{"id":23078,"date":"2026-09-26T11:30:20","date_gmt":"2026-09-26T11:30:20","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23078"},"modified":"2026-09-26T11:30:20","modified_gmt":"2026-09-26T11:30:20","slug":"lpi-202-450-practice-test-questions-and-exam-dumps-part-20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/lpi-202-450-practice-test-questions-and-exam-dumps-part-20-q381-400\/","title":{"rendered":"LPI 202-450 Practice Test Questions and Exam Dumps Part 20 Q381-400"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/202-450-exam-dumps\"><b>LPI 202-450\u00a0 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 381. Which BIND command can be used to reload zone data without fully restarting the named service?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> named-checkzone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rndc reload<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dig reload<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> host -r<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. rndc reload<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">rndc reload<\/span><span style=\"font-weight: 400;\"> command instructs a running BIND server to reload its configuration and zone data. This allows administrators to apply changes without completely stopping and starting the <\/span><span style=\"font-weight: 400;\">named<\/span><span style=\"font-weight: 400;\"> daemon. It is particularly useful after modifying zone files or configuration settings. <\/span><span style=\"font-weight: 400;\">named-checkzone<\/span><span style=\"font-weight: 400;\"> validates zone-file syntax and consistency but does not reload the server. <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\"> is a DNS query utility, while <\/span><span style=\"font-weight: 400;\">host<\/span><span style=\"font-weight: 400;\"> performs DNS lookups. Using <\/span><span style=\"font-weight: 400;\">rndc reload<\/span><span style=\"font-weight: 400;\"> is therefore a standard operational method for applying DNS changes to an active BIND installation while minimizing service interruption.<\/span><\/p>\n<p><b>Question 382. Which Apache directive specifies the directory containing the files served for a virtual host?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerName<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ServerAlias<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DirectoryIndex<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DocumentRoot<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. DocumentRoot<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">DocumentRoot<\/span><span style=\"font-weight: 400;\"> directive identifies the filesystem directory from which web content is served. In a virtual-host configuration, each site can have its own <\/span><span style=\"font-weight: 400;\">DocumentRoot<\/span><span style=\"font-weight: 400;\">, allowing multiple websites to use different directories on the same server. <\/span><span style=\"font-weight: 400;\">ServerName<\/span><span style=\"font-weight: 400;\"> identifies the hostname, <\/span><span style=\"font-weight: 400;\">ServerAlias<\/span><span style=\"font-weight: 400;\"> provides additional hostnames, and <\/span><span style=\"font-weight: 400;\">DirectoryIndex<\/span><span style=\"font-weight: 400;\"> specifies default files such as <\/span><span style=\"font-weight: 400;\">index.html<\/span><span style=\"font-weight: 400;\">. Correctly configuring <\/span><span style=\"font-weight: 400;\">DocumentRoot<\/span><span style=\"font-weight: 400;\"> is essential because Apache must know where to locate requested resources. File permissions and Apache access controls must also permit the web server to read the selected directory and its contents.<\/span><\/p>\n<p><b>Question 383. Which NFS configuration file defines filesystems that are exported to clients?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/exports<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/fstab<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/nfs.conf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/mounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. \/etc\/exports<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">\/etc\/exports<\/span><span style=\"font-weight: 400;\"> file defines the filesystems that an NFS server makes available to remote clients. Each export can specify permitted hosts or networks and options controlling access behavior, such as read-only access or root squashing. After modifying the file, administrators commonly use <\/span><span style=\"font-weight: 400;\">exportfs<\/span><span style=\"font-weight: 400;\"> to update the active export table. <\/span><span style=\"font-weight: 400;\">\/etc\/fstab<\/span><span style=\"font-weight: 400;\"> is generally used for filesystem mounting, including persistent NFS client mounts. The other files do not serve as the standard primary export-definition file. Proper <\/span><span style=\"font-weight: 400;\">\/etc\/exports<\/span><span style=\"font-weight: 400;\"> configuration is important for both functionality and NFS security.<\/span><\/p>\n<p><b>Question 384. Which Samba command checks the syntax and reports errors in the smb.conf configuration?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbstatus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbclient<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> testparm<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> smbpasswd<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. testparm<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">testparm<\/span><span style=\"font-weight: 400;\"> utility validates and displays information about the Samba configuration, including the contents of <\/span><span style=\"font-weight: 400;\">smb.conf<\/span><span style=\"font-weight: 400;\">. It is commonly used after configuration changes to detect syntax problems or unexpected settings before restarting Samba services. <\/span><span style=\"font-weight: 400;\">smbstatus<\/span><span style=\"font-weight: 400;\"> reports current Samba connections and locks, <\/span><span style=\"font-weight: 400;\">smbclient<\/span><span style=\"font-weight: 400;\"> provides a command-line SMB client, and <\/span><span style=\"font-weight: 400;\">smbpasswd<\/span><span style=\"font-weight: 400;\"> manages Samba password information. Running <\/span><span style=\"font-weight: 400;\">testparm<\/span><span style=\"font-weight: 400;\"> during troubleshooting can help identify configuration mistakes before they cause service startup failures or unexpected share behavior.<\/span><\/p>\n<p><b>Question 385. Which DNS record type is specifically used to define a canonical alias for another hostname?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> MX<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CNAME<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. CNAME<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CNAME, or Canonical Name, record creates an alias from one DNS name to another canonical hostname. For example, <\/span><span style=\"font-weight: 400;\">www.example.com<\/span><span style=\"font-weight: 400;\"> can be configured as a CNAME pointing to <\/span><span style=\"font-weight: 400;\">web01.example.com<\/span><span style=\"font-weight: 400;\">. DNS clients then resolve the canonical target according to normal DNS processing. MX records identify mail servers, PTR records provide reverse mappings, and NS records identify authoritative name servers. CNAME records are useful for maintaining aliases without duplicating the target&#8217;s address records, although DNS configuration rules restrict where CNAME records can be used within a zone.<\/span><\/p>\n<p><b>Question 386. Which DHCP option identifies the default gateway that a client should use?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 15<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 3<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 6<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Option 51<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Option 3<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DHCP option 3 provides the default gateway, or router, information to a DHCP client. A server can supply one or more router addresses through this option, allowing the client to determine where traffic destined for remote networks should be sent. Option 6 specifies DNS servers, option 15 specifies the domain name, and option 51 defines the IP address lease time. If a client has a valid IP address but cannot reach remote networks, checking the DHCP-provided option 3 information can help identify a missing or incorrect default route.<\/span><\/p>\n<p><b>Question 387. Which Postfix configuration parameter specifies the hostname used by the mail system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> myhostname<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mydestination<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> relayhost<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mynetworks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. myhostname<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Postfix <\/span><span style=\"font-weight: 400;\">myhostname<\/span><span style=\"font-weight: 400;\"> parameter specifies the system&#8217;s hostname as used by the mail system. It is an important part of Postfix identity and can influence generated message headers and SMTP behavior. <\/span><span style=\"font-weight: 400;\">mydestination<\/span><span style=\"font-weight: 400;\"> identifies destinations for which Postfix performs local delivery, <\/span><span style=\"font-weight: 400;\">relayhost<\/span><span style=\"font-weight: 400;\"> specifies an upstream relay, and <\/span><span style=\"font-weight: 400;\">mynetworks<\/span><span style=\"font-weight: 400;\"> identifies trusted client networks. Administrators should ensure that <\/span><span style=\"font-weight: 400;\">myhostname<\/span><span style=\"font-weight: 400;\"> corresponds appropriately to the server&#8217;s configured hostname and DNS environment. Correct hostname configuration helps avoid confusing SMTP identity and mail-delivery problems.<\/span><\/p>\n<p><b>Question 388. Which Dovecot utility is commonly used to perform mailbox administration tasks such as searching or manipulating messages?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> doveconf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dovecot<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> doveadm<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dovemail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. doveadm<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">doveadm<\/span><span style=\"font-weight: 400;\"> utility provides administrative commands for Dovecot and can perform various mailbox and user-management operations. Depending on the command and configuration, administrators can use it to inspect mailboxes, search messages, move or delete messages, and perform other maintenance tasks. <\/span><span style=\"font-weight: 400;\">doveconf<\/span><span style=\"font-weight: 400;\"> is primarily used to inspect effective Dovecot configuration, while <\/span><span style=\"font-weight: 400;\">dovecot<\/span><span style=\"font-weight: 400;\"> is the main server program. Understanding the distinction between configuration inspection and mailbox administration is important when managing Dovecot-based IMAP and POP3 services.<\/span><\/p>\n<p><b>Question 389. Which SSH configuration directive controls whether password-based authentication is permitted?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PermitRootLogin<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PasswordAuthentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AllowUsers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PubkeyAuthentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. PasswordAuthentication<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The OpenSSH <\/span><span style=\"font-weight: 400;\">PasswordAuthentication<\/span><span style=\"font-weight: 400;\"> directive controls whether clients may authenticate using passwords. When password authentication is disabled, users generally need another permitted authentication mechanism, such as public-key authentication. <\/span><span style=\"font-weight: 400;\">PermitRootLogin<\/span><span style=\"font-weight: 400;\"> controls root-account login behavior, <\/span><span style=\"font-weight: 400;\">AllowUsers<\/span><span style=\"font-weight: 400;\"> restricts which accounts may connect, and <\/span><span style=\"font-weight: 400;\">PubkeyAuthentication<\/span><span style=\"font-weight: 400;\"> controls public-key authentication. Administrators often disable password authentication in environments that require key-based access, but they must ensure valid alternative credentials are configured first to avoid locking out legitimate users.<\/span><\/p>\n<p><b>Question 390. Which command can display recent authentication-related messages from the system journal?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> journalctl -u named<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> journalctl -u apache2<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> journalctl -u nfs-server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> journalctl -u ssh<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. journalctl -u ssh<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">journalctl -u ssh<\/span><span style=\"font-weight: 400;\"> command can display journal entries associated with the SSH service when the service unit is named <\/span><span style=\"font-weight: 400;\">ssh<\/span><span style=\"font-weight: 400;\">. On systems where the unit is named differently, such as <\/span><span style=\"font-weight: 400;\">sshd<\/span><span style=\"font-weight: 400;\">, the corresponding service name should be used. Journal logs can help administrators investigate successful and failed connection attempts, authentication errors, and service startup issues. The other commands target different services: BIND, Apache, and NFS. Examining service-specific journal entries is a useful troubleshooting technique when diagnosing authentication or daemon-related problems.<\/span><\/p>\n<p><b>Question 391. Which nftables family supports rules that can apply to both IPv4 and IPv6 traffic?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> inet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> arp<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> bridge<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> netdev<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. inet<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The nftables <\/span><span style=\"font-weight: 400;\">inet<\/span><span style=\"font-weight: 400;\"> address family is designed for rules that can handle both IPv4 and IPv6 traffic. This can simplify firewall configurations because administrators can define common filtering logic without maintaining entirely separate IPv4 and IPv6 rule sets. The <\/span><span style=\"font-weight: 400;\">ip<\/span><span style=\"font-weight: 400;\"> family is specific to IPv4, while <\/span><span style=\"font-weight: 400;\">ip6<\/span><span style=\"font-weight: 400;\"> is specific to IPv6. Other families such as <\/span><span style=\"font-weight: 400;\">bridge<\/span><span style=\"font-weight: 400;\"> and <\/span><span style=\"font-weight: 400;\">netdev<\/span><span style=\"font-weight: 400;\"> serve different packet-processing contexts. Using an <\/span><span style=\"font-weight: 400;\">inet<\/span><span style=\"font-weight: 400;\"> table is therefore useful when a firewall needs consistent filtering policies across both major IP versions.<\/span><\/p>\n<p><b>Question 392. Which DNS record is used to associate an IPv6 address with a hostname?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PTR<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AAAA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CNAME<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. AAAA<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AAAA record maps a hostname to an IPv6 address. It is the IPv6 equivalent of an A record, which maps a hostname to an IPv4 address. PTR records are used for reverse DNS mappings, while CNAME records create aliases to other hostnames. For example, a web server that has an IPv6 address can have an AAAA record associated with its hostname. Administrators can use <\/span><span style=\"font-weight: 400;\">dig AAAA hostname<\/span><span style=\"font-weight: 400;\"> to inspect IPv6 address records and verify that DNS is providing the expected IPv6 information.<\/span><\/p>\n<p><b>Question 393. Which Apache module provides URL rewriting functionality?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_ssl<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_proxy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_rewrite<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> mod_status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. mod_rewrite<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Apache <\/span><span style=\"font-weight: 400;\">mod_rewrite<\/span><span style=\"font-weight: 400;\"> module provides URL rewriting capabilities. It works with directives such as <\/span><span style=\"font-weight: 400;\">RewriteRule<\/span><span style=\"font-weight: 400;\"> and <\/span><span style=\"font-weight: 400;\">RewriteCond<\/span><span style=\"font-weight: 400;\"> to transform or redirect requests according to defined patterns and conditions. It is widely used for clean URLs, application routing, redirects, and conditional request processing. <\/span><span style=\"font-weight: 400;\">mod_ssl<\/span><span style=\"font-weight: 400;\"> provides TLS support, <\/span><span style=\"font-weight: 400;\">mod_proxy<\/span><span style=\"font-weight: 400;\"> supports proxy functionality, and <\/span><span style=\"font-weight: 400;\">mod_status<\/span><span style=\"font-weight: 400;\"> provides server-status information. When troubleshooting rewrite behavior, administrators should verify that the module is enabled and that the relevant rewrite directives are correctly placed in the applicable configuration context.<\/span><\/p>\n<p><b>Question 394. Which NFS utility reports statistics about NFS client and server operations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> showmount<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> nfsstat<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> exportfs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rpcinfo<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. nfsstat<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">nfsstat<\/span><span style=\"font-weight: 400;\"> utility reports statistics related to NFS operations. It can provide information about client and server activity, including procedure calls and various protocol-related counters. These statistics can help administrators investigate performance or communication problems involving NFS. <\/span><span style=\"font-weight: 400;\">showmount<\/span><span style=\"font-weight: 400;\"> displays exported filesystems and client information, <\/span><span style=\"font-weight: 400;\">exportfs<\/span><span style=\"font-weight: 400;\"> manages NFS exports, and <\/span><span style=\"font-weight: 400;\">rpcinfo<\/span><span style=\"font-weight: 400;\"> reports RPC service information. When an NFS environment experiences unusual delays or failures, examining <\/span><span style=\"font-weight: 400;\">nfsstat<\/span><span style=\"font-weight: 400;\"> output can provide additional evidence about the behavior of the NFS subsystem.<\/span><\/p>\n<p><b>Question 395. Which Postfix file commonly contains mail aliases such as mapping an administrative address to a local user?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/postfix\/main.cf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/aliases<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/postfix\/master.cf<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> \/etc\/resolv.conf<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. \/etc\/aliases<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">\/etc\/aliases<\/span><span style=\"font-weight: 400;\"> file commonly contains local mail aliases that map addresses to other local recipients, programs, or destinations. A typical example is mapping an administrative address such as <\/span><span style=\"font-weight: 400;\">postmaster<\/span><span style=\"font-weight: 400;\"> to a specific local account. After modifying aliases, administrators commonly run <\/span><span style=\"font-weight: 400;\">newaliases<\/span><span style=\"font-weight: 400;\"> so that Postfix can use the updated alias database. <\/span><span style=\"font-weight: 400;\">main.cf<\/span><span style=\"font-weight: 400;\"> contains major Postfix configuration parameters, while <\/span><span style=\"font-weight: 400;\">master.cf<\/span><span style=\"font-weight: 400;\"> defines service processes and their behavior. <\/span><span style=\"font-weight: 400;\">\/etc\/resolv.conf<\/span><span style=\"font-weight: 400;\"> is related to DNS resolver configuration and has no role in defining Postfix mail aliases.<\/span><\/p>\n<p><b>Question 396. Which Linux command can display listening TCP and UDP sockets together with associated processes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip route<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ss -lntup<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ip addr<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dig<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. ss -lntup<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ss -lntup<\/span><span style=\"font-weight: 400;\"> command provides information about listening sockets and can include the associated processes. The options request listening sockets, numeric addresses and ports, TCP and UDP sockets, and process information. This makes the command useful when determining which services are listening on particular ports. <\/span><span style=\"font-weight: 400;\">ip route<\/span><span style=\"font-weight: 400;\"> displays routing information, <\/span><span style=\"font-weight: 400;\">ip addr<\/span><span style=\"font-weight: 400;\"> displays interface addresses, and <\/span><span style=\"font-weight: 400;\">dig<\/span><span style=\"font-weight: 400;\"> performs DNS queries. When troubleshooting unexpected network exposure, checking listening sockets can help identify services that are accepting connections and may require additional firewall or service configuration.<\/span><\/p>\n<p><b>Question 397. Which OpenSSH directive specifies whether public-key authentication is enabled?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> PubkeyAuthentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> PasswordAuthentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AuthorizedKeysFile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AllowGroups<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. PubkeyAuthentication<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The OpenSSH <\/span><span style=\"font-weight: 400;\">PubkeyAuthentication<\/span><span style=\"font-weight: 400;\"> directive controls whether public-key authentication is permitted by the SSH server. When enabled, users can authenticate using an appropriate private key corresponding to a public key accepted by the server. <\/span><span style=\"font-weight: 400;\">PasswordAuthentication<\/span><span style=\"font-weight: 400;\"> controls password authentication, <\/span><span style=\"font-weight: 400;\">AuthorizedKeysFile<\/span><span style=\"font-weight: 400;\"> identifies the file containing accepted public keys, and <\/span><span style=\"font-weight: 400;\">AllowGroups<\/span><span style=\"font-weight: 400;\"> restricts access to members of specified groups. Public-key authentication is widely used for administrative access because it can avoid transmitting reusable passwords during authentication and can be integrated with automated management systems.<\/span><\/p>\n<p><b>Question 398. Which SELinux command searches audit records for messages related to access denials?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> restorecon<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> getenforce<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> ausearch<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> semanage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. ausearch<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">ausearch<\/span><span style=\"font-weight: 400;\"> utility searches Linux audit logs for selected events and is commonly used to investigate SELinux access denials. Administrators can filter audit records to locate relevant messages and then use the information to determine which process, file, or policy rule was involved. <\/span><span style=\"font-weight: 400;\">restorecon<\/span><span style=\"font-weight: 400;\"> restores file security contexts, <\/span><span style=\"font-weight: 400;\">getenforce<\/span><span style=\"font-weight: 400;\"> reports SELinux enforcement mode, and <\/span><span style=\"font-weight: 400;\">semanage<\/span><span style=\"font-weight: 400;\"> manages persistent SELinux configuration. When an application is blocked by SELinux, examining audit records with tools such as <\/span><span style=\"font-weight: 400;\">ausearch<\/span><span style=\"font-weight: 400;\"> can provide evidence needed to diagnose the policy interaction.<\/span><\/p>\n<p><b>Question 399. Which command can test whether a remote TCP port is reachable without establishing a full application-level session?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> nc -z<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dig -x<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> host -t<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> rndc status<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. nc -z<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">nc -z<\/span><span style=\"font-weight: 400;\"> option allows netcat to scan for listening TCP or UDP ports without sending application data in the normal interactive manner. For example, <\/span><span style=\"font-weight: 400;\">nc -zv server.example.com 443<\/span><span style=\"font-weight: 400;\"> can test whether TCP port 443 is reachable and accepting connections. This makes netcat useful for basic connectivity and firewall troubleshooting. <\/span><span style=\"font-weight: 400;\">dig -x<\/span><span style=\"font-weight: 400;\"> performs reverse DNS queries, <\/span><span style=\"font-weight: 400;\">host -t<\/span><span style=\"font-weight: 400;\"> performs DNS lookups for a specified record type, and <\/span><span style=\"font-weight: 400;\">rndc status<\/span><span style=\"font-weight: 400;\"> reports BIND server status. Port testing should be performed only against systems where such testing is authorized.<\/span><\/p>\n<p><b>Question 400. Which OpenVPN configuration directive identifies the remote VPN server to which a client should connect?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> cipher<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> dev<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> proto<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> remote<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. remote<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In an OpenVPN client configuration, the <\/span><span style=\"font-weight: 400;\">remote<\/span><span style=\"font-weight: 400;\"> directive specifies the hostname or IP address of the remote VPN server and can also include the destination port. For example, a client configuration may identify a VPN gateway by hostname and port using the <\/span><span style=\"font-weight: 400;\">remote<\/span><span style=\"font-weight: 400;\"> directive. <\/span><span style=\"font-weight: 400;\">dev<\/span><span style=\"font-weight: 400;\"> specifies the virtual network device type, <\/span><span style=\"font-weight: 400;\">proto<\/span><span style=\"font-weight: 400;\"> specifies the transport protocol, and <\/span><span style=\"font-weight: 400;\">cipher<\/span><span style=\"font-weight: 400;\"> relates to encryption configuration depending on the OpenVPN version and setup. Correctly configuring the remote endpoint is essential because the client needs to know where to establish the VPN connection.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full LPI 202-450\u00a0 Exam Dumps and Practice Test Dumps &nbsp; Question 381. Which BIND command can be used to reload zone data without fully restarting the named service? named-checkzone rndc reload dig reload host -r Correct Answer: 2. rndc reload Explanation :- The rndc reload command instructs a running BIND server to reload its [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23078"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23078"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23078\/revisions"}],"predecessor-version":[{"id":23079,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23078\/revisions\/23079"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}