
LPIC-3 Security
Domain 1Objective 4
325.4 DNS and Cryptography (weight: 5) LPIC-3-SECURITY Practice Questions (Page 5)
Part of the Topic 325: Cryptography domain, which makes up ~28% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
9concepts
Questions 21–25
- 21
A company operates a DNSSEC-signed zone with a KSK and ZSK. They need to roll the KSK because it may have been compromised. They want to minimize the risk of validation failures during the rollover. Which procedure should they follow?
Select an answer first - 22
Which BIND configuration statement enables DNSSEC signing for a zone?
Select an answer first - 23
Which of the following is required for a TLSA record to be usable for DANE validation?
Select an answer first - 24
Which command-line tool is specifically designed to perform DNSSEC validation and can be used to troubleshoot validation issues?
Select an answer first - 25
What is a key tag in DNSSEC?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.