{"id":23050,"date":"2026-09-26T11:23:46","date_gmt":"2026-09-26T11:23:46","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23050"},"modified":"2026-09-26T11:23:46","modified_gmt":"2026-09-26T11:23:46","slug":"lpi-202-450-practice-test-questions-and-exam-dumps-part-6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/lpi-202-450-practice-test-questions-and-exam-dumps-part-6-q101-120\/","title":{"rendered":"LPI 202-450 Practice Test Questions and Exam Dumps Part 6 Q101-120"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/202-450-exam-dumps\"><b>LPI 202-450\u00a0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 101. Which BIND configuration directive specifies which clients are permitted to perform recursive queries?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> allow-transfer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> allow-update<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> allow-notify<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> allow-recursion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. allow-recursion<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The BIND <\/span><span style=\"font-weight: 400;\">allow-recursion<\/span><span style=\"font-weight: 400;\"> option controls which clients are permitted to use the server for recursive DNS queries. Restricting recursion is important on servers that should not provide recursive service to arbitrary external clients. <\/span><span style=\"font-weight: 400;\">allow-transfer<\/span><span style=\"font-weight: 400;\"> controls which hosts may receive zone transfers, <\/span><span style=\"font-weight: 400;\">allow-update<\/span><span style=\"font-weight: 400;\"> controls dynamic DNS updates, and <\/span><span style=\"font-weight: 400;\">allow-notify<\/span><span style=\"font-weight: 400;\"> controls which servers may send zone-change notifications. Recursive DNS servers should generally limit access to trusted networks or clients. Combining recursion controls with appropriate ACL definitions provides more precise management of who can use the server as a resolver.<\/span><\/p>\n<p><b>Question 102. Which BIND command can be used to verify the syntax of the main named configuration file?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> named-checkconf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> named-checkzone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rndc-check<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> bind-config<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. named-checkconf<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">named-checkconf<\/span><span style=\"font-weight: 400;\"> checks the syntax of BIND&#8217;s configuration files, especially the main <\/span><span style=\"font-weight: 400;\">named.conf<\/span><span style=\"font-weight: 400;\"> configuration. It can help administrators identify malformed statements before attempting to restart or reload the DNS server. <\/span><span style=\"font-weight: 400;\">named-checkzone<\/span><span style=\"font-weight: 400;\"> has a different purpose: it validates the contents and structure of an individual DNS zone file. <\/span><span style=\"font-weight: 400;\">rndc<\/span><span style=\"font-weight: 400;\"> is used to control a running named service, while the other commands listed are not standard BIND configuration-validation utilities. Running <\/span><span style=\"font-weight: 400;\">named-checkconf<\/span><span style=\"font-weight: 400;\"> after configuration changes can prevent service failures caused by syntax errors.<\/span><\/p>\n<p><b>Question 103. Which DNS record type identifies a service location by specifying a target hostname and port?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TXT<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SRV<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SOA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. SRV<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SRV records provide information about the location of services, including the target hostname and TCP or UDP port where the service is available. An SRV record can also include priority and weight values that influence service selection. They are commonly used by protocols and applications that need DNS-based service discovery. TXT records contain text information, PTR records provide reverse DNS mappings, and SOA records contain administrative information about a DNS zone. Understanding SRV records is useful when troubleshooting applications that depend on DNS-based discovery rather than simple hostname-to-address resolution.<\/span><\/p>\n<p><b>Question 104. What is the primary purpose of the DNS SOA serial number?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To specify the DNS listening port<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify the version of the zone data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define the default gateway<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify the mail exchanger<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To identify the version of the zone data<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The SOA serial number identifies the current version of a DNS zone. Secondary name servers compare the serial number of their local copy with the value on the primary server to determine whether updated zone data needs to be transferred. Administrators should increment the serial number whenever zone data changes in a way that needs to be propagated. The SOA record also contains refresh, retry, and expiration timing information. The serial number does not specify a DNS port, gateway, or mail exchanger; those functions are handled by other configuration elements and DNS records.<\/span><\/p>\n<p><b>Question 105. Which Apache directive specifies the email address or contact information displayed on certain server-generated error pages?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerAdmin<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ErrorDocument<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerContact<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AdminEmail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. ServerAdmin<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">ServerAdmin<\/span><span style=\"font-weight: 400;\"> directive specifies the email address of the server administrator. Apache can use this information on certain automatically generated error pages so users know whom to contact regarding server problems. <\/span><span style=\"font-weight: 400;\">ErrorDocument<\/span><span style=\"font-weight: 400;\"> controls the documents or responses returned for specific HTTP error codes. <\/span><span style=\"font-weight: 400;\">ServerName<\/span><span style=\"font-weight: 400;\"> identifies the server&#8217;s hostname, while <\/span><span style=\"font-weight: 400;\">ServerRoot<\/span><span style=\"font-weight: 400;\"> defines the base directory containing server configuration and related files. Although modern websites often customize error pages, understanding <\/span><span style=\"font-weight: 400;\">ServerAdmin<\/span><span style=\"font-weight: 400;\"> remains useful when examining Apache configuration and server-generated responses.<\/span><\/p>\n<p><b>Question 106. Which Apache directive can define a custom response document for an HTTP 404 error?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ErrorPage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ErrorDocument<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CustomError<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NotFoundDocument<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. ErrorDocument<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">ErrorDocument<\/span><span style=\"font-weight: 400;\"> directive defines what Apache should return when a particular HTTP error occurs. For example, an administrator can configure a custom page for status code 404, which indicates that a requested resource was not found. The directive can point to a local URL, a local file, or other supported response forms depending on the configuration. This allows websites to provide more useful error pages instead of relying on generic server responses. Other directives such as <\/span><span style=\"font-weight: 400;\">DocumentRoot<\/span><span style=\"font-weight: 400;\"> and <\/span><span style=\"font-weight: 400;\">DirectoryIndex<\/span><span style=\"font-weight: 400;\"> serve different purposes within Apache.<\/span><\/p>\n<p><b>Question 107. Which HTTP status code indicates that the requested resource was not found?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 404<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 401<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 403<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 503<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. 404<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">HTTP status code 404 indicates that the server could not find a representation of the requested resource. It commonly occurs when a URL points to a nonexistent file, an incorrect path, or a resource that has been removed without an appropriate redirect. A 401 response concerns authentication, 403 indicates that access is forbidden, and 503 indicates that the service is temporarily unavailable. When troubleshooting 404 errors, administrators should verify the requested URL, Apache&#8217;s DocumentRoot and aliases, rewrite rules, and whether the expected resource actually exists.<\/span><\/p>\n<p><b>Question 108. Which NFS-related service traditionally provides RPC port registration and discovery for services on systems using older NFS architectures?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> nfsd<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mountd<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rpcbind<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> idmapd<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. rpcbind<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">rpcbind<\/span><span style=\"font-weight: 400;\"> maps RPC service numbers to network ports and allows clients to discover the ports used by RPC-based services. Older NFS configurations commonly rely on RPC services such as mountd and locking-related daemons, making rpcbind an important part of service discovery. NFSv4 reduces this dependency by using TCP port 2049 for its core protocol. <\/span><span style=\"font-weight: 400;\">nfsd<\/span><span style=\"font-weight: 400;\"> provides the NFS server functionality, <\/span><span style=\"font-weight: 400;\">mountd<\/span><span style=\"font-weight: 400;\"> handles mount-related requests in applicable configurations, and <\/span><span style=\"font-weight: 400;\">idmapd<\/span><span style=\"font-weight: 400;\"> is associated with NFSv4 identity mapping. Understanding rpcbind is useful when troubleshooting older NFS deployments and firewall rules.<\/span><\/p>\n<p><b>Question 109. Which NFS command can be used to re-export filesystems after changes to the export configuration?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> showmount -r<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> exportfs -r<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nfsstat -r<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mount.nfs -r<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. exportfs -r<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">exportfs -r<\/span><span style=\"font-weight: 400;\"> command re-exports filesystems according to the current export configuration. It is commonly used after changes to <\/span><span style=\"font-weight: 400;\">\/etc\/exports<\/span><span style=\"font-weight: 400;\"> so that the NFS server&#8217;s active export table reflects the updated configuration. <\/span><span style=\"font-weight: 400;\">showmount<\/span><span style=\"font-weight: 400;\"> is primarily used to query export information, <\/span><span style=\"font-weight: 400;\">nfsstat<\/span><span style=\"font-weight: 400;\"> displays NFS statistics, and <\/span><span style=\"font-weight: 400;\">mount.nfs<\/span><span style=\"font-weight: 400;\"> is used by clients to mount NFS filesystems. Administrators should verify both the export configuration and the resulting active exports when troubleshooting access problems.<\/span><\/p>\n<p><b>Question 110. Which Samba parameter controls whether users can modify files in a share?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> writable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> write users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> read only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> modify access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. read only<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Samba <\/span><span style=\"font-weight: 400;\">read only<\/span><span style=\"font-weight: 400;\"> parameter controls whether a share permits clients to modify its contents. When set to <\/span><span style=\"font-weight: 400;\">yes<\/span><span style=\"font-weight: 400;\">, the share is read-only from the Samba service&#8217;s perspective; when set to <\/span><span style=\"font-weight: 400;\">no<\/span><span style=\"font-weight: 400;\">, clients may be allowed to write, provided underlying filesystem permissions also permit the operation. <\/span><span style=\"font-weight: 400;\">write users<\/span><span style=\"font-weight: 400;\"> can identify users permitted to write under applicable Samba configurations, but <\/span><span style=\"font-weight: 400;\">read only<\/span><span style=\"font-weight: 400;\"> is the primary share-level setting for general write access. Samba access controls must always be considered alongside Linux ownership and filesystem permission settings.<\/span><\/p>\n<p><b>Question 111. Which Samba utility can be used to connect to a remote SMB share from the command line and transfer files?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbstatus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> testparm<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbclient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbmountd<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. smbclient<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">smbclient<\/span><span style=\"font-weight: 400;\"> provides a command-line interface for accessing SMB\/CIFS shares. It can be used to list available shares, authenticate to a server, browse directories, and transfer files. Administrators frequently use it to test whether a Samba or Windows file server is reachable and whether credentials have appropriate access. <\/span><span style=\"font-weight: 400;\">smbstatus<\/span><span style=\"font-weight: 400;\"> displays active Samba sessions and locks, while <\/span><span style=\"font-weight: 400;\">testparm<\/span><span style=\"font-weight: 400;\"> validates Samba configuration. <\/span><span style=\"font-weight: 400;\">smbmountd<\/span><span style=\"font-weight: 400;\"> is not a standard Samba utility. Testing with <\/span><span style=\"font-weight: 400;\">smbclient<\/span><span style=\"font-weight: 400;\"> can help separate SMB authentication or sharing problems from issues involving filesystem mounting.<\/span><\/p>\n<p><b>Question 112. Which Linux configuration file determines the order in which sources such as files and DNS are consulted for hostname resolution?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/resolv.conf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/hostname<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/nsswitch.conf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/networks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. \/etc\/nsswitch.conf<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">\/etc\/nsswitch.conf<\/span><span style=\"font-weight: 400;\"> file controls the sources and ordering used by the Name Service Switch for various types of information, including hostname resolution. For example, a system may be configured to check <\/span><span style=\"font-weight: 400;\">\/etc\/hosts<\/span><span style=\"font-weight: 400;\"> before querying DNS. <\/span><span style=\"font-weight: 400;\">\/etc\/resolv.conf<\/span><span style=\"font-weight: 400;\"> contains resolver-specific settings such as nameserver addresses, while <\/span><span style=\"font-weight: 400;\">\/etc\/hostname<\/span><span style=\"font-weight: 400;\"> identifies the local host. <\/span><span style=\"font-weight: 400;\">\/etc\/networks<\/span><span style=\"font-weight: 400;\"> can contain network-name mappings but does not generally control the lookup order. Understanding NSS is important because a system can have correctly configured DNS but still resolve a hostname using another source first.<\/span><\/p>\n<p><b>Question 113. Which command can request a DHCP lease renewal on a Linux client using the common ISC DHCP client utility?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> dhcp-renew<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dhclient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> leasectl<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dhcpclientctl<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. dhclient<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">dhclient<\/span><span style=\"font-weight: 400;\"> is the traditional ISC DHCP client utility used to obtain and manage DHCP leases. Depending on the options and existing lease state, it can request or renew an address from a DHCP server. Exact DHCP client tooling varies between Linux distributions because NetworkManager, systemd-networkd, and other frameworks may manage DHCP directly. Nevertheless, <\/span><span style=\"font-weight: 400;\">dhclient<\/span><span style=\"font-weight: 400;\"> is an important command in Linux networking knowledge and is commonly encountered in LPIC-2 material. Administrators should first determine which network-management system controls the interface before manually invoking DHCP client commands.<\/span><\/p>\n<p><b>Question 114. Which Postfix parameter controls the network interfaces on which the SMTP server listens?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> inet_interfaces<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mynetworks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smtp_bind_address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> listen_interfaces<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. inet_interfaces<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Postfix <\/span><span style=\"font-weight: 400;\">inet_interfaces<\/span><span style=\"font-weight: 400;\"> parameter specifies the network interfaces or addresses on which Postfix accepts network connections. It can be configured to listen on all interfaces, selected addresses, or localhost depending on the server&#8217;s intended role. <\/span><span style=\"font-weight: 400;\">mynetworks<\/span><span style=\"font-weight: 400;\"> defines networks that are trusted for relay and is not the same as determining listening interfaces. Other parameters may affect outbound SMTP connections, but <\/span><span style=\"font-weight: 400;\">inet_interfaces<\/span><span style=\"font-weight: 400;\"> directly controls where Postfix&#8217;s network services bind. Correct configuration helps limit unnecessary exposure of mail services to untrusted networks.<\/span><\/p>\n<p><b>Question 115. Which SMTP response code generally indicates successful completion of a requested mail action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 250<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 354<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 421<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 550<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. 250<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SMTP response code 250 generally indicates that a requested action completed successfully. It is commonly returned after commands such as EHLO, MAIL FROM, RCPT TO, or successful message acceptance, depending on the stage of the SMTP transaction. Code 354 indicates that the server is ready to receive message data, 421 indicates that the service is unavailable or closing the connection, and 550 commonly indicates a requested action was not completed because the mailbox or command was rejected. Understanding SMTP response codes helps administrators diagnose mail-delivery failures.<\/span><\/p>\n<p><b>Question 116. Which Dovecot authentication mechanism allows users to authenticate using credentials supplied through a system authentication database such as PAM?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> passdb<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> namespace<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mail_location<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> service imap<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. passdb<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dovecot uses <\/span><span style=\"font-weight: 400;\">passdb<\/span><span style=\"font-weight: 400;\"> configuration to define how user authentication credentials are verified. A passdb can use mechanisms such as PAM, system databases, SQL, LDAP, or other supported authentication sources depending on the deployment. <\/span><span style=\"font-weight: 400;\">userdb<\/span><span style=\"font-weight: 400;\"> separately provides user information such as mailbox location and UID\/GID data. <\/span><span style=\"font-weight: 400;\">namespace<\/span><span style=\"font-weight: 400;\"> defines mailbox namespaces, while <\/span><span style=\"font-weight: 400;\">mail_location<\/span><span style=\"font-weight: 400;\"> specifies where messages are stored. Understanding the distinction between passdb and userdb is important when configuring Dovecot authentication and diagnosing situations where users can authenticate but mailbox information cannot be resolved correctly.<\/span><\/p>\n<p><b>Question 117. Which SSH command generates a new public\/private key pair for authentication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-copy-id<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-keygen<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-keyscan<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-add<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. ssh-keygen<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">ssh-keygen<\/span><span style=\"font-weight: 400;\"> generates and manages SSH authentication key pairs. It can create modern key types such as Ed25519 and can also be used to inspect or convert supported keys. <\/span><span style=\"font-weight: 400;\">ssh-copy-id<\/span><span style=\"font-weight: 400;\"> installs a public key into a remote user&#8217;s <\/span><span style=\"font-weight: 400;\">authorized_keys<\/span><span style=\"font-weight: 400;\"> file, <\/span><span style=\"font-weight: 400;\">ssh-keyscan<\/span><span style=\"font-weight: 400;\"> retrieves public host keys, and <\/span><span style=\"font-weight: 400;\">ssh-add<\/span><span style=\"font-weight: 400;\"> loads private keys into an authentication agent. A typical public-key authentication setup involves generating a key pair with <\/span><span style=\"font-weight: 400;\">ssh-keygen<\/span><span style=\"font-weight: 400;\">, installing the public key on the remote account, and keeping the private key securely protected.<\/span><\/p>\n<p><b>Question 118. Which SSH feature allows a remote host to use an SSH authentication agent running on the client?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local port forwarding<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> X11 forwarding<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Agent forwarding<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Agent forwarding<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SSH agent forwarding allows a remote SSH session to communicate with an authentication agent running on the original client. This can allow the user to authenticate to another SSH server without copying the private key to the intermediate host. It is enabled with options such as <\/span><span style=\"font-weight: 400;\">ForwardAgent<\/span><span style=\"font-weight: 400;\"> or the <\/span><span style=\"font-weight: 400;\">-A<\/span><span style=\"font-weight: 400;\"> client option. Because a forwarded agent can potentially be abused by a compromised remote host during the forwarded session, administrators should enable agent forwarding only where necessary and on trusted systems. Local port forwarding and X11 forwarding serve different purposes.<\/span><\/p>\n<p><b>Question 119. Which Linux command can temporarily switch SELinux from enforcing mode to permissive mode?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> setenforce 0<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> semanage permissive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> selinuxctl permissive<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> restorecon 0<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. setenforce 0<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The command <\/span><span style=\"font-weight: 400;\">setenforce 0<\/span><span style=\"font-weight: 400;\"> changes the current SELinux enforcement mode to permissive. In permissive mode, SELinux policy violations are logged but are not generally blocked by enforcement. <\/span><span style=\"font-weight: 400;\">setenforce 1<\/span><span style=\"font-weight: 400;\"> switches back to enforcing mode. This change is normally temporary and does not permanently disable SELinux. Administrators can use permissive mode during troubleshooting to determine whether SELinux policy is contributing to an access problem, but they should review audit logs and correct policy issues rather than relying on permissive mode as a permanent configuration.<\/span><\/p>\n<p><b>Question 120. Which nftables object is used to group rules that process packets according to defined hooks and priorities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Set<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Chain<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Map<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Counter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Chain<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An nftables chain contains rules that are evaluated for packets. Base chains are associated with packet-processing hooks and can have priorities that determine when they are evaluated relative to other chains. Sets store collections of values, maps associate keys with values, and counters track packet and byte statistics. Tables provide a higher-level organizational container for chains, sets, maps, and other objects. Understanding nftables&#8217; hierarchy is important when constructing or troubleshooting firewall rules because tables and chains organize how packet-processing rules are applied.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full LPI 202-450\u00a0 Exam Dumps and Practice Test Dumps &nbsp; Question 101. Which BIND configuration directive specifies which clients are permitted to perform recursive queries? allow-transfer allow-update allow-notify allow-recursion Correct Answer: 4. allow-recursion Explanation :- The BIND allow-recursion option controls which clients are permitted to use the server for recursive DNS queries. Restricting recursion [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23050"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23050"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23050\/revisions"}],"predecessor-version":[{"id":23051,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23050\/revisions\/23051"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}