Skip to content

702-100 BSD Specialist Practice Questions

Prepare for 702-100 with more than an answer.

256 questions in the full set20 sample questionsUpdated Jan 26, 2026
Level
Specialist
Valid for
5 years
Domains covered on the exam 5
  1. BSD Installation and Software Management23%
  2. Storage Devices and BSD Filesystems18%
  3. Basic BSD System Administration23%
  4. Basic BSD Network Administration17%
  5. Basic Unix Skills19%
  1. 1

    A sysadmin needs to schedule a resource-intensive data processing script, /usr/local/bin/process_data.sh, to run every Sunday at 3:15 AM on an OpenBSD server. What is the correct crontab entry to achieve this?

    Show answer details

    Correct answer: A

    The crontab format consists of five time-and-date fields followed by the command. The fields are: minute (0-59), hour (0-23), day of month (1-31), month (1-12), and day of week (0-7, where both 0 and 7 represent Sunday). Therefore, 15 3 * * 7 correctly specifies 15 minutes past the 3rd hour, on any day of the month, in any month, but only when the day of the week is Sunday.

  2. 2

    While using vi to edit a large configuration file on a NetBSD system, you need to find all occurrences of the string 192.168.1.1 and replace them with 10.10.0.1. Which vi command, executed in command mode, will perform this replacement globally throughout the entire file?

    Show answer details

    Correct answer: B

    This is the correct and most robust vi substitute command. The % specifies the range as the entire file. s is the substitute command. The . characters in the IP address must be escaped with a backslash (\.) to be treated as literal periods rather than regex wildcards. The /g flag at the end ensures that all occurrences on each line are replaced, not just the first one.

  3. 3

    An administrator of a FreeBSD server needs to enable a service called customappd to start at boot time. They have already placed a valid startup script for it in /usr/local/etc/rc.d/. What is the correct entry to add to /etc/rc.conf to enable this service?

    Show answer details

    Correct answer: A

    In the FreeBSD rc system, services are enabled by adding a line to /etc/rc.conf with the format service_name_enable="YES". The service name is derived from the script's filename in /usr/local/etc/rc.d/.

  4. 4

    A security policy requires that the /tmp directory on a new OpenBSD server be mounted with options that prevent the execution of binaries and the interpretation of device files stored within it. Which fstab entry line for /tmp reflects these security best practices?

    Show answer details

    Correct answer: B

    This entry includes several critical security options. noexec prevents the execution of any binaries from this filesystem. nodev prevents the interpretation of character or block special devices. nosuid prevents set-user-identifier or set-group-identifier bits from taking effect. This combination is a standard hardening practice for world-writable directories like /tmp.

  5. 5

    A new administrator is trying to understand the process lifecycle on a FreeBSD system. They observe a process in the Z state in the output of ps. What does this state indicate?

    stateDiagram-v2 [*] --> Running Running --> Sleeping: I/O Wait Sleeping --> Running: I/O Complete Running --> Stopped: Signal (SIGSTOP) Stopped --> Running: Signal (SIGCONT) Running --> Zombie: exit() Zombie --> [*]: wait()
    Show answer details

    Correct answer: C

    A process in the 'Z' state is a 'zombie' or 'defunct' process. This means the process has completed execution, but it still has an entry in the process table. This entry remains until the parent process reads the child's exit status by calling the wait() system call. Zombie processes consume a negligible amount of system resources, but a large number of them can indicate a bug in the parent application.

  6. 6

    A system administrator is hardening a new FreeBSD server that will host critical financial data. A primary requirement is to prevent any modifications to kernel modules at runtime, even by the root user, once the system is fully booted. Which configuration in /etc/sysctl.conf will achieve this specific security objective?

    Show answer details

    Correct answer: B

    Setting kern.securelevel to 2 provides all the protections of level 1 (such as immutable file flags and preventing writing to raw disk devices) and additionally prevents the loading or unloading of kernel modules. This directly meets the requirement of preventing runtime modifications to kernel modules.

  7. 7

    During a post-incident review of a compromised NetBSD server, an analyst needs to determine the exact commands executed by a specific user, 'rogueuser', during their logged-in sessions. Which command should the analyst use to get the most detailed process accounting information for this purpose?

    Show answer details

    Correct answer: D

    The lastcomm utility, when process accounting is enabled, provides detailed information about previously executed commands from the accounting file. Specifying the username rogueuser filters the output to show only commands executed by that user, which is exactly what is needed for the forensic analysis. last shows login sessions, ac shows connect time, and sa summarizes accounting information, but lastcomm lists the actual commands.

  8. 8

    An administrator is setting up a new OpenBSD firewall. To ensure maximum security and adhere to the principle of least privilege, they want to prevent the resolution of DNS queries for any domain not explicitly listed in /etc/hosts. Which of the following lines, when added to /etc/resolv.conf, will enforce this policy?

    Show answer details

    Correct answer: B

    In OpenBSD's /etc/resolv.conf, the lookup directive specifies the sources and order for name resolution. By setting it to lookup file, the system is instructed to ONLY use the /etc/hosts file for lookups and to not query any DNS servers (bind). This effectively blocks external DNS queries and meets the security requirement.

  9. 9

    A developer needs to compile a custom application on a FreeBSD server that has several build-time dependencies. They want to ensure that all required dependencies are installed automatically before the compilation begins, using the native source-based package management system. Which command should be executed from within the application's source directory in the ports tree?

    Show answer details

    Correct answer: D

    In the FreeBSD ports system, the make install command will automatically fetch, extract, patch, configure, build, and install the software. Crucially, it also handles dependencies recursively. If a dependency is not found, the ports framework will descend into that dependency's port directory and build and install it first. The install-recursive target is an alias that makes this behavior explicit, but make install is the standard, idiomatic way to achieve this.

  10. 10

    A systems administrator is scripting a backup solution for a NetBSD server. The script needs to create a compressed archive of the /etc directory. The administrator wants to use tar and pipe its output to xz for high-ratio compression. Which of the following commands correctly achieves this?

    Show answer details

    Correct answer: B

    This command correctly uses a standard Unix pipeline. tar -cf - /etc creates an archive of /etc and writes it to standard output (the - filename). The pipe | redirects this standard output to the standard input of the xz command, which compresses the data and writes it to its standard output. Finally, the > redirects the compressed output stream to the specified file /backups/etc.tar.xz. While BSD tar often has integrated compression flags (-J for xz), this pipeline method is the most portable and fundamental way to accomplish the task.

Create an account to continue.