1.
Which option is used in /etc/vfstab to limit the size of a tmpfs file system to 512MB to prevent a memory denial of service (DoS)?
2.
The Key Distribution Center (KDC) is a central part of the Kerberos authentication system. How should the system running the KDC be configured?
3.
The security administrator wants to log all changes that are made to the device policy. Which Solaris 10 subsystem will be used to log changes to the device policy?
4.
A system administrator is new to the Solaris cryptographic framework. During minimization and hardening, the system administrator discovered a running /usr/lib/ crypto/kcfd and disabled this daemon. To verify the integrity of a Solaris binary, the system administrator is comparing the MD5 checksum of a binary with the information from the Solaris Fingerprint Database at SunSolve. To get the local checksum, he is using the command digest. What will happen when executing this command?
 
5.
In which Solaris OS subsystem is User Rights Management implemented?
6.
It is corporate practice to use the Solaris Security Toolkit on all Sun systems. This has been successfully done for years, and the administrators are experienced with the tool. Starting with Solaris 10, the company now also uses Solaris zones. Which two statements regarding Solaris Security Toolkit are correct? (Choose two.)
7.
On a system with these settings in audit_control: dir:/var/audit flags:lo,ex,nt naflags:na minfree:20 Which will NOT be a factor in the size of the audit trail generated by the system?
8.
The security administrator has created a Basic Audit and Report Tool (BART) control manifest for the /etc directory. A test manifest is created about one hour later, and the two manifests are compared. The administrator checks all attributes for the files in /etc. Which event will NOT be reported by comparing the two manifests with BART?
9.
A security administrator would like to restrict the number of simultaneous lightweight processes (LWPs) that the webadm role may have at any given time. The security administrator has created the following policy in /etc/ projects: user.webadm:10000::::task.max-lwps=(privileged,5,deny) What will be the impact if the webadm role attempted to start a sixth LWP?
10.
Which of the descriptions is a high-level overview of how Kerberos works?