[Jan 14, 2022] 202-450 PDF Dumps is essential on your 202-450 Exam Questions Certain Success! [Q35-Q56]

Share

[Jan 14, 2022]  202-450 PDF Dumps is essential on your 202-450 Exam Questions Certain Success!

202-450 PDF Questions - Perfect Prospect To Go With 202-450 Practice Exam


Topic 4: Network Client Management

This part requires that the students have proficiency in customizing a DHCP server. This involves setting default & per client options as well as adding BOOTP & static hosts. In addition, the candidates should demonstrate their skills in customizing PAM for maintaining authentication with the help of different available techniques. They also need to develop competency in the fundamental SSSD functionality as well as executing queries & updates to an LDAP server. The examinees should know how to import and add items, as well as add and handle users. They need to understand how to customize a fundamental OpenLDAP server, including comprehending the LDIF format as well as crucial access controls.


LPI 202-450 Exam Syllabus Topics:

TopicDetails

Domain Name Server

Basic DNS server configuration

Weight: 3
Description:Candidates should be able to configure BIND to function as a caching-only DNS server. This objective includes the ability to manage a running server and configuring logging.

Key Knowledge Areas:
-
BIND 9.x configuration files, terms and utilities
-Defining the location of the BIND zone files in BIND configuration files
-Reloading modified configuration and zone files
-Awareness of dnsmasq, djbdns and PowerDNS as alternate name servers

The following is a partial list of the used files, terms and utilities:
-
/etc/named.conf
-/var/named/
-/usr/sbin/rndc
-kill
-host
-dig

Create and maintain DNS zones

Weight: 3
Description: Candidates should be able to create a zone file for a forward or reverse zone and hints for root level servers. This objective includes setting appropriate values for records, adding hosts in zones and adding zones to the DNS. A candidate should also be able to delegate zones to another DNS server.

Key Knowledge Areas:
-
BIND 9 configuration files, terms and utilities
-Utilities to request information from the DNS server
-Layout, content and file location of the BIND zone files
-Various methods to add a new host in the zone files, including reverse zones

Terms and Utilities:
-
/var/named/
-zone file syntax
-resource record formats
-named-checkzone
-named-compilezone
-masterfile-format
-dig
-nslookup
-host

Securing a DNS server

Weight: 2
Description: Candidates should be able to configure a DNS server to run as a non-root user and run in a chroot jail. This objective includes secure exchange of data between DNS servers.

Key Knowledge Areas:
-
BIND 9 configuration files
-Configuring BIND to run in a chroot jail
-Split configuration of BIND using the forwarders statement
-Configuring and using transaction signatures (TSIG)
-Awareness of DNSSEC and basic tools
-Awareness of DANE and related records

Terms and Utilities:
-
/etc/named.conf
-/etc/passwd
-DNSSEC
-dnssec-keygen
-dnssec-signzone

Web Services

Implementing a web server

Weight: 4
Description: Candidates should be able to install and configure a web server. This objective includes monitoring the server’s load and performance, restricting client user access, configuring support for scripting languages as modules and setting up client user authentication. Also included is configuring server options to restrict usage of resources. Candidates should be able to configure a web server to use virtual hosts and customize file access.

Key Knowledge Areas:
-
Apache 2.4 configuration files, terms and utilities
-Apache log files configuration and content
-Access restriction methods and files
-mod_perl and PHP configuration
-Client user authentication files and utilities
-Configuration of maximum requests, minimum and maximum servers and clients
-Apache 2.4 virtual host implementation (with and without dedicated IP addresses)
-Using redirect statements in Apache’s configuration files to customize file access

Terms and Utilities:
- access logs and error logs
-.htaccess
-httpd.conf
-mod_auth_basic, mod_authz_host and mod_access_compat
-htpasswd
-AuthUserFile, AuthGroupFile
-apachectl, apache2ctl
-httpd, apache2

Apache configuration for HTTPS

Weight: 3
Description: Candidates should be able to configure a web server to provide HTTPS.

Key Knowledge Areas:
-
SSL configuration files, tools and utilities
-Generate a server private key and CSR for a commercial CA
-Generate a self-signed Certificate
-Install the key and certificate, including intermediate CAs
-Configure Virtual Hosting using SNI
-Awareness of the issues with Virtual Hosting and use of SSL
-Security issues in SSL use, disable insecure protocols and ciphers

Terms and Utilities:
-
Apache2 configuration files
-/etc/ssl/, /etc/pki/
-openssl, CA.pl
-SSLEngine, SSLCertificateKeyFile, SSLCertificateFile
-SSLCACertificateFile, SSLCACertificatePath
-SSLProtocol, SSLCipherSuite, ServerTokens, ServerSignature, TraceEnable

Implementing a proxy server

Weight: 2
Description: Candidates should be able to install and configure a proxy server, including access policies, authentication and resource usage.

Key Knowledge Areas:
-
Squid 3.x configuration files, terms and utilities
-Access restriction methods
-Client user authentication methods
-Layout and content of ACL in the Squid configuration files

Terms and Utilities:
-
squid.conf
-acl
-http_access

Implementing Nginx as a web server and a reverse proxy

Weight: 2
Description: Candidates should be able to install and configure a reverse proxy server, Nginx. Basic configuration of Nginx as a HTTP server is included.

Key Knowledge Areas:
-
Nginx
-Reverse Proxy
-Basic Web Server

Terms and Utilities:
-
/etc/nginx/
-nginx

File Sharing

SAMBA Server Configuration

Weight: 5
Description: Candidates should be able to set up a Samba server for various clients. This objective includes setting up Samba as a standalone server as well as integrating Samba as a member in an Active Directory. Furthermore, the configuration of simple CIFS and printer shares is covered. Also covered is a configuring a Linux client to use a Samba server. Troubleshooting installations is also tested.

Key Knowledge Areas:
-
Samba 4 documentation
-Samba 4 configuration files
-Samba 4 tools and utilities and daemons
-Mounting CIFS shares on Linux
-Mapping Windows user names to Linux user names
-User-Level, Share-Level and AD security

Terms and Utilities:
-
smbd, nmbd, winbindd
-smbcontrol, smbstatus, testparm, smbpasswd, nmblookup
-samba-tool
-net
-smbclient
-mount.cifs
-/etc/samba/
-/var/log/samba/

NFS Server Configuration

Weight: 3
Description: Candidates should be able to export filesystems using NFS. This objective includes access restrictions, mounting an NFS filesystem on a client and securing NFS.

Key Knowledge Areas:
-
NFS version 3 configuration files
-NFS tools and utilities
-Access restrictions to certain hosts and/or subnets
-Mount options on server and client
-TCP Wrappers
-Awareness of NFSv4

Terms and Utilities:
-
/etc/exports
-exportfs
-showmount
-nfsstat
-/proc/mounts
-/etc/fstab
​-rpcinfo
-mountd
-portmapper

Network Client Management

DHCP configuration

Weight: 2
Description: Candidates should be able to configure a DHCP server. This objective includes setting default and per client options, adding static hosts and BOOTP hosts. Also included is configuring a DHCP relay agent and maintaining the DHCP server.

Key Knowledge Areas:
-
DHCP configuration files, terms and utilities
-Subnet and dynamically-allocated range setup
-Awareness of DHCPv6 and IPv6 Router Advertisements

Terms and Utilities:
-
dhcpd.conf
-dhcpd.leases
-DHCP Log messages in syslog or systemd journal
-arp
-dhcpd
-radvd
-radvd.conf

PAM authentication

Weight: 3
Description: The candidate should be able to configure PAM to support authentication using various available methods. This includes basic SSSD functionality.

Key Knowledge Areas:
-
PAM configuration files, terms and utilities
-passwd and shadow passwords
-Use sssd for LDAP authentication

Terms and Utilities:
-
/etc/pam.d/
-pam.conf
-nsswitch.conf
-pam_unix, pam_cracklib, pam_limits, pam_listfile, pam_sss
-sssd.conf

LDAP client usage

Weight: 2
Description: Candidates should be able to perform queries and updates to an LDAP server. Also included is importing and adding items, as well as adding and managing users.

Key Knowledge Areas:
-
LDAP utilities for data management and queries
-Change user passwords
-Querying the LDAP directory

Terms and Utilities:
-
ldapsearch
-ldappasswd
-ldapadd
-ldapdelete

Configuring an OpenLDAP server

Weight: 4
Description: Candidates should be able to configure a basic OpenLDAP server including knowledge of LDIF format and essential access controls.

Key Knowledge Areas:
-
OpenLDAP
-Directory based configuration
-Access Control
-Distinguished Names
-Changetype Operations
-Schemas and Whitepages
-Directories
-Object IDs, Attributes and Classes

Terms and Utilities:
-
slapd
-slapd-config
-LDIF
-slapadd
-slapcat
-slapindex
-/var/lib/ldap/
-loglevel

E-Mail Services

Using e-mail servers

Weight: 4
Description: Candidates should be able to manage an e-mail server, including the configuration of e-mail aliases, e-mail quotas and virtual e-mail domains. This objective includes configuring internal e-mail relays and monitoring e-mail servers.

Key Knowledge Areas:
-
Configuration files for postfix
-Basic TLS configuration for postfix
-Basic knowledge of the SMTP protocol
-Awareness of sendmail and exim

Terms and Utilities:
-
Configuration files and commands for postfix
-/etc/postfix/
-/var/spool/postfix/
-sendmail emulation layer commands
-/etc/aliases
-mail-related logs in /var/log/

Managing E-Mail Delivery

Weight: 2
Description: Candidates should be able to implement client e-mail management software to filter, sort and monitor incoming user e-mail.

Key Knowledge Areas:
-
Understanding of Sieve functionality, syntax and operators
-Use Sieve to filter and sort mail with respect to sender, recipient(s), headers and size
-Awareness of procmail

Terms and Utilities:
-
Conditions and comparison operators
-keep, fileinto, redirect, reject, discard, stop
-Dovecot vacation extension

Managing Remote E-Mail Delivery

Weight: 2
Description: Candidates should be able to install and configure POP and IMAP daemons.

Key Knowledge Areas:
-
Dovecot IMAP and POP3 configuration and administration
-Basic TLS configuration for Dovecot
-Awareness of Courier

Terms and Utilities:
-
/etc/dovecot/
-dovecot.conf
-doveconf
-doveadm

System Security

Configuring a router

Weight: 3
Description: Candidates should be able to configure a system to forward IP packet and perform network address translation (NAT, IP masquerading) and state its significance in protecting a network. This objective includes configuring port redirection, managing filter rules and averting attacks.

Key Knowledge Areas:
-
iptables and ip6tables configuration files, tools and utilities
-Tools, commands and utilities to manage routing tables.
-Private address ranges (IPv4) and Unique Local Addresses as well as Link Local Addresses (IPv6)
-Port redirection and IP forwarding
-List and write filtering and rules that accept or block IP packets based on source or destination protocol, port and address
-Save and reload filtering configurations

Terms and Utilities:
-
/proc/sys/net/ipv4/
-/proc/sys/net/ipv6/
-/etc/services
-iptables
-ip6tables

Securing FTP servers

Weight: 2
Description: Candidates should be able to configure an FTP server for anonymous downloads and uploads. This objective includes precautions to be taken if anonymous uploads are permitted and configuring user access.

Key Knowledge Areas:
-
Configuration files, tools and utilities for Pure-FTPd and vsftpd
-Awareness of ProFTPd
-Understanding of passive vs. active FTP connections

Terms and Utilities:
-
vsftpd.conf
-important Pure-FTPd command line options

Secure shell (SSH)

Weight: 4
Description: Candidates should be able to configure and secure an SSH daemon. This objective includes managing keys and configuring SSH for users. Candidates should also be able to forward an application protocol over SSH and manage the SSH login.

Key Knowledge Areas:
-
OpenSSH configuration files, tools and utilities
-Login restrictions for the superuser and the normal users
-Managing and using server and client keys to login with and without password
-Usage of multiple connections from multiple hosts to guard against loss of connection to remote host following configuration changes

Terms and Utilities:
-
ssh
-sshd
-/etc/ssh/sshd_config
-/etc/ssh/
-Private and public key files
-PermitRootLogin, PubKeyAuthentication, AllowUsers, PasswordAuthentication, Protocol

Security tasks

Weight: 3
Description: Candidates should be able to receive security alerts from various sources, install, configure and run intrusion detection systems and apply security patches and bugfixes.

Key Knowledge Areas:
-
Tools and utilities to scan and test ports on a server
-Locations and organizations that report security alerts as Bugtraq, CERT or other sources
-Tools and utilities to implement an intrusion detection system (IDS)
-Awareness of OpenVAS and Snort

Terms and Utilities:
-
telnet
-nmap
-fail2ban
-nc
-iptables

OpenVPN

Weight: 2
Description: Candidates should be able to configure a VPN (Virtual Private Network) and create secure point-to-point or site-to-site connections.

Key Knowledge Areas:
-
OpenVPN

Terms and Utilities:
-
/etc/openvpn/
-openvpn


NEW QUESTION 35
On a Linux router, packet forwarding for IPv4 has been enabled. After a reboot, the machine no longer forwards IP packets from other hosts. The command:
echo 1 > /proc/sys/net/ipv4/ip_forward
temporarily resolves this issue.
Which one of the following options is the best way to ensure this setting is saved across system restarts?

  • A. In /etc/sysconfig/iptables-config add ipv4.ip_forward = 1
  • B. Add echo 1 > /proc/sys/net/ipv4/ip_forward to the root user login script
  • C. In /etc/rc.local add net.ipv4.ip_forward = 1
  • D. In /etc/sysct1.conf change net.ipv4.ip_forward to 1
  • E. Add echo 1 > /proc/sys/net/ipv4/ip_forward to any user login script

Answer: D

 

NEW QUESTION 36
Performing a DNS lookup with dig results in this answer:

  • A. The . in the NS definition in the reverse lookup zone has to be removed
  • B. There is no . after linuserv.example.net in the PTR record in the reverse lookup zone file
  • C. There is no . after linuserv in the PTR record in the forward lookup zone file
  • D. There is no . after linuserv.example.net in the PTR record in the forward lookup zone file

Answer: B

 

NEW QUESTION 37
In which CIFS share must printer drivers be placed to allow Point'n'Print driver deployment on Windows?

  • A. The name of the share is specified in the option print driver share within each printable share in smb.conf
  • B. pnpdrivers$
  • C. winx64drv$
  • D. print$
  • E. NETLOGON

Answer: D

 

NEW QUESTION 38
A host, called lpi, with the MAC address 08:00:2b:4c:59:23 should always be given the IP address of
192.168.1.2 by a DHCP server running ISC DHCPD.
Which of the following configurations will achieve this?

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option E
  • E. Option C

Answer: A

 

NEW QUESTION 39
In order to prevent all anonymous FTP users from listing uploaded file names, what security precaution can be taken when creating an upload directory?

  • A. The directory must not contain other directories.
  • B. The directory must not have the execute permission set.
  • C. The directory must not have the write permission set.
  • D. The directory must not have the read or execute permission set.
  • E. The directory must not have the read permission set.

Answer: E

 

NEW QUESTION 40
Which of the following DNS records could be a glue record?

  • A. ns1.A198.51.100.53
  • B. ns1.labA198.51.100.53
  • C. labNS198.51.100.53
  • D. ns1.labGLUE198.51.100.53
  • E. ns1.labNS198.51.100.53

Answer: B

 

NEW QUESTION 41
Which directive in a Nginx server configuration block defines the TCP ports on which the virtual host will be available, and which protocols it will use?
(Specify ONLY the option name without any values.)

Answer:

Explanation:
listen

 

NEW QUESTION 42
Which Apache HTTPD directive enables HTTPS protocol support?

  • A. HTTPSEnable on
  • B. SSLEnable on
  • C. StartTLS on
  • D. HTTPSEngine on
  • E. SSLEngine on

Answer: E

 

NEW QUESTION 43
Performing a DNS lookup with dig results in this answer:

  • A. The . in the NS definition in the reverse lookup zone has to be removed
  • B. There is no . after linuserv.example.net in the PTR record in the reverse lookup zone file
  • C. There is no . after linuserv in the PTR record in the forward lookup zone file
  • D. There is no . after linuserv.example.net in the PTR record in the forward lookup zone file

Answer: B

 

NEW QUESTION 44
What is the name of the root element of the LDAP tree holding the configuration of an OpenLDAP server that is using directory based configuration?
(Specify ONLY the element's name without any additional information.)

Answer:

Explanation:
slapd

 

NEW QUESTION 45
What is the standard port used by OpenVPN?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

 

NEW QUESTION 46
Which statements about the Alias and Redirect directives in Apache HTTPD's configuration file are true?
(Choose two.)

  • A. Alias is handled on the server side
  • B. Redirect is handled on the client side
  • C. Alias is not a valid configuration directive
  • D. Redirect works with regular expressions
  • E. Alias can only reference files under DocumentRoot

Answer: A,B

 

NEW QUESTION 47
Which BIND option should be used to limit the IP addresses from which slave name servers may connect?

  • A. allow-transfer
  • B. allow-zone-transfer
  • C. allow-slaves
  • D. allow-queries
  • E. allow-secondary

Answer: A

 

NEW QUESTION 48
In order to protect a directory on an Apache HTTPD web server with a password, this configuration was added to an .htaccessfile in the respective directory:

Furthermore, a file /var/www/dir/ .htpasswdwas created with the following content:
usera:S3cr3t
Given that all these files were correctly processed by the web server processes, which of the following statements is true about requests to the directory?

  • A. The web server delivers the content of the directory without requesting authentication
  • B. Accessing the directory as useraraises HTTP error code 442 (User Not Existent)
  • C. The browser prompts the visitor for a username and password but logins for userado not seem to work
  • D. The user useracan access the site using the password s3cr3t
  • E. Requests are answered with HTTP error code 500 (Internal Server Error)

Answer: D

 

NEW QUESTION 49
Which http_accessdirective for Squid allows users in the ACL named sales_net to only access the Internet at times specified in the time_aclnamed sales_time?

  • A. http_access deny sales_time sales_net
  • B. http_access sales_net sales_time
  • C. http_access allow sales_net sales_time
  • D. http_access allow sales_net and sales-time
  • E. allow http_access sales_net sales_time

Answer: C

 

NEW QUESTION 50
In order to protect a directory on an Apache HTTPD web server with a password, this configuration was added to an .htaccess file in the respective directory:

Furthermore, a file /var/www/dir/ .htpasswd was created with the following content:
usera:S3cr3t
Given that all these files were correctly processed by the web server processes, which of the following statements is true about requests to the directory?

  • A. The web server delivers the content of the directory without requesting authentication
  • B. The browser prompts the visitor for a username and password but logins for usera do not seem to work
  • C. Requests are answered with HTTP error code 500 (Internal Server Error)
  • D. The user usera can access the site using the password s3cr3t
  • E. Accessing the directory as usera raises HTTP error code 442 (User Not Existent)

Answer: D

 

NEW QUESTION 51
Which action in a Sieve filter forwards a message to another email address without changing the message?
(Specify ONLY the action's name without any parameters.)

Answer:

Explanation:
redirect

 

NEW QUESTION 52
How are PAM modules organized and stored?

  • A. As plain text files in /etc/security/
  • B. A statically linked binaries in /etc/pam.d/bin/
  • C. As shared object files within the /lib/ directory hierarchy
  • D. As Linux kernel modules within the respective sub directory of /lib/modules/
  • E. As dynamically linked binaries in /usr/lib/pam/sbin/

Answer: E

 

NEW QUESTION 53
The content of which local file has to be transmitted to a remote SSH server in order to be able to log into the remote server using SSH keys?

  • A. ~/.ssh/config
  • B. ~/.ssh/id_rsa
  • C. ~/.ssh/authorized_keys
  • D. ~/.ssh/id_rsa.pub
  • E. ~./ssh/known_hosts

Answer: C

Explanation:
Explanation/Reference:
Reference: https://www.digitalocean.com/community/tutorials/ssh-essentials-working-with-ssh-servers- clients-and-keys

 

NEW QUESTION 54
A zone file contains the following lines:

and is included in the BIND configuration using this configuration stanza:

Which problem is contained in this configuration?

  • A. The zone cannon contain records for a name which is outside the zone's hierarchy.
  • B. An A record cannot contain an IPv4 address because its value is supposed to be a reverse DNS name.
  • C. The zone statement is the BIND configuration must contain the cross-zone-data yes; statement.
  • D. Names of records in a zone file cannot be fully qualified domain names.
  • E. The $ORIGIN declaration cannot be used in zone files that are included for a specific zone name in the BIND configuration.

Answer: E

 

NEW QUESTION 55
Which of the following statements are true regarding Server Name Indication (SNI)? (Choose two.)

  • A. It submits the host name of the requested URL during the TLS handshake.
  • B. It provides a list of available virtual hosts to the client during the TLS handshake.
  • C. It supports transparent failover of TLS sessions from one web server to another.
  • D. It enables HTTP servers to update the DNS of their virtual hosts' names using the X 509 certificates of the virtual hosts.
  • E. It allows multiple SSL/TLS secured virtual HTTP hosts to coexist on the same IP address.

Answer: A,E

Explanation:
Explanation

 

NEW QUESTION 56
......


LPI 202-450: Important Features

One of the first things that you need to know about the LPI 202-450 exam is that the applicants should understand how to perform system administration in addition to simple tasks related to maintenance, system startup, and Linux Kernel before attempting this certification test. They need to know how to configure and install the fundamental network services, such as DNS, DHCP, SSH, FTP, NFS, and Samba. Anyone going for this exam must possess the active LPIC-1 certificate otherwise they will not be eligible for the test.

202-450 Exam with Accurate LPIC-2 Exam 202, Part 2 of 2, version 4.5 PDF Questions: https://www.examcollectionpass.com/Lpi/202-450-practice-exam-dumps.html

True Lpi Exam Extraordinary Practice For the 202-450 Exam: https://drive.google.com/open?id=1fpW4thEkMG9NoAzfimu6xMnN0sJ9MDgt