Courseiva

CCNA Services and User Management Questions

26 questions · Services and User Management · All types, answers revealed

1
MCQmedium

A junior Linux administrator needs to run a long-running backup script as the user 'backupuser' but currently has an active SSH session as 'adminuser'. The script should continue running even if the SSH session disconnects, and no output should be sent to the terminal. Which command should the administrator use?

A.su backupuser -c '/usr/local/bin/backup.sh' &
B.screen -dmS backup sudo -u backupuser /usr/local/bin/backup.sh
C.at now + 0 minutes <<< 'sudo -u backupuser /usr/local/bin/backup.sh'
D.sudo -u backupuser nohup /usr/local/bin/backup.sh > /dev/null 2>&1 &
AnswerD

This command uses sudo -u to switch to backupuser, nohup to ignore SIGHUP, and redirects output to /dev/null. The ampersand backgrounds the process, ensuring it survives SSH disconnection. This is the correct approach for running a script as another user detached from the terminal.

Why this answer

The correct command combines sudo -u to run as backupuser, nohup to ignore hangup signals, and output redirection to /dev/null, with & to background it. This ensures the backup script continues after SSH disconnection and produces no terminal output, meeting both requirements precisely.

Exam trap

The trap here is assuming that simply backgrounding a process with & is enough to survive an SSH session ending, when in fact SIGHUP will still be sent without nohup or disown.

2
MCQhard

A Linux administrator needs to schedule a script to run every Monday at 3:00 AM. The script is located at /usr/local/bin/backup.sh. The administrator wants to use a systemd timer instead of cron. Which pair of files is required to implement this?

A.A .service unit and a .socket unit
B.A .timer unit and a .path unit
C.A .service unit and a .timer unit
D.A .timer unit and a .target unit
AnswerC

systemd timers require a .timer unit that defines the schedule and a corresponding .service unit that defines the command to run. The timer activates the service based on the OnCalendar setting. Both files are necessary to schedule and execute the script as specified.

Why this answer

To schedule a task with systemd, you need a .timer unit that specifies the schedule using OnCalendar, and a .service unit that contains the ExecStart command. The timer activates the service at the defined times. Other unit types like .socket, .path, or .target serve different purposes and cannot replace the .service unit for executing the script.

Exam trap

The trap here is confusing systemd unit types, such as using a .socket or .path unit for time-based scheduling instead of a .timer with a .service.

3
MCQeasy

A new employee needs a user account on a Linux server. The administrator runs 'useradd -m jdoe' and then 'passwd jdoe'. After setting the password, the employee reports that they cannot log in via SSH. The administrator verifies the password is correct. Which file should the administrator check to ensure the account is not locked?

A./etc/login.defs
B./etc/shadow
C./etc/group
D./etc/passwd
AnswerB

The /etc/shadow file contains the encrypted password and account aging information. A locked account is typically indicated by a '!' or '*' prefix in the password field. The administrator should inspect this file to see if the account is locked, which would prevent SSH login even with the correct password.

Why this answer

The /etc/shadow file holds the password hash and lock indicator. A locked account often has an exclamation mark or asterisk prepended to the password hash, which prevents authentication. Since the password was set correctly, the next step is to verify the account is not locked in /etc/shadow, for example by checking for a '!' prefix.

Exam trap

The trap here is assuming that a correct password guarantees login, overlooking that an account can be locked in /etc/shadow.

4
MCQmedium

A Linux administrator needs to ensure that a new service, `myapp.service`, starts automatically at boot and is also started immediately, without rebooting. The service unit file is already installed in `/etc/systemd/system/`. Which sequence of commands should the administrator run?

A.systemctl start myapp.service && systemctl enable myapp.service
B.systemctl link /etc/systemd/system/myapp.service && systemctl start myapp.service
C.systemctl daemon-reload && systemctl enable myapp.service
D.systemctl enable --now myapp.service
AnswerD

This command both enables the unit to start at boot and starts it immediately. The `--now` flag combines `enable` and `start`, which is exactly what the administrator needs without rebooting. It is the most efficient and correct way to satisfy both requirements in a single command.

Why this answer

The administrator must both enable the service for automatic startup at boot and start it immediately. The `systemctl enable --now` command accomplishes both tasks in one step, making it the correct choice. Other options either omit the immediate start, omit enabling, or use unnecessary commands like `daemon-reload` or `link` that do not address the requirements.

Exam trap

The trap here is assuming that enabling a service also starts it immediately, or that starting a service also enables it for boot.

5
MCQeasy

A user reports that they cannot log in to a Linux server via SSH. The administrator checks /etc/passwd and sees the user's shell is set to /sbin/nologin. What is the most likely reason for the login failure?

A.The SSH service is not running.
B.The user is not allowed to have an interactive shell.
C.The user's account is locked.
D.The user's password has expired.
AnswerB

/sbin/nologin is a shell that prints a message and exits immediately, denying interactive login. It is commonly set for system accounts or users who should only use services like FTP or email. The SSH login fails because the shell does not provide an interactive session.

Why this answer

The shell /sbin/nologin is designed to prevent interactive logins. When a user with this shell attempts to log in via SSH, the shell is executed and immediately exits, denying access. This is the most likely reason for the failure, as it directly matches the observed configuration.

Exam trap

The trap here is assuming that a login failure is always due to password or account lock issues, overlooking the shell setting that explicitly denies interactive access.

6
MCQmedium

A Linux administrator is configuring sudo for a team of developers. The developers need to run commands as the user 'webadmin' without being prompted for a password, but only for commands located in /usr/local/bin. Which sudoers entry correctly implements this?

A.%developers ALL=(ALL) NOPASSWD: /usr/local/bin/*
B.%developers ALL=(webadmin) PASSWD: /usr/local/bin/*
C.%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/*
D.%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/
AnswerC

This entry allows members of the developers group to run any command in /usr/local/bin as webadmin without a password. The wildcard * matches any command in that directory. It correctly restricts to that path and enforces NOPASSWD. This is the intended behavior.

Why this answer

The sudoers entry must specify the group, the target user (webadmin), the NOPASSWD tag, and the command path with a wildcard to allow all commands in /usr/local/bin. The correct syntax uses (webadmin) and NOPASSWD: followed by the path with /*. Other options either target the wrong user, use the wrong tag, or incorrectly specify a directory without a wildcard.

Exam trap

The trap here is using a trailing slash to indicate a directory in sudoers, which sudo treats as a literal command name, and confusing the target user specification with the runas user.

7
MCQmedium

A team wants a shared directory /srv/project where members of the group devteam can create and edit files, but files created by one member must remain editable by other members. The directory is on an ext4 filesystem, and the team does not want to manually change group ownership on every new file. Which command set achieves this?

A.setfacl -R -m g:devteam:rwx /srv/project && setfacl -R -d -m g:devteam:rwx /srv/project
B.chown :devteam /srv/project && chmod 1777 /srv/project
C.chgrp devteam /srv/project && chmod 2775 /srv/project
D.chmod g+s /srv/project && chmod o+t /srv/project
AnswerC

Setting the group to devteam and applying mode 2775 sets the setgid bit on the directory. On ext4, new files and subdirectories inherit the directory's group, so files created by any devteam member stay group-owned by devteam. Combined with group write permission (the 7 in the group position includes write), members can edit each other's files without manual chgrp.

Why this answer

The setgid bit on a directory causes new entries to inherit the directory's group rather than the creator's primary group. Pairing that with group ownership of devteam and mode 2775 gives the group read, write, and execute on the directory, so members can create and modify files. This is the traditional Unix approach for shared group workspaces and works on ext4 without additional ACL configuration.

Exam trap

The trap here is confusing the sticky bit with the setgid bit; the sticky bit controls deletion in shared directories, while setgid controls group inheritance for new files.

8
MCQhard

A Linux administrator is troubleshooting a systemd service that fails to start with the error 'Failed to start myservice.service: Unit myservice.service not found.' The service file exists at /etc/systemd/system/myservice.service and has correct permissions. Which command should the administrator run to resolve the issue?

A.systemctl reexec myservice.service
B.systemctl start myservice.service
C.systemctl enable myservice.service
D.systemctl daemon-reload
AnswerD

After creating or modifying a unit file, systemd must reload its configuration. The daemon-reload command rescans unit files and rebuilds the dependency tree, making the new service known to systemd. Without this, systemctl start will fail with 'Unit not found'.

Why this answer

When a new unit file is added to /etc/systemd/system/, systemd does not automatically detect it. The administrator must run 'systemctl daemon-reload' to reload the systemd manager configuration. This command scans for new or changed unit files and makes them available for starting and enabling.

Exam trap

The trap here is assuming that placing a unit file in the correct directory is sufficient, or confusing daemon-reload with daemon-reexec.

9
MCQmedium

A Linux administrator needs to grant the user 'alice' the ability to run all commands as root without being prompted for a password, but only from the host 'server1'. Which entry in /etc/sudoers accomplishes this?

A.alice server1=(root) NOPASSWD: /bin/bash
B.alice server1=(ALL) NOPASSWD: ALL
C.alice ALL=(server1) NOPASSWD: ALL
D.alice ALL=(ALL) NOPASSWD: server1
AnswerB

This sudoers entry allows alice to run any command as any user on the host server1 without a password. The host specification 'server1' restricts the rule to that host, and NOPASSWD: ALL removes the password prompt for all commands.

Why this answer

The sudoers file uses the format user host=(runas) command. To allow alice to run all commands as root without a password only on server1, the correct entry is 'alice server1=(ALL) NOPASSWD: ALL'. The host field restricts the rule to server1, and NOPASSWD: ALL removes the password requirement for all commands.

Exam trap

The trap here is mixing up the host and runas fields, or misplacing the NOPASSWD tag relative to the command list.

10
MCQmedium

A security policy mandates that user 'alice' must change her password every 60 days and must be warned 7 days before expiration. Which command should be used to enforce this?

A.passwd -x 60 -w 7 alice
B.chage -M 60 -W 7 alice
C.chage -m 60 -I 7 alice
D.usermod -e 2025-01-01 -f 7 alice
AnswerB

chage -M sets the maximum number of days before a password change is required, and -W sets the number of days of warning before expiration. This directly enforces the 60-day maximum and 7-day warning period for the user alice, satisfying the policy.

Why this answer

The chage command directly manipulates the password aging fields in /etc/shadow. Using -M 60 enforces the maximum days a password is valid, and -W 7 provides a warning to the user seven days before expiration. This is the correct and portable method to comply with the stated security policy.

Exam trap

The trap here is confusing the -m (minimum days) and -M (maximum days) options of chage, or assuming passwd supports the same aging flags on all distributions.

11
Multi-Selectmedium

A Linux administrator is configuring a new server and needs to ensure that the SSH service starts automatically at boot and that the firewall allows SSH connections. The system uses systemd and firewalld. Which two commands should the administrator run? (Choose two.)

Select 2 answers
A.systemctl start sshd
B.firewall-cmd --permanent --add-service=ssh
C.firewall-cmd --reload
D.systemctl enable sshd
E.systemctl mask sshd
AnswersB, D

firewall-cmd with --permanent and --add-service=ssh adds the SSH service to the permanent firewall configuration, allowing incoming connections on port 22. The --permanent flag ensures the rule survives a reload or reboot. After running this, a firewall-cmd --reload is needed to apply the change immediately, but the command itself is correct for enabling SSH access.

Why this answer

To ensure SSH starts at boot, the service must be enabled with systemctl enable. To allow SSH through firewalld, the SSH service must be added permanently with firewall-cmd --permanent --add-service=ssh. Together, these two commands satisfy both the startup and firewall requirements.

Starting the service without enabling it would not survive a reboot, and reloading the firewall without adding the rule would not open the port.

Exam trap

The trap here is confusing starting a service with enabling it, and forgetting that firewalld requires a permanent rule addition before reload.

12
MCQhard

A Linux administrator is troubleshooting a service that fails to start. The service unit file is located at /etc/systemd/system/myservice.service. The administrator runs 'systemctl status myservice' and sees 'Active: failed (Result: exit-code)'. Which of the following commands will provide the most detailed information about why the service failed?

A.systemctl cat myservice
B.journalctl -u myservice
C.systemctl show myservice
D.systemctl list-units --failed
AnswerB

The journalctl -u myservice command displays all log messages related to the myservice unit, including standard output and error from the service process. This is the most direct way to see why the service failed, as it shows the exact error messages and exit codes. It provides detailed context from the service's execution.

Why this answer

The journalctl -u myservice command retrieves all journal entries for the specified unit, including error messages and exit codes. This is the most detailed source of information for diagnosing why a service failed. Other commands show configuration or summary status but lack the runtime error details needed for troubleshooting.

Exam trap

The trap here is assuming that systemctl status or systemctl show provides enough detail, when in fact they only give a summary and the actual error is in the journal.

13
MCQmedium

A junior administrator runs `sudo useradd -m -s /bin/bash devops` on an Ubuntu 24.04 server, then immediately tries to SSH in as devops using a key that was copied to /home/devops/.ssh/authorized_keys. The login fails with 'Permission denied (publickey)'. The sshd_config has PubkeyAuthentication yes and PasswordAuthentication no. Which command is the most appropriate next step to resolve the login failure while preserving the intended account setup?

A.Run `sudo passwd -u devops` to unlock the account, then retry SSH.
B.Append `AllowUsers devops` to /etc/ssh/sshd_config and reload sshd.
C.Run `sudo chown -R devops:devops /home/devops/.ssh && sudo chmod 700 /home/devops/.ssh && sudo chmod 600 /home/devops/.ssh/authorized_keys`.
D.Regenerate the user's key pair with `ssh-keygen -t ed25519` and re-copy the public key.
AnswerC

OpenSSH's StrictModes (default yes) rejects authorized_keys if the .ssh directory or the file is group/world-writable, or if ownership is not the target user. Because the key was copied with sudo, the files are likely owned by root. Fixing ownership to devops:devops and tightening permissions to 700/600 directly addresses the cause and preserves the intended account.

Why this answer

When sudo is used to copy a public key into a user's home, the resulting authorized_keys and .ssh directory are typically owned by root and may be group- or world-writable. OpenSSH's StrictModes then refuses to use the key and reports 'Permission denied (publickey)'. Correcting ownership to the target user and setting directory mode 700 and file mode 600 satisfies StrictModes and restores key-based login without altering the account's shell or group membership.

Exam trap

The trap here is assuming any publickey denial means the key is wrong or the account is locked, when the usual cause after a sudo copy is wrong ownership or overly permissive modes on the .ssh path.

14
MCQmedium

A Linux administrator needs to ensure that a custom application service, implemented as a oneshot systemd unit, runs only after the network is fully online and the /data filesystem is mounted. The unit file currently has no ordering directives. Which systemd directive should be added to the [Unit] section to define these ordering dependencies?

A.Wants=network-online.target data.mount
B.Requires=network-online.target data.mount
C.Before=network-online.target data.mount
D.After=network-online.target data.mount
AnswerD

After= establishes ordering: the listed units must be activated before this service starts. It does not pull them in, but if they are already scheduled to start (e.g., via Wants= or Requires= elsewhere), the service will wait. This matches the requirement to run only after the network and filesystem are online.

Why this answer

Ordering dependencies in systemd are expressed with After= or Before=. After= ensures that the units listed are fully activated before the service starts. While Requires= or Wants= pull units into the transaction, they do not delay activation.

For a oneshot service that must wait for network-online.target and data.mount, After= is the correct directive to add to the [Unit] section.

Exam trap

The trap here is confusing requirement dependencies (Requires=, Wants=) with ordering dependencies (After=, Before=), leading to a service that starts too early despite being configured to depend on network and storage.

15
MCQmedium

A Linux administrator needs to ensure that a new service, myapp.service, starts automatically at boot and is currently running. The administrator runs 'systemctl enable --now myapp.service' and receives no errors, but after a reboot the service is not running. Which of the following is the most likely cause?

A.The systemctl daemon-reload command was not run after creating the unit file.
B.The service is masked by another unit with the same name in /etc/systemd/system.
C.The service was started with systemctl start instead of systemctl enable --now.
D.The service unit file is missing the [Install] section with WantedBy=multi-user.target.
AnswerD

Without an [Install] section specifying WantedBy, systemctl enable --now creates no symlink in the target's .wants directory. The service starts now but will not start at boot because systemd has no dependency link to multi-user.target, so the enable action is effectively a no-op for boot.

Why this answer

The [Install] section defines how a unit integrates with systemd's boot targets. WantedBy=multi-user.target is what allows enable to create the symlink that pulls the service into the boot transaction. Without it, enable --now starts the unit but does not configure it for automatic startup, so after reboot the service remains inactive.

Exam trap

The trap here is assuming that enable --now guarantees boot persistence even when the unit lacks an [Install] section, which silently makes enable ineffective for boot.

16
MCQmedium

A Linux administrator needs to allow members of the group 'developers' to run all commands as root without being prompted for a password, but only from the host 'build01'. The administrator adds the following line to /etc/sudoers: '%developers build01=(ALL) NOPASSWD: ALL'. After saving, users report that sudo still prompts for a password on build01. Which command should the administrator run to verify the syntax and placement of the rule?

A.visudo -c
B.grep developers /etc/sudoers
C.sudo -l -U developer1
D.sudo -V
AnswerA

Running visudo -c checks the sudoers file for syntax errors and reports the parsed result, confirming whether the rule is syntactically valid. It does not enforce placement, but it will reveal if the line was inserted in a way that breaks parsing or if an earlier conflicting rule exists. This is the standard validation step before troubleshooting further.

Why this answer

The correct command is visudo -c, which parses the sudoers file and reports syntax errors. Because the rule was added manually, a syntax mistake or misplacement could cause sudo to ignore it or fail. Validating with visudo -c ensures the file is well-formed before investigating effective privileges with sudo -l.

Exam trap

The trap here is assuming that listing a user's sudo privileges validates the sudoers file syntax, when only visudo -c performs that check.

17
MCQeasy

A user reports that they cannot run the command `sudo` to perform administrative tasks. The administrator checks and finds that the user is not listed in the `/etc/sudoers` file. Which command should the administrator use to safely edit the sudoers file and add the user?

A.echo 'username ALL=(ALL) ALL' >> /etc/sudoers
B.visudo
C.usermod -aG sudo username
D.nano /etc/sudoers
AnswerB

`visudo` is the recommended tool for editing the `/etc/sudoers` file because it locks the file to prevent concurrent edits and performs syntax checking before saving. This reduces the risk of introducing errors that could lock out sudo access. It is the safe and standard method for modifying sudoers.

Why this answer

Using `visudo` is the correct approach because it provides a safe editing environment with syntax validation and file locking. Directly editing the sudoers file or appending to it can introduce errors that break sudo. Adding a user to a group like sudo is an alternative but does not address the specific need to edit the sudoers file safely.

Exam trap

The trap here is assuming that any method of editing the sudoers file is acceptable, overlooking the critical safety features of visudo.

18
MCQmedium

A Linux administrator needs to schedule a backup script to run every day at 2:30 AM. The script is located at `/usr/local/bin/backup.sh` and must run as the user `backupuser`. Which entry in the crontab for `backupuser` will accomplish this?

A.30 2 * * 1 /usr/local/bin/backup.sh
B.30 2 1 * * /usr/local/bin/backup.sh
C.2 30 * * * /usr/local/bin/backup.sh
D.30 2 * * * /usr/local/bin/backup.sh
AnswerD

This cron entry specifies minute 30, hour 2, every day of month, every month, and every day of week, which translates to 2:30 AM daily. The command is the full path to the script. This is the correct syntax for scheduling a daily job at that time.

Why this answer

The correct cron syntax for 2:30 AM daily is `30 2 * * *`. The minute field is 30, hour is 2, and the remaining fields are wildcards to indicate every day. The other options either have invalid time values or restrict execution to specific days, failing the daily requirement.

Exam trap

The trap here is mixing up the order of minute and hour fields, or misplacing wildcards to unintentionally limit the schedule.

19
MCQhard

A Linux administrator is troubleshooting a service that fails to start. The service unit file contains 'User=appuser' and 'Group=appgroup'. The administrator runs 'systemctl start app.service' and sees the error 'Failed to determine user credentials: No such process'. Which of the following is the most likely cause?

A.The user appuser does not exist on the system.
B.The service unit file has a syntax error in the [Service] section.
C.The service binary does not have the execute permission for appuser.
D.The appgroup group exists but appuser is not a member of it.
AnswerA

The error 'Failed to determine user credentials: No such process' occurs when systemd cannot resolve the User= or Group= specified in the unit. If appuser is absent from /etc/passwd and the NSS databases, systemd cannot switch to that UID, so the service fails to start. Creating the user or correcting the unit resolves it.

Why this answer

systemd resolves User= and Group= before launching the process. If the specified account cannot be found in the user database, systemd aborts with a credential resolution error. The fix is to create the missing user or correct the unit file to reference an existing account, then reload systemd and restart the service.

Exam trap

The trap here is focusing on file permissions or group membership when the error text explicitly indicates that systemd cannot resolve the user account itself.

20
MCQmedium

A Linux administrator needs to configure sudo so that members of the group 'webadmins' can run any command as any user without being prompted for a password, but only on the host 'web01'. Which entry should be added to the sudoers file?

A.%webadmins ALL=(ALL) NOPASSWD: ALL
B.%webadmins web01=(ALL) NOPASSWD: ALL
C.webadmins web01=(ALL) NOPASSWD: ALL
D.%webadmins web01=(root) NOPASSWD: /usr/bin/apt
AnswerB

This entry grants the group webadmins (denoted by %) passwordless sudo access to run any command as any user on the host web01. The syntax is correct: user/group, host, runas, and command with NOPASSWD tag. It precisely matches the requirement.

Why this answer

The sudoers syntax allows specifying a group with %, a host, a runas list, and commands. The entry %webadmins web01=(ALL) NOPASSWD: ALL correctly allows group members to run any command as any user on web01 without a password prompt. This is the precise configuration needed.

Exam trap

The trap here is forgetting the % prefix for groups in sudoers or misplacing the host field, which could grant broader access than intended.

21
MCQmedium

A Linux administrator needs a service to be started automatically at boot and then started immediately without rebooting. The service unit file is located at /etc/systemd/system/myapp.service. Which command should the administrator run to accomplish both tasks?

A.systemctl start myapp.service && systemctl daemon-reload
B.systemctl link /etc/systemd/system/myapp.service
C.systemctl enable myapp.service && systemctl restart myapp.service
D.systemctl enable --now myapp.service
AnswerD

This command both enables the unit to start at boot by creating the appropriate symlinks and starts it immediately. The --now flag is the standard systemd way to combine enable and start in one step. It satisfies the requirement to start automatically at boot and to start the service right away without rebooting.

Why this answer

The correct command is systemctl enable --now myapp.service. The enable subcommand sets up the unit to start at boot, and --now starts it immediately. This single command satisfies both requirements without requiring a reboot or separate commands.

Other options either omit enabling, omit starting, or use commands that do not achieve both goals.

Exam trap

The trap here is assuming that starting a service also enables it for boot, or that daemon-reload is needed after enabling a unit.

22
Multi-Selecthard

A Linux administrator is troubleshooting a systemd service that fails to start. The service unit file is located at /etc/systemd/system/myapp.service. Which two commands should the administrator use to reload the systemd manager configuration and then restart the service? (Choose two.)

Select 2 answers
A.systemctl reload myapp.service
B.systemctl daemon-reload
C.systemctl enable myapp.service
D.systemctl reexec myapp.service
E.systemctl restart myapp.service
AnswersB, E

systemctl daemon-reload reloads the systemd manager configuration, including unit files. After modifying a unit file, this command is necessary for systemd to recognize changes. It does not restart services but ensures the new configuration is loaded before attempting to restart the service.

Why this answer

After editing a unit file, the administrator must run systemctl daemon-reload to make systemd aware of the changes. Then, systemctl restart myapp.service stops and starts the service with the new configuration. The other commands either do not reload the manager configuration, are invalid, or serve a different purpose such as enabling at boot.

Exam trap

The trap here is confusing systemctl daemon-reload with systemctl reload, and assuming that enabling a service or reexecuting the manager will apply unit file changes.

23
MCQhard

A Linux administrator is troubleshooting a service that fails to start at boot. The service unit file is present in `/etc/systemd/system/` and has been enabled. Running `systemctl status myservice` shows it as `inactive (dead)`. Which command should the administrator run to see the most recent boot messages for this service?

A.systemctl cat myservice
B.grep myservice /var/log/boot.log
C.journalctl -u myservice -b
D.systemctl show myservice
AnswerC

`journalctl -u myservice -b` filters the journal for messages from the specified unit and limits output to the current boot. This shows all log entries for the service since the last boot, which is exactly what the administrator needs to diagnose why the service failed to start at boot.

Why this answer

To see boot-time messages for a specific systemd service, the correct tool is `journalctl` with the `-u` (unit) and `-b` (current boot) options. This filters the journal to show only entries from that unit during the current boot. Other commands either show unit file contents, unit properties, or rely on a non-authoritative log file, and none provide the targeted boot logs needed.

Exam trap

The trap here is assuming that `systemctl status` or `systemctl show` includes historical boot logs, when they only show current state and properties.

24
Multi-Selecthard

A Linux administrator needs to grant temporary, time-limited administrative access to a contractor on a production server. The contractor must be able to run only `/usr/bin/systemctl restart nginx` as root without a password, and all actions must be logged. The administrator plans to use sudo. Which two steps are required to meet these requirements? (Choose two.)

Select 2 answers
A.Create a file in /etc/sudoers.d/ with a rule like `contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx` and validate it with visudo -c.
B.Add the contractor to the wheel group and rely on the default `%wheel ALL=(ALL) ALL` rule.
C.Enable sudo I/O logging by adding `Defaults log_output` and ensure the sudo log file or syslog destination is writable.
D.Set the contractor account's shell to /sbin/nologin to limit interactive access.
E.Add `contractor ALL=(ALL) NOPASSWD: ALL` to /etc/sudoers to simplify future administration.
AnswersA, C

A drop-in file under /etc/sudoers.d provides the specific command authorization, and NOPASSWD satisfies the no-password requirement. Restricting the command to the exact systemctl restart nginx invocation follows least privilege. Running visudo -c validates syntax and prevents a malformed sudoers file from locking out sudo, which is essential when editing production access controls.

Why this answer

Satisfying the requirement needs both a narrowly scoped sudo rule and audit logging. A drop-in file in /etc/sudoers.d with a command-specific NOPASSWD rule authorizes exactly the restart operation, while validating with visudo -c protects sudo integrity. Enabling log_output and ensuring the log destination is writable provides the session logging demanded for all actions.

Together these implement least privilege and accountability without granting broad root access.

Exam trap

The trap here is equating 'administrative access' with full sudo via wheel or NOPASSWD: ALL, when the scenario explicitly limits the allowed command to one systemctl invocation.

25
MCQhard

A Linux administrator needs to configure a service to run as a specific user and group, and to restart automatically on failure. The service is managed by systemd. Which directive in the unit file should the administrator use to specify the user and group, and which directive to ensure automatic restart?

A.User= and Group= in the [Service] section; Restart=on-abort
B.ExecStart= with su or sudo; Restart=on-abnormal
C.User= and Group= in the [Unit] section; Restart=always
D.User= and Group= in the [Service] section; Restart=on-failure
AnswerD

The User and Group directives in the [Service] section specify the user and group under which the service runs. Restart=on-failure ensures systemd restarts the service if it exits with a non-zero status or is terminated abnormally. This combination meets both requirements.

Why this answer

The correct directives are User= and Group= in the [Service] section, and Restart=on-failure. These set the execution context and restart policy. User and Group must be in [Service] because they affect how the service process runs.

Restart=on-failure restarts the service when it exits with a non-zero code or is killed by a signal, covering typical failure conditions.

Exam trap

The trap here is placing User and Group in the [Unit] section and using Restart=always instead of on-failure, or confusing the various restart conditions.

26
MCQmedium

A Linux administrator needs to configure a system so that the service `httpd` starts automatically when the system boots into the default target. Which command should the administrator use?

A.systemctl daemon-reload
B.systemctl enable httpd
C.systemctl start httpd
D.chkconfig httpd on
AnswerB

The `systemctl enable httpd` command creates the necessary symbolic links in the systemd configuration directories to ensure the httpd service is started automatically when the system reaches the default target during boot. This is the standard method for enabling a service to start at boot on modern Linux distributions using systemd.

Why this answer

Enabling a service with `systemctl enable httpd` sets up the proper symlinks so that systemd starts the service when the default target is reached during boot. Starting the service only affects the current runtime, while enabling ensures persistence across reboots. Other commands like `chkconfig` are for older init systems and `daemon-reload` only refreshes unit definitions.

Exam trap

The trap here is confusing the immediate action of starting a service with the persistent action of enabling it at boot.

Ready to test yourself?

Try a timed practice session using only Services and User Management questions.