A legacy host runs its telnet service under xinetd, configured in /etc/xinetd.d/telnet. Which change turns the service off while keeping the configuration file in place?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct Add or set `disable = yes` inside the service block, then reload xinetd.

Correct. disable = yes is the per-service switch xinetd reads. Reloading xinetd (or sending it SIGHUP) makes it stop listening on that port.

Not correct Set `wait = yes` inside the service block.

Wrong. wait selects the threading model: yes means xinetd hands the socket to a single-threaded server and waits for it to exit (typical for UDP), no means it forks a new server per connection (typical for TCP). It does not disable anything.

Not correct Comment the telnet line out of /etc/inetd.conf.

Wrong on this host. /etc/inetd.conf is the configuration of the older inetd superserver, which xinetd replaces. xinetd never reads it, so the service keeps running.

Not correct Set `server = /bin/false` inside the service block.

Wrong. server names the program xinetd executes for each connection. xinetd would still accept connections on the telnet port and simply run /bin/false, so the port stays open.

Why

xinetd keeps one file per service under /etc/xinetd.d, included by /etc/xinetd.conf, and each block carries attributes such as socket_type, protocol, user, server, server_args, wait and disable. The classic inetd instead uses single lines in /etc/inetd.conf, which you disable by commenting out and then signalling inetd to re-read its configuration. On current systemd distributions both superservers are largely gone: services are units, and you disable one permanently with `systemctl disable --now telnet.socket`.

Where this comes from

Cited
LPI exam objective 110.2
What it says
Turn off unused network services offered by inetd or xinetd.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500