Linux LPIC-3 Security Practice Exam

Back to exams page

Free Linux LPIC-3 Security practice exam. Take this free quiz to prepare for the LPIC-3 Security specialization exam.

Take the LPIC-3 Security course here.

1. In Linux Extended File Attributes, which of the following is a valid attribute namespace?

Question 1 of 50

2. In iptables, is the default table.

Question 2 of 50

3. To create an iptables rule specifying a port, the transport protocol utilized by such protocol must be specified as well. Which option is used to determine the transport protocol?

Question 3 of 50

4. By default, HTTP servers listen on port , whereas HTTPS servers listen on port

Question 4 of 50

5. In DNSSEC, zone signing keys must be signed by another key type called:

Question 5 of 50

6. Which of the following DNS record contains a server's DNSSEC signature?

Question 6 of 50

7. In Apache Httpd, the SSL module configuration file contains a directive used to indicate the SSL certificate file. Which directive is that?

Question 7 of 50

8. In which path is the data that can be altered by the sysctl command?

Question 8 of 50

9. the filter table, in iptables, has 3 chains. Rules that have source and destination ip addresses different from the own machine's address should be added to the chain.

Question 9 of 50

10. Linux machines must have the ________________ kernel module loaded, to be able to forward packets.

Question 10 of 50

11. A X509 SSL certificate carries a number of data, except:

Question 11 of 50

12. What happens when the command getfattr afile is run while the file afile has no extended
attributes set?

Question 12 of 50

13. Which of the following code snippets is a valid client configuration for FreeRADIUS?

Question 13 of 50

14. Which command, included in bind-utils, generates DNSSEC keys?

Question 14 of 50

15. Name one built-in iptables chain that does not belong to the nat table:

Question 15 of 50

16. To change the Type of Service IP header field, a rule must be added to the table.

Question 16 of 50

17. Which statement is true regarding the certificate of a Root CA?

Question 17 of 50

18. Command used to redefine user password info, such as expire date, minimum age and maximum age.

Question 18 of 50

19. Which command installs and configures a new FreeIPA server, including all subcomponents,
and creates a new FreeIPA domain?

Question 19 of 50

20. Which of the following components is part of FreeIPA?

Question 20 of 50

21. Command to mount a CIFS share:

Question 21 of 50

22. Which of the following commands changes the source IP address to 192.0.2.11 for all IPv4
packets which go through the network interface eth0?

Question 22 of 50

23. Which of the following information, within a DNSSEC-signed zone, is signed by the key
signing key?

Question 23 of 50

24. SELinux stands for:

Question 24 of 50

25. SELinux mode that runs in logging-only mode.

Question 25 of 50

26. Which PAM module checks new passwords against dictionary words and enforces complexity?

Question 26 of 50

27. Which command included in the Linux Audit system provides searching and filtering of the
audit log?

Question 27 of 50

28. Wireshark and Tcpdump are two examples of network tools that require the ___________ library.

Question 28 of 50

29. The SNMP protocol uses ports 161 and 162 and it uses as a transport protocol.

Question 29 of 50

30. Nmap can perform port scans using different scanning methods, but its default method is:

Question 30 of 50

31. The Nmap syn scan is also called:

Question 31 of 50

32. This is NOT a valid DNSSEC record:

Question 32 of 50

33. This software does not require the pcap library.

Question 33 of 50

34. This is not a network management software:

Question 34 of 50

35. Snort is a(n):

Question 35 of 50

36. In Snort, the _____________ environment variable determines the network which Snort should monitor.

Question 36 of 50

37. Which of the following database names can be used within a Name Service Switch (NSS) configuration file?

Question 37 of 50

38. Which of the following commands adds a new user newuser to FreeIPA?

Question 38 of 50

39. Which of the following resources of a shell and its child processes can be controlled by the Bash build-in command ulimit?

Question 39 of 50

40. Which of the following authentication methods was added to NFS in version 4?

Question 40 of 50

41. NFSv4 transmits data using both TCP and UDP transport protocols.

Question 41 of 50

42. By default, Nmap scan the most common ports.

Question 42 of 50

43. Which of the following openssl commands generates a certificate signing request (CSR) using the already existing private key contained in the file private/keypair.pem?

Question 43 of 50

44. What effect does the following command have on TCP packets?

iptables -A INPUT -d 10.142.232.1 -p tcp --dport 20:21 -j ACCEPT

Question 44 of 50

45. It is true about chroot environments:

Question 45 of 50

46. How are SELinux permissions related to standard Linux permissions?

Question 46 of 50

47. Which of the following practices are important for the security of private keys?

Question 47 of 50

48. The following command displays the current rules of the nat table (all chains):
iptables nat

Question 48 of 50

49. Which of the following access control models is established by using SELinux?

Question 49 of 50

50. Which of the following access control models is established by standard Linux Permissions?

Question 50 of 50


40+ IT Certifications · One Membership

Stop Watching. Start Doing.

Unlimited IT certification training with videos, labs, PBQs, live Cisco racks and practice exams — everything you need to pass and actually know your stuff.

  • Video theory lessons
  • Follow-along labs
  • Performance-based questions
  • Practice exams
  • Live Cisco rack access
  • 40+ certs including CompTIA, Cisco, Linux, Microsoft, AWS, CEH
Join Now — From $29

Cancel anytime. No contracts. Instant access on signup.

content-filler