On a host using TCP wrappers, /etc/hosts.deny contains `ALL: ALL` and /etc/hosts.allow contains `sshd: 192.168.1.`. A wrapped connection arrives from 192.168.1.50 for sshd. What happens?

LPIC-1 Exam 102-500, objective 110. Security hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct It is denied, because hosts.deny is consulted first and ALL: ALL matches.

Wrong. The order is the other way round: hosts.allow is always consulted first.

Not correct It is denied, because a client must be permitted in both files to be allowed through.

Wrong. The files are not an intersection. The first rule that matches, in either file, decides the outcome and the search stops there.

Not correct It is allowed, but only after the wrapped daemon is restarted, because both files are read once at startup.

Wrong. hosts.allow and hosts.deny are consulted afresh for every connection, so edits take effect immediately with no restart.

Correct It is allowed, because hosts.allow is checked first and the first matching rule wins, so the deny rule is never reached.

Correct. libwrap scans hosts.allow, finds the sshd rule matching the 192.168.1. prefix, grants access and stops.

Why

The TCP wrappers algorithm is: check /etc/hosts.allow, and on the first matching rule allow the connection; otherwise check /etc/hosts.deny, and on the first matching rule deny it; if neither matches, allow. That default-allow is why the deny-all-then-allow-selected pattern shown here is the usual configuration. Rules are `daemon_list : client_list`, where a client pattern ending in a dot matches a network prefix and one beginning with a dot matches a domain suffix. Only programs linked against libwrap, or services launched through tcpd from inetd, honour these files at all — TCP wrappers is not a packet filter and does not replace iptables or nftables.

Where this comes from

Cited
LPI exam objective 110.2
What it says
Control access to wrapped services with /etc/hosts.allow and /etc/hosts.deny.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500