System Security & Firewall Management Flashcards
7 cards from real LCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 System Security & Firewall Management flashcards as text
Which command lists all open firewalld zones and their active interfaces?
Answer: firewall-cmd --get-active-zones
firewall-cmd --get-active-zones shows each zone that has at least one interface or source assigned.
What does setting 'PermitRootLogin no' in /etc/ssh/sshd_config accomplish?
Answer: Prevents direct root login via SSH while allowing su after login
This setting blocks SSH authentication as root but does not affect local console login or su/sudo elevation.
Which auditd rule syntax watches for writes to /etc/passwd?
Answer: -w /etc/passwd -p wa -k passwd_changes
The -w flag specifies the watch path, -p wa means watch for writes and attribute changes, and -k sets the key label.
Which kernel parameter, set via sysctl, disables ICMP echo (ping) responses?
Answer: net.ipv4.icmp_echo_ignore_all = 1
Setting icmp_echo_ignore_all to 1 instructs the kernel to silently discard all ICMP echo requests.
In SELinux, what does the Boolean 'httpd_can_network_connect' control?
Answer: Whether the httpd process can initiate outbound network connections
This Boolean allows or denies the Apache httpd daemon from making outbound TCP connections, useful for reverse-proxy scenarios.
What is the effect of running 'chmod 4755' on an executable?
Answer: Sets the SUID bit so the file runs with the owner's privileges
The leading '4' in octal notation sets the Set-UID bit, causing execution under the file owner's UID.
Which command shows all current iptables rules in the filter table with line numbers?
Answer: iptables -t filter -L -n --line-numbers
Combining -t filter, -L (list), -n (numeric), and --line-numbers gives a numbered, numeric listing of filter table rules.