Courseiva
LPIC-1Chapter 7 of 17Objective 104.1

Linux Filesystem Hierarchy and Storage Management

How do you organise a sprawling pile of files, install an operating system, or add a new hard drive to a server without losing data or breaking the entire computer? This is the core problem that Linux Filesystem Hierarchy and Storage Management solves, and it is a fundamental skill tested on the LPIC-1 exam. Knowing where things go (the hierarchy) and how to manage physical and logical storage is what separates someone who can blindly follow commands from a professional who understands system architecture.

12 min read
Intermediate
Updated Jul 23, 2026
Editorial oversight: Johnson Ajibi· Senior Network & Security Engineer · MSc IT Security · IEEE Senior Member

A simple way to picture Linux Filesystem Hierarchy and Storage Management

The Filing Cabinet Office Analogy

Your computer's hard drive is the entire office building.

Inside that building, you have filing cabinets. A filing cabinet is a storage device, like a hard drive partition. You might have one cabinet for client files, another for financial records, and a third for employee information. Each cabinet is a separate, organised storage space.

Each filing cabinet has drawers. A drawer represents a filesystem, like ext4 or NTFS. It's the system that organises how files are stored inside the cabinet. You can't just throw papers into a drawer; you need folders and dividers. The filesystem is those folders and dividers.

The top drawer of the file cabinet is like the root filesystem ( / ). You must have a top drawer to start organising. Other drawers might be for specific things. A drawer labelled 'documents' that you pull out completely and use to store only office supplies is a separate filesystem mounted at a mount point. For Linux, a mount point is like the empty space on your desk where you place the drawer you've just taken out. The physical drawer is the storage, but you access its contents only after you've mounted it onto your desk at that specific spot.

The Filesystem Hierarchy Standard (FHS) is the office layout plan. It says: client files always go in the left filing cabinet, financial records in the middle one, and employee information in the right one. Every Linux system follows this plan, so no matter which office (Linux distribution) you walk into, you know exactly where to look for the 'passwords' file (in /etc) or the 'programs' folder (in /usr/bin). Without the FHS, every office would have a chaotic, unique layout.

How It Actually Works

A computer's storage is a chaotic mess of ones and zeros. To make sense of it, we need an organisational system. In the Linux world, this system has two parts: the filesystem hierarchy (the logical map of where files live) and storage management (the physical or virtual devices that hold the data).

Let us start with the hierarchy. Imagine a tree. The trunk is the root directory, represented by a single slash ( / ). From that trunk, all other directories branch out. The Filesystem Hierarchy Standard (FHS) is the agreed-upon blueprint for what those branches are. It defines a standard set of directories and what they are supposed to contain. This is not a suggestion; it is a convention that all Linux distributions follow to maintain compatibility.

Some essential top-level directories include:

/bin - Essential user command binaries (programs like 'ls', 'cp', 'mv'). Historically, this was a separate directory from /usr/bin, but modern systems often have a symlink.

/sbin - System administration binaries (programs like 'fdisk' for partitioning, 'mount', 'init'). These are for system maintenance, not everyday user tasks.

/etc - Configuration files. This is where the system and its applications store settings that control how they behave. For example, /etc/passwd stores user account information.

/dev - Device files. In Linux, every hardware device (hard drives, USB ports, terminals) is represented as a file in this directory. You interact with /dev/sda to write data to your first SATA hard drive.

/proc - A virtual filesystem. It does not contain real files on disk; it contains information about running processes and the kernel, provided by the kernel on the fly.

/var - Variable data. Files that change in size and content, such as log files (/var/log), print spools, and databases.

/tmp - Temporary files. Any user or program can write here, but the contents are usually deleted on every system reboot.

/usr - User system resources. This is the major directory for shared, read-only data. It holds most user applications (in /usr/bin), libraries (/usr/lib), documentation (/usr/share/doc), and source code (/usr/src).

/home - User home directories. Each normal user gets a folder here (e.g., /home/alice). This is where personal files, configuration, and data live.

/root - The home directory for the root (administrator) user. It is separate from /home for security reasons.

/run - A tmpfs (temporary filesystem stored in RAM) that holds volatile runtime data about the system since boot, like process ID files.

/opt - Optional add-on application software. Typically used for third-party, commercial, or self-contained software packages that are not part of the distribution's package manager.

/mnt - A temporary mount point. Designed as a place to manually mount filesystems (like a USB stick) for a short time.

/media - A mount point for removable media. Modern systems often auto-mount USB drives and CDs here, creating subdirectories with the volume name.

Now, how does this hierarchy connect to physical storage? The root filesystem ( / ) must exist on some device. That device is a partition—a logically separated section of a hard drive. A hard drive (like /dev/sda) can be divided into multiple partitions (e.g., /dev/sda1, /dev/sda2).

Each partition can then be formatted with a filesystem. A filesystem is the method the operating system uses to organise and find data on the partition. Common Linux filesystems include:

ext4 - The default, mature journaling filesystem. It keeps a log (journal) of changes before they are written, preventing corruption on crashes.

XFS - A high-performance 64-bit journaling filesystem, excellent for large files and parallel I/O.

Btrfs - A modern copy-on-write filesystem with advanced features like snapshots and subvolumes.

You cannot simply use a partition; you must first format it with a filesystem (e.g., mkfs.ext4 /dev/sdb1). Once formatted, you then mount the filesystem at a mount point—an existing empty directory within the tree. For example, you might mount your second hard drive (partition /dev/sdb1, formatted as ext4) at the mount point /data. After that, any file you put in /data is physically stored on /dev/sdb1.

The Linux kernel uses the Virtual File System (VFS) to abstract this. VFS provides a single interface for the kernel to interact with any filesystem, allowing standard commands like read() and write() to work regardless of the underlying physical format.

Why does this matter? If you run out of space in /home, you can add a new hard drive, create a partition, format it with a filesystem, and mount it at /home. The system and users continue working as if nothing changed. This is storage management—controlling where your data lives and how it is organised. The fdisk command creates partitions, mkfs creates filesystems, mount attaches them, and df shows you free space.

This diagram shows the relationship from a physical hard drive, through partitions and filesystems, to mount points within the Linux filesystem hierarchy.

Walk-Through

1

Identify the Disk Device

Use the command `lsblk` to list all block devices (disks) in your system. For example, you might see /dev/sda (the first SATA disk). This step tells you which physical hard drive you will be working on. LPIC-1 tests that you can identify the correct disk to partition.

2

Partition the Disk

Run `fdisk /dev/sda` (or `gdisk` for GPT). Inside fdisk, you create new partitions using the `n` command, choose primary or logical, and specify sizes. You write the partition table to disk with `w`. This divides the disk into logical units like /dev/sda1 and /dev/sda2.

3

Create the Filesystem

Use `mkfs.ext4 /dev/sda1` to create an ext4 filesystem on the new partition. This step writes the organisational structures (inodes, journal, superblock) onto the partition so it can hold files. For swap, use `mkswap /dev/sda2`. Without this step, the partition is just a block of raw sectors.

4

Mount the Filesystem

Create a mount point directory with `mkdir /data`. Then mount the filesystem using `mount /dev/sda1 /data`. This attaches the formatted partition to the directory tree. After this, any file saved to /data is physically stored on /dev/sda1.

5

Make the Mount Persistent via /etc/fstab

Edit /etc/fstab as root and add an entry like: `UUID=... /data ext4 defaults 0 2`. Obtain the UUID with `blkid /dev/sda1`. This ensures the mount happens automatically on every boot. If you miss this step, the mount is lost after reboot.

6

Verify and Monitor

Use `df -h` to verify the new mount is present and see available space. Use `mount` without arguments to view all active mounts. Use `lsblk -f` to verify UUIDs and filesystem types. Regular monitoring with `du` and `df` helps you catch low-space issues early.

What This Looks Like on the Job

An IT professional at a small company, say Widgets Inc., needs to set up a new file server. The server has one 500GB hard drive ( /dev/sda ). The immediate requirement: store company documents.

First, they partition the drive. They use fdisk /dev/sda to create a single large partition ( /dev/sda1 ) and a swap partition ( /dev/sda2 ) for virtual memory. The swap partition is a special type that does not have a normal filesystem but acts as an overflow for RAM.

Second, they create filesystems: mkfs.ext4 /dev/sda1 for the data partition and mkswap /dev/sda2 for swap. They activate swap with swapon /dev/sda2.

Third, they need to integrate the new filesystem into the existing hierarchy. The root (/) partition is already on /dev/sda1. They want the company's documents to be accessible at /company_docs. They create the mount point: mkdir /company_docs. Then they mount the partition: mount /dev/sda1 /company_docs. Now, any file saved to /company_docs is physically on that partition.

To make this permanent (surviving a reboot), they must edit a critical file: /etc/fstab. This file is the filesystem table; it tells the system which partitions to mount where and with what options at boot. A typical line in /etc/fstab looks like:

/dev/sda1 /company_docs ext4 defaults 0 2

This line specifies the device, mount point, filesystem type, mount options ('defaults' means standard options), a dump flag (0 for no backup), and the filesystem check order (2 means check after root).

Months later, the company grows. They run out of space. They install a 2TB hard drive ( /dev/sdb ). The professional's task is to make the /company_docs directory effectively include the new space. They could:

Mount the new drive on a subdirectory ( /company_docs/archive ).

Use a Logical Volume Manager (LVM) . LVM abstracts the physical drives into a pool of storage called a volume group. You can then create logical volumes from this pool. With LVM, they could add the new disk to the volume group and grow the logical volume that is mounted at /company_docs, all without taking the server offline or moving files.

The professional also monitors disk usage with df -h (disk free in human-readable format). If /tmp is filling up, they might mount a RAM-based tmpfs there to speed things up and clear on reboot. They use du -sh /var/* to find which log file is eating space in /var.

This entire process—partitioning, formatting, mounting, unmounting, and managing space—is the daily reality of storage management. It is not theory; it is fixing a full disk, adding a new drive to a database server, or ensuring that a log rotation (logrotate) does not fill the root filesystem.

How LPIC-1 Actually Tests This

The LPIC-1 exam objective 104.1 is strictly about creating partitions, filesystems, and managing mount points, including the FHS standard. Expect multiple-choice questions that test your understanding of commands, concepts, and the standard.

Key concepts they love to test:

The FHS directory purpose: You must know which directory holds which type of file. They will ask: 'Where are configuration files stored?' The answer is /etc. 'Where are user binaries?' /usr/bin or /bin. 'Where is variable data?' /var. They test the distinction between /usr/bin and /bin (essential vs. non-essential binaries), and between /usr and /usr/local (system vs. locally compiled software).

Partitioning commands: fdisk is for MBR (Master Boot Record) partition tables, gdisk for GPT (GUID Partition Table), and parted for either. They will test the command you use to create a partition ( fdisk /dev/sdb ) and the command to write changes ( w in fdisk). You need to know the difference between primary, extended, and logical partitions. The MBR allows only 4 primary partitions. To get more, you use an extended partition containing logical partitions.

Filesystem creation: The command mkfs is the wrapper, but mkfs.ext4 creates an ext4 filesystem. You must know mkswap is for swap, not mkfs. A trap question: 'What command creates a Linux swap filesystem?' The answer is mkswap, not mkfs.swap.

Mounting and unmounting: mount attaches a device to a mount point. umount (not 'unmount') detaches it. They will test the mount command syntax: mount -t ext4 /dev/sdb1 /mnt. They love to ask about the -a option to mount all filesystems in /etc/fstab. Another trap: 'What happens if you mount a new filesystem on a non-empty directory?' The old files become inaccessible.

/etc/fstab: They will give you a line from fstab and ask what each field means. For example: /dev/sda1 / ext4 errors=remount-ro 0 1. The 1 means it gets checked first during boot (fsck order). The 0 means it is not dumped. The defaults option set includes rw (read-write), suid (allow setuid bits), dev (interpret block devices), exec (allow executables), auto (mount at boot), nouser (only root can mount), and async (asynchronous I/O).

Filesystem checking: fsck (filesystem check) is used to repair a filesystem. They will test that the filesystem must be unmounted before running fsck. A trap: you cannot run fsck on a mounted filesystem (except root in special circumstances).

Disk usage commands: df reports disk space usage for mounted filesystems. du estimates file and directory space usage. lsblk lists block devices (disks and partitions). blkid shows the UUID (Universally Unique Identifier) of a partition, which is used in /etc/fstab to mount by UUID instead of device name (which can change).

Swap management: swapon and swapoff enable and disable swap partitions. free shows total memory including swap. They test that you can create a swap file (using dd, mkswap, and swapon) as an alternative to a swap partition.

The root filesystem: The root (/) must always be present. It must contain the directories /bin, /dev, /etc, /lib, /proc, /sbin, /tmp, /usr, and /var. Having a separate partition for /home is common. If /home fills up, the rest of the system is not affected.

Trap patterns:

They give a command with a wrong option or flag. For example, mount -t ntfs instead of ntfs-3g for reading NTFS from Linux.

They test the difference between losing data on a device vs. on a volume. If you have a partition mounted on /data and you unmount it, the data is still on the disk, just inaccessible until you remount.

They ask about permissions and mount options. Mounting with noexec prevents running binaries from that partition. That is a common security hardening technique.

Key Takeaways

The Filesystem Hierarchy Standard (FHS) dictates the purpose of every major directory, ensuring consistency across all Linux distributions for compatibility and ease of administration.

The root directory (/) is the top of the tree; everything else is a branch, and a separate filesystem can be mounted at any empty directory to expand storage without reorganising files.

Partitioning a disk (with fdisk, gdisk, or parted) creates logical sections, but does not make them usable for data until you create a filesystem (format) with mkfs.

The /etc/fstab file controls persistent mounts; one mistake in this file can prevent the system from booting, so always test changes before rebooting a production server.

Every partition has a UUID that you can find with blkid or lsblk -f; use the UUID in /etc/fstab instead of device names to avoid boot failures when disk order changes.

Running fsck on a mounted filesystem is dangerous and can corrupt your data; always unmount the filesystem before checking or repairing it with fsck.

Swap space can be a dedicated partition (created with mkswap) or a file; both are activated with swapon and monitored with swapon -s or free.

The du command measures space used by files and directories, while df measures free space on an entire mounted filesystem; use du -sh * to find the biggest consumers in /var/log when space runs low.

Easy to Mix Up

These come up on the exam all the time. Here's how to tell them apart.

Primary Partition

Can be up to 4 per MBR disk

Can hold an operating system for booting

Has a dedicated entry in the MBR partition table

Logical Partition

Must reside inside an extended partition

Cannot boot an operating system directly

No limit on number beyond the extended partition's capacity

/etc/fstab

Persistent: applied automatically on boot

System file read by init process

Each line defines one permanent mount

mount command

Temporary: lost after reboot

Command executed by user

Used for one-time or emergency mounts

ext4

Default for many Linux distributions

Older, very mature codebase

Single filesystem limited to 1 exabyte

XFS

Default for RHEL distributions

Excellent for large files and high-concurrency

Single filesystem can be up to 8 exabytes

/usr/bin

Contains packaged binaries from the distribution

Managed by package manager (apt, yum)

Should not be manually modified

/usr/local/bin

Contains locally compiled or custom scripts

Not managed by package manager

Safe place for user-installed programs

UUID

Universally unique, never changes

Generated when creating the filesystem

Preferred in /etc/fstab for reliability

Device Name (/dev/sda1)

Assigned dynamically by kernel on detection

Can change if hardware order changes

Simple to read and type, but fragile

Watch Out for These

Mistake

The root directory (/) and the /root directory are the same thing.

Correct

The root directory (/) is the top of the entire filesystem tree. The /root directory is the home directory for the root user (administrator). They are separate and distinct locations.

The naming similarity confuses beginners. Both contain the word 'root', but one is the system's starting point, the other is a user's personal folder.

Mistake

When you delete a file, it is permanently gone from the hard drive.

Correct

Deleting a file typically only removes the pointer to the data in the filesystem's index (inode). The actual data remains on the disk until overwritten by new data. This is why file recovery tools sometimes work.

People are familiar with the 'Recycle Bin' in Windows, which gives a second chance. Linux command-line deletes immediately, making it seem more permanent, but the raw data persists.

Mistake

A hard drive's partition is the same thing as a filesystem.

Correct

A partition is a logically separated section of a hard drive. A filesystem is the data structure (like ext4) that is written onto that partition to organise files. You must create a filesystem on a partition before you can store files there.

The two steps (partitioning and formatting) are often done together in modern tools or graphical installers, so beginners never see them as separate actions. They assume a partition automatically is ready to hold files.

Mistake

The /etc/fstab file cannot be edited manually; it is only modified by administration tools.

Correct

/etc/fstab is a plain text file that can be edited with any text editor (like vim or nano) as the root user. Many professionals edit it manually to add or change mount points.

Some operating systems hide configuration changes behind graphical tools, creating a belief that system files are 'protected' from direct editing. Linux gives you full control, expecting you to know what you are doing.

Mistake

You can run `fsck` on a filesystem that is currently mounted and in use.

Correct

Running `fsck` on a mounted filesystem can cause severe data corruption or system instability. You must unmount the filesystem first, or use a live CD/USB if you are checking the root filesystem.

Users see `fsck` as a repair tool, and think of it like a simple hard drive diagnostic that can run while the system is on. But fsck assumes low-level control, conflicting with the kernel's active use of the storage.

Mistake

The device name (like /dev/sdb1) is permanent and will always refer to the same physical disk.

Correct

Device names are assigned dynamically by the kernel based on detection order. Adding or removing drives can change names (e.g., a USB boot could make your internal drive become /dev/sdc). You should use UUIDs or labels in /etc/fstab for stable identification.

Beginners rely on letters and numbers that look logical (sda, sdb). They do not realise the kernel's probing order can change, making names unreliable across reboots or hardware changes.

Do You Actually Know This?

Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.

Frequently Asked Questions

What is the difference between /bin and /usr/bin?

Historically, /bin contained essential binaries needed to boot and repair the system when /usr was not mounted. Today, on many distributions, /bin is a symbolic link to /usr/bin. The LPIC-1 still tests the historical distinction: /bin is for essential commands, /usr/bin is for non-essential user commands.

Can I use a file as swap instead of a partition?

Yes. Create a file of the desired size (e.g., `dd if=/dev/zero of=/swapfile bs=1M count=2048`), then `mkswap /swapfile` and `swapon /swapfile`. Add an entry to /etc/fstab to make it persistent.

What happens if /etc/fstab has an error?

The system may fail to boot, often dropping you into an emergency shell (rescue mode). You can then edit the file to fix the error and reboot. This is why you should always back up fstab before editing.

How do I find out which partition is using the most space?

Use `df -h` to see space per mount point, or `du -sh /*` to see total usage of each top-level directory. Then drill down into the largest directory (e.g., `du -sh /var/*`). This helps you locate the culprit.

What is the difference between primary, extended, and logical partitions?

MBR (the old partition scheme) allows only 4 primary partitions. To have more, you create an extended partition, which acts as a container for multiple logical partitions inside it. GPT does not use this scheme; it allows up to 128 partitions directly.

Is /home always on a separate partition?

No, it is optional but recommended. A separate /home partition protects user data in case you need to reinstall the operating system. The root (/) partition can be reformatted and reinstalled without disturbing the /home partition.

What does 'mount -a' do?

It mounts all filesystems listed in /etc/fstab that have the 'auto' option, except those already mounted. It is commonly used after editing fstab to apply changes without rebooting.

Terms Worth Knowing

Keep going

You've finished Linux Filesystem Hierarchy and Storage Management. Continue through the LPIC-1 study guide to build a complete picture of the exam.

Done with this chapter?