Courseiva

Linux Foundation Certified System Administrator LFCS (LFCS) — Questions 76–150

406 questions total · 6pages · All types, answers revealed

Page 1

Page 2 of 6

Page 3
76
MCQeasy

A user wants to set the permissions of a file to 'rwxr-xr--'. Which octal permission value should they use with chmod?

A.754
B.755
C.644
D.744
AnswerA

The symbolic mode rwxr-xr-- maps directly to octal 754: owner rwx equals 4+2+1=7, group r-x equals 4+0+1=5, and others r-- equals 4+0+0=4. Passing 754 to chmod therefore sets exactly the requested permission bits on the file.

Why this answer

The permissions 'rwxr-xr--' mean that the owner has read, write, and execute (rwx = 7), the group has read and execute (r-x = 5), and others have only read (r-- = 4). Therefore, the correct octal value is 754. Option A is correct.

Option B (755) gives others execute, option C (644) gives owner no execute and group no execute, and option D (744) gives group no execute.

Exam trap

Candidates often miscompute the octal digits by forgetting that each class (owner, group, others) is calculated independently. Common errors include picking 755 (adding execute for others) or 744 (forgetting group execute). The new option C (644) also shows a mistake where both owner and group execute are omitted.

How to eliminate wrong answers

Option B (755) is wrong because it sets others to r-x (5) instead of r-- (4), granting execute permission to others unnecessarily. Option D (744) is wrong because it sets group to r-- (4) instead of r-x (5), denying group execute permission. Option A and C are identical and both correct; the duplication is an artifact of the answer choices.

77
MCQhard

A technician configured a new network interface eth1 on a CentOS 7 server but the interface does not obtain an IPv4 address via DHCP. Which of the following is the most likely cause?

A.The interface MTU is set too high
B.SELinux is blocking dhclient
C.NetworkManager is not managing the interface (NM_CONTROLLED=no)
D.Firewalld is blocking DHCP ports (67/68)
AnswerC

When NM_CONTROLLED=no, NetworkManager ignores the interface, so DHCP is not attempted.

Why this answer

When NM_CONTROLLED=no is set in the interface configuration file (/etc/sysconfig/network-scripts/ifcfg-eth1), NetworkManager will not manage that interface. Since dhclient is typically invoked by NetworkManager (or by legacy network scripts only if NM_CONTROLLED=yes), the interface will not automatically obtain an IPv4 address via DHCP. On CentOS 7, NetworkManager is the default network service, and disabling its control prevents DHCP client activation.

Exam trap

The trap here is that candidates often assume firewall or SELinux is the culprit for DHCP failures, but the most common cause on CentOS 7 is the NM_CONTROLLED=no setting, which disables NetworkManager's DHCP client management.

How to eliminate wrong answers

Option A is wrong because MTU (Maximum Transmission Unit) being set too high does not prevent DHCP from obtaining an address; DHCP uses Layer 2 broadcast frames and Layer 3 UDP packets, and MTU issues typically cause fragmentation or packet loss, not a complete failure to acquire an IP. Option B is wrong because SELinux does not block dhclient by default; dhclient runs in the dhcpc_t domain, and SELinux policies allow it to send and receive DHCP packets on ports 67/68. Option D is wrong because firewalld blocking DHCP ports (67/68) would prevent DHCP discovery and offer packets from reaching the client, but the question states the interface does not obtain an IPv4 address via DHCP—firewalld could cause this, but it is less likely than the direct configuration issue of NM_CONTROLLED=no, which is a common misconfiguration on CentOS 7.

78
Multi-Selecteasy

A system administrator needs to identify all available block devices on a Linux server. Which two commands can be used to accomplish this? (Choose two.)

Select 2 answers
A.blkid
B.mount
C.lsblk
D.df -h
E.fdisk -l
AnswersC, E

`lsblk` reads sysfs to list all block devices, showing disks, partitions, and their mountpoints in a tree. This directly satisfies the requirement to identify every available block device, including unmounted ones that filesystem-oriented tools would miss.

Why this answer

lsblk (C) is correct because it reads /sys/block and udev data to list all block devices in a tree view, showing disks, partitions, and their sizes, types, and mountpoints regardless of whether they are mounted. fdisk -l (E) is correct because it enumerates every block device in /proc/partitions and prints the partition table of each disk, making it a standard way to discover all available block devices. blkid (A) only reports devices that already have a filesystem or swap signature and their UUID/LABEL, so it misses unformatted or otherwise unrecognized block devices. mount (B) shows only currently mounted filesystems, not all block devices. df -h (D) reports disk space usage of mounted filesystems only, so it also fails to reveal unmounted or unformatted block devices.

Exam trap

The trap here is that candidates often confuse `blkid` with `lsblk` because of similar names, but `blkid` only shows devices with filesystem metadata, not all block devices, making it incomplete for this task.

79
MCQeasy

An administrator needs to change the ownership of the directory /srv/www to user webadmin and group webteam, including all existing files and subdirectories. Which command accomplishes this?

A.chown -R webadmin:webteam /srv/www
B.chmod -R webadmin:webteam /srv/www
C.usermod -R webadmin:webteam /srv/www
D.chown webadmin:webteam /srv/www
AnswerA

The chown command changes file owner and group. The -R option applies the change recursively to all files and subdirectories under /srv/www. Specifying webadmin:webteam sets both the user and group in a single command, which exactly meets the requirement without needing a separate chgrp invocation.

Why this answer

The chown command changes file ownership, and the -R flag applies the change recursively. Specifying both user and group as webadmin:webteam in one invocation sets the owner and group for the directory and everything beneath it. This is the standard, efficient way to recursively reassign ownership for a web directory.

Exam trap

The trap here is confusing chown with chmod, assuming that a permission command can also set ownership, or forgetting that recursive changes require the -R option.

80
MCQmedium

A system administrator notices that a new 500GB SSD (/dev/sdb) is not being recognized by the system after installation. The server uses UEFI and GPT partitioning. Which command should the administrator run first to verify that the disk is detected by the kernel?

A.fdisk -l /dev/sdb
B.lsblk
C.cat /proc/cpuinfo
D.lsusb
AnswerB

lsblk reads /sys/block and udev data to list all block devices the kernel currently recognises, so it immediately confirms whether /dev/sdb was detected after installation without altering anything. This satisfies the stem's requirement to verify kernel-level disk detection first.

Why this answer

The `lsblk` command lists all block devices recognized by the kernel, including those without a filesystem or partition table. Since the disk is new and not yet partitioned, `lsblk` will show it if the kernel has detected it, making it the correct first diagnostic step.

Exam trap

The trap here is that candidates often jump to `fdisk -l` as the first command, but it requires the device to already be recognized and may produce misleading errors if the disk is not detected, whereas `lsblk` directly shows kernel-level recognition without needing a partition table.

How to eliminate wrong answers

Option A is wrong because `fdisk -l /dev/sdb` will fail or show an error if the disk is not detected by the kernel, and it requires the device node to exist; it is not a reliable first check for kernel detection. Option C is wrong because `cat /proc/cpuinfo` displays CPU information, not storage device detection. Option D is wrong because `lsusb` lists USB devices only, and a 500GB SSD is likely connected via SATA or NVMe, not USB.

81
MCQeasy

An administrator wants to change the primary group of user 'jane' from 'staff' to 'developers'. Which command accomplishes this?

A.usermod -g developers jane
B.usermod -G developers jane
C.groupmod -g developers jane
D.chgrp developers jane
AnswerA

`usermod -g` sets the user's primary group in `/etc/passwd`, which is exactly what the stem requires when changing jane's primary group from `staff` to `developers`. The lowercase `-g` targets the primary GID; uppercase `-G` would instead manage supplementary groups, leaving the primary group unchanged.

Why this answer

The `usermod -g` command changes the primary group of a user. The `-g` option specifies the new primary group (by name or GID), and the user's existing primary group is replaced. This directly accomplishes the administrator's goal of changing jane's primary group from 'staff' to 'developers'.

Exam trap

The trap here is confusing the `-g` (primary group) and `-G` (supplementary groups) options of `usermod`, leading candidates to mistakenly choose the uppercase `-G` option when the question explicitly asks for a primary group change.

How to eliminate wrong answers

Option B is wrong because `usermod -G` (uppercase) modifies the supplementary group list, not the primary group; it would add 'developers' as an additional group while leaving the primary group unchanged. Option C is wrong because `groupmod -g` changes the GID of an existing group, not the primary group of a user; it would rename or renumber the 'developers' group itself. Option D is wrong because `chgrp` changes the group ownership of files or directories, not the primary group of a user account.

82
Multi-Selecthard

Which two commands can add an existing user to a supplementary group?

Select 2 answers
A.useradd -G
B.gpasswd -a
C.addgroup
D.groupmod
E.usermod -aG
AnswersB, E

gpasswd -a user group appends the user to the named group's member list in /etc/group, granting supplementary membership without altering the primary group. It edits group membership directly, complementing usermod -aG which does the same via the user's entry.

Why this answer

Option B, gpasswd -a, is correct because gpasswd with the -a (add) flag adds an existing user to a named supplementary group, e.g. `gpasswd -a alice developers`, modifying /etc/group without altering the user's primary group. Option E, usermod -aG, is correct because usermod with -G specifies supplementary groups and the -a (append) flag ensures the listed group is added to the user's existing supplementary group set rather than replacing it, e.g. `usermod -aG developers alice`. Option A, useradd -G, is wrong here because useradd creates new accounts and its -G flag sets supplementary groups only at account-creation time, so it cannot add an already-existing user.

Option C, addgroup, is wrong because it is a Debian/Ubuntu convenience script for creating a new group (and optionally adding a user at creation), not the standard command for adding an existing user to an existing supplementary group. Option D, groupmod, is wrong because it modifies a group's attributes such as its name (-n) or GID (-g), and does not manage user membership.

Exam trap

The trap here is that candidates often confuse `usermod -G` (which replaces all supplementary groups) with `usermod -aG` (which appends), leading them to select `usermod -G` alone as correct, or they mistakenly think `useradd -G` can modify an existing user.

83
Multi-Selectmedium

Which TWO directives are typically used in a systemd service unit file to configure dependencies?

Select 2 answers
A.After
B.Wants
C.Before
D.Alias
E.Requires
AnswersB, E

Wants establishes a weak dependency: systemd starts the wanted unit when this service starts, but failure of that unit does not stop this one. It satisfies the requirement for a dependency directive while tolerating the target's absence, unlike Requires, which enforces a strict dependency.

Why this answer

In a systemd unit file, Wants= (option B) and Requires= (option E) are dependency directives that pull in other units: Wants= establishes a weak dependency where the listed units are started if possible but failure does not stop this unit, while Requires= establishes a strong dependency where the listed units must be activated successfully or this unit fails. Both belong to the [Unit] section and define which other units are needed, which is exactly what the question asks. By contrast, After= (option A) and Before= (option C) only control ordering — they specify start/stop sequence relative to other units but do not create a dependency that pulls those units in.

Alias= (option D) merely provides an alternative name for the unit and has nothing to do with dependencies.

Exam trap

The trap here is that candidates often confuse ordering directives (`After`, `Before`) with dependency directives (`Wants`, `Requires`), mistakenly thinking that specifying an order also implies a dependency, but systemd treats them as separate concepts that must be explicitly combined.

84
MCQhard

A Linux server is unable to resolve the hostname 'app.internal.example.com' but can resolve other names. The /etc/nsswitch.conf file contains: hosts: files mdns4_minimal [NOTFOUND=return] dns. The /etc/hosts file does not list the hostname. Which configuration change would most likely resolve the issue?

A.Change the hosts line to: hosts: dns files mdns4_minimal
B.Configure /etc/resolv.conf to use a different DNS server
C.Remove the mdns4_minimal entry or change it to 'mdns4' without the NOTFOUND=return
D.Add the hostname to the local multicast DNS configuration
AnswerC

Removing `mdns4_minimal` or dropping its `[NOTFOUND=return]` action stops the resolver aborting the lookup when multicast DNS returns nothing. With that action present, the `dns` source is never consulted for names mDNS cannot answer, so `app.internal.example.com` fails despite DNS being reachable.

Why this answer

The issue is that mdns4_minimal with [NOTFOUND=return] causes the resolver to stop after a failed mDNS query, preventing it from falling back to DNS. Since the hostname is not in /etc/hosts and not reachable via mDNS, the resolver returns 'not found' immediately without querying DNS. Removing the mdns4_minimal entry or changing it to 'mdns4' (without the NOTFOUND=return) allows the resolver to proceed to DNS if mDNS fails.

Exam trap

The trap here is that candidates assume the issue is with DNS configuration or order, but the real problem is the [NOTFOUND=return] action on mdns4_minimal, which prematurely terminates the resolution chain for non-.local hostnames.

How to eliminate wrong answers

Option A is wrong because changing the order to 'dns files mdns4_minimal' would still leave the mdns4_minimal with [NOTFOUND=return] in place, so if mDNS fails, the resolver still returns immediately without consulting DNS. Option B is wrong because the server can resolve other names, indicating that the DNS server in /etc/resolv.conf is working correctly; the problem is specific to the resolution order and fallback behavior, not the DNS server itself. Option D is wrong because adding the hostname to multicast DNS configuration would only help if the hostname is served via mDNS on the local link, but the hostname 'app.internal.example.com' is likely a standard DNS name, not a .local mDNS name, so mDNS would not resolve it anyway.

85
MCQhard

A process is consuming 99% CPU and is unresponsive to normal shutdown requests. After running 'top', you see the PID is 1234. What is the most appropriate command to stop the process gracefully first?

A.kill -15 1234
B.kill -19 1234
C.kill -2 1234
D.kill -9 1234
AnswerA

SIGTERM (15) requests orderly termination, letting the process release resources and exit cleanly — exactly the graceful first step the stem demands for PID 1234. Escalating straight to SIGKILL (9) would deny that cleanup, so `kill -15 1234` is the appropriate initial action before considering stronger signals.

Why this answer

Kill -15 1234. The SIGTERM signal (15) is the standard way to request a process terminate gracefully, allowing it to clean up resources, close files, and perform shutdown routines. This is the most appropriate first step before escalating to stronger signals, as it gives the process a chance to exit normally.

Exam trap

The trap here is that candidates often jump to kill -9 (SIGKILL) as the first solution when a process is unresponsive, but the LFCS exam emphasizes the principle of escalating signals gracefully, starting with SIGTERM.

How to eliminate wrong answers

Option B is wrong because kill -19 sends SIGSTOP, which pauses the process but does not terminate it; the process remains in memory and can be resumed with SIGCONT, so it does not stop the process gracefully. Option C is wrong because kill -2 sends SIGINT, which is typically used to interrupt a foreground process from the terminal (like Ctrl+C) and may not be effective for a background or daemon process that is unresponsive to normal shutdown requests. Option D is wrong because kill -9 sends SIGKILL, which forcefully terminates the process without allowing any cleanup; this should be a last resort after graceful methods fail, not the first attempt.

86
MCQmedium

A user needs to locate all regular files under /etc that are larger than 1 MB and have not been accessed in the last 30 days. Which command finds these files?

A.find /etc -type f -size +1M -mtime +30
B.locate /etc -type f -size +1M -atime +30
C.find /etc -type f -size 1M -atime 30
D.find /etc -type f -size +1M -atime +30
AnswerD

The find command with -type f limits results to regular files. The -size +1M matches files larger than 1 megabyte. The -atime +30 selects files whose last access time is more than 30 days ago. This combination precisely meets the requirement of locating large, infrequently accessed files under /etc.

Why this answer

The find command is the correct tool for complex file searches based on metadata. The -type f option restricts to regular files, -size +1M selects files larger than 1 MB, and -atime +30 identifies files not accessed in over 30 days. Together, these criteria match the administrator's needs exactly.

Exam trap

The trap here is confusing access time (-atime) with modification time (-mtime), or forgetting that find requires a plus sign to indicate 'greater than' for numeric comparisons.

87
MCQeasy

To display the first 10 lines of a file named 'log.txt', which command is correct?

A.less log.txt
B.tail log.txt
C.head log.txt
D.cat log.txt
AnswerC

head reads from the start of the file and, with no -n option, defaults to ten lines, printing them to standard output. That default exactly matches the stem's requirement to display the first 10 lines of log.txt.

Why this answer

The `head` command is designed to display the first 10 lines of a file by default. Running `head log.txt` outputs the first 10 lines of the file without any additional options, making it the correct choice for this task.

Exam trap

The trap here is that candidates often confuse `head` with `tail` or assume `less` or `cat` are appropriate for displaying only the first few lines, when in fact `head` is the specific command for that purpose.

How to eliminate wrong answers

Option A is wrong because `less` is a pager that displays the file interactively, allowing scrolling both forward and backward, but it does not default to showing only the first 10 lines; it shows the beginning of the file and waits for user input. Option B is wrong because `tail` displays the last 10 lines of a file by default, not the first 10 lines. Option D is wrong because `cat` outputs the entire contents of the file to the terminal, not just the first 10 lines.

88
MCQeasy

A system administrator wants to view the last 10 lines of the system log file '/var/log/syslog' and continue to watch for new lines as they are appended. Which command should be used?

A.tail -n 10 /var/log/syslog
B.less /var/log/syslog
C.tail -n 10 -f /var/log/syslog
D.head -n 10 /var/log/syslog
AnswerC

The -n 10 flag prints the final ten lines, and -f keeps the file descriptor open, streaming appended lines to standard output as they are written. This combination satisfies both viewing historical entries and live monitoring of /var/log/syslog in one command.

Why this answer

The `tail -n 10 -f /var/log/syslog` command first displays the last 10 lines of the file and then uses the `-f` (follow) flag to continuously monitor the file for new appended lines, outputting them in real time. This matches the requirement to both view the last 10 lines and watch for new entries.

Exam trap

The trap here is that candidates often confuse `tail -n 10` (static view) with `tail -f` (follow mode), or mistakenly think `less` with its Shift+F feature is the default answer, but the question explicitly requires a single command that both shows the last 10 lines and continuously watches for new lines.

How to eliminate wrong answers

Option A is wrong because `tail -n 10 /var/log/syslog` only shows the last 10 lines and then exits, without continuing to watch for new lines. Option B is wrong because `less /var/log/syslog` opens the file for interactive paging but does not automatically show only the last 10 lines or follow new appends without manual intervention (e.g., pressing Shift+F). Option D is wrong because `head -n 10 /var/log/syslog` shows the first 10 lines of the file, not the last 10, and does not follow new lines.

89
MCQeasy

A Linux server is configured with a custom systemd service unit for a backup script. After editing /etc/systemd/system/backup.service to add an EnvironmentFile directive, the administrator runs 'systemctl start backup' but systemctl status shows the unit still using the old environment. Which command should the administrator run to apply the unit file changes?

A.systemctl reenable backup
B.systemctl daemon-reload
C.systemctl restart backup
D.systemctl reload backup
AnswerB

systemd reads unit files into memory when it starts or when a unit is first loaded. After modifying a unit file, systemd must reload its configuration to pick up changes. Without daemon-reload, systemctl start uses the cached unit definition and ignores the new EnvironmentFile, so the service continues with the old environment.

Why this answer

After editing a systemd unit file, systemd continues using the previously loaded definition until it is told to reload. The daemon-reload subcommand makes systemd re-parse all unit files, applying changes such as new EnvironmentFile directives. Only then will a subsequent start or restart use the updated environment.

The other subcommands act on the running service or enablement state without refreshing the unit definition.

Exam trap

The trap here is assuming that restarting a service after editing its unit file is enough to apply the changes, when systemd must first reload its configuration.

90
Drag & Dropmedium

Order the steps to set up passwordless SSH key-based authentication.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Key generation, copying, and testing are essential; permissions and file verification ensure security.

91
MCQhard

A system administrator manages a database server service (database.service) that experiences periodic CPU spikes, causing excessive load on the server. The administrator wants to limit the service's CPU usage to 25% of a single CPU core. The service is running on a system with cgroup v2. Which directive should be added to the [Service] section of the unit file to achieve this?

A.CPUAccounting=true
B.CPUQuota=25%
C.CPUWeight=100
D.CPUShares=256
AnswerB

CPUQuota constrains aggregate CPU time within the cgroup v2 hierarchy, expressed as a percentage of one core. Setting CPUQuota=25% caps database.service at a quarter of a single CPU, directly limiting the spikes causing excessive load.

Why this answer

In cgroup v2, the `CPUQuota=` directive in a systemd unit file directly limits the CPU time a service can use, expressed as a percentage of a single CPU core. Setting `CPUQuota=25%` restricts the service to using at most 25% of one core, which matches the administrator's requirement to cap CPU usage at 25% of a single core.

Exam trap

The trap here is that candidates often confuse `CPUQuota=` (a hard limit) with `CPUWeight=` or `CPUShares=` (relative priority settings), mistakenly thinking a weight or share value can enforce a specific percentage cap on CPU usage.

How to eliminate wrong answers

Option A is wrong because `CPUAccounting=true` enables CPU usage accounting and statistics for the service, but it does not impose any limit on CPU usage; it only tracks and reports usage. Option C is wrong because `CPUWeight=100` sets the relative scheduling priority (weight) for the service in cgroup v2, which influences how CPU time is distributed among competing services but does not enforce a hard cap on CPU usage. Option D is wrong because `CPUShares=` is a cgroup v1 directive that provides relative CPU weight, not a hard limit; in cgroup v2, it is replaced by `CPUWeight=`, and neither option can enforce a specific percentage cap like 25%.

92
MCQmedium

A process is stuck in an uninterruptible sleep (D state) and cannot be killed. What is the most likely cause?

A.The process has been stopped by a signal
B.The process is waiting for a network response
C.The process is waiting for I/O from a failing disk
D.The process is waiting for CPU
AnswerC

D state means the process is blocked in an uninterruptible kernel wait, typically pending I/O completion. A failing disk never returns that I/O, so the process cannot be signalled or killed until the device responds or is reset.

Why this answer

A process in uninterruptible sleep (D state) is typically waiting for I/O from a block device, such as a disk. When a disk is failing or unresponsive, the kernel cannot complete the I/O request, and the process cannot be killed because doing so would risk data corruption or filesystem inconsistency. This state is a kernel-level wait that ignores signals, including SIGKILL.

Exam trap

Linux Foundation often tests the misconception that any 'stuck' process is due to network issues, but the D state specifically indicates block I/O, not network I/O, which uses interruptible sleep (S state).

How to eliminate wrong answers

Option A is wrong because a process stopped by a signal enters a T state (stopped), not D state; such processes can be resumed or killed. Option B is wrong because waiting for a network response typically results in interruptible sleep (S state), as network I/O can be interrupted by signals; D state is reserved for block I/O operations. Option D is wrong because waiting for CPU is represented by the R state (runnable) or S state (sleeping while waiting for CPU), not D state.

93
MCQmedium

A system administrator wants to display a list of all currently running processes with their parent process IDs. Which command is most appropriate?

A.pstree
B.jobs
C.top
D.ps -ef
AnswerD

`ps -ef` lists every running process with full details, including the PPID column, satisfying the requirement to show parent process IDs. The `-e` flag selects all processes system-wide, while `-f` produces the full-format listing containing UID, PID, PPID, C, STIME, TTY, TIME and CMD.

Why this answer

(ps -ef) is correct because the 'ps' command with the '-e' flag displays all processes, and the '-f' flag provides a full-format listing that includes the PPID (parent process ID) in the output. This directly meets the requirement to list all currently running processes with their parent process IDs.

Exam trap

The trap here is that candidates may confuse 'pstree' (which shows parent-child relationships visually) with 'ps -ef' (which lists numeric PPIDs), or assume 'top' is suitable for a static list, when the question specifically asks for a list with parent process IDs, not a tree or dynamic view.

How to eliminate wrong answers

Option A is wrong because pstree displays processes in a tree hierarchy showing parent-child relationships, but it does not show the numeric parent process ID (PPID) in its default output; it focuses on the tree structure rather than a list with PPIDs. Option B is wrong because the 'jobs' command lists only background jobs associated with the current shell session, not all running processes on the system. Option C is wrong because 'top' provides a dynamic, real-time view of running processes and can display PPID if configured, but it is not a static list command and does not output a simple list of all processes with their PPIDs by default.

94
MCQhard

A server has multiple IP aliases on eth0. Remote hosts cannot reach the secondary IP addresses. What should the administrator check?

A.The server's routing table includes routes for the secondary IPs' subnets.
B.The ARP flux settings are configured correctly.
C.The interface is set to NOARP.
D.The secondary IPs are in the same subnet as the primary.
AnswerB

ARP flux controls how the kernel replies to ARP requests across interfaces. With multiple IP aliases on eth0, incorrect arp_ignore or arp_announce settings cause replies to secondary addresses from the wrong interface, so remote hosts cannot reach them.

Why this answer

When multiple IP aliases are configured on a single Ethernet interface, the kernel may respond to ARP requests inconsistently, a behavior known as ARP flux. This causes remote hosts to receive conflicting MAC addresses for the secondary IPs, preventing connectivity. Correctly configuring ARP flux settings (e.g., using `arp_ignore=1` and `arp_announce=2` via sysctl) ensures the kernel responds only from the appropriate IP and advertises the correct MAC.

Exam trap

The trap here is that candidates assume secondary IPs must be in the same subnet as the primary (Option D) or that routing entries are needed (Option A), when the actual cause is the kernel's default ARP behavior, which is controlled by sysctl settings.

How to eliminate wrong answers

Option A is wrong because the routing table does not need routes for the secondary IPs' subnets; the secondary IPs are local to the interface, and the kernel handles them via local routing automatically. Option C is wrong because setting the interface to NOARP would disable ARP entirely, preventing any IP communication on that interface, not just secondary IPs. Option D is wrong because secondary IPs can be in a different subnet from the primary; the issue is ARP flux, not subnet matching.

95
MCQhard

A user reports that they cannot execute a file even though they are in the file's group. The file has permissions 644 and group ownership 'staff'. The user is a member of 'staff'. What is the likely issue?

A.The file lacks execute permission for the group
B.The file does not have the setgid bit
C.The user's primary group is not 'staff'
D.The user is not the owner of the file
AnswerA

Permissions 644 grant read and write to the owner, and read only to group and others; no execute bit is set for any class. Group membership is irrelevant because the group triad is r--. Adding execute for the group, giving 654 or 754, is required before a 'staff' member can run the file.

Why this answer

The file has permissions 644, which means the owner has read/write (6), the group has read-only (4), and others have read-only (4). Since the user is a member of the group 'staff' but not the owner, they fall under the group permission class. The group lacks execute permission (the 'x' bit), so the user cannot execute the file.

Execute permission is required to run a file as a command or script, regardless of group membership.

Exam trap

LFCS exams often test the distinction between file ownership and group membership, trapping candidates who think being in the group automatically grants execute permission without checking the actual permission bits.

How to eliminate wrong answers

Option B is wrong because the setgid bit is not required for executing a file; it affects the effective group ID during execution, not the ability to execute. Option C is wrong because the user's primary group does not matter for file access; being a member of the file's group ('staff') is sufficient to apply group permissions. Option D is wrong because ownership is not required for execution; group membership grants the group permissions, which in this case lack execute.

96
MCQmedium

A user 'dlee' reports that they cannot run 'sudo' commands despite being in the 'wheel' group. The /etc/sudoers file contains the line '%wheel ALL=(ALL) ALL'. What is the most likely cause?

A.The user has not logged out and back in after being added to the 'wheel' group.
B.The user's primary group is not 'wheel'.
C.The 'wheel' group does not exist on the system.
D.The sudoers file must be edited with visudo, otherwise changes are ignored.
AnswerA

Group membership changes do not apply to existing sessions. If 'dlee' was added to 'wheel' while logged in, the current session still has the old group set. Logging out and back in refreshes the group memberships, allowing sudo to recognize the new group. This is a common oversight.

Why this answer

The most common reason a user cannot use sudo after being added to a group is that the group membership change has not taken effect in their current session. Linux processes inherit group memberships at login, so a new login is required. After logging out and back in, the user's session will include the 'wheel' group, and sudo will grant access according to the sudoers rule.

Exam trap

The trap here is assuming that group changes apply immediately; they require a new login session.

97
Multi-Selecthard

A Linux server has a filesystem mounted at /data that is running out of space. The administrator needs to identify which directories under /data are consuming the most disk space and then safely remove old log files. Which two commands should the administrator use? (Choose two.)

Select 2 answers
A.df -h /data
B.du -sh /data/*
C.ls -lR /data | less
D.find /data -type f -name '*.log' -mtime +30 -delete
E.rm -rf /data/*
AnswersB, D

du -sh /data/* summarizes the disk usage of each immediate item under /data in human-readable form, quickly revealing which directories are largest. This directly addresses the need to identify space consumers without listing every file, making it efficient for locating the problematic directory.

Why this answer

To find which directories are using the most space, du -sh /data/* provides a per-directory summary. After identifying the culprit, find can precisely locate and delete old log files based on age, avoiding accidental removal of recent data. df only shows filesystem totals, ls -lR is too verbose, and rm -rf is destructive and indiscriminate.

Exam trap

The trap here is using df to try to find which directories are large, when df only reports filesystem-level usage, not directory breakdowns.

98
MCQhard

A server uses firewalld. Which command permanently allows HTTP traffic?

A.firewall-cmd --add-service=http
B.firewall-cmd --add-service=http --permanent
C.firewall-cmd --add-port=80/tcp
D.systemctl reload firewalld
AnswerB

The `--permanent` flag writes the HTTP service allowance into firewalld's persistent configuration, satisfying the stem's requirement that the change survive a reload or reboot. Without it, the rule would exist only in the runtime configuration and be lost. Running `firewall-cmd --reload` afterwards activates the saved rule.

Why this answer

The `--permanent` flag is required to make the rule persist across reboots when using `firewall-cmd`. Without it, the rule is only added to the runtime configuration and will be lost after a firewall reload or system restart. The `--add-service=http` parameter uses the predefined service definition for HTTP (port 80/tcp), which is the proper way to allow HTTP traffic in firewalld.

Exam trap

The trap here is that candidates often assume `firewall-cmd --add-service=http` alone is sufficient, forgetting that without `--permanent`, the rule is ephemeral and will be lost on reload or reboot.

How to eliminate wrong answers

Option A is wrong because it omits the `--permanent` flag, so the rule is applied only to the runtime configuration and will not survive a firewall reload or reboot. Option C is wrong because `--add-port=80/tcp` adds a direct port rule rather than using the predefined HTTP service; while it may work functionally, it bypasses firewalld's service abstraction and is not the standard method for allowing HTTP traffic. Option D is wrong because `systemctl reload firewalld` reloads the firewall configuration but does not add any rule; it would only apply permanent rules that were already added, not create a new rule.

99
MCQhard

A system has a process stuck in uninterruptible sleep (D state). The administrator wants to identify which kernel function it is waiting on. Which tool should be used?

A.cat /proc/PID/stack
B.gdb -p PID
C.perf top -p PID
D.strace -p PID
AnswerA

A task in D state is blocked inside a kernel call, and /proc/PID/stack exposes the kernel stack trace showing the exact function it sleeps in. Userspace tools such as ps or top only report the state, not the waiting function.

Why this answer

Reading /proc/PID/stack directly shows the kernel stack trace of the process, revealing the exact kernel function or wait queue the process is blocked on while in uninterruptible sleep (D state). This is the only tool listed that can inspect the kernel-side call stack without attaching a debugger or altering process state.

Exam trap

The trap here is that candidates often confuse strace (user-space syscall tracing) with kernel stack inspection, assuming strace can show kernel internals, but strace only traces syscall entry/exit and cannot reveal the internal kernel function where the process is blocked.

How to eliminate wrong answers

Option B (gdb -p PID) is wrong because gdb attaches to a user-space process and inspects user-space memory and registers; it cannot access the kernel stack or show which kernel function caused the D state. Option C (perf top -p PID) is wrong because perf top samples performance counters and shows hot functions in user and kernel space, but it does not display the current blocked stack trace for a process in D state. Option D (strace -p PID) is wrong because strace traces system calls, but a process in uninterruptible sleep is already inside a kernel function and not making new system calls; strace will hang or show no output.

100
MCQmedium

A large company needs to create 100 user accounts from a list of names in a CSV file. Which tool is most efficient for batch user creation?

A.vipw
B.for loop with useradd
C.newusers
D.pwconv
AnswerC

`newusers` reads a plain-text file of colon-separated records and creates each account in one pass, satisfying the CSV batch requirement without scripting loops. It also sets passwords from the same file, unlike `useradd`, which handles a single account per invocation and would need 100 separate calls.

Why this answer

The `newusers` command is the most efficient tool for batch user creation because it reads a file in a specific format (username:password:UID:GID:comment:home_directory:shell) and can create multiple user accounts in a single pass, automatically handling password hashing and home directory creation. This avoids the overhead of scripting loops and multiple `useradd` invocations, making it ideal for bulk operations like creating 100 accounts from a CSV list.

Exam trap

The trap here is that candidates may think a `for loop with useradd` is the most flexible approach, but the LFCS exam emphasizes efficiency and built-in tools, making `newusers` the correct choice for batch operations over scripting a loop.

How to eliminate wrong answers

Option A is wrong because `vipw` is used to safely edit the /etc/passwd file with locking, not for batch user creation; it requires manual entry of each user line and does not automate account setup. Option B is wrong because while a `for loop with useradd` can technically create multiple users, it is less efficient than `newusers` as it requires separate shell calls for each user, lacks built-in batch password handling, and is more error-prone when processing a CSV file. Option D is wrong because `pwconv` is used to convert passwords to shadow passwords (creating /etc/shadow from /etc/passwd), not for creating user accounts.

101
MCQeasy

A junior administrator needs to mount an ISO image located at /opt/images/install.iso to the directory /mnt/iso without burning it to a physical disc. Which command should be used?

A.losetup /dev/loop0 /opt/images/install.iso && mount /dev/loop0 /mnt/iso
B.mount --bind /opt/images/install.iso /mnt/iso
C.mount -o loop /opt/images/install.iso /mnt/iso
D.mount -t iso9660 /opt/images/install.iso /mnt/iso
AnswerC

The loop option tells mount to associate the ISO file with a loop device, making it accessible as a block device, and then mount it at the specified directory. This is the standard method for accessing ISO images without physical media. The directory /mnt/iso must already exist before running the command.

Why this answer

Mounting an ISO file requires the loop option so the kernel can treat the file as a block device and read its ISO9660 filesystem. The mount -o loop command is the simplest and most common way to achieve this. Alternatives like specifying only the filesystem type or using a bind mount do not correctly expose the ISO's contents.

Exam trap

The trap here is thinking that specifying the iso9660 filesystem type is sufficient to mount an ISO file, when the loop option is the critical piece that associates the file with a loop device.

102
MCQhard

An administrator is preparing a new server that will use software RAID 1 for the root filesystem. The system has two identical 500 GB disks, /dev/sda and /dev/sdb. The administrator wants to create the RAID array and then place LVM on top of it. Which command correctly creates the RAID 1 array using the entire disks?

A.mdadm --create /dev/md0 --level=0 --raid-devices=2 /dev/sda /dev/sdb
B.mdadm --assemble /dev/md0 /dev/sda /dev/sdb
C.mdadm --create /dev/md0 --level=1 --raid-devices=2 /dev/sda1 /dev/sdb1
D.mdadm --create /dev/md0 --level=1 --raid-devices=2 /dev/sda /dev/sdb
AnswerD

mdadm --create with --level=1 and --raid-devices=2 creates a RAID 1 array named /dev/md0 using the two specified disks. This is the correct syntax to initialize a mirrored array on whole disks. After creation, the administrator can create LVM physical volumes on /dev/md0 and proceed with volume group and logical volume setup.

Why this answer

Creating a RAID 1 array on whole disks requires mdadm --create with --level=1 and --raid-devices=2, followed by the device paths. RAID 1 provides mirroring for redundancy. Using --level=0 would create a stripe with no redundancy, and --assemble is only for activating existing arrays.

The correct device paths are the whole disks, not partitions.

Exam trap

The trap here is mixing up mdadm --create with mdadm --assemble, or specifying the wrong RAID level for the required redundancy.

103
MCQeasy

A system administrator wants to view the current runtime status of the sshd.service, including whether it is active, its main PID, and recent log entries. Which command should they use?

A.systemctl show sshd.service
B.systemctl status sshd.service
C.journalctl -u sshd.service -f
D.systemctl list-units --type=service | grep sshd
AnswerB

systemctl status sshd.service displays the current state of the service, including whether it is active, the main PID, and the most recent log lines. This directly provides the runtime status and recent logs as requested. It is the standard command for checking a service's health and recent activity in systemd.

Why this answer

systemctl status sshd.service is the correct command because it provides a concise overview of the service's current state, including active/inactive, main PID, and the last few log lines. It combines status and recent logs in one output, exactly matching the administrator's need. Other commands either only show logs or only list units without detailed status.

Exam trap

The trap here is thinking that journalctl -u sshd.service -f shows the current status, when it only follows logs and does not display the service state.

104
MCQeasy

A junior administrator issued the command 'usermod -L alice' to lock the account of user alice. However, alice is still able to log in via SSH using a public key. What is the most likely reason?

A.The usermod -L command only locks the password but does not prevent SSH key-based authentication.
B.The usermod -L command only changes the user's shell to /sbin/nologin.
C.The usermod -L command requires a restart of the SSH service to take effect.
D.The usermod -L command is not effective on accounts with a UID less than 1000.
AnswerA

The usermod -L flag prepends an exclamation mark to the encrypted password field in /etc/shadow, disabling password authentication only. SSH public key authentication bypasses that field entirely, so alice's authorised_keys entry still grants access. Locking the account fully requires expiring it or removing the key.

Why this answer

The `usermod -L` command locks the user's password by placing an exclamation mark (!) in the second field of the /etc/shadow file, which prevents password-based authentication. However, SSH public key authentication does not rely on the password field; it uses the authorized_keys file and the SSH daemon's public key challenge-response mechanism. Therefore, even with a locked password, the user can still log in via SSH if their public key is present in ~/.ssh/authorized_keys.

Exam trap

The trap here is that candidates assume `usermod -L` disables all authentication methods, but it only affects password-based authentication, not SSH public key or other key-based mechanisms.

How to eliminate wrong answers

Option B is wrong because `usermod -L` does not change the user's shell; it only locks the password. Changing the shell to /sbin/nologin is done with `usermod -s /sbin/nologin` or `chsh`. Option C is wrong because `usermod -L` takes effect immediately on the password database; no SSH service restart is required, as SSH checks the password status at each authentication attempt.

Option D is wrong because `usermod -L` works on any user account regardless of UID; there is no UID threshold for password locking, and the command affects all users with entries in /etc/shadow.

105
MCQhard

Given the routing table, if the server sends a packet to destination 10.0.1.200, which interface will be used and what is the next hop?

A.eth1 via 10.0.1.1
B.eth1 directly to 10.0.1.200
C.eth0 with next hop 10.0.0.1
D.eth0 with next hop 10.0.1.200
AnswerB

The routing table contains a route for 10.0.1.0/24 reachable via eth1 with no gateway, meaning the destination is on-link. The kernel therefore resolves 10.0.1.200 directly through eth1, sending the frame to that host rather than to a next-hop router.

Why this answer

The destination 10.0.1.200 falls within the directly connected network 10.0.1.0/24 on eth1. According to the routing table, this route has a /24 netmask and is marked as directly connected, meaning no next-hop router is needed. The server will ARP for 10.0.1.200 and send the packet directly to that host via eth1.

Exam trap

The trap here is that candidates often assume all traffic must go through a gateway (next hop), forgetting that directly connected routes allow direct delivery without a router, leading them to pick Option A or C.

How to eliminate wrong answers

Option A is wrong because it incorrectly specifies a next-hop gateway (10.0.1.1) for a directly connected network; when the destination is on the same subnet, the packet is sent directly, not via a router. Option C is wrong because eth0 is associated with the 10.0.0.0/24 network, and 10.0.1.200 is not within that subnet; the routing table would not use eth0 for this destination. Option D is wrong because eth0 is not the correct interface for the 10.0.1.0/24 network, and even if it were, a directly connected route does not use a next-hop IP; the packet would be sent directly to the destination MAC.

106
MCQhard

A Linux server uses systemd-resolved for DNS resolution. Users report that queries for internal hostnames such as 'db.corp.example.com' are failing, while external names resolve correctly. The administrator runs 'resolvectl status' and sees that the interface eth0 has DNS servers 10.0.0.53 and 'DNS Domain: corp.example.com'. Which command should be used to query the internal DNS server directly and verify that it responds to the name?

A.resolvectl query db.corp.example.com
B.dig @10.0.0.53 db.corp.example.com
C.nslookup db.corp.example.com 10.0.0.53
D.systemd-resolve --status
AnswerB

This command sends a DNS query directly to the internal DNS server at 10.0.0.53, bypassing systemd-resolved. It verifies whether that specific server can resolve the hostname, isolating the problem to either the server or the local resolver configuration. If the server responds correctly, the issue is likely with systemd-resolved's routing or caching; if it fails, the DNS server itself is the problem.

Why this answer

To verify that the internal DNS server at 10.0.0.53 can resolve the hostname, the administrator should query it directly with 'dig @10.0.0.53 db.corp.example.com'. This bypasses systemd-resolved and tests the server's response. If the server answers correctly, the problem lies in systemd-resolved's configuration, such as a missing routing domain or incorrect DNS server assignment for the interface.

Exam trap

The trap here is using resolvectl query, which goes through systemd-resolved and may reproduce the same failure, instead of querying the DNS server directly to isolate the issue.

107
MCQeasy

A system administrator notices that the disk space on the root filesystem is at 95% usage. After investigating, they find that a large log file named 'access.log' in /var/log is taking up significant space. The administrator deletes the file using 'rm /var/log/access.log' but the disk usage remains at 95%. Running 'df -h' still shows the same usage. What is the most likely cause and the correct next step?

A.The file is compressed and needs to be decompressed. Use 'gzip -d access.log' first.
B.The filesystem is marked as full in the superblock. Use 'fsck' to repair the filesystem.
C.The file is still open by a process. Use 'lsof | grep access.log' to identify the process and restart it.
D.The file has multiple hard links. Use 'find / -links +1' to locate all hard links and delete them.
AnswerC

Deleting a file only unlinks its directory entry; the inode and its blocks persist while a process holds the descriptor open, so df still reports the space. lsof identifies that holding process, and restarting it releases the descriptor, reclaiming the space.

Why this answer

When a file is deleted with 'rm' while it is still open by a running process, the file's directory entry is removed, but the inode and data blocks remain allocated until the process closes the file descriptor. This causes 'df' to still report the space as used. The correct next step is to use 'lsof' to find the process holding the file open and restart it, which releases the file descriptor and frees the disk space.

Exam trap

The trap here is that candidates assume 'rm' immediately frees disk space, but they overlook that open file descriptors by running processes (e.g., syslog, Apache) keep the data blocks allocated until the process is restarted or the descriptor is closed.

How to eliminate wrong answers

Option A is wrong because the file was already deleted, not compressed; 'gzip -d' would fail on a removed file and does not address the open file handle issue. Option B is wrong because the filesystem is not marked as full in the superblock; 'fsck' repairs filesystem metadata corruption, not space accounting for open deleted files. Option D is wrong because hard links would cause the file to still exist under another name, but 'rm' would only remove one link; however, 'df' would show freed space only after all links are removed, but the question states the file was deleted and space remains, which points to an open file descriptor, not multiple hard links.

108
MCQhard

A system administrator cannot restart a service because another unit 'stop' the request. The status message says 'Unit test.service is not running, but has pending stop job'. What is the most likely cause?

A.The service unit file has RefuseManualStop=yes
B.The service has a dependency that is stopping
C.A previous stop command is still being processed
D.The service is masked
AnswerC

A pending stop job means systemd has queued the stop operation but the unit has not yet reached an inactive state, so a restart request is refused until that job completes. This directly matches the "pending stop job" status, indicating the earlier stop command is still being processed.

Why this answer

The message 'Unit test.service is not running, but has pending stop job' indicates that systemd has queued a stop operation for the service, but the stop job has not yet completed. This typically happens when a previous 'systemctl stop' command was issued but the service's stop process (e.g., ExecStop script) is still running or hanging. Until that job finishes, any attempt to restart the service will be blocked because systemd serializes jobs for the same unit.

Exam trap

The trap here is that candidates confuse 'pending stop job' with a configuration error like masking or manual-stop refusal, when in fact it is a transient state caused by an incomplete stop operation.

How to eliminate wrong answers

Option A is wrong because RefuseManualStop=yes prevents manual stop commands entirely, but the status shows a stop job is pending, meaning a stop was initiated; RefuseManualStop would have rejected the stop request outright, not left it pending. Option B is wrong because a dependency stopping would affect the dependent unit's state, but the error message specifically refers to a pending stop job on test.service itself, not on a dependency. Option D is wrong because a masked service cannot be started or stopped at all; its unit file is symlinked to /dev/null, and attempting to stop it would fail immediately with a different error, not a pending stop job.

109
Drag & Dropmedium

Order the steps to set up a LVM logical volume from a new disk.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for setting up an LVM logical volume from a new disk is: first create a physical volume (PV) using pvcreate, then create a volume group (VG) with vgcreate, then create a logical volume (LV) with lvcreate, then format the LV with a filesystem using mkfs, and finally mount it to a directory. This order ensures all dependencies are satisfied: the VG requires the PV, the LV requires the VG, and the filesystem requires the LV.

110
MCQhard

An administrator has a volume group vg_data with 50 GB of free extents. The logical volume /dev/vg_data/lv_archive is 200 GB and must grow to 350 GB. The administrator runs lvextend -L +150G /dev/vg_data/lv_archive and it fails. Which is the most likely cause?

A.The volume group does not have enough free extents to satisfy the 150 GB request.
B.The logical volume is formatted with XFS, which cannot be extended with lvextend.
C.The +150G syntax is invalid and should be --size 150G instead.
D.The filesystem must be unmounted before any logical volume can be extended.
AnswerA

lvextend can only allocate from unallocated physical extents in the volume group. With just 50 GB free, a request for 150 GB of additional space cannot be satisfied, so the command fails before any resizing occurs. The administrator must first add a physical volume with vgextend.

Why this answer

lvextend allocates physical extents from the volume group's free pool. With only 50 GB free, a 150 GB growth request cannot be met, so the command exits with an error before touching the logical volume. The fix is to add capacity to vg_data, for example by creating a physical volume on a new disk and running vgextend, then repeating the lvextend.

Exam trap

The trap here is blaming the filesystem or the syntax when the real constraint is simply free space in the volume group.

111
MCQeasy

A system administrator needs to identify the absolute path of the executable that would be run when typing the command 'ls'. Which command should they use?

A.find / -name ls
B.whereis ls
C.which ls
D.locate ls
AnswerC

The which command searches the directories listed in the PATH environment variable and displays the full path of the executable that would be executed. It is the standard tool for locating a command's binary in the user's path.

Why this answer

The which command is designed to search the PATH and report the full path of the executable that would be run. whereis, locate, and find do not respect the PATH or executable resolution order, so they cannot reliably answer which binary would execute. Thus, which is the correct choice.

Exam trap

The trap here is assuming that any file-finding command can determine which executable runs, when only which considers the PATH and execution order.

112
MCQeasy

A junior administrator created a user account with the command `useradd -m devuser`. The account was created without a password, and the administrator now wants to set an initial password so the user can log in. Which command should the administrator use to assign a password to the account?

A.usermod -p devuser
B.passwd devuser
C.chage -p devuser
D.useradd -p devuser
AnswerB

The passwd command with a username argument sets or changes that account's password when run by root. It prompts for the new password twice and writes the resulting hash to /etc/shadow. This is the standard, supported way to give a newly created account its first password, and it also updates the last-change field used by password aging.

Why this answer

Assigning an initial password to an existing account is done with passwd followed by the username when executed as root. That command prompts interactively for the new secret, hashes it, and writes it to /etc/shadow, immediately enabling authentication. The other commands either expect a pre-hashed string, manage unrelated metadata, or apply only during account creation, so none of them sets a usable password here.

Exam trap

The trap here is assuming that usermod -p or useradd -p accepts a plaintext password, when both actually require an already-encrypted hash string from crypt or openssl passwd.

113
MCQmedium

A system administrator configures a web server using systemd. After creating a custom service unit file, the administrator runs `systemctl daemon-reload` but the service still fails to start with a 'Unit not found' error. What is the most likely cause?

A.The administrator forgot to run `systemctl enable` before starting the service.
B.The unit file is placed in /usr/lib/systemd/system/ instead of /etc/systemd/system/.
C.The administrator is not in the 'systemd' group.
D.The service name was misspelled in the `systemctl start` command.
AnswerD

systemd resolves units by exact filename, so a typographical error in the unit name passed to systemctl start yields 'Unit not found' even after daemon-reload succeeds. Verifying the spelling against the unit file in /etc/systemd/system corrects the invocation.

Why this answer

The 'Unit not found' error after `systemctl daemon-reload` typically indicates that systemd cannot locate a unit with the specified name. While correct placement of unit files is important, systemd scans both /etc/systemd/system/ and /usr/lib/systemd/system/ after a daemon-reload. Therefore, placing a custom unit in /usr/lib/systemd/system/ would not cause this error.

The most likely cause is that the service name was misspelled in the `systemctl start` command. A simple typo would lead to a 'Unit not found' message because systemd looks for an exact match. Other options like forgetting `systemctl enable` or group membership do not affect unit discovery at start time.

Exam trap

Candidates often overthink the directory paths and forget that a simple typo in the service name is the most common cause of 'Unit not found' errors. The trap is focusing on file placement rather than the exact command used to start the service.

How to eliminate wrong answers

Option A is wrong because `systemctl enable` creates symlinks for automatic startup but is not required to start a service; `systemctl start` can start a service without enabling it. Option C is wrong because there is no 'systemd' group in standard Linux; systemd operations are controlled by user privileges (root or sudo) and polkit rules, not group membership. Option D is wrong because while a misspelled service name would cause a 'Unit not found' error, the question states the administrator created a custom unit file and ran `daemon-reload`, making the file location the more likely and fundamental issue.

114
Multi-Selecthard

Which THREE of the following are valid systemd unit types?

Select 3 answers
A.notification
B.startup
C.target
D.socket
E.service
AnswersC, D, E

A target unit groups other units into a synchronisation point, replacing SysV runlevels during boot. It satisfies the stem's requirement for a valid systemd unit type, since systemd recognises targets natively alongside service, socket, device, mount, automount, swap, timer, path, slice and scope units.

Why this answer

Option C (target) is a valid systemd unit type: targets group other units and synchronize boot, replacing SysV runlevels (e.g., multi-user.target). Option D (socket) is valid: socket units describe an IPC or network socket that systemd listens on and activates the corresponding service via socket activation. Option E (service) is valid: service units define and control daemons or oneshot processes managed by systemd (e.g., sshd.service).

Options A (notification) and B (startup) are not systemd unit types; notification is not a unit type at all, and startup is not a recognized unit suffix, whereas real types include service, socket, target, device, mount, automount, swap, timer, path, slice, and scope.

Exam trap

The trap here is that candidates may confuse systemd unit types with service configuration directives (like Type=notify) or with generic terms like 'startup', leading them to select invalid options that sound plausible but are not defined in systemd's unit type specification.

115
MCQmedium

A Linux server uses LVM for its data volume /dev/vg_data/lv_app. The volume group vg_data has 30 GB of free extents and the logical volume lv_app is currently 100 GB. An administrator runs `lvextend -L +20G /dev/vg_data/lv_app` and receives a success message, but `df -h /app` still reports 100 GB. The filesystem on lv_app is ext4. Which command must the administrator run next to make the additional space usable?

A.e2fsck -f /dev/vg_data/lv_app
B.resize2fs /dev/vg_data/lv_app
C.xfs_growfs /app
D.pvresize /dev/vg_data/lv_app
AnswerB

The ext4 filesystem must be grown to match the enlarged block device; resize2fs performs that online growth without unmounting. lvextend only resizes the logical volume, so df still reports the old filesystem size until resize2fs runs. This is the standard two-step procedure for ext4 on LVM without the -r shortcut.

Why this answer

Extending an LVM logical volume with lvextend changes only the block device mapping; the ext4 filesystem inside keeps its original size until resized. Running resize2fs against the LV path grows the filesystem online to fill the new extents, after which df reflects the additional capacity. The XFS-only grow tool, a consistency checker, and a PV-level resize command all fail to accomplish this here.

Exam trap

The trap here is assuming lvextend also resizes the filesystem, when in fact the filesystem must be grown separately for ext4.

116
MCQmedium

A Linux server cannot reach the internet, but internal LAN connectivity works. The output of 'ip route' shows a default gateway of 192.168.1.1, but pinging 8.8.8.8 fails. What is the most likely cause?

A.The default gateway is not reachable or has no internet connectivity.
B.The ARP table is corrupted.
C.The default gateway is missing.
D.DNS resolution is failing.
AnswerA

LAN connectivity proves the interface and local routing work, while a failed ping to 8.8.8.8 indicates the default route's next hop cannot forward traffic. The gateway at 192.168.1.1 is either unreachable or lacks upstream internet connectivity.

Why this answer

The default gateway 192.168.1.1 is present in the routing table, but pinging 8.8.8.8 fails while internal LAN connectivity works. This indicates that the gateway itself either cannot be reached (e.g., due to a layer 2 issue or misconfiguration) or, more likely, it has no upstream internet connectivity. Since the default route is configured, the failure is not due to a missing gateway but rather the gateway's inability to forward traffic to external networks.

Exam trap

The trap here is that candidates often assume a missing default gateway is the problem when they see internet failure, but the question explicitly states the default gateway is present, shifting the focus to the gateway's own connectivity rather than the local routing table.

How to eliminate wrong answers

Option B is wrong because a corrupted ARP table would prevent communication with any host on the local subnet, including the default gateway, causing internal LAN connectivity to fail as well; since internal connectivity works, ARP is functioning correctly. Option C is wrong because the 'ip route' output explicitly shows a default gateway of 192.168.1.1, so the default gateway is not missing. Option D is wrong because DNS resolution is irrelevant when pinging a raw IP address like 8.8.8.8; the failure occurs at the network layer, not at the application layer.

117
MCQmedium

A system administrator is managing a RHEL 8 server that requires a static IP address on interface ens192. The administrator modifies /etc/sysconfig/network-scripts/ifcfg-ens192 to set BOOTPROTO=static, IPADDR=192.168.1.100, PREFIX=24, GATEWAY=192.168.1.1, and DNS1=8.8.8.8. After saving, the administrator runs 'systemctl restart NetworkManager'. The interface obtains the correct static IP and network connectivity works. However, after a reboot of the server, the interface fails to come up with the static IP and instead obtains an IP via DHCP from the local network. The administrator verifies that the DHCP server is active and that the physical connection is good. What is the most likely cause of the issue?

A.The kernel parameter nomodeset is set in /etc/default/grub.
B.The firewall is blocking the static IP assignment.
C.The ONBOOT parameter is set to no or missing in the configuration file.
D.The network service is not enabled to start at boot.
AnswerC

ONBOOT=yes is required for the interface to start at boot.

Why this answer

The ONBOOT parameter controls whether the interface is activated at system boot. If set to 'no' or missing entirely, NetworkManager will not bring up the interface automatically after a reboot, causing it to fall back to DHCP if a DHCP client is active. Setting BOOTPROTO=static and IPADDR correctly only takes effect when ONBOOT=yes is present.

Exam trap

The trap here is that candidates assume setting BOOTPROTO=static and IPADDR is sufficient, overlooking the mandatory ONBOOT=yes parameter required for automatic activation at boot.

How to eliminate wrong answers

Option A is wrong because the kernel parameter 'nomodeset' affects video driver initialization, not network interface configuration or static IP assignment. Option B is wrong because the firewall operates at Layer 3/4 and does not block the assignment of a static IP address to an interface; it filters traffic after the IP is assigned. Option D is wrong because the 'network' service is deprecated in RHEL 8 and replaced by NetworkManager, which is enabled by default; the issue is not about the service being disabled but about the per-interface ONBOOT setting.

118
MCQmedium

A Linux administrator wants to view the current resource limits (such as CPU and memory) applied to a running systemd service named database.service. Which command will display these limits?

A.systemctl show database.service
B.systemctl cat database.service
C.systemctl status database.service
D.systemctl list-dependencies database.service
AnswerA

systemctl show displays all properties of a unit, including resource control settings like CPUQuota, MemoryLimit, and others. This command provides a comprehensive view of the service's current configuration, including limits, without needing to inspect the unit file.

Why this answer

To view the effective resource limits of a running service, systemctl show is the appropriate command. It outputs all properties, including CPUQuota, MemoryLimit, and other cgroup-related settings. systemctl status and cat do not show the current effective limits, and list-dependencies is unrelated.

Exam trap

The trap here is assuming that systemctl status or systemctl cat will display resource limits, when in fact only systemctl show provides the full set of runtime properties.

119
MCQmedium

Which bonding mode provides high availability without requiring switch configuration?

A.mode 1 (active-backup)
B.mode 4 (802.3ad)
C.mode 6 (balance-alb)
D.mode 0 (balance-rr)
AnswerA

Mode 1 (active-backup) keeps one slave active while others stand by, failing over without any switch-side link aggregation. Because it uses no LACP or static EtherChannel, it delivers high availability with zero switch configuration, satisfying the stem's constraint.

Why this answer

Mode 1 (active-backup) provides high availability by designating one NIC as active and the others as standby, with automatic failover if the active link fails. It requires no special switch configuration because it does not use any link aggregation protocol or load-balancing algorithm that depends on switch-side settings.

Exam trap

The trap here is that candidates often confuse 'high availability' with 'load balancing' and choose mode 0 or mode 4, not realizing that those modes require switch configuration or do not inherently provide failover without additional setup.

How to eliminate wrong answers

Option B is wrong because mode 4 (802.3ad) requires the switch to be configured with a matching LACP (Link Aggregation Control Protocol) port channel. Option C is wrong because mode 6 (balance-alb) requires the switch to accept packets from multiple MAC addresses on the same port, which may need switch-side ARP filtering or port security adjustments. Option D is wrong because mode 0 (balance-rr) requires the switch to support Ethernet bonding (e.g., static link aggregation) and typically needs switch configuration to treat the multiple links as a single logical link.

120
MCQhard

A system administrator needs to securely transfer files between two Linux servers using port 22. The administrator uses the following command: 'scp file.txt user@remote:/tmp/'. The transfer fails with the error 'Permission denied (publickey)'. What is the most likely cause?

A.The client's public key is not in the remote user's authorized_keys file.
B.The remote server does not have SSH installed.
C.The SSH service is not running on the remote server.
D.The remote server's firewall is blocking port 22.
AnswerA

Port 22 confirms SSH is reachable, so the failure is authentication. Public-key authentication requires the client's public key to appear in the remote user's authorized_keys file; without that entry the server rejects the key and returns Permission denied (publickey).

Why this answer

The error 'Permission denied (publickey)' indicates that the SSH key-based authentication failed. SCP uses SSH for transport, and by default, SSH on the remote server checks the client's public key against the remote user's ~/.ssh/authorized_keys file. If the client's public key is not listed there, the SSH server rejects the connection, causing the SCP transfer to fail.

Exam trap

The trap here is that candidates often confuse network-level issues (firewall, service status) with authentication-level errors, but the specific 'Permission denied (publickey)' message directly points to SSH key authentication failure, not connectivity or service availability.

How to eliminate wrong answers

Option B is wrong because if the remote server did not have SSH installed, the error would typically be 'Connection refused' or 'No route to host', not 'Permission denied (publickey)'. Option C is wrong because if the SSH service were not running, the client would receive a 'Connection refused' error, not a publickey authentication failure. Option D is wrong because if the remote server's firewall were blocking port 22, the client would see a timeout or 'Connection refused' error, not a publickey permission error.

121
MCQhard

A company's database server uses LVM for storage. The system administrator notices that the logical volume /dev/vg_db/lv_data is at 95% capacity. The server is in production and cannot be taken offline. The volume group vg_db has free physical extents. Which command sequence should the administrator use to safely increase the size of the logical volume and filesystem without unmounting?

A.lvextend /dev/vg_db/lv_data /dev/sdb; resize2fs /dev/vg_db/lv_data
B.lvresize -L +10G /dev/vg_db/lv_data; mkfs.ext4 /dev/vg_db/lv_data
C.lvextend -L +10G /dev/vg_db/lv_data; mount -o remount /dev/vg_db/lv_data
D.lvextend -L +10G /dev/vg_db/lv_data; resize2fs /dev/vg_db/lv_data
AnswerD

Extending the logical volume with lvextend consumes free physical extents in vg_db, then resize2fs grows the ext2/3/4 filesystem online, satisfying the no-unmount constraint. This pairing works only because the filesystem is ext-based; XFS would instead require xfs_growfs.

Why this answer

It first extends the logical volume using `lvextend -L +10G` to allocate additional physical extents from the volume group, then resizes the ext4 filesystem online with `resize2fs` to utilize the new space. Both operations can be performed without unmounting the filesystem, as ext4 supports online resizing and LVM allows live extension of logical volumes.

Exam trap

The trap here is that candidates may think `mount -o remount` resizes the filesystem or that `mkfs.ext4` can be used to expand an existing filesystem, when in fact a filesystem-specific resize command is required after extending the logical volume.

How to eliminate wrong answers

Option A is wrong because it specifies a physical volume (`/dev/sdb`) instead of a size increment, which would attempt to use the entire device rather than adding a specific amount of space, and the syntax is incorrect for extending by a size. Option B is wrong because `mkfs.ext4` would create a new filesystem, destroying existing data, and does not resize the current filesystem. Option C is wrong because `mount -o remount` only re-mounts the filesystem and does not resize it; the filesystem must be explicitly resized with `resize2fs` after extending the logical volume.

122
MCQmedium

A Linux server is configured to boot into a graphical target, but after a recent kernel update, the system hangs at a black screen after the GRUB menu. You can still access a rescue shell via the installation media. Which command should you use to make the system boot into a multi-user text target by default, allowing you to troubleshoot?

A.systemctl isolate multi-user.target
B.grub2-mkconfig -o /boot/grub2/grub.cfg
C.systemctl set-default multi-user.target
D.systemctl enable multi-user.target
AnswerC

This command sets the default boot target to multi-user.target, which starts a text-based multi-user environment without a graphical display manager. It is the correct approach to bypass the graphical target and gain a usable console for troubleshooting. The change is persistent and can be reverted once the issue is resolved.

Why this answer

The default systemd target is managed via the default.target symbolic link. To change it persistently, the systemctl set-default command is used. Setting it to multi-user.target ensures the system boots to a text console, allowing the administrator to diagnose the graphical failure.

This is the standard method for altering the default runlevel equivalent in systemd-based distributions.

Exam trap

The trap here is confusing systemctl isolate (runtime change) with systemctl set-default (persistent change).

123
MCQeasy

A system administrator wants to combine two network interfaces for increased throughput and fault tolerance. The requirement is that both links are active simultaneously and the system can tolerate a failure of one link without interruption. Which bonding mode should be used?

A.Mode 4 (802.3ad)
B.Mode 2 (balance-xor)
C.Mode 1 (active-backup)
D.Mode 0 (balance-rr)
AnswerA

Mode 4 (802.3ad) is correct because it implements IEEE 802.3ad Link Aggregation Control Protocol (LACP), which allows both links to be active simultaneously for increased throughput while providing fault tolerance. If one link fails, traffic is automatically redistributed across the remaining active links without interruption, meeting the requirement.

Why this answer

Mode 4 (802.3ad) is correct because it implements IEEE 802.3ad Link Aggregation Control Protocol (LACP), which allows both links to be active simultaneously for increased throughput while providing fault tolerance. If one link fails, traffic is automatically redistributed across the remaining active links without interruption, meeting the requirement for both active links and failure tolerance.

Exam trap

The trap here is that candidates often confuse Mode 4 (802.3ad) with Mode 0 (balance-rr) because both allow active links, but Mode 0 lacks the standardized LACP negotiation and seamless failover that Mode 4 provides, leading to incorrect selection when fault tolerance is explicitly required.

How to eliminate wrong answers

Option B (Mode 2, balance-xor) is wrong because while it allows both links to be active, it does not provide fault tolerance without interruption—a link failure may cause traffic disruption until the bonding driver rebalances. Option C (Mode 1, active-backup) is wrong because it uses only one active link at a time, failing the requirement for both links to be active simultaneously. Option D (Mode 0, balance-rr) is wrong because although both links are active, it does not support 802.3ad negotiation and may cause out-of-order packet delivery, and it does not guarantee seamless failover without interruption.

124
MCQhard

An administrator configures a systemd service with Restart=on-failure and RestartSec=10. What happens if the service exits with a non-zero exit code?

A.It restarts immediately
B.It retries infinitely regardless of exit code
C.It does not restart
D.It waits 10 seconds before restarting
AnswerD

Restart=on-failure triggers a restart whenever the process exits non-zero, and RestartSec=10 inserts a ten-second delay before systemd attempts that restart. This satisfies the stem's non-zero exit condition while honouring the configured interval, so the unit is relaunched after the pause rather than immediately.

Why this answer

When Restart=on-failure is set, systemd only restarts the service if it exits with a non-zero exit code or is terminated by a signal (excluding SIGHUP, SIGINT, SIGTERM, and SIGPIPE). The RestartSec=10 directive then introduces a 10-second delay before the restart attempt, preventing rapid restart loops and giving the system time to stabilize.

Exam trap

The trap here is that candidates often confuse Restart=on-failure with Restart=always, assuming any exit triggers a restart, or they forget that RestartSec applies even when Restart=on-failure is set, leading them to choose 'immediately' (Option A).

How to eliminate wrong answers

Option A is wrong because RestartSec=10 explicitly adds a 10-second delay; the service does not restart immediately. Option B is wrong because Restart=on-failure does not cause infinite retries for any exit code — it only triggers restarts on non-zero exit codes or certain signals, and the number of restart attempts is limited by StartLimitBurst and StartLimitInterval (default 5 attempts within 10 seconds). Option C is wrong because the service does restart on a non-zero exit code when Restart=on-failure is configured; it only does not restart if the exit code is zero.

125
MCQmedium

A system administrator notices that a web server is not reachable from the internet but is reachable from the internal network. The server's IP is 10.0.1.10/24, and the gateway is 10.0.1.1. Which command should be used to verify the default gateway configuration?

A.arp -a
B.ip route show
C.ip addr show
D.ss -tln
AnswerB

`ip route show` dumps the kernel routing table, exposing the default route and its gateway. For 10.0.1.10/24, it confirms whether a `default via 10.0.1.1` entry exists — the exact misconfiguration that would block internet-bound traffic while leaving the internal subnet reachable.

Why this answer

The `ip route show` command displays the kernel routing table, including the default gateway entry. Since the server is reachable internally but not from the internet, a missing or incorrect default gateway is the likely cause. This command directly verifies whether a default route (e.g., via 10.0.1.1) is present.

Exam trap

The trap here is that candidates often confuse `ip addr show` (which shows IP configuration) with `ip route show` (which shows routing), leading them to check the IP address instead of the default gateway when troubleshooting external connectivity.

How to eliminate wrong answers

Option A is wrong because `arp -a` shows the ARP cache (IP-to-MAC address mappings) for the local network, not the routing table or default gateway. Option C is wrong because `ip addr show` displays IP addresses and interface configuration, not routing information. Option D is wrong because `ss -tln` lists listening TCP sockets and their ports, which is used to verify service availability, not network-layer routing.

126
MCQmedium

A server runs out of inodes. The administrator needs to find which filesystem is exhausted and which directory has the most files. Which command sequence best accomplishes this?

A.df -i; find / -type f | wc -l
B.df -i; find / -xdev -type f -printf '%h\0' | sort -z | uniq -c -z | sort -rn | head
C.df -i; du --inodes /
D.df -h; du -sh /
AnswerB

`df -i` reports inode usage per filesystem, isolating the exhausted mount. The `find` pipeline then counts files per directory: `-xdev` prevents crossing into other filesystems, `-printf '%h\0'` emits each file's directory NUL-separated, and `sort -z | uniq -c -z | sort -rn` ranks directories by file count.

Why this answer

`df -i` first checks inode usage across all mounted filesystems to identify which one is exhausted. Then the `find / -xdev -type f -printf '%h\0' | sort -z | uniq -c -z | sort -rn | head` command counts files per directory on the root filesystem only (due to `-xdev`), using null-delimited output to handle special characters in filenames, and sorts to show the directory with the most files. This directly addresses both parts of the problem: identifying the exhausted filesystem and the directory with the most files.

Exam trap

The trap here is that candidates often confuse inode exhaustion with disk space exhaustion and choose `df -h` and `du -sh` (Option D), or they use a recursive file count without restricting to a single filesystem (Option A), failing to isolate the problematic filesystem and directory.

How to eliminate wrong answers

Option A is wrong because `find / -type f | wc -l` counts all files across all mounted filesystems (including network and virtual filesystems), which can be misleading and does not restrict to the exhausted filesystem; it also does not group files by directory, so it cannot identify which directory has the most files. Option C is wrong because `du --inodes /` is not a valid option in standard `du`; the `--inodes` flag is not supported by GNU `du` (it is a `df` option), and even if it were, it would not provide per-directory file counts. Option D is wrong because `df -h` shows disk space usage, not inode usage, and `du -sh /` shows total disk space used by the root filesystem, which is irrelevant to an inode exhaustion problem.

127
MCQeasy

Which command displays the listening UDP ports on a Linux system?

A.ss -a
B.ss -tln
C.ss -uln
D.netstat -tln
AnswerC

-u for UDP, -l for listening, -n for numeric.

Why this answer

`ss -uln` specifically displays listening UDP sockets. The `-u` flag filters for UDP, `-l` shows only listening sockets, and `-n` displays numeric addresses and ports (avoiding DNS resolution). This is the most precise command for listing listening UDP ports.

Exam trap

The trap here is that candidates often confuse the `-t` (TCP) and `-u` (UDP) flags, or assume that `netstat -tln` or `ss -tln` will show all listening ports, forgetting that UDP requires explicit `-u` filtering.

How to eliminate wrong answers

Option A is wrong because `ss -a` shows all sockets (both listening and non-listening, TCP and UDP), which is too broad and does not filter for UDP or listening state specifically. Option B is wrong because `ss -tln` filters for TCP sockets only (`-t`), so it will not display any UDP ports. Option D is wrong because `netstat -tln` also filters for TCP sockets only (`-t`), and while netstat can show UDP with `-u`, this option omits the `-u` flag, so it shows only listening TCP ports.

128
Multi-Selecthard

Which THREE statements about Linux network bonding modes are correct? (Choose three.)

Select 3 answers
A.Mode 2 (balance-xor) distributes traffic based on packet type.
B.Mode 0 (balance-rr) can cause out-of-order packet delivery.
C.Modes 5 and 6 (balance-tlb and balance-alb) require IEEE 802.3ad switch support.
D.Mode 4 (802.3ad) requires the switch to support LACP.
E.Mode 1 (active-backup) provides fault tolerance but only one link is active at a time.
AnswersB, D, E

Correct.

Why this answer

Mode 0 (balance-rr) transmits packets in sequential order from the first available slave through the last, then starts over. This round-robin distribution can cause packets belonging to the same TCP session to take different physical paths, leading to out-of-order delivery at the receiver, which may trigger TCP retransmissions and degrade performance.

Exam trap

The trap here is that candidates often confuse 'balance-rr' with 'balance-xor' and assume round-robin distributes traffic based on a hash or packet type, when in fact it simply cycles through slaves without any flow-level awareness.

129
Multi-Selecthard

Which THREE fields are part of a standard /etc/group entry?

Select 3 answers
A.Group password (often 'x')
B.Primary GID of user
C.Group name
D.Home directory of group
E.Group members list
AnswersA, C, E

The group password field, usually shown as 'x', occupies the second colon-separated position in /etc/group, between the group name and GID. It satisfies the stem's requirement for a standard field, since shadowed group passwords live in /etc/gshadow while this placeholder remains in the entry.

Why this answer

A standard /etc/group entry has four colon-separated fields: group name, group password, group ID (GID), and group members list. Option C (group name) is correct because the first field of each /etc/group line is the group's name, such as 'sudo' or 'developers'. Option A (group password, often 'x') is correct because the second field holds the group password placeholder, typically 'x' when shadow group passwords are used via /etc/gshadow.

Option E (group members list) is correct because the fourth field is a comma-separated list of supplementary members of the group. Option B (primary GID of user) is not part of /etc/group; a user's primary GID is stored in the fourth field of /etc/passwd. Option D (home directory of group) does not exist in /etc/group; home directories are per-user fields in /etc/passwd, not per-group fields.

Exam trap

The trap here is that candidates often confuse the fields of /etc/group with those of /etc/passwd, mistakenly thinking that a group entry includes a primary GID or home directory, which are user-specific attributes stored in /etc/passwd.

130
MCQhard

A systems administrator is responsible for a production Linux server running CentOS 7 that provides SSH access to users. The administrator decides to tighten security by restricting SSH access to a specific management subnet 10.0.0.0/24. While connected to the server via SSH from a workstation on 10.0.0.50, the administrator adds the following iptables rule: iptables -A INPUT -p tcp --dport 22 -s 10.0.0.0/24 -j ACCEPT followed by iptables -P INPUT DROP. Immediately after the rule change, the administrator loses all connectivity to the server, including SSH. The administrator suspects that the new default policy dropped the existing SSH session. What is the most reliable method for the administrator to regain access to the server without rebooting?

A.Use netcat to send a TCP reset packet to the SSH server.
B.Use iptables-save and iptables-restore from another host on the same subnet.
C.Use IPMI or iDRAC to access the server's console and remove or modify the iptables rules.
D.Boot the server into single-user mode and flush iptables rules.
AnswerC

Out-of-band management provides console access independent of network.

Why this answer

IPMI (Intelligent Platform Management Interface) or iDRAC (Integrated Dell Remote Access Controller) provides out-of-band management access to the server's console, independent of the operating system's network stack. This allows the administrator to log in locally, remove or modify the iptables rules that dropped the SSH session, and restore connectivity without rebooting. Since the default INPUT policy was set to DROP, all new and existing SSH packets are blocked, but out-of-band management bypasses iptables entirely.

Exam trap

The trap here is that candidates assume iptables rules only affect new connections, forgetting that changing the default policy to DROP without a stateful rule for ESTABLISHED connections will immediately terminate existing sessions, and they overlook out-of-band management as the only non-reboot recovery option.

How to eliminate wrong answers

Option A is wrong because netcat cannot send a TCP reset packet to an existing SSH session that is already blocked by the iptables DROP policy; the kernel's netfilter will drop any packets to port 22, including resets, and netcat operates at the application layer, not at the raw socket level required to inject a reset. Option B is wrong because iptables-save and iptables-restore require an active SSH session or network connectivity to execute commands on the target server; since the administrator has lost all connectivity, there is no way to run these commands from another host. Option D is wrong because booting into single-user mode requires a reboot, which the question explicitly states should be avoided; moreover, single-user mode is a boot-time option that cannot be entered without restarting the system.

131
MCQhard

A Linux administrator needs to configure VLAN tagging on a network bridge to isolate traffic from different virtual machines. The physical interface is eth0, and VLAN ID 100 should be accessible via the bridge br0. Which set of commands correctly creates this configuration using the ip command?

A.ip link add link eth0 name eth0.100 type vlan id 100; ip link add br0 type bridge; ip link set eth0.100 master br0; ip link set br0 up
B.ip link add br0 type bridge; ip link set eth0 master br0; ip link set br0 up
C.ip link add eth0.100 link eth0 type vlan id 100; ip link set eth0.100 master br0; ip link add br0 type bridge
D.ip link add name br0 type bridge; ip link add link br0 name vlan100 type vlan id 100; ip link set eth0 master br0
AnswerA

The commands create a VLAN sub-interface eth0.100 tagged with ID 100 on eth0, create bridge br0, then enslave eth0.100 to br0 and bring the bridge up. Traffic entering br0 traverses the VLAN 100 tag, isolating it from other VLANs.

Why this answer

It first creates a VLAN interface (eth0.100) on top of physical interface eth0 with VLAN ID 100 using `ip link add link eth0 name eth0.100 type vlan id 100`. It then creates a bridge (br0) with `ip link add br0 type bridge`, attaches the VLAN interface to the bridge as a port with `ip link set eth0.100 master br0`, and finally brings the bridge up. This sequence ensures that traffic tagged with VLAN 100 on eth0 is properly forwarded through the bridge to virtual machines, while untagged or other VLAN traffic is isolated.

Exam trap

The trap here is that candidates often forget the order of operations — the bridge must exist before enslaving a port, and the VLAN interface must be created on the physical NIC, not on the bridge itself.

How to eliminate wrong answers

Option B is wrong because it directly attaches the physical interface eth0 to the bridge without creating a VLAN interface, so no VLAN tagging or isolation is configured — all traffic on eth0 passes through the bridge untagged. Option C is wrong because it attempts to set eth0.100 as a slave of br0 before the bridge br0 has been created, which will fail since the bridge must exist first for the `master` command to succeed. Option D is wrong because it creates a VLAN interface on top of the bridge (br0) rather than on the physical interface eth0, which would tag traffic originating from the bridge itself rather than isolating incoming VLAN 100 traffic from eth0.

132
MCQhard

A security policy requires that a user account 'temp_audit' be locked immediately without changing the password. Which command locks the account and prevents login?

A.userdel temp_audit
B.usermod -L temp_audit
C.chage -E 0 temp_audit
D.passwd -u temp_audit
AnswerB

usermod -L prefixes the password hash in /etc/shadow with an exclamation mark, immediately preventing password-based login while leaving the stored hash unchanged. This locks the account without altering the password, exactly as the policy requires.

Why this answer

The `usermod -L` command locks a user account by placing an exclamation mark (!) at the beginning of the password hash in /etc/shadow, effectively disabling password-based authentication without altering the existing password. This satisfies the security policy requirement to immediately prevent login without changing the password.

Exam trap

The trap here is confusing `usermod -L` with `passwd -l` (which also locks the account) or mistaking `chage -E 0` for an immediate lock, when in fact `chage` sets a future expiration date and does not prevent all authentication methods like SSH keys or sudo.

How to eliminate wrong answers

Option A is wrong because `userdel temp_audit` deletes the user account entirely, which violates the requirement to lock the account without changing the password. Option C is wrong because `chage -E 0` sets the account expiration date to epoch (January 1, 1970), which locks the account but is not immediate if the current date is already past epoch; it also does not prevent all login methods (e.g., SSH keys may still work depending on PAM configuration). Option D is wrong because `passwd -u temp_audit` unlocks the account (the -u flag means unlock), which is the opposite of the required action.

133
Multi-Selecthard

An administrator is diagnosing why a server cannot reach the host 198.51.100.25. The server has one interface, eth0, with address 192.0.2.10/24. Running `ip route show` returns only the default route via 192.0.2.1. Which two commands will help determine whether the problem is at layer 2 or layer 3? (Choose two.)

Select 2 answers
A.ip neigh show 192.0.2.1
B.ss -tulnp | grep 198.51.100.25
C.ip link show eth0
D.dig +short 198.51.100.25
E.traceroute 198.51.100.25
AnswersA, E

This command displays the ARP/neighbor table entry for the gateway. If the gateway's MAC address is unresolved or shows FAILED, the problem is at layer 2. If it is REACHABLE, layer 2 to the gateway is working, and the issue is likely at layer 3 or beyond.

Why this answer

To isolate layer 2 versus layer 3, check the neighbor table for the gateway and trace the path to the destination. An unresolved neighbor entry points to a layer 2 problem, while a resolved entry with a traceroute that stops beyond the first hop points to layer 3 or higher. Interface state and DNS queries do not make this distinction.

Exam trap

The trap here is selecting commands that show local socket or interface state instead of tools that test reachability and neighbor resolution.

134
MCQeasy

Which command adds an existing user to a supplementary group without removing the user from other groups?

A.groupmod -a username groupname
B.usermod -A groupname username
C.usermod -aG groupname username
D.usermod -g groupname username
AnswerC

The -a flag appends the group to the user's existing supplementary group list rather than replacing it; without -a, usermod -G would overwrite all current supplementary memberships. This preserves the user's other groups while adding the new one.

Why this answer

The correct command is `usermod -aG groupname username`. The `-a` option (append) combined with `-G` (supplementary groups) adds the user to the specified group without affecting existing supplementary group memberships. Option A (`groupmod -a`) is incorrect because `groupmod` modifies group attributes, not user membership.

Option B (`-A`) is not a valid `usermod` option. Option D (`-g`) changes the user's primary group, not supplementary groups.

135
MCQhard

A system administrator is troubleshooting a server that fails to boot because the root filesystem, which is on an LVM logical volume, cannot be found. The administrator suspects that the initramfs does not include the necessary LVM modules. Which command should be used to rebuild the initramfs for the currently running kernel on a Debian-based system?

A.grub-mkconfig -o /boot/grub/grub.cfg
B.update-initramfs -u
C.dracut -f
D.mkinitrd -f /boot/initrd.img-$(uname -r)
AnswerB

update-initramfs -u updates the initramfs for the currently running kernel on Debian-based systems. It regenerates the initramfs image using the current configuration, which should include LVM modules if the system is configured to use LVM. This is the correct command to ensure the boot image can activate LVM volumes.

Why this answer

On Debian-based systems, the initramfs is managed with update-initramfs. Running update-initramfs -u regenerates the image for the current kernel, incorporating any needed modules such as LVM. Other tools like dracut or mkinitrd are used on different distributions and are not the default on Debian, and grub-mkconfig only updates the bootloader configuration.

Exam trap

The trap here is assuming that initramfs tools are universal across distributions, when each family has its own default command.

136
MCQeasy

A user wants to view the contents of a compressed log file /var/log/syslog.2.gz without decompressing it first. Which command should they use?

A.gunzip /var/log/syslog.2.gz
B.cat /var/log/syslog.2.gz
C.zcat /var/log/syslog.2.gz
D.less /var/log/syslog.2.gz
AnswerC

zcat streams the decompressed contents of gzip-compressed files straight to standard output, leaving the original .gz file untouched on disk. This directly satisfies the stem's constraint of viewing /var/log/syslog.2.gz without decompressing it first, unlike gunzip, which would replace the archive with an uncompressed file.

Why this answer

`zcat` is a utility that reads compressed files (typically gzip-compressed) and outputs their decompressed content to standard output without permanently decompressing the file. This allows the user to view the contents of `/var/log/syslog.2.gz` directly in the terminal.

Exam trap

The trap here is that candidates may confuse `zcat` with `gunzip` or assume `less` can handle compressed files natively, but the LFCS exam expects knowledge of the specific command designed for viewing compressed files without decompression.

How to eliminate wrong answers

Option A is wrong because `gunzip` permanently decompresses the file, replacing the `.gz` file with an uncompressed version, which is not what the user wants. Option B is wrong because `cat` cannot interpret gzip compression; it will output raw binary data, which is unreadable. Option D is wrong because `less` does not natively handle gzip-compressed files; it would display binary garbage unless used with a wrapper like `zless` or a pipe from `zcat`.

137
MCQhard

An administrator created an LVM snapshot of a logical volume to perform a backup. During the backup, the snapshot runs out of space. What will happen to the original logical volume?

A.The original volume becomes read-only.
B.The backup completes successfully but data may be inconsistent.
C.The snapshot becomes invalid and must be recreated.
D.The original volume is automatically extended.
AnswerC

LVM snapshots have a fixed size; when copy-on-write data fills it, the snapshot is marked invalid and further writes to the origin are not tracked. The original logical volume remains intact and usable, but the snapshot cannot be used for backup and must be recreated.

Why this answer

When an LVM snapshot runs out of space, it becomes invalid and cannot track changes made to the original logical volume during the backup. The snapshot is automatically dropped by the device-mapper, and any attempt to mount or read it will fail. The original logical volume remains fully functional and unaffected, but the snapshot must be recreated to perform a new backup.

Exam trap

The trap here is that candidates often assume the original volume will be affected (e.g., become read-only or extended) when the snapshot runs out of space, but LVM isolates the original volume from snapshot failures, so only the snapshot is invalidated.

How to eliminate wrong answers

Option A is wrong because the original volume does not become read-only; LVM snapshots are copy-on-write, and running out of space in the snapshot only invalidates the snapshot, not the original volume. Option B is wrong because the backup cannot complete successfully; once the snapshot runs out of space, it is dropped and becomes inaccessible, so the backup process will fail or produce an error. Option D is wrong because LVM does not automatically extend snapshots or original volumes; snapshot size must be manually monitored and extended using 'lvextend' before it fills up.

138
MCQmedium

An administrator must change the ownership of /srv/project and every file and directory beneath it to user alice and group devs, without altering permissions. Which command should be used?

A.chmod -R alice:devs /srv/project
B.chgrp -R alice:devs /srv/project
C.usermod -R alice:devs /srv/project
D.chown -R alice:devs /srv/project
AnswerD

This is correct because chown changes file owner and group, and the -R flag applies the change recursively through the directory tree. The syntax user:group sets both owner and group in one operation. Permissions are untouched, satisfying the requirement to change ownership only for /srv/project and everything beneath it.

Why this answer

Changing both owner and group recursively is the job of chown with the -R flag and the user:group syntax. This updates ownership metadata on every file and directory under the target path while leaving permission bits intact. chmod, usermod, and chgrp each address different attributes and cannot fulfill the combined owner-and-group requirement.

Exam trap

The trap here is assuming chmod can set ownership because both commands modify file metadata.

139
MCQmedium

A system administrator runs 'ss -tuln' and sees that port 80 is listening. What does the 'u' option represent?

A.User
B.Unix sockets
C.UDP
D.Unicast
AnswerC

In the ss command, the 'u' flag restricts output to UDP sockets, complementing 't' for TCP. Combined with 'l' and 'n', it lists listening UDP ports numerically, confirming which transport protocol is bound to port 80.

Why this answer

In the `ss` command, the `-u` option filters output to show only UDP sockets. Since the question shows `ss -tuln`, which combines `-t` (TCP), `-u` (UDP), `-l` (listening), and `-n` (numeric), the `u` specifically represents UDP. This is confirmed by the `ss` man page and standard Linux networking tools.

Exam trap

The trap here is that candidates confuse `-u` with 'Unix sockets' (which is `-x`) or 'User' (which is `-p`), because the letter 'u' is commonly associated with 'Unix' or 'user' in other commands, but in `ss` it specifically means UDP.

How to eliminate wrong answers

Option A is wrong because `-u` does not stand for 'User'; user information is displayed with the `-p` option or by default in some output formats, not with `-u`. Option B is wrong because Unix sockets are displayed with the `-x` option, not `-u`; `-u` is exclusively for UDP sockets. Option D is wrong because 'Unicast' is a type of network transmission, not a socket type or protocol filter in `ss`; `ss` uses `-u` to filter by UDP protocol, not by unicast addressing.

140
MCQeasy

Which file stores the encrypted password (or password hash) for user accounts?

A./etc/group
B./etc/shadow
C./etc/passwd
D./etc/gshadow
AnswerB

The /etc/shadow file holds the encrypted password hash, readable only by root, unlike the world-readable /etc/passwd which merely stores an 'x' placeholder. This satisfies the requirement to identify where the actual password hash for user accounts is kept.

Why this answer

/etc/shadow is correct because it stores encrypted password hashes for user accounts, along with password aging information. It is readable only by root to prevent unauthorized access to password hashes. The /etc/passwd file historically stored passwords but now only contains user account information, with the password field replaced by an 'x' indicating the hash is in /etc/shadow.

Exam trap

The trap is assuming that /etc/passwd still stores passwords, as it did in early Unix systems. Candidates must remember that modern systems use /etc/shadow for password hashes, and /etc/passwd only contains a placeholder.

How to eliminate wrong answers

Option A is wrong because /etc/group stores group information, not user passwords. Option C is wrong because /etc/passwd stores user account information but not the password hash; it contains a placeholder 'x' in the password field. Option D is wrong because /etc/gshadow stores group passwords and group administrators, not user passwords.

141
MCQeasy

Refer to the exhibit. The administrator wants to create a RAID 1 array using /dev/sdb1 and /dev/sdc1. Which command should be used?

A.mdadm --create /dev/md0 --level=5 --raid-devices=2 /dev/sdb1 /dev/sdc1
B.mdadm --create /dev/md0 --level=1 --raid-devices=2 /dev/sdb1 /dev/sdc1
C.mdadm --create /dev/md0 --level=10 --raid-devices=2 /dev/sdb1 /dev/sdc1
D.mdadm --create /dev/md0 --level=0 --raid-devices=2 /dev/sdb1 /dev/sdc1
AnswerB

The `--create` mode with `--level=1` builds a RAID 1 mirror across exactly two member devices, satisfying the stem's redundancy requirement. Naming `/dev/sdb1` and `/dev/sdc1` after `--raid-devices=2` matches the declared count, so mdadm assembles `/dev/md0` without prompting for a missing or spare disk.

Why this answer

RAID 1 (mirroring) requires exactly two devices to provide redundancy by duplicating data across both disks. The `--level=1` parameter specifies RAID 1, and `--raid-devices=2` matches the two partitions /dev/sdb1 and /dev/sdc1.

Exam trap

The trap here is that candidates confuse RAID levels and their minimum device requirements, often selecting RAID 5 or RAID 10 without verifying the device count, or mistakenly thinking RAID 0 provides redundancy.

How to eliminate wrong answers

Option A is wrong because `--level=5` (RAID 5) requires a minimum of three devices for striping with distributed parity, not two. Option C is wrong because `--level=10` (RAID 10) is a nested RAID combining mirroring and striping, requiring at least four devices (two mirrored pairs). Option D is wrong because `--level=0` (RAID 0) provides striping without redundancy, which does not meet the administrator's goal of creating a RAID 1 array.

142
MCQeasy

You need to check the default gateway on a Linux server. Which command displays the current routing table, including the default route?

A.ip route show
B.ifconfig -a
C.ss -tuln
D.netstat -i
AnswerA

The 'ip route show' command displays the kernel's routing table, including the default route (usually shown as 'default via <gateway> dev <interface>'). This is the correct and modern command to view routes. It provides all necessary information to identify the default gateway.

Why this answer

The correct command is 'ip route show', which displays the routing table including the default route. The other commands show interface configuration (ifconfig), interface statistics (netstat -i), or listening sockets (ss -tuln), none of which reveal the default gateway.

Exam trap

The trap here is confusing commands that show interface addresses or listening ports with those that show routing information.

143
Matchingmedium

Match each Linux package management command to its distribution.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Debian/Ubuntu

RHEL/CentOS 7

Fedora/RHEL 8+

openSUSE

Arch Linux

Why these pairings

Package managers are tied to specific distribution families: apt (Debian/Ubuntu), yum (RHEL/CentOS 7), dnf (Fedora/RHEL 8+), pacman (Arch), and zypper (openSUSE). Common confusions arise from mixing these tools across distributions.

144
MCQeasy

A user reports that they cannot delete a file named 'important.txt' located in their home directory. The file is owned by the user and the user has write permission on the directory. Running 'rm important.txt' produces the error: 'rm: cannot remove 'important.txt': Operation not permitted'. The user has also tried using 'sudo rm' but gets the same error. Which of the following is the most likely cause and correct solution?

A.The file has an ACL that denies deletion. Use 'setfacl -b important.txt' to remove ACLs.
B.The file has the immutable attribute set. Use 'lsattr important.txt' and if the 'i' attribute is present, remove it with 'chattr -i important.txt'.
C.The file is currently in use by another process. Use 'lsof' to find the process and kill it.
D.The directory has the sticky bit set, preventing deletion. Use 'chmod o-t .' to remove the sticky bit.
AnswerB

The immutable attribute (i) prevents deletion even by root, which explains why 'sudo rm' also fails despite directory write permission. Checking with 'lsattr' and clearing it via 'chattr -i important.txt' directly resolves the "Operation not permitted" error, satisfying the scenario's constraint that ownership and permissions are already correct.

Why this answer

The error 'Operation not permitted' despite the user owning the file and having write permission on the directory indicates a filesystem-level restriction rather than a permission or ACL issue. The immutable attribute (i) on the file prevents any modification, including deletion, even by the root user. Running 'lsattr' reveals the attribute, and 'chattr -i' removes it, allowing deletion.

Exam trap

The trap here is that candidates confuse 'Operation not permitted' with standard permission errors, overlooking the immutable attribute as a filesystem-level override that affects even root and is not visible with 'ls -l'.

How to eliminate wrong answers

Option A is wrong because ACLs (Access Control Lists) do not produce an 'Operation not permitted' error for a file owner; they would show 'Permission denied' if applicable, and 'setfacl -b' removes all ACLs, which is unnecessary here. Option C is wrong because a file in use by another process would typically give a 'Text file busy' or 'Device or resource busy' error, not 'Operation not permitted', and killing the process would not resolve an immutable attribute. Option D is wrong because the sticky bit on a directory affects deletion of files owned by other users, not the file owner; the user owns the file, so the sticky bit does not block deletion, and 'chmod o-t' removes the sticky bit from the current directory, which is not the issue.

145
MCQhard

A security policy requires that all users in the 'admin' group must have a umask of 027 set automatically upon login. An administrator adds 'umask 027' to /etc/profile. However, users report that the umask is still 022. What is a likely cause?

A.The umask in /etc/profile is overridden by user-specific .bash_profile or .bashrc files.
B.The umask command in /etc/profile has a syntax error that is silently ignored.
C.The admin placed the umask command after the call to /etc/bash.bashrc which resets it.
D.The admin forgot to run 'source /etc/profile' on each user's session.
AnswerA

Login shells read /etc/profile first, then ~/.bash_profile, ~/.bash_login or ~/.profile. If any of these later files sets umask 022, it overwrites the earlier 027 value, so the policy fails despite the correct edit to /etc/profile.

Why this answer

User-specific shell configuration files (like ~/.bash_profile, ~/.bash_login, or ~/.profile for login shells, and ~/.bashrc for interactive non-login shells) are sourced after /etc/profile. These files can override the system-wide umask setting with a user-defined value, such as the default 022. Since the administrator only modified /etc/profile, any existing user-specific umask command in their personal dotfiles will take precedence.

Exam trap

The trap here is that candidates assume /etc/profile is the final authority for login shell settings, but they overlook that user-specific dotfiles are sourced after it and can override variables like umask.

How to eliminate wrong answers

Option B is wrong because the 'umask 027' command has no syntax error; umask accepts a three-digit octal value and is not silently ignored—if there were a syntax error, the shell would display an error message. Option C is wrong because /etc/bash.bashrc is typically sourced for interactive non-login shells, not for login shells where /etc/profile is read first; moreover, the order of sourcing does not cause a reset unless a later file explicitly changes the umask. Option D is wrong because /etc/profile is automatically sourced by the login shell for all users when they log in; running 'source /etc/profile' manually is unnecessary and not part of standard login procedures.

146
Drag & Dropmedium

Order the steps to create a systemd service unit that runs a script at boot.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Creating the unit file, enabling for boot, starting, and checking status are standard steps.

147
MCQmedium

An administrator receives a report that a specific directory /var/log is consuming too much disk space. Which command should be used to determine the total disk space used by that directory?

A.df -h /var/log
B.ls -la /var/log
C.fdisk /var/log
D.du -sh /var/log
AnswerD

du -s summarises total usage for the directory rather than listing every file, and -h renders it in human-readable units. This directly answers the request for total space consumed by /var/log, unlike df, which reports filesystem-level usage.

Why this answer

The `du -sh /var/log` command calculates the total disk space used by the specified directory. The `-s` flag summarizes the total size, `-h` provides human-readable output (e.g., in KB, MB, GB), and the path `/var/log` targets the directory in question. This is the standard Linux command for determining directory disk usage.

Exam trap

The trap here is that candidates confuse `df` (filesystem-level usage) with `du` (directory-level usage), often selecting `df -h` because it shows disk space, without realizing it reports on the entire partition rather than the specific directory.

How to eliminate wrong answers

Option A is wrong because `df -h /var/log` reports the disk space usage of the filesystem (partition) that contains `/var/log`, not the directory itself; it shows total, used, and available space for the entire mount point. Option B is wrong because `ls -la /var/log` lists the contents of the directory with file sizes but does not sum them recursively, so it cannot provide the total disk space consumed by the directory tree. Option C is wrong because `fdisk /var/log` is a partition table manipulation tool that operates on block devices (e.g., /dev/sda), not on directories; it would fail with an error when given a directory path.

148
MCQeasy

A Linux server has a single Ethernet interface eth0. The administrator needs to assign a static IPv4 address 192.0.2.10/24 with gateway 192.0.2.1 on a system that uses systemd-networkd. Which file should be created or edited to configure this interface?

A./etc/network/interfaces
B./etc/systemd/network/10-eth0.network
C./etc/netplan/01-netcfg.yaml
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerB

systemd-networkd reads .network files from /etc/systemd/network/, /run/systemd/network/, and /usr/lib/systemd/network/. A file named 10-eth0.network in /etc/systemd/network/ is the correct location to define a static address, gateway, and DNS for eth0. The numeric prefix controls processing order, and the [Match] section must match the interface name.

Why this answer

systemd-networkd uses .network files stored in /etc/systemd/network/ (or /run and /usr/lib). A file such as 10-eth0.network with a [Match] section for eth0 and a [Network] section specifying Address=192.0.2.10/24 and Gateway=192.0.2.1 is the correct way to assign a static IPv4 configuration. The other paths belong to different network management frameworks.

Exam trap

The trap here is confusing the configuration file locations of different network management tools, such as ifupdown, NetworkManager, or netplan, with the native systemd-networkd format.

149
MCQeasy

A user reports that a shell script 'backup.sh' in /home/user/scripts fails to execute. What is the most likely cause?

A.The script is not in the user's PATH.
B.The script does not have execute permission for the user.
C.The script must be owned by root.
D.The script does not have a shebang line (#!/bin/bash) at the top.
AnswerB

Without execute permission, the kernel refuses to run the file as a program, returning "Permission denied" even though the script's contents are readable. The stem specifies a script that fails to execute, and this is the most common cause; `chmod +x backup.sh` resolves it.

Why this answer

The most likely cause is that the script lacks execute permission for the user. In Linux, a file must have the execute bit set (e.g., `chmod +x backup.sh`) to be run as a script. Without it, the shell will refuse to execute the file, even if the user has read access and the script is syntactically correct.

Exam trap

The trap here is that candidates often assume a missing shebang (Option D) is the primary cause, but the LFCS exam tests that execute permission is the fundamental requirement for running any script directly.

How to eliminate wrong answers

Option A is wrong because the script is being executed directly (e.g., `./backup.sh` or via a full path), so PATH is irrelevant; PATH only matters when invoking a command by name without a path. Option C is wrong because script ownership does not affect execution; any user with execute permission can run it, regardless of owner. Option D is wrong because while a shebang is good practice, the shell will still attempt to execute the script using the default shell (usually /bin/sh) if no shebang is present; the script would run, not fail to execute entirely.

150
MCQeasy

A system administrator receives an alert that disk /dev/sda is predicted to fail soon. The server uses LVM, and /dev/sda is part of a volume group named vg_system. Which of the following is the best course of action to replace the failing disk without downtime?

A.Use dd to clone /dev/sda to a new disk and then replace.
B.Use ddrescue to copy data, then replace the disk.
C.Remove /dev/sda from the volume group and add a new disk.
D.Use pvmove to move physical extents to another disk, then remove the old disk.
AnswerD

pvmove relocates the physical extents residing on the failing physical volume to another disk in vg_system while the volume group stays online. The old disk can then be removed with vgreduce and pvremove, replacing it without downtime.

Why this answer

Pvmove relocates physical extents from /dev/sda to another physical volume in the same volume group while the filesystem remains online and accessible. This allows the failing disk to be removed from vg_system without any downtime, preserving LVM metadata and data integrity.

Exam trap

The trap here is that candidates confuse block-level cloning (dd) with LVM-aware migration (pvmove), assuming any copy tool can replace a disk in an LVM setup without understanding that LVM metadata and extent mapping must be handled correctly to avoid downtime or data corruption.

How to eliminate wrong answers

Option A is wrong because dd clones the entire block device including LVM metadata, which can cause UUID conflicts and requires the disk to be offline or unmounted, leading to downtime. Option B is wrong because ddrescue is designed for data recovery from failing media, not for live migration within LVM, and still requires the disk to be taken offline. Option C is wrong because removing /dev/sda from the volume group without first moving its extents would cause data loss; vgreduce can only remove a physical volume that has no allocated extents.

Page 1

Page 2 of 6

Page 3

All pages