{"id":23052,"date":"2026-09-26T11:24:15","date_gmt":"2026-09-26T11:24:15","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23052"},"modified":"2026-09-26T11:24:15","modified_gmt":"2026-09-26T11:24:15","slug":"lpi-202-450-practice-test-questions-and-exam-dumps-part-7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/lpi-202-450-practice-test-questions-and-exam-dumps-part-7-q121-140\/","title":{"rendered":"LPI 202-450 Practice Test Questions and Exam Dumps Part 7 Q121-140"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/202-450-exam-dumps\"><b>LPI 202-450\u00a0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 121. Which BIND configuration statement specifies the default time-to-live for negative DNS responses in a zone&#8217;s SOA record?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> refresh<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> minimum<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> retry<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> expire<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. minimum<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In a DNS SOA record, the minimum field traditionally specifies the negative caching TTL, which determines how long resolvers may cache certain negative responses such as NXDOMAIN. In modern DNS terminology, this field is commonly described as the negative caching TTL rather than simply the default TTL for all records. The refresh, retry, and expire fields have different purposes for secondary servers: refresh controls when a secondary checks the primary, retry controls how soon it retries a failed refresh, and expire determines when the secondary stops serving the zone after prolonged inability to contact the primary. Understanding these SOA fields is important when troubleshooting DNS propagation and caching behavior.<\/span><\/p>\n<p><b>Question 122. Which Apache directive is used to define the hostname and port combination for which a virtual host responds?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DocumentRoot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerName<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DirectoryIndex<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Listen<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Listen<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Listen directive tells Apache which IP addresses and ports it should listen on for incoming connections. For example, <\/span><span style=\"font-weight: 400;\">Listen 80<\/span><span style=\"font-weight: 400;\"> makes Apache accept HTTP connections on TCP port 80. In a virtual-host configuration, ServerName identifies the hostname associated with a particular virtual host, while DocumentRoot specifies the directory containing its web content. DirectoryIndex controls which file Apache serves when a directory is requested. Although Listen can influence which virtual hosts are reachable, it does not itself define the hostname associated with a virtual host. Understanding the distinction between global listening configuration and virtual-host matching is essential for Apache administration.<\/span><\/p>\n<p><b>Question 123. Which command displays the NFS exports that a specified server makes available to clients?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> showmount -e<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nfsstat -m<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> exportfs -u<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rpcinfo -p<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. showmount -e<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">showmount -e<\/span><span style=\"font-weight: 400;\"> command queries an NFS server and displays the filesystems that the server is exporting. It is particularly useful when troubleshooting whether an NFS export is actually being advertised to clients. The <\/span><span style=\"font-weight: 400;\">nfsstat<\/span><span style=\"font-weight: 400;\"> command provides statistics about NFS activity, while <\/span><span style=\"font-weight: 400;\">exportfs<\/span><span style=\"font-weight: 400;\"> manages the server&#8217;s export table. <\/span><span style=\"font-weight: 400;\">rpcinfo -p<\/span><span style=\"font-weight: 400;\"> lists registered RPC services and their ports but does not specifically display the exported filesystems. Administrators commonly use <\/span><span style=\"font-weight: 400;\">showmount -e server.example.com<\/span><span style=\"font-weight: 400;\"> before attempting to mount a remote NFS filesystem to verify that the expected export is available.<\/span><\/p>\n<p><b>Question 124. Which Apache directive specifies the directory containing the web documents for a virtual host?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerAlias<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DirectoryIndex<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DocumentRoot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ErrorLog<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. DocumentRoot<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">DocumentRoot<\/span><span style=\"font-weight: 400;\"> directive specifies the filesystem directory from which Apache serves files for a website or virtual host. For example, <\/span><span style=\"font-weight: 400;\">DocumentRoot \/var\/www\/example<\/span><span style=\"font-weight: 400;\"> tells Apache to serve content from that directory. <\/span><span style=\"font-weight: 400;\">ServerAlias<\/span><span style=\"font-weight: 400;\"> defines additional hostnames that can match a virtual host, while <\/span><span style=\"font-weight: 400;\">DirectoryIndex<\/span><span style=\"font-weight: 400;\"> specifies default files such as <\/span><span style=\"font-weight: 400;\">index.html<\/span><span style=\"font-weight: 400;\"> when a directory is requested. <\/span><span style=\"font-weight: 400;\">ErrorLog<\/span><span style=\"font-weight: 400;\"> identifies the log file used for error messages. Correctly configuring DocumentRoot is fundamental when creating multiple virtual hosts because each site can point to a separate content directory while sharing the same Apache installation.<\/span><\/p>\n<p><b>Question 125. Which Samba utility checks the syntax and validity of the smb.conf configuration file without starting the Samba services?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbpasswd<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbclient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbstatus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> testparm<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. testparm<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">testparm<\/span><span style=\"font-weight: 400;\"> utility validates and reports the effective Samba configuration contained in <\/span><span style=\"font-weight: 400;\">smb.conf<\/span><span style=\"font-weight: 400;\">. It is commonly run after editing Samba configuration files to detect syntax errors or unexpected settings before restarting the Samba services. <\/span><span style=\"font-weight: 400;\">smbpasswd<\/span><span style=\"font-weight: 400;\"> manages Samba passwords, <\/span><span style=\"font-weight: 400;\">smbclient<\/span><span style=\"font-weight: 400;\"> provides a command-line client for accessing SMB\/CIFS resources, and <\/span><span style=\"font-weight: 400;\">smbstatus<\/span><span style=\"font-weight: 400;\"> displays information about current Samba connections and locks. Running <\/span><span style=\"font-weight: 400;\">testparm<\/span><span style=\"font-weight: 400;\"> is therefore an important administrative and troubleshooting step whenever shares, authentication settings, access controls, or other Samba parameters have been modified.<\/span><\/p>\n<p><b>Question 126. Which DHCP message does a DHCP server normally send in response to a client&#8217;s DHCPDISCOVER message?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPOFFER<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPDECLINE<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPRELEASE<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPNAK<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. DHCPOFFER<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A DHCP client normally begins the address allocation process by broadcasting a DHCPDISCOVER message. A DHCP server responds with a DHCPOFFER containing a proposed IP address and associated configuration parameters such as the subnet mask, default gateway, and lease duration. The client then typically responds with DHCPREQUEST to indicate which offer it accepts. DHCPACK confirms the requested lease, while DHCPNAK indicates that the requested configuration is not acceptable. DHCPDECLINE is used by a client when it detects that an offered address is already in use, and DHCPRELEASE is used to relinquish an existing lease.<\/span><\/p>\n<p><b>Question 127. Which Postfix parameter specifies the destinations for which the local machine should accept mail as the final destination?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> relayhost<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> myorigin<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mydestination<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> inet_interfaces<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. mydestination<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Postfix <\/span><span style=\"font-weight: 400;\">mydestination<\/span><span style=\"font-weight: 400;\"> parameter defines the domains and hostnames for which the server considers itself the final destination. Mail addressed to those destinations is delivered locally rather than relayed elsewhere. The <\/span><span style=\"font-weight: 400;\">relayhost<\/span><span style=\"font-weight: 400;\"> parameter identifies a system through which outgoing mail should be relayed. <\/span><span style=\"font-weight: 400;\">myorigin<\/span><span style=\"font-weight: 400;\"> determines the domain that appears in locally generated mail, while <\/span><span style=\"font-weight: 400;\">inet_interfaces<\/span><span style=\"font-weight: 400;\"> controls the network interfaces on which Postfix accepts connections. Correctly configuring <\/span><span style=\"font-weight: 400;\">mydestination<\/span><span style=\"font-weight: 400;\"> is important for preventing mail delivery problems and ensuring that the server recognizes the domains it is responsible for.<\/span><\/p>\n<p><b>Question 128. Which command can be used to display the current DNS resolver configuration managed by systemd-resolved?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> dig status<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> resolvectl status<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dnsctl show<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> systemctl dns<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. resolvectl status<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">resolvectl status<\/span><span style=\"font-weight: 400;\"> command displays detailed information about the DNS configuration managed by systemd-resolved. It can show DNS servers, DNS domains, link-specific settings, and resolver status for network interfaces. This makes it useful when diagnosing situations where a system has network connectivity but cannot resolve hostnames correctly. The <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\"> utility is primarily used to query DNS servers and inspect DNS responses rather than display the local resolver configuration. The other commands are not standard utilities for displaying systemd-resolved DNS status. Administrators can use resolvectl information together with tools such as <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\"> to distinguish local resolver configuration issues from authoritative DNS problems.<\/span><\/p>\n<p><b>Question 129. Which OpenSSH configuration option controls whether password authentication is permitted for SSH users?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PasswordAuthentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PubkeyAuthentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PermitUserEnvironment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> UseDNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. PasswordAuthentication<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">PasswordAuthentication<\/span><span style=\"font-weight: 400;\"> option in OpenSSH controls whether users may authenticate using passwords. Setting <\/span><span style=\"font-weight: 400;\">PasswordAuthentication no<\/span><span style=\"font-weight: 400;\"> disables password-based authentication, commonly when an administrator wants to require public-key authentication. <\/span><span style=\"font-weight: 400;\">PubkeyAuthentication<\/span><span style=\"font-weight: 400;\"> controls public-key authentication, while <\/span><span style=\"font-weight: 400;\">PermitUserEnvironment<\/span><span style=\"font-weight: 400;\"> determines whether user-specific environment settings may be accepted. <\/span><span style=\"font-weight: 400;\">UseDNS<\/span><span style=\"font-weight: 400;\"> concerns DNS lookups associated with incoming SSH connections and does not control authentication methods. After modifying <\/span><span style=\"font-weight: 400;\">sshd_config<\/span><span style=\"font-weight: 400;\">, administrators should validate the configuration and reload or restart the SSH service carefully, especially on remote systems, to avoid accidentally locking themselves out.<\/span><\/p>\n<p><b>Question 130. Which DNS record type identifies the mail server responsible for receiving email for a domain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TXT<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CNAME<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MX<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. MX<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An MX, or Mail Exchange, record identifies the mail servers responsible for accepting email for a DNS domain. MX records contain a priority value, allowing multiple mail servers to be listed with different preferences. Sending mail systems query the recipient domain&#8217;s MX records to determine where messages should be delivered. An NS record identifies authoritative name servers, a CNAME creates an alias for another DNS name, and a TXT record stores arbitrary text information such as SPF-related data. Correct MX configuration is therefore essential for reliable inbound email delivery and is a fundamental part of DNS administration.<\/span><\/p>\n<p><b>Question 131. Which NFS export option prevents the root user on an NFS client from being treated as root on the exported filesystem?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> noexec<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> root_squash<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> sync<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> subtree_check<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. root_squash<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The NFS <\/span><span style=\"font-weight: 400;\">root_squash<\/span><span style=\"font-weight: 400;\"> option maps requests from the root user on an NFS client to an unprivileged identity on the server. This prevents a remote client administrator from automatically receiving root-level access to files in an exported filesystem. It is an important security measure for NFS exports. The <\/span><span style=\"font-weight: 400;\">noexec<\/span><span style=\"font-weight: 400;\"> option prevents execution of binaries from a mounted filesystem, <\/span><span style=\"font-weight: 400;\">sync<\/span><span style=\"font-weight: 400;\"> controls how export operations are committed, and <\/span><span style=\"font-weight: 400;\">subtree_check<\/span><span style=\"font-weight: 400;\"> relates to checking paths within exported directory trees. Administrators should carefully consider export permissions because NFS access controls operate across the network and can expose sensitive files if configured incorrectly.<\/span><\/p>\n<p><b>Question 132. Which SMTP response code indicates that a requested mail action was successfully completed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 220<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 354<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 250<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 550<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. 250<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SMTP response code 250 indicates that a requested mail action has been successfully completed. It is commonly returned after commands such as <\/span><span style=\"font-weight: 400;\">MAIL FROM<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">RCPT TO<\/span><span style=\"font-weight: 400;\">, or <\/span><span style=\"font-weight: 400;\">DATA<\/span><span style=\"font-weight: 400;\"> have been successfully processed, depending on the stage of the SMTP conversation. Code 220 generally indicates that a service is ready, while 354 indicates that the server is ready to receive the message body after the DATA command. Code 550 commonly indicates a permanent failure such as a rejected mailbox or unavailable recipient. Understanding SMTP response codes is useful when diagnosing mail delivery and Postfix-related problems.<\/span><\/p>\n<p><b>Question 133. Which command creates a symbolic link from one pathname to another?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ln -h<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> link -s<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> cp -l<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ln -s<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. ln -s<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ln -s<\/span><span style=\"font-weight: 400;\"> command creates a symbolic link. A symbolic link contains a reference to another pathname rather than representing a second directory entry for the same inode. For example, <\/span><span style=\"font-weight: 400;\">ln -s \/var\/www\/html \/srv\/www<\/span><span style=\"font-weight: 400;\"> creates a symbolic link named <\/span><span style=\"font-weight: 400;\">\/srv\/www<\/span><span style=\"font-weight: 400;\"> pointing to <\/span><span style=\"font-weight: 400;\">\/var\/www\/html<\/span><span style=\"font-weight: 400;\">. The command is useful for maintaining flexible directory structures and redirecting applications to alternate locations. A hard link is created with <\/span><span style=\"font-weight: 400;\">ln<\/span><span style=\"font-weight: 400;\"> without the <\/span><span style=\"font-weight: 400;\">-s<\/span><span style=\"font-weight: 400;\"> option. Understanding the distinction between symbolic and hard links is important when configuring web content, application directories, and system administration tasks.<\/span><\/p>\n<p><b>Question 134. Which Apache directive can restrict access to a directory by requiring authenticated users to belong to a specified authorization group?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Listen<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerTokens<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> LogLevel<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Require<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In Apache 2.4, the <\/span><span style=\"font-weight: 400;\">Require<\/span><span style=\"font-weight: 400;\"> directive controls authorization and can be used to restrict access based on authenticated users, groups, IP addresses, or other authorization providers. For example, <\/span><span style=\"font-weight: 400;\">Require group admins<\/span><span style=\"font-weight: 400;\"> can restrict access to members of a configured authentication group. Authentication establishes who the user is, while authorization determines whether that authenticated user is allowed to access a resource. Directives such as Listen and LogLevel serve different purposes, controlling network sockets and logging verbosity respectively. Proper use of Require is therefore central to configuring protected directories and administrative areas in Apache.<\/span><\/p>\n<p><b>Question 135. Which command displays the routing table using the modern iproute2 utilities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> route -show<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> netstat -dns<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. ip route<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ip route<\/span><span style=\"font-weight: 400;\"> command displays the kernel&#8217;s current routing table using the modern iproute2 networking tools. It can also be used to add, modify, and delete routes. For example, <\/span><span style=\"font-weight: 400;\">ip route<\/span><span style=\"font-weight: 400;\"> may show a default route through a gateway as well as routes for directly connected networks. The older <\/span><span style=\"font-weight: 400;\">route<\/span><span style=\"font-weight: 400;\"> utility can also display routing information on many systems, but <\/span><span style=\"font-weight: 400;\">ip route<\/span><span style=\"font-weight: 400;\"> is the standard modern approach. Exam questions commonly distinguish routing information from DNS configuration and interface information, so administrators should understand how <\/span><span style=\"font-weight: 400;\">ip route<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">ip addr<\/span><span style=\"font-weight: 400;\">, and resolver tools serve different purposes.<\/span><\/p>\n<p><b>Question 136. Which Dovecot command-line utility is primarily used for mailbox administration and maintenance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> doveconf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dovecotctl<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> doveadm<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> imapctl<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. doveadm<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">doveadm<\/span><span style=\"font-weight: 400;\"> utility provides administrative commands for managing Dovecot mailboxes and related data. Administrators can use it for tasks such as searching mailboxes, moving messages, managing indexes, and performing other mailbox maintenance operations. <\/span><span style=\"font-weight: 400;\">doveconf<\/span><span style=\"font-weight: 400;\"> is primarily used to query and inspect Dovecot configuration. Dovecot itself provides the IMAP and POP3 services, while <\/span><span style=\"font-weight: 400;\">doveadm<\/span><span style=\"font-weight: 400;\"> serves as an administration interface. Understanding these tools is important for LPIC-2 because Dovecot configuration and mailbox management are part of the E-Mail Services objectives.<\/span><\/p>\n<p><b>Question 137. Which PAM configuration module is commonly used to enforce password complexity and quality requirements on Linux systems?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_pwquality<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_nologin<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_limits<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_motd<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. pam_pwquality<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">pam_pwquality<\/span><span style=\"font-weight: 400;\"> module is commonly used to enforce password quality requirements through PAM. It can apply rules involving password length, character classes, and other password-strength requirements, depending on the system configuration. <\/span><span style=\"font-weight: 400;\">pam_nologin<\/span><span style=\"font-weight: 400;\"> can prevent non-root users from logging in when a designated nologin condition exists, while <\/span><span style=\"font-weight: 400;\">pam_limits<\/span><span style=\"font-weight: 400;\"> applies resource limits and <\/span><span style=\"font-weight: 400;\">pam_motd<\/span><span style=\"font-weight: 400;\"> is associated with displaying login messages. PAM modules are chained through configuration files, allowing administrators to build authentication and account policies from multiple components.<\/span><\/p>\n<p><b>Question 138. Which nftables command displays the currently loaded ruleset?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft show all<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft ruleset list<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft -L<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft list ruleset<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. nft list ruleset<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The command <\/span><span style=\"font-weight: 400;\">nft list ruleset<\/span><span style=\"font-weight: 400;\"> displays the currently loaded nftables ruleset, including tables, chains, and rules. It is a fundamental troubleshooting command because it allows an administrator to inspect the active firewall configuration rather than relying solely on configuration files. nftables organizes filtering rules into tables and chains, with rules evaluated according to the configured hooks and priorities. The command can be run to verify whether expected filtering, NAT, or forwarding rules are actually loaded. This is especially useful after firewall changes or during troubleshooting of unexpected network connectivity.<\/span><\/p>\n<p><b>Question 139. Which DNS record type is specifically used to map a hostname to an IPv6 address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AAAA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SRV<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. AAAA<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AAAA record maps a hostname to an IPv6 address. It is the IPv6 counterpart of the A record, which maps a hostname to an IPv4 address. PTR records are used for reverse DNS lookups, while SRV records identify services and their associated hosts and ports. For example, a DNS zone may contain an AAAA record mapping <\/span><span style=\"font-weight: 400;\">server.example.com<\/span><span style=\"font-weight: 400;\"> to an IPv6 address. Understanding the differences among common DNS record types is essential when configuring forward and reverse zones and troubleshooting name resolution in dual-stack IPv4 and IPv6 environments.<\/span><\/p>\n<p><b>Question 140. Which command can be used to verify the syntax of a BIND zone file before reloading the DNS server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> named-checkconf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rndc reload<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dig zonecheck<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> named-checkzone<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. named-checkconf<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">named-checkconf<\/span><span style=\"font-weight: 400;\"> utility checks the syntax of the main BIND configuration, such as <\/span><span style=\"font-weight: 400;\">\/etc\/named.conf<\/span><span style=\"font-weight: 400;\">, rather than validating the contents of an individual zone file. For an actual zone file, <\/span><span style=\"font-weight: 400;\">named-checkzone<\/span><span style=\"font-weight: 400;\"> is the more specific validation utility. The distinction is important when troubleshooting BIND configuration. An administrator can use <\/span><span style=\"font-weight: 400;\">named-checkconf<\/span><span style=\"font-weight: 400;\"> to detect configuration syntax errors and <\/span><span style=\"font-weight: 400;\">named-checkzone<\/span><span style=\"font-weight: 400;\"> to validate resource records and zone-file structure. After successful validation, <\/span><span style=\"font-weight: 400;\">rndc reload<\/span><span style=\"font-weight: 400;\"> can be used to instruct a running BIND server to reload its configuration and zones.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full LPI 202-450\u00a0 Exam Dumps and Practice Test Dumps &nbsp; Question 121. Which BIND configuration statement specifies the default time-to-live for negative DNS responses in a zone&#8217;s SOA record? refresh minimum retry expire Correct Answer: 2. minimum Explanation :- In a DNS SOA record, the minimum field traditionally specifies the negative caching TTL, which [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23052"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23052"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23052\/revisions"}],"predecessor-version":[{"id":23053,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23052\/revisions\/23053"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}