202-450 Exam Questions
302 real 202-450 exam questions with expert-verified answers and explanations. Page 1 of 7.
- Question #2214 Troubleshooting
Some users are unable to connect to specific local hosts by name, while accessing hosts in other zones works as expected. Given that the hosts are reachable by their IP addresses,...
DNS troubleshootingBIND logsname resolutionlog files - Question #3208 Domain Name Server
A BIND server should never answer queries from certain networks or hosts. Which configuration directive could be used for this purpose?
BIND configurationblackhole directiveaccess controlnamed.conf - Question #4208 Domain Name Server
What is the purpose of a PTR record?
PTR recordreverse DNSDNS record typesIP to name - Question #5208 Domain Name Server
Performing a DNS lookup with dig results in this answer: What might be wrong in the zone definition?
zone file syntaxFQDN trailing dotPTR recordreverse lookup zone - Question #6208 Domain Name Server
What directive can be used in named.conf to restrict zone transfers to the 192.168.1.0/24 network?
zone transferallow-transfernamed.confAXFR - Question #7208 Domain Name Server
To securely use dynamic DNS updates, the use of TSIG is recommended. Which TWO statements about TSIG are true?
TSIGdynamic DNS updatesDNS securitytime synchronization - Question #10211 Network Client Management
Which option is used to configure pppd to use up to two DNS server addresses provided by the remote server?
pppdusepeerdnsPPP configurationDNS client - Question #11211 Network Client Management
A DNS server has the IP address 192.168.0.1. Which TWO of the following need to be done on a client machine to use this DNS server?
resolv.confnsswitch.confDNS client configurationname resolution - Question #12212 E-Mail Services
The mailserver is currently called fred, while the primary MX record points to mailhost.example.org. What must be done to direct example.org email towards fred?
MX recordA recordmail routingDNS zone configuration - Question #14208 Domain Name Server
Which option can be used to allow access to a BIND DNS server from only specified networks/hosts?
allow-queryBIND access controlnamed.confquery restriction - Question #15209 Web Services
There is a restricted area in an Apache site, which requires users to authenticate against the file /srv/www/security/site-passwd. Which command is used to CHANGE the password of e...
htpasswdBasic authenticationApache user managementpassword file - Question #16209 Web Services
Consider the following / srv/www/ default/html/ restricted/.htaccess AuthType Basic AuthUserFile / srv/www/ security/ site-passwd AuthName Restricted Require valid-user Order deny,...
.htaccessSatisfy directiveaccess controlBasic authentication - Question #17209 Web Services
A web server is expected to handle approximately 200 simultaneous requests during normal use with an occasional spike in activity and is performing slowly. Which directives in http...
MaxClientsStartServersApache performance tuninghttpd.conf - Question #18209 Web Services
Which statements about the Alias and Redirect directives in Apache's configuration file are true?
Alias directiveRedirect directiveApache URL mappingclient vs server handling - Question #20209 Web Services
When Apache is configured to use name-based virtual hosts:
name-based virtual hostsVirtualHost blockApache configurationServerName - Question #22HTTP Services
Which Apache directive is used to configure the main directory for the site, out of which it will serve documents?
ApacheDocumentRootweb server directivessite configuration - Question #24HTTP Services
The innd configuration file has been changed and it should be used as soon as possible. What is the fastest way to accomplish that?
INNctlinndinndconfiguration reload - Question #25HTTP Services
What command can be used to add a new newsgroup called LPI that allows posting?
INNctlinndnewsgroupNNTP administration - Question #26211 Network Client Management
Which TWO of the following commands could be used to add a second IP address to eth0?
ifconfigIP aliasingvirtual interfaceeth0 - Question #27211 Network Client Management
If the command arp -f is run, which file will be read by default?
ARParp command/etc/ethersaddress resolution - Question #28211 Network Client Management
What command must be used to print the kernel's routing table?
routerouting tablekernel routingnetwork commands - Question #29211 Network Client Management
What command would be used to configure the interface eth1:1 with the IP address 10 10.34 and the netmask 255.255.255.0?
ifconfigIP configurationnetmaskvirtual interface - Question #30211 Network Client Management
Which option must be used with ifconfig, to also see interfaces that are down?
ifconfig-a flagnetwork interfacesdowned interfaces - Question #32211 Network Client Management
What is the command to add another IP address to an interface that already has (at least) one IP address?
ifconfigIP aliasingeth0:1secondary IP address - Question #33211 Network Client Management
route shows the following output: Which of the following statements is correct?
route!H flagrejected host routerouting table output - Question #34211 Network Client Management
A network client has an ethernet interface configured with an IP address in the subnet 192.168.0.0/24. This subnet has a router, with the IP address 192.168.0.1, that connects this...
route adddefault gatewaynetwork configurationrouting - Question #35211 Network Client Management
A server with 2 network interfaces, eth0 and eth1, should act as a router. eth0 has the IP address 192.168.0.1 in the subnet 192.168.0.1/24 and eth1 has the IP address 10.0.0.1 in...
IP forwarding/proc/sys/net/ipv4/ip_forwardiptablesrouter configuration - Question #36211 Network Client Management
What command is used to add a route to the 192.168.4.0/24 network via 192.168.0.2?
route add-net flaggatewaystatic route - Question #37211 Network Client Management
Considering the following kernel IP routing table now, which of the following commands must be emove the route to the network 10.10.1.0/24?
route del-net flagrouting tableroute removal - Question #38213 System Security
Which of the following sentences is true, when using the following /etc/pam.d/login file? #%PAM-l.0 auth required /lib/security/pam_securetty.so auth required /lib/security/pam_nol...
PAMpam.d/loginLDAP authenticationcontrol flags - Question #39213 System Security
LDAP-based authentication against a newly-installed LDAP server does not work as expected. The file /etc/pam.d/login includes the following configuration parameters. Which of them...
PAMpam_ldapauthentication misconfigurationuse_first_pass - Question #40213 System Security
What is the advantage of using SASL authentication with OpenLDAP?
SASLOpenLDAPauthenticationplaintext password protection - Question #41213 System Security
In a PAM configuration file, which of the following is true about the required control flag?
PAMcontrol flagsauthentication modulesLinux security - Question #43213 System Security
As of Linux kernel 2.4, which software is used to configure a VPN?
VPNFreeS/WANIPSeckernel 2.4 - Question #44213 System Security
A program, called vsftpd, running in a chroot jail, is giving the following error: /bin/vsftpd: error while loading shared libraries: libc.so.6: cannot open shared object file: No...
chroot jailshared librariesvsftpdstatic linking - Question #45213 System Security
Which of the following can the program tripwire NOT check?
tripwirefile integrityIDSboot sectors - Question #46214 Troubleshooting
The following is an excerpt from the output of tcpdump -nli eth1 'udp': 13:03:17.277327 IP 192.168.123.5.1065 > 192.168.5.112.53: 43653+ A? lpi.org. (25) 13:03:17.598624 IP 192.168...
tcpdumpDNSpacket analysisUDP port 53 - Question #49213 System Security
A server is being used as a smurf amplifier, whereby it is responding to ICMP Echo-Request packets sent to its broadcast address. To disable this, which command needs to be run?
smurf attackICMP broadcast/proc/sysDoS prevention - Question #50213 System Security
When the default policy for the iptables INPUT chain is set to DROP, why should a rule allowing traffic to localhost exist?
iptablesloopback interfaceINPUT chaininter-process communication - Question #51213 System Security
To be able to access the server with the IP address 10.12.34.56 using HTTPS, a rule for iptables has to be written. Given that the client host's IP address is 192.168.43.12, which...
iptablesHTTPSTCP port 443FORWARD chain - Question #54213 System Security
When connecting to an SSH server for the first time, its fingerprint is received and stored in a file, which is located at:
SSHknown_hostshost fingerprintpublic key authentication - Question #56210 File Sharing
Which THREE of the following actions should be considered when a FTP chroot jail is created?
FTPchroot jail/etc/passwdvsftpd - Question #58214 Troubleshooting
Connecting to a remote host on the same LAN using ssh public-key authentication works but forwarding X11 doesn't. The remote host allows access to both services. Which of the follo...
SSHX11 forwardingsshd_configremote display - Question #59213 System Security
An iptables firewall was configured to use the target MASQUERADE to share a dedicated wireless connection to the Internet with a few hosts on the local network. The Internet connec...
iptablesMASQUERADESNATNAT - Question #60213 System Security
Which command line creates an SSH tunnel for POP and SMTP protocols?
SSH tunnelPOPSMTPport forwarding - Question #63Domain Name Server
Which of these tools can provide the most information about DNS queries?
digDNS query toolsname resolutionDNS diagnostics - Question #65Network Client Management
Which command would release the current IP address leased by a DHCP server?
DHCPdhclientIP releasenetwork configuration - Question #66System Security
Remote access to a CD-RW device on a machine on a LAN must be restricted to a selected user group. Select the TWO correct alternatives that describe the possible solutions for this...
PAMpam_consolesudodevice access control - Question #67System Security
Select the alternative that shows the correct way to disable a user login (except for root)
PAMpam_nologinlogin restrictionauthentication - Question #68Network Client Management
A new user was created on a master NIS server using useradd but cannot log in from an NIS client. Older users can log in. Which step was probably forgotten, when creating the new u...
NISyppushNIS mapsuser propagation