You ran systemctl disable --now ssh.service on a host, yet after a reboot connections to port 22 are still accepted, and an sshd process only appears in the process list once a client connects. What explains this, and what stops it?
LPIC-1 Exam 102-500, objective 110. Security hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct The unit ssh.socket is enabled and holds port 22 itself, spawning a service instance per connection; run systemctl disable --now ssh.socket.
Correct. A socket unit owns the listening socket and systemd starts the matching service only when traffic arrives, which is why nothing is running until a client connects. Disabling the service unit leaves the socket unit untouched.
Not correct disable only removes the enablement symlinks, so the old sshd survived the reboot; run systemctl stop ssh.service.
Wrong. --now already stopped the service, and no process survives a reboot. It also fails to explain why sshd appears only after a connection arrives.
Not correct The vendor preset re-enables ssh.service at every boot; run systemctl preset ssh.service.
Wrong. Presets are applied when a package is installed or when systemctl preset is run explicitly, not on each boot, and systemctl preset would simply reapply the vendor's default anyway.
Not correct xinetd is intercepting port 22 and starting sshd on demand; comment out the includedir line in /etc/xinetd.conf.
Wrong here, although the described behaviour is genuinely how a superdaemon works. Removing the includedir line would also disable every other xinetd service rather than one, and systemctl status ssh.socket would have shown the real owner of the port.
Why
Socket activation is the systemd successor to inetd and xinetd: the .socket unit listens, and the .service unit is started on demand when a connection arrives. Because the two units are enabled and disabled independently, a service can look thoroughly disabled while its socket still answers. Always check both names, for example with systemctl list-units 'ssh*', before concluding a port is closed.
Where this comes from
- Cited
- manual page systemd.socket(5)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.
More questions on this objective
- During an audit you must list every file under /usr that has the set-user-ID bit set, regardless of what its other permission bits are. Which command does that? machine-checked
- You locked the password of the account `intern` and confirmed that its hash in /etc/shadow now begins with an exclamation mark. The intern nevertheless still reaches a shell on the host over SSH, without being prompted for anything. What is going on, and what actually stops it? machine-checked
- You have just been added to a sudo rule on a host and want sudo itself to report which commands you are allowed to run there, without running any of them. Type the complete command. machine-checked
- A daemon started from your bash session keeps hitting a 'too many open files' error. Which command raises the limit on open file descriptors for the current shell and the processes it starts to 4096? machine-checked
- You are about to take a server down for maintenance and want ordinary users refused at login for the next hour, with an explanatory message, while root can still get in. On a system using PAM's pam_nologin, creating which file achieves this? machine-checked
- Which two commands report the users who are logged in right now, rather than a history of past logins? (Choose two.) machine-checked