
LPIC-3 Security
Domain 1Objective 4
325.4 DNS and Cryptography (weight: 5) LPIC-3-SECURITY Practice Questions (Page 6)
Part of the Topic 325: Cryptography domain, which makes up ~28% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
9concepts
Questions 26–30
- 26
Why must DNSSEC-signed zones be re-signed periodically?
Select an answer first - 27
A company runs two BIND name servers: a primary and a secondary. They want to ensure that zone transfers from the primary to the secondary are authenticated and that only the secondary can request transfers. Which configuration should be used on the primary server?
Select an answer first - 28
Which BIND configuration option enables DNSSEC validation on a recursive resolver?
Select an answer first - 29
A DNSSEC-signed zone is served by BIND. Users report that some resolvers return SERVFAIL for the zone. The administrator runs 'dig example.com A' and receives a response with the AD flag, but 'dig +dnssec example.com A' shows no RRSIG records. What is the most likely cause?
Select an answer first - 30
A company runs an authoritative BIND server for example.com. They recently signed the zone with DNSSEC using a single key. Now they want to implement a proper key hierarchy with a Key Signing Key (KSK) and a Zone Signing Key (ZSK). They also want to minimize the risk of a compromised ZSK allowing an attacker to forge zone data. Which approach best meets these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to LPIC-3-SECURITY
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.