Linux Foundation · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
10% of exam · 6 sample questions below
An administrator wants to enforce that users in the 'contractors' group must change their password every 30 days, with a warning 7 days before expiry. Which command should be used?
groupmod -p 30 contractors
passwd -x 30 -w 7 contractors
usermod -e 30 contractors
chage -M 30 -W 7 contractors
Incorrect. `chage -M 30 -W 7` is the right command for password aging, but it requires a username, not a group name.
Which THREE commands can be used to list all users currently logged into the system?
w
The `w` command reads `/var/run/utmp` and prints every logged-in user alongside their terminal, source host, login time and current activity, satisfying the requirement to list all users currently logged into the system. It shows the full session table rather than only the invoking user, as `whoami` would.
last
users
The 'users' command reads utmp and outputs a space-separated list of usernames for every active login session, printing a name once per session. It satisfies the requirement to list all users currently logged into the system.
id
who
`who` reads the utmp database, which records active login sessions, and prints each logged-in user with their terminal, login time and remote host. This directly satisfies the stem's requirement to list all users currently logged into the system, unlike commands that query account databases rather than live sessions.
Which THREE files are directly related to user and group management in a Linux system? (Select three.)
/etc/sudoers
/etc/login.defs
/etc/group
/etc/group stores group names, GIDs and membership lists, forming the core database consulted by group management tools. It is directly related to user and group management, unlike unrelated system files such as /etc/fstab or /etc/hosts.
/etc/passwd
/etc/passwd stores user account records — username, UID, GID, home directory and login shell — making it a core file for user management. Group membership is also referenced here via the primary GID field, satisfying the stem's requirement for files directly tied to user and group administration.
/etc/shadow
/etc/shadow holds the encrypted password hashes and ageing fields — last change, minimum, maximum and warning days — separate from /etc/passwd to restrict read access. It directly governs user authentication and password policy, satisfying the stem's user-management criterion.
A user 'alice' cannot log in via SSH. The administrator checks /etc/passwd and sees: alice:x:1002:1002::/home/alice:/sbin/nologin. Which command should be used to allow alice to log in with a bash shell?
usermod -d /home/alice alice
usermod -u 1002 alice
usermod -s /bin/bash alice
The account's login shell is set to /sbin/nologin, which deliberately blocks interactive SSH sessions. Running usermod -s /bin/bash alice rewrites the seventh field of alice's /etc/passwd entry to a valid interactive shell, directly satisfying the requirement that she log in with bash.
useradd -m -s /bin/bash alice
A security policy requires that user 'svc_backup' have a password that never expires. Additionally, the account should be locked after 90 days of inactivity. Which set of commands achieves this?
chage -W 7 -I 90 svc_backup
chage -E 2025-01-01 -I 90 svc_backup
chage -M 99999 -I 90 svc_backup
The -M 99999 flag sets the maximum days between password changes to effectively never expire, meeting the no-expiry policy. The -I 90 flag sets the inactivity period, after which the account is locked, satisfying the 90-day lockout requirement precisely.
chage -M 90 -I 90 svc_backup
A user named 'charlie' has just been added to the 'devops' group. However, when 'charlie' runs 'sudo -l', no sudo entries are shown. What is the most likely cause?
'charlie' is not listed by name in the sudoers file.
'charlie' must log out and log back in for the group change to take effect.
Group membership is resolved at login and cached in the session's credential set. Charlie's existing shell still holds the old groups, so sudo matches no rule. Logging out and back in refreshes the supplementary group list, making the devops sudo entries visible.
'charlie' is also a member of another group that restricts sudo.
The systemctl command is not executable by 'charlie'.
The sudoers file has a syntax error.
Want more User and Group Management practice?
Practice this domain13% of exam · 6 sample questions below
A system administrator wants to view the last 10 lines of the system log file '/var/log/syslog' and continue to watch for new lines as they are appended. Which command should be used?
tail -n 10 /var/log/syslog
less /var/log/syslog
tail -n 10 -f /var/log/syslog
The -n 10 flag prints the final ten lines, and -f keeps the file descriptor open, streaming appended lines to standard output as they are written. This combination satisfies both viewing historical entries and live monitoring of /var/log/syslog in one command.
head -n 10 /var/log/syslog
An administrator is troubleshooting a server that runs a critical application. The server has 16 GB of RAM and 8 CPU cores. The administrator notices that the server becomes very slow during peak hours. Analysis of 'iostat -x 1' shows that the average wait time (await) for the main disk (sda) is consistently above 1000 ms, while the average service time (svctm) is around 5 ms. What is the most likely cause?
The CPU is overloaded, causing processes to wait for CPU time.
The system is using swap space heavily, causing disk I/O.
The disk is experiencing hardware errors.
There is a large queue of I/O requests waiting to be serviced.
Await of 1000ms against svctm of 5ms means requests spend almost all their time queued rather than being serviced. The disk itself is fast; the bottleneck is the backlog of pending I/O requests exceeding what sda can dispatch concurrently.
A systems administrator is troubleshooting a server that runs a database application. The server has 64 GB of RAM and 16 CPU cores. The administrator notices that the system is using a significant amount of swap space even though there is plenty of free memory. The 'free -m' command shows: total memory = 65536, used = 50000, free = 15536, buffers/cache = 10000, swap total = 8192, swap used = 6000. Which of the following is the most likely cause?
The vm.dirty_ratio and vm.dirty_background_ratio are set too high.
The vm.swappiness value is set too high.
A high vm.swappiness value makes the kernel aggressively reclaim anonymous pages to swap even when free memory remains, matching the observed 6 GB swap usage alongside 15 GB free. Lowering swappiness keeps pages resident until memory pressure genuinely demands swapping.
The database is configured to use huge pages, which are not swappable.
The vm.vfs_cache_pressure is set too low.
Which TWO of the following are correct statements about systemd journald configuration?
The 'MaxRetentionSec' directive sets the maximum time to retain journal entries.
MaxRetentionSec specifies the maximum time (in seconds) that journal entries are kept. Older entries are deleted.
The 'RuntimeMaxUse' directive applies to the journal stored in /var/log/journal.
The 'SystemMaxUse' directive in journald.conf limits the maximum disk space used by the journal.
This is correct; SystemMaxUse specifies the maximum amount of disk space the journal may use on persistent storage.
The 'Compress' directive is set to 'no' by default.
The 'ForwardToSyslog' directive is set to 'yes' by default.
A system administrator needs to check the current CPU load and memory usage on a Linux server. Which command should be used to display a dynamic, real-time view of running processes and system resource utilization?
uptime
top
top provides a continuously refreshing, real-time view of running processes alongside CPU load averages and memory utilisation, updating by default every few seconds. This satisfies the dynamic, real-time requirement, unlike one-shot tools such as free or vmstat.
ps aux
free -h
Based on the journalctl output, what is the most likely cause of the service failure?
Another process is already using port 8080.
The journal shows the service failed to bind its listening socket because port 8080 was already held by another process, producing an address-already-in-use error. This satisfies the stem by identifying port contention, not a configuration or permission fault, as the cause.
The service configuration file has a syntax error.
The system is out of memory.
The service is trying to write to a read-only filesystem.
Want more Operation of Running Systems practice?
Practice this domainA user reports that a script fails with 'Permission denied' when executed. The script has permissions -rw-r--r-- and is owned by the user. Which command should the user run to make the script executable for the owner only?
chmod u+s script.sh
chmod u+x script.sh
The file lacks execute permission for the owner, producing 'Permission denied'. chmod u+x adds execute only for the owner, matching the requirement to make it executable for the owner alone without altering group or other permissions.
chown :users script.sh
chmod +x script.sh
A system administrator needs to find all files in /var/log that have been modified in the last 7 days. Which command accomplishes this?
find /var/log -type f -atime -7
find /var/log -type f -ctime -7
find /var/log -type f -mtime +7
find /var/log -type f -mtime -7
Correct: -mtime -7 means modified less than 7 days ago.
A user wants to find the location of the 'grep' binary. Which command should they use?
man grep
which grep
The which command searches the directories listed in the PATH environment variable and returns the full path of the first matching executable. This directly locates the grep binary's filesystem location, satisfying the user's requirement without invoking or executing it.
uname -a
grep -r 'grep' /usr/bin
Which THREE commands can be used to view the contents of a file?
grep
find
cat
Concatenates and displays file contents.
head
Displays the first few lines of a file.
less
Displays file contents page by page.
What is the purpose of the chmod 755 command in this exhibit?
Add execute permission for the owner only
Remove write permission for others
Set the setuid bit
Set permissions to rwxr-xr-x
Numeric mode 755 grants the owner read, write and execute (7), and group and others read and execute (5), producing rwxr-xr-x. This satisfies the requirement to translate the octal permission value into its symbolic equivalent.
Based on the exhibit, which process will be affected if the root user runs 'kill 5678'?
The www-data process with PID 5678
Sending SIGTERM to PID 5678 terminates the process owned by www-data, since kill defaults to signal 15 and root bypasses ownership restrictions. This satisfies the exhibit's constraint: the target PID belongs to the www-data user, so root's kill affects that specific process rather than any other.
The root process (PID 1234)
All www-data processes
No process, because root cannot kill www-data processes
Want more Essential Commands practice?
Practice this domainA system administrator notices that a web server is not reachable from the internet but is reachable from the internal network. The server's IP is 10.0.1.10/24, and the gateway is 10.0.1.1. Which command should be used to verify the default gateway configuration?
arp -a
ip route show
`ip route show` dumps the kernel routing table, exposing the default route and its gateway. For 10.0.1.10/24, it confirms whether a `default via 10.0.1.1` entry exists — the exact misconfiguration that would block internet-bound traffic while leaving the internal subnet reachable.
ip addr show
ss -tln
A developer needs to temporarily allow incoming TCP connections on port 8080 for testing. Which iptables command adds a rule to the INPUT chain to accept this traffic?
iptables -A OUTPUT -p tcp --sport 8080 -j ACCEPT
iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
The -A INPUT flag appends a rule to the INPUT chain, -p tcp matches the protocol, --dport 8080 targets the destination port, and -j ACCEPT sets the verdict. This permits inbound TCP connections on port 8080 without altering existing rules.
iptables -A FORWARD -p tcp --dport 8080 -j ACCEPT
iptables -I INPUT 1 -p tcp --dport 8080 -j DROP
An administrator wants to permanently configure a static IP address on a CentOS 7 system. Which file should be edited?
/etc/sysconfig/network-scripts/ifcfg-eth0
Editing /etc/sysconfig/network-scripts/ifcfg-eth0 satisfies the persistence constraint: CentOS 7's NetworkManager and legacy network service both read per-interface ifcfg files at boot, so BOOTPROTO=none, IPADDR, NETMASK and GATEWAY survive reboots. Runtime tools like ip or ifconfig change only the live kernel state and are lost on restart.
/etc/sysconfig/network
/etc/hostname
/etc/network/interfaces
A network administrator needs to block all incoming SSH traffic (port 22) from the 192.168.2.0/24 subnet. Which iptables command accomplishes this?
iptables -A INPUT -d 192.168.2.0/24 -p tcp --dport 22 -j DROP
iptables -A OUTPUT -d 192.168.2.0/24 -p tcp --sport 22 -j DROP
iptables -A INPUT -s 192.168.2.0/24 -j DROP
iptables -A INPUT -s 192.168.2.0/24 -p tcp --dport 22 -j DROP
Appending a rule to the INPUT chain with `-s 192.168.2.0/24` matches the source subnet, `-p tcp --dport 22` targets SSH, and `-j DROP` silently discards matching packets, satisfying the requirement to block all incoming SSH from that subnet.
An administrator is troubleshooting intermittent connectivity issues. Running 'ping -c 100 -i 0.2 10.0.0.1' shows about 5% packet loss. What is the primary purpose of the '-i 0.2' option?
It sets the TTL to 0.2
It sets the timeout to 0.2 seconds
It sets the packet size to 0.2 bytes
It sets the interval between pings to 0.2 seconds
The -i flag controls the delay between successive ping packets, so 0.2 sets a 200 ms gap rather than the default one second. This accelerates the 100-packet run, letting the administrator gather loss statistics quickly while still detecting the intermittent connectivity.
Which command displays the listening UDP ports on a Linux system?
ss -a
ss -tln
ss -uln
-u for UDP, -l for listening, -n for numeric.
netstat -tln
Want more Networking practice?
Practice this domain12% of exam · 6 sample questions below
A system administrator configures a web server using systemd. After creating a custom service unit file, the administrator runs `systemctl daemon-reload` but the service still fails to start with a 'Unit not found' error. What is the most likely cause?
The administrator forgot to run `systemctl enable` before starting the service.
The unit file is placed in /usr/lib/systemd/system/ instead of /etc/systemd/system/.
The administrator is not in the 'systemd' group.
The service name was misspelled in the `systemctl start` command.
systemd resolves units by exact filename, so a typographical error in the unit name passed to systemctl start yields 'Unit not found' even after daemon-reload succeeds. Verifying the spelling against the unit file in /etc/systemd/system corrects the invocation.
A server runs a custom application that listens on TCP port 8080. The administrator wants to ensure the application starts automatically on boot and restarts if it crashes. Which systemd unit file directive should be used to achieve the restart behavior?
RestartSec=5
Type=notify
RemainAfterExit=yes
Restart=on-failure
`Restart=on-failure` restarts the service only when it exits with a non-zero status, is killed by a signal, or times out — satisfying the crash-recovery requirement without restarting after a clean stop. Paired with `WantedBy=multi-user.target`, it also covers automatic start at boot for the port 8080 application.
An administrator needs to configure a service to run as a non-root user for security reasons. Which systemd unit file directive accomplishes this?
AmbientCapabilities=CAP_NET_BIND_SERVICE
DynamicUser=yes
User=myuser
`User=` drops privileges to the named account before the service's main process starts, satisfying the stem's non-root requirement. systemd performs the setuid itself, so no shell wrapper or `su` is needed. Pair it with `Group=` for full control over the process credentials.
Group=myuser
A developer reports that a web application's logs are not being written to /var/log/myapp.log. The service runs as user 'myapp' and the log directory /var/log/myapp/ has permissions 755 owned by root. What is the most likely cause?
AppArmor is denying access.
SELinux is blocking the write.
The service is logging to systemd-journald instead of a file.
The service user 'myapp' does not have write permission to the log directory.
Directory permissions 755 grant write access only to the root owner, so user 'myapp' cannot create or append to files within /var/log/myapp/. The service therefore fails to open the log for writing, satisfying the stem's constraint that logs are absent despite the service running.
Which THREE actions will affect the state of a systemd service that is currently running? (Choose three.)
systemctl kill myapp.service
Sending a signal via systemctl kill terminates or signals the running process, immediately altering the unit's active state. It satisfies the stem's requirement for an action affecting a currently running service, unlike query or enable operations that leave runtime state untouched.
systemctl reload myapp.service
Issuing `systemctl reload myapp.service` triggers the service's ExecReload command, causing systemd to re-read its configuration without stopping the process. This changes the running service's operational state, satisfying the stem's requirement that the action affects a currently running unit, unlike commands that merely query status.
systemctl disable myapp.service
systemctl daemon-reload
systemctl stop myapp.service
Stopping the unit terminates its running processes and transitions the service from active to inactive. This is the definitive state-changing action, directly satisfying the stem's requirement that the action affect a currently running systemd service.
An administrator runs 'systemctl status sshd' and sees the output above. The administrator wants sshd to start automatically at boot. Which command should be used?
systemctl reenable sshd
systemctl mask sshd
systemctl start sshd
systemctl enable sshd
systemctl enable creates the symlinks in the appropriate target's .wants directory, so systemd starts sshd automatically during boot. It does not start the unit now, which is why enable is paired with start when immediate activation is also needed.
Want more Service Configuration practice?
Practice this domainWhich command can be used to display the UUID of a filesystem on /dev/sdb1?
blkid /dev/sdb1
`blkid /dev/sdb1` queries the block device directly, reading the filesystem superblock to report its UUID, TYPE and LABEL. Because it inspects the device itself rather than mount tables, it satisfies the stem's requirement to display the UUID of the filesystem on that specific unmounted partition.
tune2fs -l /dev/sdb1
df -h /dev/sdb1
lsblk /dev/sdb1
An administrator needs to mount an XFS filesystem with options to optimize for a database workload. Which mount option would reduce metadata updates to improve performance?
noexec
nodiratime
relatime
noatime
noatime suppresses access-time updates on every file read, eliminating a metadata write per read. For a database workload performing constant reads, this reduces journal and metadata overhead on the XFS filesystem, improving throughput without affecting data integrity.
A system administrator notices that a new 500GB SSD (/dev/sdb) is not being recognized by the system after installation. The server uses UEFI and GPT partitioning. Which command should the administrator run first to verify that the disk is detected by the kernel?
fdisk -l /dev/sdb
lsblk
lsblk reads /sys/block and udev data to list all block devices the kernel currently recognises, so it immediately confirms whether /dev/sdb was detected after installation without altering anything. This satisfies the stem's requirement to verify kernel-level disk detection first.
cat /proc/cpuinfo
lsusb
Which TWO commands can be used to mount a filesystem on /dev/sdb1 to /mnt/data?
mount /mnt/data /dev/sdb1
mount /dev/sdb1 /mnt/data
The two-argument form lets mount auto-detect the filesystem type from the device's superblock, then attach /dev/sdb1 at /mnt/data. No type or options are required, satisfying the requirement to mount that specific block device at that mount point.
mount -t ext4 /dev/sdb1 /mnt/data
The `-t ext4` flag explicitly declares the filesystem type, so the kernel invokes the ext4 driver rather than probing. This satisfies the stem's requirement to mount the specific block device `/dev/sdb1` at the `/mnt/data` mount point, and works even when automatic detection is unavailable or ambiguous.
mount -o loop /dev/sdb1 /mnt/data
mount -t auto /dev/sdb1 /mnt/data -o loop
Which THREE of the following are valid Linux filesystem types that can be used for root partitions on a modern Linux system?
XFS
XFS is a mature, high-performance 64-bit journaling filesystem, and every mainstream distribution supports it as a root partition, including GRUB and initramfs tooling. It satisfies the stem's requirement for a valid modern Linux root filesystem type.
NTFS
FAT32
Btrfs
Btrfs is a copy-on-write filesystem with snapshots, checksums and subvolumes, and distributions such as openSUSE and Fedora support it as a root partition. It satisfies the stem's requirement for a valid modern Linux root filesystem type.
ext4
ext4 is a journalling filesystem with extents, delayed allocation and support for volumes up to 1 EiB, and every mainstream distribution's installer offers it for the root partition. It remains a valid, fully supported root filesystem type on modern Linux systems.
After extending the logical volume, the df output still shows 100G. What is the most likely reason?
The filesystem on the logical volume has not been resized.
Extending the logical volume only enlarges the block device; the filesystem on top retains its original size until explicitly grown. Since df reports filesystem capacity, not volume size, it still shows 100G. Resizing the filesystem (for example with resize2fs or xfs_growfs) is required to reflect the added space.
lvresize must be used instead of lvextend.
The kernel has not detected the new size; reboot required.
The mount point must be remounted with the 'remount' option.
Want more Storage Management practice?
Practice this domainThe LFCS exam is performance-based — there are no multiple-choice questions. It is a hands-on lab exam completed within 120 minutes. You complete practical tasks in a live or simulated environment. Courseiva practice questions cover the underlying concepts.
Hands-on Linux administration tasks completed in a live Linux environment.
The exam covers 6 domains: User and Group Management, Operation of Running Systems, Essential Commands, Networking, Service Configuration, Storage Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Linux Foundation LFCS exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.