Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 202-450 topic 1 question 56 discussion

Actual exam question from LPI's 202-450
Question #: 56
Topic #: 1
[All 202-450 Questions]

It has been discovered that the company mail server is configured as an open relay. Which of the following actions would help prevent the mail server from being used as an open relay while maintaining the possibility to receive company mails? (Choose two.)

  • A. Restrict Postfix to only accept e-mail for domains hosted on this server
  • B. Configure Dovecot to support IMAP connectivity
  • C. Configure netfilter to not permit port 25 traffic on the public network
  • D. Restrict Postfix to only relay outbound SMTP from the internal network
  • E. Upgrade the mailbox format from mbox to maildir
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
MBison
Highly Voted 3 years ago
I think, it's A & D: A: Restrict to domains hosted on this server: Yes, we want to receive mails addressed to the company domains from outside B: irrelevant C: Block port 25 on public networks: If we block port 25, we can't receive any emails, which conflicts to A. D: Restrict relay to outbound SMTP to internal network: Yes, we want only send outgoing emails to other SMTP servers, if they are coming from our internal network E: irrelevant
upvoted 7 times
HarryKalahan
2 years, 6 months ago
I would select A and D too, but I have a doubt about your explanation in answer D. If we restrict relay to outbound SMTP traffic, wouldn't we avoiding workers of our company to send emails as well if they are at home for example (they would be outside of the company network)? I am a bit confused. This question is not easy and we don't know the LPI arguments.
upvoted 2 times
...
...
hobokabobo
Highly Voted 3 years, 9 months ago
I think rather A&D
upvoted 5 times
Adonist
3 years, 9 months ago
A and C is correct. D would be only if you are relaying to another mail server instead.
upvoted 1 times
...
...
sonic66
Most Recent 1 month, 1 week ago
Selected Answer: AD
"maintaining the possibility to receive company mails" -> C is in conflict, if you block the SMTP port on public network, the company can't receive mails from outside (public) A -> We restrict reception to our domain only D -> We restrict only our private LAN to send to outside
upvoted 1 times
...
Lantos
11 months, 3 weeks ago
I've found a "mynetworks" parameter, which is used to restrict the mail relaying by subnets mainly. So D option seems to be true. https://www.postfix.org/postconf.5.html#mynetworks
upvoted 1 times
...
Armina
2 years, 2 months ago
Selected Answer: AD
A and D are correct. Company supposed to receive mails from outside (public) but sending mail should be only possible to internal mail address. In this way preventing “open relay” (using mail outside of company to send to any other public mails) is partly rejected and just receiving from public and private internal are accepted by postfix server. ######### C is not correct because both inbound and outbound traffic of the port 26 will be blocked (rejected) on public Ethernet Network that means: iptables -A INPUT -i eth0-public -p tcp --dport 25 -j REJECT iptables -A OUTPUT -o eth0-public -p tcp --dport 25 -j REJECT
upvoted 1 times
Armina
2 years, 2 months ago
*traffic of the port 25
upvoted 1 times
...
...
Adonist
3 years, 8 months ago
Thinking again I believe C and D looks fine
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...