Question No : 1

What effect does the following command have on TCP packets?
iptables- A INPUT -d 10 142 232.1 -p tcp -dport 20:21 -j ACCEPT
A. Forward all TCP traffic not on port 20 or 21 to the IP address 10.142 232.1
B. Drop all TCP traffic coming from 10 142 232.1 destined for port 20 or 21.
C. Accept only TCP traffic from 10.142 232.1 destined for port 20 or 21.
D. Accept all TCP traffic on port 20 and 21 for the IP address
Answer: C

Question No : 2

Which of the following prefixes could be present in the output of getcifsacl? (Choose THREE correct answers.)
Answer: A,C,E

Question No : 3

Which of the following statements is true about chroot environments?
A. Symbolic links to data outside the chroot path are followed, making files and directories accessible
B. Hard links to files outside the chroot path are not followed, to increase security
C. The chroot path needs to contain all data required by the programs running in the chroot environment
D. Programs are not able to set a chroot path by using a function call, they have to use the command chroot
E. When using the command chroot, the started command is running in its own namespace and cannot communicate with other processes
Answer: C

Question No : 4

Which command, included in BIND, generates DNSSEC keys? (Specify ONLY the command without any path or parameters.)
Answer: A

Question No : 5

Which of the following commands adds users using SSSD's local service?
A. sss_adduser
B. sss_useradd
C. sss_add
D. sss-addlocaluser
E. sss_local_adduser
Answer: B

Question No : 6

What option of mount.cifs specifies the user that appears as the local owner of the files of a mounted CIFS share when the server does not provide ownership information? (Specify ONLY the option name without any values or parameters.)
A. uld=arg
Answer: A

Question No : 7

What command is used to update NVTs from the OpenVAS NVT feed? (Specify ONLY the command without any path or parameters).
Answer: A

Question No : 8

Which command included in the Linux Audit system provides searching and filtering of the audit log? (Specify ONLY the command without any path or parameters.)
Answer: A

Question No : 9

Linux Extended File Attributes are organized in namespaces. Which of the following names correspond to existing attribute namespaces? (Choose THREE correct answers.)
A. default
B. system
C. owner
D. trusted
E. user
Answer: B,D,E

Question No : 10

Which of the following resources of a shell and its child processes can be controlled by the Bash build-in command ulimit? (Choose THREE correct answers.)
A. The maximum size of written files
B. The maximum number of open file descriptors
C. The maximum number of newly created files
D. The maximum number of environment variables
E. The maximum number of user processes
Answer: A,B,E

Question No : 11

Which option of the openvpn command should be used to ensure that ephemeral keys are not written to the swap space?
A. --mlock
B. --no-swap
C. --root-swap
D. --keys-no-swap
Answer: A

Question No : 12

Which of the following openssl commands generates a certificate signing request (CSR) using the already existing private key contained in the file private/keypair.pem?
A. openssl req -key private/keypair.pem -out req/csr.pem
B. openssl req - new -key private/keypair.pem -out req/csr.pem
C. openssl gencsr -key private/keypair.pem -out req/csr.pem
D. openssl gencsr -new- key private/keypair.pem -out req/csr.pem
Answer: B

Question No : 13

What effect does the configuration SSLStrictSNIVHostCheck on have on an Apache HTTPD virtual host?
A. The clients connecting to the virtual host must provide a client certificate that was issued by the same CA that issued the server's certificate.
B. The virtual host is served only to clients that support SNI.
C. All of the names of the virtual host must be within the same DNS zone.
D. The virtual host is used as a fallback default for all clients that do not support SNI.
E. Despite its configuration, the virtual host is served only on the common name and Subject Alternative Names of the server certificates.
Answer: B

Question No : 14

Given a proper network and name resolution setup, which of the following commands establishes a trust between a FreelPA domain and an Active Directory domain?
A. ipa trust-add --type ad addom --admin Administrator --password
B. ipa-ad -add-trust --account ADDOM\Administrator--query-password
C. net ad ipajoin addom -U Administrator -p
D. trustmanager add -_domain ad: //addom --user Administrator -w
E. ipa ad join addom -U Administrator -w
Answer: A

Question No : 15

Which DNS label points to the DANE information used to secure HTTPS connections to https://www.example.com/?
A. example.com
B. dane.www.example.com
C. soa.example com
D. www.example.com
E. _443_tcp.www example.com
Answer: E
