300-300 Sample Questions

300-300 Sample Questions & Answers

Handling Active Directory name resolution and acting as its domain controller takes well over a quarter of the exam, ahead of core Samba concepts and maintenance, file share and DFS setup, authentication clients, and FreeIPA identity management.

Launch the full 300-300 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Topic 303: Samba Share Configuration · File Share Configuration

    A system administrator is troubleshooting a Samba file share. Users report that they cannot see certain files they know exist and to which they have read permissions at the filesystem level. The administrator suspects a Samba configuration issue is hiding these files. Which parameter in smb.conf is the most likely cause of this behavior?

    Show answer & explanation

    Correct answer: B

    The veto files parameter instructs Samba to hide files and directories that match the specified patterns, making them invisible and inaccessible to SMB clients, regardless of filesystem permissions. If a pattern in this list inadvertently matches legitimate files, they will disappear from the users' view. hide unreadable hides files the user cannot read, but the scenario states they have read permissions. dont descend applies to directories, and case sensitive = yes affects name matching, not visibility.

  2. Question 2Beginner

    Topic 304: Samba Client Configuration · SSSD Configuration

    True or False: When a Linux client uses SSSD to connect to an Active Directory domain, the ad_access_filter option in sssd.conf can be used to restrict access based on a user's AD group membership using a standard LDAP filter.

    Show answer & explanation

    Correct answer: A

    True. The ad_access_filter parameter allows an administrator to specify a custom LDAP filter that is evaluated against the user object in Active Directory during the access control phase. A common use case is to restrict logins to members of a specific AD group, for example: ad_access_filter = (memberOf=cn=LinuxUsers,ou=Groups,dc=example,dc=com). This is a powerful method for controlling access to Linux systems from Active Directory.

  3. Question 3Intermediate

    Topic 305: Linux Identity Management and File Sharing · FreeIPA Entity Management

    An organization is migrating from a legacy NIS-based identity management system to FreeIPA. To ensure a smooth transition, they want to continue serving NIS clients from the FreeIPA servers. What must be configured on the FreeIPA server to enable this functionality?

    Show answer & explanation

    Correct answer: C

    FreeIPA includes a compatibility tree and services to respond to NIS client requests. This functionality must be explicitly enabled. This can be done during the initial server installation by answering 'yes' to configuring the NIS domain and server, or by passing the --setup-nis flag to ipa-server-install. This configures the schema and starts the necessary services (ypserv) to serve NIS maps from the FreeIPA LDAP backend.

  4. Question 4Beginner

    Topic 301: Samba Basics · Troubleshooting Samba

    A system administrator needs to troubleshoot a failing Samba domain provision process. To get the most detailed output possible during the samba-tool domain provision command, which command-line option should be used?

    Show answer & explanation

    Correct answer: B

    Most Samba command-line tools, including samba-tool, use the -d or --debuglevel= option to control the verbosity of logging output. A debug level of 10 provides the maximum amount of detail, which is essential for diagnosing complex issues during processes like domain provisioning. --verbose is a common flag in many Linux utilities but is not the primary mechanism for detailed debugging in Samba. --log-stdout redirects logs but does not set the level, and --show-progress only affects progress indicators.

  5. Question 5Advanced

    Topic 305: Linux Identity Management and File Sharing · FreeIPA Active Directory Integration

    Case Study:

    A medium-sized media production company, 'CreativeFrames', is restructuring its IT infrastructure. They have an existing Windows Active Directory domain (corp.creativeframes.com) used for workstations and administrative staff. The video editing department uses a fleet of high-performance Linux workstations and needs access to a large, high-speed storage server running Linux.

    Current Situation:
    The Linux workstations currently authenticate against a legacy OpenLDAP server, and home directories are provided via NFSv3. This setup is unreliable, and managing user identities across AD and OpenLDAP is a significant administrative burden. The storage server is a standalone Samba server using security = user with a local smbpasswd file, requiring separate credentials.

    Requirements:

    1. Consolidate user identity management. All users (AD and Linux-specific) should be managed from a single point of truth where possible.
    2. Linux users must be able to log into their workstations using their primary corporate credentials.
    3. The new storage solution must support Windows ACLs to provide granular permissions for cross-departmental projects.
    4. The solution should provide centralized management for sudo rules and automount maps for the Linux workstations.

    Constraints:

    • The existing Active Directory domain must remain the primary identity source for corporate users.
    • A complete migration away from AD is not an option.

    Which solution best meets all of CreativeFrames' requirements?

    Show answer & explanation

    Correct answer: C

    This solution meets all requirements. Deploying FreeIPA and establishing a trust with AD allows for consolidated identity management while respecting the constraint that AD remains primary. Linux clients authenticating against FreeIPA (via SSSD) can leverage its centralized management for sudo and automount maps. Because of the trust, AD users can authenticate to IPA-enrolled clients and services. The Samba server, joined to the IPA realm, can authenticate both IPA and trusted AD users and can be configured to support Windows ACLs (vfs_acl_xattr). This eliminates the need for OpenLDAP and the local smbpasswd file.

  6. Question 6IntermediateSelect 2

    Topic 303: Samba Share Configuration · File Share Security

    When configuring a Samba share to use Windows ACLs on a Linux filesystem, which TWO of the following are essential prerequisites? (Select TWO).

    Show answer & explanation

    Correct answers: A, C

    Samba stores Windows ACLs in extended attributes (xattrs) on the Linux filesystem. The filesystem must be mounted with support for user extended attributes (user_xattr) and POSIX ACLs (acl) to store and process this information correctly.

    The acl_xattr VFS module is responsible for the translation layer between Windows Security Descriptors (ACLs) and the POSIX ACLs and extended attributes stored on the filesystem. This module must be enabled for the share.

  7. Question 7Intermediate

    Topic 304: Samba Client Configuration · Troubleshooting SSSD

    After configuring SSSD on a Linux server to authenticate against an Active Directory domain, a user reports that while they can log in, their group memberships are not correctly reflected. They are missing access to resources controlled by AD group permissions. The id username command shows only their primary group. What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: B

    SSSD provides several services, including authentication (pam) and identity lookups (nss). If the nss service is not enabled in the main [sssd] section, the system's Name Service Switch cannot use SSSD to look up user information, including supplementary group memberships. Authentication may still succeed via PAM, but commands like id and getent group will not be able to retrieve the full group list from SSSD. The other options relate to schema mapping or token groups, which are less likely to be the primary cause for a complete lack of secondary groups.

  8. Question 8Beginner

    Topic 301: Samba Basics · Diagnostic Tools

    A developer needs to quickly test access to a Samba share from the Linux command line without permanently mounting it. They want to list the contents of a share named data on a server fileserv. Which smbclient command will accomplish this non-interactively?

    Show answer & explanation

    Correct answer: B

    The smbclient command can be run non-interactively by using the -c or --command option followed by a string of commands to execute. smbclient -c 'ls' //fileserv/data will authenticate, execute the ls command within the share's context to list its contents, and then exit. The -L option is used to list all shares on a server, not the contents of a specific share.

  9. Question 9Beginner

    Topic 305: Linux Identity Management and File Sharing · FreeIPA Entity Management

    In a FreeIPA environment, what is the primary purpose of a Host-Based Access Control (HBAC) rule?

    Show answer & explanation

    Correct answer: B

    Host-Based Access Control (HBAC) is a core feature of FreeIPA that defines a policy combining who (users/groups), where (which client hosts), and what (which services like sshd, login, etc.) are allowed. It provides a centralized way to enforce login and service access policies across all IPA-enrolled clients. It does not replace sudo for command elevation but works alongside it to control initial access.

  10. Question 10Intermediate

    Topic 303: Samba Share Configuration · Print Share Configuration

    An administrator is setting up a new Samba print server to integrate with an existing CUPS server. The goal is to automatically make all printers from the CUPS backend available to Windows clients without defining each one individually in smb.conf. Which set of parameters is required in the [printers] section to achieve this?

    Show answer & explanation

    Correct answer: C

    To integrate Samba with CUPS dynamically, you must set the printing backend with printing = cups. Then, printcap name = cups tells Samba to query the CUPS server for the list of available printers, rather than reading a static /etc/printcap file. This combination allows any printer added to CUPS to automatically become visible as a share on the Samba server.

Ready for the real thing?

The full 300-300 simulator has every exam-style question, timed mode, and instant scoring.