A system running systemd-resolved carries the line `hosts: resolve [!UNAVAIL=return] files dns` in /etc/nsswitch.conf. What is the effect of the bracketed action?
LPIC-1 Exam 102-500, objective 109. Networking fundamentals hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct The files and dns sources are consulted only when the resolve module is unavailable
Correct. The exclamation mark negates the status, so the rule reads: for any status other than UNAVAIL, return the result of resolve at once. Only when resolve is unavailable does the search fall through to files and dns.
Not correct The search stops immediately, returning nothing, whenever resolve reports UNAVAIL
Wrong. That is what an unnegated [UNAVAIL=return] would mean. The leading exclamation mark inverts the status match.
Not correct It repeats the query against resolve until the module becomes available
Wrong. NSS actions are one of return, continue or merge. There is no retry action, and no source is ever queried twice for the same lookup.
Not correct It marks the resolve entry as optional, so a missing module is not logged as an error
Wrong. The bracketed syntax controls flow between sources; it says nothing about logging. A missing NSS module simply yields the UNAVAIL status.
Why
An /etc/nsswitch.conf source may be followed by [STATUS=ACTION] pairs, where the statuses are success, notfound, unavail and tryagain and the actions are return, continue and merge. Prefixing a status with an exclamation mark negates it, so the pair matches every other status. The defaults are [SUCCESS=return] and [NOTFOUND=continue], which is why an unqualified list keeps trying the next source until one succeeds.
Where this comes from
- Cited
- manual page nsswitch.conf(5)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 109 and space the ones you get wrong.
More questions on this objective
- A subnet is defined as 192.168.10.0/26. How many addresses in it can actually be assigned to hosts? machine-checked
- A host is configured with the address 172.20.35.77/20. What is the network address of its subnet? machine-checked
- In IPv6, which address is the loopback address, equivalent in role to 127.0.0.1 in IPv4? machine-checked
- Which is the correct fully compressed form of the IPv6 address 2001:0db8:0000:0000:0000:ff00:0042:8329? machine-checked
- Which pairing of a service with its default port number is correct? machine-checked
- DNS normally uses UDP port 53. In which situation does a DNS client or server fall back to TCP on port 53? machine-checked