Courseiva

CCNA Essential System Services and Networking Questions

56 questions · Essential System Services and Networking · All types, answers revealed

1
MCQmedium

A DHCP server assigns IP addresses to clients, but some clients are not receiving the correct gateway. Which configuration file should be checked on the DHCP server?

A./etc/dhcpd.conf
B./etc/dhcp/dhclient.conf
C./etc/dhcp/dhcpd.conf
D./etc/resolv.conf
AnswerC

dhcpd.conf holds the subnet declarations and their router option values that clients receive as their default gateway. An incorrect or missing router statement there causes clients to obtain addresses without the proper gateway, so this file must be checked.

Why this answer

The DHCP server configuration file on Linux systems is typically located at /etc/dhcp/dhcpd.conf (or /etc/dhcpd.conf on some older distributions). This file contains the subnet declarations, option definitions (such as option routers for the default gateway), and other parameters that the DHCP server uses to assign IP addresses and configuration details to clients. If clients are not receiving the correct gateway, the 'option routers' directive within this file should be checked and corrected.

Exam trap

The trap here is that candidates often confuse the DHCP server configuration file path with the older /etc/dhcpd.conf (option A) or mistakenly think the client configuration file (option B) controls server-side gateway assignment, when in fact the server's gateway is set via 'option routers' in /etc/dhcp/dhcpd.conf.

How to eliminate wrong answers

Option A is wrong because /etc/dhcpd.conf is an older, deprecated path; modern distributions use /etc/dhcp/dhcpd.conf, and the question expects the current standard location. Option B is wrong because /etc/dhcp/dhclient.conf is the client-side configuration file for the DHCP client (dhclient), not the server; it controls how the client requests and applies DHCP options, not how the server assigns them. Option D is wrong because /etc/resolv.conf is the DNS resolver configuration file, which specifies nameservers and search domains for the local system; it has no role in DHCP server gateway assignment.

2
MCQmedium

An administrator wants systemd-journald logs to persist across reboots. What must be created?

A.The directory /run/log/journal
B.The file /etc/journald.conf
C.The directory /var/log/journal
D.The directory /var/spool/journal
AnswerC

Journald writes to /run/log/journal (tmpfs) by default, so logs vanish on reboot. Creating /var/log/journal on disk switches storage to persistent mode, satisfying the requirement that entries survive restarts. The directory must exist before journald starts using it.

Why this answer

By default, systemd-journald stores logs in a volatile tmpfs at /run/log/journal, which is cleared on reboot. To make logs persistent, the directory /var/log/journal must be created. When systemd-journald detects this directory exists, it automatically switches to persistent storage, writing logs to /var/log/journal and preserving them across reboots.

Exam trap

The trap here is that candidates often assume editing the configuration file /etc/journald.conf is sufficient, but without the actual directory /var/log/journal existing, systemd-journald will not switch to persistent storage unless Storage=persistent is explicitly set and the directory is created.

How to eliminate wrong answers

Option A is wrong because /run/log/journal is the default volatile location for systemd-journald logs; it is automatically created on tmpfs and does not persist across reboots. Option B is wrong because /etc/journald.conf is the configuration file for systemd-journald, but creating it alone does not enable persistence; the key setting is Storage=persistent in that file, but the directory /var/log/journal must also exist (or be created) for persistence to take effect. Option D is wrong because /var/spool/journal is not a standard path used by systemd-journald; the correct persistent directory is /var/log/journal as defined by the journald documentation and the systemd source code.

3
MCQmedium

An Ubuntu 20.04 server needs a static IP address. The administrator has created a netplan YAML file at /etc/netplan/01-netcfg.yaml. What is the next step to apply the configuration?

A.netplan apply
B.ifconfig eth0 down; ifconfig eth0 up
C.service network-manager restart
D.systemctl restart networking
AnswerA

Netplan reads YAML definitions under /etc/netplan and generates the backend configuration for systemd-networkd or NetworkManager. Running netplan apply commits the new static addressing immediately without a reboot, satisfying the requirement to activate the file the administrator created.

Why this answer

On Ubuntu 20.04, netplan is the default network configuration tool, and the correct command to apply changes from a YAML file in /etc/netplan/ is 'netplan apply'. This command parses the YAML, generates the appropriate backend configuration (systemd-networkd or NetworkManager), and applies it without requiring a reboot. It is the standard, supported method for activating static IP settings on modern Ubuntu systems.

Exam trap

The trap here is that candidates may confuse the legacy 'systemctl restart networking' or 'ifconfig' commands with the modern netplan workflow, assuming any service restart will apply the YAML configuration, but only 'netplan apply' correctly processes the netplan files and triggers the appropriate backend.

How to eliminate wrong answers

Option B is wrong because 'ifconfig eth0 down; ifconfig eth0 up' is a legacy method that does not read netplan YAML files; it only toggles the interface state and may not persist or apply the new static IP configuration. Option C is wrong because 'service network-manager restart' restarts the NetworkManager service, but on Ubuntu 20.04 with netplan, the default backend is systemd-networkd (unless explicitly configured otherwise), and this command may not correctly apply netplan settings or could interfere with the intended backend. Option D is wrong because 'systemctl restart networking' targets the old 'networking' service (used by ifupdown), which is not the active network stack on Ubuntu 20.04; netplan uses systemd-networkd or NetworkManager, so this command is irrelevant and will not apply the netplan configuration.

4
MCQhard

A company manages a cluster of 50 web servers running Ubuntu 20.04. The servers are configured to synchronize time with an internal NTP server at 10.0.0.100 using the default ntpd. The NTP server itself syncs with external stratum 2 servers. Recently, the security team implemented a restrictive iptables firewall on all servers, allowing only essential services. Several servers in the 10.0.1.0/24 network now report time drift and ntpq -p shows all peers with '?' status. A network engineer runs tcpdump on one affected server and sees no NTP replies from 10.0.0.100. The NTP server's firewall is configured to allow inbound NTP from 10.0.0.0/24 only. The engineer also notes that the server's /etc/ntp.conf contains the line 'restrict 10.0.0.100' (which is incorrect) and that ntpq -crv shows 'sync target not reachable'. Which single action will most directly resolve the synchronization issue for the affected servers?

A.Add an iptables rule on the affected server to accept outbound UDP packets to 10.0.0.100 port 123.
B.Remove the line 'restrict 10.0.0.100' from /etc/ntp.conf.
C.Modify the NTP server's firewall to allow inbound NTP from 10.0.1.0/24.
D.Add a static route on the affected server for 10.0.0.100 via a different gateway.
AnswerC

The NTP server's firewall only permits inbound NTP from 10.0.0.0/24, so replies to the affected 10.0.1.0/24 servers are dropped, explaining the '?' peer status and absent tcpdump replies. Widening the rule to include 10.0.1.0/24 restores the return path, satisfying the reachability constraint that the client-side restrict line cannot fix.

Why this answer

The affected servers are in the 10.0.1.0/24 network, but the NTP server's firewall only allows inbound NTP from 10.0.0.0/24. Even if the client's firewall permits outbound UDP to port 123, the server will drop the requests because they originate from an unauthorized subnet. Therefore, modifying the NTP server's firewall to accept NTP traffic from 10.0.1.0/24 directly resolves the synchronization issue.

Option A (client firewall fix) is necessary but not sufficient because the server will still block the requests. Option B fixes the incorrect restrict line but does not address the firewall. Option D is irrelevant as routing is not the problem.

Exam trap

Candidates often focus on the client's firewall or the incorrect restrict line, but the most direct cause is the NTP server's firewall misconfiguration. Even if the client allows outbound traffic, the server drops requests from the wrong subnet.

How to eliminate wrong answers

Option A is wrong because the problem is not the client's outbound firewall; the client can send NTP requests, but the NTP server's firewall blocks replies to 10.0.1.0/24, so adding an outbound rule on the client does nothing. Option B is wrong because the 'restrict 10.0.0.100' line in /etc/ntp.conf is syntactically incorrect (it should be 'restrict 10.0.0.100 mask 255.255.255.255' or similar) but even if corrected, it controls access to the local NTP service, not the ability to receive replies from the server; the core issue is the server-side firewall. Option D is wrong because the affected server can already reach 10.0.0.100 (it sends requests), and adding a static route does not address the firewall blocking replies; the routing is fine.

5
Multi-Selectmedium

On a modern Linux system using systemd-networkd for interface management and systemd-resolved for DNS, which THREE files are typically involved in network configuration and DNS resolution?

Select 3 answers
A./etc/systemd/network/10-static.network
B./etc/network/interfaces
C./etc/resolv.conf
D./etc/hosts
E./etc/sysconfig/network-scripts/ifcfg-eth0
AnswersA, C, D

systemd-networkd uses .network files in this directory.

Why this answer

On a modern Linux system using systemd-networkd, network interface configuration is defined in .network files within /etc/systemd/network/, such as 10-static.network (Option A). systemd-resolved manages DNS resolution and typically writes to /etc/resolv.conf (Option C) as a symlink to its own stub resolver. /etc/hosts (Option D) is a static host-to-IP mapping file that is consulted by the system's resolver before DNS queries, making it a standard part of DNS resolution. Together, these three files are directly involved in network configuration and DNS resolution under systemd.

Exam trap

The trap here is that candidates often assume /etc/network/interfaces or ifcfg-eth0 are still relevant on modern systemd-based distributions, but systemd-networkd uses its own .network files, and the question explicitly specifies systemd-networkd and systemd-resolved.

6
MCQeasy

A developer asks the system administrator to configure a local web server for testing using Apache. The server should serve files from /var/www/test. Which directive must be set in the Apache configuration to set this document root?

A.Alias /test /var/www/test
B.ServerRoot /var/www/test
C.DocumentRoot /var/www/test
D.DirectoryIndex /var/www/test
AnswerC

DocumentRoot defines the directory from which Apache serves files, so setting DocumentRoot /var/www/test makes that path the web root. Requests then resolve against /var/www/test, satisfying the requirement for a local test server serving that location.

Why this answer

The DocumentRoot directive in Apache defines the top-level directory from which it serves files for a given virtual host or the main server. Setting DocumentRoot /var/www/test tells Apache to map incoming HTTP requests to files under that directory, making it the correct choice for serving files from /var/www/test.

Exam trap

The trap here is that candidates confuse DocumentRoot with ServerRoot or Alias, often thinking ServerRoot defines where web files are served from, when in fact it points to Apache's own installation directory.

How to eliminate wrong answers

Option A is wrong because Alias maps a URL path to a filesystem directory but does not set the primary document root; it is used for additional URL-to-directory mappings. Option B is wrong because ServerRoot specifies the directory where Apache's configuration, logs, and modules reside, not the directory for serving web content. Option D is wrong because DirectoryIndex defines the default file (e.g., index.html) to serve when a directory is requested, not the document root path.

7
MCQeasy

A Linux administrator needs to check the current status of the systemd service named sshd, including whether it is active and its recent log entries. Which command should she run?

A.journalctl -u sshd
B.service sshd status
C.systemctl is-active sshd
D.systemctl status sshd
AnswerD

This command displays the current state (active/inactive), the main PID, and the most recent log lines for the sshd service. It directly answers the requirement to check status and recent logs in a single step, making it the correct and efficient choice.

Why this answer

The systemctl status command provides a concise overview of a unit's state, including whether it is active, the main PID, and recent journal entries. It is the standard systemd tool for checking both status and recent logs, making it the most complete and appropriate choice for the administrator's needs.

Exam trap

The trap here is confusing journalctl -u sshd with systemctl status sshd; only the latter shows both the current state and recent logs together.

8
MCQhard

A company runs a web server using Apache with multiple virtual hosts. The administrator needs to restrict access to a specific virtual host based on the client IP address. Which configuration directive should be placed inside the <VirtualHost> block to deny IP 192.168.1.100?

A.Require host 192.168.1.100
B.Require not ip 192.168.1.100
C.Deny from 192.168.1.100
D.Require valid-user
AnswerB

New syntax: Require not ip denies the specific IP.

Why this answer

In Apache 2.4 and later, access control is managed using the `Require` directive with the `not` modifier to deny specific IP addresses. Placing `Require not ip 192.168.1.100` inside the `<VirtualHost>` block will deny access to that IP while allowing all others, as the default behavior is to require all IPs unless a `Require` directive explicitly grants access.

Exam trap

The trap here is that candidates familiar with Apache 2.2 may choose `Deny from` (Option C), not realizing that LPIC-1 exams focus on Apache 2.4 syntax where `Require` directives are the standard, and legacy directives are deprecated.

How to eliminate wrong answers

Option A is wrong because `Require host` is used to allow or deny based on hostnames (e.g., domain names), not IP addresses; it would attempt a reverse DNS lookup on the client IP, which is not the correct method for IP-based restrictions. Option C is wrong because `Deny from` is a legacy Apache 2.2 directive that is deprecated in Apache 2.4 and may not work unless the `mod_access_compat` module is loaded; it is not the modern recommended approach. Option D is wrong because `Require valid-user` is used for authentication-based access control (requiring a valid user/password), not for IP-based restrictions.

9
MCQmedium

Based on the exhibit, what is the most likely cause of the SSH service failure?

A.The sshd service is disabled.
B.The firewall is blocking port 22.
C.Another service is already listening on port 22.
D.The SSH configuration file has a syntax error.
AnswerC

SSH binds to TCP port 22; if another process already holds that port, sshd cannot bind and fails to start. The exhibit's bind error confirms this conflict, making a competing listener the most likely cause rather than configuration or key issues.

Why this answer

The exhibit shows that the sshd service failed to start because the address (0.0.0.0:22) is already in use. This indicates that another process is already bound to port 22, preventing sshd from binding to it. Therefore, the most likely cause is that another service is already listening on port 22.

Exam trap

The trap here is that candidates often assume SSH failures are always due to firewall rules or disabled services, but the specific error message 'address already in use' directly points to a port conflict, not a firewall or configuration syntax issue.

How to eliminate wrong answers

Option A is wrong because if the sshd service were disabled, the system would not attempt to start it at all, and the error message would not indicate a port conflict. Option B is wrong because a firewall blocking port 22 would not cause sshd to fail to start; the service would still bind to the port, but connections would be dropped by the firewall. Option D is wrong because a syntax error in the SSH configuration file would produce a different error message (e.g., 'sshd: fatal: bad configuration options'), not an 'address already in use' error.

10
MCQhard

A server uses systemd-resolved for DNS. Users report that name resolution works for external domains but fails for internal company hostnames. The administrator checks /etc/resolv.conf and sees 'nameserver 127.0.0.53'. Which action will resolve the issue?

A.Set the internal DNS server in /etc/nsswitch.conf by adding 'dns' after 'files' in the hosts line.
B.Add 'search company.internal' to /etc/resolv.conf and run systemd-resolve --flush-caches.
C.Replace 127.0.0.53 with the internal DNS server IP in /etc/resolv.conf and restart the network service.
D.Edit /etc/systemd/resolved.conf and add the internal DNS server to the DNS= line, then restart systemd-resolved.
AnswerD

With systemd-resolved, /etc/resolv.conf points to the stub listener at 127.0.0.53. Actual upstream DNS servers are configured in /etc/systemd/resolved.conf under the DNS= directive. Adding the internal DNS server there and restarting the service will make systemd-resolved forward internal queries to the correct server, fixing resolution for internal hostnames.

Why this answer

systemd-resolved uses a stub listener at 127.0.0.53, and upstream DNS servers are configured in /etc/systemd/resolved.conf. To resolve internal domains, the internal DNS server must be added to the DNS= setting, followed by a restart of systemd-resolved. Editing /etc/resolv.conf directly, adjusting search domains, or modifying nsswitch.conf does not provide the correct upstream server and will not fix internal name resolution.

Exam trap

The trap here is editing /etc/resolv.conf manually on a system where it is a symlink managed by systemd-resolved, which will be overwritten.

11
MCQhard

A Linux server uses systemd-resolved for DNS resolution. Users report that hostname resolution fails intermittently. The administrator inspects /etc/resolv.conf and finds it is a symlink to /run/systemd/resolve/stub-resolv.conf with nameserver 127.0.0.53. Which command should the administrator use to verify the current DNS servers and resolution status?

A.cat /etc/resolv.conf
B.resolvectl status
C.systemctl status systemd-resolved
D.dig @127.0.0.53 example.com
AnswerB

resolvectl status displays the current DNS servers, DNS domains, and other resolver configuration for each network interface. It shows which DNS servers are being used and can help diagnose intermittent resolution issues by revealing if multiple interfaces have conflicting DNS settings.

Why this answer

The resolvectl status command provides detailed information about the current DNS servers and resolution configuration for all interfaces. This is essential for diagnosing intermittent resolution failures, as it reveals if multiple interfaces are providing conflicting DNS servers or if fallback DNS is misconfigured.

Exam trap

The trap here is relying on /etc/resolv.conf to see DNS servers, but with systemd-resolved it only contains the stub address, not the actual upstream servers.

12
MCQmedium

After a reboot, a server fails to obtain an IP address on its sole ethernet interface. The administrator checks /etc/netplan/01-netcfg.yaml and finds the configuration looks correct. However, the interface shows no IP. The system uses systemd-networkd. Which command should be run next to apply the configuration and bring up the interface?

A.netplan apply
B.ifup eth0
C.systemctl restart networking
D.systemctl restart systemd-networkd
AnswerA

`netplan apply` parses the YAML and hands the resulting configuration to the systemd-networkd backend, which then brings the interface up and requests a lease. Since the stem confirms systemd-networkd is the renderer and the file is already correct, this regenerates and reloads the network state without a reboot.

Why this answer

The correct command is 'netplan apply' because the system uses netplan to manage network configuration, which generates backend configuration files for systemd-networkd. After editing the YAML file, 'netplan apply' parses the configuration, applies it to the running system, and triggers systemd-networkd to reconfigure the interface without requiring a full restart of the service.

Exam trap

The trap here is that candidates assume 'systemctl restart systemd-networkd' is sufficient, but without running 'netplan apply' first, the backend configuration files are not regenerated from the YAML, so the interface remains unconfigured.

How to eliminate wrong answers

Option B is wrong because 'ifup eth0' is a legacy tool from the ifupdown suite (used with /etc/network/interfaces) and does not interact with netplan or systemd-networkd; it would fail or be ignored on a system using netplan. Option C is wrong because 'systemctl restart networking' targets the legacy 'networking' service (ifupdown), which is not used when systemd-networkd is the backend; it may not be installed or enabled, and restarting it would not apply netplan YAML changes. Option D is wrong because 'systemctl restart systemd-networkd' would restart the service but would not cause netplan to regenerate the backend configuration files; the interface would still use the old or no configuration unless 'netplan apply' is run first to write the new .network files.

13
Multi-Selecthard

An administrator needs to monitor real-time network bandwidth usage on a Linux server. Which two tools are specifically designed for this purpose? (Choose two.)

Select 2 answers
A.netstat
B.nload
C.traceroute
D.ping
E.iftop
AnswersB, E

nload is a console bandwidth monitor that graphs inbound and outbound traffic per network interface in real time, refreshing continuously. It satisfies the stem's real-time bandwidth requirement directly, reading interface counters without packet capture, unlike general utilities such as netstat or ss.

Why this answer

B (nload) is correct because it is a command-line tool that displays real-time network traffic and bandwidth usage on a per-interface basis, showing incoming and outgoing data rates with a dynamic graph. E (iftop) is correct because it listens to network traffic on a specified interface and displays a real-time table of bandwidth usage per connection, similar to top for processes. Both tools are specifically designed for monitoring live bandwidth consumption, unlike general networking utilities.

Exam trap

The trap here is that candidates often confuse netstat's interface statistics (e.g., -i option) with real-time monitoring, but netstat only provides cumulative byte/packet counts since boot, not live bandwidth rates, making it unsuitable for real-time bandwidth monitoring.

14
MCQeasy

On a Debian-based system using ifupdown, which file should be edited to configure a static IP address for an interface?

A./etc/systemd/network/50-static.network
B./etc/network/interfaces
C./etc/netplan/01-netcfg.yaml
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerB

On Debian systems using ifupdown, /etc/network/interfaces is the canonical configuration file where interface stanzas define addressing. Editing it to add an iface entry with static address, netmask and gateway satisfies the requirement for persistent static IP configuration applied by ifup at boot.

Why this answer

On Debian-based systems using the traditional ifupdown suite, the file `/etc/network/interfaces` is the central configuration file for defining network interfaces, including static IP addresses. This file is parsed by the `ifup` and `ifdown` commands to bring interfaces up or down with the specified settings, such as `address`, `netmask`, and `gateway`.

Exam trap

The trap here is that candidates often confuse the default network configuration file for Debian-based systems with those used by other distributions (Red Hat) or newer abstraction layers (Netplan, systemd-networkd), leading them to pick a file that is technically valid but not used by the ifupdown tool specified in the question.

How to eliminate wrong answers

Option A is wrong because `/etc/systemd/network/50-static.network` is used by `systemd-networkd`, not by the ifupdown suite; Debian systems using ifupdown do not rely on systemd-networkd for interface configuration. Option C is wrong because `/etc/netplan/01-netcfg.yaml` is the configuration file for Netplan, which is used on Ubuntu (and some other distributions) as a frontend for systemd-networkd or NetworkManager, not for the traditional ifupdown system. Option D is wrong because `/etc/sysconfig/network-scripts/ifcfg-eth0` is the configuration file format used by Red Hat-based distributions (e.g., CentOS, Fedora) with the legacy network service, not by Debian-based systems.

15
MCQeasy

A system administrator notices that the system time is incorrect by several minutes. Which command should be used first to check the status of NTP synchronization?

A.timedatectl
B.ntpdate
C.date
D.hwclock
AnswerA

timedatectl reports the system clock, time zone, and whether NTP synchronisation is active, showing the service state and last sync. It satisfies the stem's requirement to check NTP status first, before adjusting configuration with chronyc or restarting services.

Why this answer

The `timedatectl` command is the correct first step because it shows the current system time, time zone, and NTP synchronization status in a single output. It directly reports whether NTP is active and whether the clock is synchronized, making it the standard diagnostic tool on modern systemd-based Linux distributions.

Exam trap

The trap here is that candidates often confuse `ntpdate` as a diagnostic tool because it can query an NTP server, but it is not designed to show the ongoing synchronization status of the system's NTP service.

How to eliminate wrong answers

Option B is wrong because `ntpdate` is a legacy command used for one-time manual time setting, not for checking synchronization status; it also requires stopping the NTP service first. Option C is wrong because `date` only displays or sets the system time without any NTP status information. Option D is wrong because `hwclock` manages the hardware clock (RTC) and does not show NTP synchronization status.

16
Multi-Selecteasy

Which three files are essential for network configuration and name resolution on a typical Linux system? (Choose three.)

Select 3 answers
A./etc/network/interfaces
B./etc/hosts
C./etc/sysctl.conf
D./etc/nsswitch.conf
E./etc/resolv.conf
AnswersB, D, E

Maps hostnames to IP addresses locally.

Why this answer

The `/etc/hosts` file provides static hostname-to-IP address mapping, allowing name resolution before DNS is queried. It is essential for local network configuration and fallback resolution, as defined by RFC 952 and the glibc Name Service Switch (NSS) framework.

Exam trap

The trap here is that candidates often confuse distribution-specific network configuration files (like `/etc/network/interfaces`) with essential system-wide name resolution files, leading them to select options that are not universally required across all Linux distributions.

17
Multi-Selecthard

Which TWO commands can be used to display the current firewall rules in a system using nftables? (Choose two.)

Select 2 answers
A.systemctl status nftables
B.iptables -L -n
C.nft list ruleset
D.nft list table inet filter
E.firewall-cmd --list-all
AnswersC, D

The nft list ruleset command dumps every table, chain and rule in the current nftables ruleset, giving a complete view of active firewall configuration. It directly satisfies the stem's requirement to display current firewall rules without naming a specific table or family.

Why this answer

`nft list ruleset` is the primary command in nftables to display the entire ruleset, including all tables, chains, and rules, regardless of the address family. Option D is also correct because `nft list table inet filter` specifically displays the rules within the 'filter' table of the 'inet' family, which is a valid way to show a subset of the firewall rules. Both commands rely on the nftables framework, which is the modern replacement for iptables on Linux.

Exam trap

The trap here is that candidates may confuse the legacy iptables command (`iptables -L -n`) with nftables, or assume that `systemctl status nftables` shows rules, when in fact it only shows the service's runtime state.

18
MCQmedium

A Linux administrator is troubleshooting a server that cannot resolve external hostnames. The server has a static IP address and can ping 8.8.8.8 successfully. The administrator checks /etc/resolv.conf and finds only 'nameserver 127.0.0.53'. Which command will best help determine the actual DNS servers being used and the resolution path?

A.cat /etc/nsswitch.conf
B.resolvectl status
C.nslookup google.com
D.dig google.com
AnswerB

resolvectl status displays the current DNS servers, DNS domains, and per-interface configuration managed by systemd-resolved. It reveals the actual upstream DNS servers and whether the stub resolver is functioning correctly, which is essential for diagnosing why external hostnames fail to resolve.

Why this answer

The resolvectl status command provides detailed information about the current DNS servers and resolution configuration for all interfaces, which is crucial for diagnosing why external hostnames cannot be resolved despite network connectivity.

Exam trap

The trap here is assuming that /etc/resolv.conf contains the actual DNS servers, but with systemd-resolved it only shows the stub address, so tools like resolvectl are needed to see the real servers.

19
Multi-Selectmedium

A Linux administrator needs to configure a system to use a proxy server for HTTP and HTTPS traffic for all users. Which TWO environment variables should be set in a system-wide profile script to ensure that command-line tools like curl and wget use the proxy? (Choose two.)

Select 2 answers
A.no_proxy
B.all_proxy
C.ftp_proxy
D.http_proxy
E.https_proxy
AnswersD, E

The http_proxy environment variable specifies the proxy server for HTTP requests. Many command-line tools, including curl and wget, check this variable to determine the proxy for HTTP URLs. Setting it system-wide ensures all users and processes inherit the proxy configuration.

Why this answer

Setting http_proxy and https_proxy in a system-wide profile script ensures that command-line tools like curl and wget route HTTP and HTTPS traffic through the proxy. These variables are widely recognized and provide comprehensive coverage for web traffic.

Exam trap

The trap here is assuming that a single variable like all_proxy or ftp_proxy covers all web traffic, but HTTP and HTTPS require separate variables for reliable proxy configuration.

20
Multi-Selecteasy

Which TWO tools can be used to query DNS records? (Choose two.)

Select 2 answers
A.nslookup
B.ss
C.dig
D.ping
E.traceroute
AnswersA, C

Name server lookup, queries DNS.

Why this answer

A is correct because nslookup is a classic DNS query tool that sends DNS queries to name servers to resolve domain names to IP addresses or vice versa. It directly queries DNS records (A, AAAA, MX, CNAME, etc.) using the DNS protocol (UDP/TCP port 53).

Exam trap

The trap here is that candidates may confuse network diagnostic tools (ping, traceroute, ss) with DNS-specific utilities, assuming any tool that tests connectivity can also query DNS records.

21
MCQhard

A Linux system's hostname resolution does not consult /etc/hosts before querying DNS. Which file controls the order of name resolution services?

A./etc/nsswitch.conf
B./etc/host.conf
C./etc/resolv.conf
D./etc/dnsmasq.conf
AnswerA

/etc/nsswitch.conf defines the hosts database entry, listing the order in which resolution services such as files, dns and myhostname are consulted. Editing its hosts line restores /etc/hosts precedence before DNS, directly satisfying the stem's requirement to control name resolution ordering.

Why this answer

The /etc/nsswitch.conf file controls the order of name resolution services by defining the 'hosts' database entry, which specifies the sources (e.g., files, dns) and their lookup order. If the entry is 'hosts: dns files', the system queries DNS before /etc/hosts, bypassing the local file. This file is part of the GNU C Library's Name Service Switch (NSS) framework, which governs all system databases like passwd, group, and hosts.

Exam trap

The trap here is that candidates confuse /etc/nsswitch.conf with /etc/resolv.conf or /etc/host.conf, assuming DNS order is controlled by resolver configuration files rather than the NSS database order.

How to eliminate wrong answers

Option B is wrong because /etc/host.conf is a legacy configuration file used by the old glibc resolver (pre-NSS) to control resolver behavior, such as order (bind, hosts), but it is deprecated and not the primary mechanism on modern Linux systems. Option C is wrong because /etc/resolv.conf only specifies DNS resolver parameters (nameservers, search domains, options) and does not control the order of name resolution services or whether /etc/hosts is consulted. Option D is wrong because /etc/dnsmasq.conf is the configuration file for the dnsmasq DNS forwarder and DHCP server, which is a separate service and does not control the system-wide name resolution order used by the resolver library.

22
MCQmedium

A Linux server acts as a router between an internal network and the internet. After enabling IPv4 forwarding, clients still cannot reach external hosts. The administrator confirms the routing table is correct and the external interface is up. Which command displays the current kernel packet-filter rules so the administrator can verify whether forwarding is being blocked?

A.ip route show
B.ss -tulpn
C.nft list ruleset
D.ip -s link show
AnswerC

nft list ruleset prints every table, chain, and rule in the nftables ruleset, including any forward chain that could be dropping or rejecting traffic. On a modern distribution using nftables as the packet-filter backend, this shows exactly what is filtering forwarded packets, making it the right command to diagnose blocked forwarding.

Why this answer

Forwarded packets traverse the forward path of the packet filter, so a drop or reject rule there prevents transit traffic even when routing and interface state are correct. On a host using the nftables backend, nft list ruleset dumps the entire ruleset, exposing any forward chain rules that block the traffic and allowing the administrator to confirm the cause.

Exam trap

The trap here is assuming that correct routing and an up interface are sufficient for forwarding, when a packet-filter rule in the forward chain can silently drop transit traffic.

23
Multi-Selecthard

A Linux server uses nftables as its firewall. The administrator needs to allow incoming SSH (TCP/22) and HTTP (TCP/80) while dropping all other incoming traffic. Which TWO statements about implementing this are correct? (Choose two.)

Select 2 answers
A.Rules must be added to the output chain to allow responses from the server to clients.
B.The rule 'tcp dport { 22, 80 } accept' can be used to allow both SSH and HTTP in a single rule.
C.A base chain must be created with type filter and hook input to process incoming packets.
D.The default policy of the input chain must be set to accept to allow the specified ports.
E.The command 'nft add rule ip filter input tcp dport 22 accept' will persist across reboots by default.
AnswersB, C

nftables supports set-based matching. The syntax 'tcp dport { 22, 80 } accept' matches packets with destination port 22 or 80 and accepts them. This is efficient and concise, reducing the number of rules. It is a valid and recommended way to allow multiple ports.

Why this answer

To filter incoming traffic with nftables, you must create a base chain with type filter and hook input. Allowing multiple ports can be done with a set in a single rule. The default policy should be drop to block other traffic, and connection tracking handles return traffic without output rules.

Rules are not persistent unless saved and loaded at boot.

Exam trap

The trap here is assuming nftables rules persist automatically or that output rules are needed for return traffic, when conntrack handles it and persistence requires saving.

24
MCQeasy

Refer to the exhibit. A system administrator runs 'ip route show default' and gets this output. What does it indicate?

A.The DNS server is 192.168.1.1.
B.The default route points to gateway 192.168.1.1 on interface eth0.
C.The system has no internet access.
D.The IP address of the system is 192.168.1.1.
AnswerB

The default route entry specifies a gateway address of 192.168.1.1 reachable via the eth0 device. Any traffic lacking a more specific matching route is forwarded to that gateway, confirming eth0 as the egress interface for off-subnet destinations.

Why this answer

The command 'ip route show default' displays the default route entry in the kernel routing table. The output shows that the default route (destination 0.0.0.0/0) is via gateway 192.168.1.1 and uses interface eth0, meaning all traffic not matching a more specific route is sent to that gateway on that interface.

Exam trap

The trap here is confusing the default gateway with other network parameters like DNS server or the system's own IP address, leading candidates to incorrectly associate the gateway IP with those unrelated services.

How to eliminate wrong answers

Option A is wrong because the default route specifies a gateway for network traffic, not a DNS server; DNS server configuration is handled in /etc/resolv.conf or via systemd-resolved, not in the routing table. Option C is wrong because having a default route to 192.168.1.1 indicates the system has a path to reach external networks, provided the gateway is operational and the system has proper connectivity. Option D is wrong because the IP address of the system is not shown in the default route output; the system's IP address is typically found using 'ip addr show' or 'ifconfig', and 192.168.1.1 is the gateway address, not the system's own address.

25
MCQmedium

A Linux server uses chrony for time synchronization. The administrator notices that the system clock is drifting by several seconds per day. Which command should she use to verify which NTP servers are currently selected and the estimated offset?

A.ntpq -p
B.chronyc sources -v
C.timedatectl status
D.chronyc tracking
AnswerB

This command lists all configured time sources, indicates which are selected for synchronization (marked with ^*), and shows the estimated offset, jitter, and other statistics. It directly answers the need to verify server selection and offset, making it the correct choice.

Why this answer

The chronyc sources -v command provides a detailed list of all time sources, including which ones are currently selected for synchronization and their estimated offsets. This is exactly what the administrator needs to diagnose drift and verify server selection. The other commands either show only summary information or are not native to chrony.

Exam trap

The trap here is assuming that chronyc tracking lists the individual NTP servers, when it only shows the currently selected reference and overall offset.

26
Multi-Selectmedium

Which THREE steps are required to configure a network interface with a static IP address using the ip command (assuming interface eth0)? (Choose three.)

Select 3 answers
A.ifconfig eth0 192.168.1.10 netmask 255.255.255.0
B.ip route add default via 192.168.1.1
C.ip addr add 192.168.1.10/24 dev eth0
D.ip link set eth0 up
E.echo 'nameserver 8.8.8.8' > /etc/resolv.conf
AnswersB, C, D

Adds default gateway.

Why this answer

The `ip route add default via 192.168.1.1` command sets the default gateway for the system, which is essential for routing traffic to networks beyond the local subnet. Without a default route, the static IP configuration would only allow communication within the local network (192.168.1.0/24), making this step mandatory for full network connectivity.

Exam trap

The trap here is that candidates often confuse the `ip` command with legacy tools like `ifconfig` (option A) or include DNS configuration (option E) as part of the `ip` command workflow, when in fact DNS is handled by separate system services and not by the `ip` command.

27
MCQhard

A server runs systemd-resolved and uses a VPN. DNS queries fail intermittently. The administrator checks /etc/resolv.conf and finds it is a symlink to /run/systemd/resolve/stub-resolv.conf. Which command should be used to view the effective DNS servers and debug the issue?

A.cat /etc/resolv.conf
B.resolvectl status
C.systemctl restart systemd-resolved
D.dig @localhost
AnswerB

`resolvectl status` queries systemd-resolved directly over D-Bus, exposing per-link DNS servers, current DNS server, and DNSSEC settings for each interface. Because /etc/resolv.conf only points at the 127.0.0.53 stub, it hides the VPN link's actual upstream servers, so this command reveals the split-DNS configuration causing the intermittent failures.

Why this answer

B is correct because `resolvectl status` is the native command for querying systemd-resolved's internal state, showing the per-link DNS servers, search domains, and current resolver configuration. Since `/etc/resolv.conf` is a symlink to the stub resolver, `cat /etc/resolv.conf` only shows the stub listener address (127.0.0.53), not the actual upstream DNS servers used by systemd-resolved. `resolvectl status` reveals the effective DNS servers for each network interface, including VPN interfaces, which is essential for debugging intermittent failures.

Exam trap

The trap here is that candidates assume `cat /etc/resolv.conf` shows the real DNS servers, but because it is a symlink to the stub resolver's configuration, it only shows 127.0.0.53, masking the actual upstream servers that systemd-resolved uses.

How to eliminate wrong answers

Option A is wrong because `cat /etc/resolv.conf` only displays the stub resolver's loopback address (127.0.0.53), not the actual upstream DNS servers that systemd-resolved queries; this gives no insight into which DNS servers are failing. Option C is wrong because `systemctl restart systemd-resolved` is a brute-force action that disrupts all active DNS resolution and does not provide diagnostic information about current DNS servers or intermittent failures. Option D is wrong because `dig @localhost` sends queries to the stub resolver on 127.0.0.53, which may succeed even when upstream queries fail, and it does not reveal which upstream servers are configured or their status.

28
MCQhard

After running 'ip route show default', a system administrator sees no output. Users on that system can only communicate with hosts on the local subnet. What is the most likely cause?

A.DNS is misconfigured
B.A firewall is blocking all traffic
C.The network interface is down
D.The default gateway is missing
AnswerD

With no default route in the routing table, the kernel has no next-hop for off-subnet destinations, so packets are dropped and only local-subnet hosts remain reachable. Adding a default gateway restores forwarding beyond the local subnet.

Why this answer

The `ip route show default` command displays the default gateway entry in the routing table. An empty output indicates that no default route is configured. Without a default gateway, the system cannot route packets to destinations outside its local subnet, which explains why users can only communicate with hosts on the local subnet.

Exam trap

The trap here is that candidates may confuse DNS resolution with routing, assuming that name resolution failure is the root cause, when in fact the absence of a default gateway directly prevents any off-subnet IP communication regardless of DNS status.

How to eliminate wrong answers

Option A is wrong because DNS misconfiguration would affect name resolution, not basic IP connectivity; the system could still reach external IP addresses if a default gateway existed. Option B is wrong because a firewall blocking all traffic would prevent all communication, including local subnet traffic, which is not the case here. Option C is wrong because if the network interface were down, the system would have no network connectivity at all, not just limited to the local subnet.

29
MCQeasy

A technician is troubleshooting network connectivity. The server's IP is 192.168.1.10/24, and the gateway is 192.168.1.1. The server can ping the gateway but cannot ping 8.8.8.8. Which command is most appropriate to check if the default route is configured?

A.route -n
B.ifconfig eth0
C.ping 192.168.1.1
D.arp -n
AnswerA

The `route -n` command prints the kernel routing table numerically, revealing whether a default route (destination 0.0.0.0) exists via gateway 192.168.1.1. Since the server reaches its local subnet but not 8.8.8.8, a missing default route is the likely fault, and this command directly confirms it.

Why this answer

The `route -n` command displays the kernel IP routing table without resolving hostnames, showing the default route (destination 0.0.0.0) and its gateway. Since the server can ping the gateway but not 8.8.8.8, the issue is likely a missing or incorrect default route, which `route -n` directly reveals.

Exam trap

The trap here is that candidates assume a successful ping to the gateway implies a default route exists, but the gateway being reachable does not mean the server has a route to forward traffic beyond the local subnet.

How to eliminate wrong answers

Option B is wrong because `ifconfig eth0` only shows the IP address, netmask, and MAC of the interface, not the routing table or default gateway. Option C is wrong because `ping 192.168.1.1` was already performed successfully (as stated in the scenario) and only verifies local gateway reachability, not the existence of a default route. Option D is wrong because `arp -n` displays the ARP cache (IP-to-MAC mappings) for local network hosts, which is irrelevant to checking the default route configuration.

30
MCQhard

A system administrator notices that the NTP service on a Linux server is not synchronizing time with external NTP servers. The administrator runs 'ntpq -p' and sees that all servers listed have a 'reach' value of 0. Which of the following is the most likely cause?

A.The system timezone is incorrectly set.
B.The NTP service is configured to use the local clock.
C.A firewall is blocking UDP port 123.
D.The NTP server is using a different NTP version.
AnswerC

A reach value of 0 means no NTP reply packets have been received in the last eight poll intervals. Blocked UDP port 123 prevents the server responses from arriving, so the client cannot synchronise despite the daemon running.

Why this answer

The `reach` value of 0 in `ntpq -p` output indicates that the NTP client has received no responses from any of the configured servers. Since NTP uses UDP port 123 for communication, a firewall blocking this port would prevent the client from sending or receiving NTP packets, resulting in zero reachability. This is the most common cause when all servers show a reach of 0.

Exam trap

The trap here is that candidates may confuse a reach value of 0 with a stratum value of 16 or a synchronization failure due to timezone misconfiguration, but the reach value specifically indicates network-level communication failure, not configuration or version issues.

How to eliminate wrong answers

Option A is wrong because the system timezone setting affects the display of local time, not the synchronization process with NTP servers; NTP works with UTC internally. Option B is wrong because if the NTP service were configured to use the local clock, the `ntpq -p` output would typically show a server entry like `LOCAL(0)` with a reach value greater than 0, not all servers at 0. Option D is wrong because NTP is backward compatible; different NTP versions (v3, v4) can interoperate, and version mismatch would not cause a reach value of 0 for all servers.

31
MCQeasy

A junior administrator is asked to verify which TCP ports are listening on a Linux server and which processes own them. Which command provides this information directly?

A.netstat -r
B.lsof -i :22
C.ip link show
D.ss -tulpn
AnswerD

ss is the modern replacement for netstat. The flags -t (TCP), -u (UDP), -l (listening), -p (processes), and -n (numeric) together show all listening TCP and UDP sockets with numeric ports and the associated process. This directly answers which ports are open and which programs own them.

Why this answer

The ss command with -tulpn is the standard tool on modern Linux to list listening TCP and UDP sockets, show numeric addresses, and map them to owning processes. Netstat -r shows routes, ip link show displays interface state, and lsof -i :22 is limited to a single port. Only ss -tulpn provides a comprehensive view of all listening ports and their processes.

Exam trap

The trap here is assuming any netstat or ip command will show listening ports, when only specific flags like -tulpn or ss -tulpn do so.

32
Matchingmedium

Match each Linux command to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Search text using patterns

Change file permissions

Report snapshot of current processes

Archive files

Stream editor for filtering and transforming text

Why these pairings

The correct matches are: cp for copying files, grep for searching text, and chmod for changing permissions. Common confusions include mixing these commands due to similar syntax or overlapping contexts.

33
MCQhard

An administrator is troubleshooting a DNS issue. The command 'dig @8.8.8.8 example.com' returns a response, but 'host example.com' returns 'Host not found'. Which of the following is the most likely cause?

A.The network interface is down.
B.The /etc/hosts file is corrupt.
C.The DNS server at 8.8.8.8 is not responding.
D.The /etc/resolv.conf file is misconfigured.
AnswerD

The `host` command queries the resolver configured in /etc/resolv.conf, whereas `dig @8.8.8.8` bypasses that file by querying the specified server directly. Since the explicit query succeeds, the resolver configuration must be faulty, satisfying the stem's constraint that only the default lookup path fails.

Why this answer

The command 'dig @8.8.8.8 example.com' succeeds, proving that the DNS server at 8.8.8.8 is reachable and functional, and that network connectivity is fine. However, 'host example.com' fails because it uses the system's default resolver, which reads /etc/resolv.conf to determine which DNS server to query. If /etc/resolv.conf is misconfigured (e.g., missing or incorrect nameserver entries), the resolver cannot reach a valid DNS server, resulting in 'Host not found'.

Exam trap

The trap here is that candidates see a successful 'dig' and assume DNS is fully working, not realizing that 'dig' with an explicit server bypasses the local resolver configuration, while 'host' relies on /etc/resolv.conf.

How to eliminate wrong answers

Option A is wrong because if the network interface were down, 'dig @8.8.8.8' would also fail (no route to host). Option B is wrong because the /etc/hosts file is used for local hostname resolution before DNS; a corrupt file could cause incorrect mappings but would not cause a 'Host not found' error when the DNS query itself fails—the resolver would still attempt DNS. Option C is wrong because the 'dig @8.8.8.8' command succeeded, directly proving that 8.8.8.8 is responding.

34
MCQhard

Refer to the exhibit. A system administrator finds this line in /etc/rsyslog.conf. What is the effect of this configuration?

A.Only messages with facility *.info are forwarded.
B.All syslog messages are forwarded via TCP to the server.
C.All syslog messages are forwarded via UDP to the server at 192.168.1.100 on port 514.
D.Only authentication-related messages are forwarded.
AnswerC

The selector * matches every facility and severity, and the single @ prefix specifies forwarding over UDP to 192.168.1.100 on the default syslog port 514. This satisfies the exhibit's requirement to relay all messages to that remote collector.

Why this answer

The line `*.* @192.168.1.100:514` in rsyslog.conf uses the `@` symbol to indicate UDP forwarding. The `*.*` selector means all facilities and all priorities, so every syslog message is forwarded via UDP to the server at 192.168.1.100 on port 514. This is a standard rsyslog syntax for remote logging.

Exam trap

The trap here is that candidates confuse the single `@` (UDP) with double `@@` (TCP), or misinterpret `*.*` as a specific facility filter rather than the universal wildcard for all syslog messages.

How to eliminate wrong answers

Option A is wrong because `*.*` does not restrict to facility `*.info`; it includes all facilities and all priorities, not just info-level messages. Option B is wrong because the single `@` specifies UDP, not TCP; TCP forwarding would use two `@@` symbols (e.g., `*.* @@192.168.1.100:514`). Option D is wrong because `*.*` covers all facilities, not just authentication-related (auth, authpriv); there is no facility filter applied.

35
MCQeasy

Which of the following commands will display the default gateway of a Linux system?

A.arp -a
B.netstat -i
C.ip route show
D.ifconfig
AnswerC

The ip route show command prints the kernel routing table, whose default entry (destination 0.0.0.0/0) lists the gateway address. This directly satisfies the stem's requirement to display the default gateway, unlike ip addr, which only shows interface addressing.

Why this answer

The `ip route show` command displays the kernel routing table, which includes the default gateway as a default route (typically `default via <gateway-IP>`). This is the standard modern tool for viewing routing information on Linux systems.

Exam trap

The trap here is that candidates often confuse `netstat -r` (which does show the routing table) with `netstat -i` (which only shows interface statistics), leading them to incorrectly select option B.

How to eliminate wrong answers

Option A is wrong because `arp -a` displays the ARP cache (IP-to-MAC address mappings), not routing information or the default gateway. Option B is wrong because `netstat -i` shows network interface statistics (packets, errors, etc.), not the routing table or default gateway. Option D is wrong because `ifconfig` displays network interface configuration (IP address, netmask, etc.) but does not show routing information or the default gateway.

36
MCQmedium

An organization's DNS server (BIND) is authoritatively serving the example.com zone. The administrator needs to add a mail exchange record for mail.example.com with priority 10. Which resource record should be added to the zone file?

A.example.com. IN MX 10 mail.example.com.
B.mail.example.com. IN A 192.168.1.10
C.mail.example.com. IN CNAME example.com.
D.example.com. IN TXT "v=spf1 mx -all"
AnswerA

The MX record must sit at the zone apex (example.com.) with preference 10 and point to mail.example.com., the mail server's FQDN. Placing the owner name at mail.example.com. would instead declare a mail exchanger for that host, not the domain.

Why this answer

An MX record specifies the mail exchange server for a domain, and the syntax 'example.com. IN MX 10 mail.example.com.' defines a priority of 10 for the mail server mail.example.com. This record tells other mail servers to deliver email for @example.com to mail.example.com, with lower priority values preferred.

Exam trap

The trap here is that candidates often confuse the purpose of MX records with A or CNAME records, or mistakenly think an SPF TXT record is the correct way to designate a mail server, when in fact MX records are the standard mechanism for mail routing.

How to eliminate wrong answers

Option B is wrong because it adds an A record for mail.example.com, which maps a hostname to an IP address, but the question specifically asks for a mail exchange record (MX), not an address record. Option C is wrong because it creates a CNAME alias from mail.example.com to example.com, which would cause mail delivery issues (RFC 1034 prohibits CNAME records at the same node as other record types like MX). Option D is wrong because it adds a TXT record with an SPF policy, which is used for sender policy framework to prevent email spoofing, not for routing mail to a specific server.

37
Multi-Selecteasy

Which TWO commands are commonly used to start, stop, or restart system services on a Linux system that uses systemd as its init system?

Select 2 answers
A.service
B.journalctl
C.chkconfig
D.systemctl
E.init.d
AnswersA, D

service is a legacy wrapper that works with systemd on most distros.

Why this answer

The `service` command is a legacy tool that works with System V init scripts, but on systems using systemd, it is often mapped to `systemctl` via compatibility wrappers. This allows `service` to start, stop, or restart services on systemd-based distributions, making it a commonly used command for these tasks.

Exam trap

The trap here is that candidates may confuse `chkconfig` or `init.d` as valid systemd commands, forgetting that systemd replaced these with `systemctl` and that `service` is only a compatibility wrapper, not a native systemd tool.

38
MCQhard

A sysadmin is troubleshooting a connectivity issue between two servers in different subnets. The output of 'traceroute 192.168.2.10' shows packets reaching a router but not the destination. The router's firewall uses iptables. Which rule would prevent the traceroute from completing?

A.-A INPUT -i lo -j LOG
B.-A INPUT -p udp -j ACCEPT
C.-A INPUT -p tcp --dport 80 -j REJECT
D.-A INPUT -p icmp --icmp-type port-unreachable -j DROP
AnswerD

Blocks ICMP Port Unreachable, which stops traceroute responses.

Why this answer

Traceroute relies on ICMP Time Exceeded messages from intermediate routers and an ICMP Port Unreachable message from the destination to signal completion. Dropping ICMP type 3 (Destination Unreachable) packets, specifically port-unreachable (code 3), prevents the final response from reaching the source, causing traceroute to hang after reaching the last hop.

Exam trap

The trap here is that candidates often focus on blocking the UDP probes themselves (e.g., via -p udp -j DROP) rather than understanding that traceroute completion depends on the ICMP response from the destination, not just the probe packets.

How to eliminate wrong answers

Option A is wrong because logging (-j LOG) does not drop or reject packets; it only records them, so traceroute traffic would still pass. Option B is wrong because accepting UDP packets (-p udp -j ACCEPT) would actually help traceroute, which uses high UDP ports by default, not block it. Option C is wrong because rejecting TCP traffic on port 80 (-p tcp --dport 80 -j REJECT) is unrelated to traceroute, which uses UDP probes (or ICMP on some systems) and does not target port 80.

39
MCQeasy

A junior administrator on a systemd host needs the OpenSSH daemon to start automatically after every reboot and to begin running immediately without rebooting the machine. Which single command accomplishes both requirements?

A.systemctl start sshd.service
B.systemctl enable sshd.service
C.systemctl enable --now sshd.service
D.systemctl daemon-reload
AnswerC

The enable subcommand creates the persistent boot-time symlinks, while the --now flag additionally starts the unit in the running transaction. Both requirements are met in one step: the daemon is active immediately and will be pulled in automatically on subsequent boots. It is the standard idempotent way to activate and persist a service.

Why this answer

Persisting a service across boots requires enabling it so systemd creates the appropriate wants symlinks, while running it right away requires an active start. The enable --now combination performs both operations atomically, so the daemon is active and will also be pulled in at every subsequent boot without an intervening reboot or a second command.

Exam trap

The trap here is treating enable and start as interchangeable, when enable controls boot-time activation and start only affects the current runtime state.

40
Multi-Selectmedium

A Linux administrator needs to configure a system to act as a router between two subnets. The system has two network interfaces: eth0 (192.168.1.1/24) and eth1 (10.0.0.1/24). Which TWO steps are required to enable routing between these subnets? (Choose two.)

Select 2 answers
A.Add static routes for each subnet on both interfaces.
B.Set the default gateway on both subnets to point to the router's interface IP.
C.Configure firewall rules to allow forwarding between the interfaces.
D.Enable IP forwarding by setting net.ipv4.ip_forward=1.
E.Enable NAT (masquerading) on the external interface.
AnswersC, D

Even with IP forwarding enabled, firewall rules may block forwarded traffic. By default, many distributions have a default deny policy in the FORWARD chain. The administrator must add rules to allow traffic from eth0 to eth1 and vice versa, such as iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT and the reverse. This ensures that packets are not dropped by the firewall.

Why this answer

To enable a Linux system to route traffic between two directly connected subnets, IP forwarding must be enabled in the kernel, and firewall rules must permit forwarding between the interfaces. Static routes are not needed because the networks are directly connected. NAT is not required for internal routing, and configuring client gateways is done on the clients, not the router.

Exam trap

The trap here is overlooking the need for firewall rules in the FORWARD chain, as many administrators assume enabling IP forwarding is sufficient.

41
MCQeasy

A small office has a network printer with IP 192.168.1.100. The printer is shared via CUPS. A user reports that they cannot print a document from their workstation. The printer appears in the list of available printers, but when they try to print, the job hangs in the queue with status 'processing'. The administrator suspects the printer may be offline or the CUPS service is not running. Which command should the administrator run first to gather diagnostic information about the printer and its queue?

A.ping 192.168.1.100
B.lpstat -t
C.lpadmin -p printer -E
D.systemctl restart cups
AnswerB

lpstat -t reports the CUPS scheduler status, default destination, printer states and queued jobs, revealing whether the printer is disabled or the queue is stalled. It gathers the broadest diagnostic picture first, before more targeted checks such as lpinfo or restarting cups.

Why this answer

The `lpstat -t` command shows the complete status of the CUPS print system, including all printers, their queues, and whether they are accepting jobs. Since the job is stuck with 'processing' status, this command will reveal if the printer is idle, disabled, or unreachable, and whether the queue is enabled or paused. It is the first diagnostic step before testing network connectivity or restarting services.

Exam trap

The trap here is that candidates assume a network connectivity test (ping) is the logical first step, but the question specifically asks for diagnostic information about the printer and its queue, which requires CUPS-specific status reporting, not just ICMP reachability.

How to eliminate wrong answers

Option A is wrong because `ping` only tests basic network layer connectivity to 192.168.1.100, but does not provide any information about the CUPS printer queue status, job state, or whether the printer is accepting jobs. Option C is wrong because `lpadmin -p printer -E` enables the printer and sets it as the default, but it does not display diagnostic information; it modifies configuration and could disrupt an existing setup. Option D is wrong because `systemctl restart cups` restarts the CUPS service, which is a troubleshooting action that should only be taken after gathering diagnostic data; it may clear the queue and lose job information without identifying the root cause.

42
MCQhard

A server in a corporate network uses systemd-resolved for DNS. Internal hostnames (e.g., server.example.lan) fail to resolve, but external names (e.g., google.com) work. The /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf. The administrator checks the systemd-resolved configuration and finds that the internal DNS server is listed globally, but the network interface has no specific DNS set. Which command should be used to assign the internal DNS server to the interface and fix resolution?

A.Add the internal hostnames to /etc/hosts.
B.Run 'resolvectl dns eth0 10.0.0.1' to set the DNS server for the interface.
C.Restart systemd-resolved service.
D.Edit /etc/resolv.conf and add the internal DNS server.
AnswerB

Running `resolvectl dns eth0 10.0.0.1` assigns the internal DNS server to the eth0 interface at runtime, satisfying the stem's constraint that the interface has no per-link DNS configured. systemd-resolved routes queries for internal domains through the link-specific server, so server.example.lan resolves while external lookups continue via the global entry.

Why this answer

`resolvectl dns eth0 10.0.0.1` assigns the internal DNS server specifically to the network interface (eth0), overriding the global setting for that interface. In systemd-resolved, per-interface DNS settings take precedence over global DNS servers, so this command ensures that internal hostnames are resolved by the internal DNS server while external names continue to work via the global configuration.

Exam trap

The trap here is that candidates assume editing /etc/resolv.conf or restarting the service will fix the issue, but they fail to recognize that systemd-resolved requires explicit per-interface DNS assignment via `resolvectl` to override the global setting for a specific network interface.

How to eliminate wrong answers

Option A is wrong because adding hostnames to /etc/hosts is a static workaround that does not fix the underlying DNS resolution issue for dynamic internal hostnames; it is not a scalable solution and does not leverage the DNS server. Option C is wrong because restarting systemd-resolved does not change the configuration; it only reloads the existing settings, which still lack a per-interface DNS server for eth0. Option D is wrong because /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf, which is managed by systemd-resolved; manually editing it would be overwritten by systemd-resolved and is not the correct way to configure per-interface DNS in systemd-resolved.

43
Drag & Dropmedium

Order the steps to mount an NFS share from a remote server.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

NFS mounting requires the client package, a local directory, and the mount command with server and export path.

44
MCQeasy

A user submitted a print job to a CUPS printer but used the wrong options. Which command should the administrator use to cancel the job?

A.lpstat
B.cancel
C.lprm
D.lpadmin
AnswerB

The cancel command is part of CUPS and cancels print jobs.

Why this answer

The `cancel` command is the correct CUPS utility to terminate a print job that has already been submitted. It accepts either a job ID (e.g., `cancel 123`) or a printer name (e.g., `cancel printer-name`) to cancel the currently active job on that printer. This command directly communicates with the CUPS daemon to remove the job from the queue.

Exam trap

The trap here is that candidates familiar with legacy BSD/LPD printing systems may instinctively choose `lprm`, but CUPS uses the `cancel` command as its standard job cancellation tool, and `lprm` is not the correct CUPS command.

How to eliminate wrong answers

Option A is wrong because `lpstat` is used to display the status of printers and print jobs, not to cancel them. Option C is wrong because `lprm` is the BSD/LPD print system command for removing jobs; CUPS does not use `lprm` natively (though it may be aliased for compatibility, the standard CUPS command is `cancel`). Option D is wrong because `lpadmin` is used for printer configuration and administration (adding, removing, or setting default printers), not for canceling individual print jobs.

45
MCQmedium

A sysadmin notices that after modifying iptables rules, the SSH service is unreachable from a specific subnet (192.168.1.0/24). Which command should be used to view the current rules with line numbers for easier identification?

A.iptables -L
B.iptables -L --line-numbers
C.iptables -t raw -L
D.iptables -t nat -L
AnswerB

The --line-numbers flag appends rule position numbers to each chain's output, letting the sysadmin pinpoint the exact rule blocking 192.168.1.0/24 before deleting or inserting. Plain iptables -L lists rules without numbers, making precise identification and correction harder.

Why this answer

The `iptables -L --line-numbers` command displays all current iptables rules in the default filter table with line numbers prepended to each rule. This allows the sysadmin to easily identify and reference specific rules (e.g., for deletion or insertion) when troubleshooting why SSH traffic from 192.168.1.0/24 is being dropped or rejected.

Exam trap

The trap here is that candidates may choose `iptables -L` (Option A) because it shows rules, but they overlook the `--line-numbers` flag, which is critical for efficient rule management and is a common LPIC-1 exam detail.

How to eliminate wrong answers

Option A is wrong because `iptables -L` lists rules without line numbers, making it harder to pinpoint the exact rule affecting SSH traffic. Option C is wrong because `iptables -t raw -L` shows rules in the raw table, which is used for connection tracking exemptions (e.g., NOTRACK), not for filtering SSH traffic. Option D is wrong because `iptables -t nat -L` shows rules in the NAT table, which handles address translation (SNAT/DNAT) and does not affect packet filtering decisions for SSH reachability.

46
MCQmedium

A web server running on this host is not accessible from clients. Based on the exhibit, what is the most likely reason?

A.The FORWARD chain policy is DROP.
B.The OUTPUT chain policy is ACCEPT.
C.Incoming HTTP traffic is blocked by a DROP rule on port 80.
D.SSH traffic is blocked.
AnswerC

A DROP rule on port 80 silently discards inbound HTTP packets before the web server can respond, which matches the exhibit showing no listener reachability from clients. Because DROP gives no rejection response, clients time out rather than receive a connection refused error, confirming the firewall as the blocking constraint.

Why this answer

The exhibit shows a firewall rule set where the INPUT chain has a DROP rule for destination port 80 (HTTP). Since incoming HTTP traffic from clients must traverse the INPUT chain to reach the local web server process, this DROP rule explicitly blocks all inbound HTTP requests, making the web server inaccessible. The FORWARD chain is irrelevant because traffic destined for the local host uses the INPUT chain, not FORWARD.

Exam trap

The trap here is that candidates often confuse the FORWARD chain with the INPUT chain, assuming that blocking traffic to a local service requires a FORWARD rule, when in fact the INPUT chain governs packets destined for the host itself.

How to eliminate wrong answers

Option A is wrong because the FORWARD chain policy only affects traffic routed through the host (e.g., acting as a router), not traffic destined for the local host; the web server is local, so FORWARD is not involved. Option B is wrong because the OUTPUT chain policy being ACCEPT controls outbound traffic from the local host, not inbound HTTP requests from clients; it has no effect on incoming connections. Option D is wrong because SSH traffic (port 22) is not mentioned in the exhibit as being blocked; the issue is specifically HTTP on port 80, and SSH is irrelevant to web server accessibility.

47
MCQeasy

A user reports that they cannot connect to a remote server using SSH. The administrator checks the SSH server status and it is running. Which of the following is the most likely cause?

A.A firewall is blocking port 22.
B.The client's subnet mask is incorrect.
C.The client cannot resolve the server's hostname.
D.The SSH server is using UDP instead of TCP.
AnswerA

With the SSH daemon confirmed running, a firewall dropping inbound TCP port 22 is the most likely cause, since the service listens but packets never reach it. This directly explains the connection failure despite a healthy server process.

Why this answer

SSH operates over TCP port 22 by default. If the SSH server is running but the client cannot connect, a firewall blocking port 22 is the most likely cause because it would prevent the TCP handshake from completing, even though the SSH daemon (sshd) is active and listening.

Exam trap

The trap here is that candidates may assume a running SSH server guarantees connectivity, overlooking that a firewall can block the port even when the service is active, or they may confuse SSH's TCP usage with UDP-based protocols like DNS.

How to eliminate wrong answers

Option B is wrong because an incorrect subnet mask would prevent the client from reaching any host outside its local subnet, but the question specifies a remote server, so routing or gateway issues would be more relevant; a subnet mask error alone would not selectively block SSH while allowing other traffic. Option C is wrong because if the client cannot resolve the server's hostname, the user would likely receive a 'Name or service not known' error, not a connection failure to a running SSH server; the administrator could test with the server's IP address to isolate DNS issues. Option D is wrong because SSH uses TCP (Transmission Control Protocol) for reliable, connection-oriented communication, not UDP; UDP is used by protocols like DNS or DHCP, and SSH has no UDP mode.

48
MCQeasy

A user reports that they cannot access the company's web server. The administrator confirms the server is running and network connectivity is fine. Which command should be used to verify that the HTTP service is listening on the correct port?

A.ping 127.0.0.1
B.netstat -rn
C.iperf3 -c localhost
D.ss -tlnp
AnswerD

ss -tlnp lists listening TCP sockets with numeric ports and the owning process, directly confirming whether the HTTP service is bound to the expected port. The -l flag restricts output to listening sockets, satisfying the verification requirement.

Why this answer

`ss -tlnp`, is correct because it lists TCP listening sockets with their port numbers and associated processes. The `-t` flag filters for TCP, `-l` shows only listening sockets, `-n` displays numeric addresses and ports (avoiding DNS lookups), and `-p` reveals the process ID/name. This directly verifies whether the HTTP service (typically port 80 or 443) is actively listening on the expected interface.

Exam trap

The trap here is that candidates may confuse general network connectivity tools (ping, iperf3) or routing commands (netstat -rn) with service-specific port listening checks, failing to recognize that only `ss` (or `netstat -tlnp`) directly confirms the HTTP daemon is bound to the correct port.

How to eliminate wrong answers

Option A is wrong because `ping 127.0.0.1` tests only local loopback connectivity and does not check whether a specific service (like HTTP) is listening on a port. Option B is wrong because `netstat -rn` displays the routing table, not listening sockets or service ports. Option C is wrong because `iperf3 -c localhost` is a network throughput testing tool that measures bandwidth between client and server, not a command to verify whether a specific service is listening on a port.

49
MCQmedium

A system administrator wants to monitor network traffic on a specific port (TCP/443) entering the server. Which command will capture packets on interface eth0 and display them in real-time?

A.netstat -tulpn | grep :443
B.ss -tulpn | grep :443
C.tcpdump -i eth0 port 443
D.iptables -L -n -v
AnswerC

tcpdump captures live packets on a named interface, and the port 443 filter restricts output to TCP/443 traffic, satisfying both the interface and real-time display requirements. Other tools either read saved files or lack equivalent filtering.

Why this answer

C is correct because `tcpdump -i eth0 port 443` captures packets on interface eth0 filtering for TCP port 443 (HTTPS) and displays them in real-time as they arrive. This command uses the libpcap library to intercept raw network frames, making it the standard tool for live packet capture and analysis.

Exam trap

The trap here is that candidates confuse commands that show socket state (netstat/ss) with commands that capture live packets (tcpdump), leading them to pick a command that only lists current connections rather than monitoring traffic in real-time.

How to eliminate wrong answers

Option A is wrong because `netstat -tulpn | grep :443` shows listening sockets and established connections, not live packet capture; it only displays current socket states from /proc/net/tcp, not real-time traffic. Option B is wrong because `ss -tulpn | grep :443` similarly lists socket statistics from kernel data, not packet-level capture; it cannot show individual packets or their contents. Option D is wrong because `iptables -L -n -v` lists firewall rules and their packet/byte counters, but it does not capture or display packet contents in real-time; it only shows accumulated statistics for rules.

50
MCQeasy

An administrator is configuring a DHCP server to assign IP addresses to clients in the 192.168.10.0/24 subnet. The server should provide the default gateway as 192.168.10.1 and DNS server as 8.8.8.8. Which option in /etc/dhcp/dhcpd.conf defines the default gateway?

A.option subnet-mask 255.255.255.0;
B.option routers 192.168.10.1;
C.option broadcast-address 192.168.10.255;
D.option domain-name-servers 8.8.8.8;
AnswerB

`option routers` is the DHCP parameter that delivers the default gateway address to clients, satisfying the stem's requirement to advertise 192.168.10.1 as the gateway for the 192.168.10.0/24 subnet. The `routers` option maps directly to DHCP option 3, which clients interpret as their default route.

Why this answer

The `option routers` directive in the ISC DHCP server configuration file `/etc/dhcp/dhcpd.conf` explicitly defines the default gateway (router) that clients should use. This directive sends the Router Option (option 3) in the DHCPOFFER and DHCPACK messages, instructing clients to set their default route to the specified IP address.

Exam trap

The trap here is that candidates may confuse the `option routers` directive with `option domain-name-servers` or `option subnet-mask`, especially since all three are commonly used together in a subnet declaration, but only `option routers` sets the default gateway.

How to eliminate wrong answers

Option A is wrong because `option subnet-mask 255.255.255.0;` defines the subnet mask (option 1) for the client, not the default gateway. Option C is wrong because `option broadcast-address 192.168.10.255;` sets the broadcast address (option 28) for the subnet, which is a separate parameter from the router. Option D is wrong because `option domain-name-servers 8.8.8.8;` specifies the DNS server (option 6) for name resolution, not the default gateway.

51
MCQeasy

A Linux administrator needs to view the current kernel ring buffer messages to diagnose a hardware issue that occurred during boot. Which command will display these messages?

A.journalctl -k
B.tail -f /var/log/syslog
C.dmesg
D.cat /var/log/messages
AnswerC

The dmesg command displays the kernel ring buffer, which contains messages from the kernel, including hardware detection, driver loading, and boot-time messages. It is the standard tool to view these messages in real time or from the last boot. The administrator can use dmesg to diagnose hardware issues by examining the output for errors or warnings related to devices.

Why this answer

The kernel ring buffer stores messages generated by the kernel, including hardware detection and driver initialization. The dmesg command is specifically designed to read and display this buffer. Other commands like journalctl -k or log files may contain overlapping information but are not guaranteed to show the full ring buffer, especially for early boot messages.

Therefore, dmesg is the most direct and reliable choice.

Exam trap

The trap here is confusing the kernel ring buffer with general system logs, leading to commands that may not show all hardware messages.

52
Multi-Selectmedium

Which THREE of the following are valid files or directories used by the Domain Name System (DNS) resolution process on a Linux system?

Select 3 answers
A./etc/host.conf
B./etc/resolv.conf
C./etc/named.conf
D./etc/sysconfig/network
E./etc/nsswitch.conf
AnswersA, B, E

/etc/host.conf configures the order in which the resolver consults sources such as hosts, bind and nis, satisfying the stem's requirement for a valid DNS resolution file. It is read by glibc's resolver, letting administrators prioritise local /etc/hosts entries over DNS queries or vice versa.

Why this answer

Option A, /etc/host.conf, is correct because it is a legacy configuration file that tells the resolver library the order in which resolution services are queried (e.g., 'order hosts,bind'), directly affecting how hostnames are resolved. Option B, /etc/resolv.conf, is correct because it defines the DNS resolver configuration, listing nameserver IP addresses, the search domain, and options such as ndots and timeout used by the resolver. Option E, /etc/nsswitch.conf, is correct because its 'hosts:' line specifies the Name Service Switch order (e.g., 'files dns') that determines whether /etc/hosts, DNS, or other sources are consulted during name resolution.

Option C, /etc/named.conf, is not part of the client resolution process; it is the main configuration file for the BIND (named) DNS server daemon. Option D, /etc/sysconfig/network, is a Red Hat-style file for general network settings like hostname and gateway, not a DNS resolver file.

Exam trap

The trap here is that candidates confuse server-side DNS configuration files (like `/etc/named.conf`) with client-side resolution files, or they overlook `/etc/host.conf` and `/etc/nsswitch.conf` as essential parts of the DNS resolution chain.

53
MCQmedium

A system administrator wants to configure NTP client on a server running systemd and using systemd-timesyncd. Which file should be edited to set the NTP server?

A./etc/chrony.conf
B./etc/systemd/timesyncd.conf
C./etc/ntp.conf
D./etc/ntp/ntp.conf
AnswerB

Editing /etc/systemd/timesyncd.conf sets the NTP servers used by systemd-timesyncd, satisfying the stem's systemd constraint. The NTP= directive under the [Time] section specifies upstream servers, after which the service is restarted. Unlike chrony's /etc/chrony.conf or ntpd's /etc/ntp.conf, this file belongs solely to systemd-timesyncd.

Why this answer

On a system using systemd-timesyncd, the NTP server configuration is stored in /etc/systemd/timesyncd.conf. This file is read by the systemd-timesyncd service to determine which NTP servers to synchronize with. Editing this file is the correct method for configuring NTP clients under systemd.

Exam trap

The trap here is that candidates often confuse the configuration files for different NTP implementations (ntpd, chrony, and systemd-timesyncd) and may default to the traditional /etc/ntp.conf without recognizing that systemd-timesyncd uses its own dedicated file.

How to eliminate wrong answers

Option A is wrong because /etc/chrony.conf is the configuration file for chrony, a different NTP implementation, not for systemd-timesyncd. Option C is wrong because /etc/ntp.conf is the configuration file for the traditional ntpd service, not for systemd-timesyncd. Option D is wrong because /etc/ntp/ntp.conf is an alternative path for ntpd configuration (often used on some distributions like FreeBSD), but it is not used by systemd-timesyncd.

54
MCQmedium

A company is deploying a new web application and needs to ensure high availability. They have two web servers and want to use DNS round-robin. Which DNS record type is most appropriate?

A.MX
B.PTR
C.CNAME
D.A
AnswerD

An A record maps a hostname directly to an IPv4 address. Publishing multiple A records with the same name, one per web server, lets DNS return the addresses in rotating order, distributing client requests across both servers and satisfying the round-robin high-availability requirement.

Why this answer

DNS round-robin distributes traffic across multiple servers by returning multiple A records for a single hostname in a rotating order. An A record maps a hostname to an IPv4 address, so using multiple A records for the same name is the standard method for DNS-based load balancing. This allows each web server to be reached via its own IP address, enabling high availability without additional hardware or software.

Exam trap

The trap here is that candidates may confuse CNAME records with A records, thinking a CNAME can point to multiple servers, but CNAMEs are single-target aliases and cannot provide round-robin distribution.

How to eliminate wrong answers

Option A is wrong because MX records are used for mail exchange routing, specifying mail servers for a domain, not for web server load balancing. Option B is wrong because PTR records perform reverse DNS lookups (IP to hostname), which are irrelevant for distributing web traffic. Option C is wrong because CNAME records create an alias from one hostname to another, but they cannot point to multiple IP addresses or provide round-robin functionality; they only map a name to a single canonical name.

55
MCQhard

An administrator must grant a contractor temporary, passwordless sudo access to run only /usr/bin/systemctl restart nginx on a production web server. Which entry in a file under /etc/sudoers.d/ best meets this requirement while limiting privilege escalation?

A.contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx
B.contractor ALL=(ALL) NOPASSWD: /usr/bin/systemctl
C.contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart *
D.%contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx
AnswerA

This rule permits the named user to run exactly that command as root without a password and nothing else. Because sudo matches the command line against the specified path and arguments, unrelated systemctl subcommands are denied, which satisfies the least-privilege requirement for temporary contractor access.

Why this answer

Least privilege requires specifying both the permitted binary and its exact arguments. Listing the full command with its unit argument confines the contractor to restarting nginx as root without a password, while the absence of wildcards prevents reusing the rule for other services. A dedicated file under /etc/sudoers.d keeps the change auditable and easy to revoke.

Exam trap

The trap here is forgetting that a sudoers command without its arguments allows every subcommand of that binary, so omitting "restart nginx" silently grants far more than intended.

56
MCQhard

A database server on a Linux system is configured to listen on TCP port 3306. The administrator wants to restrict access to the database server to only the local network (192.168.1.0/24) using iptables. Which of the following iptables rules achieves this?

A.iptables -A INPUT -p tcp --dport 3306 -d 192.168.1.0/24 -j DROP
B.iptables -A OUTPUT -p tcp --dport 3306 -d 192.168.1.0/24 -j ACCEPT
C.iptables -A INPUT -p tcp --dport 3306 -s 192.168.1.0/24 -j ACCEPT
D.iptables -A OUTPUT -p tcp --sport 3306 -s 192.168.1.0/24 -j ACCEPT
AnswerC

This rule matches TCP destination port 3306 with source 192.168.1.0/24 and accepts it, restricting database access to the local subnet. Other traffic to that port falls through to subsequent rules, satisfying the stem's local-network-only constraint.

Why this answer

It adds an INPUT chain rule that accepts TCP traffic destined for port 3306 only when the source address is within the 192.168.1.0/24 subnet. This effectively restricts incoming database connections to the local network, while all other sources are implicitly dropped by the default INPUT policy or subsequent rules.

Exam trap

The trap here is confusing the -s (source) and -d (destination) flags, leading candidates to pick Option A which drops traffic to the local network instead of accepting traffic from it.

How to eliminate wrong answers

Option A is wrong because it uses the -d (destination) flag instead of -s (source), and then jumps to DROP, which would block traffic destined for the 192.168.1.0/24 network (i.e., traffic going out to that subnet) rather than restricting incoming connections from it. Option B is wrong because it applies to the OUTPUT chain, which controls outgoing traffic; restricting access to an incoming database server requires an INPUT chain rule, not OUTPUT. Option D is wrong because it uses the OUTPUT chain with --sport 3306 (source port) and -s (source address), which would match outgoing packets originating from port 3306 with a source address in 192.168.1.0/24 — this is irrelevant for controlling incoming connections to the database server.

Ready to test yourself?

Try a timed practice session using only Essential System Services and Networking questions.