Courseiva
Network Client ManagementmediumMultiple ChoiceObjective-mapped

LPIC-2 Network Client Management Practice Question

A Linux client is configured to authenticate users against an LDAP server using PAM. Some users are unable to log in, while others succeed. The admin has verified that the LDAP server is reachable and that the user entries exist. Which of the following is the most likely cause?

⚠ Common exam trap

Many exam-takers assume all authentication failures are due to network or service issues, but the question specifically states the LDAP server is reachable and user entries exist, so the cause must be a client-side configuration limit that affects only some users, such as a size limit in pam_ldap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The pam_ldap configuration has a size limit that restricts search results.

The pam_ldap configuration can include a size limit (e.g., 'pam_ldap size_limit 500') that restricts the number of entries returned from an LDAP search. When a user logs in, PAM may perform a search that returns multiple matching entries (e.g., due to ambiguous username or group membership lookups), and if the result set exceeds this limit, the search fails for some users. This explains why some users succeed while others fail, even though the LDAP server is reachable and user entries exist.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The nsswitch.conf file is missing the 'ldap' entry for 'passwd'.

    Why it's wrong here

    This would affect all users, not just some.

  • The pam_ldap configuration has a size limit that restricts search results.

    Why this is correct

    A size limit can cause some valid users to be omitted from search results, leading to intermittent failures.

  • The LDAP server is using different encryption settings.

    Why it's wrong here

    Encryption mismatch would affect all users, not just some.

  • The nslcd service is not running.

    Why it's wrong here

    If nslcd is not running, all LDAP lookups would fail.

About these practice questions

One of 507 original LPIC-2 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-2 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-2 exam.