
LPIC-3 Security
Domain 4Objective 3
328.3 Packet Filtering (weight: 5) LPIC-3-SECURITY Practice Questions (Page 3)
Part of the Topic 328: Network Security domain, which makes up ~27% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~9–16 in this domain), expect 2–4 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
11concepts
Questions 11–15
- 11
In connection tracking, what does the NEW state represent?
Select an answer first - 12
Two firewalls in an active-passive HA pair protect a DMZ. The active firewall handles all traffic and maintains connection tracking state. When it fails, the passive firewall takes over but has no knowledge of existing connections, causing all active sessions to be dropped. The administrator wants to minimize session disruption during failover. What should they implement?
Select an answer first - 13
Which iptables target is used to rewrite the source IP address of outgoing packets to the IP address of the outgoing interface?
Select an answer first - 14
Why is it important to configure both iptables and ip6tables when securing a Linux host?
Select an answer first - 15
What is the primary advantage of using IP sets with iptables?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.