security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a shared keyfile with 600 permissions.
Why it's wrong here
Keyfiles are a valid form of internal authentication, but they are considered less secure than X.509 certificates. They rely on a shared secret across all nodes, which is harder to rotate and manage at scale. In a high-security context, certificates are preferred over simple shared strings for component identification.
- ✗
Enabling SCRAM-SHA-256 for all administrative users.
Why it's wrong here
SCRAM is an authentication mechanism used for client-to-server communication, not primarily for internal cluster member-to-member authentication. While it secures user access, it does not address the requirement of ensuring that a rogue mongod instance cannot join the sharded cluster and start receiving data from the balancer.
- ✗
Configuring LDAP authorization for the __system user.
Why it's wrong here
LDAP is typically used for external user authentication and mapping groups to roles, rather than the internal heartbeat and data synchronization traffic between nodes. Internal cluster communication relies on specific mechanisms like keyfiles or X.509 to establish trust before any user-level authorization can occur within the database.
- ✓
Deploying X.509 certificates for member authentication.
Why this is correct
X.509 certificate authentication is the most robust method for internal cluster security. It uses a trusted Certificate Authority to verify the identity of each node. This prevents unauthorized nodes from joining the cluster and allows for easier certificate rotation and better compliance with modern security standards in enterprise environments.
About these practice questions
Courseiva writes every C100DBA question from scratch — 222 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official MongoDB exam blueprint
This C100DBA practice question is part of Courseiva's free MongoDB certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C100DBA exam.