LFCS Networking Practice Question
A junior administrator needs to verify that the host can resolve the name db.internal.example.com to an IPv4 address before deploying a database client. The system uses systemd-resolved. Which command queries the configured resolver and displays the answer without relying on the local nsswitch.conf ordering?
⚠ Common exam trap
The trap here is assuming that any lookup tool tests the configured resolver, when tools like getent and host actually follow nsswitch.conf and may return /etc/hosts entries instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
resolvectl query db.internal.example.com
resolvectl query is the native client for systemd-resolved. It sends the query through the resolver daemon, showing the answer, the link used, and the DNS server that responded. This isolates DNS resolution from nsswitch.conf sources like /etc/hosts, which is exactly what is needed to confirm the configured resolver can resolve the name.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
dig db.internal.example.com
Why it's wrong here
dig queries the nameserver listed in /etc/resolv.conf directly, which on systemd-resolved systems is usually 127.0.0.53. It does test DNS, but it bypasses systemd-resolved's per-link routing and caching logic, so it may not reflect what the system resolver actually returns. The requirement is to query the configured resolver, which resolvectl does more accurately.
- ✗
host db.internal.example.com
Why it's wrong here
host uses the system resolver through the standard library, so it depends on nsswitch.conf and may consult /etc/hosts first. It does not specifically target systemd-resolved, and its output is less detailed regarding which DNS server answered. For verifying the configured resolver on a systemd-resolved host, resolvectl is the appropriate tool.
- ✗
getent hosts db.internal.example.com
Why it's wrong here
getent honors nsswitch.conf and may return results from /etc/hosts, LDAP, or other sources before DNS, so it does not specifically test the configured DNS resolver. It is useful for verifying what applications will see, but it does not isolate DNS resolution as required. The administrator wants to confirm the resolver itself answers correctly.
- ✓
resolvectl query db.internal.example.com
Why this is correct
resolvectl query sends the name to systemd-resolved and reports the answer along with which link and DNS server provided it. This directly exercises the resolver configured on the system, bypassing nsswitch.conf ordering, and is the correct tool on systemd-resolved hosts. It also shows whether the answer came from cache, DNS, or another source, which is valuable for troubleshooting.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.