
LPIC-3 Security
Domain 1Objective 2
325.2 X.509 Certificates for Encryption, Signing and Authentication (weight: 4) LPIC-3-SECURITY Practice Questions (Page 3)
Part of the Topic 325: Cryptography domain, which makes up ~28% of our current practice bank. Linux Professional Institute does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 3–4 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
9concepts
Questions 11–15
- 11
A security analyst is investigating a potential downgrade attack on a corporate web server. The server is configured with SSLProtocol all -TLSv1 -TLSv1.1, and HSTS is enabled. The analyst suspects an attacker is stripping the HSTS header from responses. Which additional measure would BEST protect against this specific attack vector?
Select an answer first - 12
In Apache, which directive is used within a virtual host to enable SNI for that host?
Select an answer first - 13
What is the primary purpose of the HTTP Strict Transport Security (HSTS) header?
Select an answer first - 14
Which OpenSSL command is used to simulate a TLS server for testing purposes?
Select an answer first - 15
A company's Apache server must support a legacy application that only works with TLS 1.0. The security team has mandated that all other services on the same server must use TLS 1.2 or higher, and they want to minimize the attack surface. The administrator has decided to run the legacy application on a separate IP address. Which approach BEST satisfies both the legacy application's requirement and the security team's mandate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Linux Professional Institute. “LPIC-3-SECURITY” is a trademark of its owner, used for identification only.