On a host using TCP wrappers, /etc/hosts.deny contains only the line `in.telnetd: ALL` and /etc/hosts.allow is empty. A wrapped FTP daemon receives a connection from 203.0.113.9. What happens?

LPIC-1 Exam 102-500, objective 110. Security medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct The connection is permitted, because no rule in either file matches the pair of daemon and client.

Correct. Access is granted when a match is found in hosts.allow, denied when a match is found in hosts.deny, and granted in the remaining case where neither file matches.

Not correct The connection is refused, because an empty /etc/hosts.allow means nothing is allowed.

Wrong. An empty allow file simply produces no match; it is not read as a blanket denial. Deny-by-default has to be written explicitly as `ALL: ALL` in hosts.deny.

Not correct The connection is refused, because a daemon named in hosts.deny causes all wrapped services to be denied.

Wrong. The daemon field selects which service a rule applies to. A rule naming in.telnetd is evaluated only for in.telnetd.

Not correct The connection is permitted only if 203.0.113.9 has a reverse DNS record that resolves back to the same address.

Wrong. Name lookups matter when a rule uses a host name or domain pattern, and a mismatch yields the special PARANOID pattern, but here no rule matches at all so nothing is looked up.

Why

The wrapper evaluates hosts.allow first and stops at the first match, then hosts.deny, again stopping at the first match; if neither file matches the request is allowed. That default is why a hardening posture starts by writing `ALL: ALL` into hosts.deny and then opening specific services in hosts.allow, rather than relying on the deny file alone.

Where this comes from

Cited
manual page hosts_access(5)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500