300-300 Practice Questions
Prepare for 300-300 with more than an answer.
Unlock the full exam and previous versions
- v1Version 1 233 questions Current
- 300-100Legacy Exam 300: Mixed Environments v2.0 48 questions Locked
- Exam fee
- $200 USD
- Level
- Expert
- Valid for
- 5 years
Domains covered on the exam 5
- Topic 301: Samba Basics18%
- Topic 302: Samba and Active Directory Domains28%
- Topic 303: Samba Share Configuration17%
- Topic 304: Samba Client Configuration18%
- Topic 305: Linux Identity Management and File Sharing19%
- 1
A user on a Linux workstation, which is configured to use SSSD for authentication against a FreeIPA domain, is working in a location with an unstable network connection. Which SSSD feature allows the user to continue logging in and working even when the FreeIPA servers are unreachable?
Show answer details
Correct answer: B
A core feature of SSSD is its ability to cache user credentials (typically a hash of the password) and identity information (UID, GID, group memberships) locally. When a user successfully authenticates while online, SSSD caches this data. If the network connection to the identity provider is lost, SSSD can authenticate the user against the local cache, allowing for offline logins. This is controlled by the
cache_credentials = truesetting insssd.conf, which is the default for most providers. - 2
You are configuring a Samba server and want to verify the correctness of your
smb.conffile, checking for syntax errors and validating parameter values before restarting the service. Which command should you use?Show answer details
Correct answer: C
The
testparmutility is specifically designed to parse and validate asmb.conffile. Runningtestparm(ortestparm -sto suppress the full dump of service definitions and just show processing information) will report any syntax errors or invalid parameters. It is a critical first step before applying a new configuration to a production Samba server. - 3
What is the function of the
idmap_sssmodule when integrating a Samba file server with a FreeIPA domain?Show answer details
Correct answer: B
When Samba operates in a domain, it deals with Windows Security Identifiers (SIDs). The Linux kernel, however, understands User IDs (UIDs) and Group IDs (GIDs). The
idmap_sssbackend for Winbind allows Samba'swinbinddprocess to communicate with thesssddaemon. SSSD, which is already handling identity information from FreeIPA (and any trusted domains), performs the authoritative mapping between SIDs and UIDs/GIDs. This ensures that Samba and the rest of the Linux system have a consistent view of user identities. - 4
A Samba administrator wants to ensure that all files created in a specific share have a minimum set of permissions, specifically
rw-r-----(0640), regardless of the umask of the connecting client. Whichsmb.confparameter should be used to enforce this?Show answer details
Correct answer: C
The
create maskparameter defines the maximum permissions that are allowed when a file is created. It works by performing a bitwise AND with the permissions requested by the client. To enforce a minimum set of permissions, you should useforce create mode, which performs a bitwise OR. However, the question asks to ensure permissions of0640, which is often achieved by settingcreate maskandforce create modetogether. Among the given options,create maskis the parameter used to control permissions on file creation. If the goal is a strict0640, one would typically usecreate mask = 0640andforce create mode = 0640. Given the choices,create mask = 0640is the most relevant parameter for controlling file creation permissions. Correction: The best way to ensure minimum permissions isforce create mode. However,create maskis the standard tool to limit permissions. A better interpretation for enforcing a specific mode is to usecreate maskto limit what the client can set andforce create modeto add bits. In many contextscreate maskis used to define the final permissions. Let's reconsider.force create modeadds permissions.create maskremoves permissions. To get exactly 0640, you would setcreate mask = 0777andforce create mode = 0640. No, that's not right. The final permissions are(mode | force create mode) & create mask. To guarantee 0640, you would useforce create mode = 0640andcreate mask = 0640. Since only one is an option, let's re-evaluate the common usage.create maskis used to set the permissions on creation, similar to umask.force create modeis used to ensure certain bits are always set. The most direct answer to set the mode iscreate mask. Let's assume the client requests 0666.0666 & 0640results in0640. This works.force create modewould add bits, which isn't what's asked. Therefore,create maskis the correct answer to define the permissions on creation. - 5
Case Study:
A software development startup, 'CodeWeavers', uses a FreeIPA domain (
ipa.codeweavers.local) for centralized identity management for all its Linux developers and servers. The company has just acquired a small quality assurance (QA) team that was using a standalone Samba server (smb-qa) for storing test cases and reports. The Samba server authenticates users against its localsmbpasswdfile.Current Situation:
- The FreeIPA domain manages all developer identities.
- The
smb-qaserver is not joined to any domain. - The QA team's user accounts exist only on
smb-qa.
Requirements:
- All user authentication for the
smb-qaserver must be handled by the FreeIPA domain to eliminate local password management. - Developers from the 'dev' group in FreeIPA need read-only access to the QA shares.
- QA team members, now in the 'qa-team' group in FreeIPA, need read-write access.
- The existing data and share structure on
smb-qamust be preserved. - The solution should not require establishing a full Active Directory trust.
Which strategy is the most appropriate and direct way to meet all requirements?
graph TD subgraph FreeIPA Domain [ipa.codeweavers.local] IPA_Server[IPA Server] Dev_User[Developer] QA_User[QA User] end subgraph Standalone Samba_QA[smb-qa Server] end Dev_User -->|Needs Access| Samba_QA QA_User -->|Needs Access| Samba_QA Samba_QA -.->|Current: Local Auth| local_db[(smbpasswd)] IPA_Server -.->|Goal: Central Auth| Samba_QAShow answer details
Correct answer: D
This is the correct, modern approach for integrating a Samba server with a FreeIPA domain without a full AD trust. Enrolling the server as an IPA client provides Kerberos and identity information via SSSD. Configuring Samba with
security = ads(which works for any Kerberos realm) and theidmap_sssbackend allows Samba to directly and efficiently leverage SSSD for SID-to-UID/GID mapping. This avoids data migration, eliminates local passwords, and allows share permissions to be managed with central FreeIPA groups, meeting all requirements. - 6
A financial services company is using Samba as a domain member server to provide access to sensitive audit logs. A requirement exists to prevent users from permanently deleting files, instead moving them to a per-user, date-stamped recycle bin directory located within their own home directory. The home directories are on a separate, faster storage tier. Which VFS module and configuration parameter would achieve this specific requirement?
Show answer details
Correct answer: D
The
vfs objects = recycleparameter enables the recycle bin functionality. To meet the requirement of storing deleted files in a user-specific home directory location with a date stamp, therecycle:repositorypath must be constructed using Samba variables./home/%U/recycle_bin/%dcorrectly uses%Ufor the username and%dfor the current date, placing the recycled files on the separate storage tier where home directories reside. The other options either use a centralized repository, a relative path within the share, or incorrectly use theshadow_copy2module which is for versioning, not a recycle bin. - 7
An administrator is configuring an SSSD client to authenticate against a FreeIPA domain. A key requirement is that users must be able to log in using their short name (e.g., 'jdoe') instead of the fully qualified name ('[email protected]'). However, the system must still enforce that only users from the 'ipa.example.com' domain are queried. Which
sssd.confparameter, when set totrue, achieves this behavior?Show answer details
Correct answer: B
The
use_fully_qualified_namesparameter controls whether SSSD returns qualified or non-qualified user names. Setting it tofalseallows users to log in with their short names. The domain part is still implicitly managed by SSSD's domain configuration, ensuring that lookups are directed to the correct FreeIPA domain.re_expressionis for filtering,default_domain_suffixappends a domain, andfull_name_formatcontrols how the GECOS field is constructed, not the login name format. - 8
A university has a FreeIPA domain for its staff (
staff.university.edu) and a separate Active Directory domain for its students (students.university.edu). The goal is to allow staff members to access a Samba file server that is a member of the student AD domain, using their staff credentials. Which FreeIPA and Samba feature is required to make this cross-domain authentication possible?Show answer details
Correct answer: C
This scenario requires identities from one Kerberos realm (FreeIPA) to be authenticated by a service in another realm (the Samba server in AD). This is the primary use case for a cross-realm trust. By establishing a trust, the AD domain controllers can validate Kerberos tickets issued by the FreeIPA KDC, allowing staff members to access resources in the student domain. SSSD is involved on the client side, but the fundamental enabling technology is the trust relationship. A FreeIPA replica cannot be placed in an AD domain.
- 9
A consultant needs to securely mount a Windows SMB share on a Linux client using Kerberos authentication. The client is already joined to the Active Directory domain and the user can successfully run
kinit. Which of the followingmount.cifscommand lines is the correct syntax to mount the share using Kerberos? (Select TWO).Show answer details
Correct answer: B, D
sec=krb5explicitly tellsmount.cifsto use Kerberos v5 authentication. It will use the ticket from the user's ccache.sec=krb5ispecifies Kerberos v5 authentication with packet integrity signing, which is a more secure variant. Themulti-useroption is also commonly used in this context but not strictly required for Kerberos itself. - 10
When configuring a secure NFSv4 export on a server that is part of a FreeIPA domain, which mechanism is used to translate user and group names to numeric IDs between the client and server, avoiding mismatches?
Show answer details
Correct answer: B
In a modern FreeIPA environment, the traditional
rpc.idmapddaemon is often replaced by SSSD's capabilities. SSSD can handle the translation between NFSv4'suser@domainstring principals and the local system's numeric UID/GIDs. This provides a centralized and consistent mapping source, which is crucial in an identity-managed environment like FreeIPA. The other options are either legacy methods or not directly related to NFSv4 ID mapping.
