LPI · Free Practice Questions · Last reviewed May 2026
42real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
14% of exam · 6 sample questions below
A system administrator notices that the default gateway is missing after a reboot. The network configuration uses ifup/ifdown scripts. Which file should be modified to ensure the default gateway is persistent?
/etc/resolv.conf
/etc/network/routes
/etc/sysconfig/network
/etc/network/interfaces
/etc/network/interfaces is the Debian ifupdown configuration file, where a gateway stanza (or the gateway directive within an interface block) defines the default route. Adding it here ensures ifup restores the gateway on every boot, satisfying the persistence requirement that a manual route command cannot.
A server with IP 10.0.0.1 needs to forward packets from network 192.168.1.0/24 to 10.0.0.0/24. The administrator runs: 'iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -d 10.0.0.0/24 -j MASQUERADE'. However, traffic from 192.168.1.0/24 cannot reach 10.0.0.0/24. What is the most likely missing configuration?
A DNAT rule is also needed to translate the destination address.
A route must be added on the 10.0.0.0/24 network pointing back to 10.0.0.1.
The FORWARD chain in the filter table must have a rule to allow traffic.
NAT only rewrites addresses; the packet still traverses the FORWARD chain because it is routed, not locally delivered. With a default DROP policy there, the MASQUERADE rule alone cannot permit the flow, so an explicit FORWARD accept rule for that source and destination is required.
The IP address 10.0.0.1 is not configured on the external interface.
After adding a new network interface, the system assigns it the name 'enp0s3' instead of 'eth0'. Which of the following best describes the reason for this change?
The system uses the new predictable network interface naming scheme.
Predictable network interface naming derives names from firmware, PCI slot and onboard index rather than enumeration order, producing names like enp0s3. This replaces the legacy eth0 scheme, explaining why the new interface no longer receives eth0.
The kernel assigns names randomly to avoid conflicts.
The network card is faulty, causing the kernel to rename it.
The interface is a virtual device, so it gets a non-standard name.
Which THREE conditions must be met for a Linux system to act as a router between two networks?
IP forwarding must be enabled in the kernel (net.ipv4.ip_forward = 1).
Enabling net.ipv4.ip_forward=1 lets the kernel forward packets between interfaces rather than dropping them, satisfying the routing prerequisite. Without this sysctl, traffic arriving on one interface destined for the other network is discarded, so no forwarding occurs regardless of routing table entries or firewall rules.
The system must have a default gateway configured.
The system must have routes to the networks it will forward traffic to.
Forwarding requires a matching route in the kernel routing table for each destination network; without it, packets are dropped rather than forwarded out the other interface. This satisfies the routing-table condition needed for the system to act as a router between the two networks.
Each interface must have an IP address in the respective subnet.
Each interface must hold an IP address within the subnet it serves, otherwise the kernel cannot forward traffic onto that segment or answer ARP for the next hop. This meets the per-interface addressing condition required for routing between the two networks.
The firewall must allow forwarding (FORWARD chain policy ACCEPT).
Which TWO statements about the /etc/hosts file are true?
It can contain a line like '127.0.0.1 localhost'.
The /etc/hosts file maps hostnames to IP addresses locally, bypassing DNS resolution. A line such as '127.0.0.1 localhost' is standard, associating the loopback address with the local hostname. This satisfies the stem's requirement for a true statement about the file's contents and syntax.
It is used to resolve hostnames to IP addresses.
The /etc/hosts file provides static, local hostname-to-IP address mappings, consulted by the resolver before DNS queries. This satisfies the stem's requirement for a true statement about hostname resolution, as entries such as "192.168.1.10 server1" let the system resolve names without any network-based lookup.
It configures the DNS servers to use.
It is consulted after DNS by default.
It can define aliases for network interfaces.
A Linux host has a routing table entry that sends all traffic destined for the 10.0.0.0/8 network out interface eth1. A packet is sent from 192.168.1.100 to 10.0.0.5. Which interface will the packet exit?
eth0, then eth1 after ARP
eth0
eth1
The packet exits eth1 because the routing table's 10.0.0.0/8 entry matches the destination address 10.0.0.5, and the kernel selects the route by longest-prefix match on the destination, not the source. The source address 192.168.1.100 is irrelevant to route selection here, so traffic to 10.0.0.5 forwards out eth1.
lo
Want more Advanced Networking Configuration practice?
Practice this domain15% of exam · 6 sample questions below
A system administrator notices that a new 1TB NVMe drive (/dev/nvme0n1) is not detected by the kernel. The hardware is confirmed working. Which troubleshooting step should be taken first to check if the drive is recognized by the system's PCI subsystem?
Run lsblk to list all block devices.
Check dmesg output for errors.
Run lspci to verify the NVMe controller is detected.
lspci enumerates devices on the PCI bus, so it reveals whether the NVMe controller itself is visible to the kernel before any block-device or namespace checks. This satisfies the requirement to confirm PCI subsystem recognition first.
Run fdisk -l /dev/nvme0n1 to probe the drive.
Which TWO statements about LVM thin provisioning are correct?
Thin pools are created using the 'pvcreate' command.
The filesystem on a thin volume must support the 'discard' option to free unused space.
Thin pools allocate space on demand, so deleted blocks remain mapped until the filesystem issues discard (or fstrim runs), returning extents to the pool. Without discard support, freed space stays consumed and the pool can exhaust prematurely.
Thin volumes can be over-provisioned, allowing more virtual space than physical storage.
Thin pools allocate space on write, so the sum of virtual volume sizes may exceed the physical extents available in the volume group. This over-provisioning satisfies the stated capability, though writes fail once the pool is exhausted.
Thin provisioning requires a dm-cache device to function.
Thin volumes automatically grow when they run out of space.
The administrator wants to create a RAID 1 array using /dev/sdb1 and /dev/sdc1, then create a filesystem and mount it at /mnt/raid1. Which command sequence should be used first?
mkfs.ext4 /dev/md0
mdadm --create /dev/md0 --level=1 --raid-devices=2 /dev/sdb1 /dev/sdc1
RAID 1 arrays are assembled with mdadm's --create action, specifying --level=1 and --raid-devices=2 so both partitions are bound into /dev/md0 before any mkfs or mount step. This satisfies the stem's requirement to build the mirror first; filesystem creation and mounting follow only once the array exists.
pvcreate /dev/sdb1 /dev/sdc1
fdisk /dev/sdb && fdisk /dev/sdc
Order the steps to configure a Linux system as a DHCP client using dhclient.
Configure the interface for DHCP, then run dhclient, then check the IP address, then verify the default route, then test connectivity.
This order ensures the interface is set to obtain an IP automatically before dhclient requests one, then verifies the obtained address and route, and finally tests that the configuration works.
Run dhclient first, then configure the interface for DHCP, then check the IP address, then verify the default route, then test connectivity.
Check the IP address first, then configure the interface for DHCP, then run dhclient, then verify the default route, then test connectivity.
Configure the interface for DHCP, then check the IP address, then run dhclient, then verify the default route, then test connectivity.
Arrange the steps to configure a Linux system as a PostgreSQL database server.
Install PostgreSQL, then initialize the database cluster, then start the PostgreSQL service, then create a user and database, then test the connection.
This is the correct order because you must install the software first, then initialize the database cluster (creating the data directory), then start the service to accept connections, then create users/databases, and finally test the connection.
Install PostgreSQL, then start the PostgreSQL service, then initialize the database cluster, then create a user and database, then test the connection.
Install PostgreSQL, then initialize the database cluster, then create a user and database, then start the PostgreSQL service, then test the connection.
Install PostgreSQL, then start the PostgreSQL service, then create a user and database, then initialize the database cluster, then test the connection.
Match each security tool to its function.
iptables: A firewall tool used to set up, maintain, and inspect the tables of IP packet filter rules.
iptables is the standard Linux firewall for packet filtering and NAT.
nmap: A network scanning tool used to discover hosts and services on a network.
nmap is widely used for network discovery and security auditing.
tcpdump: A command-line packet analyzer that allows capturing and displaying network packets.
tcpdump is a powerful network traffic capture tool.
iptables: A tool for monitoring file system integrity.
nmap: A tool for banning IPs after failed login attempts.
tcpdump: A tool for scanning open ports.
Want more Block Devices, Filesystems and Advanced Storage practice?
Practice this domain15% of exam · 6 sample questions below
A system administrator needs to ensure that a custom kernel module loads automatically at boot. The module is named 'my_driver' and is built for the current kernel. Which configuration file should be modified to ensure the module loads automatically?
Add the insmod command in /etc/rc.local
Add the module name to /etc/modules.conf
Add a configuration file in /etc/modules-load.d/
Placing a .conf file containing the module name in /etc/modules-load.d/ causes systemd-modules-load.service to load it during early boot, satisfying the automatic-load-at-boot requirement. This declarative directory is the modern replacement for listing modules in /etc/modules on systemd-based distributions.
Add a configuration file in /etc/modprobe.d/
A server with a custom kernel fails to boot after a kernel update. The system displays a kernel panic: 'VFS: Unable to mount root fs on unknown-block(0,0)'. The root filesystem is on an LVM volume. What is the most likely cause?
The GRUB configuration is pointing to the wrong kernel partition.
The kernel does not have the necessary device drivers compiled in.
The root filesystem is formatted with an unsupported filesystem.
The initramfs is missing LVM support.
The unknown-block(0,0) panic means the kernel cannot locate the root device, and LVM volumes require the dm-mod and LVM modules inside the initramfs. If that image lacks LVM support, the volume never activates, matching the stem's LVM-on-root constraint exactly.
A system administrator wants to change the default kernel boot parameters temporarily to debug a boot issue. Which step should be taken at the GRUB menu to modify kernel parameters for the next boot only?
Select the kernel entry and press 'e' to edit the boot parameters.
Pressing 'e' at the GRUB menu opens an editable view of the selected kernel's boot entry, letting the administrator append or alter parameters such as debug or systemd.unit. The change applies only to that single boot, leaving the on-disk configuration untouched.
Edit /etc/default/grub and run update-grub to apply changes.
Press 'c' to enter the command line and modify parameters.
Press 'Esc' to access the advanced options menu.
A developer has compiled a custom kernel with a new feature. The kernel modules are installed in /lib/modules/$(uname -r)/. However, when the system boots, the kernel fails to load some modules with 'Exec format error'. What is the most likely cause?
The kernel configuration has disabled module loading.
The modules were compiled against a different kernel version.
'Exec format error' on module insertion indicates a vermagic mismatch: the module's compiled kernel version differs from the running kernel's, so the loader rejects the binary. Rebuilding the module against the currently running kernel headers resolves the mismatch.
The modules have incorrect file permissions.
The modules are not properly ordered in the dependency file.
A system administrator needs to find out which kernel parameters were passed at boot time. Which command displays the kernel boot parameters?
cat /proc/cmdline
Reading `/proc/cmdline` exposes the exact parameter string the bootloader handed to the kernel, satisfying the need to identify boot-time arguments. Unlike `/proc/version` or `dmesg`, which report version or runtime messages, this virtual file preserves the original command line verbatim, including `root=`, `quiet` and `ro`.
dmesg
lsmod
cat /proc/version
Which THREE factors can cause a kernel panic during boot? (Select THREE.)
Too many kernel modules loaded
Corrupted kernel image
A corrupted kernel image cannot be decompressed or executed by the bootloader, so the kernel never reaches userspace and panics immediately. This is distinct from initramfs or root filesystem faults, which fail later during module loading or root mounting.
Hardware incompatibility
Hardware incompatibility triggers a kernel panic when the booting kernel encounters devices or firmware it cannot safely drive, such as unsupported storage controllers or faulty memory. The kernel cannot delegate such faults to userspace, so it halts immediately, satisfying the stem's requirement for a cause occurring during boot.
Filesystem errors on the root partition
Missing device drivers for storage controllers
A missing storage-controller driver prevents the kernel from mounting the root filesystem, since the initramfs cannot hand over to the real root device. Without access to `/`, the kernel halts with a panic, directly satisfying the boot-time storage-access constraint described in the stem.
Want more Linux Kernel and System Startup practice?
Practice this domain14% of exam · 6 sample questions below
Which TWO statements are true regarding BIND DNS server security? (Choose two.)
The 'allow-transfer' ACL is used to restrict which clients can perform recursive queries.
The 'allow-recursion' ACL can be used to restrict which clients can use the server's recursive lookup feature.
Recursion is the server resolving queries on behalf of clients. Restricting it via allow-recursion prevents open-resolver abuse and cache-poisoning amplification, since only listed clients may trigger recursive lookups. This directly addresses the security concern of unauthorised recursive query handling.
The 'blackhole' ACL can be used to prevent cache poisoning attacks.
The 'forwarders' option can be used to disable recursion entirely.
The 'allow-query' ACL can be used to restrict which clients can send DNS queries to the server.
allow-query governs which clients may send any query to the server, limiting exposure of zone data and reducing attack surface. It is distinct from allow-recursion, which controls only recursive resolution, so it satisfies the requirement to restrict general query access.
A company uses BIND9 as the authoritative name server for its public zone example.com. External users report that they cannot resolve the MX record for the domain, but internal users can. What is the most likely cause?
The zone file lacks an MX record.
The allow-query ACL restricts queries to the internal network.
The allow-query ACL limits which clients may query the server. If it permits only internal subnets, external resolvers receive REFUSED and cannot obtain the MX record, while internal users succeed. This satisfies the stem's split between internal success and external failure.
The server is behind a firewall that blocks UDP port 53.
The recursion is set to no.
A mail server running Postfix is deferring messages for a local user. The mail log shows 'status=deferred (mailbox is locked)'. What is the most likely cause?
The user's mailbox is currently being accessed by a POP3 client.
POP3 clients commonly hold an exclusive lock on the mailbox file during retrieval. While locked, Postfix cannot deliver and defers the message with 'mailbox is locked', matching the stem's log entry and local delivery constraint.
The filesystem containing the mail spool is out of inodes.
The disk quota for the user has been exceeded.
The Postfix process lacks write permission to the mailbox.
Which Apache module is used to rewrite URLs based on rules?
mod_rewrite
mod_rewrite provides the RewriteEngine and RewriteRule directives that match incoming request URLs against regular expressions and substitute them, satisfying the stem's requirement for rule-based URL rewriting. It operates at the server level before content is served, unlike mod_alias, which only maps static paths.
mod_proxy
mod_alias
mod_redirect
A DNS administrator wants to implement DNSSEC on an authoritative zone. Which TWO resource records are essential for DNSSEC?
NSEC
DNSKEY
The DNSKEY record publishes the zone's public signing keys, allowing validators to verify RRSIG signatures and build the chain of trust. It is essential for DNSSEC, satisfying the stem's requirement for the key material that anchors zone validation.
RRSIG
RRSIG records hold the cryptographic signatures covering each RRset in the signed zone. Validators use them with DNSKEY public keys to confirm authenticity and integrity, satisfying the stem's requirement for the essential signature record in DNSSEC.
A
SOA
Refer to the exhibit. A DNS query for 'ftp.example.com' returns NXDOMAIN. What configuration change would best resolve this?
Add a CNAME record for ftp pointing to www.example.com.
Increase the serial number in the SOA record.
Ensure recursion is enabled on the server.
Add an A record for ftp pointing to an IP address.
Adding an A record for ftp maps the hostname to an IPv4 address within the example.com zone, so the resolver returns a positive answer instead of NXDOMAIN. This directly satisfies the stem's requirement: the name exists but lacks the address record needed for resolution.
Want more DNS, Web and Mail Services practice?
Practice this domain14% of exam · 6 sample questions below
An administrator needs to configure a Linux client to automatically obtain an IP address from a DHCP server but also ensure that the client uses a specific static DNS server (8.8.8.8) regardless of the DHCP-provided DNS. Which configuration should be applied?
Add 'append domain-name-servers 8.8.8.8;' to /etc/dhcp/dhclient.conf
Edit /etc/sysconfig/network-scripts/ifcfg-eth0 and set PEERDNS=no and DNS1=8.8.8.8
Add 'prepend domain-name-servers 8.8.8.8;' to /etc/dhcp/dhclient.conf
Add 'supersede domain-name-servers 8.8.8.8;' to /etc/dhcp/dhclient.conf
The supersede directive in dhclient.conf overrides any domain-name-servers value supplied by the DHCP server, forcing the client to use 8.8.8.8 while still leasing its address dynamically. This satisfies both the dynamic addressing and fixed DNS constraints.
Which file is used by the NetworkManager daemon to store connection profiles on a Linux system?
/etc/NetworkManager/system-connections/
NetworkManager stores connection profiles as individual keyfiles in /etc/NetworkManager/system-connections/, satisfying the stem's requirement for the daemon's persistent profile location. Each connection gets its own file here, unlike /etc/sysconfig/network-scripts/ (Red Hat ifcfg) or /etc/network/interfaces (Debian), which belong to other tooling.
/etc/sysconfig/network-scripts/
/etc/netctl/
/etc/systemd/network/
A Linux client is configured with two network interfaces: eth0 (connected to the internet) and eth1 (connected to a private LAN). The default route is set to eth0. The client can access the internet but cannot access hosts on the private LAN. What is the most likely cause?
A firewall on the client is blocking ICMP packets on eth1.
The eth1 interface is not configured with an IP address.
The eth1 interface is not receiving a DHCP lease.
There is no route to the private subnet via eth1.
With only a default route via eth0, traffic to the private LAN subnet has no matching route, so packets are sent to the internet gateway and dropped; adding a route via eth1 restores LAN access.
Which TWO configuration files are commonly used to specify DNS resolver settings on a Linux system? (Select TWO.)
/etc/nsswitch.conf
/etc/systemd/resolved.conf
On systemd-based distributions, systemd-resolved reads /etc/systemd/resolved.conf to define global DNS servers, search domains and DNSSEC settings, so it directly satisfies the requirement for a resolver configuration file. It coexists with the legacy /etc/resolv.conf, which resolved often manages as a symlink.
/etc/resolv.conf
/etc/resolv.conf is the traditional glibc resolver file, listing nameserver and search directives that libc reads for every DNS lookup. It satisfies the resolver-settings requirement directly, though systemd-resolved or NetworkManager may regenerate it dynamically on modern distributions.
/etc/dhcp/dhclient.conf
/etc/hosts
A company has a Linux client running Ubuntu 20.04 that is used by multiple developers. The client has two network interfaces: eth0 (connected to the corporate network with DHCP) and eth1 (connected to a test lab with static IP 192.168.100.10/24). The client needs to access both the internet (via eth0) and the lab network (192.168.100.0/24). The default gateway is 10.0.0.1 on eth0. The lab network has a server at 192.168.100.50 that provides DHCP for the lab devices, but the client's eth1 is statically configured. Recently, the client cannot reach the lab server at 192.168.100.50. The administrator checks the routing table and sees:
Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 10.0.0.1 0.0.0.0 UG 100 0 0 eth0 10.0.0.0 0.0.0.0 255.255.255.0 U 100 0 0 eth0 192.168.100.0 0.0.0.0 255.255.255.0 U 100 0 0 eth1
The administrator can ping 192.168.100.50 from the client. However, the lab server cannot ping the client. What is the most likely cause?
The lab server's default gateway is misconfigured.
The client's firewall is blocking incoming ICMP echo requests.
The routing table already contains the correct connected route for 192.168.100.0/24 via eth1, and the client can ping the server, proving outbound connectivity and ARP work. The reverse direction failing points to the client's host firewall dropping inbound ICMP echo requests.
The client has no route to the lab subnet.
The client's default gateway is misconfigured.
Which TWO commands can be used to display the current IP address and netmask of network interfaces on a Linux system?
arp -a
ifconfig
`ifconfig` queries the kernel's network interface configuration directly, printing each interface's assigned IPv4 address and netmask (plus broadcast and MTU). It satisfies the stem's requirement to display both the current IP address and netmask, unlike tools showing only link state or routing tables.
ip addr show
`ip addr show` queries the kernel's netlink interface and prints each interface's IPv4 and IPv6 addresses with prefix lengths, satisfying the requirement to display both IP address and netmask. Unlike `ifconfig`, it reports the netmask as CIDR notation and works on modern distributions where the deprecated net-tools package may be absent.
netstat -i
route -n
Want more Network Client Management practice?
Practice this domainA system administrator notices that the SSH service on a Linux server is failing to start. The log shows: 'sshd: error: Could not load host key: /etc/ssh/ssh_host_rsa_key'. What is the most likely cause and solution?
The sshd_config file has a syntax error. Run 'sshd -t' to check it.
The SSH service is managed by xinetd and the configuration is missing. Edit /etc/xinetd.d/ssh.
The /etc/ssh/sshd_config file has incorrect permissions. Change them to 600.
The host key file is missing or corrupt. Run 'ssh-keygen -A' to regenerate all missing host keys.
The error explicitly reports that sshd cannot load the RSA host key, meaning the file is absent or unreadable. Running 'ssh-keygen -A' regenerates every missing host key pair, restoring the files sshd requires before it can bind and accept connections.
A security policy requires that all users must change their passwords every 90 days. Which command enforces maximum password age for an existing user 'jdoe'?
chage -M 90 jdoe
chage -M 90 jdoe sets the maximum password age to 90 days in /etc/shadow, forcing jdoe to change the password after that interval. This directly enforces the security policy's 90-day rotation requirement for an existing account.
passwd -f jdoe
usermod -e 90 jdoe
chage -E 90 jdoe
Which file is used to configure which users and groups are allowed to use the 'cron' daemon?
/var/spool/cron/
/etc/cron.d/
/etc/crontab
/etc/cron.allow
Lists users allowed to use cron.
Given the exhibit, what is the most likely reason for the GPG error, and what is the correct way to fix it permanently?
The repository is not signed; use '--allow-unauthenticated' permanently in /etc/apt/apt.conf.d/
The repository URL is incorrect; change 'http://deb.example.com' to 'https://deb.example.com'
The InRelease file is corrupted; remove it and run 'apt-get update' again
The public key is missing; obtain and add it with 'apt-key add' or 'wget -O- | apt-key add -'
The error arises because the repository's signing key is absent from the local keyring, so apt cannot verify package signatures. Fetching the vendor's public key and importing it with apt-key add restores verification, permanently resolving the failure for that repository.
You are the security administrator for a company that runs a web application on a Linux server. The application runs under the user 'www-data' and listens on TCP port 8080. The server also runs an SSH service on port 22. Recently, an external penetration test revealed that an attacker could exploit a vulnerability in the web application to execute commands as the 'www-data' user, and from there, the attacker could escalate privileges to root due to a misconfigured sudo rule. You need to implement a defense-in-depth approach to limit the impact of such an attack. Which single action would be the most effective in preventing privilege escalation from the 'www-data' user to root, while still allowing the application to function normally?
Review and remove any sudo privileges granted to the 'www-data' user in /etc/sudoers, and ensure the application does not require sudo.
Removing sudo rights for 'www-data' directly severs the escalation path the penetration test exploited, so a compromised web process cannot gain root. The application keeps running normally because it should not need sudo; this satisfies the defence-in-depth constraint without disrupting port 8080 service.
Change the SSH port to a non-standard port to reduce the attack surface.
Run the web application in a chroot jail to isolate it from the rest of the filesystem.
Implement mandatory access control with AppArmor profiles for the web application.
An administrator is reviewing the audit rules on a Linux server. The current rules are shown in the exhibit. The administrator needs to ensure that any failed attempts to open files are logged, while also monitoring for successful outbound connections. Which of the following describes the effect of the current rules?
The first rule logs only failed openat calls, and the second rule logs all connect calls.
The first audit rule uses the -F failure flag on openat, logging only failed file opens, while the second rule without -F logs every connect call, successful or not. This matches the stem's stated monitoring goals exactly.
The first rule logs only successful openat calls, and the second rule logs only failed connect calls.
The first rule logs all openat calls, and the second rule logs all connect calls.
The first rule logs only failed openat calls, and the second rule logs only failed connect calls.
Want more System Security practice?
Practice this domain14% of exam · 6 sample questions below
A company wants to use Samba to share files with Windows clients. Which service must be enabled in Samba to support Windows Active Directory domain membership?
nmbd
smbd
swat
winbind
Winbind bridges Linux and Windows security identities, letting Samba resolve Active Directory users and groups into Linux UIDs and GIDs. Enabling it satisfies the domain-membership constraint: without winbind, Samba cannot map AD accounts for authentication, so Windows clients could not access shares as domain members.
A Samba share is configured with 'force user = jane'. A user 'bob' accesses the share. With what effective user ID will file operations be performed?
root
jane
The force user parameter overrides the connecting user's identity for all file operations on that share, so bob's access is performed as jane. Ownership and permissions therefore reflect jane, not bob, satisfying the stem's forced-identity constraint.
nobody
bob
Which Samba component provides NetBIOS name resolution and browsing services?
swat
smbd
nmbd
The nmbd daemon handles NetBIOS name resolution and browsing, satisfying the stem's requirement for both services. It answers NetBIOS name queries, registers NetBIOS names, and maintains browse lists for network neighbourhood visibility. Unlike smbd, which serves SMB/CIFS file and print shares, nmbd operates specifically at the NetBIOS naming and browsing layer.
winbind
After modifying smb.conf, which command should be used to verify the configuration syntax before restarting Samba?
net conf
testparm
`testparm` parses `smb.conf` and reports syntax errors or unknown parameters without touching the running Samba daemon, satisfying the stem's requirement to verify configuration before restarting. It also validates share definitions and prints the loaded service list, so mistakes surface safely rather than breaking active file-sharing services.
smbpasswd
smbcontrol
Which TWO files are commonly used by Samba for configuration and user authentication? (Choose two.)
/etc/samba/smbusers
/etc/passwd
/etc/samba/smbpasswd
/etc/samba/smbpasswd stores Samba's legacy encrypted password database, letting Samba authenticate users independently of the system's /etc/passwd. This satisfies the stem's user-authentication requirement, since smb.conf alone handles configuration but holds no credentials. Modern Samba deployments favour tdbsam, yet smbpasswd remains a recognised authentication file.
/etc/hosts.allow
/etc/samba/smb.conf
/etc/samba/smb.conf is Samba's primary configuration file, defining shares, security mode and global parameters that govern how the daemon behaves. It satisfies the configuration half of the stem's requirement, since Samba reads it at startup to determine which services to offer and how clients authenticate against them.
Given the smb.conf exhibit, which share(s) allow write access to user 'alice' who is a member of the 'staff' group?
share1 and share3
share3 only
share1 only
Only share1's configuration grants write permission to the staff group, which includes alice. The other shares either deny write, restrict it to different groups, or mark the share read-only, so alice cannot write to them. Hence share1 is the sole writable share for her.
share2 only
Want more File Sharing and Samba practice?
Practice this domainThe LPIC-2 exam has 60 questions and must be completed in 90 minutes. The passing score is 500/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 7 domains: Advanced Networking Configuration, Block Devices, Filesystems and Advanced Storage, Linux Kernel and System Startup, DNS, Web and Mail Services, Network Client Management, System Security, File Sharing and Samba. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official LPI LPIC-2 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.