LPI · Free Practice Questions · Last reviewed May 2026
42real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
14% of exam · 6 sample questions below
A system administrator needs to install the latest version of a package named 'webapp' from a third-party repository that has been added to the system. Which command should be used to update the package list and install the package in one step?
apt-get update && apt-get install webapp
Chaining apt-get update with apt-get install refreshes the package lists from all configured sources, including the newly added third-party repository, then installs webapp in a single command. Without the update step, apt-get install would use stale metadata and fail to locate the latest version.
apt-get upgrade webapp
dpkg -i webapp.deb
apt-cache search webapp && apt-get install webapp
A Linux administrator is troubleshooting a package dependency issue. When attempting to install package 'foo', the package manager reports a missing dependency 'libbar.so.2'. Which of the following is the most appropriate next step?
Run 'ldconfig' to update the library cache
Reinstall the 'foo' package using 'rpm -i --force foo.rpm'
Run 'rpm -q --whatrequires libbar.so.2'
Use 'apt-file search libbar.so.2' or 'dnf provides libbar.so.2' to find the package that contains the file
The missing dependency is a shared library file, not a package name, so the package manager cannot resolve it directly. Querying which package provides libbar.so.2 identifies the correct RPM or DEB to install, satisfying the dependency.
A system administrator wants to compile and install a program from source. After running './configure --prefix=/opt/myapp', the configure script fails with an error about missing 'libssl-dev'. What should the administrator do to resolve this issue?
Install the 'libssl-dev' package using the package manager
The configure script needs the OpenSSL development headers and libraries to compile against. Installing libssl-dev via the package manager provides those headers and the linker files, allowing ./configure to complete and the build to proceed.
Manually download and place the missing header files in /usr/include
Install the 'libssl' runtime library
Add the '--disable-ssl' flag to ./configure
A technician needs to remove a package named 'apache2' along with its configuration files from a Debian system. Which command should be used?
dpkg -r apache2
apt-get autoremove apache2
apt-get purge apache2
`apt-get purge apache2` removes both the package and its configuration files, satisfying the stem's explicit requirement to delete configuration alongside the package. Unlike `remove`, which leaves conffiles on disk, `purge` deletes them, so no residual settings remain on the Debian system.
apt-get remove apache2
A Linux administrator is managing a server that uses RPM-based package management. They need to find which installed package provides the '/etc/ssh/sshd_config' file. Which command should they use?
rpm -qi /etc/ssh/sshd_config
rpm -qf /etc/ssh/sshd_config
The -qf flag queries the RPM database for the package owning a specified file path, directly satisfying the need to identify the provider of /etc/ssh/sshd_config. Unlike -ql, which lists files within a named package, -qf works backwards from the file to its owning package.
rpm -ql /etc/ssh/sshd_config
rpm -qa | grep sshd_config
An organization uses a custom YUM repository. After adding a new RPM package to the repository, clients running 'yum update' do not see the new package. The repository metadata was regenerated using 'createrepo'. What is the most likely reason the clients are not seeing the update?
Clients have cached metadata and need to run 'yum clean all' or wait for cache expiration
Cached metadata is the culprit: YUM stores repository metadata locally and only refreshes it when the expiry window lapses, so freshly regenerated repodata stays invisible until then. Running 'yum clean all' forces a metadata re-download, immediately exposing the new RPM to 'yum update'.
The 'gpgcheck=1' option in the repo file prevents metadata download
The repository metadata was not signed with a GPG key
The RPM package version number is lower than the currently installed version
Want more Linux Installation and Package Management practice?
Practice this domain14% of exam · 6 sample questions below
A systems administrator needs to change the permissions of the file /home/user/script.sh so that the owner can read, write, and execute; the group can read and execute; and others have no access. Which command accomplishes this?
chmod 755 /home/user/script.sh
chmod 750 /home/user/script.sh
750 gives rwx for owner, r-x for group, and --- for others, matching the requirement.
chmod 770 /home/user/script.sh
chmod 741 /home/user/script.sh
Which TWO commands can be used to view the contents of a compressed file named archive.tar.gz without extracting it to disk?
gzip -d archive.tar.gz
bunzip2 -c archive.tar.gz | tar -t
tar -tzf archive.tar.gz
The `-t` flag lists archive contents, while `-z` pipes through gzip decompression and `-f` specifies the filename, so `tar -tzf archive.tar.gz` reads and decompresses the gzip stream in memory. This satisfies the stem's constraint of viewing contents without extracting anything to disk.
gunzip -l archive.tar.gz
zcat archive.tar.gz | tar -t
Piping through zcat decompresses the gzip stream to stdout, which tar reads from standard input; the -t flag then lists archive members without writing them to disk. This satisfies the stem's requirement to view contents without extraction, though the pipeline is redundant since tar -tzf does both steps directly.
Arrange the steps to configure a static IP address on a Linux system using the command line.
Step 1: Open the network configuration file (e.g., /etc/network/interfaces). Step 2: Configure the interface with static IP, netmask, gateway, and DNS. Step 3: Save and exit the file. Step 4: Restart the networking service.
This is the correct order because you must first open the config file, then set the parameters, save changes, and finally restart networking to apply them.
Step 1: Restart the networking service. Step 2: Open the network configuration file. Step 3: Configure the interface with static IP, netmask, gateway, and DNS. Step 4: Save and exit the file.
Step 1: Open the network configuration file. Step 2: Save and exit the file. Step 3: Configure the interface with static IP, netmask, gateway, and DNS. Step 4: Restart the networking service.
Step 1: Configure the interface with static IP, netmask, gateway, and DNS. Step 2: Restart the networking service. Step 3: Open the network configuration file. Step 4: Save and exit the file.
Match each Linux runlevel to its typical description.
runlevel 0: Halt
Runlevel 0 is used to halt the system.
runlevel 1: Single-user mode
Runlevel 1 is single-user mode, often used for maintenance.
runlevel 3: Graphical multi-user mode
runlevel 5: Multi-user mode with network
runlevel 6: Reboot
Runlevel 6 is used to reboot the system.
An administrator needs to copy a directory hierarchy from one server to another over SSH, preserving permissions, ownership, and timestamps. Which command is most appropriate?
cp -a /source /mnt/remote
tar cf - /source | ssh user@dest "tar xf - -C /target"
Preserves all metadata and works over SSH.
scp -rp /source user@dest:/target
rsync -avz /source user@dest:/target
Refer to the exhibit. The process with PID 1234 is in state 'Z'. What is the most likely cause and appropriate action?
The process is stopped; use kill -CONT to continue.
The process is a daemon; it should be restarted.
The process is sleeping; wait for it to become ready.
The process is a zombie; the parent process must be killed or wait for it to be reaped.
A 'Z' state means the process has terminated but its exit status remains in the process table because the parent has not called wait(). Killing the parent, or letting it reap the child, removes the zombie entry.
Want more GNU and Unix Commands practice?
Practice this domain14% of exam · 6 sample questions below
A system administrator wants to ensure that the syslog service starts automatically on boot and is running immediately without a reboot. Which command sequence should be used?
systemctl start syslog && systemctl enable syslog
systemctl start --enable syslog
systemctl enable syslog && systemctl start syslog
systemctl enable --now syslog
`systemctl enable --now syslog` satisfies both constraints in one invocation: `enable` creates the persistent symlink so the unit starts at every boot, while `--now` additionally starts it immediately in the current session, avoiding the reboot the stem forbids.
A server has a backup script that runs daily at midnight. The system administrator notices that the script sometimes fails because the filesystem is mounted read-only. Which approach is the best practice to ensure the script runs only when the filesystem is writable?
Add a cron job that runs before the backup to remount the filesystem read-write
Use anacron to run the job after boot
Wrap the backup command in a script that checks if the filesystem is writable before proceeding
Testing writability with a command such as touch or mount before invoking the backup prevents failures caused by a read-only remount. The wrapper aborts cleanly instead of leaving a partial archive, directly addressing the intermittent read-only filesystem constraint.
Change the cron job to run every hour until it succeeds
An administrator needs to find all files in the /var/log directory that have been modified in the last 24 hours. Which command should be used?
find /var/log -ctime 0
find /var/log -mtime 0
The -mtime 0 predicate matches files whose data was modified less than 24 hours ago, since find counts in 24-hour periods and 0 covers the current partial day. This precisely satisfies the requirement to list recently modified files under /var/log.
find /var/log -atime 0
find /var/log -mmin 1440
An administrator wants to prevent a specific user, 'john', from being able to schedule cron jobs. Which file should the administrator modify?
/var/spool/cron/crontabs
/etc/cron.allow
/etc/crontab
/etc/cron.deny
Adding john to /etc/cron.deny blocks that named user from submitting jobs via crontab, satisfying the requirement to prevent only him from scheduling cron jobs. The file lists users barred from cron, and it takes effect only while /etc/cron.allow is absent.
Which TWO commands can be used to display the current runlevel of a system?
telinit q
systemctl get-default
init 3
runlevel
The `runlevel` command reads `/var/run/utmp` and prints the previous and current runlevel, satisfying the requirement to display the system's current runlevel. It reports both values directly, for example "N 5", making it a valid answer alongside `who -r`.
who -r
who -r queries the utmp record for the current runlevel and prints it, satisfying the requirement to display the system's runlevel. Its output includes the runlevel character and the time it was entered, unlike who's default user listing.
Based on the exhibit, which of the following is true about the cleanup.sh job?
It runs at 4:30 AM every day
It runs at 4:30 AM on Monday through Friday
The cron schedule encodes minute 30, hour 4, and a day-of-week field restricted to Monday through Friday, so the job executes at 04:30 on weekdays only. This matches the stated behaviour of the cleanup.sh job shown in the exhibit.
It runs at 4:00 AM on weekdays
It runs at 4:30 AM on weekends
Want more Administrative Tasks practice?
Practice this domain15% of exam · 6 sample questions below
Which of the following commands displays the amount of free disk space on all mounted filesystems in a human-readable format?
df -i
df -h
The -h flag makes df print sizes in powers of 1024 with human-readable suffixes (K, M, G), satisfying the human-readable requirement. Without it, df reports raw 1K blocks across all mounted filesystems, which is harder to interpret.
du -sh
df -T
An administrator needs to create a new ext4 filesystem on /dev/sdb1 and wants to reserve 2% of the blocks for the root user. Which command should be used?
mkfs.ext4 -m 2 /dev/sdb1
The `-m` flag on `mkfs.ext4` sets the percentage of filesystem blocks reserved for root, so `-m 2` reserves exactly 2%, satisfying the stem's constraint. It creates the ext4 filesystem on /dev/sdb1 in one step, unlike `tune2fs -m`, which only adjusts reservation on an existing filesystem.
tune2fs -m 2 /dev/sdb1
mke2fs -r 2 /dev/sdb1
mkfs.ext4 -R 2 /dev/sdb1
A Linux system has a software RAID1 array /dev/md0 consisting of /dev/sda1 and /dev/sdb1. After replacing a failed disk, the administrator runs 'mdadm --manage /dev/md0 --add /dev/sdc1', but the array remains degraded. Which command should be used to check the status of the array?
mdadm --examine /dev/sdc1
mdadm --version
mdadm --detail /dev/md0
`mdadm --detail /dev/md0` reports the array's current state, including which member devices are active, failed or spare, and the overall RAID1 redundancy level. This directly satisfies the stem's requirement to check why the array remains degraded after adding /dev/sdc1, showing whether the new device was actually incorporated.
mdadm --query /dev/md0
Which directory in the Filesystem Hierarchy Standard (FHS) contains essential user command binaries that are needed in single-user mode?
/tmp
/sbin
/bin
/bin holds essential user command binaries required for single-user mode and system repair, such as ls, cp and sh. The FHS designates it specifically for commands needed before other filesystems are mounted, matching the stem's single-user-mode constraint.
/boot
An administrator needs to mount an ISO image file /tmp/image.iso to the directory /mnt/iso. Which command should be used?
mount -o loop /tmp/image.iso /mnt/iso
The loop option attaches the ISO as a loopback block device, allowing the kernel to read its ISO9660 filesystem and mount it at /mnt/iso. Without -o loop, mount would treat the file as a raw block device and fail.
mount -o ro /tmp/image.iso /mnt/iso
mount -t iso /tmp/image.iso /mnt/iso
mount /tmp/image.iso /mnt/iso
A system is running out of disk space on /var. The administrator finds that /var/log/syslog is 4GB. Which of the following is the best course of action to prevent future issues while keeping recent logs?
Use 'truncate -s 0 /var/log/syslog' to empty the file.
Configure logrotate to rotate and compress logs daily.
logrotate rotates /var/log/syslog on a daily schedule, compressing archived copies and enforcing retention limits, so recent logs remain readable while total size stays bounded. This directly satisfies the stem's constraint of preventing recurrence while preserving recent log data.
Configure syslog to stop logging.
Delete /var/log/syslog and create an empty file.
Want more Devices, Filesystems and FHS practice?
Practice this domain14% of exam · 6 sample questions below
A system administrator writes a script that extracts data from a CSV file and inserts it into a database. The script works correctly when run manually but fails when executed by cron. Which environment variable is most likely causing the issue?
SHELL
LANG
HOME
PATH
Cron executes jobs with a minimal environment, so PATH typically omits directories available in an interactive shell. Commands resolving manually then fail under cron because the binary cannot be located, unless absolute paths or an explicit PATH are set.
A developer needs to ensure a bash script exits immediately if any command fails, and also prints each command before executing it. Which set of shell options should be used at the beginning of the script?
set -ex
`set -e` makes the shell exit immediately when any command returns a non-zero status, satisfying the fail-fast requirement. `set -x` enables tracing, printing each command with its expanded arguments to stderr before execution. Combined as `set -ex`, both constraints in the stem are met within a single statement.
set -e
set -vx
set -ux
A script contains the following line: for i in $(cat file.txt); do echo $i; done. The file file.txt contains a single line with multiple words. How many times will the loop execute?
Equal to the number of lines in the file
Equal to the number of words in the file
Command substitution splits on IFS whitespace, so each word from the single line becomes a separate argument to `for`. The loop therefore iterates once per word, satisfying the stem's constraint of one line containing multiple words. Word count, not line count, determines execution.
Once
The loop will not execute
Which THREE statements are true about the sed command?
sed 's/old/new/g' file.txt permanently changes the file.
sed -i 's/foo/bar/g' file.txt replaces all occurrences of foo with bar in the file.
The `-i` flag edits file.txt in place, so no redirection or temporary file is needed. Combined with the `g` substitution flag, sed replaces every occurrence of foo on each matched line, not merely the first. This satisfies the requirement of replacing all occurrences directly within the file.
sed uses extended regular expressions by default.
sed '/^#/d' file.txt deletes lines that start with #.
The address `/^#/` anchors the pattern to the start of each line, so only lines beginning with `#` match; the `d` command then deletes them, leaving inline hashes untouched. This satisfies the stem's requirement for a true statement about sed's line-addressing and delete behaviour.
sed -n '3,5p' file.txt prints lines 3 to 5 of file.txt.
The `-n` flag suppresses sed's default printing of every line, so only explicit output appears. The address range `3,5` selects lines three through five, and the `p` command prints them. This satisfies the stem's requirement for a true statement about sed, correctly combining address ranges with suppressed automatic output.
A system administrator needs to ensure that a bash script continues executing even if any command in the script fails. Which of the following should be used at the beginning of the script?
set +e
`set +e` disables the errexit behaviour, so bash continues running subsequent commands after any individual command returns a non-zero exit status. This directly satisfies the stem's requirement that the script keeps executing despite failures, since errexit is off by default but may have been enabled by a prior `set -e`.
trap 'echo error' ERR
unset -e
set -e
# set +e
Match each package manager to its associated distribution family.
APT: Debian-based distributions
APT is the package manager used by Debian, Ubuntu, and their derivatives.
YUM: Red Hat-based distributions
YUM (now often replaced by DNF) is the package manager for Red Hat Enterprise Linux, Fedora, CentOS, etc.
ZYpp: SUSE-based distributions
ZYpp is the package manager used by openSUSE and SUSE Linux Enterprise.
pacman: Arch Linux
pacman is the package manager for Arch Linux and its derivatives.
APT: Red Hat-based distributions
YUM: SUSE-based distributions
Want more Shells, Scripting and Data Management practice?
Practice this domain14% of exam · 6 sample questions below
A system administrator notices that the NTP service on a Linux server is not synchronizing time with external NTP servers. The administrator runs 'ntpq -p' and sees that all servers listed have a 'reach' value of 0. Which of the following is the most likely cause?
The system timezone is incorrectly set.
The NTP service is configured to use the local clock.
A firewall is blocking UDP port 123.
A reach value of 0 means no NTP reply packets have been received in the last eight poll intervals. Blocked UDP port 123 prevents the server responses from arriving, so the client cannot synchronise despite the daemon running.
The NTP server is using a different NTP version.
Which of the following commands will display the default gateway of a Linux system?
arp -a
netstat -i
ip route show
The ip route show command prints the kernel routing table, whose default entry (destination 0.0.0.0/0) lists the gateway address. This directly satisfies the stem's requirement to display the default gateway, unlike ip addr, which only shows interface addressing.
ifconfig
A database server on a Linux system is configured to listen on TCP port 3306. The administrator wants to restrict access to the database server to only the local network (192.168.1.0/24) using iptables. Which of the following iptables rules achieves this?
iptables -A INPUT -p tcp --dport 3306 -d 192.168.1.0/24 -j DROP
iptables -A OUTPUT -p tcp --dport 3306 -d 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 3306 -s 192.168.1.0/24 -j ACCEPT
This rule matches TCP destination port 3306 with source 192.168.1.0/24 and accepts it, restricting database access to the local subnet. Other traffic to that port falls through to subsequent rules, satisfying the stem's local-network-only constraint.
iptables -A OUTPUT -p tcp --sport 3306 -s 192.168.1.0/24 -j ACCEPT
A user reports that they cannot connect to a remote server using SSH. The administrator checks the SSH server status and it is running. Which of the following is the most likely cause?
A firewall is blocking port 22.
With the SSH daemon confirmed running, a firewall dropping inbound TCP port 22 is the most likely cause, since the service listens but packets never reach it. This directly explains the connection failure despite a healthy server process.
The client's subnet mask is incorrect.
The client cannot resolve the server's hostname.
The SSH server is using UDP instead of TCP.
An administrator is troubleshooting a DNS issue. The command 'dig @8.8.8.8 example.com' returns a response, but 'host example.com' returns 'Host not found'. Which of the following is the most likely cause?
The network interface is down.
The /etc/hosts file is corrupt.
The DNS server at 8.8.8.8 is not responding.
The /etc/resolv.conf file is misconfigured.
The `host` command queries the resolver configured in /etc/resolv.conf, whereas `dig @8.8.8.8` bypasses that file by querying the specified server directly. Since the explicit query succeeds, the resolver configuration must be faulty, satisfying the stem's constraint that only the default lookup path fails.
Which THREE of the following are valid files or directories used by the Domain Name System (DNS) resolution process on a Linux system?
/etc/host.conf
/etc/host.conf configures the order in which the resolver consults sources such as hosts, bind and nis, satisfying the stem's requirement for a valid DNS resolution file. It is read by glibc's resolver, letting administrators prioritise local /etc/hosts entries over DNS queries or vice versa.
/etc/resolv.conf
/etc/resolv.conf satisfies the resolver configuration requirement: it lists the nameserver IP addresses the system queries, plus search domains and options. The glibc resolver reads it directly for every lookup, making it a valid DNS resolution file.
/etc/named.conf
/etc/sysconfig/network
/etc/nsswitch.conf
/etc/nsswitch.conf governs the order in which name-service sources are consulted, letting the hosts database list files, dns or myhostname. DNS resolution on Linux therefore depends on it, because it decides whether the resolver queries /etc/hosts or the configured nameservers first.
Want more Essential System Services and Networking practice?
Practice this domain15% of exam · 6 sample questions below
A server has two disk drives: /dev/sda (SSD) and /dev/sdb (HDD). The administrator wants to place frequently accessed files on the SSD for performance. Which approach best achieves this using Linux filesystem features?
Create separate LVM logical volumes on each disk and mount them at different mount points.
LVM lets you carve separate logical volumes from each physical disk and mount them at distinct paths, so frequently accessed data lives on the SSD while bulk data stays on the HDD. This satisfies the performance placement requirement without exotic tiering software.
Configure RAID 0 across both disks to combine speed.
Use symbolic links to redirect file access to the SSD.
Use a union mount to overlay the SSD on top of the HDD.
A technician is troubleshooting a system that fails to boot with the error 'Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. What is the most likely cause?
The init binary is missing or corrupted.
The root filesystem is corrupted and needs fsck.
The kernel lacks the necessary driver for the storage controller.
The panic occurs because the kernel cannot access the root filesystem, typically when the storage controller driver is built as a module absent from the initramfs. Without that driver, the kernel sees no block device, producing unknown-block(0,0).
The boot loader is not installed correctly.
Which hardware component uses a unique address to identify itself on the network at the data link layer?
IP address
MAC address
The MAC address is a 48-bit identifier burned into the network interface card, used at the data link layer to distinguish frames between hosts on the same segment. It uniquely satisfies the stem's requirement for a hardware component addressing at layer 2.
Hostname
Port number
A Linux system has two network interfaces: eth0 and eth1. The administrator wants to bond them for increased throughput. Which kernel module is required for bonding?
aggregation
bonding
The bonding kernel module provides the driver that aggregates eth0 and eth1 into a single logical interface, enabling the throughput increase the administrator wants. Loading it is the prerequisite before any bond configuration can be applied.
team
bond
Which command displays information about the CPU, including model name, cache size, and flags?
uname -a
lscpu
lscpu reads /proc/cpuinfo and sysfs to report CPU architecture, model name, per-core cache sizes and instruction flags in one view, satisfying the stem's requirement to display all three. Alternatives such as lspci list PCI devices, not processor details.
cat /proc/cpuinfo
dmidecode
A server with a udev rule fails to consistently assign a persistent network interface name. What is the most likely cause?
The rule uses an incorrect operator.
The BIOS device name is configured incorrectly.
The kernel module for the NIC is not loaded.
The network interface's MAC address is not unique or changes.
udev derives persistent names from stable attributes such as MAC address. If the MAC is duplicated, randomised or changes between boots, the rule matches different devices or none, producing inconsistent naming. Non-unique or volatile MAC addresses are the usual root cause.
Want more System Architecture practice?
Practice this domainThe LPIC-1 exam has 60 questions and must be completed in 90 minutes. The passing score is 500/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 7 domains: Linux Installation and Package Management, GNU and Unix Commands, Administrative Tasks, Devices, Filesystems and FHS, Shells, Scripting and Data Management, Essential System Services and Networking, System Architecture. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official LPI LPIC-1 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.