Courseiva

CCNA Lxp Security Questions

34 of 109 questions · Page 2/2 · Lxp Security topic · Answers revealed

76
MCQmedium

A security policy requires that users cannot reuse any of their last 5 passwords. Which PAM module and configuration directive enforces this?

A.pam_faillock with deny=5
B.pam_pwhistory with remember=5
C.pam_tally2 with deny=5
D.pam_pwquality with remember=5
AnswerB

`pam_pwhistory` stores previous password hashes in `/etc/security/opasswd` and compares each new password against them, rejecting any match. The `remember=5` directive retains the last five hashes, directly satisfying the policy's no-reuse constraint for the previous five passwords.

Why this answer

The pam_pwhistory module records previous password hashes and enforces password reuse restrictions via the remember directive. Setting remember=5 prevents users from reusing any of their last five passwords, exactly matching the policy requirement.

Exam trap

XK0-006 often tests the confusion between account lockout modules (pam_faillock, pam_tally2) and password history modules (pam_pwhistory), so candidates must map 'reuse' to remember, not deny.

How to eliminate wrong answers

Option A is wrong because pam_faillock with deny=5 locks accounts after five failed login attempts; it has nothing to do with password history. Option C is wrong because pam_tally2 also counts failed login attempts (and is deprecated in favor of pam_faillock), not password reuse. Option D is wrong because pam_pwquality enforces complexity rules (length, character classes) and does not support a remember directive for password history.

77
MCQmedium

A Linux administrator is configuring a server to use a centralized authentication service. The security policy requires that user credentials are never sent in clear text and that the authentication traffic is encrypted. The administrator decides to use LDAP with TLS. Which command should be used to verify that the LDAP server's certificate is valid and that the TLS handshake succeeds?

A.ss -tlnp | grep 636
B.nmap --script ssl-enum-ciphers -p 389 ldap.example.com
C.ldapsearch -H ldap://ldap.example.com -x -b '' -s base
D.openssl s_client -connect ldap.example.com:636 -showcerts
AnswerD

openssl s_client initiates a TLS connection to the specified host and port, displaying the server's certificate chain and the result of the handshake. Using port 636, the standard LDAPS port, this command verifies that the LDAP server presents a valid certificate and that TLS negotiation succeeds, directly addressing the requirement.

Why this answer

The openssl s_client command is designed to test TLS connections, making it ideal for verifying the LDAP server's certificate and handshake on the LDAPS port. It displays the certificate chain and any errors, ensuring that the encryption is correctly configured. Other commands either connect without encryption, check only for listening sockets, or do not validate the certificate in the LDAP context.

Exam trap

The trap here is using ldapsearch with an ldap:// URI and assuming it tests encryption, when it actually connects in clear text unless StartTLS is explicitly requested.

78
MCQhard

An administrator needs to ensure that only users from the 'ops' group can SSH into a server. Which configuration in /etc/ssh/sshd_config accomplishes this?

A.AllowGroups ops
B.Match Group ops DenyUsers *
C.AllowUsers ops
D.DenyUsers all
AnswerA

AllowGroups ops restricts SSH logins to members of the ops group, satisfying the requirement that only that group connects. When AllowGroups is set, all users outside the listed groups are denied, regardless of other account settings.

Why this answer

The `AllowGroups` directive in `/etc/ssh/sshd_config` restricts SSH access to only users who are members of the specified group. By setting `AllowGroups ops`, only users belonging to the 'ops' group will be permitted to log in via SSH, which directly meets the requirement.

Exam trap

The trap here is confusing `AllowUsers` (which matches usernames) with `AllowGroups` (which matches group membership), leading candidates to select option C when the requirement specifies group-based restriction.

How to eliminate wrong answers

Option B is wrong because `Match Group ops DenyUsers *` would deny all users (including those in 'ops') when the group matches, effectively blocking everyone. Option C is wrong because `AllowUsers ops` restricts access to a user named 'ops', not to members of the 'ops' group. Option D is wrong because `DenyUsers all` is invalid syntax (the correct directive is `DenyUsers` followed by specific usernames, not the keyword 'all'), and it would not achieve group-based restriction.

79
MCQhard

An administrator notices that a custom application uses port 8443/TCP. To allow external access, which firewalld command permanently opens this port in the default zone?

A.firewall-cmd --add-port=8443/tcp --permanent
B.firewall-cmd --add-service=8443/tcp --zone=public --permanent
C.firewall-cmd --add-port=8443 --permanent
D.firewall-cmd --permanent --add-port=8443
AnswerA

--add-port=8443/tcp adds the port to the default zone's permanent configuration, and --permanent ensures it survives firewalld reloads and reboots. A runtime-only change would vanish on reload, so the permanent flag is essential to the stem's requirement.

Why this answer

The correct command is firewall-cmd --permanent --add-port=8443/tcp. The --permanent flag makes it persistent, --add-port opens the port, and the syntax includes protocol. --add-service is for predefined services, not port numbers.

80
MCQeasy

A junior administrator is asked to verify that the integrity of a downloaded package file has not been altered in transit. The vendor publishes a SHA-256 checksum file alongside the package. Which command should the administrator run to compare the computed hash of the downloaded file against the published value?

A.sha256sum package.rpm
B.rpm --checksig package.rpm
C.md5sum package.rpm
D.gpg --verify package.rpm
AnswerA

sha256sum computes the SHA-256 hash of the specified file and prints it, which the administrator can compare against the vendor's published checksum. It is the standard coreutils tool for this purpose and directly fulfills the integrity verification task. A match confirms the file matches the expected content.

Why this answer

The sha256sum utility computes the SHA-256 digest of a file, allowing a direct comparison with the vendor's published checksum to confirm the download was not altered. The other commands either use a different algorithm, require signature artifacts not provided, or verify RPM signatures rather than a standalone hash file.

Exam trap

The trap here is choosing md5sum because it also produces a checksum, when the vendor published a SHA-256 value that must be matched with the same algorithm.

81
MCQeasy

A system administrator wants to enforce a password policy requiring a minimum length of 12 characters, at least one uppercase letter, and one digit. Which PAM module should be configured?

A.pam_pwquality
B.pam_unix
C.pam_faillock
D.pam_tally2
AnswerA

pam_pwquality enforces length, character-class and complexity checks through its minlen, ucredit and dcredit parameters, directly satisfying the 12-character minimum plus uppercase and digit requirements. It supersedes the older pam_cracklib module and integrates with the password stack.

Why this answer

pam_pwquality is the correct PAM module because it is specifically designed to enforce password complexity requirements, such as minimum length, uppercase letters, and digits, through configurable parameters like minlen, ucredit, and dcredit. It replaces the older pam_cracklib and is the standard module for password quality checks on modern Linux systems.

Exam trap

The trap here is that candidates confuse pam_unix (which handles authentication and password aging) with pam_pwquality (which enforces complexity), because both are commonly used together in password policies but serve distinct roles.

How to eliminate wrong answers

Option B (pam_unix) is wrong because it handles traditional Unix authentication (password hashing and verification) but does not enforce complexity rules like length or character classes. Option C (pam_faillock) is wrong because it is used for account lockout after failed login attempts, not for password composition policies. Option D (pam_tally2) is wrong because it also manages login failure counting and account locking, not password quality enforcement.

82
MCQhard

An administrator needs to view all current nftables rules. Which command should be used?

A.nft list ruleset
B.nft --list
C.nft show ruleset
D.iptables -L
AnswerA

nft list ruleset prints every table, chain and rule in the current nftables configuration, giving a complete view of loaded rules across all families. This satisfies the requirement to view all current rules without specifying a particular table.

Why this answer

nft list ruleset displays the entire ruleset. nft list table only shows a specific table.

83
Multi-Selecthard

An administrator is configuring iptables on a server. The requirements are: allow incoming SSH (port 22) from the 192.168.1.0/24 network, drop all other incoming traffic, and allow all outgoing traffic. Which three iptables rules achieve this? (Choose THREE.)

Select 3 answers
A.iptables -A INPUT -p tcp --dport 22 -s 192.168.1.0/24 -j ACCEPT
B.iptables -P OUTPUT ACCEPT
C.iptables -P FORWARD ACCEPT
D.iptables -A INPUT -p tcp --dport 22 -j ACCEPT
E.iptables -P INPUT DROP
AnswersA, B, E

This rule appends to the INPUT chain, matching TCP destination port 22 with source 192.168.1.0/24 and accepting it. It satisfies the requirement to permit SSH only from that subnet, and must precede the blanket INPUT drop so legitimate SSH is not discarded.

Why this answer

Option A is correct because it appends an INPUT rule that matches TCP packets destined for port 22 (--dport 22) with source address 192.168.1.0/24 (-s 192.168.1.0/24) and accepts them, exactly fulfilling the requirement to allow SSH only from that subnet. Option B is correct because setting the OUTPUT chain's default policy to ACCEPT (iptables -P OUTPUT ACCEPT) permits all outgoing traffic, matching the stated requirement. Option E is correct because setting the INPUT chain's default policy to DROP (iptables -P INPUT DROP) ensures that any incoming traffic not explicitly accepted by the earlier SSH rule is dropped, satisfying the 'drop all other incoming traffic' requirement.

Option C is not correct because FORWARD concerns traffic routed through the host, not traffic destined to the server itself, and the scenario does not require allowing forwarded packets. Option D is not correct because it accepts SSH from any source address, not restricted to 192.168.1.0/24 as required.

Exam trap

The trap is selecting a rule that allows SSH from any source (Option D) instead of restricting to the required subnet, or confusing FORWARD policy with INPUT/OUTPUT policies; candidates must read the source restriction carefully.

84
MCQmedium

A security auditor notices that users can set weak passwords on a Linux system. The administrator wants to enforce password complexity requiring a minimum of 12 characters, at least one uppercase letter, and at least one digit. Which PAM module should be configured in /etc/pam.d/common-password?

A.pam_unix.so
B.pam_pwquality.so
C.pam_tally2.so
D.pam_faillock.so
AnswerB

Configuring pam_pwquality.so in /etc/pam.d/common-password enforces the auditor's complexity requirement directly, using parameters such as minlen=12, ucredit=-1 and dcredit=-1 to mandate twelve characters, one uppercase letter and one digit. Unlike pam_cracklib.so, it reads settings from /etc/security/pwquality.conf, centralising policy across services.

Why this answer

The pam_pwquality.so module is specifically designed to enforce password complexity policies, such as minimum length, required character classes (uppercase, lowercase, digits, special characters), and dictionary checks. Configuring it in /etc/pam.d/common-password allows the administrator to set parameters like minlen=12, ucredit=-1, and dcredit=-1 to meet the stated requirements. This module is the standard replacement for the older pam_cracklib.so.

Exam trap

XK0-006 often tests the specific PAM module for password complexity; candidates may confuse pam_pwquality with pam_unix or lockout modules like pam_tally2 or pam_faillock, but the key is that only pam_pwquality provides the granular complexity controls required.

How to eliminate wrong answers

Option A is wrong because pam_unix.so handles traditional Unix password authentication and can enforce some password policies via arguments like minlen, but it is limited and does not support the full range of complexity requirements (e.g., requiring uppercase and digits) as flexibly as pam_pwquality. Option C is wrong because pam_tally2.so is used for account lockout after failed login attempts, not for password complexity. Option D is wrong because pam_faillock.so is also for account lockout and failed login tracking, not for setting password policies.

85
MCQhard

An administrator needs to generate a self-signed certificate valid for 365 days with a 2048-bit RSA key. Which OpenSSL command correctly creates both the private key and certificate in one step?

A.openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
B.openssl x509 -req -in req.pem -signkey key.pem -out cert.pem -days 365
C.openssl ca -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365
D.openssl genrsa -out key.pem 2048 && openssl req -new -x509 -key key.pem -out cert.pem -days 365
AnswerA

Combines key generation and self-signing in a single invocation: -newkey rsa:2048 creates the 2048-bit RSA private key, -x509 emits a self-signed certificate rather than a CSR, -days 365 sets validity, and -nodes omits key encryption.

Why this answer

The command 'openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes' generates a new 2048-bit RSA private key and a self-signed certificate in one step. The -x509 option outputs a self-signed certificate instead of a certificate request, and -nodes ensures the private key is not encrypted. This matches the requirement to create both the private key and certificate simultaneously.

Exam trap

XK0-006 often tests the confusion between generating a self-signed certificate in one step versus using separate commands, and the role of the -nodes flag.

How to eliminate wrong answers

Option B is wrong because 'openssl x509 -req' is used to sign a certificate request, not to generate a new key and self-signed certificate in one step; it requires an existing request and key. Option C is wrong because 'openssl ca' is used to sign certificates as a CA, not for generating self-signed certificates. Option D is wrong because it uses two separate commands: first generating a key with genrsa, then creating a certificate request with 'req -new -x509', which is not a single-step process and lacks the -newkey option to generate the key and certificate together.

86
MCQmedium

A Linux administrator wants to harden a server against brute-force attacks. They decide to use fail2ban to monitor SSH authentication failures. After installing and enabling the fail2ban service, they need to verify that the SSH jail is active and correctly configured. Which command should they use to check the current status of the sshd jail?

A.fail2ban-client -v
B.systemctl status fail2ban
C.fail2ban-client status sshd
D.cat /etc/fail2ban/jail.conf
AnswerC

This command queries the fail2ban server for the status of the sshd jail, showing currently banned IPs, total failed attempts, and other statistics. It is the correct way to verify that the jail is active and functioning as intended for SSH protection.

Why this answer

To verify that the sshd jail is active and functioning, the administrator should use fail2ban-client status sshd. This command queries the running fail2ban server and returns details such as the number of failed attempts, banned IPs, and total bans for that specific jail. It is the definitive way to confirm the jail's operational status after configuration.

Exam trap

The trap here is confusing service status with jail status; systemctl status fail2ban only shows if the daemon is running, not whether the sshd jail is correctly monitoring and banning.

87
MCQhard

An administrator wants to allow the user 'ops' to run only the command '/usr/bin/systemctl restart httpd' via sudo on a specific host 'webserver'. Which /etc/sudoers entry is correct?

A.ops webserver=(root) /usr/bin/systemctl restart httpd
B.ops ALL=(root) /usr/bin/systemctl restart httpd
C.ops webserver=(ALL) /usr/bin/systemctl restart httpd
D.ops webserver=(root) ALL
AnswerA

This entry grants user 'ops' on host 'webserver' permission to run only that exact systemctl restart command as root, with no wildcards or broader command scope. It satisfies the least-privilege constraint by restricting sudo to the single specified command on the specified host.

Why this answer

The sudoers entry format is: user host=(runas) command. To allow user 'ops' to run only the specified command on host 'webserver' as root, the correct entry is 'ops webserver=(root) /usr/bin/systemctl restart httpd'. This restricts both the host and the command, and specifies the runas user as root.

Exam trap

The trap is misplacing the host or runas fields, or using ALL where specificity is required; candidates must match the exact host and command restrictions stated in the question.

How to eliminate wrong answers

Option B is wrong because it uses 'ALL' for the host, meaning the user can run the command on any host, not just 'webserver', violating the specific host requirement. Option C is wrong because it uses '(ALL)' for the runas user, allowing the command to be run as any user, not just root, which is broader than required. Option D is wrong because it allows the user to run ALL commands as root on 'webserver', not just the specified systemctl command, which is far too permissive.

88
MCQeasy

Which file contains the hashed passwords and password aging information for user accounts?

A./etc/shadow
B./etc/gshadow
C./etc/group
D./etc/passwd
AnswerA

/etc/shadow stores hashed passwords plus ageing fields such as last change, minimum, maximum and warning days, readable only by root. This satisfies the requirement for a file holding both hashed passwords and password ageing information.

Why this answer

/etc/shadow stores password hashes and aging fields.

89
Multi-Selectmedium

A Linux engineer needs to harden SSH access. Which TWO of the following settings should be configured in /etc/ssh/sshd_config to enhance security? (Select TWO.)

Select 2 answers
A.MaxAuthTries 6
B.PasswordAuthentication no
C.Protocol 1
D.PermitRootLogin yes
E.AllowUsers alice bob
AnswersB, E

Disables password logins, reducing risk of brute force.

Why this answer

Option B (PasswordAuthentication no) is correct because disabling password-based authentication forces users to authenticate with SSH key pairs, eliminating brute-force and credential-stuffing attacks against account passwords. Option E (AllowUsers alice bob) is correct because it implements an explicit allowlist, so only the named accounts alice and bob may establish SSH sessions, denying all other valid system users. The remaining options weaken security: MaxAuthTries 6 (A) is too permissive since the default of 3 limits failed attempts more tightly, Protocol 1 (C) enables the obsolete and cryptographically broken SSH-1 protocol, and PermitRootLogin yes (D) allows direct root logins, which should be set to no or prohibit-password.

Exam trap

The trap here is that candidates often confuse 'hardening' with 'increasing limits' (like MaxAuthTries) or 'enabling convenience' (like PermitRootLogin yes), when the correct hardening choices actually restrict or disable weaker authentication methods.

90
MCQhard

A Linux administrator is configuring a system to use a centralized authentication service. The requirement is that if the central server is unreachable, users should still be able to log in using cached credentials. Which PAM module should be configured to provide this functionality?

A.pam_ccreds
B.pam_sss with caching enabled in SSSD
C.pam_unix
D.pam_sss
AnswerB

The pam_sss module works with SSSD to authenticate users. When SSSD is configured with caching (e.g., cache_credentials = True), it stores user credentials locally, allowing offline authentication when the central server is unreachable. This is the standard method for providing cached credentials in modern Linux environments.

Why this answer

SSSD with caching enabled provides offline authentication by storing credentials locally. The pam_sss module integrates with SSSD, and when the central server is down, SSSD uses its cache to validate credentials. Other modules like pam_unix only handle local accounts, and pam_ccreds is deprecated.

Exam trap

The trap here is thinking that pam_sss alone provides caching; it requires SSSD to be configured with cache_credentials enabled.

91
Multi-Selectmedium

A Linux administrator needs to configure sudo access for members of the 'wheel' group to run any command. Which two steps are required? (Choose TWO.)

Select 2 answers
A.Uncomment the line '%wheel ALL=(ALL) ALL' in /etc/sudoers using visudo
B.Set the setuid bit on /usr/bin/sudo
C.Run 'sudo visudo -c' to check syntax
D.Add users to the 'wheel' group using usermod -aG wheel username
E.Edit /etc/ssh/sshd_config to allow wheel group
AnswersA, D

Uncommenting `%wheel ALL=(ALL) ALL` in /etc/sudoers grants the wheel group password-prompted sudo rights to run any command as any user, satisfying the "any command" requirement. Editing via visudo validates syntax before saving, preventing a corrupted sudoers file that would lock out all sudo access.

Why this answer

Option A is correct because the '%wheel ALL=(ALL) ALL' entry in /etc/sudoers is the standard sudoers rule that grants every member of the wheel group permission to run any command as any user on any host, and it must be uncommented (edited with visudo to preserve syntax safety and file locking). Option D is correct because users only receive that sudo privilege if they are actually members of the wheel group, so adding them with 'usermod -aG wheel username' (the -a avoids removing existing supplementary groups) is a required step. Option B is wrong because /usr/bin/sudo is already installed with the setuid root bit by the package; manually setting it is unnecessary and not part of granting wheel sudo rights.

Option C is wrong because 'visudo -c' only validates sudoers syntax — it is a verification step, not a required configuration step. Option E is wrong because /etc/ssh/sshd_config controls SSH login behavior, not sudo authorization, and has nothing to do with granting wheel members command execution rights.

Exam trap

The trap here is that candidates confuse the setuid bit on sudo (which is already set) with a configuration step, or think that editing SSH config or running syntax checks alone grants sudo access, when in fact both the sudoers rule and group membership are required.

92
MCQhard

An administrator needs to generate a self-signed certificate and private key for an internal web server. Which OpenSSL command creates both in one step?

A.openssl ca -in req.pem -out cert.pem
B.openssl genrsa -out key.pem 2048 && openssl req -new -x509 -key key.pem -out cert.pem -days 365
C.openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
D.openssl x509 -req -in req.pem -signkey key.pem -out cert.pem
AnswerC

The `-x509` flag makes `req` emit a self-signed certificate rather than a certificate signing request, while `-newkey rsa:2048` generates the private key alongside it. `-keyout` and `-out` write both files in a single invocation, satisfying the requirement to create certificate and key together.

Why this answer

The `openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes` command generates a new RSA private key and a self-signed X.509 certificate in a single step. The `-x509` flag outputs a self-signed certificate instead of a CSR, `-newkey` creates the key pair, and `-nodes` prevents encryption of the private key, which is typical for an internal web server that must start without manual passphrase entry.

Exam trap

The trap here is that candidates may think Option B is correct because it technically works, but the question explicitly asks for a command that creates both 'in one step', meaning a single OpenSSL command, not a shell pipeline of two separate commands.

How to eliminate wrong answers

Option A is wrong because `openssl ca` is used to sign a certificate request (CSR) with a CA certificate, not to generate a self-signed certificate and private key together; it requires an existing CA setup and a pre-generated CSR. Option B is wrong because while it does produce a self-signed certificate and key, it uses two separate commands (`genrsa` then `req`) chained with `&&`, which is not a single OpenSSL command as the question asks for 'one step'. Option D is wrong because `openssl x509 -req` signs a CSR using an existing key (`-signkey`), but it does not generate a new private key; it requires a pre-existing CSR and key file, so it cannot create both in one step.

93
MCQhard

An administrator configures /etc/ssh/sshd_config with the following settings: PermitRootLogin no, PasswordAuthentication no, AllowUsers alice bob, MaxAuthTries 2. After restarting sshd, which of the following is true?

A.User charlie can log in using a public key.
B.User bob can log in using a public key.
C.User alice can log in using a password.
D.Root can log in using a valid password.
AnswerB

PasswordAuthentication no forces public-key authentication, and AllowUsers alice bob permits bob, so bob can log in with a public key. PermitRootLogin no blocks root, and MaxAuthTries 2 limits attempts, but neither prevents bob's key-based login.

Why this answer

PasswordAuthentication no disables password logins, so public key authentication is required. PermitRootLogin no prevents root login entirely. AllowUsers restricts to alice and bob only.

MaxAuthTries 2 limits authentication attempts. So root cannot log in even with keys, and alice/bob must use keys.

94
MCQmedium

SELinux is currently in enforcing mode. A service is being blocked by SELinux. Which command can analyze the audit log and suggest the minimum policy changes to allow the service?

A.ausearch
B.audit2allow
C.setsebool
D.restorecon
AnswerB

audit2allow reads SELinux denial records from the audit log and generates allow rules targeting the exact permissions the service was refused. This produces the minimum policy change needed, rather than disabling enforcement or granting broad access, directly satisfying the requirement to suggest least-privilege policy adjustments.

Why this answer

audit2allow reads SELinux denial messages from the audit log (or standard input) and generates a human-readable policy module that allows the previously denied operations. It is specifically designed to translate raw AVC denials into the minimal set of allow rules needed, which can then be compiled and loaded with semodule. This directly matches the requirement to analyze the audit log and suggest minimum policy changes.

Exam trap

The trap here is confusing tools that display audit logs (ausearch) with tools that generate policy from them (audit2allow), or assuming that setsebool or restorecon can dynamically create new allow rules when they only toggle existing booleans or fix file contexts.

How to eliminate wrong answers

Option A is wrong because ausearch only queries and filters audit logs; it displays denial events but does not generate policy suggestions or allow rules. Option C is wrong because setsebool toggles existing SELinux booleans on or off, but it does not analyze audit logs or create new policy rules. Option D is wrong because restorecon resets the SELinux context of files to their default values based on policy, which addresses file labeling issues but does not analyze audit logs or suggest policy changes.

95
MCQhard

A security administrator is hardening a Linux server that uses firewalld. The server hosts a web application that must be accessible only from the internal network 192.168.1.0/24 on port 443. The administrator wants to implement this using a rich rule in the public zone and ensure it persists across reboots. Which sequence of commands should the administrator use?

A.firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --runtime-to-permanent
B.firewall-cmd --permanent --zone=public --add-service=https && firewall-cmd --reload
C.firewall-cmd --permanent --zone=public --add-source=192.168.1.0/24 --add-port=443/tcp && firewall-cmd --reload
D.firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --reload
AnswerD

This command adds a permanent rich rule to the public zone that accepts IPv4 traffic from the specified subnet to TCP port 443, then reloads firewalld to apply the change immediately. The --permanent flag ensures the rule survives reboots, and the reload activates it without dropping existing connections.

Why this answer

Using a rich rule with --permanent allows granular control, specifying source address, port, and protocol in one rule. The subsequent reload applies the permanent configuration to the runtime environment. This meets the requirement of restricting access to the internal subnet on port 443 and ensuring persistence.

Exam trap

The trap here is confusing the --permanent flag with the need to reload, or assuming that adding a service or separate source/port achieves the same granular restriction as a rich rule.

96
MCQmedium

A Linux administrator needs to configure a system to use a central authentication service. The service requires that user credentials are sent over the network in an encrypted format and that the client validates the server's certificate. Which of the following should the administrator configure?

A.Configure Kerberos with a keytab file and set the default realm in /etc/krb5.conf.
B.Configure NIS with a secured map and use ypbind with a password.
C.Configure SSSD with ldap_id_use_start_tls = true and ldap_tls_reqcert = never.
D.Configure LDAP with TLS using the ldaps:// URI and set TLS_REQCERT to demand in /etc/ldap/ldap.conf.
AnswerD

Using LDAPS (LDAP over TLS) encrypts the authentication traffic. Setting TLS_REQCERT to demand enforces certificate validation, ensuring the client verifies the server's certificate. This meets both the encryption and validation requirements. It is a standard way to secure LDAP communications.

Why this answer

LDAP with TLS (LDAPS) encrypts authentication traffic, and setting TLS_REQCERT to demand ensures the client validates the server's certificate. This combination meets both the encryption and validation requirements. The other options either lack certificate validation or use insecure protocols.

Exam trap

The trap here is confusing encryption with certificate validation; some options encrypt traffic but do not verify the server's identity.

97
MCQmedium

An administrator needs to generate a self-signed certificate and private key for a web server. Which openssl command accomplishes this?

A.openssl genrsa -out key.pem 2048 && openssl req -new -x509 -key key.pem -out cert.pem -days 365
B.openssl req -new -key key.pem -out csr.pem
C.openssl ca -in csr.pem -out cert.pem
D.openssl x509 -req -in csr.pem -signkey key.pem -out cert.pem
AnswerA

Chaining genrsa with req -new -x509 produces both the private key and a self-signed certificate in one pass. The -x509 flag makes req emit a certificate rather than a signing request, satisfying the self-signed requirement without a separate CA step.

Why this answer

It first generates a 2048-bit RSA private key using `openssl genrsa`, then uses `openssl req -new -x509` to create a self-signed X.509 certificate directly from that key, bypassing the need for a Certificate Signing Request (CSR). The `-x509` flag tells OpenSSL to output a self-signed certificate instead of a CSR, and `-days 365` sets the validity period. This two-step process produces both the private key (`key.pem`) and the self-signed certificate (`cert.pem`) required for a web server.

Exam trap

The trap here is that candidates may confuse the `openssl req -new -x509` command with the CSR-only `openssl req -new` command, or think that a CSR is required for self-signed certificates, when in fact the `-x509` flag directly outputs a self-signed certificate without needing a separate CSR step.

How to eliminate wrong answers

Option B is wrong because `openssl req -new -key key.pem -out csr.pem` only generates a Certificate Signing Request (CSR), not a self-signed certificate; it requires a CA to sign the CSR to produce a certificate. Option C is wrong because `openssl ca -in csr.pem -out cert.pem` assumes a CA infrastructure is already set up and configured, and it signs an existing CSR using the CA's own key and certificate, which is not a self-signed certificate generation process. Option D is wrong because `openssl x509 -req -in csr.pem -signkey key.pem -out cert.pem` creates a self-signed certificate from a CSR, but it requires a CSR to already exist (generated by a separate command), making it a two-step process that is less direct than Option A; more importantly, it does not generate the private key, so it is incomplete for the stated requirement.

98
MCQeasy

Which log file typically records authentication failures and successes on a Debian-based system?

A./var/log/auth.log
B./var/log/messages
C./var/log/syslog
D./var/log/secure
AnswerA

On Debian-based systems, the PAM and SSH authentication subsystems write both successful and failed login events to /var/log/auth.log, making it the file that records authentication outcomes. Other distributions use /var/log/secure instead, but Debian's convention is auth.log.

Why this answer

On Debian-based systems (including Ubuntu), /var/log/auth.log is the default log file where the system's authentication subsystem writes both successful and failed authentication events. It captures output from PAM, sudo, su, sshd, and other login-related services, making it the canonical place to audit who logged in or failed to log in. Because Debian's rsyslog configuration routes authpriv facility messages to this file, it is the correct answer for authentication success and failure records.

Exam trap

XK0-006 often tests the Debian-vs-RHEL log file split, tricking candidates who memorize /var/log/secure or /var/log/messages as universal authentication logs when those are Red Hat conventions.

How to eliminate wrong answers

Option B is wrong because /var/log/messages is the general system log on Red Hat-based distributions (RHEL, CentOS, Fedora), not the authentication-specific log on Debian; Debian does not create it by default. Option C is wrong because /var/log/syslog aggregates general system and kernel messages on Debian, but authentication events are split out into auth.log via the authpriv facility, so syslog is not the primary authentication record. Option D is wrong because /var/log/secure is the authentication log used by Red Hat-based systems, not Debian-based ones, and does not exist by default on Debian.

99
MCQeasy

Which command displays the current SELinux mode?

A.selinuxenabled
B.getsebool -a
C.chcon
D.sestatus
AnswerD

Running `sestatus` queries the SELinux kernel subsystem and prints the current enforcement mode (Enforcing, Permissive, or Disabled) alongside policy version and loaded policy name. This directly satisfies the stem's requirement to display the current mode, unlike `setenforce`, which changes it, or `getenforce`, which shows only the mode.

Why this answer

The 'sestatus' command displays the current SELinux mode, including whether it is enforcing, permissive, or disabled, along with other SELinux status information.

100
MCQeasy

A Linux administrator needs to grant a user named 'bob' the ability to run the /usr/bin/systemctl command as root without being prompted for a password. Which entry should be added to the sudoers file to accomplish this?

A.bob ALL=(ALL) NOPASSWD: ALL
B.bob ALL=(root) NOPASSWD: systemctl
C.bob ALL=(ALL) PASSWD: /usr/bin/systemctl
D.bob ALL=(ALL) NOPASSWD: /usr/bin/systemctl
AnswerD

This sudoers entry allows user bob to run /usr/bin/systemctl as any user (including root) without a password prompt. The NOPASSWD tag disables the password requirement, and the command is specified with its full path as required by sudoers syntax. This precisely meets the requirement to grant passwordless systemctl execution.

Why this answer

The sudoers entry must specify the user, hosts, target user, the NOPASSWD tag, and the full path to the command. The line 'bob ALL=(ALL) NOPASSWD: /usr/bin/systemctl' grants exactly the intended permission without a password, while other options either require a password, lack the full path, or grant excessive privileges. Always use visudo to edit sudoers to avoid syntax errors.

Exam trap

The trap here is forgetting that sudoers requires absolute paths for commands and misplacing the NOPASSWD tag, leading to a non-functional or overly permissive rule.

101
Multi-Selectmedium

A Linux administrator is hardening a server and needs to ensure that the system is protected against unauthorized access. The administrator wants to implement account lockout after multiple failed login attempts and enforce password complexity. Which TWO actions should the administrator take to achieve these goals? (Choose two.)

Select 2 answers
A.Add the line 'auth required pam_tally2.so deny=5' to /etc/pam.d/sshd to lock accounts after five failed SSH login attempts.
B.Configure the pam_faillock module in /etc/pam.d/system-auth and /etc/pam.d/password-auth to lock accounts after a specified number of failed attempts.
C.Set the PASS_MAX_DAYS parameter to 90 in /etc/login.defs to enforce password expiration.
D.Edit /etc/security/pwquality.conf to set minlen=12, ucredit=-1, lcredit=-1, dcredit=-1, and ocredit=-1.
E.Set the UMASK value to 077 in /etc/login.defs to restrict default file permissions.
AnswersB, D

The pam_faillock module is designed to lock user accounts after a defined number of consecutive failed authentication attempts. Configuring it in the PAM files for system-auth and password-auth ensures that lockout applies to both login and password change operations. This directly addresses the requirement to implement account lockout, and it is the standard method on modern Linux distributions.

Why this answer

To implement account lockout, the pam_faillock module must be configured in the PAM system-auth and password-auth files, which enforces lockout across authentication services. To enforce password complexity, the /etc/security/pwquality.conf file must be edited to set parameters like minlen and character class requirements. Together, these actions meet both requirements.

Exam trap

The trap here is confusing password aging with complexity and assuming that a single PAM file or a deprecated module like pam_tally2 is sufficient for comprehensive lockout.

102
MCQmedium

A security audit reveals that the system's PAM configuration does not enforce password complexity. Which PAM module and configuration line should be added to /etc/pam.d/common-password to require at least one uppercase letter, one digit, and a minimum length of 12 characters?

A.password requisite pam_pwquality.so minlen=12 ucredit=-1 dcredit=-1
B.password sufficient pam_faillock.so minlen=12 ucredit=-1 dcredit=-1
C.password required pam_cracklib.so minlen=12 ucredit=-1 dcredit=-1
D.password required pam_unix.so minlen=12 ucredit=-1 dcredit=-1
AnswerA

`pam_pwquality.so` enforces complexity at password-change time, and the negative credit values are the mechanism: `ucredit=-1` and `dcredit=-1` each demand at least one uppercase letter and one digit, while `minlen=12` sets the minimum length. The `requisite` control ensures failure blocks the password change immediately, satisfying the audit's complexity requirement.

Why this answer

The pam_pwquality.so module is the modern replacement for pam_cracklib.so and provides password quality enforcement. The line 'password requisite pam_pwquality.so minlen=12 ucredit=-1 dcredit=-1' correctly sets the minimum length to 12 and requires at least one uppercase letter (ucredit=-1) and one digit (dcredit=-1). The 'requisite' control ensures that if this module fails, the password change is rejected immediately.

Exam trap

XK0-006 often tests the difference between pam_pwquality and pam_cracklib, and candidates may incorrectly choose pam_cracklib due to its historical use.

How to eliminate wrong answers

Option B is wrong because pam_faillock.so is used for account lockout after failed login attempts, not for password complexity. Option C is wrong because pam_cracklib.so is deprecated and may not support all options like ucredit and dcredit in the same way; pam_pwquality is the current standard. Option D is wrong because pam_unix.so handles traditional Unix password authentication and does not enforce complexity requirements like minlen, ucredit, or dcredit.

103
Multi-Selectmedium

Which THREE are valid SELinux modes?

Select 3 answers
A.Strict
B.Permissive
C.Enforcing
D.Disabled
E.Audit
AnswersB, C, D

Permissive is a valid SELinux mode: policy violations are logged but not blocked, unlike Enforcing. It satisfies the stem's requirement for a genuine SELinux operating mode, alongside Enforcing and Disabled, and is commonly used for troubleshooting before switching to enforcement.

Why this answer

SELinux has exactly three operational modes, and the three correct options here are B. Permissive, C. Enforcing, and D.

Disabled. Permissive mode is valid because SELinux loads the policy and logs AVC denials to the audit log but does not actually block any access, which is useful for troubleshooting. Enforcing mode is valid because it loads the policy and actively denies and logs any operation that violates the policy.

Disabled mode is valid because it turns SELinux off entirely at the kernel level, so no policy is loaded and no AVC messages are generated. The unmarked options do not belong: Strict is not a mode but rather a type of policy (targeted vs. strict policy), and Audit is not an SELinux mode at all, though auditd is the userspace daemon that records AVC denials.

Exam trap

XK0-006 often tests the confusion between SELinux modes and policy types, or between modes and related concepts like audit logging, causing candidates to select 'Strict' or 'Audit' as valid modes.

104
Multi-Selectmedium

A security analyst is investigating a potential breach and needs to examine user login history. Which THREE commands or log files provide information about user logins? (Select THREE.)

Select 3 answers
A.last
B.lastlog
C.lastb
D./var/log/syslog
E./var/log/messages
AnswersA, B, C

The `last` command reads `/var/log/wtmp`, listing successful login sessions with usernames, terminal lines, source hosts and timestamps. This directly satisfies the analyst's need to examine user login history during breach investigation, showing who logged in, from where, and when.

Why this answer

The `last` command (A) reads /var/log/wtmp and displays a chronological list of all successful user logins, logouts, and system reboots, making it a primary tool for reviewing login history. The `lastlog` command (B) reads /var/log/lastlog and reports the most recent login for every user account, which is useful for spotting accounts that have never logged in or that logged in unexpectedly. The `lastb` command (C) reads /var/log/btmp and lists failed login attempts, which is essential when investigating a potential breach involving brute-force or unauthorized access attempts.

Options D and E are incorrect because /var/log/syslog and /var/log/messages are general-purpose system logs that capture a broad mix of kernel, service, and application messages; while they may incidentally contain authentication-related entries, they are not dedicated login-history sources like wtmp, lastlog, and btmp.

Exam trap

The trap here is that candidates often confuse general system logs like /var/log/syslog or /var/log/messages with dedicated authentication logs, but these files lack the structured login/out records that commands like last, lastlog, and lastb specifically parse.

105
Multi-Selectmedium

A Linux administrator is hardening an SSH server. Which two of the following settings should be applied to /etc/ssh/sshd_config to improve security?

Select 2 answers
A.Port 2222
B.X11Forwarding yes
C.PermitRootLogin no
D.PasswordAuthentication no
E.Protocol 1
AnswersC, D

Disables root SSH login, reducing attack surface.

Why this answer

Option C, PermitRootLogin no, is correct because it prevents direct root logins over SSH, forcing administrators to authenticate as an unprivileged user and then escalate privileges via sudo or su, which removes a high-value target and preserves an audit trail. Option D, PasswordAuthentication no, is correct because disabling password authentication forces the use of SSH key pairs (or another stronger method), eliminating brute-force and credential-guessing attacks against user passwords. Option A, Port 2222, merely changes the listening port and is security through obscurity—it does not fix any authentication weakness and can be scanned just as easily.

Option B, X11Forwarding yes, is wrong because enabling X11 forwarding expands the attack surface and should typically be set to no on a hardened server. Option E, Protocol 1, is wrong because SSH protocol 1 is deprecated and cryptographically broken; modern sshd_config uses only protocol 2 (and the Protocol directive is obsolete in current OpenSSH).

Exam trap

XK0-006 often tests whether candidates can distinguish genuine hardening controls from security-through-obscurity measures like non-standard ports, and whether they recognize deprecated options such as Protocol 1 as insecure rather than secure.

106
MCQeasy

An administrator wants to ensure that only users in the 'wheel' group can use the sudo command. Which directive in /etc/sudoers enables this?

A.%wheel ALL=ALL
B.@wheel ALL=(ALL) ALL
C.%wheel ALL=(ALL) ALL
D.wheel ALL=(ALL) ALL
AnswerC

The %wheel ALL=(ALL) ALL entry grants members of the wheel group permission to run any command as any user, identified by the leading % group prefix. This restricts sudo rights to wheel members alone, satisfying the requirement that only that group may use sudo.

Why this answer

%wheel ALL=(ALL) ALL grants sudo access to all members of the wheel group.

107
MCQmedium

An administrator needs to configure SELinux to allow the Apache HTTP server to connect to a database server. Which SELinux boolean should be enabled?

A.httpd_can_network_connect
B.httpd_enable_cgi
C.httpd_use_nfs
D.httpd_can_network_connect_db
AnswerD

Enabling httpd_can_network_connect_db permits the httpd_t domain to open network sockets to database ports, directly satisfying the requirement that Apache connect to a database server. Other booleans govern unrelated access, such as outbound connections generally or specific database types, so this one precisely matches the stated constraint.

Why this answer

The SELinux boolean `httpd_can_network_connect_db` specifically allows the Apache HTTP server to make outbound TCP connections to database servers (e.g., MySQL, PostgreSQL). This is required when a web application needs to query a remote database. The other booleans control different aspects of httpd's behavior and do not grant network connectivity to databases.

Exam trap

A common pitfall in SELinux configuration is confusing the general network connect boolean (`httpd_can_network_connect`) with the database-specific boolean (`httpd_can_network_connect_db`). In this scenario, the database-targeted boolean is required.

How to eliminate wrong answers

Option A is wrong because `httpd_can_network_connect` allows general outbound network connections (e.g., to any TCP port), which is broader than needed and may introduce unnecessary risk; it does not specifically target database connections. Option B is wrong because `httpd_enable_cgi` controls whether httpd can execute CGI scripts, not network connectivity. Option C is wrong because `httpd_use_nfs` allows httpd to access files on NFS mounts, not to connect to a database server over the network.

108
Multi-Selectmedium

A Linux engineer needs to restrict resource usage for users in the 'developers' group. Which TWO files or commands can be used to set ulimit values?

Select 2 answers
A.sysctl command
B./etc/security/limits.conf
C./etc/pam.d/login with pam_limits.so
D./etc/ulimit.conf
E.ulimit command
AnswersB, E

/etc/security/limits.conf defines per-user and per-group ulimit values, letting the engineer apply soft and hard resource caps to the 'developers' group through a group entry, which satisfies the requirement to restrict resource usage for that group.

Why this answer

Option B, /etc/security/limits.conf, is correct because this is the PAM configuration file where persistent per-user or per-group resource limits (such as nproc, nofile, or memlock) are defined using entries like '@developers hard nproc 20'. Option E, the ulimit command, is correct because it is the shell builtin used to view or set soft and hard resource limits for the current shell session, for example 'ulimit -u 20' to cap processes. Option C is not correct on its own because /etc/pam.d/login with pam_limits.so is the PAM module that enforces the limits defined in limits.conf, but it is not where the ulimit values themselves are set.

Option A, sysctl, is incorrect because it tunes kernel parameters at runtime (e.g., net.ipv4.ip_forward) rather than per-user resource limits. Option D, /etc/ulimit.conf, is incorrect because no such standard file exists for setting ulimit values.

Exam trap

The trap here is that candidates often confuse the configuration file (/etc/security/limits.conf) with the PAM module file (/etc/pam.d/login) or think the ulimit command alone can set persistent limits for a group, when in fact ulimit only affects the current shell session and is not persistent across logins for all group members.

109
Multi-Selectmedium

A compliance auditor requires that a Linux server's /home directory be mounted with options that prevent users from executing setuid binaries stored there and from creating device files. The administrator is editing /etc/fstab for the /home entry. Which TWO mount options should be added to meet these requirements? (Choose two.)

Select 2 answers
A.noatime
B.ro
C.nosuid
D.nodev
E.noexec
AnswersC, D

The nosuid mount option prevents the execution of setuid and setgid programs on that filesystem. Because the requirement is to stop users from running setuid binaries from /home, this option directly satisfies it. It is a standard hardening measure for user-writable directories and works at the kernel mount level without affecting file permissions.

Why this answer

The nosuid option blocks execution of setuid and setgid binaries, and nodev blocks the use of device files on the filesystem. Together they harden /home against privilege escalation and device-based attacks without preventing normal file storage. noexec, noatime, and ro either do not target the stated risks or impose excessive functional restrictions that the auditor did not request.

Exam trap

The trap here is reaching for noexec when the requirement is specifically to block setuid execution, since noexec is broader and does not cover device files.

← PreviousPage 2 of 2 · 109 questions total

Ready to test yourself?

Try a timed practice session using only Lxp Security questions.