CompTIA Linux+ Security and Access Control Flashcards
7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CompTIA Linux+ Security and Access Control flashcards as text
What is the purpose of the /etc/sudoers file?
Answer: Defines which users can run commands as other users via sudo
/etc/sudoers specifies which users or groups are permitted to run commands as root or another user via sudo.
Which AppArmor command loads a profile in enforce mode?
Answer: aa-enforce
aa-enforce puts an AppArmor profile into enforce mode, actively blocking policy violations.
A Linux system uses iptables. Which command saves the current rules so they persist after reboot on a Debian-based system?
Answer: iptables-save > /etc/iptables/rules.v4
iptables-save redirects current rules to a file that iptables-persistent reads on boot for rule restoration.
Which SSH configuration directive in sshd_config disables password authentication entirely?
Answer: PasswordAuthentication no
Setting PasswordAuthentication no in sshd_config forces key-based authentication only, disabling passwords.
What does the command 'chattr +i /etc/resolv.conf' accomplish?
Answer: Sets the file immutable so it cannot be modified or deleted
chattr +i sets the immutable attribute, preventing any user including root from modifying or deleting the file without first removing the attribute.
Which tool is used to audit system calls made by a process for security analysis on Linux?
Answer: strace
strace intercepts and records system calls made by a process, making it useful for security and debugging analysis.
In a firewalld environment, which zone is typically assigned to trusted internal network interfaces?
Answer: internal
The 'internal' zone in firewalld is intended for interfaces connected to trusted internal networks with higher trust than the public zone.