Free 303-200: LPIC-3 Exam 303: Security, version 2.0 Exam Questions and Answers
48 verified practice questions for 303-200.
The first 10 questions on this page are free to read, answers included — no account and no card. A plan opens the rest of the bank, the full timed practice test and your weak-topic reporting.
Last updated: September 19, 2026
- Exam code
- 303-200
- Provider
- LPI
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Our test mode duration & pass mark
- 130 mins · 70%
- Verified answers
- Reviewed weekly
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
Which of the following access control models is established by using SELinux?
Please select an optionIncorrectCorrect answer: E
SELinux enforces an administratively defined system-wide policy that file owners cannot override, which is the definition of mandatory access control, unlike the discretionary model.
Was this answer correct?Question #2
What happens when the command getfattr afile is run while the file afile has no extended attributes set?
Please select an optionIncorrectCorrect answer: C
With no extended attributes set there is nothing to report, so getfattr prints no output and exits successfully with status 0; absence of attributes is not an error.
Was this answer correct?Question #3
How are SELinux permissions related to standard Linux permissions? (Choose TWO correct answers.)
Select 2 answers.
Please select an optionIncorrectCorrect answer: B, D
Standard Linux permissions are evaluated first, so they can deny access before SELinux is consulted; the SELinux check therefore happens after the traditional permission check.
Was this answer correct?Question #4
Which of the following prefixes could be present in the output of getcifsacl? (Choose THREE correct answers.)
Select 3 answers.
Please select an optionIncorrectCorrect answer: A, C, D
getcifsacl reports a security descriptor in the sections OWNER, GROUP and ACL, so those prefixes appear in its output. GRANT and SID are not section prefixes it prints.
Was this answer correct?Question #5
Which of the following are differences between AppArmor and SELinux? (Choose TWO correct answers).
Select 2 answers.
Please select an optionIncorrectCorrect answer: B, D
AppArmor is path-based and far easier to configure than SELinux, and SELinux keeps its labels in extended file attributes while AppArmor maintains no per-file state.
Was this answer correct?Question #6
Linux Extended File Attributes are organized in namespaces. Which of the following names correspond to existing attribute namespaces? (Choose THREE correct answers.)
Select 3 answers.
Please select an optionIncorrectCorrect answer: B, D, E
The extended attribute namespaces that exist are user, trusted, system and security; default and owner are not namespaces.
Was this answer correct?Question #7
Which of the following commands defines an audit rule that monitors read and write operations to the file/etc/firewall/rules and associates the rule with the name firewall?
Please select an optionIncorrectCorrect answer: C
auditctl -w watches the file, -p rw matches read and write accesses and -k firewall attaches the key used to search the audit log.
Was this answer correct?Question #8
Which of the following database names can be used within a Name Service Switch (NSS) configuration file? (Choose THREE correct answers).
Select 3 answers.
Please select an optionIncorrectCorrect answer: B, D, E
Name Service Switch supports the passwd, shadow and group databases among others. The other choices are not valid NSS database names as listed; the correct names are hosts and services.
Was this answer correct?Question #9
Which of the following sections are allowed within the Kerberos configuration file krb5.conf? (Choose THREE correct answers.)
Select 3 answers.
Please select an optionIncorrectCorrect answer: A, D, E
krb5.conf accepts sections including [libdefaults], [realms], [domain_realm], [capaths] and [plugins]; [crypto] and [domain] are not valid section names.
Was this answer correct?Question #10
Which of the following components are part of FreelPA? (Choose THREE correct answers.)
Select 3 answers.
Please select an optionIncorrectCorrect answer: B, D, E
FreeIPA bundles a Kerberos KDC, a certificate authority providing PKI and a 389 Directory Server; no DHCP server or intrusion detection system is included.
Was this answer correct?
Continue with 303-200: LPIC-3 Exam 303: Security, version 2.0
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in 303-200: LPIC-3 Exam 303: Security, version 2.0, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Other LPI certifications
- 101-500: LPIC-1 Exam 101 - Part 1 of 2 - version 5.0 (opens in a new tab)
- 201-450: LPIC-2 Exam 201 Part 1 of 2 version 4.5 (opens in a new tab)
- 102-500: LPIC-1 Exam 102 - Part 2 of 2 - version 5.0 (opens in a new tab)
- 202-450: LPIC-2 Exam 202 Part 2 of 2 version 4.5 (opens in a new tab)
- 010-160: Linux Essentials Certificate Exam - version 1.6 (opens in a new tab)
- 010-150: Linux Essentials (opens in a new tab)
Reviews
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah Smith
USA
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar Nyström
Sweden
★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit Sharma
India



