Which of the following parameters is used in the database on a slave server to direct clients that want to make changes to the OpenLDAP database to the master server?
A. updatedn
B. updateserver
C. updateref
D. updateuri

Correct Answer: C QUESTION 2
It is found that changes made to an OpenLDAP directory are no longer being replicated to the slave server at Tests prove that the slave server is listening on the correct port and changes are being recorded properly to the replication log file. In which file would you find the replication errors?
A. replication.err
B. replication.rej
C. 389.rej
D. 389.err

Correct Answer: C QUESTION 3
In the example below, what is the missing argument that is required to use secret as the password to authenticate the replication push with a slave directory server?
replica uri=ldaps: // 636 binddn=”cn=Replicator,dc=example,dc=com” bindmethod=simple ______________=secret
A. secure
B. master
C. credentials
D. password

Correct Answer: C QUESTION 4
When configuring OpenLDAP to use certificates, which option should be used with the TLSVerifyClient directive to ask the client for a valid certificate in order to proceed normally?
A. never
B. allow
C. try
D. demand

Correct Answer: D QUESTION 5
Which of the following procedures will test the TLS configuration of an OpenLDAP server?
A. Run the ldapsearch command with the -ZZ option, while watching network traffic with a packet analyzer.
B. Run the ldapsearch command with the -x option, while watching network traffic with a packet analyzer.
C. Run the slapcat command, while watching network traffic with a packet analyzer.
D. Verify the TLS negotiation process in the /var/log/ldap_auth.log file.
E. Verify the TLS negotiation process in the /var/log/auth.log file.

Correct Answer: A
In slapd.conf, what keyword will instruct slapd to not ask the client for a certificatE.
TLSVerifyClient = ________
A. never
B. nocert
C. none
D. unverified

Correct Answer: A
OpenLDAP can be secured by which of these options? (Select THREE correct choices)
A. TLS (Transport Layer Security)
B. ACLs (Access Control Lists)
C. HTTPS (Hypertext Transfer Protocol Secure)
D. SSL (Secure Sockets Layer)
E. OSI-L2 (OSI Layer 2 encryption)

Correct Answer: ABD
After modifying the indexes for a database in slapd.conf and running slapindex, the slapd daemon refuses to start when its init script is called. What is the most likely cause of this?
A. The indexes are not compatible with the init script.
B. The init script cannot be run after executing slapindex, without first signing the indexes with slapsign.
C. The init script has identified one or more invalid indexes.
D. The init script is starting slapd as an ordinary user, and the index files are owned by root.
Correct Answer: D
What does cachesize 1000000 represent in the slapd.conf file?
A. The number of entries to be cached.
B. The size of the cache in Bytes.
C. The size of the cache in Bits.
D. The minimum cache size in Bytes.
E. The maximum cache size in Bytes.

Correct Answer: A
What is the correct command to regenerate slapd indices based upon the current contents of the database?
A. slapd index
B. sindexd
C. slapindex
D. There is no index command, indexing is handled by the slapd daemon.

Correct Answer: C QUESTION 11
Which of the following parameters can be used in the file DB_CONFIG? (Select TWO correct answers.)
A. set_cachesize
B. set_cachepath
C. set_db_type
D. set_db_path
E. set_lg_max

Correct Answer: AE QUESTION 12
When configuring an OpenLDAP system for integration with PAM and NSS the /etc/nsswitch.conf file needs to be modified. Which of the following parameters completes this line from the /etc/nsswitch.conf file?
passwD. files _________
A. pam
B. ldap
C. pam_nss
D. pam_ldap
E. none

Correct Answer: B QUESTION 13
By configuring Pluggable Authentication Module (PAM) and Name Service Switch (NSS) technologies to use OpenLDAP, what authentication service can be replaced?
A. Microsoft NT Domain
B. Samba
C. Network Information Service (NIS)
D. Active Directory (AD)

Correct Answer: C QUESTION 14
Which option for the pam_ldap module specifies a file from which the module’s global settings can be read?
A. default
B. global
C. config
D. include

Correct Answer: C QUESTION 15
Which port in TCP/IP communication is used for Kerberos v5?
A. 888
B. 86
C. 88 D. 90

Correct Answer: C QUESTION 16
What are benefits of using Single Sign-On (SSO)? (Select THREE correct answers.)
A. Reduce IT costs due to lower number of IT help desk calls about passwords.
B. Reduce time spent re-entering passwords for the same identity.
C. Reduce number of passwords to remember.
D. Reduce password complexity.
E. Reduce number of services used by users.

Correct Answer: ABC QUESTION 17
Which of the following are true for CIFS? (Choose TWO correct answers.)
A. Filenames can be in any character set.
B. Filenames can have a maximum length of 127 characters.
C. Unlike SMB, CIFS is not optimized for slow network connections.
D. Opportunistic Locks are supported.

Correct Answer: AD QUESTION 18
CIFS relies upon which port for direct hosting without requiring NetBIOS?
A. 139
B. 443
C. 137
D. 445

Correct Answer: D QUESTION 19
Which of the following daemons are included in Samba 3? (Select THREE correct answers.)
A. wind
B. nmbd
C. winbindd
D. samba
E. smbd

Correct Answer: BCE QUESTION 20
What following statement is true about Samba 4?
A. Samba 4 can serve as an Active Directory Domain Controller.
B. Microsoft Windows clients cannot connect to Samba 4 servers.
C. Samba 4 is only a minor update of Samba 3 to fix smaller bugs and contains no new features.
D. Integration of Samba 4 in an existing Active Directory Domain is not possible.

