BIT451 · TU past paper
Network and System Administration 2082 question paper
The complete TU 2082 exam paper for Network and System Administration (BIT451), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksLinux server features and characteristicsHideAnswer
What are the salient features of Linux server? Explain the process of online server upgrade.[10]
Model Answer: Salient Features of Linux Server and Online Server Upgrade
Salient Features of Linux Server (5 marks)
1. Open Source
- Source code is freely available for modification and distribution
- Community-driven development ensures continuous improvement
- No licensing costs
2. Portability
- Runs on diverse hardware platforms (mainframes, servers, desktops, embedded systems)
- Easy to migrate between different systems
- Consistent behavior across platforms
3. Multi-user and Multitasking
- Multiple users can work simultaneously on the same system
- Multiple processes can run concurrently without interfering with each other
- Efficient resource sharing and management
4. Security
- User authentication and authorization mechanisms
- File permission system (read, write, execute)
- Firewall capabilities and encryption support
- Regular security updates from community
5. Stability and Reliability
- Can run for years without requiring restart
- Robust error handling and recovery mechanisms
- Minimal downtime and high availability
6. Scalability
- Handles increasing workloads efficiently
- Can manage large numbers of users and processes
- Suitable for both small and enterprise-level deployments
Process of Online Server Upgrade (5 marks)
Definition
Online server upgrade refers to updating or patching a Linux server while it remains operational, without causing service interruption to users.
Step-by-Step Process:
Step 1: Planning and Preparation
- Identify required updates (security patches, kernel updates, software upgrades)
- Create backup of critical data and configurations
- Schedule upgrade during low-traffic periods if possible
- Notify users about potential performance impact
Step 2: Update Repository Information
sudo apt update # For Debian/Ubuntu # or sudo yum update # For RedHat/CentOS- Refreshes package lists from repositories
- Identifies available updates
Step 3: Download Updates
- Download new packages without installing immediately
- Verify package integrity and dependencies
- Ensure sufficient disk space available
Step 4: Install Updates
sudo apt upgrade # Non-disruptive updates # or sudo apt dist-upgrade # Major version upgrades- Install updates while system remains running
- Most services continue operating
Step 5: Service Restart (if required)
- Some updates require service restart
- Restart individual services rather than entire system:
sudo systemctl restart service_name- Minimize downtime by restarting only affected services
Step 6: Verification
- Verify all services are running correctly
- Check system logs for errors
- Test critical applications and functionality
- Monitor system performance
Step 7: Rollback Plan
- Keep previous version available if issues occur
- Document changes made during upgrade
- Have recovery procedure ready
Advantages of Online Upgrade:
- Continuous service availability
- No scheduled downtime
- Improved user experience
- Cost-effective for production environments
Note: The specific commands and procedures may vary depending on the Linux distribution (Ubuntu, CentOS, Fedora, etc.) and the type of upgrade being performed.
- 210 marksDNS principles and fundamentalsHideAnswer
What are DNS principles? Explain different server types focusing on its functionalities.[10]
DNS (Domain Name System) operates on the following core principles: - DNS uses a hierarchical naming scheme organized as a tree structure - Domain names are organized in levels: root, top-level domains (TLDs), second-level domains, and s...
- 310 marksName-based virtual hostingHideAnswer
Differentiate between name based and IP based virtual hosting. Explain proxy ACL.[10]
Model Answer: Virtual Hosting and Proxy ACL
Part 1: Name-Based vs IP-Based Virtual Hosting
Name-Based Virtual Hosting
Definition: Multiple websites (virtual hosts) are hosted on a single IP address, differentiated by their domain names (hostnames).
Key Characteristics:
- Uses HTTP Host header to identify which website the client is requesting
- Server examines the Host field in the HTTP request and routes to the appropriate virtual host
- More efficient use of IP addresses
- Requires DNS to resolve multiple domain names to the same IP address
- Example: www.site1.com and www.site2.com both resolve to 192.168.1.10
Advantages:
- Conserves IP addresses (critical when IPv4 addresses are limited)
- Cost-effective hosting solution
- Easier to manage multiple sites on one server
Limitations:
- Requires HTTP/1.1 (older HTTP/1.0 clients may not send Host header)
- Cannot be used for HTTPS without SNI (Server Name Indication)
- Browser must support the Host header
IP-Based Virtual Hosting
Definition: Each virtual host is assigned a unique IP address on the same physical server.
Key Characteristics:
- Each website has its own distinct IP address
- Server uses the destination IP address to determine which virtual host to serve
- Works at the network layer (Layer 3)
- No dependency on HTTP headers
- Example: www.site1.com → 192.168.1.10, www.site2.com → 192.168.1.11
Advantages:
- Works with all HTTP versions (HTTP/1.0 and HTTP/1.1)
- Compatible with HTTPS without SNI
- No reliance on client-side Host header support
- Better for legacy systems
Limitations:
- Requires multiple IP addresses (expensive and wasteful)
- More complex network configuration
- Difficult to scale for large numbers of virtual hosts
Comparison Table
Aspect Name-Based IP-Based IP Addresses Single IP for multiple sites One IP per site Differentiation Domain name (Host header) IP address Resource Usage Efficient Wasteful HTTPS Support Requires SNI Native support Scalability Highly scalable Limited HTTP Version HTTP/1.1 required All versions
Part 2: Proxy ACL (Access Control List)
Definition
Proxy ACL is a set of rules configured on a proxy server (such as Squid) that controls and filters network traffic by allowing or denying access to specific resources based on defined criteria.
Purpose
- Control which clients can access the proxy
- Restrict access to specific websites or content
- Implement bandwidth management
- Enforce security policies
- Block malicious or inappropriate content
Common ACL Criteria
- Source IP Address: Allow/deny based on client IP
- Destination IP/Domain: Allow/deny access to specific servers or websites
- Port Numbers: Control access to specific ports
- Time-based: Restrict access during certain hours
- Protocol: Allow/deny specific protocols (HTTP, HTTPS, FTP)
- URL Patterns: Block or allow based on URL matching
- User Authentication: Control based on username/credentials
Basic ACL Rule Structure
acl <name> <type> <value> http_access allow/deny <acl_name>Example (Squid Proxy)
acl internal_network src 192.168.1.0/24 acl blocked_sites dstdomain .facebook.com .youtube.com acl work_hours time MTWHF 09:00-17:00 http_access allow internal_network work_hours http_access deny blocked_sites http_access deny allBenefits
- Enhanced security by filtering unwanted traffic
- Bandwidth optimization
- Content filtering and policy enforcement
- Protection against unauthorized access
- 45 marksFirewall concepts and requirementsHideAnswer
What is the use of firewall? Explain packet level and application level firewall. [5]
Model Answer: Firewall Uses and Types
Use of Firewall (1 mark)
A firewall is a network security system that acts as a barrier between an organization's internal network and untrusted external networks (such as the Internet). Its primary uses are:
- Monitor and control incoming and outgoing network traffic based on predetermined security rules
- Prevent unauthorized access to protected networks
- Block malicious traffic and potential threats
- Enforce security policies and access control
- Protect sensitive data from being exposed to external threats
Packet Level Firewall (2 marks)
Definition: Also called a stateless firewall, it operates at the network and transport layers (Layers 3 and 4 of the OSI model).
How it works:
- Examines each packet individually in isolation
- Analyzes packet headers containing source IP, destination IP, port numbers, and protocol type
- Makes filtering decisions based on predefined rules without considering the context of previous packets
- Does not maintain information about the state of connections
Characteristics:
- Fast and efficient (minimal processing overhead)
- Simple rule-based filtering
- Cannot detect sophisticated attacks that span multiple packets
- Suitable for basic filtering tasks
Application Level Firewall (2 marks)
Definition: Also called a proxy firewall or stateful firewall, it operates at the application layer (Layer 7 of the OSI model).
How it works:
- Examines the actual content and context of data packets
- Maintains state information about connections and sessions
- Acts as an intermediary (proxy) between client and server
- Analyzes application-level protocols (HTTP, FTP, SMTP, etc.)
- Makes intelligent filtering decisions based on application data
Characteristics:
- More secure and intelligent than packet-level firewalls
- Can detect and block application-level attacks (e.g., SQL injection, malware in files)
- Higher processing overhead and slower performance
- Better protection against sophisticated threats
- Can enforce user-level policies and authentication
Key Difference: Packet-level firewalls are fast but basic; application-level firewalls are slower but provide deeper security inspection and context-aware protection.
- 55 marksCIDR and VLSM benefits and differencesHideAnswer
What is the difference between VLSM and CIDR? List the benefits of VLSM? [5]
Model Answer: VLSM vs CIDR and Benefits of VLSM
Difference between VLSM and CIDR
Aspect VLSM CIDR Full Form Variable Length Subnet Mask Classless Inter-Domain Routing Scope Used within an organization for internal subnetting Used across the internet for routing and address allocation Subnet Mask Different subnet masks for different subnets within same network Single prefix length notation (e.g., /24) for address blocks Purpose Maximizes address utilization within a single network Eliminates class-based addressing and improves global routing efficiency Implementation Applied at the organizational/internal level Applied at ISP and inter-domain level Flexibility Allows multiple levels of subnetting with varying mask lengths Provides flexible allocation of address space in blocks Key Distinction: VLSM is a subnetting technique used internally, while CIDR is a global routing and addressing architecture.
Benefits of VLSM
-
Efficient Address Utilization
- Reduces IP address wastage by allocating only the required number of addresses to each subnet
- Different subnets can have different sizes based on actual host requirements
-
Reduced Network Overhead
- Minimizes unused IP addresses in each subnet
- Lowers the cost of IP address allocation
-
Hierarchical Subnetting
- Allows multiple levels of subnetting within a single network
- Enables creation of subnets of subnets for better organization
-
Improved Routing Efficiency
- Supports route summarization (supernetting)
- Reduces routing table size and improves routing performance
-
Scalability
- Accommodates networks of varying sizes within the same organization
- Supports network growth without major restructuring
-
Better Network Design
- Allows network administrators to design networks that match actual organizational requirements
- Provides flexibility in allocating resources based on departmental needs
-
- 65 marksWeb server configuration processHideAnswer
Explain the process of web server configuration. [5]
Web server configuration is the process of setting up and customizing a web server to handle HTTP/HTTPS requests and serve web content according to specific requirements. Here is the systematic process: - Download and install the web ser...
- 75 marksDNS zone transfer conceptsHideAnswer
Define DNS zone transfer. Why is it carried out? [5]
DNS Zone Transfer - Model Answer
Definition
A DNS zone transfer is the process of copying or replicating all DNS records (resource records) from a primary DNS server to a secondary DNS server for a particular DNS zone. It involves the complete transfer of zone data, including all A records, MX records, CNAME records, NS records, SOA records, and other resource records associated with a domain.
The zone transfer typically uses the AXFR (full zone transfer) or IXFR (incremental zone transfer) protocol over TCP port 53.
Why Zone Transfer is Carried Out
Zone transfers are performed for the following reasons:
1. Redundancy and Fault Tolerance
- Maintains backup copies of DNS data on secondary servers
- Ensures DNS service continues if the primary server fails
- Provides high availability for critical DNS infrastructure
2. Load Distribution
- Distributes DNS query load across multiple servers
- Secondary servers handle DNS queries, reducing burden on the primary server
- Improves overall DNS performance and response times
3. Geographic Distribution
- Places DNS servers in different geographic locations
- Reduces latency for users in different regions
- Improves DNS resolution speed globally
4. Data Consistency
- Ensures all authoritative DNS servers have identical zone data
- Maintains synchronization when zone records are updated on the primary server
- Prevents inconsistencies in DNS responses
5. Compliance and Reliability
- Meets requirements for authoritative DNS server configurations
- Ensures compliance with DNS standards and best practices
- Provides reliable DNS service as per SLA requirements
Note: This answer is derived from standard DNS architecture principles. Ensure your course notes on DNS infrastructure are consulted for any institution-specific emphasis.
- 85 marksDHCP troubleshooting proceduresHideAnswer
How DHCP troubleshooting is carried out? Explain. [5]
DHCP troubleshooting involves systematic diagnosis and resolution of Dynamic Host Configuration Protocol issues. Here are the main approaches: - Check if the DHCP server is running and operational - Confirm the server is listening on por...
- 95 marksSDN controller concepts and benefitsHideAnswer
Explain SDN controller. What are its benefits? [5]
An SDN (Software-Defined Networking) controller is a centralized management entity that controls the behavior of the network by managing the forwarding devices (switches and routers) in the network. It acts as an intermediary between the...
- 105 marksDifference between Cron and AnacronHideAnswer
Differentiate between cron and anacron. What are the purposes of anacron? [5]
Feature Cron Anacron ------------------------ System Type Daemon process; runs continuously One-time execution program Startup Requirement Requires system to be running at scheduled time Does not require system to be running at scheduled...
- 115 marksOpen source networking monitoring toolsHideAnswer
Explain the concept of open source networking monitoring with an example. [5]
Open source networking monitoring refers to the use of freely available, publicly accessible software tools to observe, measure, and analyze the performance and behavior of computer networks. These tools allow network administrators to t...
- 125 marksCUPS printing systemHideAnswer
Write short notes on: (a) CUPS (b) SMTP [5]
Model Answer: CUPS and SMTP
(a) CUPS (Common Unix Printing System)
CUPS is a modular printing system for Unix and Linux-based operating systems that allows computers to act as print servers.
Key Features:
- Architecture: Uses a client-server model where the CUPS daemon (cupsd) manages print jobs and printers
- Protocol: Implements Internet Printing Protocol (IPP) for communication between clients and print servers
- Functionality:
- Accepts print jobs from client applications
- Queues and schedules jobs
- Sends jobs to appropriate printers
- Manages printer drivers and filters
- Access: Can be accessed locally or over a network
- Configuration: Uses configuration files typically located in
/etc/cups/ - Advantages: Supports multiple printer types, provides print job management, and enables network printing
(b) SMTP (Simple Mail Transfer Protocol)
SMTP is an application-layer protocol used for sending emails across the Internet.
Key Characteristics:
- Purpose: Handles the transmission of outgoing mail from client to mail server, and between mail servers
- Port: Typically operates on port 25 (or 587 for authenticated submission)
- Connection Type: Uses TCP (Transmission Control Protocol) for reliable delivery
- Operation:
- Establishes connection with mail server
- Authenticates sender (if required)
- Specifies sender, recipient(s), and message content
- Transfers message to server for delivery
- Limitations: Only handles sending; receiving requires POP3 or IMAP protocols
- Security: Modern implementations use TLS/SSL encryption (SMTPS) for secure transmission
- Command-based: Uses text commands (MAIL, RCPT, DATA, etc.) for communication
Note: Answers derived from standard networking and systems administration knowledge, as reference notes were unavailable.