Courseiva

CCNA Networking Questions

75 of 97 questions · Page 1/2 · Networking topic · Answers revealed

1
MCQmedium

A financial firm requires all internal SSH connections to be encrypted with at least 256-bit ciphers. An administrator is configuring the SSH server. Which configuration line should be added to /etc/ssh/sshd_config?

A.MACs hmac-sha2-256
B.KexAlgorithms diffie-hellman-group-exchange-sha256
C.Ciphers aes256-ctr
D.HostKeyAlgorithms ssh-rsa
AnswerC

Restricting the server to `aes256-ctr` satisfies the 256-bit minimum by offering only that cipher during negotiation. Unlike `aes128-ctr`, it meets the stated strength floor, and unlike broad lists such as `aes256-ctr,aes128-ctr`, it cannot silently downgrade to a weaker algorithm.

Why this answer

The Ciphers directive in sshd_config explicitly controls the symmetric encryption algorithms used to encrypt SSH session data. The cipher aes256-ctr provides 256-bit encryption, meeting the firm's requirement for at least 256-bit ciphers. Other directives like MACs, KexAlgorithms, or HostKeyAlgorithms do not directly set the encryption cipher strength.

Exam trap

The trap here is that candidates confuse MACs, KexAlgorithms, or HostKeyAlgorithms with encryption ciphers, assuming any directive with '256' or 'sha256' implies 256-bit encryption, when only the Ciphers directive controls the symmetric encryption algorithm strength.

How to eliminate wrong answers

Option A is wrong because MACs (Message Authentication Codes) specify integrity-check algorithms like hmac-sha2-256, not encryption ciphers; they ensure data authenticity, not confidentiality. Option B is wrong because KexAlgorithms define key exchange methods (e.g., diffie-hellman-group-exchange-sha256) that negotiate session keys, but they do not determine the symmetric cipher used for encrypting the actual data stream. Option D is wrong because HostKeyAlgorithms specify which host key types (e.g., ssh-rsa) are accepted for server authentication, not the encryption cipher for the session.

2
Multi-Selecthard

A Linux server has two interfaces, ens5 (203.0.113.10/24) and ens6 (10.20.0.0/24 gateway for internal clients). Internal clients must reach the internet through ens5. The administrator has enabled net.ipv4.ip_forward=1 and configured NAT on ens5, but clients still cannot reach external hosts. Which two additional checks are most likely to resolve the problem? (Choose two.)

Select 2 answers
A.Confirm that the MASQUERADE or SNAT rule matches the outbound interface and source subnet correctly.
B.Disable the reverse path filter by setting net.ipv4.conf.all.rp_filter to 2.
C.Add a static route on the internal clients pointing to the public internet address 203.0.113.10 as the next hop.
D.Verify that the FORWARD chain policy or rules permit traffic between ens6 and ens5.
E.Ensure that the server's default route points to the upstream router on the ens5 network.
AnswersA, D

A NAT rule that references the wrong interface, such as the internal one instead of ens5, or an incorrect source range, will not translate the clients' private addresses. External hosts then have no route back to the 10.20.0.0/24 network, so replies never arrive. Verifying the rule's match criteria is essential when NAT appears configured but does not function.

Why this answer

When IP forwarding and NAT appear configured but clients still fail, the two most common culprits are a restrictive FORWARD chain that drops inter-interface traffic and a NAT rule whose interface or source match is wrong. Both must be verified because either alone prevents end-to-end connectivity for the internal subnet.

Exam trap

The trap here is assuming that enabling ip_forward and writing any NAT rule is sufficient, when firewall forwarding policy and precise NAT match criteria must both be correct.

3
MCQhard

You are a senior Linux administrator for a large data center. A junior admin reports that a newly deployed application server (192.168.100.50/24, default gateway 192.168.100.1) cannot communicate with a legacy server (192.168.200.50/24, default gateway 192.168.200.1). The two subnets are connected via a router (192.168.100.1 and 192.168.200.1). From the app server, you can ping the legacy server's IP successfully. However, when you try to establish an SSH session from the app server to the legacy server, it times out. You check the legacy server's firewall (ufw) and find that it allows SSH (port 22) from the entire 192.168.0.0/16 range. You also confirm that the SSH daemon is running and listening on 0.0.0.0:22. What is the most likely cause?

A.The router is dropping TCP packets due to ACLs.
B.The legacy server's firewall is not allowing SSH; the rule might be misconfigured.
C.The app server's firewall (ufw) is blocking incoming SSH responses.
D.The legacy server's SSH service is not listening on the correct interface.
AnswerC

Since SSH is a TCP connection, the app server sends SYN, and the legacy server replies with SYN-ACK. If the app server's ufw does not allow related/established connections or has a rule that blocks new incoming connections, the SYN-ACK will be dropped, causing a timeout. This is a common misconfiguration.

Why this answer

The app server can ping the legacy server successfully, which confirms that ICMP traffic (Layer 3) passes through the router and that the legacy server's firewall allows ICMP. However, SSH (TCP port 22) fails because the app server's own firewall (ufw) is blocking the incoming SSH response packets (SYN-ACK) from the legacy server. Since the SSH client initiates the connection from the app server, the response packets must be allowed by the app server's firewall; if ufw on the app server blocks established or related incoming traffic, the TCP handshake cannot complete, resulting in a timeout.

Exam trap

The trap here is that candidates assume the problem must be on the target server (firewall or SSH service) because the symptom is a timeout, but the ping success proves Layer 3 connectivity, shifting the issue to the client-side firewall blocking the TCP handshake response.

How to eliminate wrong answers

Option A is wrong because the app server can ping the legacy server successfully, which proves that the router is forwarding packets between subnets and that no ACL is blocking ICMP; if the router were dropping TCP packets due to ACLs, the ping would also likely fail or at least the router's behavior would be inconsistent. Option B is wrong because the legacy server's firewall explicitly allows SSH from the entire 192.168.0.0/16 range, which includes the app server's IP (192.168.100.50), and the SSH daemon is confirmed running and listening on 0.0.0.0:22, so the firewall is not the issue. Option D is wrong because the SSH daemon is listening on 0.0.0.0:22, which means it accepts connections on all interfaces, including the one with IP 192.168.200.50; there is no interface-specific misconfiguration.

4
MCQhard

An administrator is configuring a Linux server as a router. The server has two interfaces: eth0 (192.168.10.1/24) connected to the internal LAN and eth1 (203.0.113.2/24) connected to the internet. After enabling IP forwarding, internal clients still cannot reach external websites. Which command is required to allow the internal subnet to be translated to the external interface?

A.iptables -A FORWARD -s 192.168.10.0/24 -o eth1 -j ACCEPT
B.iptables -t nat -A POSTROUTING -s 192.168.10.0/24 -o eth1 -j MASQUERADE
C.iptables -t nat -A PREROUTING -s 192.168.10.0/24 -o eth1 -j MASQUERADE
D.iptables -t nat -A POSTROUTING -d 192.168.10.0/24 -i eth1 -j SNAT --to-source 203.0.113.2
AnswerB

This rule performs source NAT (masquerading) for traffic from the internal subnet leaving via eth1. It rewrites the source address to that of eth1, allowing return traffic. Without it, external hosts cannot route replies back to the private 192.168.10.0/24 network, so clients fail to reach websites.

Why this answer

For internal clients to reach the internet through a Linux router, their private source addresses must be translated to the router's public address. The correct rule uses the nat table's POSTROUTING chain with MASQUERADE on the outbound interface, enabling source NAT for the internal subnet.

Exam trap

The trap here is selecting a FORWARD rule alone, forgetting that NAT is also needed for private addresses to communicate with external networks.

5
MCQmedium

A storage administrator must add a persistent secondary IPv4 address 192.0.2.50/24 to interface eth1 on a RHEL 9 server using NetworkManager. The primary address is already configured. Which command adds the address so that it survives a reboot?

A.ip addr add 192.0.2.50/24 dev eth1
B.echo 'IPADDR1=192.0.2.50' >> /etc/sysconfig/network-scripts/ifcfg-eth1 && systemctl restart network
C.nmcli con mod eth1 +ipv4.addresses 192.0.2.50/24 && nmcli con up eth1
D.nmcli con mod eth1 ipv4.addresses 192.0.2.50/24 && nmcli con up eth1
AnswerC

The nmcli con mod command with the + prefix appends the address to the existing ipv4.addresses list in the connection profile, preserving the primary address. Running nmcli con up reactivates the connection and applies the change. Because the profile is stored persistently, the secondary address is restored on reboot, satisfying the requirement.

Why this answer

On RHEL 9, NetworkManager stores connection profiles, and nmcli con mod edits them persistently. Using the + prefix before ipv4.addresses appends the new address to the existing list, preserving the primary address. Reactivating the connection with nmcli con up applies the change immediately, and the profile ensures the secondary address returns after a reboot.

Exam trap

The trap here is omitting the + prefix, which silently replaces the existing address list instead of appending to it.

6
MCQeasy

A system administrator needs to permanently configure a network interface named ens33 with a static IPv4 address of 192.168.1.100/24 and a default gateway of 192.168.1.1 on a system using NetworkManager. Which command should the administrator use to achieve this?

A.nmcli connection modify 'ens33' ipv4.addresses 192.168.1.100/24 ipv4.gateway 192.168.1.1 ipv4.method manual
B.ip addr add 192.168.1.100/24 dev ens33
C.ifconfig ens33 192.168.1.100 netmask 255.255.255.0 up
D.route add default gw 192.168.1.1 ens33
AnswerA

The `nmcli connection modify` command writes the static IPv4 address, prefix and default gateway into the NetworkManager connection profile, and `ipv4.method manual` disables DHCP so the settings survive reboot. This satisfies the requirement for a permanent configuration, unlike `ip addr add`, which only changes the running kernel state.

Why this answer

It uses the `nmcli` command to modify the NetworkManager connection profile for interface ens33, setting a static IPv4 address with CIDR notation and a default gateway, and explicitly setting the method to 'manual' to ensure the configuration persists across reboots. NetworkManager is the default network service on modern Linux distributions, and `nmcli` is the proper tool for permanent configuration changes.

Exam trap

The trap here is that candidates often choose temporary commands like `ip addr add` or `ifconfig` because they work immediately, but the LFCS exam specifically tests the ability to make permanent changes using the system's network management service (NetworkManager) rather than transient runtime commands.

How to eliminate wrong answers

Option B is wrong because `ip addr add` only adds an IP address temporarily to the interface; it does not persist after a reboot and does not configure a default gateway or set the addressing method to manual. Option C is wrong because `ifconfig` is deprecated and does not provide persistent configuration; any changes made with it are lost on reboot, and it does not interact with NetworkManager. Option D is wrong because `route add default gw` only adds a temporary default route; it does not set a static IP address, does not persist across reboots, and does not use NetworkManager's configuration system.

7
MCQhard

An administrator must ensure that a Linux router forwards IPv4 packets between its two interfaces, eth0 and eth1, without rebooting. Which command enables this behavior immediately?

A.iptables -A FORWARD -j ACCEPT
B.echo 1 > /proc/sys/net/ipv4/ip_forward
C.ip link set eth0 up && ip link set eth1 up
D.sysctl -w net.ipv4.ip_forward=1
AnswerD

The sysctl -w command writes the value 1 to the net.ipv4.ip_forward kernel parameter at runtime, immediately enabling IPv4 packet forwarding. This satisfies the requirement without a reboot. The change is temporary unless also written to /etc/sysctl.conf or a file under /etc/sysctl.d/ for persistence.

Why this answer

Enabling IPv4 forwarding requires setting the kernel parameter net.ipv4.ip_forward to 1. The sysctl -w command applies this change at runtime, immediately allowing the router to forward packets between interfaces. Firewall rules and interface states are separate concerns; they do not substitute for the kernel forwarding parameter.

Exam trap

The trap here is confusing firewall FORWARD rules or interface activation with the kernel's routing capability.

8
MCQhard

A systemd-networkd managed interface enp1s0 needs to be configured with a static IP address 192.168.1.100/24 and a default gateway via 192.168.1.1. Which .network file configuration is correct?

A.[Match] Interface=enp1s0 [Network] StaticIP=192.168.1.100/24 Gateway=192.168.1.1
B.[Link] Name=enp1s0 [Network] IPAddress=192.168.1.100/24 Gateway=192.168.1.1
C.[Match] Name=enp1s0 [Network] Address=192.168.1.100/24 Gateway=192.168.1.1
D.[Match] Name=enp1s0 [Network] Address=192.168.1.100/24 DefaultGateway=192.168.1.1
AnswerC

systemd-networkd reads [Match] to bind the file to enp1s0, then [Network] applies the static address and default gateway. Address=192.168.1.100/24 sets the host address and prefix, while Gateway=192.168.1.1 installs the default route, satisfying both stem requirements exactly.

Why this answer

Systemd-networkd uses the `[Match]` section with `Name=` to match the interface, and the `[Network]` section with `Address=` to assign a static IP address and `Gateway=` to set the default gateway. The syntax `Address=192.168.1.100/24` is the proper directive for defining a static IP address in a .network file, and `Gateway=192.168.1.1` correctly specifies the default gateway.

Exam trap

The trap here is that candidates confuse the `[Match]` section key `Name=` with `Interface=` (which is used in other tools like ifcfg files) and mistakenly use `DefaultGateway=` (a valid directive in some network configuration systems like Netplan) instead of the correct `Gateway=` in systemd-networkd.

How to eliminate wrong answers

Option A is wrong because it uses `Interface=` in the `[Match]` section (the correct key is `Name=`) and `StaticIP=` in the `[Network]` section (the correct key is `Address=`). Option B is wrong because it uses `[Link]` instead of `[Match]` to identify the interface, and `IPAddress=` is not a valid directive in the `[Network]` section (the correct directive is `Address=`). Option D is wrong because it uses `DefaultGateway=` instead of the correct `Gateway=` directive for setting the default gateway in systemd-networkd.

9
MCQhard

You are a systems administrator for a company that runs a critical application on a Linux server with two network interfaces: eth0 (public IP 203.0.113.10/24, gateway 203.0.113.1) and eth1 (private IP 10.0.1.10/24, no gateway). The server must be accessible via SSH (port 22) from the internet, but only from a specific management subnet 198.51.100.0/24. Additionally, the server should be able to access the internet for package updates, but no other inbound traffic from the internet is allowed. The local firewall is iptables. After implementing rules, you find that the server cannot reach the internet (e.g., ping 8.8.8.8 fails), but SSH from the management subnet works. What is the most likely cause?

A.The server's DNS resolver is not configured
B.The SSH rule is misconfigured and accidentally blocks all traffic
C.The iptables rules do not include a rule to allow established and related connections
D.The default policy on the INPUT chain is DROP
AnswerC

Without a state tracking rule, return traffic for outbound connections is blocked, breaking internet access.

Why this answer

Iptables is stateful: by default, the INPUT chain processes only the first packet of a connection. Without a rule allowing established and related connections (e.g., `-m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT`), return traffic from the server's outbound internet requests (e.g., ping to 8.8.8.8) is blocked by the INPUT chain, causing the failure. SSH from the management subnet works because the initial SYN packet is allowed, but the server's outbound traffic fails because the response packets are not recognized as part of an allowed flow.

Exam trap

The trap here is that candidates assume a default DROP policy on INPUT is the root cause, but they overlook that stateful filtering requires an explicit rule for return traffic, which is a classic LFCS and iptables nuance.

How to eliminate wrong answers

Option A is wrong because DNS resolution is irrelevant to a direct ping to 8.8.8.8 (an IP address), and the question states the server cannot reach the internet at all, not just resolve names. Option B is wrong because if the SSH rule were misconfigured and accidentally blocked all traffic, SSH from the management subnet would also fail, but the question confirms SSH works. Option D is wrong because a default DROP policy on the INPUT chain would still allow SSH from the management subnet if an explicit ACCEPT rule exists for that traffic; the issue is specifically that outbound-initiated traffic's return packets are not matched by any rule, not the default policy itself.

10
MCQeasy

An administrator needs to temporarily assign the IPv4 address 172.16.5.20/24 to interface ens3, which is currently up but unconfigured. The change should not persist across reboots. Which command accomplishes this?

A.nmcli con mod ens3 ipv4.addresses 172.16.5.20/24
B.ip link set ens3 address 172.16.5.20/24
C.ifconfig ens3 172.16.5.20 netmask 255.255.255.0 up
D.ip addr add 172.16.5.20/24 dev ens3
AnswerD

The ip addr add command from the iproute2 suite assigns an address to a specific interface for the current runtime. Because it does not write to any persistent configuration file, the address disappears after a reboot, which matches the requirement for a temporary change on an already-up interface.

Why this answer

Runtime address assignment on Linux is performed with the iproute2 ip addr add command, which targets a named interface and does not alter persistent configuration. NetworkManager's nmcli modifies stored profiles and persists changes, while ifconfig is legacy. The ip command is the current, supported tool for non-persistent interface changes.

Exam trap

The trap here is reaching for nmcli or ifconfig out of habit, when the requirement is a temporary change and the supported modern tool is ip.

11
MCQeasy

A technician must verify which network services are listening on TCP ports and which processes own them on a production server. Which command provides this information directly?

A.lsof -i :22
B.netstat -rn
C.ss -tlnp
D.ip neigh show
AnswerC

The ss command from iproute2 displays socket statistics. The flags -t, -l, -n, and -p select TCP sockets, listening state, numeric addresses, and the owning process respectively. This combination directly lists listening TCP ports along with the process names and PIDs that hold them, matching the requirement.

Why this answer

The ss utility with the -tlnp flags enumerates TCP listening sockets, keeps addresses numeric, and shows the owning process for each. This single command answers both parts of the requirement: which ports are listening and which processes hold them. The other tools either display unrelated tables or cover only a single port.

Exam trap

The trap here is picking a legacy or single-purpose tool like netstat or lsof when ss -tlnp is the modern command that lists all listening TCP sockets with their processes.

12
MCQhard

An administrator is troubleshooting name resolution on a server. Queries for internal names succeed, but every query for external names fails with 'connection timed out; no servers could be reached'. The file /etc/resolv.conf contains 'nameserver 10.20.30.40' and 'nameserver 10.20.30.41'. The internal DNS servers are reachable, and the administrator wants to test which external name servers actually respond. Which command best performs this test?

A.getent hosts example.com
B.nslookup 8.8.8.8 example.com
C.dig example.com
D.dig @8.8.8.8 example.com
AnswerD

The dig command with an explicit @server argument sends the query directly to that name server, bypassing the servers listed in resolv.conf. This lets the administrator confirm whether an external resolver answers, isolating whether the failure lies with the configured internal servers or with outbound DNS connectivity.

Why this answer

To determine whether an external resolver responds, the query must be sent directly to that resolver rather than to the servers in resolv.conf. The dig command's @server syntax does exactly this, bypassing local configuration. If a direct query to a public resolver succeeds, the problem is with the internal servers' forwarding or recursion; if it fails, outbound DNS traffic is likely blocked.

Exam trap

The trap here is running dig without an @server argument, which silently reuses the resolv.conf servers that are already known to be failing for external names.

13
Multi-Selectmedium

A Linux server has two network interfaces: eth0 (192.168.1.10/24) and eth1 (10.0.0.10/24). The administrator wants to configure the server to route traffic between the two networks. Which two actions are required? (Choose two.)

Select 2 answers
A.Set the default gateway on both client networks to point to the server's respective interface addresses.
B.Enable NAT (masquerading) on the server for both networks.
C.Configure iptables FORWARD rules to accept traffic between the interfaces.
D.Add static routes on the server for both networks.
E.Enable IP forwarding by setting net.ipv4.ip_forward=1.
AnswersC, E

By default, many distributions have a firewall that drops forwarded packets. Adding iptables FORWARD rules to accept traffic ensures that packets are not blocked by the firewall. This is required in addition to enabling IP forwarding for the server to route traffic successfully.

Why this answer

To route traffic between two directly connected networks, the server must have IP forwarding enabled and firewall rules that permit forwarding. Connected routes already exist, so static routes for those networks are not needed. NAT is not required for internal routing, and client gateway configuration is done on the clients, not the server.

Exam trap

The trap here is assuming that NAT or static routes are needed for internal routing, when only forwarding and firewall permissions are required.

14
MCQeasy

The command 'ss -tuln' shows port 80 is listening on a server, but a remote client cannot connect via HTTP. What is the most likely cause?

A.The HTTP service is not running
B.The client has a misconfigured default gateway
C.The server's /etc/hosts file is misconfigured
D.A firewall is blocking incoming TCP port 80
AnswerD

The socket is bound and listening, so the service itself is reachable locally; the failure occurs in transit. A firewall dropping or rejecting inbound TCP port 80 prevents the remote client's SYN from reaching the listener, which is the classic symptom here.

Why this answer

The `ss -tuln` command shows that port 80 is in the LISTEN state, which means the HTTP service (e.g., Apache or Nginx) is bound to the port and ready to accept connections. Since the server is listening but the remote client cannot connect, the most likely cause is a firewall (such as iptables, nftables, or a cloud security group) that is blocking incoming TCP SYN packets destined for port 80, preventing the three-way handshake from completing.

Exam trap

The trap here is that candidates see 'listening' on port 80 and assume the service is fully accessible, forgetting that a firewall can silently drop incoming packets even when the service is up and listening.

How to eliminate wrong answers

Option A is wrong because if the HTTP service were not running, `ss -tuln` would not show port 80 in the LISTEN state; the command output explicitly confirms the service is running. Option B is wrong because a misconfigured default gateway on the client would prevent the client from reaching any remote network, not just port 80 on this specific server; the client can likely reach other services or the server itself via other ports. Option C is wrong because the `/etc/hosts` file is used for local hostname resolution and does not affect network connectivity at the transport layer; a misconfigured hosts file would cause a DNS-like resolution failure, not a TCP connection timeout or reset.

15
MCQeasy

A system administrator needs to ensure that a Linux server can communicate with other hosts on the same subnet. Which command should be used to verify the IP address and netmask configuration?

A.netstat -rn
B.route -n
C.ifconfig
D.ip addr show
AnswerD

ip addr show displays each interface's assigned IPv4 address and prefix length, letting the administrator confirm subnet configuration and netmask. It reads kernel state directly, satisfying the stem's requirement to verify addressing before testing same-subnet communication.

Why this answer

The `ip addr show` command is the modern, recommended tool in Linux for viewing IP addresses and netmasks (prefix lengths) assigned to network interfaces. It directly displays the configuration needed to verify subnet communication, unlike legacy tools that may not show the netmask clearly or mix routing information.

Exam trap

The trap here is that candidates often choose `ifconfig` out of habit, not realizing it is deprecated and may be missing on minimal installations, while `ip addr show` is the current standard and always available in modern Linux distributions.

How to eliminate wrong answers

Option A is wrong because `netstat -rn` displays the kernel routing table, not IP address or netmask configuration. Option B is wrong because `route -n` also shows the routing table, not interface IP/netmask details. Option C is wrong because `ifconfig` is deprecated and may not be installed by default on modern distributions; it can show IP and netmask but is less reliable and lacks the structured output of `ip`.

16
MCQhard

A technician configured a new network interface eth1 on a CentOS 7 server but the interface does not obtain an IPv4 address via DHCP. Which of the following is the most likely cause?

A.The interface MTU is set too high
B.SELinux is blocking dhclient
C.NetworkManager is not managing the interface (NM_CONTROLLED=no)
D.Firewalld is blocking DHCP ports (67/68)
AnswerC

When NM_CONTROLLED=no, NetworkManager ignores the interface, so DHCP is not attempted.

Why this answer

When NM_CONTROLLED=no is set in the interface configuration file (/etc/sysconfig/network-scripts/ifcfg-eth1), NetworkManager will not manage that interface. Since dhclient is typically invoked by NetworkManager (or by legacy network scripts only if NM_CONTROLLED=yes), the interface will not automatically obtain an IPv4 address via DHCP. On CentOS 7, NetworkManager is the default network service, and disabling its control prevents DHCP client activation.

Exam trap

The trap here is that candidates often assume firewall or SELinux is the culprit for DHCP failures, but the most common cause on CentOS 7 is the NM_CONTROLLED=no setting, which disables NetworkManager's DHCP client management.

How to eliminate wrong answers

Option A is wrong because MTU (Maximum Transmission Unit) being set too high does not prevent DHCP from obtaining an address; DHCP uses Layer 2 broadcast frames and Layer 3 UDP packets, and MTU issues typically cause fragmentation or packet loss, not a complete failure to acquire an IP. Option B is wrong because SELinux does not block dhclient by default; dhclient runs in the dhcpc_t domain, and SELinux policies allow it to send and receive DHCP packets on ports 67/68. Option D is wrong because firewalld blocking DHCP ports (67/68) would prevent DHCP discovery and offer packets from reaching the client, but the question states the interface does not obtain an IPv4 address via DHCP—firewalld could cause this, but it is less likely than the direct configuration issue of NM_CONTROLLED=no, which is a common misconfiguration on CentOS 7.

17
MCQhard

A Linux server is unable to resolve the hostname 'app.internal.example.com' but can resolve other names. The /etc/nsswitch.conf file contains: hosts: files mdns4_minimal [NOTFOUND=return] dns. The /etc/hosts file does not list the hostname. Which configuration change would most likely resolve the issue?

A.Change the hosts line to: hosts: dns files mdns4_minimal
B.Configure /etc/resolv.conf to use a different DNS server
C.Remove the mdns4_minimal entry or change it to 'mdns4' without the NOTFOUND=return
D.Add the hostname to the local multicast DNS configuration
AnswerC

Removing `mdns4_minimal` or dropping its `[NOTFOUND=return]` action stops the resolver aborting the lookup when multicast DNS returns nothing. With that action present, the `dns` source is never consulted for names mDNS cannot answer, so `app.internal.example.com` fails despite DNS being reachable.

Why this answer

The issue is that mdns4_minimal with [NOTFOUND=return] causes the resolver to stop after a failed mDNS query, preventing it from falling back to DNS. Since the hostname is not in /etc/hosts and not reachable via mDNS, the resolver returns 'not found' immediately without querying DNS. Removing the mdns4_minimal entry or changing it to 'mdns4' (without the NOTFOUND=return) allows the resolver to proceed to DNS if mDNS fails.

Exam trap

The trap here is that candidates assume the issue is with DNS configuration or order, but the real problem is the [NOTFOUND=return] action on mdns4_minimal, which prematurely terminates the resolution chain for non-.local hostnames.

How to eliminate wrong answers

Option A is wrong because changing the order to 'dns files mdns4_minimal' would still leave the mdns4_minimal with [NOTFOUND=return] in place, so if mDNS fails, the resolver still returns immediately without consulting DNS. Option B is wrong because the server can resolve other names, indicating that the DNS server in /etc/resolv.conf is working correctly; the problem is specific to the resolution order and fallback behavior, not the DNS server itself. Option D is wrong because adding the hostname to multicast DNS configuration would only help if the hostname is served via mDNS on the local link, but the hostname 'app.internal.example.com' is likely a standard DNS name, not a .local mDNS name, so mDNS would not resolve it anyway.

18
MCQhard

A server has multiple IP aliases on eth0. Remote hosts cannot reach the secondary IP addresses. What should the administrator check?

A.The server's routing table includes routes for the secondary IPs' subnets.
B.The ARP flux settings are configured correctly.
C.The interface is set to NOARP.
D.The secondary IPs are in the same subnet as the primary.
AnswerB

ARP flux controls how the kernel replies to ARP requests across interfaces. With multiple IP aliases on eth0, incorrect arp_ignore or arp_announce settings cause replies to secondary addresses from the wrong interface, so remote hosts cannot reach them.

Why this answer

When multiple IP aliases are configured on a single Ethernet interface, the kernel may respond to ARP requests inconsistently, a behavior known as ARP flux. This causes remote hosts to receive conflicting MAC addresses for the secondary IPs, preventing connectivity. Correctly configuring ARP flux settings (e.g., using `arp_ignore=1` and `arp_announce=2` via sysctl) ensures the kernel responds only from the appropriate IP and advertises the correct MAC.

Exam trap

The trap here is that candidates assume secondary IPs must be in the same subnet as the primary (Option D) or that routing entries are needed (Option A), when the actual cause is the kernel's default ARP behavior, which is controlled by sysctl settings.

How to eliminate wrong answers

Option A is wrong because the routing table does not need routes for the secondary IPs' subnets; the secondary IPs are local to the interface, and the kernel handles them via local routing automatically. Option C is wrong because setting the interface to NOARP would disable ARP entirely, preventing any IP communication on that interface, not just secondary IPs. Option D is wrong because secondary IPs can be in a different subnet from the primary; the issue is ARP flux, not subnet matching.

19
MCQhard

A server uses firewalld. Which command permanently allows HTTP traffic?

A.firewall-cmd --add-service=http
B.firewall-cmd --add-service=http --permanent
C.firewall-cmd --add-port=80/tcp
D.systemctl reload firewalld
AnswerB

The `--permanent` flag writes the HTTP service allowance into firewalld's persistent configuration, satisfying the stem's requirement that the change survive a reload or reboot. Without it, the rule would exist only in the runtime configuration and be lost. Running `firewall-cmd --reload` afterwards activates the saved rule.

Why this answer

The `--permanent` flag is required to make the rule persist across reboots when using `firewall-cmd`. Without it, the rule is only added to the runtime configuration and will be lost after a firewall reload or system restart. The `--add-service=http` parameter uses the predefined service definition for HTTP (port 80/tcp), which is the proper way to allow HTTP traffic in firewalld.

Exam trap

The trap here is that candidates often assume `firewall-cmd --add-service=http` alone is sufficient, forgetting that without `--permanent`, the rule is ephemeral and will be lost on reload or reboot.

How to eliminate wrong answers

Option A is wrong because it omits the `--permanent` flag, so the rule is applied only to the runtime configuration and will not survive a firewall reload or reboot. Option C is wrong because `--add-port=80/tcp` adds a direct port rule rather than using the predefined HTTP service; while it may work functionally, it bypasses firewalld's service abstraction and is not the standard method for allowing HTTP traffic. Option D is wrong because `systemctl reload firewalld` reloads the firewall configuration but does not add any rule; it would only apply permanent rules that were already added, not create a new rule.

20
MCQhard

Given the routing table, if the server sends a packet to destination 10.0.1.200, which interface will be used and what is the next hop?

A.eth1 via 10.0.1.1
B.eth1 directly to 10.0.1.200
C.eth0 with next hop 10.0.0.1
D.eth0 with next hop 10.0.1.200
AnswerB

The routing table contains a route for 10.0.1.0/24 reachable via eth1 with no gateway, meaning the destination is on-link. The kernel therefore resolves 10.0.1.200 directly through eth1, sending the frame to that host rather than to a next-hop router.

Why this answer

The destination 10.0.1.200 falls within the directly connected network 10.0.1.0/24 on eth1. According to the routing table, this route has a /24 netmask and is marked as directly connected, meaning no next-hop router is needed. The server will ARP for 10.0.1.200 and send the packet directly to that host via eth1.

Exam trap

The trap here is that candidates often assume all traffic must go through a gateway (next hop), forgetting that directly connected routes allow direct delivery without a router, leading them to pick Option A or C.

How to eliminate wrong answers

Option A is wrong because it incorrectly specifies a next-hop gateway (10.0.1.1) for a directly connected network; when the destination is on the same subnet, the packet is sent directly, not via a router. Option C is wrong because eth0 is associated with the 10.0.0.0/24 network, and 10.0.1.200 is not within that subnet; the routing table would not use eth0 for this destination. Option D is wrong because eth0 is not the correct interface for the 10.0.1.0/24 network, and even if it were, a directly connected route does not use a next-hop IP; the packet would be sent directly to the destination MAC.

21
MCQhard

A Linux server uses systemd-resolved for DNS resolution. Users report that queries for internal hostnames such as 'db.corp.example.com' are failing, while external names resolve correctly. The administrator runs 'resolvectl status' and sees that the interface eth0 has DNS servers 10.0.0.53 and 'DNS Domain: corp.example.com'. Which command should be used to query the internal DNS server directly and verify that it responds to the name?

A.resolvectl query db.corp.example.com
B.dig @10.0.0.53 db.corp.example.com
C.nslookup db.corp.example.com 10.0.0.53
D.systemd-resolve --status
AnswerB

This command sends a DNS query directly to the internal DNS server at 10.0.0.53, bypassing systemd-resolved. It verifies whether that specific server can resolve the hostname, isolating the problem to either the server or the local resolver configuration. If the server responds correctly, the issue is likely with systemd-resolved's routing or caching; if it fails, the DNS server itself is the problem.

Why this answer

To verify that the internal DNS server at 10.0.0.53 can resolve the hostname, the administrator should query it directly with 'dig @10.0.0.53 db.corp.example.com'. This bypasses systemd-resolved and tests the server's response. If the server answers correctly, the problem lies in systemd-resolved's configuration, such as a missing routing domain or incorrect DNS server assignment for the interface.

Exam trap

The trap here is using resolvectl query, which goes through systemd-resolved and may reproduce the same failure, instead of querying the DNS server directly to isolate the issue.

22
MCQmedium

A Linux server cannot reach the internet, but internal LAN connectivity works. The output of 'ip route' shows a default gateway of 192.168.1.1, but pinging 8.8.8.8 fails. What is the most likely cause?

A.The default gateway is not reachable or has no internet connectivity.
B.The ARP table is corrupted.
C.The default gateway is missing.
D.DNS resolution is failing.
AnswerA

LAN connectivity proves the interface and local routing work, while a failed ping to 8.8.8.8 indicates the default route's next hop cannot forward traffic. The gateway at 192.168.1.1 is either unreachable or lacks upstream internet connectivity.

Why this answer

The default gateway 192.168.1.1 is present in the routing table, but pinging 8.8.8.8 fails while internal LAN connectivity works. This indicates that the gateway itself either cannot be reached (e.g., due to a layer 2 issue or misconfiguration) or, more likely, it has no upstream internet connectivity. Since the default route is configured, the failure is not due to a missing gateway but rather the gateway's inability to forward traffic to external networks.

Exam trap

The trap here is that candidates often assume a missing default gateway is the problem when they see internet failure, but the question explicitly states the default gateway is present, shifting the focus to the gateway's own connectivity rather than the local routing table.

How to eliminate wrong answers

Option B is wrong because a corrupted ARP table would prevent communication with any host on the local subnet, including the default gateway, causing internal LAN connectivity to fail as well; since internal connectivity works, ARP is functioning correctly. Option C is wrong because the 'ip route' output explicitly shows a default gateway of 192.168.1.1, so the default gateway is not missing. Option D is wrong because DNS resolution is irrelevant when pinging a raw IP address like 8.8.8.8; the failure occurs at the network layer, not at the application layer.

23
MCQmedium

A system administrator is managing a RHEL 8 server that requires a static IP address on interface ens192. The administrator modifies /etc/sysconfig/network-scripts/ifcfg-ens192 to set BOOTPROTO=static, IPADDR=192.168.1.100, PREFIX=24, GATEWAY=192.168.1.1, and DNS1=8.8.8.8. After saving, the administrator runs 'systemctl restart NetworkManager'. The interface obtains the correct static IP and network connectivity works. However, after a reboot of the server, the interface fails to come up with the static IP and instead obtains an IP via DHCP from the local network. The administrator verifies that the DHCP server is active and that the physical connection is good. What is the most likely cause of the issue?

A.The kernel parameter nomodeset is set in /etc/default/grub.
B.The firewall is blocking the static IP assignment.
C.The ONBOOT parameter is set to no or missing in the configuration file.
D.The network service is not enabled to start at boot.
AnswerC

ONBOOT=yes is required for the interface to start at boot.

Why this answer

The ONBOOT parameter controls whether the interface is activated at system boot. If set to 'no' or missing entirely, NetworkManager will not bring up the interface automatically after a reboot, causing it to fall back to DHCP if a DHCP client is active. Setting BOOTPROTO=static and IPADDR correctly only takes effect when ONBOOT=yes is present.

Exam trap

The trap here is that candidates assume setting BOOTPROTO=static and IPADDR is sufficient, overlooking the mandatory ONBOOT=yes parameter required for automatic activation at boot.

How to eliminate wrong answers

Option A is wrong because the kernel parameter 'nomodeset' affects video driver initialization, not network interface configuration or static IP assignment. Option B is wrong because the firewall operates at Layer 3/4 and does not block the assignment of a static IP address to an interface; it filters traffic after the IP is assigned. Option D is wrong because the 'network' service is deprecated in RHEL 8 and replaced by NetworkManager, which is enabled by default; the issue is not about the service being disabled but about the per-interface ONBOOT setting.

24
MCQmedium

Which bonding mode provides high availability without requiring switch configuration?

A.mode 1 (active-backup)
B.mode 4 (802.3ad)
C.mode 6 (balance-alb)
D.mode 0 (balance-rr)
AnswerA

Mode 1 (active-backup) keeps one slave active while others stand by, failing over without any switch-side link aggregation. Because it uses no LACP or static EtherChannel, it delivers high availability with zero switch configuration, satisfying the stem's constraint.

Why this answer

Mode 1 (active-backup) provides high availability by designating one NIC as active and the others as standby, with automatic failover if the active link fails. It requires no special switch configuration because it does not use any link aggregation protocol or load-balancing algorithm that depends on switch-side settings.

Exam trap

The trap here is that candidates often confuse 'high availability' with 'load balancing' and choose mode 0 or mode 4, not realizing that those modes require switch configuration or do not inherently provide failover without additional setup.

How to eliminate wrong answers

Option B is wrong because mode 4 (802.3ad) requires the switch to be configured with a matching LACP (Link Aggregation Control Protocol) port channel. Option C is wrong because mode 6 (balance-alb) requires the switch to accept packets from multiple MAC addresses on the same port, which may need switch-side ARP filtering or port security adjustments. Option D is wrong because mode 0 (balance-rr) requires the switch to support Ethernet bonding (e.g., static link aggregation) and typically needs switch configuration to treat the multiple links as a single logical link.

25
MCQhard

A system administrator needs to securely transfer files between two Linux servers using port 22. The administrator uses the following command: 'scp file.txt user@remote:/tmp/'. The transfer fails with the error 'Permission denied (publickey)'. What is the most likely cause?

A.The client's public key is not in the remote user's authorized_keys file.
B.The remote server does not have SSH installed.
C.The SSH service is not running on the remote server.
D.The remote server's firewall is blocking port 22.
AnswerA

Port 22 confirms SSH is reachable, so the failure is authentication. Public-key authentication requires the client's public key to appear in the remote user's authorized_keys file; without that entry the server rejects the key and returns Permission denied (publickey).

Why this answer

The error 'Permission denied (publickey)' indicates that the SSH key-based authentication failed. SCP uses SSH for transport, and by default, SSH on the remote server checks the client's public key against the remote user's ~/.ssh/authorized_keys file. If the client's public key is not listed there, the SSH server rejects the connection, causing the SCP transfer to fail.

Exam trap

The trap here is that candidates often confuse network-level issues (firewall, service status) with authentication-level errors, but the specific 'Permission denied (publickey)' message directly points to SSH key authentication failure, not connectivity or service availability.

How to eliminate wrong answers

Option B is wrong because if the remote server did not have SSH installed, the error would typically be 'Connection refused' or 'No route to host', not 'Permission denied (publickey)'. Option C is wrong because if the SSH service were not running, the client would receive a 'Connection refused' error, not a publickey authentication failure. Option D is wrong because if the remote server's firewall were blocking port 22, the client would see a timeout or 'Connection refused' error, not a publickey permission error.

26
MCQeasy

A system administrator wants to combine two network interfaces for increased throughput and fault tolerance. The requirement is that both links are active simultaneously and the system can tolerate a failure of one link without interruption. Which bonding mode should be used?

A.Mode 4 (802.3ad)
B.Mode 2 (balance-xor)
C.Mode 1 (active-backup)
D.Mode 0 (balance-rr)
AnswerA

Mode 4 (802.3ad) is correct because it implements IEEE 802.3ad Link Aggregation Control Protocol (LACP), which allows both links to be active simultaneously for increased throughput while providing fault tolerance. If one link fails, traffic is automatically redistributed across the remaining active links without interruption, meeting the requirement.

Why this answer

Mode 4 (802.3ad) is correct because it implements IEEE 802.3ad Link Aggregation Control Protocol (LACP), which allows both links to be active simultaneously for increased throughput while providing fault tolerance. If one link fails, traffic is automatically redistributed across the remaining active links without interruption, meeting the requirement for both active links and failure tolerance.

Exam trap

The trap here is that candidates often confuse Mode 4 (802.3ad) with Mode 0 (balance-rr) because both allow active links, but Mode 0 lacks the standardized LACP negotiation and seamless failover that Mode 4 provides, leading to incorrect selection when fault tolerance is explicitly required.

How to eliminate wrong answers

Option B (Mode 2, balance-xor) is wrong because while it allows both links to be active, it does not provide fault tolerance without interruption—a link failure may cause traffic disruption until the bonding driver rebalances. Option C (Mode 1, active-backup) is wrong because it uses only one active link at a time, failing the requirement for both links to be active simultaneously. Option D (Mode 0, balance-rr) is wrong because although both links are active, it does not support 802.3ad negotiation and may cause out-of-order packet delivery, and it does not guarantee seamless failover without interruption.

27
MCQmedium

A system administrator notices that a web server is not reachable from the internet but is reachable from the internal network. The server's IP is 10.0.1.10/24, and the gateway is 10.0.1.1. Which command should be used to verify the default gateway configuration?

A.arp -a
B.ip route show
C.ip addr show
D.ss -tln
AnswerB

`ip route show` dumps the kernel routing table, exposing the default route and its gateway. For 10.0.1.10/24, it confirms whether a `default via 10.0.1.1` entry exists — the exact misconfiguration that would block internet-bound traffic while leaving the internal subnet reachable.

Why this answer

The `ip route show` command displays the kernel routing table, including the default gateway entry. Since the server is reachable internally but not from the internet, a missing or incorrect default gateway is the likely cause. This command directly verifies whether a default route (e.g., via 10.0.1.1) is present.

Exam trap

The trap here is that candidates often confuse `ip addr show` (which shows IP configuration) with `ip route show` (which shows routing), leading them to check the IP address instead of the default gateway when troubleshooting external connectivity.

How to eliminate wrong answers

Option A is wrong because `arp -a` shows the ARP cache (IP-to-MAC address mappings) for the local network, not the routing table or default gateway. Option C is wrong because `ip addr show` displays IP addresses and interface configuration, not routing information. Option D is wrong because `ss -tln` lists listening TCP sockets and their ports, which is used to verify service availability, not network-layer routing.

28
MCQeasy

Which command displays the listening UDP ports on a Linux system?

A.ss -a
B.ss -tln
C.ss -uln
D.netstat -tln
AnswerC

-u for UDP, -l for listening, -n for numeric.

Why this answer

`ss -uln` specifically displays listening UDP sockets. The `-u` flag filters for UDP, `-l` shows only listening sockets, and `-n` displays numeric addresses and ports (avoiding DNS resolution). This is the most precise command for listing listening UDP ports.

Exam trap

The trap here is that candidates often confuse the `-t` (TCP) and `-u` (UDP) flags, or assume that `netstat -tln` or `ss -tln` will show all listening ports, forgetting that UDP requires explicit `-u` filtering.

How to eliminate wrong answers

Option A is wrong because `ss -a` shows all sockets (both listening and non-listening, TCP and UDP), which is too broad and does not filter for UDP or listening state specifically. Option B is wrong because `ss -tln` filters for TCP sockets only (`-t`), so it will not display any UDP ports. Option D is wrong because `netstat -tln` also filters for TCP sockets only (`-t`), and while netstat can show UDP with `-u`, this option omits the `-u` flag, so it shows only listening TCP ports.

29
Multi-Selecthard

Which THREE statements about Linux network bonding modes are correct? (Choose three.)

Select 3 answers
A.Mode 2 (balance-xor) distributes traffic based on packet type.
B.Mode 0 (balance-rr) can cause out-of-order packet delivery.
C.Modes 5 and 6 (balance-tlb and balance-alb) require IEEE 802.3ad switch support.
D.Mode 4 (802.3ad) requires the switch to support LACP.
E.Mode 1 (active-backup) provides fault tolerance but only one link is active at a time.
AnswersB, D, E

Correct.

Why this answer

Mode 0 (balance-rr) transmits packets in sequential order from the first available slave through the last, then starts over. This round-robin distribution can cause packets belonging to the same TCP session to take different physical paths, leading to out-of-order delivery at the receiver, which may trigger TCP retransmissions and degrade performance.

Exam trap

The trap here is that candidates often confuse 'balance-rr' with 'balance-xor' and assume round-robin distributes traffic based on a hash or packet type, when in fact it simply cycles through slaves without any flow-level awareness.

30
MCQhard

A systems administrator is responsible for a production Linux server running CentOS 7 that provides SSH access to users. The administrator decides to tighten security by restricting SSH access to a specific management subnet 10.0.0.0/24. While connected to the server via SSH from a workstation on 10.0.0.50, the administrator adds the following iptables rule: iptables -A INPUT -p tcp --dport 22 -s 10.0.0.0/24 -j ACCEPT followed by iptables -P INPUT DROP. Immediately after the rule change, the administrator loses all connectivity to the server, including SSH. The administrator suspects that the new default policy dropped the existing SSH session. What is the most reliable method for the administrator to regain access to the server without rebooting?

A.Use netcat to send a TCP reset packet to the SSH server.
B.Use iptables-save and iptables-restore from another host on the same subnet.
C.Use IPMI or iDRAC to access the server's console and remove or modify the iptables rules.
D.Boot the server into single-user mode and flush iptables rules.
AnswerC

Out-of-band management provides console access independent of network.

Why this answer

IPMI (Intelligent Platform Management Interface) or iDRAC (Integrated Dell Remote Access Controller) provides out-of-band management access to the server's console, independent of the operating system's network stack. This allows the administrator to log in locally, remove or modify the iptables rules that dropped the SSH session, and restore connectivity without rebooting. Since the default INPUT policy was set to DROP, all new and existing SSH packets are blocked, but out-of-band management bypasses iptables entirely.

Exam trap

The trap here is that candidates assume iptables rules only affect new connections, forgetting that changing the default policy to DROP without a stateful rule for ESTABLISHED connections will immediately terminate existing sessions, and they overlook out-of-band management as the only non-reboot recovery option.

How to eliminate wrong answers

Option A is wrong because netcat cannot send a TCP reset packet to an existing SSH session that is already blocked by the iptables DROP policy; the kernel's netfilter will drop any packets to port 22, including resets, and netcat operates at the application layer, not at the raw socket level required to inject a reset. Option B is wrong because iptables-save and iptables-restore require an active SSH session or network connectivity to execute commands on the target server; since the administrator has lost all connectivity, there is no way to run these commands from another host. Option D is wrong because booting into single-user mode requires a reboot, which the question explicitly states should be avoided; moreover, single-user mode is a boot-time option that cannot be entered without restarting the system.

31
MCQhard

A Linux administrator needs to configure VLAN tagging on a network bridge to isolate traffic from different virtual machines. The physical interface is eth0, and VLAN ID 100 should be accessible via the bridge br0. Which set of commands correctly creates this configuration using the ip command?

A.ip link add link eth0 name eth0.100 type vlan id 100; ip link add br0 type bridge; ip link set eth0.100 master br0; ip link set br0 up
B.ip link add br0 type bridge; ip link set eth0 master br0; ip link set br0 up
C.ip link add eth0.100 link eth0 type vlan id 100; ip link set eth0.100 master br0; ip link add br0 type bridge
D.ip link add name br0 type bridge; ip link add link br0 name vlan100 type vlan id 100; ip link set eth0 master br0
AnswerA

The commands create a VLAN sub-interface eth0.100 tagged with ID 100 on eth0, create bridge br0, then enslave eth0.100 to br0 and bring the bridge up. Traffic entering br0 traverses the VLAN 100 tag, isolating it from other VLANs.

Why this answer

It first creates a VLAN interface (eth0.100) on top of physical interface eth0 with VLAN ID 100 using `ip link add link eth0 name eth0.100 type vlan id 100`. It then creates a bridge (br0) with `ip link add br0 type bridge`, attaches the VLAN interface to the bridge as a port with `ip link set eth0.100 master br0`, and finally brings the bridge up. This sequence ensures that traffic tagged with VLAN 100 on eth0 is properly forwarded through the bridge to virtual machines, while untagged or other VLAN traffic is isolated.

Exam trap

The trap here is that candidates often forget the order of operations — the bridge must exist before enslaving a port, and the VLAN interface must be created on the physical NIC, not on the bridge itself.

How to eliminate wrong answers

Option B is wrong because it directly attaches the physical interface eth0 to the bridge without creating a VLAN interface, so no VLAN tagging or isolation is configured — all traffic on eth0 passes through the bridge untagged. Option C is wrong because it attempts to set eth0.100 as a slave of br0 before the bridge br0 has been created, which will fail since the bridge must exist first for the `master` command to succeed. Option D is wrong because it creates a VLAN interface on top of the bridge (br0) rather than on the physical interface eth0, which would tag traffic originating from the bridge itself rather than isolating incoming VLAN 100 traffic from eth0.

32
Multi-Selecthard

An administrator is diagnosing why a server cannot reach the host 198.51.100.25. The server has one interface, eth0, with address 192.0.2.10/24. Running `ip route show` returns only the default route via 192.0.2.1. Which two commands will help determine whether the problem is at layer 2 or layer 3? (Choose two.)

Select 2 answers
A.ip neigh show 192.0.2.1
B.ss -tulnp | grep 198.51.100.25
C.ip link show eth0
D.dig +short 198.51.100.25
E.traceroute 198.51.100.25
AnswersA, E

This command displays the ARP/neighbor table entry for the gateway. If the gateway's MAC address is unresolved or shows FAILED, the problem is at layer 2. If it is REACHABLE, layer 2 to the gateway is working, and the issue is likely at layer 3 or beyond.

Why this answer

To isolate layer 2 versus layer 3, check the neighbor table for the gateway and trace the path to the destination. An unresolved neighbor entry points to a layer 2 problem, while a resolved entry with a traceroute that stops beyond the first hop points to layer 3 or higher. Interface state and DNS queries do not make this distinction.

Exam trap

The trap here is selecting commands that show local socket or interface state instead of tools that test reachability and neighbor resolution.

33
MCQmedium

A system administrator runs 'ss -tuln' and sees that port 80 is listening. What does the 'u' option represent?

A.User
B.Unix sockets
C.UDP
D.Unicast
AnswerC

In the ss command, the 'u' flag restricts output to UDP sockets, complementing 't' for TCP. Combined with 'l' and 'n', it lists listening UDP ports numerically, confirming which transport protocol is bound to port 80.

Why this answer

In the `ss` command, the `-u` option filters output to show only UDP sockets. Since the question shows `ss -tuln`, which combines `-t` (TCP), `-u` (UDP), `-l` (listening), and `-n` (numeric), the `u` specifically represents UDP. This is confirmed by the `ss` man page and standard Linux networking tools.

Exam trap

The trap here is that candidates confuse `-u` with 'Unix sockets' (which is `-x`) or 'User' (which is `-p`), because the letter 'u' is commonly associated with 'Unix' or 'user' in other commands, but in `ss` it specifically means UDP.

How to eliminate wrong answers

Option A is wrong because `-u` does not stand for 'User'; user information is displayed with the `-p` option or by default in some output formats, not with `-u`. Option B is wrong because Unix sockets are displayed with the `-x` option, not `-u`; `-u` is exclusively for UDP sockets. Option D is wrong because 'Unicast' is a type of network transmission, not a socket type or protocol filter in `ss`; `ss` uses `-u` to filter by UDP protocol, not by unicast addressing.

34
MCQeasy

You need to check the default gateway on a Linux server. Which command displays the current routing table, including the default route?

A.ip route show
B.ifconfig -a
C.ss -tuln
D.netstat -i
AnswerA

The 'ip route show' command displays the kernel's routing table, including the default route (usually shown as 'default via <gateway> dev <interface>'). This is the correct and modern command to view routes. It provides all necessary information to identify the default gateway.

Why this answer

The correct command is 'ip route show', which displays the routing table including the default route. The other commands show interface configuration (ifconfig), interface statistics (netstat -i), or listening sockets (ss -tuln), none of which reveal the default gateway.

Exam trap

The trap here is confusing commands that show interface addresses or listening ports with those that show routing information.

35
MCQeasy

A Linux server has a single Ethernet interface eth0. The administrator needs to assign a static IPv4 address 192.0.2.10/24 with gateway 192.0.2.1 on a system that uses systemd-networkd. Which file should be created or edited to configure this interface?

A./etc/network/interfaces
B./etc/systemd/network/10-eth0.network
C./etc/netplan/01-netcfg.yaml
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerB

systemd-networkd reads .network files from /etc/systemd/network/, /run/systemd/network/, and /usr/lib/systemd/network/. A file named 10-eth0.network in /etc/systemd/network/ is the correct location to define a static address, gateway, and DNS for eth0. The numeric prefix controls processing order, and the [Match] section must match the interface name.

Why this answer

systemd-networkd uses .network files stored in /etc/systemd/network/ (or /run and /usr/lib). A file such as 10-eth0.network with a [Match] section for eth0 and a [Network] section specifying Address=192.0.2.10/24 and Gateway=192.0.2.1 is the correct way to assign a static IPv4 configuration. The other paths belong to different network management frameworks.

Exam trap

The trap here is confusing the configuration file locations of different network management tools, such as ifupdown, NetworkManager, or netplan, with the native systemd-networkd format.

36
MCQeasy

An administrator wants to permanently configure a static IP address on a CentOS 7 system. Which file should be edited?

A./etc/sysconfig/network-scripts/ifcfg-eth0
B./etc/sysconfig/network
C./etc/hostname
D./etc/network/interfaces
AnswerA

Editing /etc/sysconfig/network-scripts/ifcfg-eth0 satisfies the persistence constraint: CentOS 7's NetworkManager and legacy network service both read per-interface ifcfg files at boot, so BOOTPROTO=none, IPADDR, NETMASK and GATEWAY survive reboots. Runtime tools like ip or ifconfig change only the live kernel state and are lost on restart.

Why this answer

On CentOS 7, network interface configuration is stored in individual files under /etc/sysconfig/network-scripts/, named ifcfg-<interface>. The ifcfg-eth0 file contains parameters like BOOTPROTO, IPADDR, NETMASK, and GATEWAY, and setting BOOTPROTO=static along with the IP address values permanently configures a static IP. This is the standard method for RHEL/CentOS 7 systems using the legacy network scripts (not NetworkManager's keyfile format).

Exam trap

The trap here is that candidates familiar with Debian-based systems may choose /etc/network/interfaces (Option D), while those who confuse global network settings with per-interface settings may pick /etc/sysconfig/network (Option B), both of which are incorrect for CentOS 7's static IP configuration.

How to eliminate wrong answers

Option B is wrong because /etc/sysconfig/network is a system-wide file that sets global networking parameters (e.g., HOSTNAME, GATEWAY) but does not define per-interface IP addresses; editing it alone cannot configure a static IP for a specific interface. Option C is wrong because /etc/hostname only sets the system's hostname, not IP address configuration; it is unrelated to static IP assignment. Option D is wrong because /etc/network/interfaces is the configuration file used by Debian/Ubuntu systems (ifupdown), not by CentOS 7 which uses the ifcfg files under /etc/sysconfig/network-scripts/.

37
Multi-Selectmedium

Which TWO commands can be used to view the current routing table on a Linux system?

Select 2 answers
A.netstat -rn
B.ifconfig -a
C.ss -tuln
D.route -n
E.ip addr
AnswersA, D

`netstat -rn` reads the kernel's routing information and prints it numerically, with `-r` selecting the routing table and `-n` suppressing DNS lookups so addresses appear as raw IPs. This satisfies the stem's requirement to view the current routing table, though `netstat` is deprecated on modern systems in favour of `ip route`.

Why this answer

Option A, netstat -rn, is correct because the -r flag displays the kernel routing table and -n shows addresses numerically, producing the current routing table on a Linux system. Option D, route -n, is correct because the route command with -n prints the kernel IP routing table in numeric form, which is a classic way to view routes. Option B, ifconfig -a, is wrong because it only shows network interface configuration (addresses, flags, MTU), not routes.

Option C, ss -tuln, is wrong because it lists TCP/UDP listening sockets, not the routing table. Option E, ip addr, is wrong because it displays interface addresses and link information, not routes (the routing table would be shown with ip route).

Exam trap

The trap here is that candidates confuse `ip addr` (which shows addresses) with `ip route` (which shows routes), or assume `ifconfig` shows routing information because it displays interface details, but it never shows the routing table.

38
MCQmedium

A network administrator needs to block all incoming SSH traffic (port 22) from the 192.168.2.0/24 subnet. Which iptables command accomplishes this?

A.iptables -A INPUT -d 192.168.2.0/24 -p tcp --dport 22 -j DROP
B.iptables -A OUTPUT -d 192.168.2.0/24 -p tcp --sport 22 -j DROP
C.iptables -A INPUT -s 192.168.2.0/24 -j DROP
D.iptables -A INPUT -s 192.168.2.0/24 -p tcp --dport 22 -j DROP
AnswerD

Appending a rule to the INPUT chain with `-s 192.168.2.0/24` matches the source subnet, `-p tcp --dport 22` targets SSH, and `-j DROP` silently discards matching packets, satisfying the requirement to block all incoming SSH from that subnet.

Why this answer

It appends a rule to the INPUT chain that matches packets originating from the 192.168.2.0/24 subnet (-s 192.168.2.0/24) using TCP protocol with destination port 22 (--dport 22), and then drops them (-j DROP). This precisely blocks all incoming SSH traffic from that subnet while leaving other traffic unaffected.

Exam trap

The trap here is that candidates often confuse the -s and -d flags, or mistakenly apply the rule to the OUTPUT chain, thinking they need to block outgoing responses rather than incoming connection attempts.

How to eliminate wrong answers

Option A is wrong because it uses -d (destination) instead of -s (source), which would match packets destined to the 192.168.2.0/24 subnet, not packets coming from it. Option B is wrong because it adds a rule to the OUTPUT chain with --sport 22, which would block outgoing SSH responses from the local machine, not incoming SSH connections. Option C is wrong because it drops all traffic from the 192.168.2.0/24 subnet regardless of protocol or port, which is overly broad and would block legitimate traffic such as DNS or HTTP from that subnet.

39
MCQmedium

An administrator is unable to SSH into the server from a remote host at 192.168.1.100. Based on the exhibited iptables rules, what is the most likely reason?

A.The SSH rule only allows connections from 10.0.1.0/24, and 192.168.1.100 is not in that subnet
B.SSH is not allowed from any source
C.The INPUT chain policy is ACCEPT, so SSH should be allowed
D.The DROP rule for SSH is not matching because of packet count zero
AnswerA

The second rule allows SSH only from 10.0.1.0/24, and the third rule drops all other SSH.

Why this answer

The exhibited iptables rules show an SSH rule that explicitly accepts incoming TCP traffic on port 22 only from the source subnet 10.0.1.0/24. The remote host at 192.168.1.100 is not within that subnet, so the SSH rule does not match, and the packet will fall through to the next rule or the default policy. Since no other rule permits SSH from 192.168.1.100, the connection is implicitly dropped or rejected, preventing SSH access.

Exam trap

The trap here is that candidates see the INPUT chain policy is ACCEPT and assume all traffic is allowed, overlooking that a more specific rule (like the SSH rule with a source restriction) can prevent traffic from non-matching sources, effectively overriding the default policy for that service.

How to eliminate wrong answers

Option B is wrong because the iptables rules do allow SSH from the specific subnet 10.0.1.0/24, so SSH is not disallowed from all sources. Option C is wrong because while the INPUT chain policy is ACCEPT, the packet must first match a rule; if a rule explicitly restricts SSH to a specific subnet, packets from other sources are not accepted by that rule and will be evaluated by subsequent rules or the default policy, which in this case does not permit the connection. Option D is wrong because a packet count of zero on a DROP rule simply indicates that no packets have matched that rule yet; it does not mean the rule is inactive or not matching—the rule will still match and drop packets that meet its criteria, and the zero count is irrelevant to whether SSH is allowed from 192.168.1.100.

40
MCQhard

An administrator is troubleshooting intermittent connectivity issues. Running 'ping -c 100 -i 0.2 10.0.0.1' shows about 5% packet loss. What is the primary purpose of the '-i 0.2' option?

A.It sets the TTL to 0.2
B.It sets the timeout to 0.2 seconds
C.It sets the packet size to 0.2 bytes
D.It sets the interval between pings to 0.2 seconds
AnswerD

The -i flag controls the delay between successive ping packets, so 0.2 sets a 200 ms gap rather than the default one second. This accelerates the 100-packet run, letting the administrator gather loss statistics quickly while still detecting the intermittent connectivity.

Why this answer

The '-i 0.2' option in the ping command sets the interval between sending ICMP Echo Request packets to 0.2 seconds. This allows the administrator to send pings more frequently than the default (typically 1 second), which helps in detecting intermittent connectivity issues over a shorter test duration. By sending 100 packets at a 0.2-second interval, the test completes in about 20 seconds, making it practical for troubleshooting transient packet loss.

Exam trap

The trap here is that candidates confuse '-i' with timeout or TTL options, mistakenly thinking it controls how long to wait for a reply rather than the spacing between packet transmissions.

How to eliminate wrong answers

Option A is wrong because '-i' does not set the TTL (Time to Live); TTL is set with the '-t' option in ping. Option B is wrong because '-i' controls the interval between packets, not the timeout; the timeout for waiting for a reply is set with '-W' (or '-w' for a deadline). Option C is wrong because '-i' does not affect packet size; packet size is set with '-s' (e.g., '-s 1472' for a specific payload size).

41
MCQmedium

A Linux server has two interfaces: enp3s0 (192.168.10.5/24) and enp4s0 (10.0.0.5/24). The default route is via 192.168.10.1. A junior admin adds a static route to 10.1.0.0/16 via 10.0.0.1 using the command: ip route add 10.1.0.0/16 via 10.0.0.1. After this, users report that traffic to 10.1.1.0/24 fails. Which command should the administrator run to confirm that the kernel is selecting the correct route and interface for destination 10.1.1.10?

A.ip route get 10.1.1.10
B.ip -s link show enp4s0
C.ip route show table all
D.traceroute -n 10.1.1.10
AnswerA

This command asks the kernel which route and source address it would use for the destination, showing the resolved interface and gateway. In this scenario, it would reveal whether the static route via 10.0.0.1 is chosen or whether the default route via 192.168.10.1 is used instead, directly diagnosing the reported failure.

Why this answer

The kernel chooses routes based on longest prefix match and metric. To verify which route and interface are selected for a specific destination, the ip route get command is used. It performs a route lookup and displays the resolved source address, gateway, and output interface, directly answering why traffic to 10.1.1.0/24 may fail despite a static route being added.

Exam trap

The trap here is assuming that adding a static route guarantees it will be used, without verifying the kernel's actual route selection for the destination.

42
Multi-Selecteasy

Which TWO methods can be used to set a static IPv4 address on a CentOS 7 system? (Choose two.)

Select 2 answers
A.Run the command 'systemctl set-static-ip eth0 192.168.1.100/24'
B.Use 'ip addr add 192.168.1.100/24 dev eth0'
C.Use the nmtui utility
D.Edit the /etc/network/interfaces file
E.Edit the /etc/sysconfig/network-scripts/ifcfg-eth0 file directly
AnswersC, E

The nmtui text interface writes persistent configuration into NetworkManager connection profiles, satisfying CentOS 7's requirement for a static IPv4 address that survives reboot. Unlike temporary `ip addr` changes, nmtui edits the connection's ipv4.method to manual and stores the address, prefix, gateway and DNS, which NetworkManager then applies at every activation.

Why this answer

Nmtui is a text-based user interface for NetworkManager, which is the default networking service on CentOS 7. It allows you to interactively configure network interfaces, including setting a static IPv4 address, without needing to manually edit configuration files. Option E is correct because the ifcfg-eth0 file in /etc/sysconfig/network-scripts is the traditional, direct configuration method for network interfaces on CentOS 7, where you can set BOOTPROTO=static and define IPADDR, PREFIX, and GATEWAY.

Exam trap

The trap here is that candidates often confuse temporary runtime commands like 'ip addr add' with permanent configuration methods, or they assume that systemctl can be used for network configuration because it is a common system administration tool.

43
MCQmedium

A Linux server's primary interface is ens3. Administrators report that after a recent reboot, the server's hostname resolves to 127.0.1.1 instead of its static address 203.0.113.25. The file /etc/hosts currently contains only the default '127.0.0.1 localhost' line. Which single change will make the hostname resolve to 203.0.113.25 for local lookups while leaving DNS resolution for all other names untouched?

A.Add the line '127.0.1.1 server1.example.com server1' to /etc/hosts.
B.Add 'hosts: dns files' to /etc/nsswitch.conf so DNS is consulted before the hosts file.
C.Add an A record for server1.example.com pointing to 203.0.113.25 in the zone file on the authoritative DNS server.
D.Add the line '203.0.113.25 server1.example.com server1' to /etc/hosts.
AnswerD

The hosts file is consulted before DNS by the default nsswitch.conf ordering, so adding the static address with the hostname makes local resolution return 203.0.113.25. This is the standard fix when a host needs its own FQDN and short name mapped to a routable address rather than the loopback alias, and it does not affect resolution of any other domain.

Why this answer

Local name resolution follows the order defined in nsswitch.conf, which by default checks the hosts file before DNS. Because the hosts file only contains the loopback line, the hostname has no local mapping. Adding a hosts entry that pairs the hostname and FQDN with the actual interface address makes the machine resolve its own name to 203.0.113.25 without disturbing DNS lookups for any other domain.

Exam trap

The trap here is assuming the loopback alias 127.0.1.1 is the correct fix for any hostname resolution problem, when the requirement is a specific routable address.

44
Multi-Selectmedium

Which THREE are built-in chains in the iptables filter table? (Choose three.)

Select 3 answers
A.POSTROUTING
B.INPUT
C.OUTPUT
D.FORWARD
E.PREROUTING
AnswersB, C, D

INPUT is one of the three built-in chains of the iptables filter table, alongside FORWARD and OUTPUT. It processes packets destined for the local host itself, satisfying the stem's requirement for a built-in filter chain rather than a user-defined one.

Why this answer

The filter table in iptables is used for packet filtering decisions based on IP addresses, ports, and protocols. Its built-in chains are INPUT (for packets destined for the local system), OUTPUT (for packets originating from the local system), and FORWARD (for packets routed through the system). These three chains allow you to control traffic at different points in the packet flow.

Exam trap

The trap here is that candidates often confuse the filter table's chains with those of the nat table (PREROUTING, POSTROUTING) because all chains are used in packet traversal, but only INPUT, OUTPUT, and FORWARD belong to the filter table.

45
MCQmedium

Refer to the exhibit. The output of 'ip addr show' reveals that eth0 is in state DOWN and has no IPv4 address. Which command is most likely to bring the interface up and obtain an IP via DHCP?

A.ip link set eth0 up
B.ifup eth0
C.ip route add default via 192.168.1.1 dev eth0
D.ip link set dev eth0 up
AnswerB

ifup invokes the network configuration scripts, which will start DHCP based on config.

Why this answer

The `ifup` command is a distribution-agnostic tool that reads the interface configuration from files (e.g., `/etc/network/interfaces` on Debian/Ubuntu or `/etc/sysconfig/network-scripts/ifcfg-eth0` on RHEL/CentOS) and brings the interface up while automatically initiating a DHCP client (e.g., dhclient or dhcpcd) to obtain an IPv4 address. This is the standard way to activate a network interface with its configured addressing method, including DHCP, in a single step.

Exam trap

The trap here is that candidates often assume `ip link set eth0 up` (options A or D) is sufficient to obtain an IP via DHCP, but this command only activates the link layer and does not invoke any DHCP client, leaving the interface without an IP address.

How to eliminate wrong answers

Option A is wrong because `ip link set eth0 up` only changes the interface's administrative state to UP but does not trigger any DHCP client or assign an IP address; the interface will remain without an IPv4 address unless a separate DHCP command is run. Option C is wrong because `ip route add default via 192.168.1.1 dev eth0` adds a default gateway route, but this command requires the interface to already have an IP address and be in the UP state; it does not bring the interface up nor obtain an IP via DHCP. Option D is wrong because `ip link set dev eth0 up` is functionally identical to option A (just a different syntax) and similarly does not initiate DHCP or assign an IP address.

46
MCQmedium

A Linux server acting as a VPN gateway uses an nftables ruleset in the inet filter table. The administrator wants all forwarded traffic from the 10.8.0.0/24 VPN subnet to the 192.168.50.0/24 LAN to be accepted, while dropping any other forwarded traffic. Which nftables rule should be added to the forward chain to accomplish this?

A.nft add rule inet filter forward ip daddr 10.8.0.0/24 ip saddr 192.168.50.0/24 accept
B.nft add rule inet filter forward ip saddr 10.8.0.0/24 ip daddr 192.168.50.0/24 accept
C.nft add rule inet filter forward ip saddr 10.8.0.0/24 ip daddr 192.168.50.0/24 drop
D.nft add rule inet filter input ip saddr 10.8.0.0/24 ip daddr 192.168.50.0/24 accept
AnswerB

This rule matches forwarded packets whose source is in the VPN subnet and destination is in the LAN, then accepts them. Because nftables evaluates rules in order and the final policy can be drop, placing this accept before a drop rule or default drop policy correctly permits only the intended traffic while blocking everything else.

Why this answer

Forwarded traffic between two networks is evaluated in the forward chain of the inet filter table. The rule must use ip saddr for the VPN subnet and ip daddr for the LAN subnet with an accept verdict. Placing this rule before any default drop policy permits only the specified flow, and other forwarded traffic is refused by the chain policy.

Exam trap

The trap here is confusing the input chain with the forward chain, when routed traffic between two remote networks is only evaluated by the forward chain.

47
Multi-Selecthard

Which THREE conditions must be met for a Linux system to function as a router between two networks?

Select 3 answers
A.Each interface has an IP address in the respective subnet
B.IP forwarding is enabled (net.ipv4.ip_forward = 1)
C.Both interfaces have the same MAC address
D.iptables rules allow forwarding (FORWARD chain policy or rules)
E.The system is configured as the default gateway for both networks
AnswersA, B, D

The router must have an IP in each network to send/receive packets.

Why this answer

Each interface must have an IP address in its respective subnet for the Linux system to receive packets from that network and forward them to the other. Without an IP address in the subnet, the interface cannot participate in ARP resolution or routing decisions for that network.

Exam trap

The trap here is that candidates often think a router must be the default gateway for both networks, but in reality, it only needs to have IP addresses in each subnet and proper routing entries; the default gateway is a client-side setting, not a router requirement.

48
Multi-Selectmedium

Which TWO commands can be used to display the routing table on a Linux system?

Select 2 answers
A.route -n
B.ip route show
C.ip addr show
D.arp -a
E.ss -tln
AnswersA, B

The legacy net-tools command queries the kernel routing table directly and prints it numerically with -n, avoiding DNS lookups. It satisfies the stem's requirement to display routes on systems where net-tools remains installed, though iproute2 has largely superseded it.

Why this answer

The `route -n` command displays the kernel IP routing table with numeric addresses, showing destination, gateway, netmask, and interface. The `ip route show` command is the modern equivalent from the iproute2 suite, which also displays the routing table with more detailed information. Both are standard tools for viewing routing decisions on a Linux system.

Exam trap

The trap here is that candidates often confuse `ip addr show` (which displays interface addresses) with `ip route show` (which displays routes), or mistake `arp -a` for a routing command because both involve network layer information.

49
MCQhard

An administrator is configuring a bridge using iproute2. Which command correctly attaches eth0 to bridge br0?

A.ip link set br0 master eth0
B.ip link set eth0 master br0
C.nmcli device modify eth0 master br0
D.brctl addif br0 eth0
AnswerB

The `master` keyword in `ip link set` enslaves the interface to the bridge, so eth0 becomes a br0 port. This is the iproute2 equivalent of `brctl addif br0 eth0`, satisfying the requirement to attach eth0 to br0.

Why this answer

The `ip link set eth0 master br0` command attaches the physical interface `eth0` as a slave port of the bridge `br0` using the iproute2 suite. The `master` keyword specifies the bridge device that should become the master of the specified interface, which is the standard way to add an interface to a bridge with iproute2.

Exam trap

The trap here is that candidates often confuse the order of arguments in the `ip link set` command, mistakenly using `ip link set br0 master eth0` (Option A) because they think the bridge should be the 'master' of the interface, but the syntax requires the slave interface first followed by `master <bridge>`.

How to eliminate wrong answers

Option A is wrong because it attempts to set `br0` as a slave of `eth0` (i.e., `ip link set br0 master eth0`), which would make the bridge a port of the physical interface—the opposite of the intended configuration. Option C is wrong because `nmcli device modify eth0 master br0` is not a valid nmcli syntax; the correct nmcli command to attach an interface to a bridge is `nmcli connection add type bridge-slave ifname eth0 master br0` or `nmcli device connect eth0 master br0`. Option D is wrong because `brctl addif br0 eth0` is a valid command from the deprecated bridge-utils package, not from iproute2, and the question explicitly specifies using iproute2.

50
MCQmedium

A company has a server with two network interfaces: eth0 (192.168.1.10/24, gateway 192.168.1.1) and eth1 (10.0.0.10/24, gateway 10.0.0.1). The server needs to reach a remote network 172.16.0.0/16 via a VPN tunnel that terminates at 10.0.0.5 on eth1. Which command should be used to add a route for this traffic?

A.ip route add 172.16.0.0/16 via 10.0.0.5 dev eth1
B.ip route add 172.16.0.0/16 via 10.0.0.5 dev eth0
C.ip route add 172.16.0.0/16 via 192.168.1.1 dev eth0
D.ip route add 172.16.0.0/16 dev eth1
AnswerA

Routing 172.16.0.0/16 via 10.0.0.5 on eth1 satisfies the stem's constraint that VPN traffic must egress the second interface, since 10.0.0.5 is reachable only through eth1's 10.0.0.0/24 subnet. Specifying both the gateway and dev eth1 prevents the kernel selecting eth0's default route.

Why this answer

The VPN tunnel endpoint is at 10.0.0.5 on the eth1 network, so traffic to 172.16.0.0/16 must be forwarded via that next-hop IP address using the eth1 interface. The `ip route add` command with `via 10.0.0.5 dev eth1` explicitly sets the gateway and egress interface, ensuring packets are sent through the VPN tunnel.

Exam trap

The trap here is that candidates often forget to specify the `via` next-hop IP when the destination is not directly connected, or they mistakenly use the default gateway instead of the VPN tunnel endpoint, assuming all external traffic goes through the same gateway.

How to eliminate wrong answers

Option B is wrong because it specifies `dev eth0`, but the VPN tunnel endpoint (10.0.0.5) is not reachable on the 192.168.1.0/24 network; eth0 has no route to 10.0.0.0/24, so the packet would be dropped or misrouted. Option C is wrong because it uses the default gateway 192.168.1.1 as the next-hop, which would send traffic to the local LAN gateway instead of the VPN tunnel endpoint at 10.0.0.5, failing to reach the remote network. Option D is wrong because it omits the `via` parameter; without a next-hop IP, the kernel assumes the destination is directly connected on eth1, but 172.16.0.0/16 is not on the 10.0.0.0/24 subnet, so the route would be invalid and traffic would not be forwarded.

51
MCQmedium

A Linux server has a single interface ens3 with address 203.0.113.10/24. The administrator runs `ss -tulnp` and sees that a service is listening on 127.0.0.1:8080 only. Remote clients on the Internet report they cannot reach the service on port 8080 even though the firewall allows the port. Which change is the most appropriate to allow remote access while preserving the service's intended exposure?

A.Add a route for 127.0.0.1 via ens3 so that external packets can reach the loopback address.
B.Restart the service after changing its configuration to bind to 0.0.0.0 or the specific external address instead of 127.0.0.1.
C.Enable IP forwarding with `sysctl -w net.ipv4.ip_forward=1` so that packets can be forwarded to the loopback listener.
D.Configure a DNAT rule redirecting external port 8080 to 127.0.0.1:8080 on the same host.
AnswerB

The service is bound to the loopback address, so it only accepts connections from the local host regardless of firewall rules. Rebinding to 0.0.0.0 or 203.0.113.10 makes the socket reachable on the external interface, which is the direct fix for the observed behavior.

Why this answer

A listener bound to 127.0.0.1 accepts only connections that originate on the local machine. Firewall rules and routing cannot change this. The correct remedy is to reconfigure the service to bind to 0.0.0.0 or the external address, then restart it so the new socket is created.

Exam trap

The trap here is assuming a firewall or routing problem when the listening socket itself is bound only to the loopback address.

52
MCQhard

An administrator is diagnosing a Linux router that forwards packets between two internal subnets. Users on 10.20.30.0/24 can reach hosts on 10.20.40.0/24, but responses from 10.20.40.0/24 arrive with the router's external address as the source. The administrator wants to inspect the NAT rules without modifying them. Which command displays the current rules in the nat table with packet and byte counters?

A.iptables -t nat -L -n -v
B.nft list ruleset
C.iptables -L -n -v
D.iptables -t nat -S
AnswerA

This lists all chains in the nat table, shows numeric addresses and ports with -n, and includes packet and byte counters with -v. It is read-only, so it satisfies the requirement to inspect without modifying. The output shows the PREROUTING, INPUT, OUTPUT, and POSTROUTING chains with their rules and hit counts, which is exactly what is needed to confirm which NAT rule is rewriting source addresses.

Why this answer

The nat table holds the PREROUTING, OUTPUT, and POSTROUTING chains where SNAT, DNAT, and MASQUERADE rules live. To inspect them with hit counters, iptables must be invoked with -t nat and the verbose flag -v, plus -n to avoid DNS lookups. This gives a clear picture of which rule is rewriting source addresses on the return path, without altering any rule.

Exam trap

The trap here is forgetting that iptables defaults to the filter table, so omitting -t nat silently shows the wrong set of chains and hides all NAT rules.

53
Multi-Selectmedium

Which THREE are common tools used for network troubleshooting on Linux?

Select 3 answers
A.traceroute
B.fdisk
C.ping
D.tcpdump
E.useradd
AnswersA, C, D

Traceroute maps the hop-by-hop path packets take to a destination and reports where latency or loss appears. This makes it a standard Linux tool for diagnosing routing problems, unreachable hosts and intermediate network failures during troubleshooting.

Why this answer

traceroute (A) is a standard Linux network diagnostic tool that maps the hop-by-hop path packets take to a destination by manipulating the IP TTL field and reading ICMP Time Exceeded replies, making it essential for locating routing problems. ping (C) is a core troubleshooting utility that sends ICMP Echo Request packets and measures Echo Reply responses to verify basic IP reachability and round-trip latency to a host. tcpdump (D) is a packet capture and analysis tool that uses libpcap to inspect live traffic at the frame/packet level, which is indispensable for diagnosing protocol-level and connectivity issues. The remaining options are not network troubleshooting tools: fdisk (B) is a disk partitioning utility for managing block devices, and useradd (E) is an account management command for creating local user accounts.

Exam trap

The trap here is that candidates might confuse system administration tools (like fdisk and useradd) with network utilities, or incorrectly assume that any command that interacts with the system can be used for network troubleshooting, when only dedicated network diagnostic tools like traceroute, ping, and tcpdump are appropriate.

54
MCQhard

A system administrator is troubleshooting network connectivity from a server that can reach internal resources but cannot access the internet. The server's /etc/sysconfig/network-scripts/ifcfg-eth0 file contains: BOOTPROTO=static, IPADDR=10.0.0.10, NETMASK=255.255.255.0, GATEWAY=10.0.0.1. The administrator runs 'ip route show' and sees: default via 10.0.0.1 dev eth0. However, 'ping 8.8.8.8' fails. Which is the most likely cause?

A.The default gateway is missing from the routing table.
B.The gateway 10.0.0.1 is not configured to forward traffic to the internet (no NAT or upstream route).
C.DNS resolution is not configured.
D.A firewall is blocking outbound ICMP traffic.
AnswerB

The default route exists and points at 10.0.0.1, so local routing is fine. Failure to reach 8.8.8.8 indicates the gateway itself lacks NAT or an upstream route, meaning it cannot forward traffic beyond the internal network.

Why this answer

The routing table shows a default gateway (10.0.0.1) is present, so the issue is not a missing route. Since the server can reach internal resources but not the internet, the most likely cause is that the gateway itself (10.0.0.1) is not configured to perform NAT or does not have an upstream route to forward traffic beyond the local subnet. Without this, packets destined for 8.8.8.8 are sent to the gateway but are then dropped because the gateway has no path to the internet.

Exam trap

The trap here is that candidates often assume a missing default gateway is the problem when ping fails, but the question explicitly shows the default route exists, so the real issue is the gateway's inability to forward traffic beyond the local network.

How to eliminate wrong answers

Option A is wrong because the 'ip route show' output explicitly shows 'default via 10.0.0.1 dev eth0', meaning the default gateway is present in the routing table. Option C is wrong because DNS resolution is not required for a ping to an IP address like 8.8.8.8; the failure occurs at the network layer, not at the application or name resolution layer. Option D is wrong because while a firewall could block ICMP, the question states the server can reach internal resources, and the most likely cause given the routing configuration is a gateway issue; a firewall blocking outbound ICMP would not explain why the gateway itself is unreachable for internet traffic, and the symptom is consistent with a lack of NAT or upstream route on the gateway.

55
Multi-Selecthard

Which TWO are valid methods to configure a network interface on a Linux system?

Select 2 answers
A.Using sysctl to set net.ipv4.conf.eth0.forwarding
B.Using systemctl enable network.service
C.Editing /etc/network/interfaces
D.Using nmcli connection add
E.Editing /etc/sysconfig/network
AnswersC, D

Editing /etc/network/interfaces is the Debian/Ubuntu ifupdown mechanism: persistent interface definitions consumed at boot by ifupdown, supporting static addressing, DHCP and VLAN stanzas. It satisfies the question's requirement for a valid configuration method on those distributions.

Why this answer

Option C is correct because /etc/network/interfaces is the standard configuration file used by the ifupdown toolset on Debian-based Linux distributions to define network interfaces, their addressing (static or DHCP), and related parameters. Option D is correct because nmcli connection add is the NetworkManager command-line method for creating a new connection profile that configures an interface, including its IP addressing, gateway, and DNS settings. Option A is not a valid interface configuration method because sysctl only tunes kernel runtime parameters such as net.ipv4.conf.eth0.forwarding (packet forwarding), not interface addressing or link settings.

Option B is not valid because systemctl enable network.service merely sets the legacy network service to start at boot; it does not itself configure an interface. Option E is not valid because /etc/sysconfig/network is a Red Hat-style file that historically held global hostname and gateway settings, not per-interface configuration.

Exam trap

The trap here is that candidates confuse global network configuration files (like /etc/sysconfig/network) with per-interface configuration files, or mistake sysctl for a tool that can set interface IP addresses, when it only modifies kernel parameters unrelated to interface addressing.

56
MCQeasy

A Linux administrator needs to display the IP addresses and netmasks of all network interfaces on a server. Which command provides this information in a concise, modern format?

A.ip addr show
B.netstat -i
C.route -n
D.ifconfig -a
AnswerA

The 'ip addr show' command from the iproute2 package displays all network interfaces with their IPv4 and IPv6 addresses, netmasks in CIDR notation, and link-layer information. It is the modern replacement for ifconfig and is available by default on virtually all current Linux distributions, providing concise and consistent output.

Why this answer

The 'ip addr show' command is the modern, preferred tool for displaying interface IP addresses and netmasks. It is part of iproute2, which is standard on current Linux systems, and its output clearly shows each interface's addresses in CIDR notation. The other commands either show different information (netstat -i, route -n) or are deprecated and not always installed (ifconfig).

Exam trap

The trap here is assuming that ifconfig is still the standard tool for viewing interface addresses, or confusing interface statistics with address information.

57
MCQeasy

Which tool is the recommended method for persistently configuring network interfaces in RHEL 8?

A.Using the 'ip' command with persistent flags
B.Using nmcli commands
C.Editing /etc/sysconfig/network-scripts/ifcfg-* files directly
D.Using systemd-networkd configuration files
AnswerB

NetworkManager is the default RHEL 8 network service, and nmcli writes settings into persistent connection profiles under /etc/NetworkManager/system-connections, so they survive reboot. Editing ifcfg files directly or using ip commands only changes runtime state, failing the persistence requirement.

Why this answer

In RHEL 8, NetworkManager is the default networking daemon, and 'nmcli' is the recommended command-line tool for persistently configuring network interfaces. Unlike temporary 'ip' commands, nmcli writes configuration to NetworkManager connection profiles, ensuring changes survive reboots. Red Hat officially deprecates direct editing of ifcfg files in RHEL 8 and uses NetworkManager as the primary interface.

Exam trap

The trap here is that candidates familiar with older RHEL versions (6/7) may default to editing ifcfg files directly, not realizing that RHEL 8 deprecates this method and officially recommends nmcli for persistent configuration.

How to eliminate wrong answers

Option A is wrong because the 'ip' command only makes runtime changes that are lost on reboot; it has no persistent flags to save configuration. Option C is wrong because while ifcfg files are still read by NetworkManager for backward compatibility, Red Hat deprecates direct editing in RHEL 8 and recommends nmcli or nmtui instead. Option D is wrong because systemd-networkd is not the default or recommended network stack in RHEL 8; RHEL 8 uses NetworkManager, not systemd-networkd.

58
Multi-Selectmedium

Which TWO commands can be used to display the routing table on a Linux system? (Choose two.)

Select 2 answers
A.route -n
B.ip route
C.ss -r
D.traceroute
E.ping -R
AnswersA, B

Route command with -n shows numeric routes.

Why this answer

The `route -n` command displays the kernel IP routing table with numeric addresses, showing destination, gateway, netmask, and interface. The `ip route` command from the iproute2 suite shows the same routing table with more detail and is the modern replacement for `route`. Both are standard tools for viewing routing information on Linux.

Exam trap

The trap here is that candidates confuse `ss` with `route` or `ip` because `ss` is a socket statistics tool, and the `-r` option might be misread as 'route', but `ss -r` only resolves hostnames in its output and does not display routing information.

59
MCQmedium

You manage a Linux server that provides DHCP services to a small office network using the dhcpd daemon. The server has two network interfaces: eth0 (192.168.1.1/24) serving the internal network, and eth1 (192.168.0.1/24) connected to a DMZ. The DHCP server is configured to serve addresses only on eth0. Users on the internal network report that they are not receiving IP addresses. You check the DHCP server and find that the dhcpd service is running and listening on UDP port 67. From a client, you run tcpdump and see DHCPDISCOVER packets being sent, but no DHCPOFFER from the server. You also verify that no firewall rules are blocking DHCP traffic on either side. What is the most likely reason for the failure?

A.The DHCP server's IP address is not in the same subnet as the clients.
B.The dhcpd configuration file does not have a subnet declaration for the 192.168.1.0/24 network.
C.The dhcpd service is not running.
D.The network switch is blocking broadcast packets.
AnswerB

dhcpd only offers leases for subnets declared in its configuration. Without a subnet declaration for 192.168.1.0/24, the daemon receives DHCPDISCOVER on eth0 but has no address pool or scope to answer from, so no DHCPOFFER is sent despite the service listening.

Why this answer

The dhcpd daemon will only respond to DHCPDISCOVER packets on interfaces for which it has a matching subnet declaration in its configuration file (typically /etc/dhcp/dhcpd.conf). Without a subnet declaration for 192.168.1.0/24, dhcpd ignores all DHCP traffic on eth0, even though the service is running and listening on UDP port 67. The absence of DHCPOFFER packets despite seeing DHCPDISCOVERs confirms that the server is not processing the requests for that subnet.

Exam trap

The trap here is that candidates assume a running service with an open port (UDP 67) is sufficient to serve DHCP, but the dhcpd daemon requires explicit subnet declarations to process requests on each interface.

How to eliminate wrong answers

Option A is wrong because the DHCP server's IP address (192.168.1.1) is in the same subnet as the clients (192.168.1.0/24), so subnet mismatch is not the issue. Option C is wrong because the problem states the dhcpd service is running and listening on UDP port 67, so the service is operational. Option D is wrong because the switch blocking broadcast packets would prevent DHCPDISCOVERs from reaching the server, but the tcpdump shows DHCPDISCOVER packets are being sent, and no firewall rules are blocking traffic, so the switch is not the cause.

60
MCQhard

A system administrator is troubleshooting network connectivity from a Linux server to a remote host at 10.0.0.1. The server has a default gateway of 192.168.1.1. Running `ping 10.0.0.1` fails, but `ping 192.168.1.1` succeeds. The output of `ip route show` shows a default route via 192.168.1.1. Which additional step should the administrator take to further investigate?

A.Check the ARP table for 10.0.0.1.
B.Verify that the firewall on the remote host allows ICMP.
C.Run traceroute to 10.0.0.1 to see where packets are dropped.
D.Check if the remote host is in the same subnet as the server.
AnswerC

Traceroute maps each hop along the path to 10.0.0.1, revealing where packets stop or time out. Since the default gateway responds, the fault lies beyond it; traceroute pinpoints the failing router or firewall hop, satisfying the need to isolate where connectivity breaks.

Why this answer

The ping to the default gateway succeeds, confirming local network and ARP resolution are functional, while the ping to the remote host fails. Running traceroute to 10.0.0.1 will reveal the exact hop where packets are dropped, isolating whether the issue lies in routing beyond the gateway, a firewall along the path, or a missing route on an intermediate router.

Exam trap

The trap here is that candidates assume a failed ping to a remote host must be due to a local ARP issue or firewall on the destination, but the successful ping to the gateway proves local connectivity works, making traceroute the logical next step to trace the path.

How to eliminate wrong answers

Option A is wrong because the ARP table is only relevant for hosts on the same subnet; 10.0.0.1 is not on the local subnet (the server's IP is presumably in 192.168.1.0/24), so ARP will never contain an entry for it. Option B is wrong because the question asks for the next step in investigating the connectivity issue from the server's perspective; while the remote host's firewall could block ICMP, the administrator should first verify the path with traceroute before assuming a firewall issue. Option D is wrong because the remote host is clearly not in the same subnet (10.0.0.1 vs. 192.168.1.0/24), and the successful ping to the gateway confirms the server is correctly forwarding traffic to the default route.

61
Multi-Selectmedium

A Linux server has an interface eth0 with IP 192.168.1.100/24. You need to temporarily add a secondary IP address 192.168.1.101/24 to the same interface for testing, and then verify that both addresses are present. Which two commands will accomplish this? (Choose two.)

Select 2 answers
A.ip link set eth0 up
B.ip addr show dev eth0
C.ip route add 192.168.1.101/24 dev eth0
D.ip addr add 192.168.1.101/24 dev eth0
E.ifconfig eth0 192.168.1.101 netmask 255.255.255.0
AnswersB, D

The 'ip addr show dev eth0' command displays all IP addresses configured on eth0, including the primary and any secondary addresses. This is the correct way to verify that both 192.168.1.100 and 192.168.1.101 are present. It is the standard verification command for IP configuration.

Why this answer

To add a secondary IP address temporarily, use 'ip addr add 192.168.1.101/24 dev eth0'. To verify, use 'ip addr show dev eth0'. The ifconfig command would replace the primary address, not add a secondary.

The ip route command is for routing, and ip link set up only changes the interface state.

Exam trap

The trap here is using ifconfig without an alias, which replaces the primary IP instead of adding a secondary, and confusing ip route with ip addr.

62
MCQhard

A Linux router has two interfaces: wan0 with address 198.51.100.10/24 and lan0 with address 10.10.0.1/24. Hosts on 10.10.0.0/24 can ping the router's lan0 address but cannot reach any Internet host. The administrator has already enabled net.ipv4.ip_forward=1. Which command is required to allow the internal hosts to reach external networks?

A.iptables -t nat -A POSTROUTING -s 10.10.0.0/24 -o wan0 -j MASQUERADE
B.iptables -A FORWARD -i lan0 -o wan0 -j ACCEPT
C.ip route add default via 198.51.100.1 dev lan0
D.iptables -t nat -A PREROUTING -i wan0 -j DNAT --to-destination 10.10.0.1
AnswerA

Because the internal hosts use private addresses that are not routable on the Internet, the router must translate their source addresses to its public wan0 address. A POSTROUTING MASQUERADE rule on the outbound interface performs this source NAT, so return traffic can be de-NATed and delivered back to the internal hosts.

Why this answer

Forwarding lets packets pass between interfaces, but private RFC 1918 sources cannot traverse the public Internet. The router must rewrite the source address of outbound packets to its public address, which is done with source NAT. A POSTROUTING MASQUERADE rule on the WAN interface accomplishes this dynamically, using the interface's current address, and enables return traffic to be mapped back to the correct internal host.

Exam trap

The trap here is believing that enabling ip_forward or adding a FORWARD accept rule is sufficient, when private source addresses must also be translated before they can reach the Internet.

63
MCQmedium

A server running Ubuntu 20.04 uses netplan for network configuration. The admin wants to set a static IP address 10.0.0.100/24 on interface enp0s3 with gateway 10.0.0.1 and DNS servers 8.8.8.8 and 8.8.4.4. Which YAML configuration is correct?

A.network: version: 2 ethernets: enp0s3: addresses: - 10.0.0.100/24 gateway: 10.0.0.1 nameservers: addresses: [8.8.8.8, 8.8.4.4]
B.network: version: 2 ethernets: enp0s3: address: 10.0.0.100/24 gateway4: 10.0.0.1 dns-nameservers: 8.8.8.8 8.8.4.4
C.network: ethernets: enp0s3: addresses: 10.0.0.100/24 gateway4: 10.0.0.1 nameservers: addresses: [8.8.8.8, 8.8.4.4]
D.network: version: 2 ethernets: enp0s3: addresses: - 10.0.0.100/24 gateway4: 10.0.0.1 nameservers: addresses: [8.8.8.8, 8.8.4.4]
AnswerD

Correct. Proper Netplan YAML: 'version: 2', 'addresses' as a list, 'gateway4' for IPv4 default gateway, and 'nameservers' with 'addresses' list for DNS servers. All required fields are present and correctly formatted.

Why this answer

It uses the proper Netplan YAML syntax: `addresses` as a list, `gateway4` for the IPv4 default gateway, and `nameservers` with an `addresses` list. This matches the required static IP 10.0.0.100/24, gateway 10.0.0.1, and DNS servers 8.8.8.8 and 8.8.4.4.

Exam trap

The trap here is that candidates confuse the legacy ifupdown syntax (e.g., `address`, `dns-nameservers`) with the required Netplan YAML structure, or forget the mandatory `version: 2` field.

How to eliminate wrong answers

Option A is wrong because it uses `gateway` instead of `gateway4`; Netplan requires `gateway4` for IPv4 gateways. Option B is wrong because it uses `address` (singular) instead of `addresses` (plural list), and `dns-nameservers` is a legacy ifupdown syntax not valid in Netplan. Option C is wrong because it omits the required `version: 2` field, which Netplan mandates for the configuration to be recognized.

64
MCQeasy

A user reports that they can access websites by IP address but not by domain name. Which command should the administrator use to diagnose the issue?

A.dig google.com
B.netstat -r
C.traceroute 8.8.8.8
D.ping google.com
AnswerA

Name resolution is the failing layer, since IP connectivity works. dig queries DNS directly for google.com, revealing whether the resolver returns an answer, times out, or reports SERVFAIL, isolating DNS from routing or firewall faults.

Why this answer

The user can access websites by IP address but not by domain name, indicating a DNS resolution failure. The `dig` command is the correct diagnostic tool because it directly queries DNS servers to test domain name resolution, bypassing the system's resolver cache and configuration. This allows the administrator to isolate whether the issue lies with DNS resolution or other network layers.

Exam trap

The trap here is that candidates often choose `ping google.com` (Option D) because it's a common connectivity test, but they fail to recognize that the symptom (access by IP but not name) specifically points to DNS, making `dig` the targeted diagnostic tool.

How to eliminate wrong answers

Option B is wrong because `netstat -r` displays the routing table, which is unrelated to DNS resolution; it would not help diagnose why domain names fail to resolve. Option C is wrong because `traceroute 8.8.8.8` tests network path connectivity to an IP address, which is already working per the user's report, and does not involve DNS. Option D is wrong because `ping google.com` would fail due to the same DNS resolution issue, making it useless for diagnosis; it would not reveal whether the problem is with DNS or something else.

65
MCQeasy

A Linux server needs to resolve the hostname db.internal.example.com to an IP address. The administrator wants to query the DNS server directly without relying on the local resolver cache. Which command should be used?

A.hostname -f
B.ping db.internal.example.com
C.dig db.internal.example.com
D.cat /etc/resolv.conf
AnswerC

The dig command queries DNS servers directly and displays the full response, including the answer, authority, and additional sections. It bypasses the local resolver cache by sending a query to the configured DNS server. This makes it ideal for troubleshooting DNS resolution for a specific hostname.

Why this answer

The dig command is the standard tool for querying DNS servers directly. It sends a DNS query and displays the response, bypassing local caching mechanisms like nscd or systemd-resolved. Other commands either rely on the system resolver, display local host information, or show configuration files without performing a lookup.

Exam trap

The trap here is assuming that any command that resolves a hostname queries DNS directly, when most use the system resolver and cache.

66
MCQeasy

A developer needs to temporarily allow incoming TCP connections on port 8080 for testing. Which iptables command adds a rule to the INPUT chain to accept this traffic?

A.iptables -A OUTPUT -p tcp --sport 8080 -j ACCEPT
B.iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
C.iptables -A FORWARD -p tcp --dport 8080 -j ACCEPT
D.iptables -I INPUT 1 -p tcp --dport 8080 -j DROP
AnswerB

The -A INPUT flag appends a rule to the INPUT chain, -p tcp matches the protocol, --dport 8080 targets the destination port, and -j ACCEPT sets the verdict. This permits inbound TCP connections on port 8080 without altering existing rules.

Why this answer

The INPUT chain processes traffic destined for the local system, and the `--dport 8080` flag matches incoming TCP packets with destination port 8080. The `-j ACCEPT` target allows these packets through, which is exactly what is needed to temporarily permit incoming TCP connections on port 8080 for testing.

Exam trap

The trap here is that candidates often confuse the INPUT chain with the FORWARD chain, or mistakenly think that `--sport` (source port) is appropriate for incoming traffic, when `--dport` (destination port) is required for packets arriving at the local system.

How to eliminate wrong answers

Option A is wrong because it adds a rule to the OUTPUT chain (which handles outgoing traffic) and uses `--sport 8080` (source port), which would match outgoing packets originating from port 8080, not incoming connections. Option C is wrong because the FORWARD chain handles traffic routed through the system, not traffic destined for the local host; adding a rule there would not affect incoming connections to the local system. Option D is wrong because it uses `-j DROP` to reject traffic, and while `-I INPUT 1` inserts the rule at the top, the action is to drop, not accept, the incoming TCP connections on port 8080.

67
MCQhard

An administrator needs to allow incoming SSH connections on port 22 from the 192.168.50.0/24 subnet while blocking all other incoming SSH traffic, without disrupting existing established connections. Which command sequence using nftables accomplishes this?

A.nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept; nft add rule inet filter input tcp dport 22 drop
B.nft add rule inet filter input tcp dport 22 drop; nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept
C.nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 drop; nft add rule inet filter input tcp dport 22 accept
D.nft add rule inet filter input ip saddr 192.168.50.0/24 tcp dport 22 accept; nft add rule inet filter input tcp dport 22 reject
AnswerA

The first rule accepts SSH from the specified subnet, and the second drops all other SSH traffic. Because rules are evaluated in order, allowed sources match the accept rule before reaching the drop rule. Established connections are unaffected if the input chain already accepts them earlier.

Why this answer

nftables evaluates rules in the order they appear within a chain. To allow a specific source and block the rest, the accept rule for that source must precede the drop rule for the port. Reversing the order or inverting the match conditions produces the opposite of the desired policy.

Exam trap

The trap here is assuming that nftables reorders rules or that a later accept can override an earlier drop; rule order is strictly sequential.

68
MCQeasy

Based on the tcpdump output in the exhibit, what can be concluded about the TCP handshake?

A.The connection attempt failed because only three packets are shown.
B.The connection was reset by the remote host.
C.The handshake is incomplete because there is no ACK from the server.
D.The TCP three-way handshake completed successfully.
AnswerD

The capture shows SYN, SYN-ACK and ACK exchanged in sequence between the hosts, confirming the three-way handshake completed and the connection entered ESTABLISHED state. This satisfies the exhibit evidence, ruling out a reset, refused connection or incomplete handshake.

Why this answer

The TCP three-way handshake completes successfully when three packets are exchanged: SYN, SYN-ACK, and ACK. The tcpdump output shows exactly these three packets, confirming a successful handshake. The presence of the final ACK from the client to the server's SYN-ACK indicates that the connection is established.

Exam trap

The trap here is that candidates may mistakenly think a three-packet handshake is incomplete or failed, when in fact the TCP three-way handshake is defined as exactly three packets, and the final ACK from the client completes it.

How to eliminate wrong answers

Option A is wrong because a successful TCP three-way handshake consists of exactly three packets (SYN, SYN-ACK, ACK), so seeing three packets does not indicate failure. Option B is wrong because a reset (RST) packet would appear in the output if the connection were reset by the remote host, but no RST flag is shown. Option C is wrong because the handshake is complete; the server sends a SYN-ACK (the second packet), and the client responds with an ACK (the third packet), which is the expected final step.

69
MCQeasy

A system administrator needs to configure a static IP address on a CentOS 7 server. Which file should be edited to set the IP address permanently?

A./etc/netplan/01-netcfg.yaml
B./etc/network/interfaces
C./etc/hostname
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerD

On CentOS 7, NetworkManager and the legacy network service read per-interface configuration from /etc/sysconfig/network-scripts/ifcfg-eth0, so editing this file sets a persistent static address. Changes survive reboot, unlike runtime ip commands, satisfying the stem's requirement for permanent configuration.

Why this answer

On CentOS 7, network interfaces are configured via scripts located in /etc/sysconfig/network-scripts/, with each interface having a file named ifcfg-<interface>. The ifcfg-eth0 file stores static IP settings such as IPADDR, NETMASK, and GATEWAY, which are read by the network service (network.service) to apply persistent configuration.

Exam trap

The trap here is that candidates familiar with Ubuntu or Debian systems may incorrectly choose /etc/network/interfaces (Option B) or /etc/netplan/01-netcfg.yaml (Option A), forgetting that CentOS 7 uses the Red Hat-style ifcfg scripts in /etc/sysconfig/network-scripts/.

How to eliminate wrong answers

Option A is wrong because /etc/netplan/01-netcfg.yaml is used by Netplan, a network configuration utility for Ubuntu (starting from 17.10) and not by CentOS 7, which uses the legacy ifcfg system. Option B is wrong because /etc/network/interfaces is the configuration file for Debian/Ubuntu systems using ifupdown, not for CentOS 7. Option C is wrong because /etc/hostname only sets the system's hostname, not IP address configuration; it contains a single line with the hostname and has no effect on network interface addressing.

70
MCQeasy

A user reports that they cannot reach a remote server by hostname but can reach it by IP address. Which configuration file is most likely misconfigured?

A./etc/resolv.conf
B./etc/sysconfig/network
C./etc/hosts
D./etc/nsswitch.conf
AnswerA

Hostname resolution relies on the DNS servers listed in /etc/resolv.conf; reaching the server by IP proves network connectivity is fine. A missing or incorrect nameserver entry there prevents the resolver from translating the hostname, matching the stem's symptom exactly.

Why this answer

The /etc/resolv.conf file configures the system's DNS resolver, specifying the nameservers to query for hostname-to-IP resolution. If a user can reach a server by IP but not by hostname, it indicates that DNS resolution is failing, which is most commonly due to a missing or incorrect nameserver entry in /etc/resolv.conf.

Exam trap

The trap here is that candidates often confuse /etc/resolv.conf with /etc/hosts or /etc/nsswitch.conf, thinking that a hostname resolution failure must be due to a missing static entry or a misconfigured lookup order, rather than the fundamental DNS resolver configuration.

How to eliminate wrong answers

Option B is wrong because /etc/sysconfig/network is a Red Hat/CentOS-specific file for setting global network parameters (e.g., hostname, gateway), not for DNS resolver configuration. Option C is wrong because /etc/hosts provides static hostname-to-IP mappings; if it were misconfigured, the user might not reach the server by hostname, but the fact that they can reach it by IP suggests DNS is the issue, not a missing or incorrect static entry. Option D is wrong because /etc/nsswitch.conf controls the order of name service lookups (e.g., 'hosts: files dns'), but a misconfiguration here would affect the lookup order, not the actual DNS resolver configuration; the core problem is the resolver itself, not the order.

71
MCQmedium

A Linux server running NetworkManager has a Wi-Fi interface wlp3s0 that must connect to the corporate WPA2-Enterprise network 'CorpNet' with 802.1X PEAP authentication, using identity 'jdoe' and password 'S3cr3t!'. The administrator wants to create and activate this connection entirely from the command line without editing configuration files manually. Which sequence of commands will accomplish this?

A.nmcli con add type ethernet ifname wlp3s0 con-name CorpNet, then nmcli con up CorpNet
B.nmcli con add type wifi ifname wlp3s0 con-name CorpNet ssid CorpNet wifi-sec.key-mgmt wpa-psk wifi-sec.psk 'S3cr3t!'
C.nmcli con add type wifi ifname wlp3s0 con-name CorpNet ssid CorpNet, then nmcli con modify CorpNet wifi-sec.key-mgmt wpa-eap 802-1x.eap peap 802-1x.identity jdoe 802-1x.password 'S3cr3t!', then nmcli con up CorpNet
D.nmcli dev wifi connect CorpNet password 'S3cr3t!'
AnswerC

This is the correct sequence: 'nmcli con add type wifi' creates the profile with the given ssid and interface, 'nmcli con modify' sets the key management to wpa-eap and the 802.1X parameters including eap method, identity, and password, and 'nmcli con up' activates it. All required fields for WPA2-Enterprise are supplied, so the connection will authenticate and associate without manual file editing.

Why this answer

The correct approach uses 'nmcli con add type wifi' to create a profile, then 'nmcli con modify' to set 'wifi-sec.key-mgmt wpa-eap' and the 802.1X parameters (EAP method, identity, password), and finally 'nmcli con up' to activate it. WPA2-Enterprise requires 802.1X/EAP configuration, not a pre-shared key, and the connection type must match the wireless interface for NetworkManager to manage it properly.

Exam trap

The trap here is assuming that a simple 'nmcli dev wifi connect' with a password is sufficient for any secured Wi-Fi network, when enterprise networks require explicit 802.1X/EAP parameters.

72
MCQmedium

A network interface eth0 is not receiving an IP address via DHCP. Which command can be used to troubleshoot the DHCP client process?

A.dhclient -v eth0
B.systemctl status dhcpd
C.nmcli dev show eth0
D.dhcpd -t
AnswerA

Running dhclient with -v on eth0 forces the DHCP client into verbose foreground mode, printing each DHCPDISCOVER, DHCPOFFER, DHCPREQUEST and DHCPACK exchange. This exposes whether the client transmits, receives offers, or fails, directly troubleshooting the DHCP client process.

Why this answer

The `dhclient -v eth0` command runs the DHCP client in verbose mode on interface eth0, which is the correct tool to troubleshoot the DHCP client process. It shows detailed messages about the DHCPDISCOVER, DHCPOFFER, DHCPREQUEST, and DHCPACK exchange, helping identify where the process fails. This directly addresses the issue of the interface not receiving an IP address via DHCP.

Exam trap

The trap here is confusing the DHCP client process (dhclient) with the DHCP server process (dhcpd), leading candidates to choose options that manage or test the server instead of the client.

How to eliminate wrong answers

Option B is wrong because `systemctl status dhcpd` checks the status of the DHCP server daemon (dhcpd), not the DHCP client process; the client process is managed by dhclient or NetworkManager, not dhcpd. Option C is wrong because `nmcli dev show eth0` displays the current configuration and state of the interface as managed by NetworkManager, but it does not initiate or debug the DHCP client transaction itself. Option D is wrong because `dhcpd -t` tests the syntax of the DHCP server configuration file (typically /etc/dhcp/dhcpd.conf), which is irrelevant to troubleshooting the client-side DHCP process.

73
MCQmedium

A Linux server has a single network interface enp3s0 that must obtain its IPv4 address automatically from a DHCP server on the local subnet. The administrator prefers to manage this connection with NetworkManager and wants the setting to persist across reboots. Which command will configure the connection profile named 'Wired connection 1' to use DHCP?

A.nmcli dev connect enp3s0
B.ip addr add dev enp3s0 dhcp
C.nmcli con mod 'Wired connection 1' ipv4.method manual
D.nmcli con mod 'Wired connection 1' ipv4.method auto
AnswerD

This command modifies the existing NetworkManager connection profile to use automatic IPv4 configuration (DHCP). The 'ipv4.method auto' setting tells NetworkManager to request an address from a DHCP server, and because it modifies the persistent profile, the change survives reboots. It is the correct way to enable DHCP on a specific connection.

Why this answer

NetworkManager stores connection settings in profiles, and the ipv4.method property controls how IPv4 addressing is obtained. Setting it to auto enables DHCP for that profile. Modifying the profile with nmcli con mod makes the change persistent, unlike temporary ip commands.

The other options either configure static addressing, use an invalid command syntax, or only activate an existing profile without changing its addressing method.

Exam trap

The trap here is confusing device activation with configuration, assuming that connecting a device automatically sets it to DHCP.

74
MCQeasy

An administrator needs to assign a temporary IPv4 address of 10.20.30.40/24 to interface enp0s3 for immediate testing. The change should not persist after a reboot. Which command accomplishes this?

A.nmcli con mod enp0s3 ipv4.addresses 10.20.30.40/24
B.ifconfig enp0s3 10.20.30.40 netmask 255.255.255.0 up
C.ip addr add 10.20.30.40/24 dev enp0s3
D.ip route add 10.20.30.40/24 dev enp0s3
AnswerC

The `ip addr add` command adds an address to an interface in the running kernel and does not modify any configuration file, so the address disappears after a reboot. This matches the requirement for a temporary address used only for testing.

Why this answer

Temporary address changes are made directly in the kernel with the `ip` utility. Adding an address with `ip addr add` affects only the current runtime state, so a reboot restores the previous configuration. Persistent tools such as NetworkManager or editing configuration files are used when the change must survive restarts.

Exam trap

The trap here is choosing a persistent configuration tool such as NetworkManager when the scenario explicitly requires the change to be non-persistent.

75
MCQmedium

You administer a Linux server that acts as a network gateway. It has two network interfaces: eth0 (external, with IP 203.0.113.10/24, gateway 203.0.113.1) and eth1 (internal, with IP 192.168.1.1/24). The server is running firewalld and has IP forwarding enabled. Internal hosts (192.168.1.0/24) can access the internet through NAT, which is configured using firewalld's masquerade on the external zone. However, you need to allow a specific internal server (192.168.1.100) to be reachable from the internet on TCP port 443 (HTTPS). You add a port forwarding rule using firewall-cmd: 'firewall-cmd --zone=external --add-forward-port=port=443:proto=tcp:toport=443:toaddr=192.168.1.100'. After reloading the firewall, external users still cannot connect to 203.0.113.10:443. You verify that the internal server is running HTTPS and that its local firewall allows port 443. What is the most likely reason the port forwarding is not working?

A.The port forwarding rule should be added to the internal zone instead of the external zone.
B.The internal server has a different default gateway.
C.The rule needs to include masquerade for the destination address; use a rich rule with 'masquerade'.
D.IP forwarding is not enabled on the system.
AnswerC

In firewalld, simple port forwarding often does not work without masquerade on the external zone. A rich rule with 'masquerade' is required, e.g., 'firewall-cmd --add-rich-rule="rule family=ipv4 destination address=203.0.113.10 forward-port port=443 protocol=tcp to-port=443 to-addr=192.168.1.100"' which implicitly uses masquerade? Actually standard practice is to use a rich rule. Option C is the best answer.

Why this answer

A simple port forward rule in firewalld does not automatically rewrite the source IP address for return traffic. Without masquerade on the forwarded traffic, the internal server sees the original external source IP and sends its response directly to that IP, bypassing the gateway. Adding a rich rule with 'masquerade' for the destination address ensures that the gateway performs SNAT on the forwarded packets, so the internal server sees the gateway as the source and returns traffic through it.

Exam trap

The trap here is that candidates assume a port forward rule alone is sufficient for bidirectional communication, overlooking the need for source NAT (masquerade) on the forwarded traffic to ensure proper return path routing.

How to eliminate wrong answers

Option A is wrong because port forwarding for externally initiated connections must be placed in the zone associated with the incoming interface (external), not the internal zone; the internal zone handles traffic from the internal network. Option B is wrong because the internal server's default gateway is irrelevant for inbound connections that are forwarded by the gateway; the server only needs to respond to the gateway's IP (192.168.1.1) for the return path to work. Option D is wrong because the question states that IP forwarding is enabled and internal hosts already access the internet through NAT, confirming that forwarding is active.

Page 1 of 2 · 97 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Networking questions.