{"id":23060,"date":"2026-09-26T11:27:51","date_gmt":"2026-09-26T11:27:51","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23060"},"modified":"2026-09-26T11:27:51","modified_gmt":"2026-09-26T11:27:51","slug":"lpi-202-450-practice-test-questions-and-exam-dumps-part-11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/lpi-202-450-practice-test-questions-and-exam-dumps-part-11-q201-220\/","title":{"rendered":"LPI 202-450 Practice Test Questions and Exam Dumps Part 11 Q201-220"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/202-450-exam-dumps\"><b>LPI 202-450\u00a0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 201. Which BIND record controls the authoritative information and timing parameters for a DNS zone?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MX<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SOA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CNAME<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. SOA<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The SOA, or Start of Authority, record contains administrative information for a DNS zone. It identifies the primary authoritative name server and includes the responsible party, serial number, refresh interval, retry interval, expire interval, and negative caching TTL. Secondary servers use the serial number to determine whether their copy of the zone needs to be updated. NS records identify authoritative name servers, MX records identify mail servers, and CNAME records provide aliases. A correctly maintained SOA record is therefore fundamental to zone management, secondary synchronization, and DNS administration.<\/span><\/p>\n<p><b>Question 202. Which Apache directive can define additional hostnames that should be handled by the same virtual host?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerAlias<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DocumentRoot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ErrorDocument<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DirectoryIndex<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. ServerAlias<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">ServerAlias<\/span><span style=\"font-weight: 400;\"> directive specifies additional hostnames that should match an existing virtual host. For example, a virtual host with <\/span><span style=\"font-weight: 400;\">ServerName www.example.com<\/span><span style=\"font-weight: 400;\"> can use <\/span><span style=\"font-weight: 400;\">ServerAlias example.com<\/span><span style=\"font-weight: 400;\"> so requests for both names are handled by the same configuration. <\/span><span style=\"font-weight: 400;\">DocumentRoot<\/span><span style=\"font-weight: 400;\"> specifies the directory containing web content, <\/span><span style=\"font-weight: 400;\">DirectoryIndex<\/span><span style=\"font-weight: 400;\"> identifies default files for directory requests, and <\/span><span style=\"font-weight: 400;\">ErrorDocument<\/span><span style=\"font-weight: 400;\"> controls custom responses for HTTP errors. ServerAlias is particularly useful when a website must respond to several related domain names without maintaining separate virtual-host configurations.<\/span><\/p>\n<p><b>Question 203. Which NFS mount option makes a client mount a filesystem as read-only?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> sync<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> hard<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> noexec<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ro<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. ro<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The NFS <\/span><span style=\"font-weight: 400;\">ro<\/span><span style=\"font-weight: 400;\"> mount option mounts the exported filesystem as read-only from the client perspective. This prevents normal write operations through that mount and can be useful when clients only need to consume shared data. The <\/span><span style=\"font-weight: 400;\">hard<\/span><span style=\"font-weight: 400;\"> option controls retry behavior when the NFS server becomes unavailable, <\/span><span style=\"font-weight: 400;\">noexec<\/span><span style=\"font-weight: 400;\"> prevents execution of binaries from the mounted filesystem, and <\/span><span style=\"font-weight: 400;\">sync<\/span><span style=\"font-weight: 400;\"> concerns synchronization behavior. Read-only access should also be considered alongside server-side export permissions because both client and server configuration can influence the effective access available to users.<\/span><\/p>\n<p><b>Question 204. Which Samba configuration parameter specifies the filesystem directory associated with a share?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> path<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> valid users<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> browseable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> guest ok<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. path<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Samba <\/span><span style=\"font-weight: 400;\">path<\/span><span style=\"font-weight: 400;\"> parameter specifies the local filesystem directory that is exported through an SMB share. For example, <\/span><span style=\"font-weight: 400;\">path = \/srv\/shared<\/span><span style=\"font-weight: 400;\"> associates the Samba share with that directory. <\/span><span style=\"font-weight: 400;\">valid users<\/span><span style=\"font-weight: 400;\"> controls which users may access the share, <\/span><span style=\"font-weight: 400;\">browseable<\/span><span style=\"font-weight: 400;\"> determines whether it appears in browse lists, and <\/span><span style=\"font-weight: 400;\">guest ok<\/span><span style=\"font-weight: 400;\"> controls whether guest access is permitted. Samba access therefore involves both the share configuration and underlying Linux filesystem permissions. A correctly configured path is essential because Samba must be able to access the directory and its contents using the permissions of the relevant service or user context.<\/span><\/p>\n<p><b>Question 205. Which DNS record type creates an alias that points one DNS name to another canonical name?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MX<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TXT<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CNAME<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. CNAME<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CNAME record creates an alias from one DNS name to another canonical name. For example, <\/span><span style=\"font-weight: 400;\">www.example.com<\/span><span style=\"font-weight: 400;\"> can be configured as a CNAME pointing to <\/span><span style=\"font-weight: 400;\">web01.example.com<\/span><span style=\"font-weight: 400;\">. When resolving the alias, the DNS client can then continue resolving the canonical target. PTR records are used for reverse DNS, MX records identify mail servers, and TXT records contain textual information. CNAME records are useful for service aliases and hostname abstraction, although they have specific DNS restrictions and generally should not be used at the zone apex where other required records coexist.<\/span><\/p>\n<p><b>Question 206. Which DHCP message confirms that a server has accepted a client&#8217;s requested lease?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPDISCOVER<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPREQUEST<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPACK<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCPOFFER<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. DHCPACK<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCPACK is the message a DHCP server normally sends to confirm that a client&#8217;s requested configuration and lease have been accepted. The typical allocation sequence begins with DHCPDISCOVER, followed by DHCPOFFER, DHCPREQUEST, and DHCPACK. DHCPNAK can be sent when the requested configuration is invalid or cannot be provided. Understanding these messages helps administrators diagnose DHCP failures. If a client receives an offer but does not receive an appropriate acknowledgment, troubleshooting should include DHCP server configuration, network connectivity, relay behavior, firewall rules, and address-pool availability.<\/span><\/p>\n<p><b>Question 207. Which Postfix parameter identifies the domains for which the server is an authorized final destination?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> mydestination<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> relayhost<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mynetworks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> myorigin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. mydestination<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Postfix <\/span><span style=\"font-weight: 400;\">mydestination<\/span><span style=\"font-weight: 400;\"> parameter identifies domains and hostnames for which the mail server considers itself the final destination. Messages addressed to these destinations can be delivered locally rather than relayed to another server. <\/span><span style=\"font-weight: 400;\">relayhost<\/span><span style=\"font-weight: 400;\"> specifies an upstream relay, <\/span><span style=\"font-weight: 400;\">mynetworks<\/span><span style=\"font-weight: 400;\"> identifies trusted networks, and <\/span><span style=\"font-weight: 400;\">myorigin<\/span><span style=\"font-weight: 400;\"> determines the domain used for locally generated mail. Incorrect <\/span><span style=\"font-weight: 400;\">mydestination<\/span><span style=\"font-weight: 400;\"> settings can cause local mail to be rejected, routed incorrectly, or treated as mail requiring relay. Administrators should therefore configure it consistently with the system hostname and domains hosted by the server.<\/span><\/p>\n<p><b>Question 208. Which Dovecot setting controls which mail protocols are enabled, such as IMAP and POP3?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> mail_location<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> protocols<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> passdb<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> userdb<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. protocols<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Dovecot <\/span><span style=\"font-weight: 400;\">protocols<\/span><span style=\"font-weight: 400;\"> setting determines which supported mail protocols are enabled, such as IMAP and POP3. For example, a configuration can enable IMAP while disabling POP3 when only IMAP access is required. <\/span><span style=\"font-weight: 400;\">mail_location<\/span><span style=\"font-weight: 400;\"> specifies mailbox storage, <\/span><span style=\"font-weight: 400;\">passdb<\/span><span style=\"font-weight: 400;\"> provides authentication information, and <\/span><span style=\"font-weight: 400;\">userdb<\/span><span style=\"font-weight: 400;\"> supplies user-related mailbox information. Protocol configuration should also be considered together with listener and TLS settings because enabling a protocol does not by itself guarantee that clients can connect successfully. Proper protocol selection reduces unnecessary service exposure.<\/span><\/p>\n<p><b>Question 209. Which SSH command generates a new public\/private key pair?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-add<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-agent<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-keygen<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ssh-copy-id<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. ssh-keygen<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ssh-keygen<\/span><span style=\"font-weight: 400;\"> utility generates and manages SSH public\/private key pairs. It can create keys using algorithms such as Ed25519 or RSA, depending on the OpenSSH version and selected options. <\/span><span style=\"font-weight: 400;\">ssh-agent<\/span><span style=\"font-weight: 400;\"> manages private keys in an authentication agent, <\/span><span style=\"font-weight: 400;\">ssh-add<\/span><span style=\"font-weight: 400;\"> loads a private key into that agent, and <\/span><span style=\"font-weight: 400;\">ssh-copy-id<\/span><span style=\"font-weight: 400;\"> installs a public key into a remote user&#8217;s authorized keys file. Public-key authentication is commonly preferred for secure administrative access because it avoids transmitting passwords during authentication and can support strong, manageable credentials.<\/span><\/p>\n<p><b>Question 210. Which SELinux command reports whether the system is currently enforcing or permissive?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> restorecon<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> semanage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> audit2allow<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> getenforce<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. getenforce<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">getenforce<\/span><span style=\"font-weight: 400;\"> command reports the current SELinux enforcement mode, normally returning <\/span><span style=\"font-weight: 400;\">Enforcing<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">Permissive<\/span><span style=\"font-weight: 400;\">, or <\/span><span style=\"font-weight: 400;\">Disabled<\/span><span style=\"font-weight: 400;\"> depending on the system state. <\/span><span style=\"font-weight: 400;\">restorecon<\/span><span style=\"font-weight: 400;\"> restores SELinux file contexts, <\/span><span style=\"font-weight: 400;\">semanage<\/span><span style=\"font-weight: 400;\"> manages persistent policy-related settings, and <\/span><span style=\"font-weight: 400;\">audit2allow<\/span><span style=\"font-weight: 400;\"> can generate policy rules from audit information. Checking the enforcement mode is often an early troubleshooting step when an application unexpectedly receives access denials. However, the mode alone does not explain why access is denied; administrators should also examine SELinux contexts, policy rules, and audit logs.<\/span><\/p>\n<p><b>Question 211. Which nftables command adds a rule to accept TCP traffic destined for port 443 in an existing input chain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft allow tcp 443<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft add rule inet filter input tcp dport 443 accept<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft insert tcp 443 input<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft permit inet 443<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. nft add rule inet filter input tcp dport 443 accept<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The nftables command <\/span><span style=\"font-weight: 400;\">nft add rule inet filter input tcp dport 443 accept<\/span><span style=\"font-weight: 400;\"> adds an accept rule to the <\/span><span style=\"font-weight: 400;\">input<\/span><span style=\"font-weight: 400;\"> chain of the <\/span><span style=\"font-weight: 400;\">filter<\/span><span style=\"font-weight: 400;\"> table in the <\/span><span style=\"font-weight: 400;\">inet<\/span><span style=\"font-weight: 400;\"> family. It matches TCP packets whose destination port is 443 and accepts them. The relevant table and chain must already exist unless the command is part of a larger configuration sequence that creates them first. Understanding nftables syntax requires identifying the family, table, chain, protocol, matching criteria, and verdict. This structure provides flexible control over firewall behavior.<\/span><\/p>\n<p><b>Question 212. Which DNS query type asks a resolver for the IPv4 address associated with a hostname?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AAAA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MX<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An A query requests the IPv4 address associated with a DNS hostname. For example, querying an A record for <\/span><span style=\"font-weight: 400;\">www.example.com<\/span><span style=\"font-weight: 400;\"> may return an IPv4 address such as <\/span><span style=\"font-weight: 400;\">192.0.2.10<\/span><span style=\"font-weight: 400;\">. AAAA records provide IPv6 addresses, PTR records perform reverse mapping from addresses to hostnames, and MX records identify mail servers. When troubleshooting DNS, administrators can explicitly specify the record type with tools such as <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\">. Comparing A and AAAA responses can also help diagnose differences in IPv4 and IPv6 connectivity.<\/span><\/p>\n<p><b>Question 213. Which Apache module is commonly used to rewrite requested URLs according to configurable rules?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_status<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_proxy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_rewrite<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_autoindex<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. mod_rewrite<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Apache&#8217;s <\/span><span style=\"font-weight: 400;\">mod_rewrite<\/span><span style=\"font-weight: 400;\"> module provides rule-based URL rewriting and redirection. It can modify requested URLs, implement redirects, route requests to different resources, and support various application URL structures. <\/span><span style=\"font-weight: 400;\">mod_proxy<\/span><span style=\"font-weight: 400;\"> provides proxy functionality, <\/span><span style=\"font-weight: 400;\">mod_status<\/span><span style=\"font-weight: 400;\"> exposes server-status information, and <\/span><span style=\"font-weight: 400;\">mod_autoindex<\/span><span style=\"font-weight: 400;\"> can generate directory listings. Because rewrite rules can affect many requests, administrators should test them carefully and inspect Apache logs when unexpected redirects or 404 errors occur. Understanding rewrite conditions and substitutions is particularly important for modern websites using clean or application-generated URLs.<\/span><\/p>\n<p><b>Question 214. Which NFS service is responsible for registering RPC-based services and helping clients determine their ports on systems using traditional NFS configurations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> rpcbind<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> sshd<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> named<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbd<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. rpcbind<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">rpcbind<\/span><span style=\"font-weight: 400;\"> service maps RPC program numbers to network addresses and ports. Traditional NFS configurations rely on RPC-based services, and clients can query rpcbind to determine where required services are listening. NFSv4 simplifies this architecture by using TCP port 2049 for its primary protocol, although other services may still exist depending on the environment. <\/span><span style=\"font-weight: 400;\">sshd<\/span><span style=\"font-weight: 400;\"> provides SSH access, <\/span><span style=\"font-weight: 400;\">named<\/span><span style=\"font-weight: 400;\"> provides DNS, and <\/span><span style=\"font-weight: 400;\">smbd<\/span><span style=\"font-weight: 400;\"> provides Samba file-sharing services. Understanding rpcbind is particularly important when troubleshooting older NFS deployments and firewall rules involving dynamic RPC services.<\/span><\/p>\n<p><b>Question 215. Which Postfix utility can remove or otherwise perform administrative operations on messages in the mail queue?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> postconf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> postmap<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> postqueue<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> postsuper<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. postsuper<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">postsuper<\/span><span style=\"font-weight: 400;\"> utility performs administrative operations on the Postfix mail queue, including operations such as deleting queued messages under appropriate administrative control. <\/span><span style=\"font-weight: 400;\">postqueue<\/span><span style=\"font-weight: 400;\"> is commonly used to inspect or trigger queue processing, <\/span><span style=\"font-weight: 400;\">postconf<\/span><span style=\"font-weight: 400;\"> manages configuration parameters, and <\/span><span style=\"font-weight: 400;\">postmap<\/span><span style=\"font-weight: 400;\"> creates lookup databases. Queue administration should be performed carefully because deleting messages can permanently remove mail that has not yet been delivered. Administrators should normally inspect queue identifiers and delivery status before taking corrective action.<\/span><\/p>\n<p><b>Question 216. Which Dovecot database provides information about a user&#8217;s mailbox location and other user-specific settings?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> passdb<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> userdb<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> auth_mechanisms<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> protocols<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. userdb<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dovecot&#8217;s <\/span><span style=\"font-weight: 400;\">userdb<\/span><span style=\"font-weight: 400;\"> provides user-specific information needed after authentication, such as mailbox location, UID, GID, home directory, or other account-related values depending on the configuration. <\/span><span style=\"font-weight: 400;\">passdb<\/span><span style=\"font-weight: 400;\"> is responsible for authentication credentials, while <\/span><span style=\"font-weight: 400;\">auth_mechanisms<\/span><span style=\"font-weight: 400;\"> defines supported authentication methods and <\/span><span style=\"font-weight: 400;\">protocols<\/span><span style=\"font-weight: 400;\"> controls enabled mail protocols. Keeping authentication and user information conceptually separate allows Dovecot to use different backend systems for passwords and mailbox data. Incorrect userdb configuration can result in successful authentication followed by mailbox-access or permission problems.<\/span><\/p>\n<p><b>Question 217. Which SSH configuration option controls whether public-key authentication is enabled?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PubkeyAuthentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PermitRootLogin<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AllowGroups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> X11Forwarding<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. PubkeyAuthentication<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The OpenSSH <\/span><span style=\"font-weight: 400;\">PubkeyAuthentication<\/span><span style=\"font-weight: 400;\"> option controls whether public-key authentication is permitted. When enabled, SSH can authenticate users using authorized public keys rather than relying solely on passwords. <\/span><span style=\"font-weight: 400;\">PermitRootLogin<\/span><span style=\"font-weight: 400;\"> controls direct root access, <\/span><span style=\"font-weight: 400;\">AllowGroups<\/span><span style=\"font-weight: 400;\"> restricts which groups may log in, and <\/span><span style=\"font-weight: 400;\">X11Forwarding<\/span><span style=\"font-weight: 400;\"> controls X11 forwarding. Public-key authentication typically involves a private key retained securely by the client and a corresponding public key stored in the user&#8217;s authorized keys configuration on the server. Proper file permissions and ownership are important for successful key-based authentication.<\/span><\/p>\n<p><b>Question 218. Which command searches the Linux audit log for events associated with a particular SELinux denial?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> restorecon<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ausearch<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> semanage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> getsebool<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. ausearch<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ausearch<\/span><span style=\"font-weight: 400;\"> utility searches Linux audit logs for events that match specified criteria. It is frequently used when investigating SELinux denials because SELinux access-control decisions can generate audit records. Administrators can use appropriate search filters to identify recent denial events and then inspect the associated information to determine which process, file, class, or permission was involved. <\/span><span style=\"font-weight: 400;\">restorecon<\/span><span style=\"font-weight: 400;\"> manages file contexts, <\/span><span style=\"font-weight: 400;\">semanage<\/span><span style=\"font-weight: 400;\"> manages persistent SELinux configuration, and <\/span><span style=\"font-weight: 400;\">getsebool<\/span><span style=\"font-weight: 400;\"> displays Boolean settings. Audit information should be interpreted carefully before changing policy.<\/span><\/p>\n<p><b>Question 219. Which DNS tool can perform a reverse lookup when given an IP address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> named-checkconf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rndc<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> host<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> exportfs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. host<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">host<\/span><span style=\"font-weight: 400;\"> utility can perform both forward and reverse DNS lookups. When given an IP address, it can query the corresponding reverse DNS information, normally using a PTR record. This is useful for checking whether an address has an associated hostname. <\/span><span style=\"font-weight: 400;\">named-checkconf<\/span><span style=\"font-weight: 400;\"> validates BIND configuration syntax, <\/span><span style=\"font-weight: 400;\">rndc<\/span><span style=\"font-weight: 400;\"> controls a running BIND server, and <\/span><span style=\"font-weight: 400;\">exportfs<\/span><span style=\"font-weight: 400;\"> manages NFS exports. Reverse DNS results depend on the appropriate reverse zone and PTR record being configured and delegated correctly, so a missing result does not necessarily indicate a problem with forward DNS.<\/span><\/p>\n<p><b>Question 220. Which command displays the current IPv4 and IPv6 neighbor cache maintained by the Linux kernel?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip neigh<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip addr<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ss -n<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. ip neigh<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ip neigh<\/span><span style=\"font-weight: 400;\"> command displays the Linux kernel&#8217;s neighbor table, which contains information about neighboring devices and their link-layer address mappings. For IPv4, this commonly corresponds to ARP information, while IPv6 uses Neighbor Discovery. The table can help administrators diagnose local-network connectivity problems, stale address mappings, or incomplete neighbor resolution. <\/span><span style=\"font-weight: 400;\">ip addr<\/span><span style=\"font-weight: 400;\"> displays interface addresses, <\/span><span style=\"font-weight: 400;\">ip route<\/span><span style=\"font-weight: 400;\"> displays routing information, and <\/span><span style=\"font-weight: 400;\">ss<\/span><span style=\"font-weight: 400;\"> displays socket information. Examining the neighbor table is particularly useful when a host has an IP configuration but cannot communicate correctly with devices on its local network.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full LPI 202-450\u00a0 Exam Dumps and Practice Test Dumps &nbsp; Question 201. Which BIND record controls the authoritative information and timing parameters for a DNS zone? NS MX SOA CNAME Correct Answer: 3. SOA Explanation :- The SOA, or Start of Authority, record contains administrative information for a DNS zone. It identifies the primary [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23060"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23060"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23060\/revisions"}],"predecessor-version":[{"id":23061,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23060\/revisions\/23061"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}