An application connects to `licence.example.com` without trouble, yet `dig licence.example.com` returns NXDOMAIN. Which command best confirms where the working answer is actually coming from?

LPIC-1 Exam 102-500, objective 109. Networking fundamentals medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct getent hosts licence.example.com

Correct. getent resolves through the Name Service Switch, exactly as the application's library calls do, so it shows the answer that /etc/hosts or any other configured source supplies.

Not correct dig +short licence.example.com

Wrong. +short only trims dig's output. dig speaks to name servers directly and never consults /etc/hosts or nsswitch.conf, so it will keep reporting NXDOMAIN.

Not correct host -a licence.example.com

Wrong. host is another DNS client; -a requests all records over DNS. Like dig, it bypasses the NSS sources entirely.

Not correct nslookup -debug licence.example.com

Wrong. nslookup is a third DNS-only client. More debug output about a DNS query cannot reveal a non-DNS source of the answer.

Why

dig, host and nslookup are DNS troubleshooting tools: they build a DNS query and send it to a name server, ignoring /etc/nsswitch.conf and /etc/hosts. Ordinary programs instead call getaddrinfo, which walks the sources on the hosts line of nsswitch.conf. getent hosts drives the same NSS path from the shell, which is why a name that resolves for applications but not for dig is almost always coming from /etc/hosts or another non-DNS source.

Where this comes from

Cited
manual page getent(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 109 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Networking fundamentals

Practise LPIC-1 Exam 102-500