BIT451 · TU past paper
Network and System Administration 2082.1 question paper
The complete TU 2082.1 exam paper for Network and System Administration (BIT451), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksTCP/IP protocol layers and functionalitiesHideAnswer
Explain the functionalities of different layers of TCP/IP protocol suite.How IPV6 is different from IPV4? Explain.[6+4]
(a) Functionalities of Different Layers of TCP/IP Protocol Suite The TCP/IP model consists of four layers, each with distinct functionalities: - Provides network services directly to user applications and end-users - Handles user interac...
- 210 marksUser and group managementHideAnswer
Explain user, group, and privilege management in Linux system administration using suitable commands.[10]
--- --- --- --- --- Task Command --------------- Create user useradd -m username Create group groupadd groupname Add user to group usermod -aG group user Change permissions chmod 755 file Change owner chown user:group file Grant sudo use...
- 310 marksDNS zone transfer conceptsHideAnswer
What is DNS zone transfer?Explain the difference between full zone transfer (AXFR) and incremental zone transfer (IXFR).Why is zone transfer security important?[3+5+2]
DNS zone transfer is the process of copying or replicating the entire DNS database (zone file) from a primary DNS server to a secondary DNS server. It involves transferring all DNS records (resource records) associated with a particular ...
- 45 marksCUPS printing systemHideAnswer
What is CUPS? Explain basic CUPS configuration. [1+4]
CUPS stands for Common Unix Printing System. It is a modular printing system for Unix-like operating systems (including Linux) that allows computers to act as print servers and clients. CUPS enables users to print to local and network pr...
- 55 marksProxy caching server configuration and benHideAnswer
What is a proxy caching server? Explain its configuration and benefits for network performance and bandwidth management. [1+4]
Proxy Caching Server: Definition, Configuration, and Benefits
1. Definition of Proxy Caching Server
A proxy caching server is an intermediary server that sits between client computers and origin servers (web servers). It intercepts client requests, stores copies of frequently accessed web content locally, and serves that cached content to subsequent requests without fetching from the origin server again.
The proxy acts as a "middleman" that:
- Receives HTTP requests from clients
- Checks if requested content exists in its cache
- Returns cached content if available (cache hit)
- Forwards requests to origin servers if content is not cached (cache miss)
- Stores responses for future use
2. Configuration of Proxy Caching Server
Key Configuration Parameters:
a) Cache Storage
- Define cache directory location and total cache size (e.g., 1GB, 10GB)
- Set maximum object size to cache (e.g., don't cache files > 100MB)
- Configure cache replacement policy (LRU - Least Recently Used, LFU - Least Frequently Used)
b) Cache Expiration (TTL - Time To Live)
- Set expiration time for different content types
- Static content: longer TTL (e.g., 7 days)
- Dynamic content: shorter TTL (e.g., 1 hour)
- Configure based on HTTP headers (Cache-Control, Expires)
c) Access Control
- Define which clients can use the proxy
- Specify allowed/blocked domains
- Set authentication requirements
d) Refresh Policies
- Configure when to revalidate cached content with origin server
- Set conditional request headers (If-Modified-Since, ETag)
e) Logging and Monitoring
- Enable access logs to track cache hits/misses
- Monitor cache performance metrics
3. Benefits for Network Performance and Bandwidth Management
Network Performance Benefits:
Benefit Explanation Reduced Latency Cached content served locally is much faster than fetching from distant origin servers Faster Response Times Users experience quicker page loads and downloads Reduced Server Load Origin servers handle fewer requests, improving their response time Better User Experience Faster access to frequently used content Bandwidth Management Benefits:
Benefit Explanation Bandwidth Savings Repeated requests for same content don't consume WAN bandwidth; served from local cache Reduced WAN Traffic Can reduce outbound bandwidth by 30-70% depending on content patterns Lower ISP Costs Less data transferred = lower bandwidth bills Efficient Resource Utilization Network links used more efficiently for new/unique content Congestion Reduction Fewer requests traverse the network backbone Example Impact:
If 100 users request the same 5MB file:
- Without proxy cache: 500MB transferred over WAN
- With proxy cache: 5MB transferred (first request only) + local distribution
Conclusion: Proxy caching servers are essential infrastructure for optimizing network performance and controlling bandwidth costs, particularly in organizations with high internet usage or limited WAN capacity.
- 65 marksFirewall configuration using iptablesHideAnswer
Describe firewall configuration using iptables or firewalld to allow: SSH, HTTP/HTTPS and Custom port. [5]
iptables is a command-line utility for configuring Linux kernel firewall rules. Here's how to configure it: 1. Allow SSH (port 22): 2. Allow HTTP (port 80): 3. Allow HTTPS (port 443): 4. Allow Custom Port (e.g., port 8080): 5. Set defaul...
- 75 marksXinetd and Inetd servicesHideAnswer
What is the difference between Xinetd and Inetd services? [5]
Difference between Xinetd and Inetd Services
Overview
Both inetd and xinetd are internet super-servers that manage network services on Unix/Linux systems, but they differ significantly in architecture, functionality, and performance.
Key Differences
Aspect Inetd Xinetd Generation Older, traditional super-server Newer, enhanced replacement Configuration Single /etc/inetd.conffileMultiple files in /etc/xinetd.d/directoryService Management Spawns process for each connection Can limit connections and manage resources Access Control Limited built-in security features Advanced access control lists (ACLs) Logging Basic syslog support Enhanced logging capabilities Performance Less efficient under heavy load Better resource management Flexibility Rigid configuration More configurable and flexible
Detailed Differences
1. Architecture & Design
- Inetd: Monolithic design; reads single configuration file at startup
- Xinetd: Modular design; reads configuration from directory allowing per-service configuration
2. Connection Handling
- Inetd: Spawns a new process for every incoming connection without resource limits
- Xinetd: Can limit concurrent connections, implement rate limiting, and manage resource allocation per service
3. Security Features
- Inetd: Minimal access control
- Xinetd: Supports:
- IP-based access control
- Time-based service availability
- Connection rate limiting
- Service binding to specific interfaces
4. Configuration Flexibility
- Inetd: Single file format; difficult to manage many services
- Xinetd: Separate configuration files per service; easier maintenance and scalability
Conclusion
Xinetd is the modern successor to inetd, offering superior resource management, security, and flexibility, making it the preferred choice for contemporary Linux systems.
- 85 marksSDN controller and data plane communicatioHideAnswer
How do SDN controllers communicate with data planes? Explain SDN architecture with a diagram. [1+4]
SDN controllers communicate with data planes through the Southbound Interface using standardized protocols: - OpenFlow Protocol (most common): Controllers send flow rules and instructions to switches via OpenFlow messages - NETCONF/YANG:...
- 95 marksNetwork troubleshooting commandsHideAnswer
What are different network troubleshooting commands? [5]
Network Troubleshooting Commands
Answer
Network troubleshooting commands are utilities used to diagnose, monitor, and resolve network connectivity and performance issues. Here are the main categories and commands:
1. Connectivity Testing Commands
-
ping: Tests reachability of a host by sending ICMP echo requests. Verifies if a remote host is alive and measures round-trip time.
ping <hostname/IP address> -
tracert/traceroute: Traces the route packets take to reach a destination. Shows all intermediate hops and their response times.
tracert <destination> (Windows) traceroute <destination> (Linux/Unix)
2. DNS Resolution Commands
-
nslookup: Queries DNS servers to resolve domain names to IP addresses and vice versa.
nslookup <domain name> -
dig: Performs DNS lookups with detailed information about DNS records.
dig <domain name>
3. Network Configuration Commands
-
ipconfig/ifconfig: Displays network interface configuration including IP address, subnet mask, and gateway.
ipconfig (Windows) ifconfig (Linux/Unix) -
route: Displays and modifies the routing table.
route print
4. Connection and Port Testing
-
telnet: Tests connectivity to a specific port on a remote host.
telnet <host> <port> -
netstat: Shows active network connections, listening ports, and network statistics.
netstat -an
5. Packet Analysis
- tcpdump/Wireshark: Captures and analyzes network packets for detailed traffic inspection.
These commands help identify network problems, verify connectivity, and diagnose performance issues systematically.
-
- 105 marksDHCP principles and operationHideAnswer
What is DHCP? How can you configure the DHCP server? Explain. [1+4]
DHCP: Definition and Server Configuration
1. What is DHCP? (1 mark)
DHCP (Dynamic Host Configuration Protocol) is a network protocol that automatically assigns IP addresses and other network configuration parameters to devices (clients) on a network. Instead of manually configuring each device with a static IP address, DHCP enables devices to obtain their network settings dynamically from a DHCP server.
Key purpose: Simplifies network administration by automating IP address allocation and management.
2. How to Configure the DHCP Server (4 marks)
Configuration Steps:
Step 1: Install DHCP Server Software
- Install the DHCP server package on the designated server machine
- Example:
apt-get install isc-dhcp-server(on Linux/Ubuntu)
Step 2: Configure the DHCP Configuration File
The main configuration file is typically
/etc/dhcp/dhcpd.conf. Key configurations include:-
Define Subnet: Specify the network subnet and netmask
subnet 192.168.1.0 netmask 255.255.255.0 { } -
Set IP Address Pool: Define the range of IP addresses to be assigned
range 192.168.1.100 192.168.1.200; -
Configure Default Gateway: Specify the router/gateway address
option routers 192.168.1.1; -
Set DNS Servers: Provide DNS server addresses
option domain-name-servers 8.8.8.8, 8.8.4.4; -
Set Lease Time: Define how long a client can use an assigned IP
default-lease-time 600; max-lease-time 7200;
Step 3: Specify Network Interface
- Configure which network interface the DHCP server listens on
- Edit
/etc/default/isc-dhcp-serverand setINTERFACESv4="eth0"
Step 4: Start and Enable the Service
- Start the DHCP server:
systemctl start isc-dhcp-server - Enable on boot:
systemctl enable isc-dhcp-server
Step 5: Verify Configuration
- Check service status:
systemctl status isc-dhcp-server - Monitor DHCP logs for client requests and IP assignments
Result: Clients on the network can now automatically obtain IP addresses and network settings from the configured DHCP server.
- 115 marksSMTP, POP3, and IMAP email protocolsHideAnswer
Explain the roles of SMTP, POP3, and IMAP in email communication. [5]
Email communication requires multiple protocols working together. SMTP, POP3, and IMAP are the three fundamental protocols that handle different aspects of email transmission and retrieval. --- Role: Sending and relaying emails - Functio...
- 1210 marksVariable Length Subnet MaskingHideAnswer
Write short notes on: a) VLSM b) ACL [5+2.5+2.5]
Definition: VLSM is a subnetting technique that allows different subnets within the same network to have different subnet mask lengths. Unlike traditional subnetting where all subnets use the same mask, VLSM enables variable-length masks...