โ† All Linux Flashcard Decks

CompTIA Linux+ Security and Access Control Flashcards

7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CompTIA Linux+ Security and Access Control flashcards as text
  1. Which command shows all open files and the processes using them, useful for detecting unauthorized network connections?

    Answer: lsof -i

    lsof -i lists all open internet sockets and the processes associated with them, aiding in detecting unexpected connections.

  2. What is the effect of setting 'umask 027' for a user session?

    Answer: New files get permissions 640 and directories get 750

    umask 027 subtracts from default permissions (666 for files, 777 for dirs), yielding 640 for new files and 750 for new directories.

  3. Which SELinux context component determines what type of access is allowed between objects?

    Answer: Type

    The Type component (also called domain for processes) is what SELinux policy rules primarily use to control access between subjects and objects.

  4. A security policy requires all accounts lock after 5 failed login attempts. Which PAM module enforces this?

    Answer: pam_faillock.so

    pam_faillock.so tracks failed authentication attempts and locks accounts after a configurable threshold is exceeded.

  5. Which command generates a new SSH key pair using the Ed25519 algorithm?

    Answer: ssh-keygen -t ed25519

    ssh-keygen -t ed25519 generates an Ed25519 key pair, which is more secure and efficient than RSA for SSH authentication.

  6. What does the Linux audit daemon (auditd) primarily do?

    Answer: Records security-relevant events to a log for compliance and forensics

    auditd collects kernel audit events (file access, system calls, user logins) and writes them to /var/log/audit/audit.log for review.

  7. Which file restricts which users are allowed to use the cron scheduling service?

    Answer: /etc/cron.allow

    When /etc/cron.allow exists, only users listed in it may use cron; if it doesn't exist, /etc/cron.deny is consulted instead.