
LPIC-3 Security
Domain 1Objective 4
325.4 DNS and Cryptography (weight: 5) LPIC-3-SECURITY Practice Questions (Page 3)
Part of the Topic 325: Cryptography domain, which makes up ~28% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
9concepts
Questions 11–15
- 11
An organization wants to use DANE to authenticate the TLS certificate of its mail server (mail.example.com) without relying on public CAs. The domain example.com is DNSSEC-signed. Which record should be published to associate the mail server's certificate with the domain?
Select an answer first - 12
In DNSSEC, what is the primary difference between a Key Signing Key (KSK) and a Zone Signing Key (ZSK)?
Select an answer first - 13
Two BIND servers are configured to use TSIG for zone transfers. The secondary server fails to transfer the zone, and the logs show 'bad key' errors. What is the most likely cause?
Select an answer first - 14
An organization wants to use DANE to secure connections to its web server. The domain is DNSSEC-signed. Which condition must be met for DANE to work?
Select an answer first - 15
Which tool would you use to check the syntax and DNSSEC records of a zone file before loading it into BIND?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.