Courseiva

Linux Foundation Certified System Administrator LFCS (LFCS) — Questions 151–225

406 questions total · 6pages · All types, answers revealed

Page 2

Page 3 of 6

Page 4
151
MCQeasy

An administrator needs to delete user 'obsolete' and remove its home directory and mail spool. Which command should be used?

A.userdel -f obsolete
B.userdel -r obsolete
C.userdel obsolete
D.groupdel obsolete
AnswerB

The -r flag instructs userdel to remove the account together with its home directory and mail spool. Without -r, those files persist as orphans, so this satisfies the stem's explicit requirement to delete both the user and associated data.

Why this answer

The correct command is `userdel -r obsolete` because the `-r` flag removes the user's home directory and mail spool in addition to deleting the user account. This matches the requirement to delete the user 'obsolete' along with its home directory and mail spool, as specified in the question.

Exam trap

The trap here is that candidates may confuse the `-r` flag with the `-f` flag, assuming `-f` (force) also removes files, or they may think `userdel` alone is sufficient, missing the requirement to clean up the home directory and mail spool.

How to eliminate wrong answers

Option A is wrong because `userdel -f` forces the removal of the user even if they are logged in, but it does not remove the home directory or mail spool; the `-f` flag is for force, not for recursive removal. Option C is wrong because `userdel obsolete` only removes the user account without deleting the home directory or mail spool, leaving those files orphaned. Option D is wrong because `groupdel obsolete` is used to delete a group, not a user, and it does not affect the user's home directory or mail spool.

152
MCQeasy

An administrator needs to change the group ownership of the directory /srv/project and all of its existing contents to the group developers, without altering the user ownership. Which command should be used?

A.chmod -R g+developers /srv/project
B.usermod -g developers /srv/project
C.chown -R developers /srv/project
D.chgrp -R developers /srv/project
AnswerD

chgrp changes group ownership and the -R flag applies the change recursively to the directory and all existing contents. It leaves user ownership untouched, which matches the requirement exactly, and it is the purpose-built command for changing group ownership on Linux systems.

Why this answer

Changing group ownership recursively is the job of chgrp -R. It applies only the group change and leaves user ownership intact, which is precisely what the scenario requires. chown with a bare name targets the user, chmod alters permissions rather than ownership, and usermod operates on account definitions instead of filesystem objects.

Exam trap

The trap here is assuming chown with a single name sets the group, when it actually sets the user owner.

153
Multi-Selecteasy

Which TWO commands can be used to display the current working directory?

Select 2 answers
A.which pwd
B.pwd
C.date
D.echo $PWD
E.whoami
AnswersB, D

pwd is the shell builtin that prints the absolute pathname of the current working directory, directly satisfying the requirement to display it. It reads the shell's tracked directory state rather than resolving a path argument.

Why this answer

Option B, `pwd`, is correct because it is the dedicated shell builtin/utility that prints the absolute pathname of the current working directory. Option D, `echo $PWD`, is correct because the shell maintains the `PWD` environment variable holding the current working directory, and `echo` expands it to display that path. Option A, `which pwd`, only locates the executable or builtin for `pwd` and prints its path rather than the working directory.

Option C, `date`, displays the current system date and time, and option E, `whoami`, prints the effective username — neither relates to the working directory.

Exam trap

Linux Foundation often tests the distinction between commands that display the working directory and commands that merely locate or describe other things, tricking candidates into selecting `which pwd` because it contains the letters 'pwd'.

154
MCQeasy

An administrator wants to permanently configure a static IP address on a CentOS 7 system. Which file should be edited?

A./etc/sysconfig/network-scripts/ifcfg-eth0
B./etc/sysconfig/network
C./etc/hostname
D./etc/network/interfaces
AnswerA

Editing /etc/sysconfig/network-scripts/ifcfg-eth0 satisfies the persistence constraint: CentOS 7's NetworkManager and legacy network service both read per-interface ifcfg files at boot, so BOOTPROTO=none, IPADDR, NETMASK and GATEWAY survive reboots. Runtime tools like ip or ifconfig change only the live kernel state and are lost on restart.

Why this answer

On CentOS 7, network interface configuration is stored in individual files under /etc/sysconfig/network-scripts/, named ifcfg-<interface>. The ifcfg-eth0 file contains parameters like BOOTPROTO, IPADDR, NETMASK, and GATEWAY, and setting BOOTPROTO=static along with the IP address values permanently configures a static IP. This is the standard method for RHEL/CentOS 7 systems using the legacy network scripts (not NetworkManager's keyfile format).

Exam trap

The trap here is that candidates familiar with Debian-based systems may choose /etc/network/interfaces (Option D), while those who confuse global network settings with per-interface settings may pick /etc/sysconfig/network (Option B), both of which are incorrect for CentOS 7's static IP configuration.

How to eliminate wrong answers

Option B is wrong because /etc/sysconfig/network is a system-wide file that sets global networking parameters (e.g., HOSTNAME, GATEWAY) but does not define per-interface IP addresses; editing it alone cannot configure a static IP for a specific interface. Option C is wrong because /etc/hostname only sets the system's hostname, not IP address configuration; it is unrelated to static IP assignment. Option D is wrong because /etc/network/interfaces is the configuration file used by Debian/Ubuntu systems (ifupdown), not by CentOS 7 which uses the ifcfg files under /etc/sysconfig/network-scripts/.

155
MCQmedium

A technician must create a hard link named 'report_link' to an existing file '/data/report.txt'. Which command should be used?

A.cp /data/report.txt report_link
B.ln /data/report.txt report_link
C.mv /data/report.txt report_link
D.ln -s /data/report.txt report_link
AnswerB

Without any options, ln creates a hard link. This command creates a hard link named report_link that points to the same inode as /data/report.txt. Both names refer to the same file data, and changes through either name are reflected in the other.

Why this answer

The ln command without options creates a hard link by default. This results in two directory entries pointing to the same inode, which is exactly what a hard link is. The other commands either create symbolic links, copies, or rename the file, none of which produce a hard link as required.

Exam trap

The trap here is assuming that ln always creates symbolic links; actually, the -s option is needed for symbolic links, while the default is hard links.

156
MCQeasy

A Linux administrator needs to modify the default runlevel (target) on a systemd-based Linux server so that it boots into a graphical environment by default. Which command should the administrator use?

A.systemctl enable graphical.target
B.ln -sf /usr/lib/systemd/system/graphical.target /etc/systemd/system/default.target
C.systemctl isolate graphical.target
D.systemctl set-default graphical.target
AnswerD

This command sets the default boot target to graphical.target by creating a symlink from /etc/systemd/system/default.target to /usr/lib/systemd/system/graphical.target. It ensures that on the next boot, the system will start the graphical environment. This is the correct and recommended method for changing the default runlevel on systemd systems.

Why this answer

The default systemd target is controlled by the /etc/systemd/system/default.target symlink. The systemctl set-default command is the official way to change this symlink to point to the desired target, such as graphical.target for a graphical boot. Unlike isolate, which only changes the current state, set-default persists across reboots.

Using enable is incorrect because it does not alter the default.target symlink. Manual symlink creation is possible but not the recommended practice.

Exam trap

The trap here is confusing the immediate effect of isolating a target with the persistent change of setting the default target, leading to a temporary switch that does not survive a reboot.

157
MCQmedium

A system administrator has a cron job that runs a backup script. The script requires the variable BACKUP_DIR to be set, but the administrator cannot modify the script. Which is the most appropriate place to define the variable for cron?

A.In the crontab file with the line 'BACKUP_DIR=/var/backups' before the command
B.In /etc/profile.d/backup.sh
C.In /etc/environment
D.In ~/.bash_profile
AnswerA

Crontab variable assignments are parsed by cron itself and exported into the job's environment, so BACKUP_DIR reaches the script without editing it. Shell profile files are not sourced for cron jobs, and the script cannot be modified per the stem's constraint.

Why this answer

Cron jobs run in a minimal environment and do not source shell profiles or login scripts. Defining BACKUP_DIR directly in the crontab file before the command ensures the variable is set in the cron execution context, which is the only reliable way to pass environment variables to cron without modifying the script.

Exam trap

The trap here is that candidates assume cron inherits the user's login environment or sources profile files, but cron explicitly does not, making inline crontab variable definitions the only correct approach.

How to eliminate wrong answers

Option B is wrong because /etc/profile.d/ scripts are sourced only by interactive login shells, not by cron, which uses a non-interactive, non-login shell. Option C is wrong because /etc/environment is read by PAM (pam_env.so) during login sessions, but cron does not use PAM for environment setup. Option D is wrong because ~/.bash_profile is sourced only for interactive login shells, and cron does not invoke a login shell.

158
Multi-Selectmedium

Which TWO commands can be used to view the current routing table on a Linux system?

Select 2 answers
A.netstat -rn
B.ifconfig -a
C.ss -tuln
D.route -n
E.ip addr
AnswersA, D

`netstat -rn` reads the kernel's routing information and prints it numerically, with `-r` selecting the routing table and `-n` suppressing DNS lookups so addresses appear as raw IPs. This satisfies the stem's requirement to view the current routing table, though `netstat` is deprecated on modern systems in favour of `ip route`.

Why this answer

Option A, netstat -rn, is correct because the -r flag displays the kernel routing table and -n shows addresses numerically, producing the current routing table on a Linux system. Option D, route -n, is correct because the route command with -n prints the kernel IP routing table in numeric form, which is a classic way to view routes. Option B, ifconfig -a, is wrong because it only shows network interface configuration (addresses, flags, MTU), not routes.

Option C, ss -tuln, is wrong because it lists TCP/UDP listening sockets, not the routing table. Option E, ip addr, is wrong because it displays interface addresses and link information, not routes (the routing table would be shown with ip route).

Exam trap

The trap here is that candidates confuse `ip addr` (which shows addresses) with `ip route` (which shows routes), or assume `ifconfig` shows routing information because it displays interface details, but it never shows the routing table.

159
MCQhard

Refer to the exhibit. What is the most likely security issue?

A.SSH service is not running.
B.The root account is disabled.
C.Someone is attempting to brute-force the root password.
D.The firewall is blocking SSH.
AnswerC

Repeated failed root logins from a single source in the authentication log indicate a brute-force attempt against the root account. The pattern of many rapid failures, rather than a single error, distinguishes deliberate password guessing from ordinary mistyped credentials.

Why this answer

The exhibit shows multiple failed SSH login attempts for the root user from the same IP address in quick succession, as seen in the auth.log or secure log entries. This pattern indicates a brute-force attack, where an attacker systematically tries different passwords to gain unauthorized root access. Option C is correct because the repeated 'Failed password for root' messages are the hallmark of a brute-force attempt.

Exam trap

The trap here is that candidates may see 'SSH' and 'root' and incorrectly assume the service is down or the account is disabled, rather than recognizing the pattern of repeated failed login attempts as a brute-force attack.

How to eliminate wrong answers

Option A is wrong because the SSH service is clearly running and accepting connections, as evidenced by the log entries showing SSH authentication attempts. Option B is wrong because the root account is not disabled; if it were disabled, the log would show 'User root not allowed because account is locked' or similar, not 'Failed password' attempts. Option D is wrong because the firewall is not blocking SSH; if it were, the connection attempts would not reach the SSH daemon to generate authentication failure logs.

160
MCQhard

You are a system administrator for a company that runs a web server on a Linux system. The web server logs are stored in /var/log/nginx/access.log. The log file grows rapidly and rotates weekly via logrotate. The system has been running for several months. Recently, the development team reported that the web server is responding slowly. You suspect that the disk I/O might be high due to log file activity. You check the disk usage and find that /var/log/nginx/access.log is 4 GB, and the rotated logs (access.log.1.gz, access.log.2.gz, etc.) total another 10 GB. The /var partition has 20 GB total, so it's 70% full. You decide to reduce the disk usage by compressing the current log file and truncating it without stopping the nginx service. Which command sequence should you use to safely achieve this?

A.:> /var/log/nginx/access.log && cp /var/log/nginx/access.log /var/log/nginx/access.log.bak && gzip /var/log/nginx/access.log.bak
B.cp /var/log/nginx/access.log /var/log/nginx/access.log.bak && :> /var/log/nginx/access.log && gzip /var/log/nginx/access.log.bak
C.rm /var/log/nginx/access.log && touch /var/log/nginx/access.log && chmod 644 /var/log/nginx/access.log
D.mv /var/log/nginx/access.log /var/log/nginx/access.log.bak && touch /var/log/nginx/access.log && gzip /var/log/nginx/access.log.bak
AnswerB

Copying the log preserves its contents, then truncating with ':>' empties the original inode while nginx keeps writing to it, and gzip compresses the backup. This satisfies the constraint of compressing and truncating without stopping nginx, avoiding the inode-swap problem that 'mv' would cause.

Why this answer

It first copies the current log file to a backup, then truncates the original file in place using the shell null command (`:>`) without stopping nginx, and finally compresses the backup. This ensures nginx continues writing to the same inode (file descriptor remains valid) and the disk space is reclaimed after compression.

Exam trap

The trap here is that candidates often choose `mv` and `touch` (Option D) thinking it's the standard logrotate method, but without signaling nginx, the old file descriptor remains attached to the moved file, causing the new empty file to be ignored and log data to be written to the renamed file instead.

How to eliminate wrong answers

Option A is wrong because it truncates the log file before copying it, resulting in an empty backup and loss of log data. Option C is wrong because `rm` removes the file entirely, breaking nginx's open file descriptor and causing it to log to a deleted inode until restarted; `touch` creates a new file with a different inode, and the permission reset is unnecessary. Option D is wrong because `mv` moves the file to a new name, which changes the inode; nginx continues writing to the old inode (now renamed), and the new `touch`ed file is not used until nginx is restarted or signaled, causing log loss or misdirection.

161
MCQmedium

A backup script must create a compressed archive of the /etc directory, preserving file permissions and timestamps. Which command should be used?

A.gzip -r /etc > backup.tar.gz
B.cpio -ov < /etc > backup.cpio
C.rsync -av /etc /backup/etc
D.tar -czvf backup.tar.gz /etc
AnswerD

tar with -czvf creates a gzipped archive preserving permissions and timestamps.

Why this answer

The `tar -czvf` command creates a compressed archive (via gzip) that preserves file permissions and timestamps by default when run as root. The `-c` flag creates the archive, `-z` compresses it with gzip, `-v` provides verbose output, and `-f` specifies the archive filename. Tar is the standard Unix tool for bundling files into a single archive while retaining metadata like ownership, permissions, and timestamps.

Exam trap

The trap here is that candidates confuse `gzip` (which compresses individual files) with `tar` (which archives directories), or they think `rsync` creates an archive file when it actually creates a directory copy, not a compressed archive.

How to eliminate wrong answers

Option A is wrong because `gzip -r` recursively compresses individual files in place, not creating a single archive; it would replace each file with a .gz version, losing the directory structure and not preserving permissions in a bundled format. Option B is wrong because `cpio -ov < /etc` reads from stdin, but `/etc` is a directory, not a file list; cpio requires a list of files piped via `find` or similar, and without `--preserve-modification-time` it does not preserve timestamps by default. Option C is wrong because `rsync -av` synchronizes files to a destination directory, not creating a single compressed archive file; it preserves permissions and timestamps but produces a directory copy, not a portable archive like tar.gz.

162
MCQhard

A developer reports that a web application's logs are not being written to /var/log/myapp.log. The service runs as user 'myapp' and the log directory /var/log/myapp/ has permissions 755 owned by root. What is the most likely cause?

A.AppArmor is denying access.
B.SELinux is blocking the write.
C.The service is logging to systemd-journald instead of a file.
D.The service user 'myapp' does not have write permission to the log directory.
AnswerD

Directory permissions 755 grant write access only to the root owner, so user 'myapp' cannot create or append to files within /var/log/myapp/. The service therefore fails to open the log for writing, satisfying the stem's constraint that logs are absent despite the service running.

Why this answer

The /var/log/myapp/ directory has permissions 755, which grants read and execute access to the 'others' category but not write. Since the service runs as user 'myapp', which is not the owner (root) and not in the root group, it falls under 'others' and thus lacks write permission. Without write permission on the directory, the service cannot create or write to /var/log/myapp.log, even if the file itself might have different permissions.

Exam trap

The trap here is that candidates may focus on file permissions of the log file itself rather than the directory permissions, or incorrectly assume that SELinux or AppArmor is the default cause for permission denials without evidence of their enforcement.

How to eliminate wrong answers

Option A is wrong because AppArmor is a Linux security module that uses profiles to restrict program capabilities, but there is no indication that AppArmor is enabled or that a profile is blocking the write; the issue is purely a filesystem permission problem. Option B is wrong because SELinux is a mandatory access control system that enforces security policies via contexts, but the question does not mention SELinux being enabled or any denial audit messages; the permissions 755 on the directory are the direct cause. Option C is wrong because while systemd-journald can capture logs, the developer explicitly states logs are not being written to /var/log/myapp.log, and the service configuration likely targets that file; the issue is not about the logging destination but the inability to write due to permissions.

163
MCQeasy

Which command displays the amount of free and used memory in the system?

A.free -h
B.df -h
C.ps aux
D.netstat -i
AnswerA

`free -h` reads `/proc/meminfo` and reports total, used, free, shared, buffer/cache and available memory, with the `-h` flag scaling values into human-readable units. This directly satisfies the stem's requirement to display free and used memory amounts, unlike commands showing process or disk statistics.

Why this answer

The `free -h` command displays the total, used, and free physical memory (RAM) and swap space in a human-readable format (e.g., GiB, MiB). The `-h` flag converts raw byte counts into appropriate units, making it the correct tool for checking memory usage.

Exam trap

The trap here is that candidates confuse `df` (disk free) with `free` (memory free) due to similar names, or assume `ps aux` shows total memory usage when it only shows per-process values.

How to eliminate wrong answers

Option B is wrong because `df -h` reports disk filesystem usage (mounted partitions), not memory. Option C is wrong because `ps aux` lists running processes and their resource usage (CPU, memory per process), not the system-wide free and used memory totals. Option D is wrong because `netstat -i` displays network interface statistics (packets, errors, collisions), not memory information.

164
MCQmedium

Refer to the exhibit. The service unit file has Restart=on-failure, but systemctl show displays Restart=no. What is the most likely reason?

A.The User=backup directive overrides Restart.
B.The unit file was edited but systemctl daemon-reload was not run.
C.The unit is not enabled.
D.The Restart directive is only valid for Type=simple.
AnswerB

Editing a unit file does not alter the loaded configuration; systemd caches unit definitions until `systemctl daemon-reload` re-reads them. Because the stale in-memory copy still holds the original `Restart=no`, `systemctl show` reports that value, satisfying the stem's mismatch between the file's `Restart=on-failure` and the displayed setting.

Why this answer

The most likely reason is that the unit file was edited but `systemctl daemon-reload` was not executed. When a service unit file is modified, systemd does not automatically reload the configuration; it continues to use the cached version until `systemctl daemon-reload` is run. This explains why `systemctl show` displays `Restart=no` despite the file containing `Restart=on-failure`.

Exam trap

Linux Foundation often tests the distinction between editing a unit file and reloading the daemon, trapping candidates who assume changes take effect immediately without running `systemctl daemon-reload`.

How to eliminate wrong answers

Option A is wrong because the `User=` directive does not override the `Restart=` directive; `User=` specifies the user under which the service runs, while `Restart=` controls the restart policy, and they are independent settings. Option C is wrong because whether a unit is enabled (i.e., configured to start at boot) has no effect on the current runtime restart policy shown by `systemctl show`; `Restart=` is applied regardless of enablement status. Option D is wrong because the `Restart=` directive is valid for all service types, including `Type=simple`; there is no restriction that limits it to specific types.

165
MCQeasy

A junior administrator needs to create a new empty file named report.txt in the current working directory. They want to ensure that if the file already exists, its contents are not altered. Which command should they run?

A.mkdir report.txt
B.echo > report.txt
C.cat > report.txt
D.touch report.txt
AnswerD

The touch command updates the access and modification timestamps of report.txt, and if the file does not exist, it creates an empty file. It does not modify the file's contents if it already exists, so it safely meets the requirement without risking data loss.

Why this answer

The touch command is designed to create empty files or update timestamps without modifying existing content. Redirection methods like echo > or cat > would truncate the file if it already exists, risking data loss. mkdir creates a directory, not a file. Therefore, touch is the correct choice for safely creating an empty file.

Exam trap

The trap here is assuming that any command that creates a file will also safely leave existing content untouched, when in fact redirection operators truncate files by default.

166
Drag & Dropmedium

Order the steps to create a new partition on a disk using fdisk.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to create a partition with fdisk is: first use 'n' to create a new partition, then specify the partition type and number (e.g., primary, logical) when prompted, then define the starting and ending sectors, and finally use 'w' to write the changes to the disk. Skipping or reordering steps can lead to errors or unintended configurations.

167
MCQmedium

A network administrator needs to block all incoming SSH traffic (port 22) from the 192.168.2.0/24 subnet. Which iptables command accomplishes this?

A.iptables -A INPUT -d 192.168.2.0/24 -p tcp --dport 22 -j DROP
B.iptables -A OUTPUT -d 192.168.2.0/24 -p tcp --sport 22 -j DROP
C.iptables -A INPUT -s 192.168.2.0/24 -j DROP
D.iptables -A INPUT -s 192.168.2.0/24 -p tcp --dport 22 -j DROP
AnswerD

Appending a rule to the INPUT chain with `-s 192.168.2.0/24` matches the source subnet, `-p tcp --dport 22` targets SSH, and `-j DROP` silently discards matching packets, satisfying the requirement to block all incoming SSH from that subnet.

Why this answer

It appends a rule to the INPUT chain that matches packets originating from the 192.168.2.0/24 subnet (-s 192.168.2.0/24) using TCP protocol with destination port 22 (--dport 22), and then drops them (-j DROP). This precisely blocks all incoming SSH traffic from that subnet while leaving other traffic unaffected.

Exam trap

The trap here is that candidates often confuse the -s and -d flags, or mistakenly apply the rule to the OUTPUT chain, thinking they need to block outgoing responses rather than incoming connection attempts.

How to eliminate wrong answers

Option A is wrong because it uses -d (destination) instead of -s (source), which would match packets destined to the 192.168.2.0/24 subnet, not packets coming from it. Option B is wrong because it adds a rule to the OUTPUT chain with --sport 22, which would block outgoing SSH responses from the local machine, not incoming SSH connections. Option C is wrong because it drops all traffic from the 192.168.2.0/24 subnet regardless of protocol or port, which is overly broad and would block legitimate traffic such as DNS or HTTP from that subnet.

168
MCQmedium

An administrator runs `ls -l` and sees a file entry whose permission string begins with a lowercase `l`. What does this indicate about the entry?

A.It is a symbolic link whose target is resolved when the link is accessed.
B.It is a named pipe used for inter-process communication.
C.It is a regular file that has the setuid bit enabled.
D.It is a block device node used for buffered disk access.
AnswerA

A leading l in the file type column denotes a symbolic link, a special file holding a pathname that the kernel resolves at access time. Unlike hard links, a symlink has its own inode and can point across filesystems, and it becomes dangling if the target path no longer exists.

Why this answer

The first character of the permission string encodes file type, and l specifically means symbolic link. Device nodes, regular files, and FIFOs each have their own distinct type character, so recognizing the type column is essential before choosing commands such as readlink, stat, or find -type l.

Exam trap

The trap here is reading the leading character as a permission rather than a file type indicator.

169
MCQmedium

An administrator is unable to SSH into the server from a remote host at 192.168.1.100. Based on the exhibited iptables rules, what is the most likely reason?

A.The SSH rule only allows connections from 10.0.1.0/24, and 192.168.1.100 is not in that subnet
B.SSH is not allowed from any source
C.The INPUT chain policy is ACCEPT, so SSH should be allowed
D.The DROP rule for SSH is not matching because of packet count zero
AnswerA

The second rule allows SSH only from 10.0.1.0/24, and the third rule drops all other SSH.

Why this answer

The exhibited iptables rules show an SSH rule that explicitly accepts incoming TCP traffic on port 22 only from the source subnet 10.0.1.0/24. The remote host at 192.168.1.100 is not within that subnet, so the SSH rule does not match, and the packet will fall through to the next rule or the default policy. Since no other rule permits SSH from 192.168.1.100, the connection is implicitly dropped or rejected, preventing SSH access.

Exam trap

The trap here is that candidates see the INPUT chain policy is ACCEPT and assume all traffic is allowed, overlooking that a more specific rule (like the SSH rule with a source restriction) can prevent traffic from non-matching sources, effectively overriding the default policy for that service.

How to eliminate wrong answers

Option B is wrong because the iptables rules do allow SSH from the specific subnet 10.0.1.0/24, so SSH is not disallowed from all sources. Option C is wrong because while the INPUT chain policy is ACCEPT, the packet must first match a rule; if a rule explicitly restricts SSH to a specific subnet, packets from other sources are not accepted by that rule and will be evaluated by subsequent rules or the default policy, which in this case does not permit the connection. Option D is wrong because a packet count of zero on a DROP rule simply indicates that no packets have matched that rule yet; it does not mean the rule is inactive or not matching—the rule will still match and drop packets that meet its criteria, and the zero count is irrelevant to whether SSH is allowed from 192.168.1.100.

170
MCQmedium

A user must change their password at next login per security policy. The admin wants to expire the password immediately. Which command accomplishes this?

A.passwd -f username
B.usermod -p '' username
C.chage -M 90 username
D.chage -d 0 username
AnswerD

`chage -d 0 username` sets the last-password-change date to the epoch, so the system treats the password as aged beyond its maximum lifetime and forces a change at next login. This directly satisfies the immediate-expiry constraint, unlike `passwd -e`, which achieves the same via a different flag.

Why this answer

The chage -d 0 username command sets the 'last password change' date to 0 (January 1, 1970), which forces the user to change their password at the next login. This is the standard Linux method to immediately expire a user's password without disabling the account.

Exam trap

LFCS often tests the confusion between password expiration (chage -d 0) and password aging policies (chage -M), or between passwd options and chage options, causing candidates to pick a command that sets a future expiration instead of immediate expiration.

How to eliminate wrong answers

Option A is wrong because passwd -f username only sets the 'force change' flag in some Unix variants (like Solaris), but on Linux it is not the correct way to expire a password; the -f option in Linux passwd is used to force a password change but is not the standard method and may not be available. Option B is wrong because usermod -p '' username sets the password field to an empty string, which effectively disables password authentication or sets a blank password, not expire it. Option C is wrong because chage -M 90 username sets the maximum password age to 90 days, which does not expire the password immediately; it only sets a future expiration.

171
MCQeasy

A system administrator needs to mount an ext4 filesystem with the options 'noatime' and 'errors=remount-ro'. Which mount command is correct?

A.mount -o noatime,errors=remount /dev/sda1 /mnt
B.mount -o noatime -o errors=remount-ro /dev/sda1 /mnt
C.mount -o atime=no,errors=remount-ro /dev/sda1 /mnt
D.mount -o noatime,errors=remount-ro /dev/sda1 /mnt
AnswerD

The -o flag passes a comma-separated option list to mount, so noatime and errors=remount-ro are applied together for this ext4 filesystem. The device and mount point follow in the correct order, satisfying both requested behaviours.

Why this answer

The `mount -o noatime,errors=remount-ro /dev/sda1 /mnt` command uses a single `-o` flag with a comma-separated list of mount options, which is the proper syntax for specifying multiple options. The `noatime` option disables updating the access time on reads, and `errors=remount-ro` tells the kernel to remount the filesystem as read-only if an I/O error is encountered, both of which are valid ext4 mount options.

Exam trap

The trap here is that candidates may incorrectly use multiple `-o` flags (as in option B) or mistype the `errors` option (as in option A), confusing the `remount-ro` syntax with the unrelated `remount` command, or they may assume `atime=no` is a valid alternative to `noatime` (as in option C).

How to eliminate wrong answers

Option A is wrong because it specifies `errors=remount` instead of `errors=remount-ro`; the correct option requires the `-ro` suffix to indicate remount as read-only. Option B is wrong because it uses two separate `-o` flags (`-o noatime -o errors=remount-ro`), which is invalid syntax; the mount command accepts only one `-o` option, and multiple options must be comma-separated within a single `-o` argument. Option C is wrong because `atime=no` is not a valid mount option; the correct syntax to disable access time updates is `noatime` (or `relatime` for relative updates), not `atime=no`.

172
MCQmedium

A junior admin runs 'ls -l' and sees permissions '-rwxrwxr-x' on a file. What is the octal representation?

A.755
B.770
C.775
D.777
AnswerC

The symbolic string `-rwxrwxr-x` maps each permission triad to its octal digit: owner `rwx` equals 7, group `rwx` equals 7, and others `r-x` equals 5, giving 775. This directly satisfies the stem's requirement to convert the displayed mode into its octal equivalent.

Why this answer

The permissions '-rwxrwxr-x' break down as: owner (rwx = 4+2+1 = 7), group (rwx = 4+2+1 = 7), others (r-x = 4+0+1 = 5). This gives the octal value 775. Option C is correct because it matches this calculation exactly.

Exam trap

The trap here is that candidates often misread the last three characters 'r-x' as 'rwx' or 'r--', leading them to choose 777 or 755 instead of correctly calculating 775.

How to eliminate wrong answers

Option A (755) is wrong because it represents owner rwx (7), group r-x (5), others r-x (5), which would require group permissions to be r-x, not rwx. Option B (770) is wrong because it represents owner rwx (7), group rwx (7), others --- (0), which would deny all permissions to others, but the file shows r-x for others. Option D (777) is wrong because it represents owner rwx (7), group rwx (7), others rwx (7), which would give write permission to others, but the file shows r-x (no write) for others.

173
MCQeasy

A system administrator is managing a web application running as a systemd service on a new Linux server. The application requires a specific environment variable, DATABASE_URL, to be set before starting. The administrator has created a custom service unit file at /etc/systemd/system/webapp.service with the following content: [Unit] Description=Web Application Service [Service] ExecStart=/usr/local/bin/webapp Restart=on-failure The administrator prefers to keep configuration separate from the unit file for easier updates. The service fails to start. Upon investigation, the administrator notices that the DATABASE_URL variable is not being passed to the process. What is the most appropriate course of action to ensure the environment variable is correctly set?

A.Add an Environment directive in the [Service] section: Environment=DATABASE_URL=value
B.Add EnvironmentFile=/etc/webapp.env in the [Service] section and place the variable in that file
C.Export the DATABASE_URL variable in the shell before running systemctl start webapp
D.Modify the ExecStart line to: ExecStart=/usr/bin/env DATABASE_URL=value /usr/local/bin/webapp
AnswerB

EnvironmentFile= satisfies the requirement to keep configuration outside the unit file, letting systemd read DATABASE_URL from /etc/webapp.env and inject it into the process environment at start. This is the native mechanism for separating variables from unit definitions.

Why this answer

Using EnvironmentFile allows the administrator to keep the DATABASE_URL variable in a separate file, which can be updated without modifying the unit file. Option A hardcodes the variable in the unit file, reducing flexibility. Option C only sets the variable in the current shell session and does not persist for the service.

Option D modifies ExecStart but is less standard and less maintainable than using EnvironmentFile.

174
MCQmedium

A Linux server's boot process fails after a kernel upgrade. The GRUB2 menu appears, but selecting the newest kernel panics. You need to boot the previous kernel temporarily to recover the system. Which command should you use at the GRUB2 menu to edit the selected entry's boot parameters?

A.Press 'a' to append parameters to the kernel line, then press Enter to boot.
B.Press 'e' to edit the selected menu entry, then modify the 'linux' line and press Ctrl+X to boot.
C.Press 'c' to enter the GRUB command line, then run 'boot' with the previous kernel path.
D.Press 'Tab' to list available kernels, then type the kernel version and press Enter.
AnswerB

In GRUB2, pressing 'e' allows editing the selected menu entry. You can modify the kernel command line on the 'linux' line, for example to change the root device or add 'systemd.unit=rescue.target'. After editing, Ctrl+X boots the modified entry. This is the standard method to temporarily alter boot parameters without making permanent changes.

Why this answer

To temporarily modify boot parameters in GRUB2, you edit the menu entry by pressing 'e', adjust the kernel command line, and boot with Ctrl+X. This allows booting an older kernel or adding options like 'systemd.unit=emergency.target' without permanent changes. The other methods are either for GRUB Legacy or incorrect for this purpose.

Exam trap

The trap here is confusing GRUB Legacy's 'a' key for appending parameters with GRUB2's 'e' key for editing the entire entry.

175
MCQhard

An administrator is troubleshooting intermittent connectivity issues. Running 'ping -c 100 -i 0.2 10.0.0.1' shows about 5% packet loss. What is the primary purpose of the '-i 0.2' option?

A.It sets the TTL to 0.2
B.It sets the timeout to 0.2 seconds
C.It sets the packet size to 0.2 bytes
D.It sets the interval between pings to 0.2 seconds
AnswerD

The -i flag controls the delay between successive ping packets, so 0.2 sets a 200 ms gap rather than the default one second. This accelerates the 100-packet run, letting the administrator gather loss statistics quickly while still detecting the intermittent connectivity.

Why this answer

The '-i 0.2' option in the ping command sets the interval between sending ICMP Echo Request packets to 0.2 seconds. This allows the administrator to send pings more frequently than the default (typically 1 second), which helps in detecting intermittent connectivity issues over a shorter test duration. By sending 100 packets at a 0.2-second interval, the test completes in about 20 seconds, making it practical for troubleshooting transient packet loss.

Exam trap

The trap here is that candidates confuse '-i' with timeout or TTL options, mistakenly thinking it controls how long to wait for a reply rather than the spacing between packet transmissions.

How to eliminate wrong answers

Option A is wrong because '-i' does not set the TTL (Time to Live); TTL is set with the '-t' option in ping. Option B is wrong because '-i' controls the interval between packets, not the timeout; the timeout for waiting for a reply is set with '-W' (or '-w' for a deadline). Option C is wrong because '-i' does not affect packet size; packet size is set with '-s' (e.g., '-s 1472' for a specific payload size).

176
MCQhard

A service unit has the directive 'ExecStartPre=/bin/true' and 'ExecStart=/usr/bin/myapp'. What is the effect of ExecStartPre?

A.It sets an environment variable.
B.It runs a post-start script.
C.It runs a pre-start script; if it fails, the service still starts.
D.It runs a pre-start script; if it fails, the service is not started.
AnswerD

ExecStartPre runs before ExecStart, and systemd requires each ExecStartPre command to exit successfully before proceeding. Since /bin/true always returns zero, the service starts normally; had it failed, systemd would mark the unit failed and skip ExecStart, satisfying the stem's dependency constraint.

Why this answer

ExecStartPre is a systemd directive that specifies a command to run before the main ExecStart command. If the ExecStartPre command fails (returns a non-zero exit code), systemd will not proceed to start the service, unless the '-' prefix is used to ignore failure. Here, /bin/true always succeeds (exit code 0), so it does not block the service, but the directive itself is designed to enforce a pre-start check.

Exam trap

The trap here is that candidates may confuse ExecStartPre with ExecStartPost or assume that a pre-start script failure is non-fatal, but systemd strictly enforces that a failed ExecStartPre prevents the service from starting unless explicitly configured otherwise.

How to eliminate wrong answers

Option A is wrong because ExecStartPre does not set environment variables; that is the role of Environment or EnvironmentFile directives. Option B is wrong because ExecStartPre runs before the main process, not after; ExecStartPost is the directive for post-start scripts. Option C is wrong because it states the service still starts if ExecStartPre fails; by default, systemd treats a failed ExecStartPre as a fatal error and does not start the service, unless the command is prefixed with '-' to allow failure.

177
Multi-Selectmedium

A Linux server is experiencing performance issues. You need to identify which processes are consuming the most CPU and memory in real-time. Which two commands can provide this information interactively? (Choose two.)

Select 2 answers
A.iostat
B.top
C.vmstat
D.htop
E.ps aux
AnswersB, D

top is an interactive process viewer that displays a real-time list of processes sorted by CPU usage by default. It shows CPU and memory usage per process and updates periodically. It allows interactive commands like sorting by memory (press M) and killing processes. This directly meets the requirement for real-time monitoring of CPU and memory.

Why this answer

top and htop are interactive process viewers that display real-time CPU and memory usage per process. vmstat and iostat provide system-wide statistics but lack per-process detail and interactivity. ps aux gives a static snapshot, not real-time updates. Therefore, top and htop are the correct choices.

Exam trap

The trap here is assuming that ps aux provides real-time updates, when it only shows a static snapshot at the moment of execution.

178
Multi-Selecteasy

Which TWO commands can be used to display the contents of a text file that has been compressed with gzip without decompressing it to disk?

Select 2 answers
A.xzcat file.gz
B.gzip -l file.gz
C.zcat file.gz
D.gunzip -c file.gz
E.bzcat file.gz
AnswersC, D

`zcat` decompresses gzip data to standard output, leaving the `.gz` file untouched on disk. This satisfies the stem's constraint of viewing contents without writing a decompressed copy, streaming the uncompressed bytes straight to the terminal for inspection.

Why this answer

Option C, zcat file.gz, is correct because zcat is functionally equivalent to gunzip -c and writes the decompressed contents of a gzip file directly to standard output, leaving no decompressed file on disk. Option D, gunzip -c file.gz, is correct because the -c (--stdout) flag tells gunzip to send the decompressed data to standard output instead of replacing the .gz file with an uncompressed one. Option A, xzcat file.gz, is wrong because xzcat handles files compressed with xz/lzma, not gzip format.

Option B, gzip -l file.gz, is wrong because -l only lists the compressed and uncompressed sizes and ratio; it does not display the file's contents. Option E, bzcat file.gz, is wrong because bzcat decompresses bzip2 files, not gzip files.

Exam trap

The trap here is that candidates often confuse compression tools and their corresponding cat utilities (e.g., `xzcat` for xz, `bzcat` for bzip2, `zcat` for gzip), leading them to select a command that works on a different compression format.

179
MCQmedium

A Linux server has two interfaces: enp3s0 (192.168.10.5/24) and enp4s0 (10.0.0.5/24). The default route is via 192.168.10.1. A junior admin adds a static route to 10.1.0.0/16 via 10.0.0.1 using the command: ip route add 10.1.0.0/16 via 10.0.0.1. After this, users report that traffic to 10.1.1.0/24 fails. Which command should the administrator run to confirm that the kernel is selecting the correct route and interface for destination 10.1.1.10?

A.ip route get 10.1.1.10
B.ip -s link show enp4s0
C.ip route show table all
D.traceroute -n 10.1.1.10
AnswerA

This command asks the kernel which route and source address it would use for the destination, showing the resolved interface and gateway. In this scenario, it would reveal whether the static route via 10.0.0.1 is chosen or whether the default route via 192.168.10.1 is used instead, directly diagnosing the reported failure.

Why this answer

The kernel chooses routes based on longest prefix match and metric. To verify which route and interface are selected for a specific destination, the ip route get command is used. It performs a route lookup and displays the resolved source address, gateway, and output interface, directly answering why traffic to 10.1.1.0/24 may fail despite a static route being added.

Exam trap

The trap here is assuming that adding a static route guarantees it will be used, without verifying the kernel's actual route selection for the destination.

180
Multi-Selecteasy

Which TWO methods can be used to set a static IPv4 address on a CentOS 7 system? (Choose two.)

Select 2 answers
A.Run the command 'systemctl set-static-ip eth0 192.168.1.100/24'
B.Use 'ip addr add 192.168.1.100/24 dev eth0'
C.Use the nmtui utility
D.Edit the /etc/network/interfaces file
E.Edit the /etc/sysconfig/network-scripts/ifcfg-eth0 file directly
AnswersC, E

The nmtui text interface writes persistent configuration into NetworkManager connection profiles, satisfying CentOS 7's requirement for a static IPv4 address that survives reboot. Unlike temporary `ip addr` changes, nmtui edits the connection's ipv4.method to manual and stores the address, prefix, gateway and DNS, which NetworkManager then applies at every activation.

Why this answer

Nmtui is a text-based user interface for NetworkManager, which is the default networking service on CentOS 7. It allows you to interactively configure network interfaces, including setting a static IPv4 address, without needing to manually edit configuration files. Option E is correct because the ifcfg-eth0 file in /etc/sysconfig/network-scripts is the traditional, direct configuration method for network interfaces on CentOS 7, where you can set BOOTPROTO=static and define IPADDR, PREFIX, and GATEWAY.

Exam trap

The trap here is that candidates often confuse temporary runtime commands like 'ip addr add' with permanent configuration methods, or they assume that systemctl can be used for network configuration because it is a common system administration tool.

181
Multi-Selectmedium

A system administrator is troubleshooting a custom systemd service that fails to start. They want to override a setting in the service's unit file without modifying the original file in /usr/lib/systemd/system/. Which two methods can be used to create a drop-in override? (Choose two.)

Select 2 answers
A.Edit the unit file directly in /usr/lib/systemd/system/ and run systemctl daemon-reload.
B.Create a file in /etc/systemd/system/<service>.service.d/ with a .conf extension.
C.Copy the original unit file to /etc/systemd/system/ and edit it there.
D.Run systemctl edit <service>.service and add directives in the editor.
E.Use systemctl mask <service>.service to create an override.
AnswersB, D

Drop-in directories under /etc/systemd/system/<service>.service.d/ are read by systemd and override the original unit file. Files with a .conf extension in this directory are automatically included. This method is recommended for local overrides because it does not touch the vendor-provided unit file and survives package updates.

Why this answer

The two correct methods are creating a drop-in directory with a .conf file and using systemctl edit. Both place overrides in /etc/systemd/system/<service>.service.d/ and are applied after daemon-reload. They preserve the original unit file and are the intended way to customize services without conflicting with package updates.

Other methods either replace the unit, mask it, or modify vendor files.

Exam trap

The trap here is thinking that copying the entire unit file to /etc/systemd/system/ is the same as a drop-in override, when it actually replaces the unit and can cause update conflicts.

182
Multi-Selecteasy

Which two commands can be used to set password expiration policies for a user?

Select 2 answers
A.usermod
B.passwd
C.chage
D.expiry
E.pwconv
AnswersB, C

The passwd command, via its -e, -n, -x, -w and -i options, sets password expiration fields such as maximum age, minimum age and warning period for a user. This satisfies the requirement for a command that configures password expiration policy.

Why this answer

The `passwd` command (option B) can set password expiration policies for a user via options such as `-e` (expire immediately), `-n` (minimum days), `-x` (maximum days), `-w` (warning days), and `-i` (inactive days), e.g., `passwd -x 90 -n 7 -w 14 user`. The `chage` command (option C) is specifically designed to modify password aging information in `/etc/shadow`, using flags like `-M` (max days), `-m` (min days), `-W` (warn days), `-I` (inactive days), and `-E` (account expiration date), e.g., `chage -M 90 -W 14 user`. The other options do not belong: `usermod` (A) manages account properties like groups, shell, and home directory but does not set password aging fields; `expiry` (D) is not a standard Linux command for this purpose; and `pwconv` (E) creates or updates `/etc/shadow` from `/etc/passwd` rather than setting expiration policies.

Exam trap

The trap here is that candidates often confuse `usermod` with `chage` because `usermod` can lock accounts, but it cannot set password aging parameters like maximum days or warning periods.

183
MCQmedium

A company follows the principle of least privilege. Several developers need sudo access to run specific commands like systemctl and journalctl. What is the best practice for granting this access?

A.Use 'usermod -a -G sudo' for each developer and edit /etc/sudoers manually with visudo
B.Create a new group 'devops', add developers to it, and create a sudoers drop-in file with rules for specific commands
C.Add all developers to the 'wheel' group and configure %wheel ALL=(ALL) ALL
D.Edit /etc/sudoers directly to add each developer username with command restrictions
AnswerB

A dedicated group with a sudoers drop-in file scopes privileges to named binaries, satisfying least privilege without granting full root or editing the main sudoers file. Command-level rules let developers run systemctl and journalctl only, and group membership simplifies later revocation.

Why this answer

It follows the principle of least privilege by creating a dedicated 'devops' group and using a sudoers drop-in file (e.g., /etc/sudoers.d/devops) to grant only specific commands like systemctl and journalctl. This avoids modifying the main /etc/sudoers file directly, which is error-prone, and ensures that developers have no more privileges than necessary. The drop-in file approach is the recommended best practice for maintainability and security.

Exam trap

The trap here is that candidates often default to adding users to the 'sudo' or 'wheel' group for convenience, overlooking the principle of least privilege and the proper use of sudoers drop-in files for command-specific restrictions.

How to eliminate wrong answers

Option A is wrong because using 'usermod -a -G sudo' adds developers to the 'sudo' group, which typically grants full root access via %sudo ALL=(ALL:ALL) ALL, violating least privilege. Option C is wrong because adding developers to the 'wheel' group with %wheel ALL=(ALL) ALL grants unrestricted root access, which is excessive and insecure. Option D is wrong because editing /etc/sudoers directly is error-prone and not scalable; the best practice is to use a drop-in file in /etc/sudoers.d/ for granular command restrictions.

184
MCQmedium

A Linux server's primary interface is ens3. Administrators report that after a recent reboot, the server's hostname resolves to 127.0.1.1 instead of its static address 203.0.113.25. The file /etc/hosts currently contains only the default '127.0.0.1 localhost' line. Which single change will make the hostname resolve to 203.0.113.25 for local lookups while leaving DNS resolution for all other names untouched?

A.Add the line '127.0.1.1 server1.example.com server1' to /etc/hosts.
B.Add 'hosts: dns files' to /etc/nsswitch.conf so DNS is consulted before the hosts file.
C.Add an A record for server1.example.com pointing to 203.0.113.25 in the zone file on the authoritative DNS server.
D.Add the line '203.0.113.25 server1.example.com server1' to /etc/hosts.
AnswerD

The hosts file is consulted before DNS by the default nsswitch.conf ordering, so adding the static address with the hostname makes local resolution return 203.0.113.25. This is the standard fix when a host needs its own FQDN and short name mapped to a routable address rather than the loopback alias, and it does not affect resolution of any other domain.

Why this answer

Local name resolution follows the order defined in nsswitch.conf, which by default checks the hosts file before DNS. Because the hosts file only contains the loopback line, the hostname has no local mapping. Adding a hosts entry that pairs the hostname and FQDN with the actual interface address makes the machine resolve its own name to 203.0.113.25 without disturbing DNS lookups for any other domain.

Exam trap

The trap here is assuming the loopback alias 127.0.1.1 is the correct fix for any hostname resolution problem, when the requirement is a specific routable address.

185
Multi-Selectmedium

Which THREE are built-in chains in the iptables filter table? (Choose three.)

Select 3 answers
A.POSTROUTING
B.INPUT
C.OUTPUT
D.FORWARD
E.PREROUTING
AnswersB, C, D

INPUT is one of the three built-in chains of the iptables filter table, alongside FORWARD and OUTPUT. It processes packets destined for the local host itself, satisfying the stem's requirement for a built-in filter chain rather than a user-defined one.

Why this answer

The filter table in iptables is used for packet filtering decisions based on IP addresses, ports, and protocols. Its built-in chains are INPUT (for packets destined for the local system), OUTPUT (for packets originating from the local system), and FORWARD (for packets routed through the system). These three chains allow you to control traffic at different points in the packet flow.

Exam trap

The trap here is that candidates often confuse the filter table's chains with those of the nat table (PREROUTING, POSTROUTING) because all chains are used in packet traversal, but only INPUT, OUTPUT, and FORWARD belong to the filter table.

186
MCQeasy

An administrator wants to force a user to change their password at next login. Which command should be used?

A.passwd -l user
B.passwd -e user
C.chage -m 0 user
D.usermod -p '!' user
AnswerB

passwd -e user expires the account's password immediately, setting the shadow field so the next login forces a change. This directly satisfies the requirement to force a password change at next login, unlike -l or -d which lock or clear it.

Why this answer

The `passwd -e user` command immediately expires the user's password, forcing them to change it at the next login. This is the standard method to achieve this requirement on Linux systems.

Exam trap

The trap here is confusing account locking (`passwd -l` or `usermod -p '!'`) with password expiration, as both prevent normal login but only expiration forces a password change at next login.

How to eliminate wrong answers

Option A is wrong because `passwd -l user` locks the user account, preventing any login, rather than forcing a password change. Option C is wrong because `chage -m 0 user` sets the minimum number of days between password changes to 0, which allows the user to change their password immediately but does not force a change at next login. Option D is wrong because `usermod -p '!' user` sets the password field to an invalid value (starting with '!'), which effectively locks the account, not forcing a password change.

187
MCQeasy

A junior administrator needs to identify the UUID of the ext4 filesystem on /dev/nvme0n1p2 so it can be referenced in /etc/fstab instead of the device path. Which command displays that UUID?

A.lsblk -o NAME,SIZE,TYPE
B.fdisk -l /dev/nvme0n1p2
C.mount | grep nvme0n1p2
D.blkid /dev/nvme0n1p2
AnswerD

blkid reads the filesystem superblock and prints the UUID, type, and label for the given device. It is the standard, low-level way to obtain a filesystem UUID for use in /etc/fstab. The other tools either report partition-table GUIDs or require the filesystem to be mounted.

Why this answer

blkid probes the device and reports the filesystem UUID stored in the ext4 superblock, which is exactly the value needed for an fstab entry like UUID=xxxx-... /data ext4 defaults 0 2. It works whether or not the filesystem is mounted. The other commands either display partition-table metadata or require mounting and still do not print the UUID.

Exam trap

The trap here is confusing the partition-table PARTUUID shown by partitioning tools with the filesystem UUID reported by blkid.

188
MCQhard

Refer to the exhibit. An administrator tries to start myapp.service with 'systemctl start myapp.service' but receives 'Failed to start myapp.service: Unit myapp.service is not loaded properly: Invalid argument'. What is the most likely issue?

A.The unit file has a syntax error.
B.The service name is misspelled.
C.The ExecStart path is invalid.
D.The service is masked.
AnswerA

systemd parses unit files strictly; a malformed directive or invalid argument causes the parser to reject the unit, producing 'not loaded properly: Invalid argument'. The daemon cannot build the unit's dependency graph until the syntax is corrected.

Why this answer

The error 'Unit myapp.service is not loaded properly: Invalid argument' indicates that systemd attempted to parse the unit file but encountered a syntax error or an invalid directive. This typically happens when a key-value pair in the unit file is malformed, such as a missing equals sign, an unsupported option, or a value that does not conform to systemd's expected format. Unlike a runtime failure (e.g., a missing ExecStart binary), this error occurs during the loading phase, before any execution attempt.

Exam trap

Linux Foundation often tests the distinction between loading-phase errors (syntax, invalid argument) and runtime errors (execution failures, missing binaries), causing candidates to confuse a malformed unit file with a broken ExecStart path.

How to eliminate wrong answers

Option B is wrong because a misspelled service name would produce a 'Unit not found' error, not an 'Invalid argument' error, as systemd would not find a matching unit file. Option C is wrong because an invalid ExecStart path (e.g., a nonexistent binary) would cause a runtime failure after the unit is loaded, producing an error like 'main process exited, code=exited, status=203/EXEC' or 'Failed at step EXEC', not a loading-phase syntax error. Option D is wrong because a masked service would produce 'Failed to start myapp.service: Unit myapp.service is masked.' or 'Unit file is masked.', clearly indicating the masked state rather than an invalid argument.

189
Multi-Selecteasy

A system administrator needs to ensure that a custom service named 'myapp.service' starts automatically after a reboot and also restarts automatically no matter how the service stops, even if it exits normally. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Run 'systemctl mask myapp.service' to prevent manual stops.
B.Run 'systemctl enable myapp.service' to enable the service.
C.Set 'Restart=on-failure' in the [Service] section of the service file.
D.Set 'Restart=always' in the [Service] section of the service file.
E.Add 'After=network.target' to the [Unit] section of the service file.
AnswersB, D

Enabling the unit creates the systemd symlink under the appropriate target's .wants directory, so systemd starts myapp.service automatically at boot. This satisfies the reboot-persistence constraint, complementing the restart behaviour configured separately in the unit file.

Why this answer

Option B is correct because 'systemctl enable myapp.service' creates the necessary symlinks (typically under /etc/systemd/system/*.wants/) so systemd starts the unit automatically at boot, satisfying the reboot requirement. Option D is correct because 'Restart=always' in the [Service] section instructs systemd to restart the service regardless of exit status, including a clean exit code 0, which matches the requirement that it restart no matter how it stops. Option C is incorrect because 'Restart=on-failure' only restarts on non-zero exit codes, signals, or timeouts, so a normal exit would not trigger a restart.

Option A is incorrect because 'systemctl mask' links the unit to /dev/null and prevents it from being started at all, the opposite of the desired behavior. Option E is incorrect because 'After=network.target' only orders startup relative to the network target and does not enable boot startup or automatic restarts.

Exam trap

LFCS often tests the distinction between 'Restart=on-failure' and 'Restart=always' — candidates pick on-failure assuming it covers all cases, but it explicitly excludes clean exits, which the question calls out.

190
MCQmedium

After creating an XFS filesystem on /dev/sdb1, an admin mounts it and writes data. Later, they run 'xfs_info /mnt/data' and see the filesystem was created with default settings. What is the default inode size for XFS on a typical Linux system?

A.512 bytes
B.128 bytes
C.4096 bytes
D.256 bytes
AnswerD

XFS defaults to a 256-byte inode on typical Linux systems, which is what `xfs_info` reports when `mkfs.xfs` runs without an `-i size=` override. This satisfies the stem's constraint of a filesystem created with default settings, so 256 bytes is the value observed.

Why this answer

The default inode size for XFS on a typical Linux system is 256 bytes. This is set at filesystem creation time and provides a balance between supporting extended attributes (like ACLs and SELinux contexts) and minimizing metadata overhead. The `xfs_info` command confirms the default settings, which include this 256-byte inode size.

Exam trap

The trap here is that candidates often confuse the default inode size of XFS (256 bytes) with that of ext4 (128 bytes) or mistake the block size (4096 bytes) for the inode size, leading them to select option B or C.

How to eliminate wrong answers

Option A is wrong because 512 bytes is not the default inode size for XFS; it is an optional larger size used when many extended attributes are needed, but it increases metadata overhead. Option B is wrong because 128 bytes is the default inode size for ext4, not XFS; XFS uses a larger inode to accommodate its B-tree-based metadata structures. Option C is wrong because 4096 bytes is the default block size for XFS, not the inode size; confusing block size with inode size is a common mistake.

191
MCQmedium

An administrator needs to view a list of users who have logged in recently. Which command provides this information?

A.users
B.who
C.finger
D.last
AnswerD

last reads /var/log/wtmp, which records every login and logout session, so it lists users who logged in recently with timestamps. who and w show only currently active sessions, and lastlog reports each account's most recent login only.

Why this answer

The `last` command reads the `/var/log/wtmp` file to display a list of all users who have logged in and out, including recent login sessions. This makes it the correct choice for viewing a history of recent logins, as it provides timestamps, duration, and originating host information.

Exam trap

The trap here is that candidates often confuse `who` or `users` (which show current sessions) with `last` (which shows historical login records), leading them to pick a command that only displays active users rather than recent login history.

How to eliminate wrong answers

Option A is wrong because `users` only shows the usernames of currently logged-in users, not a history of recent logins. Option B is wrong because `who` displays information about currently logged-in users (including terminal and login time), but does not show historical login records. Option C is wrong because `finger` can show a user's last login time from `/var/log/lastlog`, but it does not provide a comprehensive list of all recent login events and is not the standard command for viewing a login history.

192
Multi-Selectmedium

Which TWO commands can be used to display real-time process resource usage on a Linux system? (Choose two.)

Select 2 answers
A.vmstat 1
B.htop
C.ps -aux
D.free -h
E.top
AnswersB, E

htop provides an interactive, colour-coded real-time view of per-process CPU, memory and swap consumption, refreshing continuously. It satisfies the stem's requirement to display live process resource usage, unlike static tools such as ps, which capture only a single snapshot.

Why this answer

Option B (htop) is correct because htop is an interactive process viewer that continuously refreshes and displays real-time CPU, memory, and per-process resource usage, updating by default every second. Option E (top) is correct because top is the classic interactive monitor that dynamically refreshes process and resource statistics in real time, also defaulting to a periodic update interval. Option A (vmstat 1) reports virtual memory, CPU, and I/O statistics every 1 second, but it summarizes system-wide counters rather than per-process resource usage, so it does not display process-level real-time usage.

Option C (ps -aux) is a snapshot command that lists processes at the moment of execution and then exits, providing no continuous real-time updates. Option D (free -h) only shows current memory and swap utilization in human-readable units and does not display process resource usage at all.

Exam trap

The trap here is that candidates often confuse static commands like ps and free with real-time monitoring tools, mistakenly thinking that any command showing resource data qualifies as real-time, when only those with continuous updates (like top and htop) meet the requirement.

193
MCQmedium

Refer to the exhibit. The output of 'ip addr show' reveals that eth0 is in state DOWN and has no IPv4 address. Which command is most likely to bring the interface up and obtain an IP via DHCP?

A.ip link set eth0 up
B.ifup eth0
C.ip route add default via 192.168.1.1 dev eth0
D.ip link set dev eth0 up
AnswerB

ifup invokes the network configuration scripts, which will start DHCP based on config.

Why this answer

The `ifup` command is a distribution-agnostic tool that reads the interface configuration from files (e.g., `/etc/network/interfaces` on Debian/Ubuntu or `/etc/sysconfig/network-scripts/ifcfg-eth0` on RHEL/CentOS) and brings the interface up while automatically initiating a DHCP client (e.g., dhclient or dhcpcd) to obtain an IPv4 address. This is the standard way to activate a network interface with its configured addressing method, including DHCP, in a single step.

Exam trap

The trap here is that candidates often assume `ip link set eth0 up` (options A or D) is sufficient to obtain an IP via DHCP, but this command only activates the link layer and does not invoke any DHCP client, leaving the interface without an IP address.

How to eliminate wrong answers

Option A is wrong because `ip link set eth0 up` only changes the interface's administrative state to UP but does not trigger any DHCP client or assign an IP address; the interface will remain without an IPv4 address unless a separate DHCP command is run. Option C is wrong because `ip route add default via 192.168.1.1 dev eth0` adds a default gateway route, but this command requires the interface to already have an IP address and be in the UP state; it does not bring the interface up nor obtain an IP via DHCP. Option D is wrong because `ip link set dev eth0 up` is functionally identical to option A (just a different syntax) and similarly does not initiate DHCP or assign an IP address.

194
Multi-Selecteasy

Which TWO commands can be used to check whether a systemd service is currently running?

Select 2 answers
A.systemctl status service
B.systemctl list-units --state=running
C.systemctl is-active service
D.systemctl is-enabled service
E.systemctl show service
AnswersA, C

'systemctl status' queries the unit's runtime state and prints Active: active (running) or inactive (dead), along with the main PID and recent log lines. This directly reports whether the service is currently running, satisfying the check required by the stem.

Why this answer

Option A, `systemctl status service`, is correct because it queries the service's runtime state and displays the Active line (e.g., `Active: active (running)`), directly showing whether the unit is currently running. Option C, `systemctl is-active service`, is correct because it prints the unit's active state (typically `active` or `inactive`) and returns exit code 0 when the service is running, making it ideal for scripted checks. Option B, `systemctl list-units --state=running`, lists all running units system-wide rather than confirming one specific service, so it is not a targeted check.

Option D, `systemctl is-enabled service`, only reports whether the unit is enabled to start at boot, not whether it is currently running. Option E, `systemctl show service`, dumps all unit properties by default and does not by itself answer the running-state question without filtering for ActiveState.

Exam trap

The trap here is that candidates often confuse 'is-enabled' (boot-time configuration) with 'is-active' (current runtime state), or think that listing all running units (option B) is a valid way to check a specific service, when in fact it requires additional parsing and does not directly answer the question.

195
MCQmedium

A support engineer must copy the directory /srv/appdata, including every subdirectory, hidden file, and preserved permission bits and timestamps, to /backup/appdata on the same host. Which command accomplishes this?

A.mv /srv/appdata /backup/appdata
B.rsync /srv/appdata /backup/appdata
C.cp -a /srv/appdata /backup/appdata
D.cp -r /srv/appdata /backup/appdata
AnswerC

The -a flag is archive mode, equivalent to -dR --preserve=all, so it recurses into subdirectories, copies symlinks as symlinks, and preserves mode, ownership where permitted, timestamps, and extended attributes. That matches the requirement to retain hidden files, permissions, and times in a single invocation on the same host.

Why this answer

Archive-mode copy is the correct tool when a directory tree must be duplicated with metadata intact, since it combines recursion with preservation of permissions, ownership, timestamps, and symlink structure. Recursive-only copy drops metadata, relocation deletes the source, and a bare rsync invocation without archive or recursive flags will not descend into directories.

Exam trap

The trap here is assuming any recursive copy preserves metadata, when only archive mode does so reliably.

196
MCQmedium

A Linux server acting as a VPN gateway uses an nftables ruleset in the inet filter table. The administrator wants all forwarded traffic from the 10.8.0.0/24 VPN subnet to the 192.168.50.0/24 LAN to be accepted, while dropping any other forwarded traffic. Which nftables rule should be added to the forward chain to accomplish this?

A.nft add rule inet filter forward ip daddr 10.8.0.0/24 ip saddr 192.168.50.0/24 accept
B.nft add rule inet filter forward ip saddr 10.8.0.0/24 ip daddr 192.168.50.0/24 accept
C.nft add rule inet filter forward ip saddr 10.8.0.0/24 ip daddr 192.168.50.0/24 drop
D.nft add rule inet filter input ip saddr 10.8.0.0/24 ip daddr 192.168.50.0/24 accept
AnswerB

This rule matches forwarded packets whose source is in the VPN subnet and destination is in the LAN, then accepts them. Because nftables evaluates rules in order and the final policy can be drop, placing this accept before a drop rule or default drop policy correctly permits only the intended traffic while blocking everything else.

Why this answer

Forwarded traffic between two networks is evaluated in the forward chain of the inet filter table. The rule must use ip saddr for the VPN subnet and ip daddr for the LAN subnet with an accept verdict. Placing this rule before any default drop policy permits only the specified flow, and other forwarded traffic is refused by the chain policy.

Exam trap

The trap here is confusing the input chain with the forward chain, when routed traffic between two remote networks is only evaluated by the forward chain.

197
Multi-Selectmedium

Which TWO commands can be used to display the contents of a text file page by page? (Select two.)

Select 2 answers
A.cat file.txt
B.head file.txt
C.more file.txt
D.less file.txt
E.tail file.txt
AnswersC, D

`more file.txt` paginates output, displaying one screenful at a time and pausing for user input before continuing. This directly satisfies the stem's requirement to view a text file page by page, unlike non-paginating tools such as `cat`, which dump the entire file at once.

Why this answer

Option C, more file.txt, is correct because more is a pager that displays a text file one screenful at a time, pausing at each page until the user presses Space or Enter to continue. Option D, less file.txt, is also correct because less is a more advanced pager that likewise presents file contents page by page, while additionally allowing backward scrolling and searching. Both commands satisfy the requirement of paging through a file's contents rather than dumping them all at once.

In contrast, A (cat file.txt) writes the entire file to standard output in one continuous stream, B (head file.txt) shows only the first 10 lines by default, and E (tail file.txt) shows only the last 10 lines by default, so none of these paginate the output.

Exam trap

The trap here is that candidates might confuse `cat` (which dumps all content) with a pager, or think `head` or `tail` can show the entire file page by page, but they only show a fixed number of lines from the beginning or end.

198
Multi-Selecthard

Which THREE conditions must be met for a Linux system to function as a router between two networks?

Select 3 answers
A.Each interface has an IP address in the respective subnet
B.IP forwarding is enabled (net.ipv4.ip_forward = 1)
C.Both interfaces have the same MAC address
D.iptables rules allow forwarding (FORWARD chain policy or rules)
E.The system is configured as the default gateway for both networks
AnswersA, B, D

The router must have an IP in each network to send/receive packets.

Why this answer

Each interface must have an IP address in its respective subnet for the Linux system to receive packets from that network and forward them to the other. Without an IP address in the subnet, the interface cannot participate in ARP resolution or routing decisions for that network.

Exam trap

The trap here is that candidates often think a router must be the default gateway for both networks, but in reality, it only needs to have IP addresses in each subnet and proper routing entries; the default gateway is a client-side setting, not a router requirement.

199
Multi-Selectmedium

Which TWO commands can be used to display the routing table on a Linux system?

Select 2 answers
A.route -n
B.ip route show
C.ip addr show
D.arp -a
E.ss -tln
AnswersA, B

The legacy net-tools command queries the kernel routing table directly and prints it numerically with -n, avoiding DNS lookups. It satisfies the stem's requirement to display routes on systems where net-tools remains installed, though iproute2 has largely superseded it.

Why this answer

The `route -n` command displays the kernel IP routing table with numeric addresses, showing destination, gateway, netmask, and interface. The `ip route show` command is the modern equivalent from the iproute2 suite, which also displays the routing table with more detailed information. Both are standard tools for viewing routing decisions on a Linux system.

Exam trap

The trap here is that candidates often confuse `ip addr show` (which displays interface addresses) with `ip route show` (which displays routes), or mistake `arp -a` for a routing command because both involve network layer information.

200
MCQmedium

A custom service requires that the network is fully operational before it starts. Which directive should be added to the [Unit] section of the service's unit file to ensure this dependency?

A.After=network-online.target
B.Requires=network.target
C.Wants=network-online.target
D.After=network.target
AnswerA

`After=network-online.target` orders the unit's start after the network-online target is reached, satisfying the requirement that networking be fully operational first. `After=` alone only sequences startup; it does not pull the target in, so `Wants=network-online.target` is typically paired with it.

Why this answer

`After=network-online.target` ensures the service starts only after the network is fully operational, including IP address assignment and connectivity. This target is reached when network managers like systemd-networkd or NetworkManager confirm the network is online, making it suitable for services that require active network interfaces.

Exam trap

The trap here is that candidates confuse `network.target` (which is reached early and does not guarantee network readiness) with `network-online.target` (which waits for full network availability), leading them to pick option D or B incorrectly.

How to eliminate wrong answers

Option B is wrong because `Requires=network.target` only declares a dependency that the network target must be active, but it does not enforce ordering; the service could start before the network is fully online. Option C is wrong because `Wants=network-online.target` is a weaker dependency that does not guarantee the network is online before the service starts; it only attempts to start the target without failing if it cannot be reached. Option D is wrong because `After=network.target` orders the service after the basic network target, but `network.target` itself is reached early during boot before the network is fully configured, so the service may start before interfaces are ready.

201
Multi-Selectmedium

Which TWO commands can be used to check the status of the sshd service on a system using systemd?

Select 2 answers
A.systemctl list-units --type=service
B.systemctl is-active sshd
C.systemctl is-enabled sshd
D.systemctl cat sshd
E.systemctl status sshd
AnswersB, E

Returns active/inactive/failed status.

Why this answer

`systemctl is-active sshd` directly queries systemd to report whether the sshd service is currently in an active (running) state, returning a simple exit code and text output (e.g., 'active' or 'inactive'). Option E is correct because `systemctl status sshd` provides a comprehensive view of the service's current state, including whether it is active, its PID, recent log entries, and cgroup details, making it a standard command for checking service health on systemd-based systems.

Exam trap

The trap here is that candidates confuse `is-enabled` (boot-time configuration) with `is-active` (current runtime state), or they assume `list-units` is a valid status check when it actually requires additional filtering to isolate a specific service.

202
MCQhard

An administrator is configuring a bridge using iproute2. Which command correctly attaches eth0 to bridge br0?

A.ip link set br0 master eth0
B.ip link set eth0 master br0
C.nmcli device modify eth0 master br0
D.brctl addif br0 eth0
AnswerB

The `master` keyword in `ip link set` enslaves the interface to the bridge, so eth0 becomes a br0 port. This is the iproute2 equivalent of `brctl addif br0 eth0`, satisfying the requirement to attach eth0 to br0.

Why this answer

The `ip link set eth0 master br0` command attaches the physical interface `eth0` as a slave port of the bridge `br0` using the iproute2 suite. The `master` keyword specifies the bridge device that should become the master of the specified interface, which is the standard way to add an interface to a bridge with iproute2.

Exam trap

The trap here is that candidates often confuse the order of arguments in the `ip link set` command, mistakenly using `ip link set br0 master eth0` (Option A) because they think the bridge should be the 'master' of the interface, but the syntax requires the slave interface first followed by `master <bridge>`.

How to eliminate wrong answers

Option A is wrong because it attempts to set `br0` as a slave of `eth0` (i.e., `ip link set br0 master eth0`), which would make the bridge a port of the physical interface—the opposite of the intended configuration. Option C is wrong because `nmcli device modify eth0 master br0` is not a valid nmcli syntax; the correct nmcli command to attach an interface to a bridge is `nmcli connection add type bridge-slave ifname eth0 master br0` or `nmcli device connect eth0 master br0`. Option D is wrong because `brctl addif br0 eth0` is a valid command from the deprecated bridge-utils package, not from iproute2, and the question explicitly specifies using iproute2.

203
MCQmedium

A Linux administrator is troubleshooting a custom systemd service named backup.service that fails to start. They run systemctl status backup.service and see that the service is in a failed state, but the output does not show detailed error messages. Which command should they use to view the most recent log entries specifically for this service?

A.journalctl -xe
B.journalctl -u backup.service -n 50
C.systemctl show backup.service
D.systemctl cat backup.service
AnswerB

journalctl -u backup.service filters the journal by the specified unit and shows log entries for that service. The -n 50 option displays the most recent 50 lines. This command directly provides the recent error messages for backup.service, which is exactly what the administrator needs to troubleshoot the failure.

Why this answer

To view logs for a specific systemd unit, journalctl with the -u option is used. Adding -n specifies the number of recent lines. This filters the journal to only backup.service, providing the most recent error messages.

Other commands like systemctl cat or show do not display logs, and journalctl -xe is not unit-specific.

Exam trap

The trap here is using systemctl status and expecting full logs, or using journalctl without unit filtering, which buries the relevant messages.

204
MCQmedium

A system administrator needs to configure a systemd service so that it restarts automatically only when it exits with a non-zero exit code, but not when it is cleanly stopped by an administrator. The service unit file currently has no Restart directive. Which combination of directives should the administrator use?

A.Restart=always and RestartSec=5
B.Restart=on-failure and RestartSec=5
C.Restart=on-success and RestartSec=5
D.Restart=on-abnormal and RestartSec=5
AnswerB

Restart=on-failure tells systemd to restart the service only when it exits with a non-zero exit code, is killed by a signal, or times out. A clean stop via systemctl stop is considered a success and will not trigger a restart. RestartSec=5 adds a five-second delay between restart attempts, which is useful to avoid rapid restart loops.

Why this answer

Restart=on-failure is the correct directive because it restarts the service only on abnormal termination, such as non-zero exit codes or signals. It does not restart on a clean stop, which matches the requirement. RestartSec=5 adds a delay to prevent tight restart loops.

The other Restart values either restart too broadly (always) or too narrowly (on-abnormal, on-success).

Exam trap

The trap here is assuming that Restart=always is needed for automatic restarts, but it also restarts after a clean administrator stop, which is not desired.

205
MCQeasy

A user reports that a background process (PID 3456) is consuming 95% of CPU and causing system slowness. The process name is 'crypto-miner'. The administrator needs to immediately stop this process and ensure it does not restart. Which set of commands should the administrator execute?

A.kill -9 3456, then locate the cron job or systemd service that starts it, and disable/remove it.
B.renice -n 19 -p 3456 and let it run with lower priority.
C.kill -9 3456 and then notify the user.
D.kill -15 3456 and hope it terminates.
AnswerA

SIGKILL (kill -9) cannot be caught or ignored, so PID 3456 terminates immediately despite consuming 95% CPU. Removing the cron job or disabling the systemd unit eliminates the persistence mechanism, satisfying the requirement that the process must not restart.

Why this answer

It addresses both immediate termination and persistence removal. The SIGKILL signal (kill -9) immediately terminates the process, and disabling the cron job or systemd service prevents automatic restart, which is critical for a malicious or unwanted process like 'crypto-miner'.

Exam trap

The trap here is that candidates focus only on stopping the process immediately (kill -9) and overlook the requirement to ensure it does not restart, leading them to choose an option that fails to address persistence.

How to eliminate wrong answers

Option B is wrong because renice only lowers CPU priority; it does not stop the process, and a CPU-intensive process can still consume 95% CPU if no other processes compete, so system slowness persists. Option C is wrong because killing the process without disabling its restart mechanism (e.g., cron or systemd) allows it to respawn immediately, failing to ensure it does not restart. Option D is wrong because SIGTERM (kill -15) requests graceful termination, which the process may ignore or trap, especially if it is malicious or designed to evade termination, leaving it running.

206
MCQhard

A systems administrator needs to add a new user 'jdoe' with a home directory in /export/home, a UID of 1500, and an expiry date of 2025-12-31. Which command should they use?

A.useradd -u 1500 -d /export/home/jdoe -e 2025-12-31 jdoe
B.useradd -u 1500 -d /export/home/jdoe -c 2025-12-31 jdoe
C.useradd -u 1500 -m -e 2025-12-31 jdoe
D.useradd -u 1500 -b /export/home -e 2025-12-31 jdoe
AnswerA

useradd accepts -u for the UID, -d for the home directory path and -e for the account expiry date, so all three constraints are set in one invocation. The path must be given explicitly since /export/home is not the default parent.

Why this answer

The `useradd` command with `-u 1500` sets the UID, `-d /export/home/jdoe` explicitly specifies the home directory path (without creating it unless `-m` is also used), and `-e 2025-12-31` sets the account expiry date in YYYY-MM-DD format. This matches all requirements: UID 1500, home directory at /export/home/jdoe, and expiry on 2025-12-31.

Exam trap

The trap here is confusing the `-c` (comment) option with `-e` (expiry) and assuming `-b` (base directory) works the same as `-d` (explicit home directory), leading candidates to pick options that set the wrong field or fail to place the home directory in the specified path.

How to eliminate wrong answers

Option B is wrong because `-c` is used to set the GECOS comment field (e.g., full name), not the expiry date; using `-c 2025-12-31` would incorrectly store the date as a comment. Option C is wrong because `-m` creates the home directory in the default base directory (usually /home), not in /export/home, and omits the explicit `-d` path, so the home directory would be /home/jdoe instead of /export/home/jdoe. Option D is wrong because `-b /export/home` sets the default base directory for new users, but without `-d` the home directory would be /export/home/jdoe only if the default naming convention is used; however, `-b` does not override the need for `-d` to explicitly set the path, and the command as written would still create /export/home/jdoe, but the option `-b` is intended for setting a system-wide default, not for specifying an individual user's home directory — the correct approach for a single user is `-d`.

207
MCQmedium

A company has a server with two network interfaces: eth0 (192.168.1.10/24, gateway 192.168.1.1) and eth1 (10.0.0.10/24, gateway 10.0.0.1). The server needs to reach a remote network 172.16.0.0/16 via a VPN tunnel that terminates at 10.0.0.5 on eth1. Which command should be used to add a route for this traffic?

A.ip route add 172.16.0.0/16 via 10.0.0.5 dev eth1
B.ip route add 172.16.0.0/16 via 10.0.0.5 dev eth0
C.ip route add 172.16.0.0/16 via 192.168.1.1 dev eth0
D.ip route add 172.16.0.0/16 dev eth1
AnswerA

Routing 172.16.0.0/16 via 10.0.0.5 on eth1 satisfies the stem's constraint that VPN traffic must egress the second interface, since 10.0.0.5 is reachable only through eth1's 10.0.0.0/24 subnet. Specifying both the gateway and dev eth1 prevents the kernel selecting eth0's default route.

Why this answer

The VPN tunnel endpoint is at 10.0.0.5 on the eth1 network, so traffic to 172.16.0.0/16 must be forwarded via that next-hop IP address using the eth1 interface. The `ip route add` command with `via 10.0.0.5 dev eth1` explicitly sets the gateway and egress interface, ensuring packets are sent through the VPN tunnel.

Exam trap

The trap here is that candidates often forget to specify the `via` next-hop IP when the destination is not directly connected, or they mistakenly use the default gateway instead of the VPN tunnel endpoint, assuming all external traffic goes through the same gateway.

How to eliminate wrong answers

Option B is wrong because it specifies `dev eth0`, but the VPN tunnel endpoint (10.0.0.5) is not reachable on the 192.168.1.0/24 network; eth0 has no route to 10.0.0.0/24, so the packet would be dropped or misrouted. Option C is wrong because it uses the default gateway 192.168.1.1 as the next-hop, which would send traffic to the local LAN gateway instead of the VPN tunnel endpoint at 10.0.0.5, failing to reach the remote network. Option D is wrong because it omits the `via` parameter; without a next-hop IP, the kernel assumes the destination is directly connected on eth1, but 172.16.0.0/16 is not on the 10.0.0.0/24 subnet, so the route would be invalid and traffic would not be forwarded.

208
MCQmedium

A Linux server has a single interface ens3 with address 203.0.113.10/24. The administrator runs `ss -tulnp` and sees that a service is listening on 127.0.0.1:8080 only. Remote clients on the Internet report they cannot reach the service on port 8080 even though the firewall allows the port. Which change is the most appropriate to allow remote access while preserving the service's intended exposure?

A.Add a route for 127.0.0.1 via ens3 so that external packets can reach the loopback address.
B.Restart the service after changing its configuration to bind to 0.0.0.0 or the specific external address instead of 127.0.0.1.
C.Enable IP forwarding with `sysctl -w net.ipv4.ip_forward=1` so that packets can be forwarded to the loopback listener.
D.Configure a DNAT rule redirecting external port 8080 to 127.0.0.1:8080 on the same host.
AnswerB

The service is bound to the loopback address, so it only accepts connections from the local host regardless of firewall rules. Rebinding to 0.0.0.0 or 203.0.113.10 makes the socket reachable on the external interface, which is the direct fix for the observed behavior.

Why this answer

A listener bound to 127.0.0.1 accepts only connections that originate on the local machine. Firewall rules and routing cannot change this. The correct remedy is to reconfigure the service to bind to 0.0.0.0 or the external address, then restart it so the new socket is created.

Exam trap

The trap here is assuming a firewall or routing problem when the listening socket itself is bound only to the loopback address.

209
MCQhard

An administrator is troubleshooting a server that runs a critical application. The server has 16 GB of RAM and 8 CPU cores. The administrator notices that the server becomes very slow during peak hours. Analysis of 'iostat -x 1' shows that the average wait time (await) for the main disk (sda) is consistently above 1000 ms, while the average service time (svctm) is around 5 ms. What is the most likely cause?

A.The CPU is overloaded, causing processes to wait for CPU time.
B.The system is using swap space heavily, causing disk I/O.
C.The disk is experiencing hardware errors.
D.There is a large queue of I/O requests waiting to be serviced.
AnswerD

Await of 1000ms against svctm of 5ms means requests spend almost all their time queued rather than being serviced. The disk itself is fast; the bottleneck is the backlog of pending I/O requests exceeding what sda can dispatch concurrently.

Why this answer

The 'await' value in iostat represents the average time (in milliseconds) for I/O requests to be serviced, including time spent waiting in the queue. With 'await' at 1000+ ms and 'svctm' at only 5 ms, the vast majority of the time is spent waiting, not being serviced. This indicates a large queue of pending I/O requests, which is the direct cause of the slowdown.

Exam trap

The trap here is that candidates confuse 'await' with 'svctm' or assume high 'await' always means slow disk hardware, when in fact the low 'svctm' proves the disk is fast but overwhelmed by queue depth.

How to eliminate wrong answers

Option A is wrong because CPU overload would show high CPU utilization or run queue length in 'top' or 'vmstat', not a high 'await' with low 'svctm'. Option B is wrong because heavy swap usage would increase I/O but would also typically show high 'svctm' due to random access patterns, and the 'await' vs 'svctm' disparity here points to queue depth, not swap. Option C is wrong because hardware errors would manifest as I/O errors in system logs or increased 'svctm' due to retries, not a consistent 5 ms service time with a 1000+ ms wait.

210
MCQhard

An administrator wants to run a script daily at 2 AM. They create a timer unit and a service unit. The service unit uses Type=oneshot. Which of the following timer configurations is correct?

A.OnUnitActiveSec=24h
B.OnBootSec=1d
C.OnActiveSec=24h
D.OnCalendar=*-*-* 02:00:00
AnswerD

OnCalendar uses systemd's calendar syntax, and *-*-* 02:00:00 specifies every day at exactly 02:00. This satisfies the daily 2 AM schedule, and pairing it with a Type=oneshot service ensures the script runs once per trigger.

Why this answer

`OnCalendar=*-*-* 02:00:00` specifies an absolute calendar event that triggers the timer at 2:00 AM every day, regardless of when the system booted or when the service last ran. This matches the requirement to run a script daily at a fixed time, and it works correctly with a `Type=oneshot` service unit.

Exam trap

The trap here is that candidates confuse `OnUnitActiveSec` (relative to last activation) with a fixed daily schedule, or they invent non-existent directives like `OnActiveSec`, while overlooking the correct `OnCalendar=` syntax for absolute time triggers.

How to eliminate wrong answers

Option A is wrong because `OnUnitActiveSec=24h` triggers the timer 24 hours after the service unit last became active, which would cause the execution time to drift if the service takes time to run or if it is manually triggered at a different time; it does not guarantee a fixed 2 AM execution. Option B is wrong because `OnBootSec=1d` triggers the timer once, 24 hours after system boot, and then never repeats; it does not create a daily recurring schedule. Option C is wrong because `OnActiveSec=24h` is not a valid systemd timer directive; the correct directive for relative time after activation is `OnUnitActiveSec`, and `OnActiveSec` does not exist in systemd timer units.

211
MCQhard

A storage administrator needs to identify which filesystem is mounted at /mnt/data and display the mount options currently in effect for it, using a single command that reads the kernel mount table. Which command should be used?

A.blkid /mnt/data
B.findmnt /mnt/data
C.lsblk /mnt/data
D.df -h /mnt/data
AnswerB

This is correct because findmnt reads /proc/self/mountinfo and prints the matching mount entry, including the source device, filesystem type, and the full option list in the OPTIONS column. It directly answers which filesystem is mounted and what options are active for that specific mount point.

Why this answer

The kernel mount table contains the authoritative record of what is mounted and with which options. findmnt queries that table and filters by mount point, displaying the source, target, filesystem type, and options. df and lsblk report capacity or topology, and blkid identifies filesystem signatures, but none of them show the active mount options for a given mount point.

Exam trap

The trap here is reaching for df to inspect a mount, when df reports space usage rather than the mount options recorded in the kernel table.

212
Drag & Dropmedium

Arrange the steps to configure a new user account with sudo privileges on a Linux system.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

After creating the user and setting a password, adding to the wheel group grants sudo access. Verification and testing confirm it works.

213
Multi-Selecthard

A Linux administrator is configuring a new iSCSI storage target. The server has two network interfaces, eth0 and eth1, and the administrator wants to use multipath I/O (DM-Multipath) for redundancy and increased throughput. Which two steps are required to properly set up DM-Multipath for the iSCSI LUNs? (Choose two.)

Select 2 answers
A.Create a bonded network interface combining eth0 and eth1, and configure iSCSI to use the bond for all traffic.
B.Use iscsiadm to log in to the target portal on both eth0 and eth1, ensuring that each interface discovers the same LUNs.
C.Format the iSCSI LUNs with a cluster-aware filesystem such as GFS2 before enabling multipath.
D.Set the iSCSI initiator name to match the target's ACL, and configure CHAP authentication for each path.
E.Install and enable the multipathd service, then configure /etc/multipath.conf with the appropriate blacklist and multipath settings.
AnswersB, E

For DM-Multipath to provide redundancy and throughput, multiple paths to the same LUN must exist. Logging in via both network interfaces creates two separate iSCSI sessions, each seeing the same LUN, which the multipath layer can then combine. If only one interface is used, there is no multipath to manage, defeating the purpose of the configuration.

Why this answer

To set up DM-Multipath for iSCSI LUNs, you must install and configure multipathd and its configuration file, and you must create multiple iSCSI sessions to the same LUNs via different network interfaces. This ensures that the multipath layer can detect and manage multiple paths. Bonding or authentication are not substitutes for multipath configuration.

Exam trap

The trap here is confusing network bonding with multipath I/O; bonding aggregates links but does not create multiple SCSI paths, which are required for DM-Multipath to function.

214
MCQhard

An administrator is diagnosing a Linux router that forwards packets between two internal subnets. Users on 10.20.30.0/24 can reach hosts on 10.20.40.0/24, but responses from 10.20.40.0/24 arrive with the router's external address as the source. The administrator wants to inspect the NAT rules without modifying them. Which command displays the current rules in the nat table with packet and byte counters?

A.iptables -t nat -L -n -v
B.nft list ruleset
C.iptables -L -n -v
D.iptables -t nat -S
AnswerA

This lists all chains in the nat table, shows numeric addresses and ports with -n, and includes packet and byte counters with -v. It is read-only, so it satisfies the requirement to inspect without modifying. The output shows the PREROUTING, INPUT, OUTPUT, and POSTROUTING chains with their rules and hit counts, which is exactly what is needed to confirm which NAT rule is rewriting source addresses.

Why this answer

The nat table holds the PREROUTING, OUTPUT, and POSTROUTING chains where SNAT, DNAT, and MASQUERADE rules live. To inspect them with hit counters, iptables must be invoked with -t nat and the verbose flag -v, plus -n to avoid DNS lookups. This gives a clear picture of which rule is rewriting source addresses on the return path, without altering any rule.

Exam trap

The trap here is forgetting that iptables defaults to the filter table, so omitting -t nat silently shows the wrong set of chains and hides all NAT rules.

215
MCQmedium

A Linux server has a volume group named vg_data that currently contains two physical volumes. The administrator needs to remove /dev/sdb1 from vg_data, but pvremove /dev/sdb1 returns an error stating the physical volume is still in use. Which command should the administrator run FIRST to migrate the extents off /dev/sdb1 onto the remaining physical volume?

A.lvconvert --repair vg_data
B.vgreduce vg_data /dev/sdb1
C.pvremove /dev/sdb1 --force
D.pvmove /dev/sdb1
AnswerD

pvmove relocates all logical extents from the specified physical volume to other physical volumes in the same volume group while the logical volumes remain online. Once the extents have been migrated, /dev/sdb1 no longer holds any allocated data, allowing vgreduce to remove it and pvremove to release the label. This is the documented first step before detaching a PV from an active VG.

Why this answer

To safely remove a physical volume from an active volume group, the allocated extents must first be moved to other PVs. pvmove performs this online migration without unmounting filesystems. Only after the PV reports zero used extents can vgreduce detach it and pvremove clear its label. Attempting vgreduce or pvremove beforehand fails because LVM protects allocated data.

Exam trap

The trap here is assuming that vgreduce or pvremove automatically evacuates data, when in fact LVM requires pvmove to migrate extents before a PV can be detached.

216
MCQmedium

A user is unable to write to a file. The output of 'ls -l file' shows '-r--r--r--'. Which command will grant write permission to the owner?

A.chmod o+w file
B.chmod u+w file
C.chmod a+w file
D.chmod g+w file
AnswerB

The file mode `-r--r--r--` gives the owner read-only access, so write permission must be added to the user (owner) class. `chmod u+w file` adds write to the owner triad while leaving group and other bits untouched, satisfying the requirement without altering existing read permissions.

Why this answer

The file's permissions are '-r--r--r--', meaning the owner has only read permission. The 'chmod u+w file' command adds write permission for the owner (u) because 'u' refers to the user/owner. This directly addresses the owner's lack of write access.

Exam trap

The trap here is that candidates often confuse 'u' (owner) with 'o' (others) or mistakenly use 'a' (all) when only owner write is needed, leading to incorrect or overly permissive commands.

How to eliminate wrong answers

Option A is wrong because 'o+w' adds write permission for 'others', not the owner, so the owner still cannot write. Option C is wrong because 'a+w' adds write permission for all categories (owner, group, others), which is overly permissive and not the minimal command to grant write access only to the owner. Option D is wrong because 'g+w' adds write permission for the group, not the owner, leaving the owner's permissions unchanged.

217
MCQeasy

To view the system's default runlevel (target) at boot, which command is used on a systemd-based system?

A.systemd-analyze
B.systemctl get-default
C.runlevel
D.cat /etc/inittab
AnswerB

`systemctl get-default` queries systemd's default target directly, reading the symlink at `/etc/systemd/system/default.target`. This satisfies the stem's requirement to view the boot target on a systemd-based system, returning values such as `graphical.target` or `multi-user.target` without altering configuration.

Why this answer

On systemd-based systems, the default target (analogous to runlevel) is managed by systemctl. The command `systemctl get-default` queries the symlink at `/etc/systemd/system/default.target` to display which target is set to boot by default, making it the correct way to view the system's default boot target.

Exam trap

The trap here is that candidates familiar with SysVinit may instinctively choose `runlevel` or `cat /etc/inittab`, not realizing that systemd replaces these with `systemctl` commands and uses target units instead of runlevels.

How to eliminate wrong answers

Option A is wrong because `systemd-analyze` is used to analyze system boot performance and show timing details, not to display the default target. Option C is wrong because `runlevel` is a legacy SysVinit command that reads `/var/run/utmp` to show the current and previous runlevels; it does not work on systemd systems to show the default boot target. Option D is wrong because `/etc/inittab` is the configuration file for SysVinit that defines runlevels; systemd-based systems do not use this file, and it is typically absent or ignored.

218
MCQeasy

A system administrator needs to set up software RAID1 on a server for /data. The available disks are /dev/sdb (500GB) and /dev/sdc (1TB). What is the maximum usable capacity of the RAID1 array?

A.500GB
B.250GB
C.1TB
D.1.5TB
AnswerA

RAID1 mirrors data across both disks, so usable capacity equals the smaller member's size. Since /dev/sdb is 500GB and /dev/sdc is 1TB, the array is limited to 500GB; the remaining 500GB on /dev/sdc is unusable.

Why this answer

RAID1 (mirroring) writes identical data to all disks in the array, so the usable capacity is limited by the smallest disk. With /dev/sdb at 500GB and /dev/sdc at 1TB, the maximum usable capacity is 500GB. The remaining space on /dev/sdc (500GB) is unusable in the RAID1 array because it cannot be mirrored.

Exam trap

The trap here is that candidates often assume RAID1 adds capacities (like RAID0) or averages them, rather than recognizing that mirroring strictly limits usable space to the smallest disk's capacity.

How to eliminate wrong answers

Option B is wrong because 250GB would only be the usable capacity if both disks were 500GB and you incorrectly halved the total (e.g., confusing RAID1 with RAID5 or RAID0). Option C is wrong because 1TB assumes the array can use the full capacity of the larger disk, which violates the mirroring constraint of RAID1. Option D is wrong because 1.5TB is the sum of both disks' capacities, which would only apply to RAID0 (striping) or JBOD, not RAID1.

219
MCQhard

Refer to the exhibit. A Linux administrator sees that 'myapp.service' is in a failed state with exit status 1. To troubleshoot, which command should the administrator use to view the full error output that the service produced before exiting?

A.systemctl status myapp.service
B.systemctl reload myapp.service
C.journalctl -u myapp.service
D.systemctl restart myapp.service
AnswerC

journalctl -u myapp.service queries the systemd journal filtered to that unit, returning the full stdout and stderr captured before the process exited with status 1. This exposes the actual error message rather than just the exit code.

Why this answer

journalctl -u myapp.service retrieves the full log output for that systemd unit from the journal, including stdout/stderr captured before the service exited with status 1. This is the correct tool to see the complete error trace, not just the summary. systemctl status only shows a truncated tail and the exit code.

Exam trap

LFCS often tests the confusion between systemctl status (summary view) and journalctl -u (full unit logs), so candidates pick status thinking it shows complete error output.

How to eliminate wrong answers

Option A is wrong because systemctl status myapp.service shows only a short summary and the last few log lines (often truncated), not the full error output. Option B is wrong because systemctl reload asks the service to reload its configuration and does nothing to display logs; it may even fail if the unit is not running. Option D is wrong because systemctl restart attempts to restart the service, which does not help retrieve the prior failure's output and may overwrite or add new log entries.

220
MCQhard

An administrator wants to enforce that users in the 'contractors' group must change their password every 30 days, with a warning 7 days before expiry. Which command should be used?

A.groupmod -p 30 contractors
B.passwd -x 30 -w 7 contractors
C.usermod -e 30 contractors
D.chage -M 30 -W 7 contractors
AnswerD

Incorrect. `chage -M 30 -W 7` is the right command for password aging, but it requires a username, not a group name.

Why this answer

None of the provided commands can be directly applied to a group. The `chage` command is the appropriate tool for password aging, but it requires a username as an argument. To enforce password aging on all users in the 'contractors' group, an administrator would need to iterate over each user in the group and run `chage -M 30 -W 7 <username>` for each.

Exam trap

The trap is that candidates may think `chage` can take a group name, but it requires a username. Also, `passwd` has similar aging options but also requires a username.

How to eliminate wrong answers

Option A is wrong because `groupmod` is used to modify group properties (like GID or group name), not password aging; the `-p` flag does not exist for password expiration. Option B is wrong because `passwd` with `-x` and `-w` can set password aging for a user, but the syntax requires a username, not a group name; it cannot be applied to a group directly. Option C is wrong because `usermod -e` sets an account expiration date (a specific date), not a password aging interval; it does not enforce a 30-day password change cycle.

221
Multi-Selecteasy

Which TWO of the following commands can be used to check and repair an ext4 filesystem?

Select 2 answers
A.fsck.ext4 /dev/sdb1
B.xfs_repair /dev/sdb1
C.mkfs.ext4 /dev/sdb1
D.e2fsck /dev/sdb1
E.btrfs check /dev/sdb1
AnswersA, D

`fsck.ext4` directly invokes the ext4-specific checker, which validates inode tables, block bitmaps and directory structures, then repairs inconsistencies. It satisfies the stem's requirement to both check and repair, and can be run against the unmounted `/dev/sdb1` device, unlike generic tools that merely report usage.

Why this answer

Option A, fsck.ext4 /dev/sdb1, is correct because fsck.ext4 is the ext4-specific front-end of the fsck utility, which checks and repairs ext4 filesystems on the specified block device. Option D, e2fsck /dev/sdb1, is also correct because e2fsck is the underlying ext2/ext3/ext4 filesystem checker that fsck.ext4 invokes, and it can both verify and repair ext4 filesystems. Option B, xfs_repair, is wrong because it is the repair tool for XFS filesystems, not ext4.

Option C, mkfs.ext4, is wrong because it creates (formats) a new ext4 filesystem rather than checking or repairing an existing one. Option E, btrfs check, is wrong because it is used to check Btrfs filesystems, not ext4.

Exam trap

The trap here is that candidates often confuse filesystem-specific repair tools (like `xfs_repair` for XFS or `btrfs check` for Btrfs) with the generic `fsck` family, or mistakenly think `mkfs.ext4` can repair a filesystem when it actually formats and destroys it.

222
MCQhard

After a kernel update, a service fails to start with 'cannot allocate memory'. The system has 16GB RAM and 8GB swap. Which command should the administrator run first to diagnose potential memory limits?

A.free -m
B.ulimit -a
C.cat /proc/meminfo
D.sysctl vm.overcommit_memory
AnswerB

ulimit -a prints all current shell resource limits, including virtual memory and max memory size, revealing whether a restrictive cap prevents the service from allocating memory despite ample physical RAM and swap. It is the fastest first diagnostic step.

Why this answer

`ulimit -a` displays all current user-level resource limits, including `max memory size`, `max processes`, and `max locked memory`. After a kernel update, the service may be hitting a newly enforced or reduced `ulimit` (e.g., `RLIMIT_AS` or `RLIMIT_DATA`), which can cause 'cannot allocate memory' even when system memory is abundant. This command is the fastest way to check if a per-process limit is the culprit.

Exam trap

The trap here is that candidates see 'cannot allocate memory' and immediately think of system memory exhaustion, leading them to choose `free -m` or `/proc/meminfo`, but the LFCS exam tests the distinction between system-wide memory and per-process resource limits enforced by `ulimit`.

How to eliminate wrong answers

Option A is wrong because `free -m` shows overall system memory and swap usage, but the error 'cannot allocate memory' can occur even with plenty of free RAM if a per-process limit is imposed; `free` does not reveal user limits. Option C is wrong because `cat /proc/meminfo` provides detailed kernel memory statistics (e.g., MemTotal, MemFree, Committed_AS) but does not show per-process resource limits enforced by the shell or PAM; it cannot diagnose a `ulimit` restriction. Option D is wrong because `sysctl vm.overcommit_memory` controls the kernel's memory overcommit policy (0=heuristic, 1=always, 2=never overcommit), but the error 'cannot allocate memory' from a service is typically a per-process limit issue, not a system-wide overcommit setting; changing this sysctl is a more advanced step after confirming limits.

223
Multi-Selectmedium

Which THREE are common tools used for network troubleshooting on Linux?

Select 3 answers
A.traceroute
B.fdisk
C.ping
D.tcpdump
E.useradd
AnswersA, C, D

Traceroute maps the hop-by-hop path packets take to a destination and reports where latency or loss appears. This makes it a standard Linux tool for diagnosing routing problems, unreachable hosts and intermediate network failures during troubleshooting.

Why this answer

traceroute (A) is a standard Linux network diagnostic tool that maps the hop-by-hop path packets take to a destination by manipulating the IP TTL field and reading ICMP Time Exceeded replies, making it essential for locating routing problems. ping (C) is a core troubleshooting utility that sends ICMP Echo Request packets and measures Echo Reply responses to verify basic IP reachability and round-trip latency to a host. tcpdump (D) is a packet capture and analysis tool that uses libpcap to inspect live traffic at the frame/packet level, which is indispensable for diagnosing protocol-level and connectivity issues. The remaining options are not network troubleshooting tools: fdisk (B) is a disk partitioning utility for managing block devices, and useradd (E) is an account management command for creating local user accounts.

Exam trap

The trap here is that candidates might confuse system administration tools (like fdisk and useradd) with network utilities, or incorrectly assume that any command that interacts with the system can be used for network troubleshooting, when only dedicated network diagnostic tools like traceroute, ping, and tcpdump are appropriate.

224
MCQhard

A server uses LVM with volume group vg_data. The logical volume lv_app is mounted at /srv/app and is 200 GiB. The administrator adds a new 500 GiB disk, /dev/sdb, creates a physical volume on it, and extends vg_data with it. They then run lvextend -L +100G /dev/vg_data/lv_app. The filesystem is ext4. Which command must be run next to make the additional space usable without unmounting /srv/app?

A.lvresize -L +100G /dev/vg_data/lv_app
B.e2fsck -f /dev/vg_data/lv_app
C.resize2fs /dev/vg_data/lv_app
D.xfs_growfs /srv/app
AnswerC

For ext4, resize2fs grows the filesystem to fill the enlarged logical volume. It can be run online on a mounted ext4 filesystem, so /srv/app remains available. Without this step, the logical volume is larger but the filesystem still reports the old size. This command is required after lvextend when using ext4.

Why this answer

After extending the logical volume with lvextend, the ext4 filesystem must be grown to use the new space. resize2fs performs this online for ext4, keeping /srv/app mounted. xfs_growfs targets XFS, e2fsck checks but does not resize, and lvresize would further change the logical volume without touching the filesystem. The correct sequence is lvextend then resize2fs.

Exam trap

The trap here is assuming that extending the logical volume automatically grows the filesystem, or using a resize tool for the wrong filesystem type.

225
MCQhard

A system administrator is troubleshooting network connectivity from a server that can reach internal resources but cannot access the internet. The server's /etc/sysconfig/network-scripts/ifcfg-eth0 file contains: BOOTPROTO=static, IPADDR=10.0.0.10, NETMASK=255.255.255.0, GATEWAY=10.0.0.1. The administrator runs 'ip route show' and sees: default via 10.0.0.1 dev eth0. However, 'ping 8.8.8.8' fails. Which is the most likely cause?

A.The default gateway is missing from the routing table.
B.The gateway 10.0.0.1 is not configured to forward traffic to the internet (no NAT or upstream route).
C.DNS resolution is not configured.
D.A firewall is blocking outbound ICMP traffic.
AnswerB

The default route exists and points at 10.0.0.1, so local routing is fine. Failure to reach 8.8.8.8 indicates the gateway itself lacks NAT or an upstream route, meaning it cannot forward traffic beyond the internal network.

Why this answer

The routing table shows a default gateway (10.0.0.1) is present, so the issue is not a missing route. Since the server can reach internal resources but not the internet, the most likely cause is that the gateway itself (10.0.0.1) is not configured to perform NAT or does not have an upstream route to forward traffic beyond the local subnet. Without this, packets destined for 8.8.8.8 are sent to the gateway but are then dropped because the gateway has no path to the internet.

Exam trap

The trap here is that candidates often assume a missing default gateway is the problem when ping fails, but the question explicitly shows the default route exists, so the real issue is the gateway's inability to forward traffic beyond the local network.

How to eliminate wrong answers

Option A is wrong because the 'ip route show' output explicitly shows 'default via 10.0.0.1 dev eth0', meaning the default gateway is present in the routing table. Option C is wrong because DNS resolution is not required for a ping to an IP address like 8.8.8.8; the failure occurs at the network layer, not at the application or name resolution layer. Option D is wrong because while a firewall could block ICMP, the question states the server can reach internal resources, and the most likely cause given the routing configuration is a gateway issue; a firewall blocking outbound ICMP would not explain why the gateway itself is unreachable for internet traffic, and the symptom is consistent with a lack of NAT or upstream route on the gateway.

Page 2

Page 3 of 6

Page 4

All pages