LFCS Operation of Running Systems Practice Question
A Linux server has a filesystem mounted at /data that is running out of space. The administrator needs to identify which directories under /data are consuming the most disk space and then safely remove old log files. Which two commands should the administrator use? (Choose two.)
⚠ Common exam trap
The trap here is using df to try to find which directories are large, when df only reports filesystem-level usage, not directory breakdowns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
du -sh /data/*
To find which directories are using the most space, du -sh /data/* provides a per-directory summary. After identifying the culprit, find can precisely locate and delete old log files based on age, avoiding accidental removal of recent data. df only shows filesystem totals, ls -lR is too verbose, and rm -rf is destructive and indiscriminate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
df -h /data
Why it's wrong here
df -h /data reports the overall usage of the filesystem mounted at /data, not the breakdown by directory. It tells the administrator that space is low but does not identify which subdirectories are responsible. This command is useful for confirming the problem but not for locating the largest directories.
- ✓
du -sh /data/*
Why this is correct
du -sh /data/* summarizes the disk usage of each immediate item under /data in human-readable form, quickly revealing which directories are largest. This directly addresses the need to identify space consumers without listing every file, making it efficient for locating the problematic directory.
- ✗
ls -lR /data | less
Why it's wrong here
ls -lR recursively lists all files with details, which can be overwhelming and does not summarize usage by directory. It does not directly show which directories consume the most space. This command is impractical for identifying large consumers on a busy filesystem and does not help with safe deletion.
- ✓
find /data -type f -name '*.log' -mtime +30 -delete
Why this is correct
find with -mtime +30 locates files older than 30 days, and -delete removes them. This safely targets old log files without affecting recent ones. It is a precise way to reclaim space after identifying large directories, assuming the administrator has verified that those logs are no longer needed.
- ✗
rm -rf /data/*
Why it's wrong here
rm -rf /data/* deletes everything under /data unconditionally, which is extremely dangerous and could destroy critical data. It does not target old logs specifically and provides no safety. This is not a recommended approach for reclaiming space and could cause severe data loss.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Linux Foundation exam blueprint
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.