LPIC-3 Exam 303: Security, 2.0

Question No: 31

Which of the following database names can be used within a Name Service Switch (NSS) configuration file? (Choose THREE correct answers).

  1. host

  2. shadow

  3. service

  4. passwd

  5. group

Answer: A,C,E

Question No: 32

Which of the following command lines sets the administrator password for ntop to testing 123?

  1. ntop -set-admin-password=testing123

  2. ntop -set-password-testing123

  3. ntop -reset-password=testing 123

  4. ntop -set-new-password=testing123

Answer: A

Question No: 33

What is the purpose of IP sets?

  1. They group together IP addresses that are assigned to the same network interfaces.

  2. They group together IP addresses and networks that can be referenced by the network routing table.

  3. They group together IP addresses that can be referenced by netfilter rules.

  4. They group together IP and MAC addresses used by the neighbors on the local network.

  5. They group together IP addresses and user names that can be referenced from

/etc/hosts allow and /etc/hosts deny

Answer: C

Question No: 34 CORRECT TEXT

What command is used to update NVTs from the OpenVAS NVT feed? (Specify ONLY the command without any path or parameters).

Answer: openvas-nvt-sync http://www.openvas.org/openvas-nvt-feed.html

Question No: 35

Which of the following lines in an OpenSSL configuration adds an X 509v3 Subject Alternative Name extension for the host names example.org and www.example.org to a certificate#39;?

  1. subjectAltName = DNS: www example.org, DNS:example.org

  2. extension= SAN: www.example.org, SAN:example.org

  3. subjectAltName: www.example.org, subjectAltName: example.org

  4. commonName = subjectAltName= www.example.org, subjectAltName = example.org

  5. subject= CN= www.example.org, CN=example.org

Answer: A

Question No: 36

Which of the following information, within a DNSSEC- signed zone, is signed by the key signing key?

  1. The non-DNSSEC records like A, AAAA or MX

  2. The zone signing key of the zone.

  3. The RRSIG records of the zone.

  4. The NSEC or NSEC3 records of the zone.

  5. The DS records pointing to the zone

Answer: B

Question No: 37

Which of the following commands displays all ebtable rules contained in the table filter including their packet and byte counters?

  1. ebtables -t nat -L -v

  2. ebtables-L-t filter -Lv

  3. ebtables-t filter-L-Lc

  4. ebtables -t filter -Ln -L

  5. ebtables-L -Lc-t filter

Answer: C

Question No: 38

Which of the following access control models is established by using SELinux?

  1. Security Access Control (SAC)

  2. Group Access Control (GAC)

  3. User Access Control (UAC)

  4. Discretionary Access Control (DAC)

  5. Mandatory Access Control (MAC)

Answer: E

Question No: 39

What is the purpose of the program snort-stat?

  1. It displays statistics from the running Snort process.

  2. It returns the status of all configured network devices.

  3. It reports whether the Snort process is still running and processing packets.

  4. It displays the status of all Snort processes.

  5. It reads syslog files containing Snort information and generates port scan statistics.

Answer: E

Question No: 40

Which of the following methods can be used to deactivate a rule in Snort? (Choose TWO correct answers.)

  1. By placing a # in front of the rule and restarting Snort

  2. By placing a pass rule in local.rules and restarting Snort.

  3. By deleting the rule and waiting for Snort to reload its rules files automatically.

  4. By adding a pass rule to /etc/snort/rules.deactivated and waiting for Snort to reload its rules files automatically.

Answer: B,C

