System Security & Firewall Management Flashcards
7 cards from real LCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Security & Firewall Management flashcards as text
Which fail2ban component reads log files and triggers bans based on defined filters?
Answer: fail2ban-server
fail2ban-server is the daemon that monitors logs and communicates with the firewall to block offending IPs.
What does 'restorecon -Rv /var/www/html' do?
Answer: Restores SELinux file contexts based on policy for the directory tree
restorecon applies the correct SELinux contexts as defined in the policy database, -R for recursive, -v for verbose.
Which SSH configuration directive restricts login to specific users?
Answer: AllowUsers
The AllowUsers directive in sshd_config accepts a space-separated list of usernames permitted to authenticate via SSH.
A server is experiencing a SYN flood attack. Which sysctl parameter helps mitigate this?
Answer: net.ipv4.tcp_syncookies = 1
TCP SYN cookies allow the server to handle SYN floods without maintaining half-open connection state in the backlog queue.
Which command in nftables lists all current rules across all tables?
Answer: nft list ruleset
nft list ruleset outputs the complete nftables configuration including all tables, chains, and rules.
What file stores the public keys authorized for key-based SSH login for a specific user?
Answer: ~/.ssh/authorized_keys
The ~/.ssh/authorized_keys file holds public keys whose corresponding private keys are accepted for authentication.
Which command shows which SELinux Boolean values are currently enabled?
Answer: getsebool -a
getsebool -a lists all SELinux Booleans and their current (on/off) state.