
LPIC-3 Security
Domain 1Objective 4
325.4 DNS and Cryptography (weight: 5) LPIC-3-SECURITY Practice Questions (Page 2)
Part of the Topic 325: Cryptography domain, which makes up ~28% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
9concepts
Questions 6–10
- 6
A validating resolver returns SERVFAIL for a domain that is DNSSEC-signed. The administrator runs 'dig +dnssec example.com A' and sees an RRSIG record, but the AD flag is not set. What is the most likely cause?
Select an answer first - 7
Which DNS record type is used by DANE to associate a certificate with a domain?
Select an answer first - 8
Which of the following record types is published in a DNSSEC-signed zone to provide authenticated denial of existence?
Select an answer first - 9
What is the purpose of a TLSA record?
Select an answer first - 10
An organization uses DANE to secure its SMTP server. They have published a TLSA record with usage 3 (DANE-EE) and a SHA-256 hash of the certificate. During a certificate renewal, the certificate is replaced with a new one. What must the administrator do to maintain DANE validation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.