303-300 Exam Questions
119 real 303-300 exam questions with expert-verified answers and explanations. Page 1 of 3.
- Question #1Network Security
Which of the following parameters to openssl s_client specifies the host name to use for TLS Server Name Indication?
openssl s_clientServer Name IndicationTLS/SSLHost verification - Question #2Cryptography
Which of the following lines in an OpenSSL configuration adds an X 509v3 Subject Alternative
X.509v3Subject Alternative NameOpenSSLPKI - Question #3Host Security
What is a buffer overflow?
buffer overflowsoftware vulnerabilitymemory safetyexploitation - Question #4Host Security
Which tool can be used to manage the Linux Audit system?
Linux AuditauditdSystem MonitoringHost Security - Question #5Access Control
What is the difference between a SetUID and SetGID bit?
SUID/SGID bitsFile permissionsAccess controlPrivilege execution - Question #6Host Security
Which of the following expressions are valid AIDE rules? (Choose TWO correct answers.)
AIDEFile IntegrityRule SyntaxHost Auditing - Question #7Threat Detection and Incident Response
Which command included in the Linux Audit system provides searching and filtering of the audit log? (Specify ONLY the command without any path or parameters.) Solution: ausearch De...
Linux AuditausearchLog FilteringSecurity Events - Question #8Host Security
Which package management tools can be used to verify the integrity of installed files on a Linux system?
Package ManagementFile Integrity VerificationRPM/DPKGSystem Administration - Question #9Threat Detection and Incident Response
What is a honeypot?
honeypotdeceptionintrusion detectionthreat detection - Question #10Network Security
Which of the following is used to perform DNSSEC validation on behalf of clients?
DNSSEC validationrecursive resolverDNS architectureauthentication - Question #11Access Control
Given a proper network and name resolution setup, which of the following commands establishes a trust between a FreeIPA domain and an Active Directory domain?
FreeIPAActive Directory integrationDomain trustIdentity management - Question #12Access Control
Which of the following command lines sets the administrator password for ntop to testing 123?
ntopadmin-passwordcli-flagsauthentication - Question #13Cryptography
What is a symmetric key?
Symmetric CryptographyEncryptionCryptographic KeysKey Management - Question #14Access Control
What is privilege escalation?
Privilege EscalationVulnerability ExploitationAccess ControlAttack Types - Question #15Host Security
Which PAM module checks new passwords against dictionary words and enforces complexity? (Specially the module name only without any path.) Solution: pam_cracklib Determine whether...
pam_cracklibPAMpassword-validationcomplexity-enforcement - Question #16Network Security
What is the purpose of TSIG in DNS?
TSIGDNS SecurityMessage AuthenticationHMAC - Question #17Network Security
What is the purpose of IP sets?
IP setsnetfilterfirewall rulespacket filtering - Question #18Access Control
What is the purpose of an extended attribute in Linux?
Extended AttributesFile MetadataLinux Filesystemxattr - Question #19Host Security
Which file is used to configure rkhunter?
rkhunterrootkit detectionhost configurationsecurity tools - Question #20Network Security
What effect does the following command have on TCP packets? iptables- A INPUT d 10.142.232.1 p tcp --dport 20:21 j ACCEPT
iptables syntaxTCP filteringfirewall rulesport-based access control - Question #21Access Control
Which of the following access control models is established by using SELinux?
SELinuxMandatory Access ControlAccess Control Models - Question #22Cryptography
Which option of the openvpn command should be used to ensure that ephemeral keys are not written to the swap space?
ephemeral keysmemory lockingOpenVPNswap protection - Question #23Access Control
Linux Extended File Attributes are organized in namespaces. Which of the following names correspond to existing attribute namespaces?(Choose THREE correct answers.)
Extended File AttributesLinux File SystemsFile MetadataAccess Control - Question #24Network Security
Which of the following terms refer to existing scan techniques with nmap? (Choose TWO correct answers.)
nmap scan typesTCP scanningport discoverynetwork reconnaissance - Question #25Access Control
Which command is used to view the access control list of a file?
ACLFile PermissionsgetfaclLinux Commands - Question #26Access Control
Which of the following commands adds a new user usera to FreeIPA?
FreeIPAuser managementCLILDAP - Question #27Network Security
What is a man-in-the-middle attack?
man-in-the-middleeavesdroppingnetwork interceptioncommunication compromise - Question #28Access Control
Which of the following prefixes could be present in the output of getcifsacl? (Choose THREE correct answers.)
CIFS ACLsgetcifsacl output formatFile permissionsSID identifiers - Question #29Network Security
When OpenVPN sends a control packet to its peer, it expects an acknowledgement in 2 seconds by default. Which of the following options changes the timeout period to 5 seconds?
OpenVPN configurationTLS timeoutVPN parametersHandshake timing - Question #30Access Control
Which permission bit allows a user to delete a file?
file-permissionsdirectory-writeunix-permissionsaccess-control - Question #31Host Security
What is the purpose of rkhunter?
rootkit detectionhost securitymalware detectionsystem hardening - Question #32Access Control
What is a certificate chain?
certificate chainsPKIdigital signaturestrust verification - Question #33Network Security
Which of the following commands changes the source IP address to 192.0.2.11 for all IPv4 packets which go through the network interface eth0?
iptablesSource NATNetwork address translationLinux firewall - Question #34Network Security
Which of the following statements is used in a parameter file for setkey in order to create a new SPD entry?
IPsecSPDsetkeySecurity Policies - Question #35Threat Detection and Incident Response
Which of the following methods can be used to deactivate a rule in Snort? (Choose TWO correct answers.)
Snort rule managementIDS configurationRule disablingPass rules - Question #36Access Control
Which of the following commands adds users using SSSD's local service?
SSSDUser ManagementLocal ServiceAuthentication - Question #37Network Security
Which of the following DNS records are used in DNSSEC?
DNSSECDNS recordscryptographic signaturesDNS security - Question #38Network Security
What is the purpose of a Certificate Authority (CA)?
Certificate AuthorityX.509 certificatesPublic Key InfrastructureDigital Signatures - Question #39Network Security
Which directive is used in an OpenVPN server configuration in order to send network configuration information to the client? (Specify ONLY the option name without any values or par...
OpenVPNVPN ConfigurationServer DirectivesClient Configuration - Question #40Access Control
Which of the following sections are allowed within the Kerberos configuration file krb5.conf? (Choose THREE correct answers.)
Kerberoskrb5.confrealmscross-realm-paths - Question #41Threat Detection and Incident Response
What is the purpose of the Linux Audit system?
auditdintrusion detectionsystem monitoringsecurity auditing - Question #42Host Security
What is Linux Malware Detect?
Linux Malware DetectMalware DetectionHost SecurityLinux Security Tools - Question #43Host Security
What is a Trojan?
TrojansMalwareThreat ClassificationSoftware Security - Question #44Network Security
What is a rogue access point?
Rogue Access PointsWireless SecurityUnauthorized AccessNetwork Threats - Question #45Cryptography
Which command, included in BIND, generates DNSSEC keys? (Specify ONLY the command without any path or parameters.) Solution: dnssec-keygen Determine whether the given solution is c...
DNSSECBINDKey GenerationCryptography - Question #46Access Control
Which of the following stanzas is a valid client configuration for FreeRADIUS?
FreeRADIUSRADIUS configurationAAA protocolClient syntax - Question #47Cryptography
Which of the following DNS record types can the command dnssec-signzone add to a zone? (Choose THREE correct answers.)
DNSSECZone SigningRRSIG RecordsNSEC/NSEC3 - Question #48Access Control
What is the purpose of file ownership in Linux systems?
file ownershipLinux permissionsaccess controluser/group permissions - Question #49Network Security
What is a DoS attack?
DoS attacksNetwork availabilityAttack methodsService disruption - Question #50Cryptography
What is a trust anchor?
Trust AnchorRoot CertificatePKICertificate Authority