試験科目:303-200: LPIC-3 Exam 303: Security, version 2.0
NO.1 Which of the following statements describes the purpose of ndpmon?
A. it monitors the network for neighbor discovery messages from new IPv6 hosts and routers
B. It monitors the network for IPv4 nodes that have not yet migrated to IPv6.
C. It monitors log files for failed login attempts in order to block traffic from offending network nodes
D. it monitors remote hosts by periodically sending echo requests to them.
E. it monitors the availability of a network link by querying network interfaces.
Answer: A


NO.2 Which of the following types can be specified within the Linux Audit system? (Choose THREE
correct answers)
A. Console rules
B. Network connection rules
C. System call rules
D. Control rules
E. File system rules
Answer: C,D,E

NO.3 Which option of the openvpn command should be used to ensure that ephemeral keys are not
written to the swap space?
A. --root-swap
B. --keys-no-swap
C. --no-swap
D. --mlock
Answer: D

NO.4 Which of the following statements are true regarding the certificate of a Root CA? (Choose
TWO correct answers.)
A. It has an infinite lifetime and never expires.
B. It does not include the private key of the CA
C. It must contain a host name as the common name.
D. It must contain an X509v3 Authority extension.
E. It is a self-signed certificate.
Answer: B,D,E

