LPIC-3 Exam 303: Security, 2.0

Question No: 11

Which of the following openssl commands generates a certificate signing request (CSR) using the already existing private key contained in the file private/keypair.pem?

  1. openssl req -key private/keypair.pem -out req/csr.pem

  2. openssl req – new -key private/keypair.pem -out req/csr.pem

  3. openssl gencsr -key private/keypair.pem -out req/csr.pem

  4. openssl gencsr -new- key private/keypair.pem -out req/csr.pem

Answer: B

Question No: 12

in which path is the data, which can be altered by the sysctl command, accessible?

  1. /dev/sys/

  2. /sys/

  3. /proc/sys/

  4. /sysctl/

Answer: C

Question No: 13 CORRECT TEXT

Which option in an Apache HTTPD configuration file enables OCSP stapling? (Specify ONLY the option name without any values or parameters.)

Answer: httpd-ssl.conf

Question No: 14

Which of the following configuration options makes Apache HTTPD require a client certificate for authentication?

  1. Limit valid-x509

  2. SSLRequestClientCert always

  3. Require valid-x509

  4. SSLVerifyClient require

  5. SSLPolicy valid-client-cert

Answer: D

Question No: 15

Given that this device has three different keys, which of the following commands deletes only the first key?

  1. cryptsetup luksDelKey /dev/sda 1 0

  2. cryptsetup luksDelkey /dev/sda 1 1

  3. cryptsetup luksDelKey / dev /mapper/crypt- vol 1

  4. cryptsetup luksDelKey / dev /mapper/crypt- vol 0

Answer: A

Question No: 16 CORRECT TEXT

Which PAM module checks new passwords against dictionary words and enforces complexity? (Specially the module name only without any path.)

Answer: pam_cracklib


Question No: 17 CORRECT TEXT

Which command, included in BIND, generates DNSSEC keys? (Specify ONLY the command without any path or parameters.)

Answer: dnssec-keygen

http://ripe60.ripe.net/pres entations/Damas-BiND_9.7_-_DNSSE_for_humans.pdf

Question No: 18 CORRECT TEXT

Which directive is used in an OpenVPN server configuration in order to send network configuration information to the client? (Specify ONLY the option name without any values or parameters.)

Answer: push https;//community.openvpn.net/openvpn/wiki/RoutedLans

Question No: 19

Which of the following types can be specified within the Linux Audit system? (Choose THREE correct answers)

  1. Control rules

  2. File system rules

  3. Network connection rules

  4. Console rules

  5. System call rules

Answer: A,B,E

Question No: 20

Which of the following resources of a shell and its child processes can be controlled by the Bash build-in command ulimit? (Choose THREE correct answers.)

  1. The maximum size of written files

  2. The maximum number of open file descriptors

  3. The maximum number of newly created files

  4. The maximum number of environment variables

  5. The maximum number of user processes

Answer: A,B,E

