A legacy host runs its telnet service under xinetd, configured in /etc/xinetd.d/telnet. Which change turns the service off while keeping the configuration file in place?
LPIC-1 Exam 102-500, objective 110. Security medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct Add or set `disable = yes` inside the service block, then reload xinetd.
Correct. disable = yes is the per-service switch xinetd reads. Reloading xinetd (or sending it SIGHUP) makes it stop listening on that port.
Not correct Set `wait = yes` inside the service block.
Wrong. wait selects the threading model: yes means xinetd hands the socket to a single-threaded server and waits for it to exit (typical for UDP), no means it forks a new server per connection (typical for TCP). It does not disable anything.
Not correct Comment the telnet line out of /etc/inetd.conf.
Wrong on this host. /etc/inetd.conf is the configuration of the older inetd superserver, which xinetd replaces. xinetd never reads it, so the service keeps running.
Not correct Set `server = /bin/false` inside the service block.
Wrong. server names the program xinetd executes for each connection. xinetd would still accept connections on the telnet port and simply run /bin/false, so the port stays open.
Why
xinetd keeps one file per service under /etc/xinetd.d, included by /etc/xinetd.conf, and each block carries attributes such as socket_type, protocol, user, server, server_args, wait and disable. The classic inetd instead uses single lines in /etc/inetd.conf, which you disable by commenting out and then signalling inetd to re-read its configuration. On current systemd distributions both superservers are largely gone: services are units, and you disable one permanently with `systemctl disable --now telnet.socket`.
Where this comes from
- Cited
- LPI exam objective 110.2
- What it says
- Turn off unused network services offered by inetd or xinetd.
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.
More questions on this objective
- During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that? machine-checked
- You locked the password of the account `intern` and confirmed that its hash in /etc/shadow now begins with an exclamation mark. The intern nevertheless still reaches a shell on the host over SSH, without being prompted for anything. What is going on, and what actually stops it? machine-checked
- You have just been added to a sudo rule on a host and want sudo itself to report which commands you are allowed to run there, without running any of them. Type the complete command. machine-checked
- A daemon started from your bash session keeps hitting a 'too many open files' error. Which command raises the limit on open file descriptors for the current shell and the processes it starts to 4096? machine-checked
- You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this? machine-checked
- Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.) machine-checked