To be able to access the server with the IP address using HTTPS, a rule for iptables has to be written. Given that the client host’s IP address is, which of the following commands is correct?

A.    iptables -A FORWARD -p tcp -s 0/0 -d -dport 80 -j ACCEPT
B.    iptables -A FORWARD -p tcp -s -d -j ACCEPT
C.    iptables -A FORWARD -p tcp -s -d -dport 443 -j ACCEPT
D.    iptables -A INPUT -p tcp -s -d -j ACCEPT
E.    iptables -A FORWARD -p tcp -s 0/0 -d -dport 443 -j ACCEPT

Answer: C

Which Apache directive is used to configure the main directory for the site, out of which it will serve documents?
Answer: DocumentRoot

Which file on a Postfix server modifies the sender address for outgoing e-mails? Please enter only the file name without the path
Answer: sender_canonical

When connecting to an SSH server for the first time, its fingerprint is received and stored in a file, which is located at:

A.    ~/ .ssh/fingerprints
B.    ~/ .ssh/id_dsa
C.    ~/ .ssh/known_hosts
D.    ~/ .ssh/id_dsa.pub
E.    ~/ .ssh/gpg.txt

Answer: C

Which command can be used to save the current iptables rules into a file? Please enter only the command without path or parameters.
Answer: iptables-save

Which THREE of the following actions should be considered when a FTP chroot jail is created?

A.    Create /dev/ and /etc/ in the chroot enviroment
B.    Create /etc/passwd in the chroot enviroment
C.    Create /var/cache/ftp in the chroot enviroment
D.    Create the user ftp in the chroot enviroment
E.    Create /usr/sbin/ in the chroot enviroment

Answer: ABD

All machines outside the network are able to send emails through the server to addresses not served by that server. If the server accepts and delivers the email, then it is a(n) _____________. Please enter the English term, without any punctuation.
Answer: open email relay

Connecting to a remote host on the same LAN using ssh public-key authentication works but forwarding X11 doesn’t. The remote host allows access to both services. Which of the following can be the reason for that behaviour?

A.    The remote user’s ssh_config file disallows X11 forwarding
B.    The remote server’s sshd_config file disallows X11 forwarding
C.    A different public key has to be used for X11
D.    X11 cannot be forwarded if public-key authentication was used
E.    X11 though SSH needs a special X11 server application installed

Answer: B

An iptables firewall was configured to use the target MASQUERADE to share a dedicated wireless connection to the Internet with a few hosts on the local network. The Internet connection becomes very unstable in rainy da
ys and users complain their connections drop when downloading e-mail or large files, while web browsing seems to be working fine. Which change to your iptables rules could alleviate the problem?

A.    Change the target MASQUERADE to SNAT
B.    Change the target MASQUERADE to DNAT
C.    Change the target MASQUERADE to BALANCE and provide a backup Internet connection
D.    Change the target MASQUERADE to REDIRECT and provide a backup Internet connection
E.    Change the target MASQUERADE to BNAT

Answer: A

Which command line creates an SSH tunnel for POP and SMTP protocols?

A.    ssh- L :110 -L :25 -1 user -N mailhost
B.    ssh -L 25:110 -1 user -N mailhost
C.    ssh -L mailhost:110 -L mailhost:25 -1 user -N mailhost
D.    ssh -L mailhost:25:110 -1 user
E.    ssh -L 110:mailhost:110 -L 25:mailhost:25 -1 user -N mailhost

Answer: E

