A financial services company is using Samba as a domain member server to provide access to sensitive audit logs. A requirement exists to prevent users from permanently deleting files, instead moving them to a per-user, date-stamped recycle bin directory located within their own home directory. The home directories are on a separate, faster storage tier. Which VFS module and configuration parameter would achieve this specific requirement?
Answer and explanation
Correct answer: D
The vfs objects = recycle parameter enables the recycle bin functionality. To meet the requirement of storing deleted files in a user-specific home directory location with a date stamp, the recycle:repository path must be constructed using Samba variables. /home/%U/recycle_bin/%d correctly uses %U for the username and %d for the current date, placing the recycled files on the separate storage tier where home directories reside. The other options either use a centralized repository, a relative path within the share, or incorrectly use the shadow_copy2 module which is for versioning, not a recycle bin.
Question 2
An administrator is configuring an SSSD client to authenticate against a FreeIPA domain. A key requirement is that users must be able to log in using their short name (e.g., 'jdoe') instead of the fully qualified name ('[email protected]'). However, the system must still enforce that only users from the 'ipa.example.com' domain are queried. Which sssd.conf parameter, when set to true, achieves this behavior?
Answer and explanation
Correct answer: B
The use_fully_qualified_names parameter controls whether SSSD returns qualified or non-qualified user names. Setting it to false allows users to log in with their short names. The domain part is still implicitly managed by SSSD's domain configuration, ensuring that lookups are directed to the correct FreeIPA domain. re_expression is for filtering, default_domain_suffix appends a domain, and full_name_format controls how the GECOS field is constructed, not the login name format.
Question 3
A university has a FreeIPA domain for its staff (staff.university.edu) and a separate Active Directory domain for its students (students.university.edu). The goal is to allow staff members to access a Samba file server that is a member of the student AD domain, using their staff credentials. Which FreeIPA and Samba feature is required to make this cross-domain authentication possible?
Answer and explanation
Correct answer: C
This scenario requires identities from one Kerberos realm (FreeIPA) to be authenticated by a service in another realm (the Samba server in AD). This is the primary use case for a cross-realm trust. By establishing a trust, the AD domain controllers can validate Kerberos tickets issued by the FreeIPA KDC, allowing staff members to access resources in the student domain. SSSD is involved on the client side, but the fundamental enabling technology is the trust relationship. A FreeIPA replica cannot be placed in an AD domain.
Question 4
Multiple answers
A consultant needs to securely mount a Windows SMB share on a Linux client using Kerberos authentication. The client is already joined to the Active Directory domain and the user can successfully run kinit. Which of the following mount.cifs command lines is the correct syntax to mount the share using Kerberos? (Select TWO).
Answer and explanation
Correct answers: B, D
sec=krb5 explicitly tells mount.cifs to use Kerberos v5 authentication. It will use the ticket from the user's ccache.
sec=krb5i specifies Kerberos v5 authentication with packet integrity signing, which is a more secure variant. The multi-user option is also commonly used in this context but not strictly required for Kerberos itself.
Question 5
When configuring a secure NFSv4 export on a server that is part of a FreeIPA domain, which mechanism is used to translate user and group names to numeric IDs between the client and server, avoiding mismatches?
Answer and explanation
Correct answer: B
In a modern FreeIPA environment, the traditional rpc.idmapd daemon is often replaced by SSSD's capabilities. SSSD can handle the translation between NFSv4's user@domain string principals and the local system's numeric UID/GIDs. This provides a centralized and consistent mapping source, which is crucial in an identity-managed environment like FreeIPA. The other options are either legacy methods or not directly related to NFSv4 ID mapping.
Question 6
A system administrator is troubleshooting a Samba file share. Users report that they cannot see certain files they know exist and to which they have read permissions at the filesystem level. The administrator suspects a Samba configuration issue is hiding these files. Which parameter in smb.conf is the most likely cause of this behavior?
Answer and explanation
Correct answer: B
The veto files parameter instructs Samba to hide files and directories that match the specified patterns, making them invisible and inaccessible to SMB clients, regardless of filesystem permissions. If a pattern in this list inadvertently matches legitimate files, they will disappear from the users' view. hide unreadable hides files the user cannot read, but the scenario states they have read permissions. dont descend applies to directories, and case sensitive = yes affects name matching, not visibility.
Question 7
True or False: When a Linux client uses SSSD to connect to an Active Directory domain, the ad_access_filter option in sssd.conf can be used to restrict access based on a user's AD group membership using a standard LDAP filter.
Answer and explanation
Correct answer: A
True. The ad_access_filter parameter allows an administrator to specify a custom LDAP filter that is evaluated against the user object in Active Directory during the access control phase. A common use case is to restrict logins to members of a specific AD group, for example: ad_access_filter = (memberOf=cn=LinuxUsers,ou=Groups,dc=example,dc=com). This is a powerful method for controlling access to Linux systems from Active Directory.
Question 8
An organization is migrating from a legacy NIS-based identity management system to FreeIPA. To ensure a smooth transition, they want to continue serving NIS clients from the FreeIPA servers. What must be configured on the FreeIPA server to enable this functionality?
Answer and explanation
Correct answer: C
FreeIPA includes a compatibility tree and services to respond to NIS client requests. This functionality must be explicitly enabled. This can be done during the initial server installation by answering 'yes' to configuring the NIS domain and server, or by passing the --setup-nis flag to ipa-server-install. This configures the schema and starts the necessary services (ypserv) to serve NIS maps from the FreeIPA LDAP backend.
Question 9
A system administrator needs to troubleshoot a failing Samba domain provision process. To get the most detailed output possible during the samba-tool domain provision command, which command-line option should be used?
Answer and explanation
Correct answer: B
Most Samba command-line tools, including samba-tool, use the -d or --debuglevel= option to control the verbosity of logging output. A debug level of 10 provides the maximum amount of detail, which is essential for diagnosing complex issues during processes like domain provisioning. --verbose is a common flag in many Linux utilities but is not the primary mechanism for detailed debugging in Samba. --log-stdout redirects logs but does not set the level, and --show-progress only affects progress indicators.
Question 10
Case Study:
A medium-sized media production company, 'CreativeFrames', is restructuring its IT infrastructure. They have an existing Windows Active Directory domain (corp.creativeframes.com) used for workstations and administrative staff. The video editing department uses a fleet of high-performance Linux workstations and needs access to a large, high-speed storage server running Linux.
Current Situation: The Linux workstations currently authenticate against a legacy OpenLDAP server, and home directories are provided via NFSv3. This setup is unreliable, and managing user identities across AD and OpenLDAP is a significant administrative burden. The storage server is a standalone Samba server using security = user with a local smbpasswd file, requiring separate credentials.
Requirements:
Consolidate user identity management. All users (AD and Linux-specific) should be managed from a single point of truth where possible.
Linux users must be able to log into their workstations using their primary corporate credentials.
The new storage solution must support Windows ACLs to provide granular permissions for cross-departmental projects.
The solution should provide centralized management for sudo rules and automount maps for the Linux workstations.
Constraints:
The existing Active Directory domain must remain the primary identity source for corporate users.
A complete migration away from AD is not an option.
Which solution best meets all of CreativeFrames' requirements?
Answer and explanation
Correct answer: C
This solution meets all requirements. Deploying FreeIPA and establishing a trust with AD allows for consolidated identity management while respecting the constraint that AD remains primary. Linux clients authenticating against FreeIPA (via SSSD) can leverage its centralized management for sudo and automount maps. Because of the trust, AD users can authenticate to IPA-enrolled clients and services. The Samba server, joined to the IPA realm, can authenticate both IPA and trusted AD users and can be configured to support Windows ACLs (vfs_acl_xattr). This eliminates the need for OpenLDAP and the local smbpasswd file.