System Security & Firewall Management Flashcards
7 cards from real LCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Security & Firewall Management flashcards as text
Which mode does SELinux operate in when it logs policy violations but does not enforce them?
Answer: Permissive
Permissive mode records AVC denials to the audit log but allows the operation, useful for troubleshooting policy issues.
What is the purpose of the 'umask 027' setting in a shell profile?
Answer: Restricts new files to owner read/write and group read only
umask 027 subtracts from 666/777 defaults, yielding 640 for files and 750 for directories, blocking world access.
Which firewall-cmd option applies all --permanent rules without restarting the firewalld service?
Answer: --reload
firewall-cmd --reload re-reads the permanent configuration and applies it to the runtime configuration without service restart.
What does the 'NOPASSWD' tag in a sudoers entry accomplish?
Answer: Allows the specified command to run via sudo without a password prompt
NOPASSWD exempts that specific rule from requiring the user's password when invoking sudo for the listed commands.
Which log file should an administrator check first to view SELinux AVC denial messages?
Answer: /var/log/audit/audit.log
The auditd daemon writes AVC (Access Vector Cache) denial records to /var/log/audit/audit.log.
An administrator wants to block all traffic from subnet 10.0.5.0/24 using iptables. Which command achieves this?
Answer: iptables -I INPUT -s 10.0.5.0/24 -j DROP
Using -I inserts the rule at the top of the INPUT chain, ensuring it is evaluated before any ACCEPT rules for that subnet.
What is the function of the 'chattr +i' command on a file?
Answer: Makes the file immutable so it cannot be modified, deleted, or renamed even by root
The +i (immutable) attribute prevents any modification, deletion, renaming, or hard-linking to the file, even by root.