Question 1
Lab simulation
Simulation RHCE Test Configuration Instructions Information for the two systems you will use in test is the following: system1.group3.example.com: is one of the main sever. system2.group3.example.com: mainly used as a client. Password for both of the two systems is atenorth System's IP is provided by DHCP, you can regard it as normal, or you can reset to Static IP in accordance with the following requirements: system1.group3.example.com: 172.24.3.5 system2.group3.example.com: 172.24.3.10 The subnet mask is 255.255.255.0 Your system is a member of DNS domain group3.example.com. All systems in DNS domain group3.example.com are all in subnet 172.24.3.0/255.255.255.0, the same all systems in this subnet are also in group3.example.com, unless specialized, all network services required to be configured can be accessed by systems of domain group3. host.group3.example.com provides a centralized authentication service domain GROUP3.EXAMPLE.COM, both system1 and system2 have already been pre-configured to be the client for this domain, this domain provides the following user account:  Firewall is enabled by default, you can turn it off when deemed appropriate, other settings about firewall may be in separate requirements. Your system will be restarted before scoring, so please ensure that all modifications and service configurations you made still can be operated after the restart without manual intervention, virtual machine instances of all examinations must be able to enter the correct multi-user level after restart without manual assistance, it will be scored zero if the test using virtual machine system cannot be restarted or be properly restarted. Corresponding distribution packages for the testing using operating system Red Hat Enterprise Linux version can be found in the following link: http://server1.group3.example.com/rhel Part of the requirements include host security, ensure your host security limit does not prevent the request to allow the host and network, although you correctly configured the network service but would have to allow the host or network is blocked, this also does not score. You will notice that some requirements which clearly do not allow services be accessed by service domain my133t.org, systems of this domain are in subnet 172.25.1.0/252.255.255.0, and systems of these subnets also belong to my 133t.org domain. PS: Notice that some test questions may depend on other exam questions, for example, you might be asked to perform a series of restrictions on a user, but this user creation may be required in other questions. For convenient identification, each exam question has some radio buttons to help you identify which questions you have already completed or not completed. Certainly, you do not need to care these buttons if you don't need them. Share directories via SMB. Configure the SMB service on the system1. Your SMB server must be a member of the STAFF Working Group. Share the folder /common and the name must be common. Only clients of domain11.example.com can access the common share. Common must be able to browse. User Andy must be able to read the content of the share, if necessary, verification code is redhat.
Reveal model answer
Close model answer
Explanation: system1:  system2: 
Question 2
Lab simulation
Simulation There were two systems: system1, main system on which most of the configuration take place system2, some configuration here  SMTP Configuration. Configure the SMTP mail service on serverX and desktopX which relay the mail only from local system through station.network0.example.com, all outgoing mail have their sender domain as example.com. Ensure that mail should not store locally. Verify the mail server is working by sending mail to a natasha user. Check the mail on both serverX and desktopX with the below URL http://station.network0.example.com/system1 http://station.network0.example.com/system2
Reveal model answer
Close model answer
Explanation: 
Question 3
Lab simulation
Simulation RHCE Test Configuration Instructions Information for the two systems you will use in test is the following: system1.group3.example.com: is one of the main sever. system2.group3.example.com: mainly used as a client. Password for both of the two systems is atenorth System's IP is provided by DHCP, you can regard it as normal, or you can reset to Static IP in accordance with the following requirements: system1.group3.example.com: 172.24.3.5 system2.group3.example.com: 172.24.3.10 The subnet mask is 255.255.255.0 Your system is a member of DNS domain group3.example.com. All systems in DNS domain group3.example.com are all in subnet 172.24.3.0/255.255.255.0, the same all systems in this subnet are also in group3.example.com, unless specialized, all network services required to be configured can be accessed by systems of domain group3. host.group3.example.com provides a centralized authentication service domain GROUP3.EXAMPLE.COM, both system1 and system2 have already been pre-configured to be the client for this domain, this domain provides the following user account:  Firewall is enabled by default, you can turn it off when deemed appropriate, other settings about firewall may be in separate requirements. Your system will be restarted before scoring, so please ensure that all modifications and service configurations you made still can be operated after the restart without manual intervention, virtual machine instances of all examinations must be able to enter the correct multi-user level after restart without manual assistance, it will be scored zero if the test using virtual machine system cannot be restarted or be properly restarted. Corresponding distribution packages for the testing using operating system Red Hat Enterprise Linux version can be found in the following link: http://server1.group3.example.com/rhel Part of the requirements include host security, ensure your host security limit does not prevent the request to allow the host and network, although you correctly configured the network service but would have to allow the host or network is blocked, this also does not score. You will notice that some requirements which clearly do not allow services be accessed by service domain my133t.org, systems of this domain are in subnet 172.25.1.0/252.255.255.0, and systems of these subnets also belong to my 133t.org domain. PS: Notice that some test questions may depend on other exam questions, for example, you might be asked to perform a series of restrictions on a user, but this user creation may be required in other questions. For convenient identification, each exam question has some radio buttons to help you identify which questions you have already completed or not completed. Certainly, you do not need to care these buttons if you don't need them. Configure IPV6 Address Configure interface eth0 on your test system, using the following IPV6 addresses: 1. The address of system1 should be 2003:ac18::305/64 (2) The address of system2 should be 2003:ac18::30a/64 (3) Both two systems must be able to communicate with systems in network 2003:ac18/64 (4) The address must still take effect after restart (5) Both two systems must maintain the current Ipv4 address and can communicate
Reveal model answer
Close model answer
Explanation: 
Question 4
Lab simulation
Simulation Make on /storage directory that only the user owner and group owner member can fully access.
Reveal model answer
Close model answer
Explanation: 1. chmod 770 /storage 2. Verify using : ls -ld /storage Note: Preview should be like: drwxrwx--- 2 root sysusers 4096 Mar 16 18:08 /storage To change the permission on directory we use the chmod command. According to the question that only the owner user (root) and group member (sysusers) can fully access the directory so: chmod 770 /archive
Question 5
Lab simulation
Simulation RHCE Test Configuration Instructions Information for the two systems you will use in test is the following: system1.group3.example.com: is one of the main sever. system2.group3.example.com: mainly used as a client. Password for both of the two systems is atenorth System's IP is provided by DHCP, you can regard it as normal, or you can reset to Static IP in accordance with the following requirements: system1.group3.example.com: 172.24.3.5 system2.group3.example.com: 172.24.3.10 The subnet mask is 255.255.255.0 Your system is a member of DNS domain group3.example.com. All systems in DNS domain group3.example.com are all in subnet 172.24.3.0/255.255.255.0, the same all systems in this subnet are also in group3.example.com, unless specialized, all network services required to be configured can be accessed by systems of domain group3. host.group3.example.com provides a centralized authentication service domain GROUP3.EXAMPLE.COM, both system1 and system2 have already been pre-configured to be the client for this domain, this domain provides the following user account:  Firewall is enabled by default, you can turn it off when deemed appropriate, other settings about firewall may be in separate requirements. Your system will be restarted before scoring, so please ensure that all modifications and service configurations you made still can be operated after the restart without manual intervention, virtual machine instances of all examinations must be able to enter the correct multi-user level after restart without manual assistance, it will be scored zero if the test using virtual machine system cannot be restarted or be properly restarted. Corresponding distribution packages for the testing using operating system Red Hat Enterprise Linux version can be found in the following link: http://server1.group3.example.com/rhel Part of the requirements include host security, ensure your host security limit does not prevent the request to allow the host and network, although you correctly configured the network service but would have to allow the host or network is blocked, this also does not score. You will notice that some requirements which clearly do not allow services be accessed by service domain my133t.org, systems of this domain are in subnet 172.25.1.0/252.255.255.0, and systems of these subnets also belong to my 133t.org domain. PS: Notice that some test questions may depend on other exam questions, for example, you might be asked to perform a series of restrictions on a user, but this user creation may be required in other questions. For convenient identification, each exam question has some radio buttons to help you identify which questions you have already completed or not completed. Certainly, you do not need to care these buttons if you don't need them. Configure Security Web Service Configure a TLS encryption for the site http://systeml.domain11.example.com,encrypt/, get a signed certificate from http://host.domain11.example.com/materials/system1.crt. Get the certificate key from http://host.domain11.example.com/materials/system1.key. Get the signature authorization information of the certificate from http://host.domain11.example.com/materials/domain11.crt
Reveal model answer
Close model answer
Explanation: 
Question 6
Lab simulation
Simulation Expand your web service including a virtual hosting, the address ishttp://wwwX.example.com, X is the number of your exam machine. However, requiring you do as the following: -- Set up the DocumentRoot of this virtual hosting as /var/http/virtual--Downloadftp//instructor.example.com/pub/rhce/www.html -- Rename www.html file document as index.html -- Move this file document to this virtual hosting's DocumentRoot -- Don't do any changes to this document -- Making sure that harry users are able to create project in /var/http/virtual Attention: Original web address is http://serverX.example.com must also can be browsed. The DNS of the Server instructor.example.com has already been analyzed as the domain wwwX.example.com.
Reveal model answer
Close model answer
Explanation:  Notice: The priority level order of deny, allow is deployed: The back is higher than in front of the priority. It means allow -> deny
Question 7
Lab simulation
Simulation Make Secondary belongs the jeff and marion users on sysusers group. But harold user should not belongs to sysusers group.
Reveal model answer
Close model answer
Explanation: 1. usermod -G sysusers jeff 2. usermod -G sysuser marion 3. Verify by reading /etc/group file Note: Using usermod command we can make user belongs to different group. There are two types of group one primary and another is secondary. Primary group can be only one but user can belong to more than one group as secondary. usermod -g groupname username - To change the primary group of the user. usermod -G groupname username - To make user belongs to secondary group.
Question 8
Lab simulation
Simulation There were two systems: system1, main system on which most of the configuration take place system2, some configuration here  Script2. Create a script on serverX called /root/createusers. When this script is called with the argument, it should add all the users from the file Download the file from http://station.network0.example.com/pub/testfile All users should have the login shell as /bin/false, password not required. When this script is called with any other argument, it should print the message as "Input File Not Found" When this script is run without any argument, it should display "Usage:/root/createusers" NOTE: if the users are added no need to delete
Reveal model answer
Close model answer
Explanation: 
Question 9
Lab simulation
Simulation RHCE Test Configuration Instructions Information for the two systems you will use in test is the following: system1.group3.example.com: is one of the main sever. system2.group3.example.com: mainly used as a client. Password for both of the two systems is atenorth System's IP is provided by DHCP, you can regard it as normal, or you can reset to Static IP in accordance with the following requirements: system1.group3.example.com: 172.24.3.5 system2.group3.example.com: 172.24.3.10 The subnet mask is 255.255.255.0 Your system is a member of DNS domain group3.example.com. All systems in DNS domain group3.example.com are all in subnet 172.24.3.0/255.255.255.0, the same all systems in this subnet are also in group3.example.com, unless specialized, all network services required to be configured can be accessed by systems of domain group3. host.group3.example.com provides a centralized authentication service domain GROUP3.EXAMPLE.COM, both system1 and system2 have already been pre-configured to be the client for this domain, this domain provides the following user account:  Firewall is enabled by default, you can turn it off when deemed appropriate, other settings about firewall may be in separate requirements. Your system will be restarted before scoring, so please ensure that all modifications and service configurations you made still can be operated after the restart without manual intervention, virtual machine instances of all examinations must be able to enter the correct multi-user level after restart without manual assistance, it will be scored zero if the test using virtual machine system cannot be restarted or be properly restarted. Corresponding distribution packages for the testing using operating system Red Hat Enterprise Linux version can be found in the following link: http://server1.group3.example.com/rhel Part of the requirements include host security, ensure your host security limit does not prevent the request to allow the host and network, although you correctly configured the network service but would have to allow the host or network is blocked, this also does not score. You will notice that some requirements which clearly do not allow services be accessed by service domain my133t.org, systems of this domain are in subnet 172.25.1.0/252.255.255.0, and systems of these subnets also belong to my 133t.org domain. PS: Notice that some test questions may depend on other exam questions, for example, you might be asked to perform a series of restrictions on a user, but this user creation may be required in other questions. For convenient identification, each exam question has some radio buttons to help you identify which questions you have already completed or not completed. Certainly, you do not need to care these buttons if you don't need them. Configure SELINUX Modify the state of selinux to Enforcing mode. Use VIM /etc/selinux
Reveal model answer
Close model answer
Explanation: 
Question 10
Lab simulation
Simulation RHCE Test Configuration Instructions Information for the two systems you will use in test is the following: system1.group3.example.com: is one of the main sever. system2.group3.example.com: mainly used as a client. Password for both of the two systems is atenorth System's IP is provided by DHCP, you can regard it as normal, or you can reset to Static IP in accordance with the following requirements: system1.group3.example.com: 172.24.3.5 system2.group3.example.com: 172.24.3.10 The subnet mask is 255.255.255.0 Your system is a member of DNS domain group3.example.com. All systems in DNS domain group3.example.com are all in subnet 172.24.3.0/255.255.255.0, the same all systems in this subnet are also in group3.example.com, unless specialized, all network services required to be configured can be accessed by systems of domain group3. host.group3.example.com provides a centralized authentication service domain GROUP3.EXAMPLE.COM, both system1 and system2 have already been pre-configured to be the client for this domain, this domain provides the following user account:  Firewall is enabled by default, you can turn it off when deemed appropriate, other settings about firewall may be in separate requirements. Your system will be restarted before scoring, so please ensure that all modifications and service configurations you made still can be operated after the restart without manual intervention, virtual machine instances of all examinations must be able to enter the correct multi-user level after restart without manual assistance, it will be scored zero if the test using virtual machine system cannot be restarted or be properly restarted. Corresponding distribution packages for the testing using operating system Red Hat Enterprise Linux version can be found in the following link: http://server1.group3.example.com/rhel Part of the requirements include host security, ensure your host security limit does not prevent the request to allow the host and network, although you correctly configured the network service but would have to allow the host or network is blocked, this also does not score. You will notice that some requirements which clearly do not allow services be accessed by service domain my133t.org, systems of this domain are in subnet 172.25.1.0/252.255.255.0, and systems of these subnets also belong to my 133t.org domain. PS: Notice that some test questions may depend on other exam questions, for example, you might be asked to perform a series of restrictions on a user, but this user creation may be required in other questions. For convenient identification, each exam question has some radio buttons to help you identify which questions you have already completed or not completed. Certainly, you do not need to care these buttons if you don't need them. Configure the SSH Access as required: Users can visit your two virtual machine systems via clients of domain group3.example.com through SSH remote.
Reveal model answer
Close model answer
Explanation: Solution 1: Modify file /etc/hosts.allow Add a line: sshd: 172.24.11. Modify file /etc/hosts.deny Add a line: sshd: 172.25.0. Both of them need to be configured. Solution 2: Add a firewall firewall-cmd -zone=block --add-source=172.25.11.0/24 --permanent firewall-cmd -reload Both of them need to be configured
Question 11
Lab simulation
Simulation RHCE Test Configuration Instructions Information for the two systems you will use in test is the following: system1.group3.example.com: is one of the main sever. system2.group3.example.com: mainly used as a client. Password for both of the two systems is atenorth System's IP is provided by DHCP, you can regard it as normal, or you can reset to Static IP in accordance with the following requirements: system1.group3.example.com: 172.24.3.5 system2.group3.example.com: 172.24.3.10 The subnet mask is 255.255.255.0 Your system is a member of DNS domain group3.example.com. All systems in DNS domain group3.example.com are all in subnet 172.24.3.0/255.255.255.0, the same all systems in this subnet are also in group3.example.com, unless specialized, all network services required to be configured can be accessed by systems of domain group3. host.group3.example.com provides a centralized authentication service domain GROUP3.EXAMPLE.COM, both system1 and system2 have already been pre-configured to be the client for this domain, this domain provides the following user account:  Firewall is enabled by default, you can turn it off when deemed appropriate, other settings about firewall may be in separate requirements. Your system will be restarted before scoring, so please ensure that all modifications and service configurations you made still can be operated after the restart without manual intervention, virtual machine instances of all examinations must be able to enter the correct multi-user level after restart without manual assistance, it will be scored zero if the test using virtual machine system cannot be restarted or be properly restarted. Corresponding distribution packages for the testing using operating system Red Hat Enterprise Linux version can be found in the following link: http://server1.group3.example.com/rhel Part of the requirements include host security, ensure your host security limit does not prevent the request to allow the host and network, although you correctly configured the network service but would have to allow the host or network is blocked, this also does not score. You will notice that some requirements which clearly do not allow services be accessed by service domain my133t.org, systems of this domain are in subnet 172.25.1.0/252.255.255.0, and systems of these subnets also belong to my 133t.org domain. PS: Notice that some test questions may depend on other exam questions, for example, you might be asked to perform a series of restrictions on a user, but this user creation may be required in other questions. For convenient identification, each exam question has some radio buttons to help you identify which questions you have already completed or not completed. Certainly, you do not need to care these buttons if you don't need them. Configure Multi-User SMB Mounts. Share the directory /devops through SMB on the systeml, as required: 1. The share name is devops 2. The shared directory devops just can be used by clients in domain11.example.com 3. The shared directory devop must be able to be browsed 4. User silene must be able to access this share through read, access code is redhat 5. User akira must be able to access this share through read and write, access code is redhat 6. This share permanently mount to system2. domain11.example.com the user /mnt/dev, make user silene as authentication any users can get temporary write permissions from akira
Reveal model answer
Close model answer
Explanation: system1  system2:  Switch to user akira on the system2, access to /mnt/dev and view files su akira cd /mnt/dev ls cifscreds add system1 touch 1
Question 12
Lab simulation
Simulation Whoever creates the file on /data make automatically owner group should be the group owner of /data directory.
Reveal model answer
Close model answer
Explanation: When user creates the file/directory, user owner will be user itself and group owner will be the primary group of the user. There is one Special Permission SGID, when you set the SGID bit on directory. When users create the file/ directory automatically owner group will be same as a parent. 1. chmod g+s /data 2. Verify using: ls -ld /data You will get: drwxrws---
Question 13
Lab simulation
Simulation Add a cron schedule to take full backup of /home on every day at 5:30 pm to /dev/st0 device.
Reveal model answer
Close model answer
Explanation: 1. vi /var/schedule 30 17 * * * /sbin/dump -0u /dev/st0 /dev/hda7 2. crontab /var/schedule 3. service crond restart We can add the cron schedule either by specifying the scripts path on /etc/crontab file or by creating on text file on crontab pattern. cron helps to schedule on recurring events. Pattern of cron is: Minute Hour Day of Month Month Day of Week Commands 0-59 0-23 1-31 1-12 0-7 where 0 and 7 mean Sunday. Note * means every. To execute the command on every two minutes */2.
Question 14
Lab simulation
Simulation One Logical Volume is created named as myvol under vo volume group and is mounted. The Initial Size of that Logical Volume is 400MB. Make successfully that the size of Logical Volume 200MB without losing any data. The size of logical volume 200MB to 210MB will be acceptable.
Reveal model answer
Close model answer
Explanation: 
|