◆ Apache Cassandra

Conduct security assessments and audits

This is real work, not a feature someone invented — it comes from real job ads and real questions people asked. Below are four ready AI prompts: get it done, make it easy for the next person to say yes to, work out the right move when you are stuck, and stop it coming back.

4prompts

The same task, four prompts

today's deadline · the next reviewer · the stuck moment · the pattern
AExecute — do the immediate taskGenerate a report listing all users in the 'production_cluster' with administrative privileges,…+
Generate a report listing all users in the 'production_cluster' with administrative privileges, including their last login time and any roles assigned.
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
BImprove — make it easier to acceptOur upcoming audit requires a comprehensive review of all access controls for the…+
Our upcoming audit requires a comprehensive review of all access controls for the 'customer_data' keyspace. I need to identify any users with write access who shouldn't have it, and confirm that all data in transit and at rest for this keyspace is encrypted. What's the most efficient way to gather this information and verify the encryption status for the auditors?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
CDecide — diagnose the stuck momentThe latest vulnerability scan just flagged an open JMX port on one of our Cassandra nodes,…+
Our recent vulnerability scan flagged an open JMX port on a Cassandra node, and I'm unsure if it's a false positive or a critical security risk.
The latest vulnerability scan just flagged an open JMX port on one of our Cassandra nodes, reporting it as a high-severity risk. I remember configuring authentication for JMX, but now I'm second-guessing if it's actually secure or if it's an unauthenticated backdoor. I'm afraid this could be a major breach point. I can't tell if the scan is being overly cautious or if we have a serious misconfiguration. What's the immediate step to verify the security of that JMX port, and how do I confirm it's not an active vulnerability?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?
DBecome — change the patternI'm constantly reacting to security audit findings for our Cassandra clusters, often…+
I often find myself scrambling to address security findings during audits because I haven't proactively monitored Cassandra's security posture.
I'm constantly reacting to security audit findings for our Cassandra clusters, often discovering misconfigurations or unpatched vulnerabilities that should have been caught earlier. It feels like I'm always playing catch-up, and it's a huge stress point before every audit. What habit should I change to proactively monitor and maintain the security posture of our Cassandra deployments, so I'm not blindsided by audit reports?
when the reply comes backPush once: ask it to sharpen the weakest part, and to say what it assumed. Helpful?

Questions people actually ask

honest answers, no sign-up

Every task here was seen in the real world. Someone doing the job named it, a real job ad asked for it, or a lot of people asked about it online.

If nothing real showed a task, it is not on the page. That is the whole rule.

They are the same job approached four ways, because what you need depends on where you are.

Get it done today. Make it easy for the next person to say yes to. Work out the right move when you are stuck. Learn the pattern so the job stops coming back.

For most of these jobs it can carry the heavy thinking - draft it, sort it, check it, rehearse it with you.

It cannot sit in your chair, take the blame when a number is wrong, or notice what nobody wrote down. Let it do the first 80%. Keep the last 20% that is truly yours.

No. Copy any prompt and paste it into the AI you already use. No account, no score, no wall in the way.

Any of them. The prompts describe the work rather than naming a product, so they are not tied to one assistant.

That is also why they keep working when you switch.

Change it freely. Every prompt is a starting line, not a rule.

Put in your real numbers, your real names and your real deadline. The more you make it yours, the better the answer comes back.

The tasks come from real job ads, published job data and the questions people ask in public forums.

The steps come from Apache Cassandra's own documentation, with practitioner sources for the traps the manual does not mention.

Push once. Ask it to sharpen the weakest part and to say what it assumed.

Most wrong answers come from a missing detail rather than a bad prompt - tell it the thing it could not know.