2082.1

BIT451 · TU past paper

Network and System Administration 2082.1 question paper

The complete TU 2082.1 exam paper for Network and System Administration (BIT451), all 12 questions with solved model answers written to the mark scheme.

Past Papers2082.120822081

Tap a question to open its answer.

  1. 110 marksTCP/IP protocol layers and functionalitiesAnswer

    Explain the functionalities of different layers of TCP/IP protocol suite.How IPV6 is different from IPV4? Explain.[6+4]

    (a) Functionalities of Different Layers of TCP/IP Protocol Suite The TCP/IP model consists of four layers, each with distinct functionalities: - Provides network services directly to user applications and end-users - Handles user interac...

  2. 210 marksUser and group managementAnswer

    Explain user, group, and privilege management in Linux system administration using suitable commands.[10]

    --- --- --- --- --- Task Command --------------- Create user useradd -m username Create group groupadd groupname Add user to group usermod -aG group user Change permissions chmod 755 file Change owner chown user:group file Grant sudo use...

  3. 310 marksDNS zone transfer conceptsAnswer

    What is DNS zone transfer?Explain the difference between full zone transfer (AXFR) and incremental zone transfer (IXFR).Why is zone transfer security important?[3+5+2]

    DNS zone transfer is the process of copying or replicating the entire DNS database (zone file) from a primary DNS server to a secondary DNS server. It involves transferring all DNS records (resource records) associated with a particular ...

  4. 45 marksCUPS printing systemAnswer

    What is CUPS? Explain basic CUPS configuration. [1+4]

    CUPS stands for Common Unix Printing System. It is a modular printing system for Unix-like operating systems (including Linux) that allows computers to act as print servers and clients. CUPS enables users to print to local and network pr...

  5. 55 marksProxy caching server configuration and benAnswer

    What is a proxy caching server? Explain its configuration and benefits for network performance and bandwidth management. [1+4]

    Proxy Caching Server: Definition, Configuration, and Benefits

    1. Definition of Proxy Caching Server

    A proxy caching server is an intermediary server that sits between client computers and origin servers (web servers). It intercepts client requests, stores copies of frequently accessed web content locally, and serves that cached content to subsequent requests without fetching from the origin server again.

    The proxy acts as a "middleman" that:

    • Receives HTTP requests from clients
    • Checks if requested content exists in its cache
    • Returns cached content if available (cache hit)
    • Forwards requests to origin servers if content is not cached (cache miss)
    • Stores responses for future use

    2. Configuration of Proxy Caching Server

    Key Configuration Parameters:

    a) Cache Storage

    • Define cache directory location and total cache size (e.g., 1GB, 10GB)
    • Set maximum object size to cache (e.g., don't cache files > 100MB)
    • Configure cache replacement policy (LRU - Least Recently Used, LFU - Least Frequently Used)

    b) Cache Expiration (TTL - Time To Live)

    • Set expiration time for different content types
    • Static content: longer TTL (e.g., 7 days)
    • Dynamic content: shorter TTL (e.g., 1 hour)
    • Configure based on HTTP headers (Cache-Control, Expires)

    c) Access Control

    • Define which clients can use the proxy
    • Specify allowed/blocked domains
    • Set authentication requirements

    d) Refresh Policies

    • Configure when to revalidate cached content with origin server
    • Set conditional request headers (If-Modified-Since, ETag)

    e) Logging and Monitoring

    • Enable access logs to track cache hits/misses
    • Monitor cache performance metrics

    3. Benefits for Network Performance and Bandwidth Management

    Network Performance Benefits:

    BenefitExplanation
    Reduced LatencyCached content served locally is much faster than fetching from distant origin servers
    Faster Response TimesUsers experience quicker page loads and downloads
    Reduced Server LoadOrigin servers handle fewer requests, improving their response time
    Better User ExperienceFaster access to frequently used content

    Bandwidth Management Benefits:

    BenefitExplanation
    Bandwidth SavingsRepeated requests for same content don't consume WAN bandwidth; served from local cache
    Reduced WAN TrafficCan reduce outbound bandwidth by 30-70% depending on content patterns
    Lower ISP CostsLess data transferred = lower bandwidth bills
    Efficient Resource UtilizationNetwork links used more efficiently for new/unique content
    Congestion ReductionFewer requests traverse the network backbone

    Example Impact:

    If 100 users request the same 5MB file:

    • Without proxy cache: 500MB transferred over WAN
    • With proxy cache: 5MB transferred (first request only) + local distribution

    Conclusion: Proxy caching servers are essential infrastructure for optimizing network performance and controlling bandwidth costs, particularly in organizations with high internet usage or limited WAN capacity.

  6. 65 marksFirewall configuration using iptablesAnswer

    Describe firewall configuration using iptables or firewalld to allow: SSH, HTTP/HTTPS and Custom port. [5]

    iptables is a command-line utility for configuring Linux kernel firewall rules. Here's how to configure it: 1. Allow SSH (port 22): 2. Allow HTTP (port 80): 3. Allow HTTPS (port 443): 4. Allow Custom Port (e.g., port 8080): 5. Set defaul...

  7. 75 marksXinetd and Inetd servicesAnswer

    What is the difference between Xinetd and Inetd services? [5]

    Difference between Xinetd and Inetd Services

    Overview

    Both inetd and xinetd are internet super-servers that manage network services on Unix/Linux systems, but they differ significantly in architecture, functionality, and performance.


    Key Differences

    AspectInetdXinetd
    GenerationOlder, traditional super-serverNewer, enhanced replacement
    ConfigurationSingle /etc/inetd.conf fileMultiple files in /etc/xinetd.d/ directory
    Service ManagementSpawns process for each connectionCan limit connections and manage resources
    Access ControlLimited built-in security featuresAdvanced access control lists (ACLs)
    LoggingBasic syslog supportEnhanced logging capabilities
    PerformanceLess efficient under heavy loadBetter resource management
    FlexibilityRigid configurationMore configurable and flexible

    Detailed Differences

    1. Architecture & Design

    • Inetd: Monolithic design; reads single configuration file at startup
    • Xinetd: Modular design; reads configuration from directory allowing per-service configuration

    2. Connection Handling

    • Inetd: Spawns a new process for every incoming connection without resource limits
    • Xinetd: Can limit concurrent connections, implement rate limiting, and manage resource allocation per service

    3. Security Features

    • Inetd: Minimal access control
    • Xinetd: Supports:
      • IP-based access control
      • Time-based service availability
      • Connection rate limiting
      • Service binding to specific interfaces

    4. Configuration Flexibility

    • Inetd: Single file format; difficult to manage many services
    • Xinetd: Separate configuration files per service; easier maintenance and scalability

    Conclusion

    Xinetd is the modern successor to inetd, offering superior resource management, security, and flexibility, making it the preferred choice for contemporary Linux systems.

  8. 85 marksSDN controller and data plane communicatioAnswer

    How do SDN controllers communicate with data planes? Explain SDN architecture with a diagram. [1+4]

    SDN controllers communicate with data planes through the Southbound Interface using standardized protocols: - OpenFlow Protocol (most common): Controllers send flow rules and instructions to switches via OpenFlow messages - NETCONF/YANG:...

  9. 95 marksNetwork troubleshooting commandsAnswer

    What are different network troubleshooting commands? [5]

    Network Troubleshooting Commands

    Answer

    Network troubleshooting commands are utilities used to diagnose, monitor, and resolve network connectivity and performance issues. Here are the main categories and commands:

    1. Connectivity Testing Commands

    • ping: Tests reachability of a host by sending ICMP echo requests. Verifies if a remote host is alive and measures round-trip time.

      ping <hostname/IP address>
      
    • tracert/traceroute: Traces the route packets take to reach a destination. Shows all intermediate hops and their response times.

      tracert <destination>  (Windows)
      traceroute <destination>  (Linux/Unix)
      

    2. DNS Resolution Commands

    • nslookup: Queries DNS servers to resolve domain names to IP addresses and vice versa.

      nslookup <domain name>
      
    • dig: Performs DNS lookups with detailed information about DNS records.

      dig <domain name>
      

    3. Network Configuration Commands

    • ipconfig/ifconfig: Displays network interface configuration including IP address, subnet mask, and gateway.

      ipconfig  (Windows)
      ifconfig  (Linux/Unix)
      
    • route: Displays and modifies the routing table.

      route print
      

    4. Connection and Port Testing

    • telnet: Tests connectivity to a specific port on a remote host.

      telnet <host> <port>
      
    • netstat: Shows active network connections, listening ports, and network statistics.

      netstat -an
      

    5. Packet Analysis

    • tcpdump/Wireshark: Captures and analyzes network packets for detailed traffic inspection.

    These commands help identify network problems, verify connectivity, and diagnose performance issues systematically.

  10. 105 marksDHCP principles and operationAnswer

    What is DHCP? How can you configure the DHCP server? Explain. [1+4]

    DHCP: Definition and Server Configuration

    1. What is DHCP? (1 mark)

    DHCP (Dynamic Host Configuration Protocol) is a network protocol that automatically assigns IP addresses and other network configuration parameters to devices (clients) on a network. Instead of manually configuring each device with a static IP address, DHCP enables devices to obtain their network settings dynamically from a DHCP server.

    Key purpose: Simplifies network administration by automating IP address allocation and management.


    2. How to Configure the DHCP Server (4 marks)

    Configuration Steps:

    Step 1: Install DHCP Server Software

    • Install the DHCP server package on the designated server machine
    • Example: apt-get install isc-dhcp-server (on Linux/Ubuntu)

    Step 2: Configure the DHCP Configuration File

    The main configuration file is typically /etc/dhcp/dhcpd.conf. Key configurations include:

    • Define Subnet: Specify the network subnet and netmask

      subnet 192.168.1.0 netmask 255.255.255.0 {
      }
      
    • Set IP Address Pool: Define the range of IP addresses to be assigned

      range 192.168.1.100 192.168.1.200;
      
    • Configure Default Gateway: Specify the router/gateway address

      option routers 192.168.1.1;
      
    • Set DNS Servers: Provide DNS server addresses

      option domain-name-servers 8.8.8.8, 8.8.4.4;
      
    • Set Lease Time: Define how long a client can use an assigned IP

      default-lease-time 600;
      max-lease-time 7200;
      

    Step 3: Specify Network Interface

    • Configure which network interface the DHCP server listens on
    • Edit /etc/default/isc-dhcp-server and set INTERFACESv4="eth0"

    Step 4: Start and Enable the Service

    • Start the DHCP server: systemctl start isc-dhcp-server
    • Enable on boot: systemctl enable isc-dhcp-server

    Step 5: Verify Configuration

    • Check service status: systemctl status isc-dhcp-server
    • Monitor DHCP logs for client requests and IP assignments

    Result: Clients on the network can now automatically obtain IP addresses and network settings from the configured DHCP server.

  11. 115 marksSMTP, POP3, and IMAP email protocolsAnswer

    Explain the roles of SMTP, POP3, and IMAP in email communication. [5]

    Email communication requires multiple protocols working together. SMTP, POP3, and IMAP are the three fundamental protocols that handle different aspects of email transmission and retrieval. --- Role: Sending and relaying emails - Functio...

  12. 1210 marksVariable Length Subnet MaskingAnswer

    Write short notes on: a) VLSM b) ACL [5+2.5+2.5]

    Definition: VLSM is a subnetting technique that allows different subnets within the same network to have different subnet mask lengths. Unlike traditional subnetting where all subnets use the same mask, VLSM enables variable-length masks...