Courseiva

Linux Foundation Certified System Administrator LFCS (LFCS) — Questions 1–75

406 questions total · 6pages · All types, answers revealed

Page 1 of 6

Page 2
1
MCQmedium

An administrator wants to ensure that a service starts automatically after a system crash. Which systemd command should be used?

A.systemctl daemon-reload
B.systemctl enable service
C.systemctl mask service
D.systemctl start service
AnswerB

systemctl enable creates the symlinks that pull the unit into the appropriate target's wants directory, so systemd starts the service automatically at boot, including after a crash-induced reboot. Starting it now would not survive a restart.

Why this answer

The `systemctl enable service` command creates the necessary symlinks in the systemd unit configuration directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) so that the service is automatically started at boot. This includes recovery after a system crash, because the crash triggers a reboot, and the enabled service will be started as part of the normal boot process.

Exam trap

The trap here is that candidates confuse `systemctl start` (immediate, one-time start) with `systemctl enable` (persistent boot-time start), leading them to choose option D, which does not survive a reboot or crash.

How to eliminate wrong answers

Option A is wrong because `systemctl daemon-reload` only reloads the systemd manager configuration and unit files, but does not change the enablement state of any service; it cannot ensure a service starts after a crash. Option C is wrong because `systemctl mask service` creates a strong symlink to `/dev/null`, which prevents the service from being started manually or automatically, even by dependencies or boot; this is the opposite of what is needed. Option D is wrong because `systemctl start service` only starts the service immediately in the current session; it does not create any boot-time or crash-recovery enablement, so the service will not start automatically after a reboot or crash.

2
MCQmedium

A security policy requires that a user's password must expire 90 days after last change, and the user must change it immediately on next login. The last password change was 30 days ago. Which set of commands achieves this?

A.chage -M 90 user1; chage -d 0 user1
B.chage -M 90 user1; chage -m 1 user1
C.chage -M 90 user1; chage -W 7 user1
D.chage -M 90 user1; chage -I 5 user1
AnswerA

Setting `-M 90` defines the maximum password age as 90 days, satisfying the expiry constraint. Setting `-d 0` backdates the last-change date to the epoch, forcing an immediate password change at next login. Together they meet both policy requirements for user1.

Why this answer

`chage -M 90 user1` sets the maximum password age to 90 days, and `chage -d 0 user1` forces the password to expire immediately (setting the last change date to epoch 0), which requires the user to change the password on the next login. This satisfies both requirements: the password will expire 90 days after the forced change, and the user must change it immediately.

Exam trap

The trap here is that candidates may confuse `-d 0` with other `chage` options like `-M`, `-m`, `-W`, or `-I`, not realizing that only `-d 0` forces an immediate password change on next login.

How to eliminate wrong answers

Option B is wrong because `chage -m 1` sets the minimum number of days between password changes to 1, which does not force immediate expiration or enforce the 90-day expiry; it only prevents the user from changing the password more than once per day. Option C is wrong because `chage -W 7` sets a warning period of 7 days before password expiration, which does not force immediate password change on next login. Option D is wrong because `chage -I 5` sets the inactive lockout period to 5 days after expiration, which does not force immediate password change on next login.

3
MCQeasy

A developer reports that a custom daemon fails to start after a reboot. The daemon's unit file is located in /etc/systemd/system/custom.service. Which of the following is the most likely cause?

A.The service was not started manually after installation.
B.The service is not enabled.
C.The SELinux policy blocks the service.
D.A firewall rule is blocking inbound connections.
AnswerB

An enabled unit creates the symlink under the target's `.wants` directory, which is what triggers the start at boot; a unit merely present in `/etc/systemd/system` is loaded but never pulled in. Since the daemon runs fine manually, only the missing enablement explains the reboot-specific failure.

Why this answer

The most likely cause is that the service is not enabled (systemctl enable). Even though the unit file exists in /etc/systemd/system, systemd only starts services automatically at boot if they are enabled. Option B is correct.

Option A is incorrect because manually starting the service after installation would work but does not affect boot behavior. Option C is unlikely because SELinux policy blocks would produce a different error (e.g., denial messages). Option D is incorrect because firewall rules do not prevent systemd from starting a service; they affect network connectivity.

4
MCQmedium

A financial firm requires all internal SSH connections to be encrypted with at least 256-bit ciphers. An administrator is configuring the SSH server. Which configuration line should be added to /etc/ssh/sshd_config?

A.MACs hmac-sha2-256
B.KexAlgorithms diffie-hellman-group-exchange-sha256
C.Ciphers aes256-ctr
D.HostKeyAlgorithms ssh-rsa
AnswerC

Restricting the server to `aes256-ctr` satisfies the 256-bit minimum by offering only that cipher during negotiation. Unlike `aes128-ctr`, it meets the stated strength floor, and unlike broad lists such as `aes256-ctr,aes128-ctr`, it cannot silently downgrade to a weaker algorithm.

Why this answer

The Ciphers directive in sshd_config explicitly controls the symmetric encryption algorithms used to encrypt SSH session data. The cipher aes256-ctr provides 256-bit encryption, meeting the firm's requirement for at least 256-bit ciphers. Other directives like MACs, KexAlgorithms, or HostKeyAlgorithms do not directly set the encryption cipher strength.

Exam trap

The trap here is that candidates confuse MACs, KexAlgorithms, or HostKeyAlgorithms with encryption ciphers, assuming any directive with '256' or 'sha256' implies 256-bit encryption, when only the Ciphers directive controls the symmetric encryption algorithm strength.

How to eliminate wrong answers

Option A is wrong because MACs (Message Authentication Codes) specify integrity-check algorithms like hmac-sha2-256, not encryption ciphers; they ensure data authenticity, not confidentiality. Option B is wrong because KexAlgorithms define key exchange methods (e.g., diffie-hellman-group-exchange-sha256) that negotiate session keys, but they do not determine the symmetric cipher used for encrypting the actual data stream. Option D is wrong because HostKeyAlgorithms specify which host key types (e.g., ssh-rsa) are accepted for server authentication, not the encryption cipher for the session.

5
MCQhard

A storage administrator wants to create a software RAID 10 (1+0) array using six disks. Which mdadm command is appropriate?

A.mdadm --create /dev/md0 --level=10 --raid-devices=6 /dev/sda /dev/sdb /dev/sdc
B.mdadm --create /dev/md0 --level=10 --raid-devices=6 /dev/sd[abcdef]
C.mdadm --create /dev/md0 --level=1 --raid-devices=6 --chunk=64 /dev/sd[abcdef]
D.mdadm --create /dev/md0 --level=10 --raid-devices=4 /dev/sda /dev/sdb /dev/sdc /dev/sdd
AnswerB

`--level=10` builds a striped mirror set, and `--raid-devices=6` declares all six member disks, satisfying the stem's RAID 1+0 over six disks constraint. The brace expansion `/dev/sd[abcdef]` supplies exactly six devices, so mdadm creates `/dev/md0` without prompting for missing members.

Why this answer

It uses the proper mdadm syntax to create a RAID 10 array with six disks. The --level=10 specifies RAID 10 (a striped mirror set), and --raid-devices=6 matches the number of disks provided via the /dev/sd[abcdef] glob, which expands to /dev/sda through /dev/sdf. This command correctly creates a RAID 10 array that combines striping and mirroring across all six devices.

Exam trap

The trap here is that candidates often confuse the required number of disks for RAID 10 (thinking any even number works, but the command must match --raid-devices to the actual device count) or mistakenly use RAID 1 (--level=1) when the question explicitly asks for RAID 10, leading them to pick option C.

How to eliminate wrong answers

Option A is wrong because it only lists three disks (/dev/sda, /dev/sdb, /dev/sdc) but specifies --raid-devices=6, which will cause mdadm to fail or prompt for missing devices; RAID 10 requires an even number of disks (at least 4) and the count must match the provided devices. Option C is wrong because it uses --level=1 (RAID 1, pure mirroring) instead of --level=10, and RAID 1 with six disks would create a single mirrored set, not the striped mirror of RAID 10; the --chunk=64 option is irrelevant for RAID 1. Option D is wrong because it specifies --raid-devices=4 but lists four disks, which would create a valid RAID 10 array but with only four disks, not the six disks required by the question.

6
MCQhard

A system administrator needs to ensure that the 'nginx' service starts automatically after a reboot on a system using systemd. The service unit file exists and is currently disabled. Which command should be used?

A.systemctl start nginx
B.systemctl daemon-reload
C.systemctl enable --now nginx
D.systemctl enable nginx
AnswerD

The systemctl enable nginx command creates symbolic links from the systemd system configuration directory to the nginx.service unit file, ensuring the service is started at boot. It does not start the service immediately, but sets it to start automatically on the next boot.

Why this answer

The systemctl enable nginx command is the correct way to configure a service to start automatically at boot. It creates the necessary symlinks without starting the service now, which matches the requirement to ensure automatic startup after a reboot.

Exam trap

The trap here is confusing starting a service with enabling it; starting affects only the current runtime, while enabling controls boot-time behavior.

7
MCQhard

An administrator needs to combine two sorted text files, /tmp/a.txt and /tmp/b.txt, into a single sorted stream on standard output while also removing duplicate lines that appear in both files. Which command should be used?

A.sort -m /tmp/a.txt /tmp/b.txt
B.comm -12 /tmp/a.txt /tmp/b.txt
C.sort -u /tmp/a.txt /tmp/b.txt
D.uniq /tmp/a.txt /tmp/b.txt
AnswerC

Passing both files as arguments to sort merges them into one input stream, and -u suppresses duplicate lines after sorting. Because the input files are already sorted, the result is a single ordered stream with duplicates from either file removed, which is exactly the stated goal.

Why this answer

Sorting both files together with duplicate suppression yields the union of their lines in order, which matches the request. Merge mode preserves duplicates, uniq cannot read two inputs and would clobber the second path, and comm -12 returns only the shared lines, so none of those alternatives produce the required combined, deduplicated stream.

Exam trap

The trap here is assuming uniq can accept two files and merge them, when its second argument is an output file.

8
Multi-Selecthard

A Linux server uses a software RAID1 array /dev/md0 assembled from /dev/sdb1 and /dev/sdc1. The administrator wants to replace the failing disk /dev/sdc with a new disk /dev/sdd without losing data or interrupting service. Which two steps are required to correctly replace the disk in the array? (Choose two.)

Select 2 answers
A.Mark /dev/sdc1 as failed with mdadm /dev/md0 --fail /dev/sdc1, then remove it with mdadm /dev/md0 --remove /dev/sdc1.
B.Recreate the array with mdadm --create /dev/md0 --level=1 --raid-devices=2 /dev/sdb1 /dev/sdd1.
C.Run mdadm --grow /dev/md0 --raid-devices=2 to resize the array after adding the new disk.
D.Use dmsetup remove /dev/md0 to detach the array, then re-add the new disk.
E.Add the new disk to the array with mdadm /dev/md0 --add /dev/sdd1, then monitor rebuild with cat /proc/mdstat.
AnswersA, E

Before physically removing a disk from a RAID array, it must be marked as failed and then removed from the array metadata. mdadm --fail tells the kernel to stop using the device, and --remove detaches it from the array. This ensures the array does not attempt to read from or write to the disk being replaced, preventing errors and data inconsistency.

Why this answer

To replace a disk in a RAID1 array, the failed disk must first be marked failed and removed from the array. Then the new disk, partitioned identically, is added with mdadm --add, which triggers a rebuild. These two steps maintain data integrity and restore redundancy without recreating or resizing the array.

Exam trap

The trap here is thinking that a new disk can simply be plugged in and will automatically join the array, or that the array must be recreated, when in fact explicit fail/remove/add steps are required.

9
MCQhard

A security policy requires that user 'svc_backup' have a password that never expires. Additionally, the account should be locked after 90 days of inactivity. Which set of commands achieves this?

A.chage -W 7 -I 90 svc_backup
B.chage -E 2025-01-01 -I 90 svc_backup
C.chage -M 99999 -I 90 svc_backup
D.chage -M 90 -I 90 svc_backup
AnswerC

The -M 99999 flag sets the maximum days between password changes to effectively never expire, meeting the no-expiry policy. The -I 90 flag sets the inactivity period, after which the account is locked, satisfying the 90-day lockout requirement precisely.

Why this answer

`chage -M 99999` sets the maximum password age to 99999 days, effectively preventing the password from ever expiring (since 99999 days far exceeds any practical lifespan). The `-I 90` flag sets the inactivity period to 90 days, meaning the account will be locked after 90 days of no login activity. This combination satisfies both security policy requirements: a non-expiring password and automatic lockout after 90 days of inactivity.

Exam trap

The trap here is that candidates often confuse `-I` (inactivity lock) with `-E` (account expiration) or assume that setting `-M 90` combined with `-I 90` will satisfy both requirements, but `-M 90` causes the password to expire, which violates the 'never expires' mandate.

How to eliminate wrong answers

Option A is wrong because `-W 7` sets a warning period of 7 days before password expiration, but it does not disable password expiration; the password will still expire based on the default maximum age (typically 99999 or a system-defined value), and `-I 90` alone does not prevent expiration. Option B is wrong because `-E 2025-01-01` sets an absolute account expiration date, which would lock the account on that date regardless of inactivity, and does not prevent password expiration; the policy requires the password to never expire, not the account to expire on a fixed date. Option D is wrong because `-M 90` sets the maximum password age to 90 days, meaning the password will expire after 90 days, contradicting the requirement that the password never expires; the `-I 90` inactivity lock would only apply after the password expires, not independently.

10
MCQmedium

A Linux administrator needs to ensure that the nginx.service is restarted automatically if it crashes, but only after a 10-second delay, and that it does not restart more than 5 times within 1 minute to avoid a restart loop. Which set of directives in the [Service] section achieves this?

A.Restart=on-failure, RestartSec=10, StartLimitIntervalSec=60, StartLimitBurst=10
B.Restart=on-failure, RestartSec=10, StartLimitIntervalSec=60, StartLimitBurst=5
C.Restart=always, RestartSec=10, StartLimitInterval=60, StartLimitBurst=5
D.Restart=on-abnormal, RestartSec=10, StartLimitIntervalSec=60, StartLimitBurst=5
AnswerB

Restart=on-failure restarts the service only when it exits with a non-zero status or is killed by a signal. RestartSec=10 sets a 10-second delay before restarting. StartLimitIntervalSec=60 and StartLimitBurst=5 limit restarts to 5 within 60 seconds, preventing loops. This combination exactly matches the requirements.

Why this answer

The correct directives are Restart=on-failure, RestartSec=10, StartLimitIntervalSec=60, and StartLimitBurst=5. Restart=on-failure ensures restarts only on crashes, RestartSec=10 adds the delay, and the start limit directives restrict restarts to 5 per 60 seconds. The other options either use the wrong restart policy, an outdated directive name, or an incorrect burst value.

Exam trap

The trap here is using StartLimitInterval instead of StartLimitIntervalSec, or confusing StartLimitBurst with the number of restarts allowed within the interval.

11
MCQmedium

A custom systemd service unit file has been created but the service fails to start with 'Exec format error'. What is the most likely cause?

A.The unit file has incorrect permissions
B.The user does not have permission to start the service
C.The service is disabled
D.The ExecStart command path is incorrect or missing shebang
AnswerD

'Exec format error' occurs when the kernel cannot execute the binary, typically because the ExecStart path is wrong or a script lacks its shebang line. The kernel then cannot identify an interpreter, so execution fails before the service runs.

Why this answer

The 'Exec format error' in systemd indicates that the binary or script specified in the ExecStart directive cannot be executed, typically because the path is incorrect, the file is not executable, or (most commonly) the script lacks a valid shebang line (e.g., #!/bin/bash). Without a shebang, the kernel does not know which interpreter to use, causing an execve() failure.

Exam trap

Linux Foundation often tests the distinction between 'Exec format error' and other startup failures, trapping candidates who confuse permission issues (chmod +x) with the missing shebang requirement for interpreted scripts.

How to eliminate wrong answers

Option A is wrong because unit file permissions (e.g., 644) do not affect execution; systemd reads the unit file as root, and the error is about the ExecStart target, not the unit file itself. Option B is wrong because if the user lacked permission to start the service, systemctl would report 'Permission denied' or 'Access denied', not an 'Exec format error'. Option C is wrong because a disabled service simply means it won't start automatically at boot; attempting to start it manually with systemctl start would still work if the unit is correct, and the error would not be 'Exec format error'.

12
MCQeasy

After editing a service unit file, which command must be run for changes to take effect?

A.systemctl restart <service>
B.systemctl daemon-reload
C.systemctl reenable <service>
D.systemctl reload <service>
AnswerB

`systemctl daemon-reload` forces systemd to re-read all unit files and rebuild its dependency tree, so the edited service definition is picked up without a reboot. Running `systemctl restart` alone reuses the cached unit, leaving your changes ignored. This satisfies the stem's requirement that modifications take effect.

Why this answer

When a service unit file is edited, systemd must be notified to reload its configuration from disk. The `systemctl daemon-reload` command instructs systemd to re-read all unit files, applying any changes to the unit definitions without requiring a full system reboot. This is necessary because systemd caches unit file contents in memory, and only a daemon-reload will update that cache.

Exam trap

The trap here is that candidates confuse restarting the service (which affects the running process) with reloading the systemd daemon (which updates the unit definition cache), leading them to choose `systemctl restart` instead of `systemctl daemon-reload`.

How to eliminate wrong answers

Option A is wrong because `systemctl restart <service>` only stops and starts the service using the currently loaded unit configuration; it does not cause systemd to re-read the unit file from disk, so any changes to the unit file itself are ignored. Option C is wrong because `systemctl reenable <service>` recreates symlinks in the systemd configuration directories but does not reload the unit definitions into systemd's running state. Option D is wrong because `systemctl reload <service>` sends a SIGHUP or equivalent signal to the service process to reload its own configuration files, not systemd's unit file definitions.

13
Multi-Selecthard

Which TWO of the following are correct statements about systemd journald configuration?

Select 2 answers
A.The 'MaxRetentionSec' directive sets the maximum time to retain journal entries.
B.The 'RuntimeMaxUse' directive applies to the journal stored in /var/log/journal.
C.The 'SystemMaxUse' directive in journald.conf limits the maximum disk space used by the journal.
D.The 'Compress' directive is set to 'no' by default.
E.The 'ForwardToSyslog' directive is set to 'yes' by default.
AnswersA, C

MaxRetentionSec specifies the maximum time (in seconds) that journal entries are kept. Older entries are deleted.

Why this answer

The 'MaxRetentionSec' directive in journald.conf specifies the maximum time (in seconds) that journal entries are retained before they are deleted. This is a time-based retention policy, distinct from size-based limits, and is used to automatically prune old log entries to manage disk usage.

Exam trap

The trap here is that candidates often confuse 'RuntimeMaxUse' with persistent storage limits, or assume 'ForwardToSyslog' is enabled by default because of legacy syslog integration, but systemd journald isolates logs by default.

14
Multi-Selectmedium

Which THREE commands can be used to list all users currently logged into the system?

Select 3 answers
A.w
B.last
C.users
D.id
E.who
AnswersA, C, E

The `w` command reads `/var/run/utmp` and prints every logged-in user alongside their terminal, source host, login time and current activity, satisfying the requirement to list all users currently logged into the system. It shows the full session table rather than only the invoking user, as `whoami` would.

Why this answer

The w command (A) is correct because it reads /var/run/utmp and displays every user currently logged in along with their terminal, source host, login time, idle time, and current process. The users command (C) is correct because it prints a space-separated list of the login names of all users currently logged into the system, derived from utmp. The who command (E) is correct because it also reads utmp and lists currently logged-in users with their terminal, login time, and remote host.

The last command (B) is not correct here because it reads /var/log/wtmp and shows historical login/logout records, including past sessions, not only users currently logged in. The id command (D) is not correct because it displays the UID, GID, and group memberships of a single specified or current user rather than listing all logged-in users.

Exam trap

Candidates often confuse `last` (which shows historical logins) with `w`, `who`, or `users` (which show current logins). They may also overlook that `users` is a valid command, or mistakenly think `id` provides login status. While `w` and `who` are commonly taught, `users` is also correct and should not be dismissed.

15
MCQeasy

A user wants to find all files in /var/log that have been modified within the last 2 days. Which command should they use?

A.find /var/log -mtime -2
B.find /var/log -mmin -2880
C.find /var/log -mtime +2
D.find /var/log -mtime 2
AnswerA

The -mtime test compares each file's modification time against 24-hour periods, so -2 selects files changed less than two days ago. This directly satisfies the stem's 'within the last 2 days' constraint, whereas -mtime +2 would return older files.

Why this answer

The `find` command with `-mtime -2` searches for files whose content was last modified less than 2 days ago (i.e., within the last 48 hours). The minus sign before the number indicates 'less than' or 'within the last N days', which matches the user's requirement to find files modified within the last 2 days.

Exam trap

The trap here is that candidates often confuse the meaning of the plus (+) and minus (-) signs with `-mtime`, mistakenly thinking `+2` means 'within the last 2 days' or that `-mtime 2` (without sign) means 'within 2 days', when in fact the signs control the direction of the time comparison.

How to eliminate wrong answers

Option B is wrong because `-mmin -2880` would find files modified within the last 2880 minutes (which is exactly 2 days), but the question asks for files modified within the last 2 days, not exactly 2 days ago; however, the more precise issue is that `-mmin` counts minutes, not days, and while 2880 minutes equals 2 days, the command would work but is not the standard or expected answer for this context. Option C is wrong because `-mtime +2` finds files modified more than 2 days ago (greater than 48 hours), which is the opposite of what is needed. Option D is wrong because `-mtime 2` (without a plus or minus sign) finds files modified exactly 2 days ago (i.e., between 48 and 72 hours ago), not within the last 2 days.

16
Multi-Selectmedium

Which THREE of the following statements about Linux file permissions are correct?

Select 3 answers
A.The command 'chmod a+w file' removes write permission for all.
B.The command 'chmod 400 secret.txt' sets read-only permission for the owner only.
C.The command 'chmod 755 file' sets permissions to rwxr-xr-x.
D.The command 'chmod u+x script.sh' adds execute permission for the owner.
E.The command 'chmod 644 file' sets permissions to rw-rw-rw-.
AnswersB, C, D

Setting mode 400 grants the owner read permission while clearing write and execute for owner, group and others, satisfying the stem's requirement for owner-only read access. The leading digit 4 maps to read in the octal notation, and the two trailing zeros deny all group and other permissions.

Why this answer

Option B is correct because chmod 400 secret.txt assigns the octal value 4 (read) to the owner and 0 (no permissions) to group and others, producing r--------, i.e., read-only for the owner only. Option C is correct because chmod 755 file sets owner to 7 (rwx), group to 5 (r-x), and others to 5 (r-x), yielding rwxr-xr-x. Option D is correct because chmod u+x script.sh uses the symbolic mode u+x to add execute permission for the file's owner without altering other permission bits.

Option A is wrong because a+w adds write permission for all (user, group, other), not removes it; removal would be a-w. Option E is wrong because chmod 644 yields rw-r--r--, not rw-rw-rw- (which would be 666).

Exam trap

The trap here is that candidates often confuse the numeric permission values (e.g., thinking 644 gives rw-rw-rw- instead of rw-r--r--) or misinterpret the symbolic mode syntax, such as assuming 'a+w' removes write permission when it actually adds it.

17
MCQhard

A DevOps engineer wants to list all running processes sorted by memory usage in descending order. Which command should be used?

A.ps aux --sort=-%mem
B.ps aux --sort=%mem
C.ps aux --sort=+mem
D.ps aux --sort=-%cpu
AnswerA

`ps aux --sort=-%mem` lists every process with user, CPU and memory columns, then orders by the `%mem` field. The leading minus reverses the default ascending sort, placing the heaviest memory consumers first, which satisfies the descending-order requirement. `aux` also captures processes beyond the current terminal, so nothing running is omitted.

Why this answer

`ps aux` lists all running processes, and `--sort=-%mem` sorts them by memory usage in descending order (the minus sign indicates descending). This is the standard way to identify memory-heavy processes for troubleshooting or resource monitoring.

Exam trap

The trap here is that candidates often confuse `%mem` with `mem` or `%cpu` with `%mem`, and may overlook the minus sign for descending order, leading them to pick ascending sort options or the wrong resource metric.

How to eliminate wrong answers

Option B is wrong because `--sort=%mem` sorts by memory usage in ascending order (lowest first), not descending as required. Option C is wrong because `--sort=+mem` uses an invalid sort key; the correct key is `%mem` (with percent sign), and the plus sign is redundant but would still sort ascending if the key were valid. Option D is wrong because `--sort=-%cpu` sorts by CPU usage descending, not memory usage, which does not meet the requirement.

18
MCQmedium

An administrator manages a server whose /home directory resides on the logical volume /dev/vg_users/lv_home. Usage reports show the LV is 98% full, and the volume group vg_users has 40 GB of free extents. The filesystem is ext4. Which sequence correctly expands the usable space to /home?

A.resize2fs /dev/vg_users/lv_home 20G && lvextend -L +20G /dev/vg_users/lv_home
B.lvextend -L +20G /dev/vg_users/lv_home && xfs_growfs /home
C.vgextend vg_users /dev/vg_users/lv_home && resize2fs /dev/vg_users/lv_home
D.lvextend -L +20G /dev/vg_users/lv_home && resize2fs /dev/vg_users/lv_home
AnswerD

lvextend grows the logical volume by 20 GB using free extents in the volume group, then resize2fs expands the ext4 filesystem to fill the larger LV. This is the standard two-step procedure for ext4 on LVM. The filesystem can be mounted during the operation, so no downtime is required for /home.

Why this answer

Extending an ext4 filesystem on LVM requires enlarging the logical volume first with lvextend, then expanding the filesystem with resize2fs. The volume group already has free extents, so no additional physical volume is needed. The filesystem can be resized online while /home remains mounted.

Exam trap

The trap here is mixing filesystem-specific growth tools, using xfs_growfs for an ext4 filesystem or reversing the order of LV and filesystem expansion.

19
Multi-Selectmedium

Which THREE of the following commands can be used to view the contents of a compressed file named 'file.gz' without permanently decompressing it? (Choose exactly three.)

Select 3 answers
A.gzip file.gz
B.zmore file.gz
C.gunzip file.gz
D.zcat file.gz
E.zless file.gz
AnswersB, D, E

zmore pipes the gzip stream through a pager, decompressing on the fly to standard output while leaving file.gz untouched on disk. That satisfies the constraint of viewing contents without permanently decompressing, and it paginates long output.

Why this answer

Option B (zmore file.gz) is correct because zmore is a filter that pipes the decompressed output of gzip-compressed files through more, letting you page through the contents without writing a decompressed file to disk. Option D (zcat file.gz) is correct because zcat decompresses the file to standard output, displaying its contents on screen while leaving the original file.gz intact. Option E (zless file.gz) is correct because zless uses less to page through the decompressed stream of a gzip file, again without permanently decompressing it.

Option A (gzip file.gz) is wrong because gzip is used to compress files (and would actually try to compress file.gz further), not to view contents. Option C (gunzip file.gz) is wrong because gunzip permanently decompresses the file, replacing file.gz with an uncompressed file, which is exactly what the question excludes.

Exam trap

The trap here is that candidates mistakenly think `gunzip` or `gzip` can be used to view file contents without permanent decompression, confusing compression/decompression commands with viewing utilities like `zcat`, `zmore`, and `zless`.

20
Multi-Selecthard

A Linux server has two interfaces, ens5 (203.0.113.10/24) and ens6 (10.20.0.0/24 gateway for internal clients). Internal clients must reach the internet through ens5. The administrator has enabled net.ipv4.ip_forward=1 and configured NAT on ens5, but clients still cannot reach external hosts. Which two additional checks are most likely to resolve the problem? (Choose two.)

Select 2 answers
A.Confirm that the MASQUERADE or SNAT rule matches the outbound interface and source subnet correctly.
B.Disable the reverse path filter by setting net.ipv4.conf.all.rp_filter to 2.
C.Add a static route on the internal clients pointing to the public internet address 203.0.113.10 as the next hop.
D.Verify that the FORWARD chain policy or rules permit traffic between ens6 and ens5.
E.Ensure that the server's default route points to the upstream router on the ens5 network.
AnswersA, D

A NAT rule that references the wrong interface, such as the internal one instead of ens5, or an incorrect source range, will not translate the clients' private addresses. External hosts then have no route back to the 10.20.0.0/24 network, so replies never arrive. Verifying the rule's match criteria is essential when NAT appears configured but does not function.

Why this answer

When IP forwarding and NAT appear configured but clients still fail, the two most common culprits are a restrictive FORWARD chain that drops inter-interface traffic and a NAT rule whose interface or source match is wrong. Both must be verified because either alone prevents end-to-end connectivity for the internal subnet.

Exam trap

The trap here is assuming that enabling ip_forward and writing any NAT rule is sufficient, when firewall forwarding policy and precise NAT match criteria must both be correct.

21
Multi-Selectmedium

Which THREE commands can display the current CPU utilization statistics on a Linux system?

Select 3 answers
A.free
B.top
C.sar -u
D.mpstat -P ALL
E.uptime
AnswersB, C, D

`top` provides a live, continuously refreshing view of per-process and aggregate CPU utilisation, satisfying the requirement to display current statistics. Its interactive display reads directly from `/proc`, showing user, system, nice, idle and wait percentages. Unlike `uptime`, which reports only load averages, `top` gives instantaneous utilisation figures.

Why this answer

Option B, top, is correct because it is an interactive process viewer that continuously reports CPU utilization statistics, including per-core and aggregate usage, load average, and per-process CPU consumption. Option C, sar -u, is correct because the -u flag of the sar command from the sysstat package reports CPU utilization statistics (user, system, iowait, idle percentages) either for the current day or a specified interval. Option D, mpstat -P ALL, is correct because mpstat from the sysstat package with -P ALL displays per-processor CPU utilization statistics, showing each individual CPU core's usage percentages.

Option A, free, is incorrect because it only reports memory and swap usage, not CPU statistics. Option E, uptime, is incorrect because it only shows the current time, system uptime, number of logged-in users, and load averages, without detailed CPU utilization percentages.

Exam trap

The trap here is that candidates may confuse `free` or `uptime` with CPU monitoring tools, but `free` is strictly memory-focused and `uptime` only shows load averages, not actual CPU utilization percentages.

22
MCQhard

An e-commerce company runs a critical application on a Linux server that occasionally becomes unresponsive. The server has 64GB RAM and runs a Java application. The operations team notices that during peak hours, the system becomes very slow and eventually the application crashes with 'OutOfMemoryError'. After restart, it works fine for a while. They suspect a memory leak but also want to ensure the system does not go down during peak hours. The system uses systemd to manage the Java service. The administrator needs to implement a solution that: (1) automatically restarts the service if it becomes unresponsive, (2) limits the memory usage of the service to prevent OOM kills on the system, and (3) provides early warning of high memory usage. Which of the following approaches best meets these requirements?

A.Set up a cron job to run every minute that checks memory usage with free and if > 90%, restart the service with systemctl restart. Also configure MemoryMax=32G in the systemd unit.
B.Configure sysctl vm.overcommit_memory=2 to prevent overcommit, and allocate huge pages for Java. Also set Restart=always in the systemd unit.
C.Use ulimit -v 33554432 in the service script to limit virtual memory, and set Restart=always. Also configure a cron job to send alerts when dmesg shows OOM.
D.Configure systemd service with WatchdogSec=30, Restart=on-failure, MemoryMax=32G. Also set up a log watcher that alerts when memory usage exceeds 28G via journalctl and a custom script.
AnswerD

WatchdogSec=30 restarts the service when it stops responding, Restart=on-failure handles crashes, and MemoryMax=32G caps consumption below the 64GB total, preventing system-wide OOM kills. The journalctl watcher alerts before the 28G threshold, meeting all three requirements.

Why this answer

It uses systemd's WatchdogSec to detect unresponsiveness and Restart=on-failure to automatically restart the service, while MemoryMax=32G enforces a hard memory limit via cgroups to prevent OOM kills. The custom log watcher provides early warning by alerting when memory usage exceeds 28G, satisfying all three requirements.

Exam trap

The trap here is that candidates often confuse ulimit or sysctl settings with cgroup-based memory limits, or assume cron-based polling is sufficient for unresponsiveness detection, overlooking systemd's built-in WatchdogSec mechanism.

How to eliminate wrong answers

Option A is wrong because using a cron job to check memory usage every minute is inefficient and may miss transient spikes, and MemoryMax=32G alone does not provide early warning. Option B is wrong because sysctl vm.overcommit_memory=2 and huge pages do not limit memory usage or provide automatic restart on unresponsiveness; Restart=always only restarts on exit, not on hang. Option C is wrong because ulimit -v limits virtual memory but does not prevent the Java process from exhausting physical memory and causing system-wide OOM; it also lacks early warning and WatchdogSec for unresponsiveness detection.

23
Multi-Selecthard

An administrator is configuring a new server with two 1 TiB NVMe disks, /dev/nvme0n1 and /dev/nvme1n1, and wants to use LVM to create a single logical volume that spans both disks for a database. The volume group will be named vg_db and the logical volume lv_db. Which two commands are required to initialize the disks for LVM and create the volume group? (Choose two.)

Select 2 answers
A.lvcreate -L 2T -n lv_db vg_db
B.mkfs.ext4 /dev/nvme0n1 /dev/nvme1n1
C.pvcreate /dev/nvme0n1 /dev/nvme1n1
D.vgcreate vg_db /dev/nvme0n1 /dev/nvme1n1
E.vgextend vg_db /dev/nvme1n1
AnswersC, D

pvcreate initializes the specified block devices as LVM physical volumes. This is the first step before creating a volume group. It writes LVM metadata to the disks, allowing them to be used in a volume group. This command correctly initializes both NVMe disks for LVM.

Why this answer

To prepare the disks and create the volume group, the administrator must first initialize the disks as physical volumes with pvcreate, then create the volume group with vgcreate, adding both physical volumes. lvcreate is a later step for creating the logical volume, mkfs.ext4 would destroy LVM metadata, and vgextend applies only to existing volume groups. The two required commands are pvcreate and vgcreate.

Exam trap

The trap here is confusing the order of LVM operations, such as trying to extend a volume group that has not been created or formatting disks before LVM initialization.

24
MCQhard

You are a senior Linux administrator for a large data center. A junior admin reports that a newly deployed application server (192.168.100.50/24, default gateway 192.168.100.1) cannot communicate with a legacy server (192.168.200.50/24, default gateway 192.168.200.1). The two subnets are connected via a router (192.168.100.1 and 192.168.200.1). From the app server, you can ping the legacy server's IP successfully. However, when you try to establish an SSH session from the app server to the legacy server, it times out. You check the legacy server's firewall (ufw) and find that it allows SSH (port 22) from the entire 192.168.0.0/16 range. You also confirm that the SSH daemon is running and listening on 0.0.0.0:22. What is the most likely cause?

A.The router is dropping TCP packets due to ACLs.
B.The legacy server's firewall is not allowing SSH; the rule might be misconfigured.
C.The app server's firewall (ufw) is blocking incoming SSH responses.
D.The legacy server's SSH service is not listening on the correct interface.
AnswerC

Since SSH is a TCP connection, the app server sends SYN, and the legacy server replies with SYN-ACK. If the app server's ufw does not allow related/established connections or has a rule that blocks new incoming connections, the SYN-ACK will be dropped, causing a timeout. This is a common misconfiguration.

Why this answer

The app server can ping the legacy server successfully, which confirms that ICMP traffic (Layer 3) passes through the router and that the legacy server's firewall allows ICMP. However, SSH (TCP port 22) fails because the app server's own firewall (ufw) is blocking the incoming SSH response packets (SYN-ACK) from the legacy server. Since the SSH client initiates the connection from the app server, the response packets must be allowed by the app server's firewall; if ufw on the app server blocks established or related incoming traffic, the TCP handshake cannot complete, resulting in a timeout.

Exam trap

The trap here is that candidates assume the problem must be on the target server (firewall or SSH service) because the symptom is a timeout, but the ping success proves Layer 3 connectivity, shifting the issue to the client-side firewall blocking the TCP handshake response.

How to eliminate wrong answers

Option A is wrong because the app server can ping the legacy server successfully, which proves that the router is forwarding packets between subnets and that no ACL is blocking ICMP; if the router were dropping TCP packets due to ACLs, the ping would also likely fail or at least the router's behavior would be inconsistent. Option B is wrong because the legacy server's firewall explicitly allows SSH from the entire 192.168.0.0/16 range, which includes the app server's IP (192.168.100.50), and the SSH daemon is confirmed running and listening on 0.0.0.0:22, so the firewall is not the issue. Option D is wrong because the SSH daemon is listening on 0.0.0.0:22, which means it accepts connections on all interfaces, including the one with IP 192.168.200.50; there is no interface-specific misconfiguration.

25
MCQhard

An administrator is configuring a Linux server as a router. The server has two interfaces: eth0 (192.168.10.1/24) connected to the internal LAN and eth1 (203.0.113.2/24) connected to the internet. After enabling IP forwarding, internal clients still cannot reach external websites. Which command is required to allow the internal subnet to be translated to the external interface?

A.iptables -A FORWARD -s 192.168.10.0/24 -o eth1 -j ACCEPT
B.iptables -t nat -A POSTROUTING -s 192.168.10.0/24 -o eth1 -j MASQUERADE
C.iptables -t nat -A PREROUTING -s 192.168.10.0/24 -o eth1 -j MASQUERADE
D.iptables -t nat -A POSTROUTING -d 192.168.10.0/24 -i eth1 -j SNAT --to-source 203.0.113.2
AnswerB

This rule performs source NAT (masquerading) for traffic from the internal subnet leaving via eth1. It rewrites the source address to that of eth1, allowing return traffic. Without it, external hosts cannot route replies back to the private 192.168.10.0/24 network, so clients fail to reach websites.

Why this answer

For internal clients to reach the internet through a Linux router, their private source addresses must be translated to the router's public address. The correct rule uses the nat table's POSTROUTING chain with MASQUERADE on the outbound interface, enabling source NAT for the internal subnet.

Exam trap

The trap here is selecting a FORWARD rule alone, forgetting that NAT is also needed for private addresses to communicate with external networks.

26
MCQmedium

A storage administrator must add a persistent secondary IPv4 address 192.0.2.50/24 to interface eth1 on a RHEL 9 server using NetworkManager. The primary address is already configured. Which command adds the address so that it survives a reboot?

A.ip addr add 192.0.2.50/24 dev eth1
B.echo 'IPADDR1=192.0.2.50' >> /etc/sysconfig/network-scripts/ifcfg-eth1 && systemctl restart network
C.nmcli con mod eth1 +ipv4.addresses 192.0.2.50/24 && nmcli con up eth1
D.nmcli con mod eth1 ipv4.addresses 192.0.2.50/24 && nmcli con up eth1
AnswerC

The nmcli con mod command with the + prefix appends the address to the existing ipv4.addresses list in the connection profile, preserving the primary address. Running nmcli con up reactivates the connection and applies the change. Because the profile is stored persistently, the secondary address is restored on reboot, satisfying the requirement.

Why this answer

On RHEL 9, NetworkManager stores connection profiles, and nmcli con mod edits them persistently. Using the + prefix before ipv4.addresses appends the new address to the existing list, preserving the primary address. Reactivating the connection with nmcli con up applies the change immediately, and the profile ensures the secondary address returns after a reboot.

Exam trap

The trap here is omitting the + prefix, which silently replaces the existing address list instead of appending to it.

27
MCQeasy

A system administrator is setting up a high-availability cluster using shared storage. Which filesystem is best suited for this environment where multiple nodes need simultaneous read-write access to the same filesystem?

A.Btrfs
B.GFS2
C.XFS
D.ext4
AnswerB

GFS2 is a clustered filesystem using distributed locking through a lock manager, letting multiple nodes mount and write to the same shared device concurrently. This satisfies the simultaneous read-write access constraint, unlike single-node filesystems such as ext4 or XFS.

Why this answer

GFS2 (Global File System 2) is a shared-disk cluster filesystem designed for high-availability environments where multiple nodes require simultaneous read-write access to the same filesystem. It uses a distributed lock manager (DLM) to coordinate access across nodes, ensuring data consistency without requiring a single metadata server. This makes it ideal for active-active cluster configurations with shared block storage.

Exam trap

The trap here is that candidates often confuse a filesystem's ability to be mounted on multiple nodes (e.g., via NFS) with true cluster-aware filesystem support, or they assume that any journaling filesystem like XFS or ext4 can be used on shared storage without a distributed lock manager.

How to eliminate wrong answers

Option A (Btrfs) is wrong because it is a copy-on-write filesystem designed for single-node use with features like snapshots and checksums, but it lacks a distributed lock manager and cannot coordinate concurrent read-write access from multiple nodes. Option C (XFS) is wrong because it is a high-performance 64-bit journaling filesystem for single-node environments; while it supports large files and parallel I/O, it does not have cluster-aware locking mechanisms. Option D (ext4) is wrong because it is a general-purpose journaling filesystem for single hosts and provides no support for shared storage or multi-node concurrent access, making it unsuitable for cluster filesystems.

28
MCQeasy

A system administrator needs to permanently configure a network interface named ens33 with a static IPv4 address of 192.168.1.100/24 and a default gateway of 192.168.1.1 on a system using NetworkManager. Which command should the administrator use to achieve this?

A.nmcli connection modify 'ens33' ipv4.addresses 192.168.1.100/24 ipv4.gateway 192.168.1.1 ipv4.method manual
B.ip addr add 192.168.1.100/24 dev ens33
C.ifconfig ens33 192.168.1.100 netmask 255.255.255.0 up
D.route add default gw 192.168.1.1 ens33
AnswerA

The `nmcli connection modify` command writes the static IPv4 address, prefix and default gateway into the NetworkManager connection profile, and `ipv4.method manual` disables DHCP so the settings survive reboot. This satisfies the requirement for a permanent configuration, unlike `ip addr add`, which only changes the running kernel state.

Why this answer

It uses the `nmcli` command to modify the NetworkManager connection profile for interface ens33, setting a static IPv4 address with CIDR notation and a default gateway, and explicitly setting the method to 'manual' to ensure the configuration persists across reboots. NetworkManager is the default network service on modern Linux distributions, and `nmcli` is the proper tool for permanent configuration changes.

Exam trap

The trap here is that candidates often choose temporary commands like `ip addr add` or `ifconfig` because they work immediately, but the LFCS exam specifically tests the ability to make permanent changes using the system's network management service (NetworkManager) rather than transient runtime commands.

How to eliminate wrong answers

Option B is wrong because `ip addr add` only adds an IP address temporarily to the interface; it does not persist after a reboot and does not configure a default gateway or set the addressing method to manual. Option C is wrong because `ifconfig` is deprecated and does not provide persistent configuration; any changes made with it are lost on reboot, and it does not interact with NetworkManager. Option D is wrong because `route add default gw` only adds a temporary default route; it does not set a static IP address, does not persist across reboots, and does not use NetworkManager's configuration system.

29
Multi-Selecteasy

Which TWO commands can display the current environment variables?

Select 2 answers
A.set
B.echo $HOME
C.env
D.export
E.printenv
AnswersC, E

env prints all exported environment variables for the current shell session, listing each name-value pair. It satisfies the requirement to display the current environment without arguments, unlike set, which also includes shell functions and non-exported variables.

Why this answer

The `env` command (option C) is correct because it prints all current environment variables and their values to standard output when run without arguments. The `printenv` command (option E) is also correct because it displays the values of all environment variables (or a specified one) in the current shell environment. Option A, `set`, is not marked correct because although it lists shell variables, it also includes shell functions and local variables, not strictly the environment variables.

Option B, `echo $HOME`, is not marked correct because it only displays the value of the single HOME variable rather than the current environment variables as a whole. Option D, `export`, is not marked correct because it is used to mark variables for export to child processes, not to display the environment.

Exam trap

The trap here is that candidates often confuse `set` (which shows all shell variables) with `env` (which shows only environment variables), or they think `echo $HOME` is a way to list all variables, when it only shows one specific variable.

30
MCQhard

An administrator must ensure that a Linux router forwards IPv4 packets between its two interfaces, eth0 and eth1, without rebooting. Which command enables this behavior immediately?

A.iptables -A FORWARD -j ACCEPT
B.echo 1 > /proc/sys/net/ipv4/ip_forward
C.ip link set eth0 up && ip link set eth1 up
D.sysctl -w net.ipv4.ip_forward=1
AnswerD

The sysctl -w command writes the value 1 to the net.ipv4.ip_forward kernel parameter at runtime, immediately enabling IPv4 packet forwarding. This satisfies the requirement without a reboot. The change is temporary unless also written to /etc/sysctl.conf or a file under /etc/sysctl.d/ for persistence.

Why this answer

Enabling IPv4 forwarding requires setting the kernel parameter net.ipv4.ip_forward to 1. The sysctl -w command applies this change at runtime, immediately allowing the router to forward packets between interfaces. Firewall rules and interface states are separate concerns; they do not substitute for the kernel forwarding parameter.

Exam trap

The trap here is confusing firewall FORWARD rules or interface activation with the kernel's routing capability.

31
MCQeasy

A system administrator needs to ensure the Apache httpd service starts automatically on system boot. Which command should they use?

A.systemctl enable httpd
B.systemctl start httpd
C.systemctl disable httpd
D.systemctl reload httpd
AnswerA

The enable subcommand creates the persistent symlink that ties httpd into the boot target, so systemd starts it automatically at every boot. Start alone only launches the service for the current session, failing the boot-persistence requirement.

Why this answer

The `systemctl enable httpd` command creates the necessary symlinks in the systemd unit configuration directories (typically `/etc/systemd/system/multi-user.target.wants/`) to ensure the Apache httpd service starts automatically at boot time. This is the correct approach because `enable` configures the service to be started on system startup, whereas `start` only runs it immediately without affecting boot behavior.

Exam trap

The trap here is confusing `systemctl start` (immediate runtime action) with `systemctl enable` (persistent boot-time configuration), leading candidates to choose the command that works now but fails after a reboot.

How to eliminate wrong answers

Option B is wrong because `systemctl start httpd` starts the service immediately in the current session but does not configure it to start on boot; it only affects the runtime state. Option C is wrong because `systemctl disable httpd` removes the boot-time symlinks, preventing the service from starting automatically at boot, which is the opposite of what is required. Option D is wrong because `systemctl reload httpd` sends a SIGHUP signal to the httpd process to reload its configuration without restarting, which has no effect on boot-time behavior.

32
Multi-Selectmedium

Which TWO of the following are valid ways to mount a filesystem with the 'noexec' option to prevent execution of binaries?

Select 2 answers
A.mount -o noexec /dev/sdb1 /mnt/data
B.Add 'exec' to the fourth field of /etc/fstab for the entry.
C.Add 'defaults' to the fourth field of /etc/fstab for the entry.
D.mount --bind /mnt/data1 /mnt/data2
E.Add 'noexec' to the fourth field of /etc/fstab for the entry.
AnswersA, E

The mount command's -o flag passes the noexec mount option alongside the device and target directory, applying it for that mount session. This satisfies the requirement to mount a filesystem with binary execution disabled without editing persistent configuration.

Why this answer

Option A is correct because the mount command's -o flag accepts the noexec mount option directly, so 'mount -o noexec /dev/sdb1 /mnt/data' mounts the device /dev/sdb1 at /mnt/data with binary execution disabled. Option E is correct because the fourth field of an /etc/fstab entry holds the mount options, so adding 'noexec' there (e.g., 'defaults,noexec') makes the filesystem mount with noexec persistently at boot or on 'mount -a'. Option B is wrong because 'exec' is the opposite of noexec and explicitly permits execution.

Option C is wrong because 'defaults' expands to rw,suid,dev,exec,auto,nouser,async, which includes exec and thus allows binaries to run. Option D is wrong because 'mount --bind' merely mirrors one directory tree onto another and does not itself set the noexec option.

Exam trap

The trap here is that candidates often confuse the 'defaults' option in fstab with a safe or neutral setting, not realizing that 'defaults' implicitly includes 'exec', so they incorrectly select option C as a valid way to prevent execution.

33
MCQhard

Based on the journalctl output, what is the most likely cause of the service failure?

A.Another process is already using port 8080.
B.The service configuration file has a syntax error.
C.The system is out of memory.
D.The service is trying to write to a read-only filesystem.
AnswerA

The journal shows the service failed to bind its listening socket because port 8080 was already held by another process, producing an address-already-in-use error. This satisfies the stem by identifying port contention, not a configuration or permission fault, as the cause.

Why this answer

The journalctl output shows a bind error on port 8080 with 'Address already in use'. This indicates that another process is already listening on that port, preventing the service from starting. In systemd, such a failure is logged with the specific errno EADDRINUSE, which directly points to a port conflict.

Exam trap

The trap here is that candidates may confuse a bind error with a configuration syntax error, but the specific 'Address already in use' message uniquely identifies a port conflict, not a parsing issue.

How to eliminate wrong answers

Option B is wrong because a syntax error in the service configuration file would typically produce a parse error or 'Failed to parse' message in journalctl, not a bind error. Option C is wrong because an out-of-memory condition would manifest as an OOM killer event or memory allocation failure, not a specific port bind error. Option D is wrong because a read-only filesystem would produce a 'Read-only file system' error (EROFS) when attempting to write, not an 'Address already in use' error.

34
MCQhard

Refer to the exhibit. The output of 'ps aux' shows a process named 'process_hog' with PID 1234 consuming 99.5% CPU. The process is stuck in an infinite loop and does not respond to SIGTERM. Which signal should be used to forcefully terminate it?

A.kill -2 1234
B.kill -9 1234
C.kill -15 1234
D.kill -19 1234
AnswerB

SIGKILL, signal 9, cannot be caught or ignored, so the kernel terminates the process immediately. SIGTERM is handled or blocked by the looping process, which is why it survived. kill -9 1234 forcefully ends it.

Why this answer

SIGKILL (signal 9) cannot be caught, blocked, or ignored by a process, making it the only reliable way to terminate a process that is stuck in an infinite loop and unresponsive to SIGTERM. Since the process does not respond to SIGTERM (signal 15), a forceful kill with kill -9 is necessary.

Exam trap

In LFCS, the key distinction is between termination signals (SIGTERM, SIGKILL) and stop signals (SIGSTOP). SIGTERM allows graceful shutdown, but if ignored, SIGKILL is the only way to force termination. Some candidates incorrectly use SIGSTOP (pause) or confuse SIGTERM with a guaranteed kill.

How to eliminate wrong answers

Option A is wrong because kill -2 sends SIGINT, which is a polite interrupt signal that can be caught or ignored by the process, and it will not force-terminate a process stuck in an infinite loop. Option C is wrong because kill -15 sends SIGTERM, which is the default termination signal that requests graceful shutdown, but the process is already unresponsive to it as stated in the question. Option D is wrong because kill -19 sends SIGSTOP, which pauses the process but does not terminate it, leaving it in a stopped state and still consuming resources.

35
MCQhard

You are managing a Linux server that hosts a critical web application. The server is running low on disk space in the root filesystem, and you need to free up space urgently. You run 'df -h' and see that /dev/sda1 is mounted on / and is 95% full. You also notice that /var/log/messages is over 2 GB in size. The application writes logs to /var/log/app.log, which is also large. The server has a separate /var partition that has plenty of free space. The application must continue running with minimal downtime. You need to compress and rotate logs without losing any data, and ensure that the root filesystem has at least 10% free space. Which of the following actions should you take first to achieve this goal?

A.Delete /var/log/app.log and /var/log/messages to free space quickly.
B.Stop the application, truncate /var/log/app.log, then restart the application.
C.Use logrotate with the 'copytruncate' option to rotate /var/log/app.log and move the rotated file to /var/old_logs/.
D.Compress /var/log/app.log using gzip and keep it in place.
AnswerC

This rotates the log without interrupting the application and moves it to a partition with space, freeing root.

Why this answer

Logrotate with the 'copytruncate' option allows the application to continue writing to the same file descriptor while the current log is copied and then truncated to zero length. This avoids any application downtime and the rotated log can be moved to the separate /var partition (which has free space) for compression or archiving, freeing space on the root filesystem without data loss.

Exam trap

The trap here is that candidates often choose to delete or truncate logs directly, not realizing that running processes hold file descriptors and that truncation does not immediately free disk space until the file descriptor is closed, or they overlook the 'copytruncate' option which allows zero-downtime rotation.

How to eliminate wrong answers

Option A is wrong because deleting log files while the application is running can cause the application to lose its file handle, potentially crash or stop logging, and data is permanently lost. Option B is wrong because stopping the application causes downtime, which violates the 'minimal downtime' requirement, and truncating the file in place does not free disk space until the file descriptor is released (the space is still held by the running process). Option D is wrong because compressing the log file in place does not free space on the root filesystem (the compressed file still occupies space on /), and the application may still be writing to the file, causing data loss or corruption.

36
MCQmedium

A system administrator needs to change the ownership of the file /var/www/html/index.html from user alice to user bob, and also change the group to webdev. Which command should they use?

A.chmod bob:webdev /var/www/html/index.html
B.usermod -o bob:webdev /var/www/html/index.html
C.chgrp bob:webdev /var/www/html/index.html
D.chown bob:webdev /var/www/html/index.html
AnswerD

The chown command changes file owner and group. Using the syntax user:group, it sets the owner to bob and the group to webdev in a single operation. This exactly matches the requirement without affecting other metadata like permissions.

Why this answer

The chown command is specifically designed to change file owner and group. Using the colon-separated syntax user:group sets both in one step. chmod deals with permissions, chgrp only changes group, and usermod manages user accounts. Thus, chown with bob:webdev is the correct and efficient solution.

Exam trap

The trap here is confusing chmod with chown, or thinking chgrp can change both owner and group when it only affects the group.

37
MCQhard

Based on the exhibit, what is the most likely cause of the blocked task?

A.CPU starvation
B.Memory leak
C.Disk I/O bottleneck or hung storage
D.Network congestion
AnswerC

A blocked task in uninterruptible sleep (D state) typically indicates the process is waiting on storage I/O that never completes. Since the exhibit shows the task stuck rather than terminated, a hung disk or saturated I/O queue is the most likely cause, directly satisfying the blocked-task symptom.

Why this answer

The exhibit shows a process in 'D' state (uninterruptible sleep), which typically indicates the process is waiting for I/O completion from a block device. When a task is blocked in this state for an extended period, it is most likely due to a disk I/O bottleneck or hung storage, as the kernel cannot interrupt this wait. CPU starvation (run queue) and memory leaks (OOM or swapping) produce different process states, making disk I/O the primary suspect.

Exam trap

The trap here is that candidates confuse a process in 'D' state (uninterruptible sleep, I/O wait) with a process that is simply sleeping or waiting on CPU, leading them to incorrectly choose CPU starvation or memory issues instead of recognizing the classic symptom of a disk I/O bottleneck.

How to eliminate wrong answers

Option A is wrong because CPU starvation manifests as processes in 'R' state (runnable) or high load averages with low CPU idle, not as a task stuck in uninterruptible sleep ('D' state). Option B is wrong because a memory leak typically leads to high memory usage, swapping, or OOM killer activity, which would show processes in 'S' (interruptible sleep) or 'R' state, not a blocked 'D' state. Option D is wrong because network congestion causes socket waits and timeouts, reflected in 'S' state or network-related kernel threads, not a task blocked on block I/O in 'D' state.

38
MCQeasy

A system administrator needs to configure a new systemd service unit file for a custom application. The service should start after the network is fully online and requires the /opt/data directory to be mounted. Which section of the unit file should contain the After= and Requires= directives to define these dependencies?

A.[Path]
B.[Install]
C.[Unit]
D.[Service]
AnswerC

The [Unit] section contains generic unit configuration options, including dependency ordering (After, Before) and requirement (Requires, Wants). Directives like After=network-online.target and RequiresMountsFor=/opt/data belong here because they define relationships with other units and mount points, not service execution parameters.

Why this answer

Dependency and ordering directives such as After= and Requires= are placed in the [Unit] section because they describe the unit's relationships with other units and targets. The [Service] section is for execution parameters, [Install] for enabling, and [Path] for path units. Thus, [Unit] is correct.

Exam trap

The trap here is assuming that all directives related to a service go in the [Service] section, but dependency directives are unit-level and belong in [Unit].

39
MCQhard

A systemd-networkd managed interface enp1s0 needs to be configured with a static IP address 192.168.1.100/24 and a default gateway via 192.168.1.1. Which .network file configuration is correct?

A.[Match] Interface=enp1s0 [Network] StaticIP=192.168.1.100/24 Gateway=192.168.1.1
B.[Link] Name=enp1s0 [Network] IPAddress=192.168.1.100/24 Gateway=192.168.1.1
C.[Match] Name=enp1s0 [Network] Address=192.168.1.100/24 Gateway=192.168.1.1
D.[Match] Name=enp1s0 [Network] Address=192.168.1.100/24 DefaultGateway=192.168.1.1
AnswerC

systemd-networkd reads [Match] to bind the file to enp1s0, then [Network] applies the static address and default gateway. Address=192.168.1.100/24 sets the host address and prefix, while Gateway=192.168.1.1 installs the default route, satisfying both stem requirements exactly.

Why this answer

Systemd-networkd uses the `[Match]` section with `Name=` to match the interface, and the `[Network]` section with `Address=` to assign a static IP address and `Gateway=` to set the default gateway. The syntax `Address=192.168.1.100/24` is the proper directive for defining a static IP address in a .network file, and `Gateway=192.168.1.1` correctly specifies the default gateway.

Exam trap

The trap here is that candidates confuse the `[Match]` section key `Name=` with `Interface=` (which is used in other tools like ifcfg files) and mistakenly use `DefaultGateway=` (a valid directive in some network configuration systems like Netplan) instead of the correct `Gateway=` in systemd-networkd.

How to eliminate wrong answers

Option A is wrong because it uses `Interface=` in the `[Match]` section (the correct key is `Name=`) and `StaticIP=` in the `[Network]` section (the correct key is `Address=`). Option B is wrong because it uses `[Link]` instead of `[Match]` to identify the interface, and `IPAddress=` is not a valid directive in the `[Network]` section (the correct directive is `Address=`). Option D is wrong because it uses `DefaultGateway=` instead of the correct `Gateway=` directive for setting the default gateway in systemd-networkd.

40
MCQmedium

A system administrator is setting up a new backup server. The server has two 4TB disks /dev/sda and /dev/sdb. The administrator decides to create a RAID1 array and then an LVM volume group on top of the RAID device. After creating the RAID1 array /dev/md0, they create a physical volume, volume group named vg_backup, and a logical volume lv_data of size 2TB. Then they format with ext4 and mount at /backup. During testing, they realize that the backup data volume will likely exceed 2TB eventually. They want to expand the filesystem to use all available space in the RAID array. What is the correct procedure?

A.lvextend -l +100%FREE /dev/vg_backup/lv_data, resize2fs /dev/vg_backup/lv_data.
B.Unmount /backup, lvextend -l +100%FREE /dev/vg_backup/lv_data, resize2fs /dev/vg_backup/lv_data, mount /backup.
C.Create a new logical volume and mount it separately.
D.Add new disk to RAID array, then extend LVM.
AnswerA

Extending the logical volume with `lvextend -l +100%FREE` consumes all remaining free extents in vg_backup, which sits on the 4TB RAID1 array, so the LV grows to roughly 4TB. `resize2fs` then expands the ext4 filesystem online to match, satisfying the requirement to use all available space.

Why this answer

The correct procedure is to extend the logical volume to use all remaining free space in the volume group with lvextend -l +100%FREE, then resize the ext4 filesystem online with resize2fs. Since ext4 supports online resizing, unmounting is not required.

Exam trap

LFCS often tests whether candidates know that ext4 can be resized online, so they might incorrectly choose to unmount first, which is unnecessary and causes downtime.

How to eliminate wrong answers

Option B is wrong because it includes unmounting the filesystem, which is unnecessary for ext4 online resizing and would cause downtime. Option C is wrong because creating a new logical volume and mounting it separately does not expand the existing filesystem to use all available space in the RAID array; it adds a separate volume, which may not be desired. Option D is wrong because adding a new disk to the RAID array is not needed; the RAID array already has free space (since the LV is only 2TB on a 4TB RAID1), and the goal is to expand the existing LV, not add more physical capacity.

41
MCQhard

You are a systems administrator for a company that runs a critical application on a Linux server with two network interfaces: eth0 (public IP 203.0.113.10/24, gateway 203.0.113.1) and eth1 (private IP 10.0.1.10/24, no gateway). The server must be accessible via SSH (port 22) from the internet, but only from a specific management subnet 198.51.100.0/24. Additionally, the server should be able to access the internet for package updates, but no other inbound traffic from the internet is allowed. The local firewall is iptables. After implementing rules, you find that the server cannot reach the internet (e.g., ping 8.8.8.8 fails), but SSH from the management subnet works. What is the most likely cause?

A.The server's DNS resolver is not configured
B.The SSH rule is misconfigured and accidentally blocks all traffic
C.The iptables rules do not include a rule to allow established and related connections
D.The default policy on the INPUT chain is DROP
AnswerC

Without a state tracking rule, return traffic for outbound connections is blocked, breaking internet access.

Why this answer

Iptables is stateful: by default, the INPUT chain processes only the first packet of a connection. Without a rule allowing established and related connections (e.g., `-m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT`), return traffic from the server's outbound internet requests (e.g., ping to 8.8.8.8) is blocked by the INPUT chain, causing the failure. SSH from the management subnet works because the initial SYN packet is allowed, but the server's outbound traffic fails because the response packets are not recognized as part of an allowed flow.

Exam trap

The trap here is that candidates assume a default DROP policy on INPUT is the root cause, but they overlook that stateful filtering requires an explicit rule for return traffic, which is a classic LFCS and iptables nuance.

How to eliminate wrong answers

Option A is wrong because DNS resolution is irrelevant to a direct ping to 8.8.8.8 (an IP address), and the question states the server cannot reach the internet at all, not just resolve names. Option B is wrong because if the SSH rule were misconfigured and accidentally blocked all traffic, SSH from the management subnet would also fail, but the question confirms SSH works. Option D is wrong because a default DROP policy on the INPUT chain would still allow SSH from the management subnet if an explicit ACCEPT rule exists for that traffic; the issue is specifically that outbound-initiated traffic's return packets are not matched by any rule, not the default policy itself.

42
MCQhard

A user 'alice' cannot log in via SSH. The administrator checks /etc/passwd and sees: alice:x:1002:1002::/home/alice:/sbin/nologin. Which command should be used to allow alice to log in with a bash shell?

A.usermod -d /home/alice alice
B.usermod -u 1002 alice
C.usermod -s /bin/bash alice
D.useradd -m -s /bin/bash alice
AnswerC

The account's login shell is set to /sbin/nologin, which deliberately blocks interactive SSH sessions. Running usermod -s /bin/bash alice rewrites the seventh field of alice's /etc/passwd entry to a valid interactive shell, directly satisfying the requirement that she log in with bash.

Why this answer

The /sbin/nologin shell in the /etc/passwd entry prevents alice from logging in via SSH. The usermod -s /bin/bash alice command changes alice's login shell to /bin/bash, allowing interactive SSH sessions. This directly addresses the shell restriction without altering other account properties.

Exam trap

The trap here is that candidates may confuse the shell field with other fields like home directory or UID, or attempt to recreate the user with useradd instead of modifying the existing account with usermod.

How to eliminate wrong answers

Option A is wrong because usermod -d /home/alice alice changes the home directory, but alice's home directory is already /home/alice, and this does not affect the login shell restriction. Option B is wrong because usermod -u 1002 alice changes the UID to 1002, which is already alice's UID, and has no impact on the shell or login ability. Option D is wrong because useradd -m -s /bin/bash alice attempts to create a new user 'alice', which will fail if the user already exists, and it does not modify the existing user's shell.

43
MCQmedium

A system administrator notices that a web server process (PID 1234) is consuming excessive CPU. They want to trace its system calls to identify the cause. Which command should be used?

A.ltrace -p 1234
B.perf record -p 1234
C.gdb -p 1234
D.strace -p 1234
AnswerD

strace attaches to a running process via -p and reports each system call it makes, exposing where PID 1234 spends time in kernel operations. This directly addresses tracing syscalls of an existing high-CPU process without restarting it.

Why this answer

The correct command is `strace -p 1234`, which attaches to the running process (PID 1234) and intercepts all system calls (e.g., read, write, open) made by that process. This allows the administrator to see exactly what the web server is doing at the kernel level, such as excessive file I/O or network operations, which can pinpoint the cause of high CPU usage. Other tools like ltrace, perf, or gdb serve different purposes (library calls, profiling, debugging) and do not directly trace system calls.

Exam trap

The trap here is that candidates confuse `strace` (system calls) with `ltrace` (library calls), as both trace function calls but at different layers of the software stack, leading them to pick the wrong tool for kernel-level analysis.

How to eliminate wrong answers

Option A is wrong because `ltrace -p 1234` traces library calls (e.g., functions from libc), not system calls; it would show calls like `malloc` or `printf` but miss kernel-level operations like `read` or `write`. Option B is wrong because `perf record -p 1234` is a performance profiling tool that samples hardware events (e.g., CPU cycles, cache misses) and does not trace individual system calls; it provides statistical analysis, not a per-call log. Option C is wrong because `gdb -p 1234` is a debugger that allows interactive inspection of the process's memory and execution, but it is not designed for tracing system calls and would require manual breakpoints and significant overhead.

44
MCQeasy

An administrator needs to temporarily assign the IPv4 address 172.16.5.20/24 to interface ens3, which is currently up but unconfigured. The change should not persist across reboots. Which command accomplishes this?

A.nmcli con mod ens3 ipv4.addresses 172.16.5.20/24
B.ip link set ens3 address 172.16.5.20/24
C.ifconfig ens3 172.16.5.20 netmask 255.255.255.0 up
D.ip addr add 172.16.5.20/24 dev ens3
AnswerD

The ip addr add command from the iproute2 suite assigns an address to a specific interface for the current runtime. Because it does not write to any persistent configuration file, the address disappears after a reboot, which matches the requirement for a temporary change on an already-up interface.

Why this answer

Runtime address assignment on Linux is performed with the iproute2 ip addr add command, which targets a named interface and does not alter persistent configuration. NetworkManager's nmcli modifies stored profiles and persists changes, while ifconfig is legacy. The ip command is the current, supported tool for non-persistent interface changes.

Exam trap

The trap here is reaching for nmcli or ifconfig out of habit, when the requirement is a temporary change and the supported modern tool is ip.

45
Drag & Dropmedium

Order the steps to recover a forgotten root password on a Linux system using single-user mode.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To recover a forgotten root password on Linux using single-user mode, you must first boot into single-user mode (e.g., by adding 'single' to the kernel command line). At the root prompt, the filesystem is mounted read-only, so you must remount it as read-write with 'mount -o remount,rw /'. Then use 'passwd root' to set a new password.

Finally, reboot the system. Attempting to change the password without remounting or rebooting prematurely will cause the recovery to fail.

46
MCQhard

A cron job runs a script every hour but sometimes fails because the script cannot find commands like 'tar' and 'gzip'. The script works when run manually from a terminal. What is the best fix?

A.Run the cron job as root.
B.Modify the script to source the user's .bashrc.
C.Use absolute paths for all commands in the script.
D.Add a PATH statement to the cron job definition.
AnswerC

Cron runs with a minimal PATH, so commands resolve differently than in an interactive shell. Using absolute paths such as /bin/tar and /bin/gzip removes that dependency, guaranteeing the script finds each binary regardless of the invoking environment.

Why this answer

Cron jobs run in a minimal environment with a restricted PATH (often just /usr/bin:/bin). When the script uses commands like 'tar' and 'gzip' without absolute paths, the shell cannot locate them. Using absolute paths (e.g., /bin/tar, /bin/gzip) ensures the script always finds the commands regardless of the environment.

Exam trap

The trap here is that candidates think adding a PATH to the cron job definition (Option D) is the best fix, but the LFCS exam emphasizes absolute paths as the more robust and portable solution for scripts run by cron.

How to eliminate wrong answers

Option A is wrong because running as root does not fix the PATH issue; root also has a minimal PATH in cron and this unnecessarily escalates privileges. Option B is wrong because sourcing .bashrc may not work reliably in cron (non-interactive shell) and .bashrc often contains interactive-only aliases or functions that can break the script. Option D is wrong because adding a PATH statement to the cron job definition (e.g., PATH=/usr/local/bin:/usr/bin:/bin) is a valid alternative but is not the 'best fix' — absolute paths are more explicit, avoid dependency on the cron environment, and are the recommended best practice for scripts run by cron.

47
Multi-Selecthard

A Linux administrator is configuring a systemd service unit for a database application. The administrator needs to ensure that the service is automatically restarted if it crashes, but only after a 10-second delay, and that the restart is not attempted if the service is explicitly stopped by an administrator. Which two directives should be used in the [Service] section to achieve these requirements? (Choose two.)

Select 2 answers
A.Restart=always
B.RestartSec=10
C.StartLimitIntervalSec=10
D.Restart=on-failure
E.RestartPreventExitStatus=0
AnswersB, D

RestartSec=10 sets the delay between the service stopping and systemd attempting to restart it. This directly satisfies the requirement for a 10-second delay before restart. It works in conjunction with Restart= to control the timing of automatic restarts, making it the second correct directive for this scenario.

Why this answer

To automatically restart a service after a crash but not after an explicit stop, Restart=on-failure is the appropriate setting because it restarts only on abnormal termination. To introduce a 10-second delay before each restart attempt, RestartSec=10 is used. Together, these directives ensure the service restarts after crashes with a delay, but remains stopped when an administrator issues systemctl stop.

Other options either restart too broadly or do not control the delay.

Exam trap

The trap here is selecting Restart=always, which seems to ensure restarts but also restarts the service after an administrator intentionally stops it, contrary to the requirement.

48
MCQeasy

A technician must verify which network services are listening on TCP ports and which processes own them on a production server. Which command provides this information directly?

A.lsof -i :22
B.netstat -rn
C.ss -tlnp
D.ip neigh show
AnswerC

The ss command from iproute2 displays socket statistics. The flags -t, -l, -n, and -p select TCP sockets, listening state, numeric addresses, and the owning process respectively. This combination directly lists listening TCP ports along with the process names and PIDs that hold them, matching the requirement.

Why this answer

The ss utility with the -tlnp flags enumerates TCP listening sockets, keeps addresses numeric, and shows the owning process for each. This single command answers both parts of the requirement: which ports are listening and which processes hold them. The other tools either display unrelated tables or cover only a single port.

Exam trap

The trap here is picking a legacy or single-purpose tool like netstat or lsof when ss -tlnp is the modern command that lists all listening TCP sockets with their processes.

49
MCQmedium

An administrator is diagnosing disk space and wants to see the total size of the /var/log directory and all its contents in human-readable units, without listing every individual file. Which command provides exactly this summary?

A.du -ah /var/log
B.du -sh /var/log
C.ls -lh /var/log
D.df -h /var/log
AnswerB

The du command estimates file space usage, the -s option summarizes only the total for the specified directory rather than every subdirectory, and -h prints sizes in human-readable units such as K, M, and G. This produces a single concise line showing the total space consumed by /var/log and everything beneath it, exactly as requested.

Why this answer

The du -sh combination reports a single human-readable total for the specified directory tree, which is precisely the summary needed. The other commands either report filesystem-level capacity, list individual entries, or enumerate every file, none of which deliver a concise total for /var/log.

Exam trap

The trap here is reaching for df because it also reports space; df describes the filesystem, while du describes the directory tree, and only the latter summarizes /var/log itself.

50
MCQhard

An administrator is troubleshooting name resolution on a server. Queries for internal names succeed, but every query for external names fails with 'connection timed out; no servers could be reached'. The file /etc/resolv.conf contains 'nameserver 10.20.30.40' and 'nameserver 10.20.30.41'. The internal DNS servers are reachable, and the administrator wants to test which external name servers actually respond. Which command best performs this test?

A.getent hosts example.com
B.nslookup 8.8.8.8 example.com
C.dig example.com
D.dig @8.8.8.8 example.com
AnswerD

The dig command with an explicit @server argument sends the query directly to that name server, bypassing the servers listed in resolv.conf. This lets the administrator confirm whether an external resolver answers, isolating whether the failure lies with the configured internal servers or with outbound DNS connectivity.

Why this answer

To determine whether an external resolver responds, the query must be sent directly to that resolver rather than to the servers in resolv.conf. The dig command's @server syntax does exactly this, bypassing local configuration. If a direct query to a public resolver succeeds, the problem is with the internal servers' forwarding or recursion; if it fails, outbound DNS traffic is likely blocked.

Exam trap

The trap here is running dig without an @server argument, which silently reuses the resolv.conf servers that are already known to be failing for external names.

51
MCQhard

A system administrator wants to kill a process with PID 1234 that is not responding to SIGTERM. Which command will forcefully terminate it?

A.kill -1 1234
B.kill -15 1234
C.kill -SIGTERM 1234
D.kill -9 1234
AnswerD

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 1234 immediately without waiting for cleanup. This satisfies the stem's requirement for forceful termination when SIGTERM (signal 15) has already failed to stop the unresponsive process.

Why this answer

Kill -9 (SIGKILL) sends signal 9, which cannot be caught, blocked, or ignored by the process. Unlike SIGTERM (signal 15), SIGKILL forces the kernel to immediately terminate the process without allowing it to clean up, making it the appropriate choice when a process is unresponsive to SIGTERM.

Exam trap

The trap here is that candidates often confuse signal numbers or assume that SIGTERM (signal 15) is always sufficient, not realizing that a process can mask or ignore it, while SIGKILL (signal 9) is the only signal that cannot be handled.

How to eliminate wrong answers

Option A is wrong because kill -1 sends SIGHUP (hangup signal), which typically causes a process to reload its configuration or terminate gracefully, not forcefully terminate. Option B is wrong because kill -15 sends SIGTERM, which is the default polite termination signal that the process can catch and ignore, so it is ineffective when the process is not responding to SIGTERM. Option C is wrong because kill -SIGTERM is equivalent to kill -15, sending the same signal that the process is already ignoring, so it will not forcefully terminate it.

52
MCQeasy

An administrator deploys a new custom service using a unit file called myapp.service. The service needs to start automatically at system boot. Which command should the administrator run to achieve this?

A.systemctl start myapp.service
B.systemctl enable myapp.service
C.systemctl add-wants myapp.service
D.systemctl daemon-reload myapp.service
AnswerB

systemctl enable creates the symlinks defined by the unit's [Install] section, wiring myapp.service into the appropriate target's .wants directory so systemd starts it at boot. Starting it immediately would instead require systemctl start, which does not persist across reboots.

Why this answer

The `systemctl enable` command creates the necessary symlinks in the systemd unit configuration directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) to ensure the service is started automatically at boot. This is the correct method to enable a service to start on boot in a systemd-based Linux system.

Exam trap

The trap here is that candidates confuse `systemctl start` (which runs the service now) with `systemctl enable` (which configures automatic startup at boot), leading them to select option A incorrectly.

How to eliminate wrong answers

Option A is wrong because `systemctl start` immediately starts the service but does not configure it to start automatically at boot; it only affects the current session. Option C is wrong because `systemctl add-wants` is not a valid systemd command; the correct command to add a dependency is `systemctl add-wants` is not recognized, and the proper way to enable a service is via `systemctl enable`. Option D is wrong because `systemctl daemon-reload` reloads systemd manager configuration but does not enable a service for boot-time startup; it is used after modifying unit files.

53
MCQmedium

An administrator has added a new disk (/dev/sdb) to a Linux system. The disk is to be used as a physical volume in an existing volume group 'vg_data'. Which sequence of commands should be executed to make the disk available to the volume group?

A.fdisk /dev/sdb; pvcreate /dev/sdb; vgextend vg_data /dev/sdb
B.pvcreate /dev/sdb; vgextend vg_data /dev/sdb
C.pvcreate /dev/sdb; vgcreate vg_data /dev/sdb
D.vgcreate /dev/sdb; vgextend vg_data /dev/sdb
AnswerB

pvcreate initialises /dev/sdb as an LVM physical volume, writing the metadata header LVM requires before any volume group can claim it. vgextend then adds that PV to the existing vg_data, extending its capacity without recreating the group or disturbing existing logical volumes.

Why this answer

It first initializes the disk as a physical volume using `pvcreate`, which writes LVM metadata to /dev/sdb, and then extends the existing volume group 'vg_data' with `vgextend`, adding the new PV to the VG. This is the standard two-step process for adding a new disk to an existing LVM volume group.

Exam trap

The trap here is that candidates may think partitioning (fdisk) is required before LVM operations, or confuse `vgcreate` (which creates a new VG) with `vgextend` (which adds to an existing VG), leading them to pick options that either perform unnecessary steps or use the wrong command for the task.

How to eliminate wrong answers

Option A is wrong because `fdisk /dev/sdb` is unnecessary and potentially harmful; LVM does not require partitioning for a PV (though partitions can be used), and running fdisk without creating a partition would leave the disk without a filesystem table, but the real issue is that `pvcreate` would then fail if the disk has a partition table or the command sequence is redundant. Option C is wrong because `vgcreate` creates a new volume group, but the question specifies the disk should be added to an *existing* volume group 'vg_data', so using `vgcreate` would either fail (if 'vg_data' already exists) or create a second VG with the same name, which is incorrect. Option D is wrong because `vgcreate` is used to create a new VG, not to add a disk to an existing one, and the order is reversed: `pvcreate` must precede `vgextend`; running `vgcreate /dev/sdb` is syntactically invalid as `vgcreate` expects a VG name followed by PVs, not a device path.

54
Multi-Selectmedium

A Linux server has two network interfaces: eth0 (192.168.1.10/24) and eth1 (10.0.0.10/24). The administrator wants to configure the server to route traffic between the two networks. Which two actions are required? (Choose two.)

Select 2 answers
A.Set the default gateway on both client networks to point to the server's respective interface addresses.
B.Enable NAT (masquerading) on the server for both networks.
C.Configure iptables FORWARD rules to accept traffic between the interfaces.
D.Add static routes on the server for both networks.
E.Enable IP forwarding by setting net.ipv4.ip_forward=1.
AnswersC, E

By default, many distributions have a firewall that drops forwarded packets. Adding iptables FORWARD rules to accept traffic ensures that packets are not blocked by the firewall. This is required in addition to enabling IP forwarding for the server to route traffic successfully.

Why this answer

To route traffic between two directly connected networks, the server must have IP forwarding enabled and firewall rules that permit forwarding. Connected routes already exist, so static routes for those networks are not needed. NAT is not required for internal routing, and client gateway configuration is done on the clients, not the server.

Exam trap

The trap here is assuming that NAT or static routes are needed for internal routing, when only forwarding and firewall permissions are required.

55
MCQeasy

A user wants to continuously monitor a log file that is being written to by a running service. Which command achieves this?

A.head -20 /var/log/syslog
B.less /var/log/syslog
C.tail -f /var/log/syslog
D.cat /var/log/syslog
AnswerC

`tail -f` keeps the file descriptor open and polls for appended data, printing new lines as the service writes them, so monitoring continues indefinitely. The `-f` (follow) flag directly satisfies the stem's requirement for continuous monitoring of a live log, unlike a one-off read that exits immediately.

Why this answer

The `tail -f` command displays the last 10 lines of a file by default and then continues to output new lines as they are appended, making it ideal for real-time monitoring of a growing log file. The `-f` flag (follow) keeps the file open and polls for changes, typically using inotify on Linux, to output new data immediately.

Exam trap

The trap here is that candidates may confuse `tail -f` with options that only show static content, such as `head` (which shows the beginning of a file) or `tail` without `-f` (which shows the end but does not follow).

How to eliminate wrong answers

Option A is wrong because `head -20` displays the first 20 lines of the file, not the last lines, and it does not continuously monitor for new entries. Option B is wrong because `less` opens the file for interactive viewing and does not automatically follow new lines unless used with the `+F` option (which enables follow mode), but the plain `less` command does not provide continuous monitoring. Option D is wrong because `cat` outputs the entire file content to the terminal and then exits, with no ability to watch for updates or limit output to the last lines.

56
MCQhard

Based on the exhibit, which process will be affected if the root user runs 'kill 5678'?

A.The www-data process with PID 5678
B.The root process (PID 1234)
C.All www-data processes
D.No process, because root cannot kill www-data processes
AnswerA

Sending SIGTERM to PID 5678 terminates the process owned by www-data, since kill defaults to signal 15 and root bypasses ownership restrictions. This satisfies the exhibit's constraint: the target PID belongs to the www-data user, so root's kill affects that specific process rather than any other.

Why this answer

The 'kill 5678' command sends the default SIGTERM (signal 15) to the process with PID 5678. Since the root user has the CAP_KILL capability and is not subject to the ordinary permission checks that restrict non-root users, root can send signals to any process, including those owned by www-data. Therefore, the www-data process with PID 5678 will be terminated.

Exam trap

The trap here is that candidates may mistakenly believe root cannot kill processes owned by other users, or they may confuse the PID argument with a process name, thinking 'kill 5678' affects all processes of a given user or name.

How to eliminate wrong answers

Option B is wrong because 'kill 5678' targets the process with PID 5678, not PID 1234; the root process (PID 1234) is unaffected unless it coincidentally has PID 5678. Option C is wrong because 'kill 5678' sends a signal only to the specific process with PID 5678, not to all www-data processes; to target all www-data processes, one would need to use a command like 'killall www-data' or 'pkill -u www-data'. Option D is wrong because root can indeed kill any process on the system, including those owned by www-data, due to the superuser's unrestricted signal capability.

57
MCQeasy

An administrator needs to check the UUID of a filesystem on /dev/sdb1. Which command should be used?

A.df -h /dev/sdb1
B.mount | grep sdb1
C.blkid /dev/sdb1
D.fdisk -l /dev/sdb1
AnswerC

`blkid /dev/sdb1` queries the block device directly, reading the filesystem superblock to report its UUID, TYPE and LABEL. It satisfies the stem's requirement to check the UUID of a specific partition without mounting it, and works regardless of whether the device is currently mounted.

Why this answer

The `blkid` command is specifically designed to locate and display block device attributes, including the UUID and filesystem type. Running `blkid /dev/sdb1` queries the device's superblock and outputs its UUID, making it the correct tool for this task.

Exam trap

The trap here is that candidates confuse `blkid` with `fdisk -l` or `df -h`, assuming those commands also display filesystem UUIDs, but only `blkid` (or `lsblk -f`) directly queries the superblock for this attribute.

How to eliminate wrong answers

Option A is wrong because `df -h` shows disk usage and mount points, not UUIDs; it reads from the mounted filesystem table, not the raw device superblock. Option B is wrong because `mount | grep sdb1` lists only current mount information (device, mount point, filesystem type, options) and does not display UUIDs. Option D is wrong because `fdisk -l` displays partition table geometry and partition types (e.g., Linux filesystem), but it does not show the UUID of the filesystem within the partition.

58
MCQmedium

A user 'dba' tries to login via SSH and fails. Based on the exhibit, what is the most likely cause?

A.The file /home/dba/file.txt is corrupt.
B.The user 'dba' has an invalid login shell.
C.The user 'dba' is not in the 'docker' group.
D.The home directory /home/dba does not have correct permissions.
AnswerB

SSH refuses interactive logins when the account's shell is not listed in /etc/shells or is set to a non-interactive value such as /sbin/nologin, terminating the session immediately. The exhibit's shell entry confirms this rather than a password or key problem.

Why this answer

The exhibit shows that the user 'dba' has an invalid login shell (e.g., /sbin/nologin or /bin/false). When the login shell is set to a non-interactive shell, SSH authentication succeeds but the session immediately closes, preventing the user from logging in. This is a common configuration for system accounts or users who should not have interactive shell access.

Exam trap

The trap here is that candidates often assume SSH login failures are always due to authentication (password/key) or file permissions, but the LFCS exam frequently tests the subtle point that an invalid login shell causes a successful authentication followed by an immediate session termination, which appears as a login failure.

How to eliminate wrong answers

Option A is wrong because a corrupt file in the user's home directory does not prevent SSH login; SSH authentication and session establishment occur before any user files are accessed. Option C is wrong because group membership (e.g., 'docker') is irrelevant to SSH login; SSH only checks the user's authentication credentials and shell validity. Option D is wrong because incorrect home directory permissions would cause issues after login (e.g., unable to read .bashrc), but they do not prevent the SSH authentication process itself; SSH only requires the home directory to exist and be accessible for reading the user's SSH configuration files like ~/.ssh/authorized_keys.

59
MCQhard

A Linux administrator is managing a systemd service called app.service that runs a Java application. The service is configured with Restart=on-failure and RestartSec=5. After a recent update, the application crashes immediately upon start with exit code 1. The administrator notices that systemd keeps restarting the service every 5 seconds indefinitely. Which command should the administrator use to view the number of times the service has been restarted and the current restart limit status?

A.journalctl -u app.service -n 50
B.systemctl status app.service
C.systemctl show app.service -p NRestarts -p StartLimitBurst -p StartLimitIntervalSec
D.systemctl list-units --state=failed
AnswerC

systemctl show with -p (property) can display specific properties. NRestarts shows the number of automatic restarts, StartLimitBurst and StartLimitIntervalSec show the rate limiting parameters. This command provides exactly the restart count and limit configuration, helping diagnose the restart loop.

Why this answer

To see the number of restarts and the restart limit configuration, systemctl show with specific properties is the correct tool. NRestarts gives the count, while StartLimitBurst and StartLimitIntervalSec define the rate limiting. Other commands provide logs or status but not these internal counters.

Exam trap

The trap here is assuming that systemctl status or journalctl will show the restart count, but only systemctl show exposes the NRestarts property and limit settings.

60
MCQeasy

The command 'ss -tuln' shows port 80 is listening on a server, but a remote client cannot connect via HTTP. What is the most likely cause?

A.The HTTP service is not running
B.The client has a misconfigured default gateway
C.The server's /etc/hosts file is misconfigured
D.A firewall is blocking incoming TCP port 80
AnswerD

The socket is bound and listening, so the service itself is reachable locally; the failure occurs in transit. A firewall dropping or rejecting inbound TCP port 80 prevents the remote client's SYN from reaching the listener, which is the classic symptom here.

Why this answer

The `ss -tuln` command shows that port 80 is in the LISTEN state, which means the HTTP service (e.g., Apache or Nginx) is bound to the port and ready to accept connections. Since the server is listening but the remote client cannot connect, the most likely cause is a firewall (such as iptables, nftables, or a cloud security group) that is blocking incoming TCP SYN packets destined for port 80, preventing the three-way handshake from completing.

Exam trap

The trap here is that candidates see 'listening' on port 80 and assume the service is fully accessible, forgetting that a firewall can silently drop incoming packets even when the service is up and listening.

How to eliminate wrong answers

Option A is wrong because if the HTTP service were not running, `ss -tuln` would not show port 80 in the LISTEN state; the command output explicitly confirms the service is running. Option B is wrong because a misconfigured default gateway on the client would prevent the client from reaching any remote network, not just port 80 on this specific server; the client can likely reach other services or the server itself via other ports. Option C is wrong because the `/etc/hosts` file is used for local hostname resolution and does not affect network connectivity at the transport layer; a misconfigured hosts file would cause a DNS-like resolution failure, not a TCP connection timeout or reset.

61
MCQmedium

A file server has an XFS filesystem on /dev/vg_data/lv_share that is nearly full. The volume group has 50 GB of free space. The administrator runs lvextend -L +20G /dev/vg_data/lv_share, which succeeds. However, df -h still reports the original size. What should the administrator do next to make the additional space usable?

A.Run partprobe /dev/vg_data/lv_share to make the kernel reread the partition table.
B.Run resize2fs /dev/vg_data/lv_share to expand the filesystem to the new size.
C.Run xfs_growfs /mountpoint, where /mountpoint is the current mount point of the filesystem.
D.Unmount the filesystem, run lvresize --resizefs /dev/vg_data/lv_share, then remount it.
AnswerC

XFS requires an explicit grow operation after the underlying block device is enlarged. xfs_growfs is run against the mount point (not the device) and expands the filesystem to fill the available space on the logical volume. This is the correct next step because lvextend only resized the LV, leaving the XFS filesystem at its old size.

Why this answer

After extending an LV that hosts an XFS filesystem, the filesystem itself must be grown separately. The XFS-specific tool is xfs_growfs, which is invoked with the mount point and can be run while the filesystem is mounted. This expands the filesystem to use the additional space, after which df will show the new size.

Exam trap

The trap here is assuming that lvextend automatically grows the filesystem, when in fact it only resizes the logical volume and a separate filesystem-specific step is needed.

62
MCQmedium

A service is configured to run as a specific user. Which directive in the [Service] section sets the user?

A.RunAs
B.User
C.Account
D.UserID
AnswerB

The User directive in the [Service] section specifies the UNIX account the service process runs as, directly satisfying the requirement to run the service under a specific user rather than root or the default system account.

Why this answer

In systemd service units, the directive to specify the user under which the service process runs is `User=` within the `[Service]` section. This directive sets the Unix user account (by name or UID) that the service's main PID will execute as, ensuring proper privilege separation and security.

Exam trap

The trap here is that candidates may confuse systemd's `User=` with the `RunAs` keyword from other operating systems (like Windows services or Solaris) or with generic terms like `Account`, leading them to pick a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because `RunAs` is not a valid systemd directive; it is a concept from other init systems like Solaris SMF or some Docker configurations. Option C is wrong because `Account` is not a systemd directive; it might be confused with the `Account=` field in PAM or NSS contexts but has no place in a systemd service unit. Option D is wrong because `UserID` is not a valid systemd directive; systemd uses `User=` for the username and `Group=` for the group, not a literal 'UserID' key.

63
MCQeasy

A service named webserver.service is failing to start. The administrator wants to see the most recent error messages related to this service. Which command provides this information?

A.journalctl -u webserver.service
B.systemctl status webserver.service --full
C.systemctl list-units --type=service | grep webserver
D.systemctl is-active webserver.service
AnswerA

journalctl -u webserver.service queries the systemd journal filtered by the unit name, returning that service's logged output, including recent failure messages. The -u flag restricts entries to the specified unit, directly satisfying the requirement to isolate webserver.service errors rather than scanning the entire journal.

Why this answer

The `journalctl -u webserver.service` command queries the systemd journal for all log entries associated with the specified unit, showing the most recent error messages in reverse chronological order. This is the standard way to view detailed, time-stamped error logs for a failing service, as `journalctl` provides access to the binary journal that captures stdout, stderr, and syslog messages from the service.

Exam trap

The trap here is that candidates confuse `systemctl status` (which shows a brief log snippet) with `journalctl -u` (which provides the full, searchable journal), assuming the status command gives complete error history when it only shows a truncated view.

How to eliminate wrong answers

Option B is wrong because `systemctl status webserver.service --full` shows the current state, recent log lines (usually the last 10), and unit metadata, but it does not display the full journal history or allow filtering by priority; it truncates output and is not designed for deep error inspection. Option C is wrong because `systemctl list-units --type=service | grep webserver` only lists loaded service units and their states (active/inactive), not any error messages or logs. Option D is wrong because `systemctl is-active webserver.service` simply returns a single word (active, inactive, failed) indicating the service's current state, with no error details whatsoever.

64
Matchingmedium

Match each file system type to its typical use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

General-purpose Linux file system

High-performance for large files

Copy-on-write with snapshots

Virtual memory paging

Temporary file system in RAM

Why these pairings

Common file systems in Linux include ext4 for general use, XFS for high-performance and large files, and Btrfs for advanced features like snapshots. Swapping definitions is a common error.

65
MCQmedium

A DevOps engineer wants to measure how long a specific command takes to execute. Which command should be used?

A.date
B.uptime
C.wall
D.time
AnswerD

The time shell keyword reports real, user and system execution durations for the following command, directly measuring elapsed runtime. Other tools such as date only bracket execution manually, and strace traces syscalls rather than timing the whole command.

Why this answer

The `time` command is specifically designed to measure the execution duration of a command, reporting real time, user CPU time, and system CPU time. It wraps the target command and tracks the elapsed wall-clock time and resource usage, making it the precise tool for benchmarking command performance.

Exam trap

The trap here is that candidates may confuse `time` with `date` or `uptime` because they all display time-related information, but only `time` measures the execution duration of a specific command.

How to eliminate wrong answers

Option A is wrong because `date` displays or sets the system date and time, but does not measure the duration of a command's execution. Option B is wrong because `uptime` shows how long the system has been running since last boot, along with load averages, not the execution time of a specific command. Option C is wrong because `wall` sends a message to all logged-in users' terminals and has no timing functionality.

66
MCQeasy

Which command will display all groups a specific user belongs to, including both primary and supplementary groups?

A.cat /etc/passwd | grep username
B.groups username
C.id -g username
D.grep username /etc/group
AnswerB

The groups command queries both the primary group from /etc/passwd and supplementary memberships from /etc/group for the named user, printing them in a single line. This satisfies the requirement to show primary and supplementary groups together, unlike id -G which lists GIDs only.

Why this answer

The 'groups' command is the standard utility to list all group memberships for a given user, showing both the primary group (from /etc/passwd) and any supplementary groups (from /etc/group). It queries the system's group database directly, making it the correct and simplest choice for this task.

Exam trap

The trap here is that candidates often confuse 'id -g' (which shows only the primary group ID) with listing all groups, or they assume grepping /etc/group is sufficient, overlooking that the primary group is defined in /etc/passwd and supplementary groups may come from external sources.

How to eliminate wrong answers

Option A is wrong because 'cat /etc/passwd | grep username' only displays the user's primary group ID (GID) from the passwd database, not supplementary groups. Option C is wrong because 'id -g username' outputs only the numeric primary group ID, not the group names or supplementary memberships. Option D is wrong because 'grep username /etc/group' only shows lines in /etc/group where the username appears in the comma-separated member list, missing the primary group and any groups where the user is not explicitly listed (e.g., via NSS or LDAP).

67
MCQeasy

A junior administrator is troubleshooting a server and needs to inspect the manual page for the 'ip' command, but the system is a minimal install where the man pages for that package were not installed. The administrator still wants the short one-line usage summary for 'ip' printed directly to the terminal. Which command should they run?

A.ip --help
B.info ip
C.whatis ip
D.man ip
AnswerA

The --help flag is handled by the utility itself and prints a concise usage summary to standard output, which works even when man pages are absent. It requires no extra packages and exits immediately, making it ideal on a minimal system where documentation was stripped out.

Why this answer

The utility's own --help option is parsed by the binary itself, so it produces usage information regardless of whether any documentation packages exist on the machine. Because the scenario explicitly describes a minimal install with no man pages, the only reliable way to obtain the short usage summary is to invoke the command with its built-in help flag.

Exam trap

The trap here is assuming that documentation commands such as man or whatis can display usage information even when the corresponding documentation packages were never installed.

68
MCQmedium

Refer to the exhibit. The administrator receives alerts that the root filesystem is almost full. Which command could free up space by removing old log files?

A.find /var/log -name '*.log' -mtime +30 -delete
B.truncate -s 0 /var/log/syslog
C.rm -rf /var/log/*
D.du -sh /var/log
AnswerA

This find invocation matches files ending in .log under /var/log whose modification time exceeds 30 days, then unlinks them, directly reclaiming space consumed by stale logs. The -mtime +30 predicate targets only aged files, satisfying the requirement to remove old logs.

Why this answer

The `find` command with `-name '*.log'` targets log files, `-mtime +30` selects files modified more than 30 days ago, and `-delete` removes them. This safely frees space by purging only old logs, preserving recent logs needed for troubleshooting.

Exam trap

Linux Foundation often tests the distinction between commands that merely display disk usage (like `du`) versus those that actually remove files, and the danger of using `rm -rf` with wildcards on system directories like /var/log.

How to eliminate wrong answers

Option B is wrong because `truncate -s 0 /var/log/syslog` empties a single log file but does not remove old log files; it only clears the current syslog, which may still be needed and does not address multiple old log files. Option C is wrong because `rm -rf /var/log/*` deletes all files in /var/log, including critical logs and possibly active log files, which could break logging services and cause data loss. Option D is wrong because `du -sh /var/log` only shows disk usage of the directory; it does not free any space or remove any files.

69
MCQhard

A system administrator needs to create a hard link named /home/user/report_hardlink to an existing file /data/reports/report.txt. Which command should be used?

A.ln /data/reports/report.txt /home/user/report_hardlink
B.ln -s /data/reports/report.txt /home/user/report_hardlink
C.ln -h /data/reports/report.txt /home/user/report_hardlink
D.link -s /data/reports/report.txt /home/user/report_hardlink
AnswerA

The ln command without options creates a hard link. The first argument is the existing target file, and the second is the new link name. This creates a hard link, which shares the same inode and data blocks as the original file, and works as long as both paths are on the same filesystem.

Why this answer

The ln command creates hard links by default. Providing the existing file as the first argument and the new link name as the second creates a hard link. Hard links share the same inode and data, so changes to one are reflected in the other.

They cannot span filesystems. The correct command simply uses ln with the target and link name.

Exam trap

The trap here is assuming that ln always creates symbolic links, or adding unnecessary options like -s that change the link type, when the requirement explicitly asks for a hard link.

70
MCQhard

A system with systemd experiences a service that fails to start due to a 'Failed to start' error with status 203/EXEC. What is the most likely cause?

A.The system has run out of memory
B.The service unit file has a missing or incorrect ExecStart command
C.The service is already running
D.The service requires a dependency that hasn't started
AnswerB

Status 203/EXEC means systemd could not execute the binary specified in ExecStart, typically because the path is wrong, the file lacks execute permission, or the interpreter is missing. Correcting the ExecStart directive resolves the failure.

Why this answer

Status 203/EXEC in systemd indicates that the service manager failed to execute the command specified in the service unit file. The most common cause is a missing or incorrect ExecStart directive, such as a typo in the binary path, a missing executable, or incorrect syntax. This error is specific to execution failures, not resource or dependency issues.

Exam trap

The trap here is that candidates confuse status 203/EXEC with a generic 'service failed to start' and incorrectly attribute it to dependencies or resource exhaustion, rather than recognizing it as a specific indicator of an exec() failure in the ExecStart directive.

How to eliminate wrong answers

Option A is wrong because out-of-memory conditions typically cause OOM kills (status 137/SIGKILL) or systemd service cgroup memory limit violations, not status 203/EXEC. Option C is wrong because if the service is already running, systemd would report a 'start-limit-hit' or 'already running' error, not an EXEC failure. Option D is wrong because dependency failures result in status 203/EXEC only if the dependency itself causes the ExecStart to fail; normally, unmet dependencies produce 'dependency failed' or 'timeout' errors, not an EXEC code.

71
MCQmedium

An administrator needs to configure software RAID 5 on three disks /dev/sda, /dev/sdb, /dev/sdc with a spare disk /dev/sdd. Which command correctly creates the RAID array?

A.mdadm --create /dev/md0 --level=5 --raid-devices=3 --spare-devices=1 /dev/sda /dev/sdb /dev/sdc /dev/sdd
B.mdadm --create /dev/md0 --level=5 --raid-devices=4 /dev/sda /dev/sdb /dev/sdc /dev/sdd
C.mdadm --create /dev/md0 --level=5 --raid-devices=3 /dev/sda /dev/sdb /dev/sdc
D.mdadm --create /dev/md0 --level=5 --raid-devices=3 --spare-devices=1 /dev/sda /dev/sdb /dev/sdc --spare /dev/sdd
AnswerA

The `--level=5` flag sets RAID 5 parity striping across three active members, while `--raid-devices=3` fixes the array's active disk count and `--spare-devices=1` designates /dev/sdd as a hot spare. Listing all four devices in order satisfies the stem's requirement for a three-disk RAID 5 array with one standby disk.

Why this answer

It uses the `--spare-devices=1` flag to designate `/dev/sdd` as a hot spare, while `--raid-devices=3` specifies that only three disks form the active RAID 5 array. The spare disk is listed after the active disks, which is the correct syntax for `mdadm --create`.

Exam trap

The trap here is that candidates often confuse `--raid-devices` with the total number of disks provided, leading them to set `--raid-devices=4` (option B) when they intend to include a spare, or they forget to specify the spare at all (option C).

How to eliminate wrong answers

Option B is wrong because `--raid-devices=4` tells mdadm to use all four disks as active members of the RAID 5 array, leaving no spare disk; this creates a four-disk RAID 5 instead of a three-disk RAID 5 with a spare. Option C is wrong because it omits the spare disk entirely, so `/dev/sdd` is not included in the command and no spare is configured. Option D is wrong because it incorrectly uses both `--spare-devices=1` and a separate `--spare` flag, which is redundant and syntactically invalid; mdadm expects the spare devices to be listed after the active devices, not with a separate `--spare` option.

72
Matchingmedium

Match each Linux permission type to its symbolic representation.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

r

w

x

s (owner execute)

t (other execute)

Why these pairings

In Linux, standard file permissions are represented by symbols: read (r), write (w), and execute (x). Each permission type maps to a unique symbol. Confusion often arises from swapping these symbols.

73
MCQeasy

A junior administrator needs to check the current runlevel and then change the system to runlevel 3 (multi-user, no GUI) on a SysVinit-based system. Which command sequence will accomplish this?

A.runlevel; init 3
B.telinit -q; telinit 3
C.chkconfig --list; init 3
D.systemctl get-default; systemctl isolate multi-user.target
AnswerA

'runlevel' displays the previous and current runlevel, and 'init 3' changes the system to runlevel 3. On SysVinit systems, runlevel 3 is typically multi-user mode without a graphical interface. This sequence is correct for checking and changing runlevels on a SysVinit-based distribution.

Why this answer

On SysVinit systems, the 'runlevel' command displays the current and previous runlevel, and 'init 3' changes to runlevel 3 (multi-user, no GUI). The other options use systemd commands or incorrect utilities that do not fulfill both requirements.

Exam trap

The trap here is assuming that 'chkconfig --list' shows the current runlevel, when it actually lists service configuration across runlevels.

74
MCQmedium

A Linux administrator is troubleshooting a custom systemd service named data-sync.service that repeatedly fails with the error 'start request repeated too quickly'. The unit file has Restart=always and RestartSec=5. Which command should the administrator use to reset the failed state and clear the restart counter so the service can be started again?

A.systemctl reset-failed data-sync.service
B.systemctl daemon-reload
C.systemctl restart data-sync.service
D.systemctl kill data-sync.service
AnswerA

This command resets the failed state of the unit and clears the restart counter maintained by systemd. When a service hits the start limit (default: 5 starts within 10 seconds), systemd refuses further starts until the counter is reset. After running this, the administrator can successfully start the service again with systemctl start.

Why this answer

When a systemd service is configured with Restart=always and crashes repeatedly, systemd enforces a start limit (default 5 starts in 10 seconds) and then refuses further starts with the error 'start request repeated too quickly'. To recover, the administrator must clear the failed state and restart counter using systemctl reset-failed, after which the service can be started normally. This command is specifically designed for this purpose and is the correct tool for the scenario.

Exam trap

The trap here is assuming that restarting the service will automatically clear the failure after the restart delay, but systemd maintains a persistent start counter that must be explicitly reset.

75
MCQeasy

A system administrator needs to ensure that a Linux server can communicate with other hosts on the same subnet. Which command should be used to verify the IP address and netmask configuration?

A.netstat -rn
B.route -n
C.ifconfig
D.ip addr show
AnswerD

ip addr show displays each interface's assigned IPv4 address and prefix length, letting the administrator confirm subnet configuration and netmask. It reads kernel state directly, satisfying the stem's requirement to verify addressing before testing same-subnet communication.

Why this answer

The `ip addr show` command is the modern, recommended tool in Linux for viewing IP addresses and netmasks (prefix lengths) assigned to network interfaces. It directly displays the configuration needed to verify subnet communication, unlike legacy tools that may not show the netmask clearly or mix routing information.

Exam trap

The trap here is that candidates often choose `ifconfig` out of habit, not realizing it is deprecated and may be missing on minimal installations, while `ip addr show` is the current standard and always available in modern Linux distributions.

How to eliminate wrong answers

Option A is wrong because `netstat -rn` displays the kernel routing table, not IP address or netmask configuration. Option B is wrong because `route -n` also shows the routing table, not interface IP/netmask details. Option C is wrong because `ifconfig` is deprecated and may not be installed by default on modern distributions; it can show IP and netmask but is less reliable and lacks the structured output of `ip`.

Page 1 of 6

Page 2

All pages