Red Hat · Free Practice Questions · Last reviewed May 2026
54real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
11% of exam · 6 sample questions below
A system administrator needs to create a new ext4 filesystem on /dev/sdb1 and mount it persistently at /data. Which set of commands should be used?
mkfs -t ext4 /dev/sdb1 && mkdir /data && mount /dev/sdb1 /data && echo '/dev/sdb1 /data ext4 defaults 0 0' >> /etc/fstab
This is the only complete sequence: mkfs -t ext4 /dev/sdb1 (equivalent to mkfs.ext4) creates a fresh ext4 filesystem, mkdir /data provides the required directory mount point, mount /dev/sdb1 /data attaches the filesystem for immediate use, and appending a correctly formatted fstab line ('/dev/sdb1 /data ext4 defaults 0 0') ensures the filesystem is mounted automatically at boot. The fstab line contains the six required fields in the correct order, making this the correct answer.
mkfs.ext4 /dev/sdb1 && mount /dev/sdb1 /data
mkfs -t ext4 /dev/sdb1 && echo '/dev/sdb1 /data ext4 defaults 0 0' >> /etc/fstab && mount /data
mkfs.ext4 /dev/sdb1 && mkdir /data && mount /dev/sdb1 /data && blkid /dev/sdb1 >> /etc/fstab
A file server is experiencing slow write performance. The admin suspects the filesystem is nearly full. Which command should be used to check disk usage per partition?
df -h
df -h — Correct: this command invokes df with human-readable units and reports actual disk space usage per mounted filesystem. It shows total capacity, used space, available space, and use percentage, which is exactly what you need to determine if a slow file server is hitting a full partition. Since full filesystems are a top cause of write performance degradation, df -h is the right first diagnostic.
df -i
du -h --max-depth=1 /
du -sh /
An administrator needs to add a 1GB swap partition on /dev/sdd1. Which series of commands accomplishes this?
mkswap /dev/sdd1 && echo '/dev/sdd1 swap swap defaults 0 0' >> /etc/fstab
mkfs.swap /dev/sdd1 && swapon /dev/sdd1
mkswap /dev/sdd1 && swapon /dev/sdd1
fdisk /dev/sdd, create partition, then mkswap /dev/sdd1, swapon /dev/sdd1, and add to /etc/fstab.
This is the complete and correct procedure: fdisk creates a 1 GB partition on /dev/sdd (assigned as /dev/sdd1), mkswap writes the swap signature to that partition, swapon activates the swap for immediate use, and adding the line to /etc/fstab ensures automatic activation at boot. The fstab entry alone or the swapon alone would be incomplete, but combining them covers both current-session and persistent swap. The fdisk step also ensures the partition actually exists with the desired size, unlike the other options that assume a preexisting /dev/sdd1.
A filesystem is reported as 'read-only' after a system crash. The admin runs fsck and sees 'clean' status. What is the most likely reason it remains read-only?
fsck cannot fix errors on ext4 filesystems.
The filesystem is still mounted; fsck cannot fix it while mounted.
The filesystem is XFS, and fsck does not repair XFS.
This is correct. XFS is not repairable by fsck; fsck only inspects the XFS log to see whether the filesystem was cleanly unmounted and reports a 'clean' status based on that flag alone, without traversing metadata structures. To actually verify and repair an XFS filesystem you must use the dedicated xfs_repair utility, so a read-only XFS filesystem after a crash would still be reported as 'clean' by fsck while remaining unusable for writes.
fsck detected errors but did not fix them automatically.
A system has two 500GB disks in a RAID1 (mirror) using mdadm. One disk fails. After replacement, what is the correct procedure to restore redundancy?
Run 'mdadm --manage /dev/md0 --add /dev/sdb'
Remove the failed disk with 'mdadm /dev/md0 --fail /dev/sdb1' then add new.
Run 'mdadm --assemble --scan' to rebuild the array automatically.
Use sfdisk to copy partition table from /dev/sda to /dev/sdb, then 'mdadm --manage /dev/md0 --add /dev/sdb1'
Use 'sfdisk' to clone the partition table from /dev/sda to /dev/sdb, ensuring the new disk has a matching partition layout with the correct RAID partition type and UUIDs. After that, 'mdadm --manage /dev/md0 --add /dev/sdb1' enrolls the freshly partitioned partition as a spare, causing the array to start rebuilding the mirror data. This sequence properly introduces the new disk into the existing RAID1 without disrupting the active array.
Which command creates an XFS filesystem on /dev/nvme0n1p1 and sets the label to 'data'?
mkfs.xfs -l data /dev/nvme0n1p1
mkfs.xfs -f /dev/nvme0n1p1
mkfs.xfs -L data /dev/nvme0n1p1
Uppercase -L is the mkfs.xfs option for setting the XFS volume label, and `data` becomes that label on /dev/nvme0n1p1. This creates a filesystem that can later be referenced via `-L data` in mount options or by symlinks under /dev/disk/by-label/. The command is correct as written and satisfies the requirement to create a labeled XFS filesystem.
mkfs.xfs -n data /dev/nvme0n1p1
Want more Create and configure file systems practice?
Practice this domain11% of exam · 6 sample questions below
A system administrator needs to ensure that a user named 'bob' can access a shared directory '/data' owned by group 'developers'. The directory has permissions 2775 and is owned by root:developers. Bob is a member of the 'developers' group. However, when Bob tries to create a file in '/data', it fails with 'Permission denied'. What is the most likely cause?
The directory has incorrect SELinux context
Even when the directory's mode and ownership (2775, root:developers) grant Bob write access, SELinux performs a separate mandatory access control check. If /data carries a context type that Bob's domain is not allowed to write to (for example, default_t instead of a type like public_content_rw_t or a domain-specific type), the kernel denies the operation with EACCES. This appears as a permission problem though standard permissions are correct. To fix, restore or apply the correct context, e.g., restorecon -Rv /data or a custom semanage fcontext rule.
Bob's umask is set to 0077
The setgid bit is not set
Bob's primary group is not developers
A company policy requires that when a user is deleted, all files owned by that user in /home should be reassigned to a 'guest' account. Which command accomplishes this?
usermod -l guest olduser
find /home -user olduser -exec chown guest {} +
find /home -user olduser -exec chown guest {} + is correct because it searches /home for every file whose owner matches the username olduser (which resolves to the UID) and executes chown guest on them in one batched command, thanks to the + terminator. This directly transfers ownership of each located file to guest, satisfying the policy efficiently. The find approach also covers files outside olduser's home directory that reside anywhere under /home, whereas other options only handle the home directory itself.
userdel -r olduser
rsync -a /home/olduser/ /home/guest/
An administrator wants to add the user 'jane' to the supplementary groups 'wheel' and 'docker' without removing her from other groups. Which command should be used?
groupmems -a jane -g wheel,docker
usermod -aG wheel,docker jane
The -aG form is a compact combined option where -a enables append mode and -G specifies the supplementary group list, so the effect is exactly the same as usermod -a -G. It adds jane to wheel and docker while retaining any other supplementary groups she already has. Although it is less readable than the separated form, it is a fully valid and correct way to accomplish the task.
usermod -a -G wheel,docker jane
Using -a alongside -G directs usermod to append the listed groups to the user's current supplementary groups instead of replacing them. This command explicitly adds jane to both wheel and docker, and because -a is present, all her existing supplementary memberships are left intact. It is the canonical, unambiguous way to satisfy the requirement, and the space between -a and -G is optional but harmless.
usermod -G wheel,docker jane
A server has a requirement that all users in the 'finance' group must have a password aging policy that forces password change every 90 days. Which approach best achieves this for existing users?
Set PASS_MAX_DAYS 90 in /etc/login.defs
Edit /etc/shadow and change the fifth field for all users
Configure pam_pwquality.so to enforce password age
Write a script to run 'chage -M 90' for each user in the finance group
A script that calls chage -M 90 for each user in the finance group is the correct approach because chage directly updates the maximum password age field in /etc/shadow for existing user accounts. For example, you can iterate over `getent group finance | cut -d: -f4`, and run chage for each member, which precisely targets the intended accounts and leaves all other users untouched.
Which TWO commands can change the primary group of an existing user?
usermod -aG
`usermod -aG` adds the user to a supplementary group, not the primary group.
gpasswd -a
`gpasswd -a` adds the user to a supplementary group, not the primary group.
vigr
groupmems -a
useradd -G
A system administrator needs to ensure that the user 'jdoe' cannot log in via SSH but can still use other services like FTP. Which approach should the administrator take?
Lock the user account with 'usermod -L jdoe'
Delete the user's password with 'passwd -d jdoe'
Remove the user's home directory
Change the user's shell to /sbin/nologin
Setting jdoe's shell to /sbin/nologin in /etc/passwd makes PAM deny interactive login sessions, typically printing 'This account is currently not available.' FTP daemons such as vsftpd or proftpd authenticate against /etc/shadow without invoking the user's shell, so they still allow file transfers. Because /sbin/nologin only blocks shell access and does not alter the password hash, it is the standard, targeted solution for allowing non-login services while prohibiting interactive logins.
Want more Manage users and groups practice?
Practice this domain11% of exam · 6 sample questions below
A system administrator needs to add a new 10GB disk to an existing volume group 'vgdata' to extend logical volumes. Which of the following is the correct sequence of commands?
pvcreate /dev/sdb, vgextend vgdata /dev/sdb, lvextend
pvcreate initializes /dev/sdb with LVM metadata, making it a physical volume that LVM can recognize. vgextend then adds that PV to the existing volume group vgdata, increasing its total allocatable space. Only after the VG has free physical extents can lvextend allocate from them to grow a logical volume, followed by a filesystem resize if needed. This dependency chain makes the order mandatory.
vgextend vgdata /dev/sdb, pvcreate /dev/sdb, lvextend
pvcreate /dev/sdb, lvextend, vgextend vgdata /dev/sdb
lvextend, vgextend vgdata /dev/sdb, pvcreate /dev/sdb
After creating a new partition on /dev/sdc, the administrator runs 'partprobe' to inform the kernel of the change. What is the primary purpose of partprobe?
To create a filesystem label
To repair a damaged partition table
To format the partition with a filesystem
To make the kernel re-read the partition table
partprobe, from the parted suite, is specifically designed to make the Linux kernel re-read the partition table from a disk. After partitioning /dev/sdc, the kernel may still have the old view, so partprobe triggers a revalidation so that the new partition appears as a block device (e.g., /dev/sdc1) without requiring a reboot. This is the correct and intended purpose of the command, though in cases where the disk is in use, a reboot or partx may be needed.
An administrator wants to extend an XFS filesystem that resides on an LVM logical volume. The volume group has free physical extents. Which is the correct sequence?
lvextend, then xfs_growfs
Extending the logical volume first is required because XFS can only be grown, and the filesystem growth depends on the block device's new capacity. After lvextend allocates the additional storage to the LV, the mounted XFS filesystem is still the old size; running xfs_growfs on the mount point resizes it online to consume the newly available space. This is the only correct sequence for an XFS filesystem on LVM.
lvextend, then resize2fs
xfs_growfs, then lvextend
resize2fs, then lvextend
A server has a software RAID 5 array /dev/md0. One of its disks fails. The administrator wants to replace it without rebooting. Which command should be used to mark the disk as failed?
mdadm --fault /dev/md0 /dev/sdb
echo faulty > /sys/block/md0/md/dev-sdb/state
mdadm --set-faulty /dev/md0 /dev/sdb
mdadm --fail /dev/md0 /dev/sdb
This is the correct command: mdadm --manage --fail /dev/md0 /dev/sdb (the --manage action is implicit when using --fail) marks /dev/sdb as faulty in the RAID 5 array /dev/md0. Once marked, mdadm removes the device from the active array, and the array continues operating in a degraded state because RAID 5 tolerates a single disk failure. You can then remove the failed disk (mdadm --remove) and replace it (mdadm --add) to rebuild redundancy, which is the proper workflow for handling a failing disk.
Which command creates a 2GB logical volume named 'lvdata' in the volume group 'vgdata'?
lvcreate -L 2G -n lvdata vgdata
This is the correct invocation. The -L 2G option explicitly sets the logical volume's size to 2 gigabytes, -n lvdata assigns the logical volume name, and vgdata is the volume group from which the space is allocated. The syntax matches lvcreate(8): lvcreate [options] volume_group.
lvcreate -n vgdata -L 2G lvdata
lvcreate -n lvdata -s 2G vgdata
lvcreate -l 2G -n lvdata vgdata
An administrator wants to create a swap partition on /dev/sdb1. After creating the partition with fdisk, which command sets up the swap area?
mkswap /dev/sdb1
mkswap /dev/sdb1 is the correct initial step because it writes the swap signature (UUID and swap superblock) onto the partition, turning it into a usable swap area. Once this initialization is complete, the swap space can be activated with swapon. Without mkswap, the partition lacks the metadata required for the kernel to recognize it as swap.
mkfs.swap /dev/sdb1
swapon /dev/sdb1
swapoff /dev/sdb1
Want more Configure local storage practice?
Practice this domain12% of exam · 6 sample questions below
Which TWO statements about systemd journal and rsyslog are correct?
rsyslog reads log messages directly from the journal files in /var/log/journal.
The command 'journalctl --list-boots' lists only the current boot's journal entries.
The command 'journalctl -u sshd.service' outputs the same as 'tail -f /var/log/messages' for SSH logs.
The journal stores logs in a structured binary format, allowing filtering by fields like _UID or _SYSTEMD_UNIT.
The systemd journal is stored as a compact, indexed binary database, not as text. Each entry includes a rich set of structured metadata fields, such as _UID, _SYSTEMD_UNIT, _PID, and _COMM, which can be used for powerful filtering with journalctl, e.g., journalctl _UID=1000. This design enables more precise querying than plain-text log files.
The journal can forward log messages to rsyslog by setting ForwardToSyslog=yes in /etc/systemd/journald.conf.
By setting ForwardToSyslog=yes in /etc/systemd/journald.conf (in the [Journal] section), journald will forward each log entry it receives to the local syslog service, typically rsyslog. This allows traditional text-based log files like /var/log/messages to continue working alongside the journal. The forwarding is a one-way push from journald to rsyslog, not the other way around.
Refer to the exhibit. A security analyst reviews the journal output for sshd.service. Which of the following best describes the observed pattern of events?
The system is under a denial-of-service attack because the connections are being closed before authentication.
The SSH service is malfunctioning and dropping connections due to a configuration error.
Multiple hosts are attempting to connect to the SSH service simultaneously, causing connection errors.
The system experienced a brute-force attack on the root account originating from IP 192.168.1.100, which eventually succeeded.
This is the classic signature of a brute-force attack: a large number of 'Failed password for root from 192.168.1.100' entries followed by an 'Accepted password for root from 192.168.1.100' entry. The attacker systematically guessed passwords until one succeeded, giving them authenticated root access to the system. The escalation to a successful login after repeated failures confirms that the attack was not just a random scan but a targeted credential-guessing attack that ultimately breached the root account.
Match each file system type to its description.
ext4: Standard journaling file system for Linux.
ext4 is the default journaling file system on most Linux distributions, building on its predecessor ext3 by adding extents, delayed allocation, and support for volumes up to 1 EiB and files up to 16 TiB. Its journal records metadata transactions before they are committed, which dramatically reduces the risk of corruption after an unclean shutdown. Backward compatibility allows ext2 and ext3 filesystems to be mounted as ext4, making it a straightforward, widely adopted choice for general-purpose storage.
XFS: High-performance file system supporting large files and parallel I/O.
XFS is a 64-bit journaling file system originally developed by SGI, engineered for high scalability and throughput on large files and parallel I/O workloads. It uses allocation groups and b-tree indexing to maintain performance even as the filesystem grows, and supports files up to 8 EiB in size. With features like delayed allocation and preallocation, XFS excels in enterprise servers handling concurrent streaming data, making it the default root filesystem on Red Hat Enterprise Linux 7 and later.
Btrfs: Copy-on-write file system with snapshots, checksums, and compression.
Btrfs is a modern copy-on-write (CoW) file system designed around advanced features rather than pure performance. Its CoW semantics enable instant, space-efficient snapshots and subvolumes, while checksums on every block detect silent data corruption and, when combined with RAID features, can self-heal damaged data. It also offers transparent compression (LZO, zlib, or ZSTD) and online resizing, allowing the filesystem capacity to be grown or shrunk without unmounting the volume.
swap: A file system used for storing temporary files (/var/tmp).
ext4: A file system that supports subvolumes and snapshots.
Match each user/group management command to its function.
useradd: Creates a new user account
useradd is the standard low-level utility in the shadow-utils package for creating new user accounts. It adds an entry to /etc/passwd and /etc/shadow, optionally creates the user's home directory, and applies defaults from /etc/login.defs and /etc/default/useradd. However, it does not assign a password; an administrator must run passwd afterward. This is the correct tool for the lifecycle stage of account creation.
useradd: Modifies an existing user account
usermod: Modifies an existing user account
usermod is the correct utility for changing the attributes of an existing user account, such as the login name (-l), home directory (-d), default shell (-s), primary group (-g), supplementary groups (-aG), and account lock state (-L/-U). It directly modifies the relevant lines in /etc/passwd, /etc/shadow, and /etc/group. usermod should be used whenever an account already exists and its properties need to be updated without deleting or recreating it.
usermod: Deletes a user account
userdel: Deletes a user account
userdel is the correct command for removing a user account from the system. It deletes the entries from /etc/passwd, /etc/shadow, and also removes the user's group membership from /etc/group. Using the -r option additionally removes the user's home directory and mail spool. userdel is the counterpart to useradd and completes the account lifecycle.
userdel: Creates a new group
groupadd: Creates a new group
groupadd is the correct tool for creating a new group on the system. It adds an entry to /etc/group and /etc/gshadow, either with an administrator-specified GID using -g or an automatically selected GID from the range defined in /etc/login.defs. It does not add members to the group; membership is assigned later with usermod -aG or gpasswd. This is the standard way to establish a new group.
groupadd: Modifies an existing group
A critical service must restart automatically after a crash. Which systemd directive should be added to the [Service] section of the service unit file?
OnFailure=
Requires=
Restart=always
Restart=always is the correct systemd directive for automatically restarting a service after it exits, regardless of the exit status. Placed in the [Service] section, it tells systemd to unconditionally restart the process, covering crashes, normal exits, and signals. This provides a high degree of availability, though it may also restart after intentional stops; more granular control can be achieved with variants like Restart=on-failure.
Wants=
Which command checks if a specific systemd service is currently running?
systemctl is-active
systemctl is-active directly queries the systemd manager over the D-Bus interface for the unit's current runtime state and prints a single word such as 'active', 'inactive', 'activating', or 'failed'. Its exit code is also set to 0 only when the service is active, making it the ideal tool for shell conditionals and monitoring scripts because it requires no output parsing or filtering.
systemctl status
systemctl list-units
systemctl show
Want more Operate running systems practice?
Practice this domain11% of exam · 6 sample questions below
A system administrator needs to ensure that a specific kernel module 'usb_storage' is not loaded automatically during boot on a RHEL 9 system. Which configuration file should be modified to blacklist this module?
Add 'blacklist usb_storage' to /etc/modules-load.d/usb_storage.conf
Add 'install usb_storage /bin/false' to /etc/sysconfig/modules/
Add 'blacklist usb_storage' to /etc/modprobe.d/blacklist.conf
This is the standard and correct approach: /etc/modprobe.d/ contains configuration consumed by modprobe, and the 'blacklist' directive instructs it to ignore any request to load usb_storage from automatic discovery (e.g., udev or coldplug). Files in this directory follow a .conf naming convention, so blacklist.conf is a conventional choice. This prevents the module from being loaded by alias, though a user could still force it with an explicit full-name modprobe command.
Add 'blacklist usb_storage' to /etc/init.d/rc.local
A Red Hat Enterprise Linux 9 system has a logical volume 'lv_data' in the volume group 'vg_data' that needs to be resized from 10G to 15G. The underlying physical volumes have enough free space. Which sequence of commands correctly resizes the logical volume and the ext4 filesystem?
lvextend -L 15G /dev/vg_data/lv_data; resize2fs /dev/vg_data/lv_data
lvextend -L 15G /dev/vg_data/lv_data; resize2fs /dev/vg_data/lv_data — This is the correct order. lvextend first expands the logical volume by adding physical extents from the volume group, making a larger block device available to the filesystem. Only after that can resize2fs safely grow the ext4 filesystem into the newly available space; attempting filesystem growth first would have no extra capacity to claim.
resize2fs /dev/vg_data/lv_data; lvextend -L 15G /dev/vg_data/lv_data
lvextend -L 15G /dev/vg_data/lv_data; xfs_growfs /dev/vg_data/lv_data
lvreduce -L 15G /dev/vg_data/lv_data; resize2fs /dev/vg_data/lv_data
A technician needs to configure a static IPv4 address on a RHEL 9 network interface 'enp1s0' using NetworkManager. Which command should be used to set the IP address?
nmcli connection modify enp1s0 ipv4.addresses 192.168.1.100/24
`nmcli connection modify` writes the static address into the NetworkManager connection profile for `enp1s0`, satisfying the requirement to configure it through NetworkManager rather than editing ifcfg files or using `ip addr`. The `ipv4.addresses` property accepts the address with prefix length, and the change persists across reboots once the connection is reactivated.
nmtui edit enp1s0 --ipv4 192.168.1.100/24
ip addr add 192.168.1.100/24 dev enp1s0
ifconfig enp1s0 192.168.1.100 netmask 255.255.255.0
A system administrator notices that a RHEL 9 server's /var/log/messages is filling up the /var partition. The administrator wants to ensure log rotation runs daily and keeps 4 weeks of logs. Which configuration file should be modified?
/etc/systemd/journald.conf
/etc/logrotate.d/syslog
This is a logrotate drop-in configuration file located under /etc/logrotate.d. logrotate reads this file when it runs, and it lists /var/log/messages (along with /var/log/secure, cron, etc.) with directives for rotation frequency, number of retained rotated logs, and a postrotate command to signal rsyslog with HUP. Editing this file is the correct way to change how those syslog files are rotated.
/etc/rsyslog.conf
/etc/cron.daily/logrotate
A user reports that they cannot log in to a RHEL 9 system. The administrator checks /etc/passwd and finds the user's shell is set to /sbin/nologin. What is the most likely cause?
The SSH service is not running.
The user account has been locked by pam_tally2.
The user's password has expired.
The user account is intentionally disabled for login.
An intentionally disabled login account is typically configured with /sbin/nologin as the user's login shell or by locking the account in /etc/shadow with an '!' or '*' in the encrypted password field. This prevents the user from starting an interactive shell while still potentially allowing non-login services like POP3 or FTP, depending on PAM configuration. Because the problem is isolated to one user and no other users are affected, an administrative disablement is the most precise cause. The system administrator can verify this with the 'chsh -l' or by inspecting the last field of /etc/passwd.
An administrator wants to install a package 'httpd' but only if it is available in the configured repositories. Which command should be used to check if the package exists?
rpm -q httpd
dnf search httpd
dnf list available httpd
dnf list available httpd asks DNF to query the enabled repository metadata and display only packages that are not yet installed and whose name exactly matches 'httpd'. The output shows the version and repository source, proving availability. Because it targets the exact package name and filters to available packages, it is the most precise way to verify httpd can be installed.
dnf install httpd
Want more Deploy, configure, and maintain systems practice?
Practice this domainAn administrator needs to ensure that a container always runs with a specific SELinux context for security reasons. The container uses a volume mount from the host. Which command should be used to start the container?
podman run --label selinux_context=container_t -v /host/data:/data myimage
podman run --privileged -v /host/data:/data myimage
podman run --selinux-context container_t -v /host/data:/data myimage
podman run --security-opt label=type:container_t -v /host/data:/data myimage
`--security-opt label=type:container_t` directly instructs the container runtime to apply the SELinux type `container_t` to the container's processes and files, which is the proper way to set a SELinux context in Podman. This option is processed by the OCI runtime and translates into the appropriate SELinux labeling call, ensuring the container is confined by the targeted policy. It is the correct method because it leverages the intended `security-opt` mechanism for SELinux type selection.
A system administrator wants to run a container that uses the rootless mode available in Podman. Which requirement must be met for rootless containers to work correctly?
The container must be run with the '--privileged' flag.
The user must have entries in /etc/subuid and /etc/subgid for user namespace mapping.
For rootless containers, every UID and GID used inside the container must be mapped to an unprivileged range on the host, and those ranges are defined in /etc/subuid and /etc/subgid. The container engine such as Podman calls newuidmap and newgidmap to apply the subordinate ID mapping, and without at least one range assigned to the user, the kernel cannot establish the user namespace and the container fails to launch. A typical entry allocates a starting UID and a count, for example 1000:100000:65536, to give the container up to 65,536 IDs to work with.
The system must have cgroups v2 enabled.
The user must have root privileges to run the container.
A container running a database service needs to persist data across restarts. The administrator decides to use a named volume. Which command creates a named volume and mounts it correctly?
podman run -v /var/lib/mysql:/var/lib/mysql mydb
podman volume create dbdata && podman run -v dbdata:/var/lib/mysql mydb
This is the correct approach because podman volume create dbdata allocates a dedicated, managed volume in Podman's storage area, and the -v dbdata:/var/lib/mysql flag uses the non-absolute source to identify it as a named volume rather than a host path. Podman handles all lifecycle operations, permissions are configured correctly for the container's user, and the volume persists across container restarts and even after the container is removed. You can inspect it with podman volume inspect and reuse it with other containers, making it the right choice for durable database data.
podman run --mount type=bind,src=dbdata,dst=/var/lib/mysql mydb
podman run --mount type=tmpfs,dst=/var/lib/mysql mydb
Which TWO statements are true regarding container images and containers in Podman?
A container can only be created from an image that is stored locally.
A container is a running or stopped instance of an image with a writable layer.
A container is the runtime instance produced when an image is instantiated, and it always has its own thin writable layer placed on top of the read-only image layers. This layer captures all file system changes made by the container, regardless of whether the container is currently executing or has been stopped. The writable layer remains associated with the container object until the container itself is deleted, so both running and stopped containers are considered instances with that writable layer.
A container image is a read-only template used to create containers.
Container images are immutable templates consisting of one or more read-only layers that hold the application code, runtime, libraries, and configuration. Because every layer is read-only, an image can be used to spawn any number of containers without the risk of the template being altered. Any modifications made during a container's life are written to a separate, ephemeral writable layer, leaving the underlying image untouched. This read-only design underpins image caching and content-addressable storage.
When a container is stopped, its writable layer is automatically removed.
A container image must be built using a Dockerfile.
Which THREE actions are required to enable a non-root user to run containers using Podman on Red Hat Enterprise Linux 8?
Ensure the user has a running systemd user instance (loginctl enable-linger).
Rootless Podman relies on a per-user systemd instance to manage the lifecycle of container processes and services. `loginctl enable-linger` ensures that this user instance starts automatically at boot and persists after the user logs out, which is essential for containers running in the background. Without linger, containers may be terminated when the user session ends.
Configure subordinate UID and GID ranges for the user in /etc/subuid and /etc/subgid.
Rootless containers need a range of sub-UIDs and sub-GIDs to map a non-root user to root inside the container namespace. Entries in /etc/subuid and /etc/subgid allocate these ranges; `useradd` can set them via --subuid-start or they can be edited manually. If no range is defined, Podman cannot perform the necessary UID/GID mapping and rootless operation fails.
Add the user to the 'docker' group to access the Docker socket.
Enable user namespaces in the kernel if not already enabled.
User namespaces are a kernel feature that allows unprivileged users to map their UID to root inside a container, which is fundamental to rootless Podman. While most distributions compile CONFIG_USER_NS=y, some hardened kernels disable it or subsume it behind the `kernel.unprivileged_userns_clone` sysctl. If user namespaces are disabled or restricted, even with correct subuid/subgid configuration, rootless container creation will fail.
Grant the user sudo privileges to run podman commands.
A system administrator needs to run a container that remains running in the background and executes a web server. Which podman command will correctly run the container detached and map host port 8080 to container port 80?
podman run -d -p 8080:80 nginx
The -d flag detaches the container, keeping it running in the background even after your shell exits. The -p flag publishes a port mapping in the form host:container, so -p 8080:80 exposes the container's port 80 (where nginx serves HTTP) on the host's port 8080. This meets the requirement of a persistent, reachable container. Because the mapping order is correct, startup will succeed and traffic to localhost:8080 reaches nginx.
podman run -d -p 80:8080 nginx
podman run -d --expose 80 nginx
podman run -d -P 8080:80 nginx
Want more Manage containers practice?
Practice this domainA junior admin needs to ensure that the 'apache' user (UID 48) cannot log in via SSH or console. Which command achieves this?
usermod -s /sbin/nologin apache
Setting the login shell to /sbin/nologin blocks interactive SSH and console sessions for apache while leaving the account valid for service processes. This satisfies the requirement to deny login without deleting the UID 48 account.
passwd -l apache
chage -l apache
usermod -e 1 apache
An administrator runs 'getenforce' and sees 'Enforcing'. They then run 'setenforce 0' but SELinux still denies access to a custom application. What is the most likely reason?
SELinux is in enforcing mode and the policy is misconfigured.
The application's SELinux context is incorrect and needs relabeling.
The issue is due to file permissions or ACLs, not SELinux.
Because the administrator has already switched SELinux to permissive mode and the access is still refused, the remaining blocker must be from Linux's discretionary access control (DAC) layer — the classic Unix permissions (owner/group/others) or POSIX ACLs. SELinux is a mandatory access control (MAC) system layered on top of DAC, so it can only deny what DAC would otherwise permit; in permissive mode it adds no denials. Inspect ls -l, getfacl, and ownership to find the real permission or ACL problem.
The change requires a reboot to take effect.
A system administrator wants to allow user 'jdoe' to execute any command as root via sudo without being prompted for a password, but only from the host 'client1.example.com'. Which sudoers rule achieves this?
jdoe client1.example.com=(root) NOPASSWD: ALL
This is the correct rule. It confines the privilege to client1.example.com, specifies that commands run as root via (root), and uses the NOPASSWD tag so jdoe is not prompted for a password. The syntax exactly matches the sudoers grammar: user host_list = (runas) TAG: command_list, so it satisfies the requirement without unnecessary wildcards.
jdoe client1.example.com=(root) ALL
jdoe ALL=(root) NOPASSWD: ALL
jdoe ALL=(root) ALL
A server's firewall is managed by firewalld. The admin adds a rule to allow HTTPS traffic to the public zone, but clients still cannot connect. What is the most likely cause?
The rule was added with --permanent but firewall-cmd --reload was not run.
Rules added with `--permanent` are written to the on-disk configuration but not loaded into the running firewalld instance. Without `firewall-cmd --reload`, the active ruleset never includes the HTTPS allowance, so clients remain blocked despite the saved rule.
The rule must be added as a rich rule, not a simple service.
The default zone is not set to public.
firewalld is just a wrapper for iptables, so iptables rules must be cleared.
Which TWO commands can be used to display SELinux contexts of files? (Choose two.)
stat -c %C
The `stat -c %C` option is correct because the `stat` command's `%C` format specifier directly prints the SELinux security context of the specified file, such as `system_u:object_r:etc_t:s0`. This works on any filesystem object and is a precise, scriptable way to retrieve only the context string.
chcon -l
id -Z
ls -Z
The `ls -Z` option is correct because it displays the SELinux security context of each listed file in the output, alongside the file name and other metadata. It is the most common and convenient command for quickly viewing file contexts in a directory.
getenforce
You are the system administrator for a small company. A developer, Alice, needs to restart the web server (httpd.service) on server 'web1.example.com' without being prompted for a password. She should also be able to run any command as root on that server, but only from the server itself (not remotely). Currently, Alice can SSH into the server using her SSH key, but when she runs 'sudo systemctl restart httpd', she is prompted for her password. You have verified that Alice is in the 'wheel' group. The sudoers file currently has the line '%wheel ALL=(ALL) ALL'. You want to modify sudoers to satisfy the requirement with minimal privilege. Which action should you take?
Add 'alice web1.example.com=(root) NOPASSWD: ALL' to /etc/sudoers.d/alice.
Add 'alice web1.example.com=(root) NOPASSWD: /usr/bin/systemctl restart httpd' to /etc/sudoers.d/alice.
This entry precisely scopes alice's sudo privilege to the exact systemctl invocation required to restart httpd, with NOPASSWD so the service can be restarted without interactive password entry. The command path /usr/bin/systemctl is verified as a literal command; arguments are permitted as given. This meets the stated requirement of minimal access while allowing the action.
Add 'alice web1.example.com=(root) /usr/bin/systemctl restart httpd' to /etc/sudoers.d/alice.
Change '%wheel ALL=(ALL) ALL' to '%wheel ALL=(ALL) NOPASSWD: ALL' in /etc/sudoers.
Want more Manage security practice?
Practice this domain11% of exam · 6 sample questions below
A developer wrote a shell script that is intended to back up log files by copying all .log files from /var/log/myapp to /backup/logs. The script runs daily via cron but the backup folder is empty. The script contains the following line: `cp /var/log/myapp/*.log /backup/logs/`. What is the most likely reason the backup fails?
The PATH variable in cron is not set, so cp cannot be found.
The script does not have execute permission for the user running cron.
No .log files exist in /var/log/myapp at the time of script execution, causing the glob to match nothing.
In a non-interactive shell, an unmatched glob like /var/log/myapp/*.log is not expanded and is passed literally to cp. cp then attempts to copy a file named `*.log`, which does not exist, producing a 'No such file or directory' error and creating no backup. Unless the script checks the glob result or has error handling, this failure can be silent, especially if cron's stderr output is not inspected.
The cron job is not enabled because the crontab syntax is incorrect.
Which THREE of the following practices are recommended when creating simple shell scripts in a Red Hat Enterprise Linux environment to ensure reliability, security, and maintainability?
Use #!/bin/sh for compatibility, even if bash-specific features are needed.
Quote variables when used in commands, e.g., "$file" instead of $file.
Unquoted variable expansions are subject to word splitting and pathname expansion, so a filename like 'My File.txt' would be split into two arguments, and a value containing '*' could expand to multiple files. Quoting, as in "$file", preserves the variable's value as one literal argument, preventing these transformations. This is essential when handling user input, file paths, or any value with whitespace or glob characters.
Start the script with a shebang line, e.g., #!/bin/bash.
A shebang line, such as #!/bin/bash, tells the operating system kernel which interpreter to invoke when the script is executed directly, and it must be the first line of the file. Without it, execution may fail with 'permission denied' or fall back to the current shell, which may not support the script's syntax. Choosing the correct shebang ensures the script runs in a predictable environment and that bash-specific features are available.
Include set -e at the beginning of the script to exit on any error.
set -e makes the script abort immediately when any command or simple pipeline returns a non-zero exit status, so errors do not silently cascade. This is a common reliability safeguard, but it has caveats: it is ignored in conditional contexts like if or while tests, and commands whose failure is expected must be explicitly handled. Used thoughtfully, it improves deterministic behavior and simplifies debugging.
Always run scripts by invoking the interpreter directly (e.g., bash script.sh) instead of making them executable.
Which TWO of the following are true about creating simple shell scripts in Red Hat Enterprise Linux?
The shebang line (e.g., #!/bin/bash) is used to specify the interpreter.
The shebang line is a special two-byte sequence (0x23 0x21) followed by an absolute path to an interpreter, such as #!/bin/bash. When the kernel tries to execute a script directly, it reads the first line, sees the shebang, and launches the specified interpreter with the script as its argument. If the interpreter path is invalid, the script fails with a "bad interpreter" error, so the shebang is essential for scripts executed as standalone commands. However, a script can omit the shebang if it is explicitly run as the argument to an interpreter, e.g., bash script.sh.
Scripts must be stored in /usr/local/bin to be found by the shell.
The script file must have execute permission (chmod +x) to be run directly.
To run a script directly as a command, the file must have one of its execute bits set (user, group, or other). The chmod +x command adds execute permission for all users, and without that bit the kernel refuses to execute the file, returning a "Permission denied" error even if the script's shebang and syntax are correct. This is because the kernel's execve() system call checks the file's mode bits for execute permission prior to starting the interpreter. Interestingly, a script without execute permission can still be run indirectly by invoking the interpreter itself, such as bash script.sh, but that bypasses direct execution.
A script must be compiled before it can be run.
A script must have a .sh file extension to be executable.
You are a system administrator for a small company. The development team has created a shell script named 'deploy.sh' that automates deployment of a web application. The script is located at /home/devops/deploy.sh. The team reports that when they run the script with './deploy.sh' from the /home/devops directory, it fails with a 'Permission denied' error. However, running 'bash deploy.sh' works fine. Additionally, the script's first line is '#!/bin/bash' and the file permissions are '-rw-rw-r--'. The team wants to be able to run the script directly without typing 'bash'. Which of the following actions should you take to resolve the issue?
Change the shebang line to '#!/bin/sh' because bash is not the default shell.
Move the script to /usr/local/bin so it can be found in the PATH.
Add the execute permission to the script using 'chmod +x /home/devops/deploy.sh'.
The correct action is to grant execute permission explicitly. The chmod +x command adds the execute bit (x) to the file's mode for the user, group, and others, which is required for the kernel to allow execve to run the script directly. Without this bit, the shell returns 'Permission denied' even though the user can read and write the file. Since the devops user already owns the file and has read/write permissions, adding the execute bit is the minimal, sufficient fix to make the script runnable.
Change the owner of the script to root using 'chown root:root /home/devops/deploy.sh'.
Arrange the steps to configure a logical volume snapshot named 'snap_lv_data' of logical volume 'lv_data'.
Create snapshot using lvcreate -s, Mount snapshot to a directory, Perform operations on snapshot, Unmount snapshot, Remove snapshot
This is the correct order for using a logical volume snapshot. First create the snapshot, then mount it to access the data, perform operations (like backups), unmount when done, and finally remove the snapshot to free space.
Mount snapshot to a directory, Create snapshot using lvcreate -s, Perform operations on snapshot, Unmount snapshot, Remove snapshot
Create snapshot using lvcreate -s, Perform operations on snapshot, Mount snapshot to a directory, Unmount snapshot, Remove snapshot
Create snapshot using lvcreate -s, Mount snapshot to a directory, Remove snapshot, Perform operations on snapshot, Unmount snapshot
An administrator writes a script that uses the 'set -e' option at the top. What is the primary effect of this option?
It treats unset variables as an error
It prints each command before execution
It enables debug mode with verbose output
It exits the script immediately if a command fails
This is the exact purpose of `set -e`, also known as `errexit`. When enabled, the shell immediately exits if any simple command, pipeline, or compound command (outside of contexts like `if`, `while`, `until`, `!`, or `&&`/`||` left operands) returns a non-zero status. This halts the script at the first error rather than continuing with unchecked failures.
Want more Create simple shell scripts practice?
Practice this domainA system administrator needs to find all files in /var/log that have been modified in the last 2 hours. Which command should be used?
find /var/log -mmin -120
The `-mmin -120` predicate is the correct choice because it directly tests modification time in minutes. A leading minus sign means "less than," so `-120` matches any file whose data was last modified within the last 120 minutes (i.e., less than two hours ago). This precisely answers the requirement to find files in `/var/log` that have been modified in the last two hours.
find /var/log -amin -120
find /var/log -mtime -0.08
find /var/log -cmin -120
A user complains that the 'ls' command no longer outputs colors. The administrator suspects a change in environment variables. Which command would help diagnose the issue?
set
declare
env
The `env` command, when run without arguments, prints the complete environment that will be passed to child processes, making it the most direct way to verify whether `LS_COLORS` is defined and what its value is. Because `ls` relies on the `LS_COLORS` environment variable to know which color codes to use (assuming color output is enabled), `env` immediately exposes whether that variable is missing, empty, or malformed. It also allows filtering, e.g., `env | grep LS_COLORS`, for a concise check.
alias
During a security audit, an administrator needs to list all TCP ports on which the system is listening, showing only the port numbers and the associated process names. Which command best achieves this?
netstat -tulpn
nmap -sT localhost
sudo ss -tlnp
sudo ss -tlnp is the correct modern command because ss is part of iproute2 and is the standard socket inspection utility in RHEL. The flags -t limit output to TCP, -l show only listening sockets, -n display numeric ports, and -p attach the PID and process name to each entry; sudo is required because process ownership information is only visible to root for sockets belonging to other users. This command directly reads kernel socket tables via /proc and gives a clean, complete list of all TCP listeners.
lsof -i TCP:1-65535
A new Linux administrator needs to read the manual page for the 'ls' command but also wants to search for the word 'color' within the manual. Which command accomplishes this?
man -k color
man ls and then type /color
This is the correct approach because man ls opens the ls manual page in a pager (typically less), and typing the slash key (/) invokes the pager's interactive search function. Entering /color immediately jumps to the first occurrence of the string 'color' in the fully formatted page, and pressing 'n' cycles through subsequent matches. This lets you quickly locate the --color option's description right where it appears in the manual.
man ls | grep color
man color
An administrator needs to terminate a hung process with PID 3456 that does not respond to 'kill -15 3456'. Which signal should be used next?
kill -9 3456
SIGKILL (signal 9) is the only signal that the Linux kernel delivers directly, bypassing any user-space signal handler in process 3456. Because neither the process nor its threads can catch, block, or ignore SIGKILL, the kernel immediately terminates the process and reaps its resources, making it the correct last resort for a hung process that has failed to respond to SIGTERM.
kill -15 3456
kill -19 3456
kill -1 3456
A backup script uses tar to create an archive, but the administrator wants to exclude the /tmp directory from the backup. Which tar option should be added?
--exclude=/tmp
The --exclude=/tmp option is correct because it directly tells GNU tar to skip the entire /tmp directory tree when creating the archive. The argument after --exclude is a shell glob pattern (or literal path) that tar matches against absolute paths while traversing the filesystem, so /tmp (and everything beneath it) will not be included. This is the standard, dedicated mechanism for omitting a directory from a backup.
--ignore-failed-read
--exclude-from=/tmp
-X /tmp
Want more Essential Tools practice?
Practice this domainThe EX200 exam is performance-based — there are no multiple-choice questions. It is a hands-on lab exam completed within 180 minutes. You complete practical tasks in a live or simulated environment. Courseiva practice questions cover the underlying concepts.
Hands-on Linux administration tasks completed in a live RHEL environment.
The exam covers 9 domains: Create and configure file systems, Manage users and groups, Configure local storage, Operate running systems, Deploy, configure, and maintain systems, Manage containers, Manage security, Create simple shell scripts, Essential Tools. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Red Hat EX200 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.