โ† All Linux Flashcard Decks

CompTIA Linux+ Security and Access Control Flashcards

7 cards from real Linux practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CompTIA Linux+ Security and Access Control flashcards as text
  1. Which command checks the integrity of installed RPM packages by verifying checksums against the RPM database?

    Answer: rpm -Va

    rpm -Va verifies all installed packages, reporting files whose attributes differ from the recorded values in the RPM database.

  2. What is the primary purpose of using TCP Wrappers (/etc/hosts.allow and /etc/hosts.deny)?

    Answer: Providing host-based access control for network services

    TCP Wrappers use hosts.allow and hosts.deny to permit or deny access to network services based on the client's hostname or IP address.

  3. A Linux administrator needs to restrict the resources a user's processes can consume. Which command applies these limits?

    Answer: ulimit -u 50

    ulimit sets per-process or per-user resource limits such as max processes (-u), open files (-n), and memory in the current shell session.

  4. Which cryptographic hash algorithm is currently recommended for storing Linux user passwords in /etc/shadow?

    Answer: SHA-512 ($6$)

    SHA-512 (identified by $6$ in the shadow file) is the current recommended algorithm for password hashing on modern Linux systems.

  5. Which nmap flag performs a SYN scan (stealth scan) to detect open ports without completing the TCP handshake?

    Answer: -sS

    nmap -sS sends SYN packets and interprets responses without completing the three-way handshake, making it less visible in logs.

  6. What is the function of the 'fail2ban' service on a Linux server?

    Answer: Monitors logs and temporarily bans IPs with repeated failed logins

    fail2ban reads log files, detects repeated authentication failures, and adds temporary firewall rules to block offending IP addresses.

  7. Which SELinux command is used to change the context of a file persistently so it survives a filesystem relabel?

    Answer: semanage fcontext -a -t httpd_sys_content_t '/var/www/html/file'

    semanage fcontext writes the context rule to policy so restorecon and relabeling operations apply the correct label persistently.