{"id":23062,"date":"2026-09-26T11:28:13","date_gmt":"2026-09-26T11:28:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23062"},"modified":"2026-09-26T11:28:13","modified_gmt":"2026-09-26T11:28:13","slug":"lpi-202-450-practice-test-questions-and-exam-dumps-part-12-q221-240","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/lpi-202-450-practice-test-questions-and-exam-dumps-part-12-q221-240\/","title":{"rendered":"LPI 202-450 Practice Test Questions and Exam Dumps Part 12 Q221-240"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/202-450-exam-dumps\"><b>LPI 202-450\u00a0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 221. Which BIND directive specifies the default time-to-live value for negative DNS responses?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> refresh<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> expire<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> minimum<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> retry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. minimum<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">minimum<\/span><span style=\"font-weight: 400;\"> field in the SOA record historically defines the negative caching TTL, meaning how long resolvers may cache negative responses such as NXDOMAIN. Modern DNS implementations follow the RFC 2308 interpretation of this field for negative caching. The other SOA fields have different purposes: refresh controls secondary-server refresh timing, retry determines how soon a secondary retries a failed refresh, and expire determines how long a secondary may continue serving a zone without successful refreshes. Understanding SOA fields is important when diagnosing DNS caching and propagation behavior.<\/span><\/p>\n<p><b>Question 222. In Apache HTTP Server, which directive can be used to define the default file served when a client requests a directory?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DirectoryIndex<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DirectoryRoot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DefaultFile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IndexFile<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. DirectoryIndex<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">DirectoryIndex<\/span><span style=\"font-weight: 400;\"> directive specifies the resources Apache should look for when a client requests a directory without naming a specific file. For example, <\/span><span style=\"font-weight: 400;\">DirectoryIndex index.html index.php<\/span><span style=\"font-weight: 400;\"> causes Apache to check those files in the specified order. This directive is commonly configured in the main Apache configuration, virtual host configuration, or permitted <\/span><span style=\"font-weight: 400;\">.htaccess<\/span><span style=\"font-weight: 400;\"> files. <\/span><span style=\"font-weight: 400;\">DirectoryRoot<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">DefaultFile<\/span><span style=\"font-weight: 400;\">, and <\/span><span style=\"font-weight: 400;\">IndexFile<\/span><span style=\"font-weight: 400;\"> are not standard Apache directives for this purpose. If none of the configured index files exists, Apache may generate a directory listing when indexing is enabled, or return an error when it is disabled.<\/span><\/p>\n<p><b>Question 223. Which command displays the NFS exports currently available from a specified server?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> showmount -e<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> exportfs -s<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nfsstat -e<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mount.nfs -l<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. showmount -e<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">showmount -e<\/span><span style=\"font-weight: 400;\"> command queries an NFS server and displays its exported file systems. For example, <\/span><span style=\"font-weight: 400;\">showmount -e nfs.example.com<\/span><span style=\"font-weight: 400;\"> can show which directories the server advertises as available for mounting. This is useful when troubleshooting NFS access or verifying that an export is being published. <\/span><span style=\"font-weight: 400;\">exportfs<\/span><span style=\"font-weight: 400;\"> is primarily used on the NFS server to manage its exports, while <\/span><span style=\"font-weight: 400;\">nfsstat<\/span><span style=\"font-weight: 400;\"> reports NFS statistics. <\/span><span style=\"font-weight: 400;\">mount.nfs<\/span><span style=\"font-weight: 400;\"> is used to mount an NFS file system rather than list server exports.<\/span><\/p>\n<p><b>Question 224. Which Samba parameter controls whether a share is visible in network browse lists?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> visible_share<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> browseable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> discoverable<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> show_share<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. browseable<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Samba <\/span><span style=\"font-weight: 400;\">browseable<\/span><span style=\"font-weight: 400;\"> parameter determines whether a share is displayed in network browse lists. Setting <\/span><span style=\"font-weight: 400;\">browseable = yes<\/span><span style=\"font-weight: 400;\"> makes the share visible through browsing mechanisms, while <\/span><span style=\"font-weight: 400;\">browseable = no<\/span><span style=\"font-weight: 400;\"> hides it from the browse list without necessarily preventing clients that know the share name from accessing it. This is different from access-control parameters such as <\/span><span style=\"font-weight: 400;\">valid users<\/span><span style=\"font-weight: 400;\">, which determine who may connect. Administrators commonly use <\/span><span style=\"font-weight: 400;\">testparm<\/span><span style=\"font-weight: 400;\"> after modifying <\/span><span style=\"font-weight: 400;\">\/etc\/samba\/smb.conf<\/span><span style=\"font-weight: 400;\"> to validate the configuration before restarting or reloading Samba services.<\/span><\/p>\n<p><b>Question 225. Which DNS record identifies the mail server responsible for accepting email for a domain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> TXT<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MX<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. MX<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An MX, or Mail Exchange, record identifies the mail servers responsible for receiving email for a DNS domain. The record contains a preference value and a hostname. For example, an MX record may direct mail for <\/span><span style=\"font-weight: 400;\">example.com<\/span><span style=\"font-weight: 400;\"> to <\/span><span style=\"font-weight: 400;\">mail.example.com<\/span><span style=\"font-weight: 400;\">. Lower preference values have higher priority when multiple MX records exist. An NS record identifies authoritative name servers, a PTR record provides reverse DNS mapping, and a TXT record stores arbitrary text information such as SPF-related data. DNS administrators can inspect MX records using tools such as <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\"> or <\/span><span style=\"font-weight: 400;\">host<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><b>Question 226. Which DHCP option specifies the default gateway that a client should use?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 6<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 15<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 3<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 12<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Option 3<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP option 3 specifies the router or default gateway information that a DHCP server supplies to clients. When a client receives this option, it can install the specified gateway as its default route. Option 6 identifies DNS servers, option 15 specifies the DNS domain name, and option 12 supplies the client hostname. Correct DHCP options are essential for proper network connectivity because a client may have an IP address while still being unable to reach remote networks if it lacks a valid default gateway.<\/span><\/p>\n<p><b>Question 227. Which Postfix command displays the contents of the mail queue in a traditional queue-list format?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> postqueue -p<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> postfix -q<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> postconf -q<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mailq &#8211;flush<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. postqueue -p<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">postqueue -p<\/span><span style=\"font-weight: 400;\"> command displays the Postfix mail queue. It provides information about queued messages, including queue IDs, sender and recipient information, message size, and the reason a message may remain undelivered. Administrators use this command when troubleshooting delayed or stuck email delivery. <\/span><span style=\"font-weight: 400;\">postfix<\/span><span style=\"font-weight: 400;\"> manages the Postfix service, while <\/span><span style=\"font-weight: 400;\">postconf<\/span><span style=\"font-weight: 400;\"> is primarily used to inspect or modify configuration parameters. The <\/span><span style=\"font-weight: 400;\">postqueue -f<\/span><span style=\"font-weight: 400;\"> option is used to request immediate queue processing, making the distinction between viewing and flushing the queue important during mail-service troubleshooting.<\/span><\/p>\n<p><b>Question 228. Which Dovecot command can be used to display the effective configuration after configuration files have been processed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> doveconf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dovecot-config<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> doveadm-config<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dovecot &#8211;show<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. doveconf<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">doveconf<\/span><span style=\"font-weight: 400;\"> utility displays Dovecot&#8217;s effective configuration. It is particularly useful when troubleshooting because Dovecot may combine settings from multiple configuration files and included fragments. Running <\/span><span style=\"font-weight: 400;\">doveconf<\/span><span style=\"font-weight: 400;\"> allows an administrator to see the resulting configuration rather than inspecting individual files separately. This helps identify incorrect settings, overrides, or unexpected defaults. <\/span><span style=\"font-weight: 400;\">doveadm<\/span><span style=\"font-weight: 400;\"> is primarily an administrative command interface for Dovecot services and mailboxes. Reviewing the effective configuration is especially useful when diagnosing authentication, mailbox, listener, or protocol-related problems.<\/span><\/p>\n<p><b>Question 229. Which SSH configuration directive controls whether password authentication is permitted?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> UsePAM<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PasswordAuthentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AllowPasswords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> LoginPassword<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. PasswordAuthentication<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The OpenSSH <\/span><span style=\"font-weight: 400;\">PasswordAuthentication<\/span><span style=\"font-weight: 400;\"> directive controls whether password-based authentication is permitted by the SSH server. In <\/span><span style=\"font-weight: 400;\">sshd_config<\/span><span style=\"font-weight: 400;\">, setting <\/span><span style=\"font-weight: 400;\">PasswordAuthentication no<\/span><span style=\"font-weight: 400;\"> disables this authentication method, while <\/span><span style=\"font-weight: 400;\">yes<\/span><span style=\"font-weight: 400;\"> permits it, subject to other authentication controls. This setting is commonly adjusted when administrators want to require public-key authentication instead of passwords. <\/span><span style=\"font-weight: 400;\">UsePAM<\/span><span style=\"font-weight: 400;\"> controls whether PAM is used by the SSH server, but it is not itself the directive that directly enables or disables password authentication. After changing the SSH server configuration, administrators should validate the configuration and reload or restart the service appropriately.<\/span><\/p>\n<p><b>Question 230. Which command displays the current SELinux enforcement mode?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> selinux-status<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> getenforce<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> sestatus-mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> enforce-status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. getenforce<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">getenforce<\/span><span style=\"font-weight: 400;\"> command displays the current SELinux mode, typically as <\/span><span style=\"font-weight: 400;\">Enforcing<\/span><span style=\"font-weight: 400;\">, <\/span><span style=\"font-weight: 400;\">Permissive<\/span><span style=\"font-weight: 400;\">, or <\/span><span style=\"font-weight: 400;\">Disabled<\/span><span style=\"font-weight: 400;\">. Enforcing mode actively applies SELinux policy, while permissive mode logs policy violations without blocking the associated operations. The <\/span><span style=\"font-weight: 400;\">setenforce<\/span><span style=\"font-weight: 400;\"> command changes between enforcing and permissive modes temporarily. <\/span><span style=\"font-weight: 400;\">sestatus<\/span><span style=\"font-weight: 400;\"> provides more comprehensive SELinux status information, including policy details and configuration. Knowing the difference between these commands is useful when troubleshooting access-denied events because SELinux restrictions can prevent an operation even when traditional Unix permissions appear to allow it.<\/span><\/p>\n<p><b>Question 231. Which nftables command lists the rules in the <\/b><b>filter<\/b><b> table of the <\/b><b>inet<\/b><b> family?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft show filter inet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft list inet filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft display table filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nft rules inet filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. nft list inet filter<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The nftables command <\/span><span style=\"font-weight: 400;\">nft list table inet filter<\/span><span style=\"font-weight: 400;\"> displays the complete contents of the <\/span><span style=\"font-weight: 400;\">filter<\/span><span style=\"font-weight: 400;\"> table in the <\/span><span style=\"font-weight: 400;\">inet<\/span><span style=\"font-weight: 400;\"> address family. The <\/span><span style=\"font-weight: 400;\">inet<\/span><span style=\"font-weight: 400;\"> family can contain rules that apply to both IPv4 and IPv6 traffic. Administrators use table and chain listing commands to inspect the active firewall configuration and troubleshoot unexpected packet handling. The general syntax follows the nftables hierarchy of family, table, chain, and rule. Commands such as <\/span><span style=\"font-weight: 400;\">nft list ruleset<\/span><span style=\"font-weight: 400;\"> can instead display the entire active nftables configuration across all families and tables.<\/span><\/p>\n<p><b>Question 232. Which DNS record maps a hostname to an IPv6 address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AAAA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CNAME<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. AAAA<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AAAA record maps a hostname to an IPv6 address. It serves a role similar to an A record, which maps a hostname to an IPv4 address. For example, an AAAA record may associate <\/span><span style=\"font-weight: 400;\">www.example.com<\/span><span style=\"font-weight: 400;\"> with an IPv6 address such as <\/span><span style=\"font-weight: 400;\">2001:db8::10<\/span><span style=\"font-weight: 400;\">. A PTR record is used for reverse DNS mapping, while a CNAME creates an alias pointing to another canonical hostname. Administrators can inspect AAAA records using <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\">, for example with <\/span><span style=\"font-weight: 400;\">dig AAAA www.example.com<\/span><span style=\"font-weight: 400;\">. Correct IPv6 DNS configuration is an important part of modern network-client management.<\/span><\/p>\n<p><b>Question 233. Which Apache directive is commonly used to enable URL rewriting through the mod_rewrite module?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RewriteRule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> URLRewrite<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RedirectRule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RouteRule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. RewriteRule<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">RewriteRule<\/span><span style=\"font-weight: 400;\"> directive defines pattern-based URL rewriting when the <\/span><span style=\"font-weight: 400;\">mod_rewrite<\/span><span style=\"font-weight: 400;\"> module is enabled. It can rewrite requested URLs internally or redirect clients to different URLs depending on the rule configuration and flags. Rewrite rules are widely used for clean URLs, redirects, application routing, and compatibility with legacy paths. The <\/span><span style=\"font-weight: 400;\">RewriteCond<\/span><span style=\"font-weight: 400;\"> directive can provide conditions that determine when a rule should be applied. <\/span><span style=\"font-weight: 400;\">Redirect<\/span><span style=\"font-weight: 400;\"> is another Apache mechanism for redirects, but it does not provide the same pattern-based processing capabilities as <\/span><span style=\"font-weight: 400;\">mod_rewrite<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><b>Question 234. Which NFS option causes a client operation to wait and retry when the server becomes temporarily unavailable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> soft<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> async<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> bg<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> hard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. hard<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The NFS <\/span><span style=\"font-weight: 400;\">hard<\/span><span style=\"font-weight: 400;\"> mount option causes NFS client requests to continue retrying when the server becomes unavailable. This behavior is important for data integrity because applications generally continue waiting rather than immediately receiving an I\/O error. By contrast, a <\/span><span style=\"font-weight: 400;\">soft<\/span><span style=\"font-weight: 400;\"> mount can return errors after retry limits are reached, which may create application-level problems depending on the workload. The <\/span><span style=\"font-weight: 400;\">bg<\/span><span style=\"font-weight: 400;\"> option controls how mounting behaves after an initial failure, while <\/span><span style=\"font-weight: 400;\">async<\/span><span style=\"font-weight: 400;\"> concerns write synchronization behavior. Administrators should understand these options carefully because NFS mount behavior directly affects application availability and data handling.<\/span><\/p>\n<p><b>Question 235. Which Postfix parameter specifies the domains for which this mail server should consider itself the final destination?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> mydestination<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> relay_domains<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mynetworks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> myorigin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. mydestination<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Postfix <\/span><span style=\"font-weight: 400;\">mydestination<\/span><span style=\"font-weight: 400;\"> parameter defines the domains and hostnames for which the server considers itself the final destination. Mail addressed to these destinations can be delivered locally rather than relayed elsewhere. This parameter is therefore important when configuring Postfix as a destination mail server. <\/span><span style=\"font-weight: 400;\">mynetworks<\/span><span style=\"font-weight: 400;\"> defines trusted client networks, <\/span><span style=\"font-weight: 400;\">relay_domains<\/span><span style=\"font-weight: 400;\"> controls domains for which the server provides relay service, and <\/span><span style=\"font-weight: 400;\">myorigin<\/span><span style=\"font-weight: 400;\"> determines the domain used for locally posted mail. Incorrect <\/span><span style=\"font-weight: 400;\">mydestination<\/span><span style=\"font-weight: 400;\"> configuration can cause mail-delivery failures or unintended relay behavior.<\/span><\/p>\n<p><b>Question 236. Which PAM module is commonly used to enforce password quality requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_limits<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_pwquality<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> pam_env<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. pam_pwquality<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">pam_pwquality<\/span><span style=\"font-weight: 400;\"> module is commonly used to enforce password-quality requirements through PAM. It can enforce characteristics such as minimum password length and restrictions on password composition, depending on the configured policy. It is typically integrated into PAM configuration for password-changing operations. <\/span><span style=\"font-weight: 400;\">pam_access<\/span><span style=\"font-weight: 400;\"> controls access based on configured rules, <\/span><span style=\"font-weight: 400;\">pam_limits<\/span><span style=\"font-weight: 400;\"> manages resource limits, and <\/span><span style=\"font-weight: 400;\">pam_env<\/span><span style=\"font-weight: 400;\"> manages environment variables. Because PAM configuration is distribution-dependent and can affect authentication broadly, administrators should carefully validate changes to avoid accidentally preventing legitimate users from authenticating or changing passwords.<\/span><\/p>\n<p><b>Question 237. Which SSH option specifies the private key file to use for public-key authentication?<\/b><\/p>\n<ol>\n<li><b><\/b> <span style=\"font-weight: 400;\">-k<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">-i<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">-p<\/span><\/li>\n<li><b><\/b> <span style=\"font-weight: 400;\">-f<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. <\/b><b>-i<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The SSH client <\/span><span style=\"font-weight: 400;\">-i<\/span><span style=\"font-weight: 400;\"> option specifies the identity, or private-key, file to use when attempting public-key authentication. For example, <\/span><span style=\"font-weight: 400;\">ssh -i ~\/.ssh\/id_ed25519 user@server<\/span><span style=\"font-weight: 400;\"> tells the SSH client to use the specified private key. The <\/span><span style=\"font-weight: 400;\">-p<\/span><span style=\"font-weight: 400;\"> option specifies a non-default SSH port, while <\/span><span style=\"font-weight: 400;\">-f<\/span><span style=\"font-weight: 400;\"> requests that SSH go into the background after authentication and <\/span><span style=\"font-weight: 400;\">-k<\/span><span style=\"font-weight: 400;\"> is associated with GSSAPI credential delegation behavior. Correct key selection is especially useful when a client has multiple identities and the administrator needs to select a particular key for a specific remote server.<\/span><\/p>\n<p><b>Question 238. Which command can be used to search the systemd journal for messages from a particular service?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> systemctl log<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> journalctl -u<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> systemd-msg<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> journal -s<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. journalctl -u<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">journalctl -u<\/span><span style=\"font-weight: 400;\"> option filters systemd journal entries by a specific systemd unit, such as a service. For example, <\/span><span style=\"font-weight: 400;\">journalctl -u sshd<\/span><span style=\"font-weight: 400;\"> can display journal messages associated with the SSH daemon service. This is useful when diagnosing service startup failures, authentication problems, or runtime errors. <\/span><span style=\"font-weight: 400;\">systemctl<\/span><span style=\"font-weight: 400;\"> manages services but does not use <\/span><span style=\"font-weight: 400;\">systemctl log<\/span><span style=\"font-weight: 400;\"> as a standard command for viewing journal entries. Administrators can combine <\/span><span style=\"font-weight: 400;\">journalctl -u<\/span><span style=\"font-weight: 400;\"> with options such as <\/span><span style=\"font-weight: 400;\">-b<\/span><span style=\"font-weight: 400;\"> to restrict results to the current boot, making troubleshooting more focused.<\/span><\/p>\n<p><b>Question 239. Which DNS utility is commonly used to perform detailed DNS queries and inspect specific record types?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> dig<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nslookupd<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dnsquery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> named-query<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. dig<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\"> utility is widely used for detailed DNS queries and troubleshooting. It allows administrators to specify record types, query particular DNS servers, inspect authoritative responses, and examine response sections. For example, <\/span><span style=\"font-weight: 400;\">dig MX example.com<\/span><span style=\"font-weight: 400;\"> requests MX records, while <\/span><span style=\"font-weight: 400;\">dig @192.0.2.53 example.com<\/span><span style=\"font-weight: 400;\"> sends the query to a specified DNS server. The <\/span><span style=\"font-weight: 400;\">host<\/span><span style=\"font-weight: 400;\"> command is also useful for simpler lookups, but <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\"> provides substantially more diagnostic detail. DNS administrators frequently use it to investigate delegation, recursion, caching, authoritative responses, and zone configuration problems.<\/span><\/p>\n<p><b>Question 240. Which command displays established TCP and UDP socket information on a modern Linux system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ss<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip sockets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> netconf<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. ss<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ss<\/span><span style=\"font-weight: 400;\"> command displays socket statistics and network connection information on Linux systems. It can show listening and established TCP connections, UDP sockets, Unix sockets, ports, process associations, and other network details. For example, <\/span><span style=\"font-weight: 400;\">ss -lnt<\/span><span style=\"font-weight: 400;\"> displays listening TCP sockets using numeric addresses and ports. The command is commonly used for troubleshooting services that are unreachable or listening on unexpected ports. Although older systems frequently used <\/span><span style=\"font-weight: 400;\">netstat<\/span><span style=\"font-weight: 400;\"> for similar tasks, <\/span><span style=\"font-weight: 400;\">ss<\/span><span style=\"font-weight: 400;\"> is the modern utility commonly associated with socket inspection and is part of the standard Linux networking toolkit.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full LPI 202-450\u00a0 Exam Dumps and Practice Test Dumps &nbsp; Question 221. Which BIND directive specifies the default time-to-live value for negative DNS responses? refresh expire minimum retry Correct Answer: 4. minimum Explanation :- The minimum field in the SOA record historically defines the negative caching TTL, meaning how long resolvers may cache negative [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23062"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23062"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23062\/revisions"}],"predecessor-version":[{"id":23063,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23062\/revisions\/23063"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}