Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Linux Professional Institute logo

LPIC-3 Security

Domain 2Objective 2

326.2 Host Intrusion Detection (weight: 4) LPIC-3-SECURITY Practice Questions (Page 3)

Part of the Topic 326: Host Security domain, which makes up ~26% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~9–16 in this domain), expect 2–4 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
11concepts

Questions 11–15

  1. 11foundation · easy

    What is the primary purpose of Linux Malware Detect (LMD)?

    Select an answer first
  2. 12expert · hard

    An administrator wants to schedule a weekly security scan on a server. The scan should run every Sunday at 3:00 AM, and the output should be logged to /var/log/security-scan.log. The administrator also wants to ensure that the scan runs even if the system was off at the scheduled time. Which approach should be used?

    Select an answer first
  3. 13expert · hard

    An administrator has configured rkhunter to run nightly via cron. The administrator notices that the scan results are not being emailed, even though the MAILTO variable is set in the crontab. The rkhunter configuration file has the following settings: MAIL_ON_WARNING=yes, MAIL_CMD=mail -s "rkhunter scan" root@localhost. What is the most likely reason the emails are not being sent?

    Select an answer first
  4. 14application · easy

    A system administrator is troubleshooting why audit rules are not being applied after a reboot. The administrator has added rules to /etc/audit/rules.d/audit.rules. Which command should the administrator run to verify that the rules are loaded?

    Select an answer first
  5. 15application · medium

    A security administrator needs to monitor all attempts to change the system's hostname on a server running the Linux Audit daemon. The administrator wants the rule to survive a reboot and to be able to later search for events specifically related to hostname changes. Which approach should the administrator use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.