A legacy host runs in.telnetd under xinetd. The service must stay enabled, but only clients in the management network 10.0.5.0/24 may reach it. Which attribute in /etc/xinetd.d/telnet expresses that?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct only_from = 10.0.5.0/24

Correct. only_from lists the remote addresses to which the service is offered. Anything not listed is refused before the server program is started.

Not correct no_access = 10.0.5.0/24

Wrong, and inverted. no_access lists the remote addresses that must be refused, so this line would block precisely the management network and admit everyone else.

Not correct bind = 10.0.5.0

Wrong. bind (also spelled interface) names a local address on this host for the service to listen on. It restricts which of the server's own interfaces answer, not which clients may connect.

Not correct access_times = 10:00-05:24

Wrong. access_times restricts the hours of the day during which the service may be used. It is a real xinetd attribute but has nothing to do with source addresses.

Why

xinetd carries its own access control, so a wrapped service can be filtered without TCP wrappers: only_from is the allow list and no_access the deny list, and if an address matches both the more specific mask wins. Contrast this with bind, which chooses a local listening address. Each service gets its own file under the directory named by the includedir line in /etc/xinetd.conf.

Where this comes from

Cited
manual page xinetd.conf(5)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500