Skip to content

303-300 LPIC-3 Security v3.0 Practice Questions

Prepare for 303-300 with more than an answer.

120 questions in the full set1 sample questionsUpdated Jan 26, 2026

Unlock the full exam and previous versions

  • v1LPIC-3 Security v3.0 120 questions Current
  • 303-200Legacy LPIC-3 Security v2.0 60 questions Locked
Exam fee
$200 USD
Level
Expert
Valid for
5 years
Domains covered on the exam 5
  1. Cryptography28.33%
  2. Host Security21.67%
  3. Access Control13.33%
  4. Network Security28.33%
  5. Threats and Vulnerability Assessment8.33%
  1. 1

    An organization is building its own Public Key Infrastructure (PKI). The security architect has designed a two-tier hierarchy with an offline Root CA and an online Intermediate CA. The Intermediate CA will be responsible for signing certificates for all internal web servers.

    The diagram below shows the intended signing process. What is the most critical security measure for protecting the long-term integrity of this entire PKI?

    graph TD subgraph "Offline / Air-gapped" RootCA[Root CA Certificate & Private Key] end subgraph "Online Network" IntermediateCA[Intermediate CA Certificate & Private Key] WebServerCert[Web Server Certificate] end RootCA --"Signs"--> IntermediateCA IntermediateCA --"Signs"--> WebServerCert

    Show answer details

    Correct answer: A

    The entire trust of a PKI rests on the security of the Root CA's private key. If this key is compromised, an attacker can issue fraudulent certificates that will be trusted by all clients, completely undermining the infrastructure. Therefore, the most critical security control is to keep the Root CA offline, powered down, and physically secured in an air-gapped environment. It should only be brought online in a controlled manner to sign a new Intermediate CA certificate or to update the Certificate Revocation List (CRL).

Create an account to continue.