
[Oct-2025] Lpi 303-300 Official Cert Guide PDF
Exam 303-300: LPIC Exam 303: Security, version 3.0 - TopExamCollection
NEW QUESTION # 71
What is the purpose of a Certificate Authority (CA)?
- A. To decrypt X.509 certificates
- B. To store X.509 certificates
- C. To issue and sign X.509 certificates
- D. To encrypt X.509 certificates
Answer: C
NEW QUESTION # 72
What option of mount.cifs specifies the user that appears as the local owner of the files of a mounted CIFS share when the server does not provide ownership information?
(Specify ONLY the option name without any values or parameters.)
Solution: uid=arg
Determine whether the given solution is correct?
- A. Correct
- B. Incorrect
Answer: A
NEW QUESTION # 73
What is a rogue access point?
- A. An unauthorized access point that is set up to look like a legitimate one
- B. A type of phishing scam
- C. A legitimate access point that is incorrectly configured
- D. A type of virus
Answer: A
NEW QUESTION # 74
An X509 certificate contains the following information:
X509v3 Basic Constraints: critical CA:TRUE, pathlen:0
Which of the following statements are true regarding the certificate?
(Choose THREE correct answers.)
- A. This certificate may never be used to sign any other certificates.
- B. This certificate will not be accepted by programs that do not understand the listed extension.
- C. This certificate may be used to sign certificates that are not also a certification authority.
- D. This certificate may be used to sign certificates of subordinate certification authorities.
- E. This certificate belongs to a certification authority.
Answer: C,D,E
NEW QUESTION # 75
Which tool can be used to check for rootkits on a Linux system?
- A. rpm
- B. OpenSCAP
- C. AIDE
- D. chkrootkit
Answer: D
NEW QUESTION # 76
Which of the following commands adds users using SSSD's local service?
- A. sss_add
- B. sss-addlocaluser
- C. sss_useradd
- D. sss_adduser
- E. sss_local_adduser
Answer: C
NEW QUESTION # 77
Which of the following openssl commands generates a certificate signing request (CSR) using the already existing private key contained in the file private/ keypair.pem?
- A. openssl gencsr -key private/keypair.pem -out req/csr.pem
- B. openssl req -key private/keypair.pem -out req/csr.pem
- C. openssl gencsr -new- key private/keypair.pem -out req/csr.pem
- D. openssl req - new -key private/keypair.pem -out req/csr.pem
Answer: D
NEW QUESTION # 78
Which option in an Apache HTTPD configuration file enables OCSP stapling?
(Specify ONLY the option name without any values or parameters.)
Solution: httpd-ssl.conf
Determine whether the given solution is correct?
- A. Correct
- B. Incorrect
Answer: B
NEW QUESTION # 79
How can host scans be automated on a Linux system?
- A. Using cron
- B. Using OpenSCAP
- C. Using chkrootkit
- D. Using Linux Audit system
Answer: A
NEW QUESTION # 80
Which file is used to configure rkhunter?
- A. /etc/audit/auditd.conf
- B. /etc/maldet.conf
- C. /etc/aide/aide.conf
- D. /etc/rkhunter.conf
Answer: D
NEW QUESTION # 81
What is the purpose of DNS over TLS and DNS over HTTPS?
- A. To improve DNS performance
- B. To allow DNS servers to communicate securely with each other
- C. To reduce DNS query times
- D. To provide secure communication between DNS clients and servers
Answer: D
NEW QUESTION # 82
What is host intrusion detection (HID)?
- A. A system that monitors and detects potential security threats on a single computer or server
- B. A system that prevents malware from infecting a network
- C. A system that detects malicious traffic on a network
- D. A system that scans files and folders for viruses
Answer: A
NEW QUESTION # 83
Which of the following DNS records are used in DNSSEC?
- A. MX
- B. PTR
- C. TXT
- D. RRSIG
Answer: D
NEW QUESTION # 84
Which DNS label points to the DANE information used to secure HTTPS connections to
https://www.example.com/?
- A. dane.www.example.com
- B. soa.example.com
- C. example.com
- D. www.example.com
- E. _443_tcp.www.example.com
Answer: E
NEW QUESTION # 85
What is a DoS attack?
- A. An attack that aims to steal sensitive information
- B. An attack that floods a network or server with traffic to make it unavailable
- C. An attack that exploits a vulnerability in software
- D. An attack that targets a specific user or organization
Answer: B
NEW QUESTION # 86
Which of the following utilities is used to generate keys for DNSSEC?
- A. delv
- B. rndc
- C. dnssec-keygen
- D. dnssec-dsfromkey
Answer: C
NEW QUESTION # 87
Which command revokes ACL-based write access for groups and named users on the file afile?
- A. setfacl ~m mask: : rx afile
- B. setfacl ~m group: * : rx, user :*: rx afile
- C. setfacl -x group: * : rx, user:*: rx afile
- D. setfacl -x mask: : rx afile
Answer: A
NEW QUESTION # 88
Which of the following commands adds a new user usera to FreeIPA?
- A. useradd usera --directory ipa --gecos "User A"
- B. ipa user-add usera --first User --last A
- C. ipa-user- add usera --name "User A"
- D. ipa-admin create user --account usera --fname User --iname A
- E. idap- useradd -H Idaps://ipa-server CN=UserA --attribs "Firstname: User: Lastname: A"
Answer: B
NEW QUESTION # 89
......
Free 303-300 Exam Dumps to Improve Exam Score: https://examcompass.topexamcollection.com/303-300-vce-collection.html

