Courseiva

Linux Foundation Certified System Administrator LFCS (LFCS) — Questions 226–300

406 questions total · 6pages · All types, answers revealed

Page 3

Page 4 of 6

Page 5
226
MCQmedium

A developer reports that a compiled binary 'app' fails to execute with 'Permission denied' error when run from a mounted directory '/mnt/software'. The binary has execute permissions for all users. What is the most likely cause?

A.SELinux is blocking execution.
B.The binary is linked against missing libraries.
C.The filesystem is mounted with the 'noexec' option.
D.The binary is setuid but owned by a user other than root.
AnswerC

The noexec mount option blocks execution of binaries on that filesystem regardless of their permission bits, producing 'Permission denied'. Since execute permissions are already set for all users, the mount flag is the remaining cause.

Why this answer

The 'noexec' mount option prevents execution of any binary files on the filesystem, regardless of their file permissions. When a filesystem is mounted with 'noexec', the kernel will refuse to execute binaries from that mount point, returning 'Permission denied' even if the binary has execute permissions for all users. This is a common security measure for mounted directories like /mnt/software to prevent unauthorized code execution.

Exam trap

The trap here is that candidates often assume 'Permission denied' always relates to file permissions (chmod) or SELinux, but the LFCS exam tests knowledge of mount options like 'noexec' which silently override file-level permissions at the filesystem level.

How to eliminate wrong answers

Option A is wrong because SELinux blocking execution would typically produce an AVC denial message in the audit log and a different error (e.g., 'Operation not permitted' or 'Permission denied' with a SELinux context mismatch), but the question states the binary has execute permissions for all users, and SELinux would not be the most likely cause without additional context like a targeted policy. Option B is wrong because missing libraries cause a 'cannot open shared object file' or 'No such file or directory' error, not 'Permission denied'. Option D is wrong because a setuid binary owned by a non-root user would still execute (though the setuid bit would be ignored for security reasons), and the error would not be 'Permission denied' unless the binary itself lacks execute permissions, which it does not.

227
MCQhard

A user named 'charlie' has just been added to the 'devops' group. However, when 'charlie' runs 'sudo -l', no sudo entries are shown. What is the most likely cause?

A.'charlie' is not listed by name in the sudoers file.
B.'charlie' must log out and log back in for the group change to take effect.
C.'charlie' is also a member of another group that restricts sudo.
D.The systemctl command is not executable by 'charlie'.
E.The sudoers file has a syntax error.
AnswerB

Group membership is resolved at login and cached in the session's credential set. Charlie's existing shell still holds the old groups, so sudo matches no rule. Logging out and back in refreshes the supplementary group list, making the devops sudo entries visible.

Why this answer

When a user is added to a new group, the group membership is only applied to new login sessions. The `sudo -l` command checks the user's current group memberships, which are cached at login time. Since 'charlie' was added to the 'devops' group while already logged in, the new group membership is not reflected until 'charlie' logs out and logs back in, or uses `newgrp` or `sg` to start a new session with the updated groups.

Exam trap

The trap here is that candidates assume group changes are immediate for all processes, but Linux caches group membership at login time, so `sudo -l` reflects only the groups present when the session started.

How to eliminate wrong answers

Option A is wrong because the sudoers file can grant sudo access via group membership (e.g., `%devops ALL=(ALL) ALL`), so 'charlie' does not need to be listed by name; the group membership should suffice. Option C is wrong because being a member of another group does not restrict sudo unless that group is explicitly denied in sudoers; group membership is additive, not restrictive. Option D is wrong because the `systemctl` command's executability is irrelevant to `sudo -l` showing entries; `sudo -l` displays the commands the user is allowed to run, not whether a specific command is executable.

Option E is wrong because a syntax error in the sudoers file would typically cause `sudo` to fail with an error message (e.g., 'syntax error near line X'), not silently show no entries.

228
MCQeasy

A user wants to find the location of the 'grep' binary. Which command should they use?

A.man grep
B.which grep
C.uname -a
D.grep -r 'grep' /usr/bin
AnswerB

The which command searches the directories listed in the PATH environment variable and returns the full path of the first matching executable. This directly locates the grep binary's filesystem location, satisfying the user's requirement without invoking or executing it.

Why this answer

The 'which' command is specifically designed to locate the binary (executable) of a command by searching the directories listed in the user's PATH environment variable. Option B, 'which grep', will output the full path to the grep binary, such as '/usr/bin/grep', directly answering the user's request.

Exam trap

The trap here is that candidates may confuse documentation commands (man) or system information commands (uname) with binary location commands, or mistakenly think a recursive grep search is an efficient way to find a binary, when 'which' is the standard, straightforward tool for this task.

How to eliminate wrong answers

Option A is wrong because 'man grep' displays the manual page for grep, which provides documentation and usage information, not the filesystem location of the binary. Option C is wrong because 'uname -a' prints system information (kernel name, hostname, kernel release, etc.), which is unrelated to locating a command's binary. Option D is wrong because 'grep -r' performs a recursive text search for the string 'grep' within files under /usr/bin, which is inefficient, may return many irrelevant matches, and does not reliably identify the grep binary itself.

229
Multi-Selecthard

Which TWO are valid methods to configure a network interface on a Linux system?

Select 2 answers
A.Using sysctl to set net.ipv4.conf.eth0.forwarding
B.Using systemctl enable network.service
C.Editing /etc/network/interfaces
D.Using nmcli connection add
E.Editing /etc/sysconfig/network
AnswersC, D

Editing /etc/network/interfaces is the Debian/Ubuntu ifupdown mechanism: persistent interface definitions consumed at boot by ifupdown, supporting static addressing, DHCP and VLAN stanzas. It satisfies the question's requirement for a valid configuration method on those distributions.

Why this answer

Option C is correct because /etc/network/interfaces is the standard configuration file used by the ifupdown toolset on Debian-based Linux distributions to define network interfaces, their addressing (static or DHCP), and related parameters. Option D is correct because nmcli connection add is the NetworkManager command-line method for creating a new connection profile that configures an interface, including its IP addressing, gateway, and DNS settings. Option A is not a valid interface configuration method because sysctl only tunes kernel runtime parameters such as net.ipv4.conf.eth0.forwarding (packet forwarding), not interface addressing or link settings.

Option B is not valid because systemctl enable network.service merely sets the legacy network service to start at boot; it does not itself configure an interface. Option E is not valid because /etc/sysconfig/network is a Red Hat-style file that historically held global hostname and gateway settings, not per-interface configuration.

Exam trap

The trap here is that candidates confuse global network configuration files (like /etc/sysconfig/network) with per-interface configuration files, or mistake sysctl for a tool that can set interface IP addresses, when it only modifies kernel parameters unrelated to interface addressing.

230
MCQeasy

Which systemd unit type is used to group services and other units together for boot execution?

A.socket
B.timer
C.service
D.target
AnswerD

A target unit groups other units and services into a synchronisation point for boot execution, satisfying the stem's grouping requirement. Unlike service units, which run a specific process, targets aggregate units and are pulled in by dependencies, replacing SysV runlevels. This makes `target` the unit type designed for boot-stage grouping.

Why this answer

In systemd, the 'target' unit type is designed to group services, sockets, timers, and other units into a logical synchronization point for boot execution. Targets do not execute code themselves but instead define dependencies (via Wants, Requires, and After directives) that ensure all associated units are started in the correct order to reach a desired system state, such as multi-user.target or graphical.target.

Exam trap

The trap here is that candidates often confuse 'service' units with the concept of grouping, because services are the most common unit type, but they fail to recognize that only 'target' units can aggregate multiple units into a single boot synchronization point.

How to eliminate wrong answers

Option A is wrong because a 'socket' unit type is used for socket-based activation (e.g., listening on a TCP port or Unix socket), not for grouping units for boot execution. Option B is wrong because a 'timer' unit type schedules and triggers services based on time or calendar events, not for grouping units during boot. Option C is wrong because a 'service' unit type manages a single daemon or process, not a collection of units; grouping multiple services requires a target.

231
MCQeasy

A user needs to view the contents of a compressed log file /var/log/syslog.gz without first decompressing it. Which command should they use?

A.zcat /var/log/syslog.gz
B.gzip -d /var/log/syslog.gz
C.gunzip /var/log/syslog.gz
D.cat /var/log/syslog.gz
AnswerA

`zcat` decompresses gzip data to standard output, so the file's contents appear on screen without altering the original `.gz` file on disk. This satisfies the stem's constraint of viewing without prior decompression, unlike `gunzip`, which removes the archive, or `cat`, which would emit raw compressed bytes.

Why this answer

`zcat` is specifically designed to read the contents of gzip-compressed files without permanently decompressing them. It decompresses the data on the fly and sends the output to stdout, allowing the user to view the log file's contents directly from the terminal.

Exam trap

The trap here is that candidates may confuse commands that permanently decompress files (like `gzip -d` or `gunzip`) with commands that only display the contents, leading them to choose an option that alters the file system state instead of just viewing the data.

How to eliminate wrong answers

Option B is wrong because `gzip -d` permanently decompresses the file, replacing `syslog.gz` with an uncompressed `syslog` file, which alters the original compressed archive. Option C is wrong because `gunzip` is equivalent to `gzip -d` and also permanently decompresses the file, removing the `.gz` version. Option D is wrong because `cat` reads raw binary data and will output garbled, unreadable content when applied to a gzip-compressed file, as it does not perform any decompression.

232
MCQeasy

A Linux administrator needs to display the IP addresses and netmasks of all network interfaces on a server. Which command provides this information in a concise, modern format?

A.ip addr show
B.netstat -i
C.route -n
D.ifconfig -a
AnswerA

The 'ip addr show' command from the iproute2 package displays all network interfaces with their IPv4 and IPv6 addresses, netmasks in CIDR notation, and link-layer information. It is the modern replacement for ifconfig and is available by default on virtually all current Linux distributions, providing concise and consistent output.

Why this answer

The 'ip addr show' command is the modern, preferred tool for displaying interface IP addresses and netmasks. It is part of iproute2, which is standard on current Linux systems, and its output clearly shows each interface's addresses in CIDR notation. The other commands either show different information (netstat -i, route -n) or are deprecated and not always installed (ifconfig).

Exam trap

The trap here is assuming that ifconfig is still the standard tool for viewing interface addresses, or confusing interface statistics with address information.

233
MCQeasy

A Linux server at a hosting provider uses a software RAID 5 array with three 2 TB disks (sda, sdb, sdc) configured as /dev/md0, hosting a large ext4 filesystem. The server experiences a performance degradation and I/O errors. The administrator checks /proc/mdstat and sees that /dev/sda is marked as failed. The remaining two disks are still active. The administrator has a spare disk /dev/sdd of the same size. The filesystem is sparse and can tolerate downtime. What is the most appropriate course of action to restore the array to a fully functional state with redundancy?

A.Recreate the RAID 5 array from scratch using all three healthy disks (sdb, sdc, sdd) and restore data from backup.
B.Run 'mdadm --manage /dev/md0 --fail /dev/sda --remove /dev/sda', then 'mdadm --manage /dev/md0 --add /dev/sdd'.
C.Run 'mdadm --manage /dev/md0 --add /dev/sdd' to directly add the new disk and let the array rebuild automatically.
D.Use LVM to mirror the two healthy disks and ignore the failed one, ensuring data redundancy.
AnswerB

Marking sda failed and removing it, then adding sdd, lets mdadm rebuild redundancy onto the spare while the degraded array stays online. This restores RAID 5 fault tolerance without recreating the ext4 filesystem, matching the requirement to regain redundancy with minimal disruption.

Why this answer

The correct procedure is to mark the failed disk as failed (if not already), remove it from the array, then add the spare disk /dev/sdd. This allows mdadm to rebuild the RAID 5 array onto the new disk, restoring redundancy. The commands 'mdadm --manage /dev/md0 --fail /dev/sda --remove /dev/sda' followed by 'mdadm --manage /dev/md0 --add /dev/sdd' accomplish this safely.

Exam trap

LFCS often tests the misconception that you can simply add a new disk to a degraded RAID array without first removing the failed disk, when in fact the failed disk must be marked failed and removed before adding the replacement.

How to eliminate wrong answers

Option A is wrong because recreating the array from scratch destroys all data and requires a backup restore, which is unnecessary when the array can be rebuilt with the spare disk. Option C is wrong because directly adding /dev/sdd without first removing the failed /dev/sda would result in a 4-disk array with one failed disk still present, and mdadm may not automatically rebuild onto the new disk; the failed disk must be removed first. Option D is wrong because using LVM to mirror the two healthy disks ignores the failed disk and does not restore the RAID 5 array; it also does not provide the same redundancy and is not the appropriate course of action for a RAID array.

234
MCQeasy

Which tool is the recommended method for persistently configuring network interfaces in RHEL 8?

A.Using the 'ip' command with persistent flags
B.Using nmcli commands
C.Editing /etc/sysconfig/network-scripts/ifcfg-* files directly
D.Using systemd-networkd configuration files
AnswerB

NetworkManager is the default RHEL 8 network service, and nmcli writes settings into persistent connection profiles under /etc/NetworkManager/system-connections, so they survive reboot. Editing ifcfg files directly or using ip commands only changes runtime state, failing the persistence requirement.

Why this answer

In RHEL 8, NetworkManager is the default networking daemon, and 'nmcli' is the recommended command-line tool for persistently configuring network interfaces. Unlike temporary 'ip' commands, nmcli writes configuration to NetworkManager connection profiles, ensuring changes survive reboots. Red Hat officially deprecates direct editing of ifcfg files in RHEL 8 and uses NetworkManager as the primary interface.

Exam trap

The trap here is that candidates familiar with older RHEL versions (6/7) may default to editing ifcfg files directly, not realizing that RHEL 8 deprecates this method and officially recommends nmcli for persistent configuration.

How to eliminate wrong answers

Option A is wrong because the 'ip' command only makes runtime changes that are lost on reboot; it has no persistent flags to save configuration. Option C is wrong because while ifcfg files are still read by NetworkManager for backward compatibility, Red Hat deprecates direct editing in RHEL 8 and recommends nmcli or nmtui instead. Option D is wrong because systemd-networkd is not the default or recommended network stack in RHEL 8; RHEL 8 uses NetworkManager, not systemd-networkd.

235
MCQeasy

A server is running out of disk space. Which command will show the disk usage of the root filesystem in a human-readable format?

A.ls -lh /
B.df -h /
C.fdisk -l /
D.du -sh /
AnswerB

The -h flag converts raw block counts into human-readable units such as G and M, while the / argument restricts output to the root filesystem alone, directly satisfying the scenario's need to identify space consumption there.

Why this answer

The `df -h /` command displays disk usage for the root filesystem (`/`) in a human-readable format (e.g., GB, MB) by using the `-h` flag. This is the standard tool for checking filesystem-level disk space, not directory-level usage.

Exam trap

The trap here is that candidates confuse `du` (directory usage) with `df` (filesystem usage), often picking `du -sh /` because it shows a large number, but they fail to realize it does not report filesystem capacity or available space, which is what the question explicitly asks for.

How to eliminate wrong answers

Option A is wrong because `ls -lh /` lists the contents of the root directory with sizes in human-readable format, but it does not show disk usage of the filesystem itself—it only shows file and directory sizes, which is not the same as filesystem capacity or usage. Option C is wrong because `fdisk -l /` is used to manipulate or display the partition table of a disk device (e.g., `/dev/sda`), not to show filesystem disk usage; passing `/` as an argument is invalid and will produce an error. Option D is wrong because `du -sh /` calculates the total disk usage of all files and directories under `/` (i.e., the entire filesystem tree), but it does not show the filesystem's total capacity or available space; it also takes significantly longer to run and is not the intended command for checking filesystem-level disk usage.

236
Drag & Dropmedium

Order the steps to configure a cron job that runs a script every day at 2 AM.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order to configure a cron job is: open the crontab file with 'crontab -e', add the cron expression with the correct time fields (minute, hour, day, month, weekday) and the script path, save the file, and then verify with 'crontab -l'. Common mistakes include adding the line before opening the editor, saving before adding, or verifying before editing.

237
Multi-Selectmedium

Which TWO commands can be used to display the routing table on a Linux system? (Choose two.)

Select 2 answers
A.route -n
B.ip route
C.ss -r
D.traceroute
E.ping -R
AnswersA, B

Route command with -n shows numeric routes.

Why this answer

The `route -n` command displays the kernel IP routing table with numeric addresses, showing destination, gateway, netmask, and interface. The `ip route` command from the iproute2 suite shows the same routing table with more detail and is the modern replacement for `route`. Both are standard tools for viewing routing information on Linux.

Exam trap

The trap here is that candidates confuse `ss` with `route` or `ip` because `ss` is a socket statistics tool, and the `-r` option might be misread as 'route', but `ss -r` only resolves hostnames in its output and does not display routing information.

238
MCQhard

A Linux server is experiencing performance issues. The administrator suspects that a process is causing excessive disk I/O. Which command should the administrator use to identify the process with the highest disk I/O usage in real-time?

A.iotop
B.vmstat 1
C.top
D.iostat -x 1
AnswerA

iotop is a specialized tool that displays real-time disk I/O usage by process. It shows which processes are reading from or writing to disk, along with the amount of I/O. This directly addresses the administrator's need to identify the process with the highest disk I/O. Running iotop (often with sudo) provides a top-like interface for I/O, making it the correct choice.

Why this answer

The tool iotop is designed to monitor disk I/O usage per process in real-time. It displays a list of processes sorted by I/O, allowing the administrator to quickly identify the culprit. Other tools like top, iostat, and vmstat provide system-wide or per-device statistics but lack per-process I/O attribution, making them less effective for this specific troubleshooting task.

Exam trap

The trap here is assuming that top or iostat can show per-process disk I/O by default, but they do not; only iotop provides that granularity.

239
MCQeasy

To compress a file while preserving the original file, which command should be used?

A.gzip file.txt
B.gzip -d file.txt.gz
C.gzip -1 file.txt
D.gzip -k file.txt
AnswerD

The `-k` flag instructs gzip to retain the source file after compression, directly satisfying the stem's requirement to preserve the original. Without it, gzip deletes `file.txt` and leaves only `file.txt.gz`. This makes `gzip -k file.txt` the precise command for producing a compressed copy while keeping the original intact.

Why this answer

The `-k` (or `--keep`) flag in `gzip` instructs the utility to compress the file while retaining the original uncompressed file. By default, `gzip` replaces the original file with a compressed version (appending `.gz`), so `-k` is the explicit option to preserve the source file.

Exam trap

Linux Foundation often tests the default behavior of `gzip` (which deletes the original) versus the `-k` flag, trapping candidates who assume compression always preserves the source file without an explicit option.

How to eliminate wrong answers

Option A is wrong because `gzip file.txt` compresses the file and, by default, deletes the original `file.txt`, leaving only `file.txt.gz`. Option B is wrong because `gzip -d file.txt.gz` decompresses the archive, which does not compress a file and also removes the `.gz` file unless `-k` is used. Option C is wrong because `gzip -1 file.txt` sets the compression level to fastest (level 1), but still removes the original file; the `-1` flag does not affect file preservation.

240
MCQhard

An administrator needs to encrypt a block device (/dev/sdc) using LUKS. Which command creates an encrypted LUKS container on the device?

A.cryptsetup luksOpen /dev/sdc encrypted_device
B.cryptsetup luksFormat /dev/sdc
C.openssl enc -aes-256-cbc -in /dev/sdc -out /dev/sdc.enc
D.dm-crypt create encrypted /dev/sdc
AnswerB

cryptsetup luksFormat initialises a LUKS header on the block device, establishing the encrypted container and prompting for the passphrase. This is the required first step before luksOpen maps it, satisfying the encryption requirement for /dev/sdc.

Why this answer

`cryptsetup luksFormat /dev/sdc` initializes the block device with a LUKS header, setting up an encrypted container that can later be opened with a passphrase or key file. This is the standard command for creating a new LUKS partition, as it writes the LUKS metadata and prepares the device for encryption.

Exam trap

The trap here is that candidates confuse `luksFormat` (which creates the container) with `luksOpen` (which opens/maps it), or they think a generic encryption tool like `openssl enc` can replace LUKS for block device encryption.

How to eliminate wrong answers

Option A is wrong because `cryptsetup luksOpen` is used to map an existing LUKS container to a device mapper name (e.g., /dev/mapper/encrypted_device), not to create a new encrypted container. Option C is wrong because `openssl enc` performs file-level encryption using a cipher like AES-256-CBC, but it does not create a LUKS container or handle block device encryption with proper metadata; it would produce an encrypted file, not a usable encrypted block device. Option D is wrong because `dm-crypt create` is not a valid command; the correct tool for device-mapper encryption is `cryptsetup`, and the syntax `dm-crypt create` does not exist in standard Linux utilities.

241
MCQhard

An administrator is creating a systemd timer unit called backup.timer that should trigger backup.service every day at 2:00 AM. The timer should also run the service immediately if the system was powered off at 2:00 AM. Which timer directives are required to achieve this?

A.OnCalendar=*-*-* 02:00:00 and Persistent=true
B.OnBootSec=2h and OnUnitActiveSec=1d
C.OnCalendar=02:00 and Persistent=false
D.OnCalendar=daily and AccuracySec=1h
AnswerA

OnCalendar=*-*-* 02:00:00 schedules the timer to trigger daily at 2:00 AM. Persistent=true ensures that if the system was off at the scheduled time, the service runs immediately upon boot. Together, these directives satisfy both the daily schedule and the catch-up requirement. They are placed in the [Timer] section of the timer unit.

Why this answer

The correct directives are OnCalendar with a full calendar specification for 2:00 AM daily and Persistent=true to handle missed runs. OnCalendar=*-*-* 02:00:00 sets the exact time, and Persistent=true stores the last trigger time on disk, so if the system was off, the timer fires immediately on next boot. Other options either set wrong times or lack persistence.

Exam trap

The trap here is using OnCalendar=daily thinking it means 2:00 AM, or forgetting that Persistent=true is needed for catch-up after downtime.

242
MCQeasy

Which command shows the default target for systemd?

A.systemctl show default
B.systemctl list-default
C.systemctl get-default
D.systemctl default
AnswerC

`systemctl get-default` queries systemd's default target directly, printing the target name that `default.target` symlinks to, such as `graphical.target` or `multi-user.target`. This satisfies the stem's requirement to show, rather than change, the boot default, unlike `systemctl isolate` or `set-default`, which alter runtime or persistent state.

Why this answer

The correct command to display the default target (the systemd unit that the system boots into by default) is `systemctl get-default`. This command reads the symlink at `/etc/systemd/system/default.target` and outputs its target, such as `multi-user.target` or `graphical.target`. Option C is correct because it directly queries systemd for the current default boot target.

Exam trap

The trap here is that candidates confuse `systemctl get-default` with `systemctl default` (which activates the default target) or with non-existent commands like `systemctl list-default`, leading them to pick a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because `systemctl show default` is not a valid systemctl subcommand; `systemctl show` is used to display properties of a unit (e.g., `systemctl show sshd.service`), not to retrieve the default target. Option B is wrong because `systemctl list-default` does not exist; the correct subcommand for listing targets is `systemctl list-units --type=target`, which shows all loaded target units, not the default one. Option D is wrong because `systemctl default` is a valid command but it changes the current target to the default target (i.e., it activates the default boot target), not displays it.

243
MCQeasy

Refer to the exhibit. The /var partition is 100% full. Which command can be used to find the largest files in /var/log to free up space?

A.ls -lS /var/log
B.find /var/log -size +100M
C.du -ah /var/log | sort -rh | head
D.df -h /var/log
AnswerC

Sorting by human-readable size in reverse order surfaces the largest entries first, satisfying the need to reclaim space in the full /var partition. The -a flag includes files as well as directories, so head returns the biggest space consumers in /var/log.

Why this answer

It uses `du -ah` to list all files and directories in /var/log with human-readable sizes, pipes the output to `sort -rh` to sort them in reverse numerical order (largest first), and then uses `head` to display only the top entries. This combination efficiently identifies the largest files consuming space, allowing the administrator to target specific files for cleanup.

Exam trap

The trap here is that candidates may choose `ls -lS` (option A) because it sorts by size, but they overlook that it does not recurse into subdirectories, making it ineffective for a directory tree like /var/log that typically contains multiple subdirectories.

How to eliminate wrong answers

Option A is wrong because `ls -lS /var/log` lists files sorted by size, but it does not recurse into subdirectories, so it will miss large files in subdirectories like /var/log/journal or /var/log/nginx. Option B is wrong because `find /var/log -size +100M` only finds files larger than 100 MB, but the /var partition could be full due to many smaller files accumulating to fill the space, and it does not sort or prioritize the largest files. Option D is wrong because `df -h /var/log` shows the disk usage of the /var/log filesystem (or partition), not the sizes of individual files, so it cannot identify which files to delete.

244
MCQmedium

An administrator runs 'systemctl status sshd' and sees the output above. The administrator wants sshd to start automatically at boot. Which command should be used?

A.systemctl reenable sshd
B.systemctl mask sshd
C.systemctl start sshd
D.systemctl enable sshd
AnswerD

systemctl enable creates the symlinks in the appropriate target's .wants directory, so systemd starts sshd automatically during boot. It does not start the unit now, which is why enable is paired with start when immediate activation is also needed.

Why this answer

The `systemctl enable sshd` command creates the necessary symlinks in the systemd unit configuration directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) so that the sshd service is started automatically at boot. This is the correct way to configure a service to start on boot in a systemd-based Linux distribution.

Exam trap

The trap here is confusing `systemctl start` (immediate runtime start) with `systemctl enable` (persistent boot-time start), leading candidates to choose Option C when the question explicitly asks for automatic startup at boot.

How to eliminate wrong answers

Option A is wrong because `systemctl reenable sshd` is not a valid systemd command; the correct command to re-enable a service is `systemctl enable sshd` (which removes and recreates symlinks if already enabled). Option B is wrong because `systemctl mask sshd` prevents the service from being started manually or automatically by linking it to `/dev/null`, which is the opposite of what is needed. Option C is wrong because `systemctl start sshd` starts the service immediately but does not configure it to start automatically at boot; it only affects the current runtime state.

245
MCQmedium

An administrator has created an LVM thin pool. Which command should be used to create a thin logical volume named 'thinvol' of size 100GB from the thin pool 'pool1' in volume group 'vg1'?

A.lvcreate -L 100G -n thinvol vg1
B.lvcreate -s vg1/pool1 -n thinvol
C.lvcreate -V 100G -T vg1/pool1 --name thinvol
D.lvcreate -L 100G -T vg1/pool1 --name thinvol
AnswerC

The -V flag creates a virtual (thin) volume, while -T names the thin pool vg1/pool1 as its backing store. This pairing is what distinguishes thin provisioning from a standard linear LV, satisfying the 100GB thinvol requirement.

Why this answer

The `lvcreate` command for thin logical volumes requires the `-V` flag to specify the virtual size of the thin volume and the `-T` flag to reference the thin pool. The syntax `-V 100G -T vg1/pool1 --name thinvol` correctly creates a thin logical volume named 'thinvol' with a virtual size of 100GB from the thin pool 'pool1' in volume group 'vg1'.

Exam trap

The trap here is that candidates often confuse the `-L` flag (used for standard LVs or pool sizes) with the `-V` flag (required for thin volumes), leading them to select option D, which incorrectly uses `-L` instead of `-V` for the thin volume's virtual size.

How to eliminate wrong answers

Option A is wrong because `lvcreate -L 100G -n thinvol vg1` creates a standard (thick) logical volume, not a thin logical volume, and does not reference a thin pool. Option B is wrong because `lvcreate -s vg1/pool1 -n thinvol` is used to create a snapshot, not a thin logical volume; the `-s` flag creates a snapshot of an existing logical volume. Option D is wrong because `lvcreate -L 100G -T vg1/pool1 --name thinvol` uses the `-L` flag to specify the size, but for thin volumes, the `-V` flag must be used to define the virtual size; `-L` is for the pool's metadata or data size, not the thin volume's virtual size.

246
MCQmedium

A Linux server uses LVM. The volume group vg_data has 10 GB of free extents. The logical volume /dev/vg_data/lv_app is 20 GB and must be increased by 5 GB while it is mounted and actively used by an application. Which command sequence correctly extends the logical volume and then grows the ext4 filesystem online?

A.lvextend -L +5G /dev/vg_data/lv_app && xfs_growfs /dev/vg_data/lv_app
B.lvextend -L +5G /dev/vg_data/lv_app && resize2fs /dev/vg_data/lv_app
C.lvresize -L +5G /dev/vg_data/lv_app && resize2fs /dev/vg_data/lv_app
D.lvextend -L 25G /dev/vg_data/lv_app && e2fsck -f /dev/vg_data/lv_app
AnswerB

lvextend -L +5G adds 5 GB to the logical volume, and resize2fs then expands the ext4 filesystem to use the new space. Because ext4 supports online resizing, this sequence works while the filesystem is mounted. This is the standard, safe method to grow both the LV and the filesystem without unmounting.

Why this answer

To extend an ext4 filesystem on LVM online, you first increase the logical volume with lvextend, then expand the filesystem with resize2fs. ext4 supports online growth, so the application can continue running. Using xfs_growfs on ext4 or running a filesystem check instead of resize2fs will not achieve the desired result.

Exam trap

The trap here is confusing filesystem-specific growth tools, such as xfs_growfs for XFS, with resize2fs for ext4.

247
MCQeasy

Which command enables a service to start automatically at boot in a systemd-based system?

A.systemctl enable service
B.systemctl set-default service
C.systemctl daemon-reload
D.systemctl start service
AnswerA

'systemctl enable' creates the symlinks under the target's .wants directory that pull the unit into the boot transaction, satisfying automatic start at boot. It does not start the service now; 'systemctl start' handles that separately.

Why this answer

The `systemctl enable` command creates the necessary symlinks in the `/etc/systemd/system/` directory tree (typically `multi-user.target.wants/`) to ensure the specified service unit is started automatically when the system boots. This is the standard mechanism in systemd to configure a service for automatic startup at boot time.

Exam trap

The trap here is confusing `systemctl enable` (which configures automatic boot-time startup) with `systemctl start` (which runs the service immediately but does not persist across reboots), leading candidates to incorrectly choose option D.

How to eliminate wrong answers

Option B is wrong because `systemctl set-default` sets the default target (e.g., `multi-user.target` or `graphical.target`), not a service; it controls which target the system boots into, not individual service autostart. Option C is wrong because `systemctl daemon-reload` reloads systemd manager configuration after unit file changes but does not enable or disable any service for boot-time startup. Option D is wrong because `systemctl start` immediately starts a service in the current session but does not configure it to start automatically at future boots.

248
MCQmedium

You manage a Linux server that provides DHCP services to a small office network using the dhcpd daemon. The server has two network interfaces: eth0 (192.168.1.1/24) serving the internal network, and eth1 (192.168.0.1/24) connected to a DMZ. The DHCP server is configured to serve addresses only on eth0. Users on the internal network report that they are not receiving IP addresses. You check the DHCP server and find that the dhcpd service is running and listening on UDP port 67. From a client, you run tcpdump and see DHCPDISCOVER packets being sent, but no DHCPOFFER from the server. You also verify that no firewall rules are blocking DHCP traffic on either side. What is the most likely reason for the failure?

A.The DHCP server's IP address is not in the same subnet as the clients.
B.The dhcpd configuration file does not have a subnet declaration for the 192.168.1.0/24 network.
C.The dhcpd service is not running.
D.The network switch is blocking broadcast packets.
AnswerB

dhcpd only offers leases for subnets declared in its configuration. Without a subnet declaration for 192.168.1.0/24, the daemon receives DHCPDISCOVER on eth0 but has no address pool or scope to answer from, so no DHCPOFFER is sent despite the service listening.

Why this answer

The dhcpd daemon will only respond to DHCPDISCOVER packets on interfaces for which it has a matching subnet declaration in its configuration file (typically /etc/dhcp/dhcpd.conf). Without a subnet declaration for 192.168.1.0/24, dhcpd ignores all DHCP traffic on eth0, even though the service is running and listening on UDP port 67. The absence of DHCPOFFER packets despite seeing DHCPDISCOVERs confirms that the server is not processing the requests for that subnet.

Exam trap

The trap here is that candidates assume a running service with an open port (UDP 67) is sufficient to serve DHCP, but the dhcpd daemon requires explicit subnet declarations to process requests on each interface.

How to eliminate wrong answers

Option A is wrong because the DHCP server's IP address (192.168.1.1) is in the same subnet as the clients (192.168.1.0/24), so subnet mismatch is not the issue. Option C is wrong because the problem states the dhcpd service is running and listening on UDP port 67, so the service is operational. Option D is wrong because the switch blocking broadcast packets would prevent DHCPDISCOVERs from reaching the server, but the tcpdump shows DHCPDISCOVER packets are being sent, and no firewall rules are blocking traffic, so the switch is not the cause.

249
MCQhard

A system administrator is troubleshooting network connectivity from a Linux server to a remote host at 10.0.0.1. The server has a default gateway of 192.168.1.1. Running `ping 10.0.0.1` fails, but `ping 192.168.1.1` succeeds. The output of `ip route show` shows a default route via 192.168.1.1. Which additional step should the administrator take to further investigate?

A.Check the ARP table for 10.0.0.1.
B.Verify that the firewall on the remote host allows ICMP.
C.Run traceroute to 10.0.0.1 to see where packets are dropped.
D.Check if the remote host is in the same subnet as the server.
AnswerC

Traceroute maps each hop along the path to 10.0.0.1, revealing where packets stop or time out. Since the default gateway responds, the fault lies beyond it; traceroute pinpoints the failing router or firewall hop, satisfying the need to isolate where connectivity breaks.

Why this answer

The ping to the default gateway succeeds, confirming local network and ARP resolution are functional, while the ping to the remote host fails. Running traceroute to 10.0.0.1 will reveal the exact hop where packets are dropped, isolating whether the issue lies in routing beyond the gateway, a firewall along the path, or a missing route on an intermediate router.

Exam trap

The trap here is that candidates assume a failed ping to a remote host must be due to a local ARP issue or firewall on the destination, but the successful ping to the gateway proves local connectivity works, making traceroute the logical next step to trace the path.

How to eliminate wrong answers

Option A is wrong because the ARP table is only relevant for hosts on the same subnet; 10.0.0.1 is not on the local subnet (the server's IP is presumably in 192.168.1.0/24), so ARP will never contain an entry for it. Option B is wrong because the question asks for the next step in investigating the connectivity issue from the server's perspective; while the remote host's firewall could block ICMP, the administrator should first verify the path with traceroute before assuming a firewall issue. Option D is wrong because the remote host is clearly not in the same subnet (10.0.0.1 vs. 192.168.1.0/24), and the successful ping to the gateway confirms the server is correctly forwarding traffic to the default route.

250
MCQmedium

A user reports that they cannot log in via SSH, but other users can. The administrator checks /var/log/auth.log and sees 'Failed password for invalid user'. What is the most likely cause?

A.The user's SSH key is not authorized
B.The user account is locked
C.The user does not exist on the system
D.The user's password has expired
AnswerC

The message 'Failed password for invalid user' is emitted by sshd when the supplied username is absent from the local account database, so authentication fails before any password comparison. Other users succeed because their accounts exist, matching the stem's selective failure.

Why this answer

The log message 'Failed password for invalid user' specifically indicates that the username presented during the SSH authentication attempt does not correspond to any account in the system's user database (e.g., /etc/passwd). This is distinct from a valid user failing authentication; the SSH server (sshd) rejects the session at the authentication stage because the user does not exist. Therefore, the most likely cause is that the user account does not exist on the system.

Exam trap

The trap here is that candidates confuse 'invalid user' (non-existent account) with 'valid user, wrong credentials' (e.g., locked account, expired password, or bad key), but the log message explicitly distinguishes between these two cases.

How to eliminate wrong answers

Option A is wrong because an SSH key not being authorized would generate a 'Failed publickey for <valid_user>' message, not 'invalid user'. Option B is wrong because a locked account (e.g., via `passwd -l` or expired password) would produce a 'Failed password for <valid_user>' or 'Authentication failure' log entry, not 'invalid user'. Option D is wrong because an expired password triggers a password change prompt or a 'Password expired' message during authentication, and the log would still reference a valid username, not 'invalid user'.

251
Multi-Selectmedium

A Linux server has an interface eth0 with IP 192.168.1.100/24. You need to temporarily add a secondary IP address 192.168.1.101/24 to the same interface for testing, and then verify that both addresses are present. Which two commands will accomplish this? (Choose two.)

Select 2 answers
A.ip link set eth0 up
B.ip addr show dev eth0
C.ip route add 192.168.1.101/24 dev eth0
D.ip addr add 192.168.1.101/24 dev eth0
E.ifconfig eth0 192.168.1.101 netmask 255.255.255.0
AnswersB, D

The 'ip addr show dev eth0' command displays all IP addresses configured on eth0, including the primary and any secondary addresses. This is the correct way to verify that both 192.168.1.100 and 192.168.1.101 are present. It is the standard verification command for IP configuration.

Why this answer

To add a secondary IP address temporarily, use 'ip addr add 192.168.1.101/24 dev eth0'. To verify, use 'ip addr show dev eth0'. The ifconfig command would replace the primary address, not add a secondary.

The ip route command is for routing, and ip link set up only changes the interface state.

Exam trap

The trap here is using ifconfig without an alias, which replaces the primary IP instead of adding a secondary, and confusing ip route with ip addr.

252
MCQhard

A system administrator configures a new server with multiple disks. After partitioning and formatting, they mount a partition to /data. Several days later, they notice that the /data filesystem is full, but 'du -sh /data' reports only 2 GB used, while the partition is 100 GB. 'df -h' shows /data is 98% full. What is the most likely cause and the correct action?

A.The filesystem is fragmented. Run 'e4defrag' to defragment.
B.The filesystem has reserved blocks for root. Reduce the reserved percentage with 'tune2fs -m 0'.
C.The 'du' command is not counting hidden files (dot files). Use 'du -sh .*' to include them.
D.There are deleted files still held open by processes. Use 'lsof /data' to find and restart those processes.
AnswerD

Deleted files still held open by running processes keep their blocks allocated, so df reports the space consumed while du cannot see the unlinked inodes. lsof /data identifies the offending processes; restarting them releases the file descriptors and reclaims the 96 GB discrepancy.

Why this answer

When a file is deleted but still held open by a running process, the filesystem does not release the disk blocks until the process closes the file descriptor. This causes 'df' to report the space as used, while 'du' cannot see the deleted file's data, leading to the discrepancy. Using 'lsof /data' identifies the processes holding the deleted files, and restarting them frees the space.

Exam trap

The trap here is that candidates often confuse the 'du' vs 'df' discrepancy with hidden files or reserved blocks, but the key clue is that 'du' shows far less usage than 'df', which points to unlinked but still-open files.

How to eliminate wrong answers

Option A is wrong because filesystem fragmentation does not cause a discrepancy between 'du' and 'df'; fragmentation affects performance, not space accounting. Option B is wrong because reserved blocks for root (default 5% on ext4) are counted as used by 'df' but are not the cause of a 98% full partition when only 2 GB is used; reducing the reserved percentage would free space but does not explain the discrepancy. Option C is wrong because 'du -sh /data' already counts all files including hidden files (dot files) by default; the '-sh' option sums the total size, and hidden files are included in that total.

253
MCQhard

A system administrator needs to schedule a one-time task that will run at 2:30 AM on July 15. Which command should be used to create this job?

A.at 2:30 AM July 15
B.crontab -e
C.systemd-run --on-calendar="*-07-15 02:30:00"
D.batch
AnswerA

The at command schedules a one-time task at a specified time and date. Running at 2:30 AM July 15 enters an interactive prompt where the command can be typed, and it will execute once at that time. This is the correct tool for one-time scheduling.

Why this answer

The at command is specifically designed for scheduling one-time tasks at a precise date and time. Using at 2:30 AM July 15 allows the administrator to queue a command that will execute once at that moment, fulfilling the requirement.

Exam trap

The trap here is confusing one-time scheduling with recurring jobs; cron is for recurring tasks, while at handles single executions.

254
MCQhard

An administrator needs to ensure that a custom service, /usr/local/bin/monitor.sh, starts automatically at boot and is restarted if it crashes. The service should run as user 'monitor' and should not depend on network being online. Which systemd unit file configuration is most appropriate?

A.Create a unit file with [Service] Type=simple, ExecStart=/usr/local/bin/monitor.sh, Restart=on-abnormal, User=monitor, and [Install] WantedBy=multi-user.target.
B.Create a unit file with [Service] Type=simple, ExecStart=/usr/local/bin/monitor.sh, Restart=always, User=monitor, and [Install] WantedBy=multi-user.target.
C.Create a unit file with [Service] Type=simple, ExecStart=/usr/local/bin/monitor.sh, Restart=always, User=monitor, and [Install] WantedBy=graphical.target.
D.Create a unit file with [Service] Type=forking, ExecStart=/usr/local/bin/monitor.sh, Restart=on-failure, User=monitor, and [Install] WantedBy=network-online.target.
AnswerB

This configuration defines a simple service that runs the script, restarts on any exit, runs as the specified user, and is enabled at boot via multi-user.target. It meets all requirements: automatic start, restart on crash, user context, and no network dependency. The Type=simple is appropriate for a script that does not fork.

Why this answer

A systemd service unit must specify the correct Type, ExecStart, Restart policy, User, and installation target. For a script that runs in the foreground, Type=simple is suitable. Restart=always ensures the service is restarted regardless of exit status, providing resilience.

User=monitor runs it with least privilege. WantedBy=multi-user.target enables start at boot without network dependency. This combination satisfies all stated requirements.

Exam trap

The trap here is assuming that Restart=on-failure covers all crash scenarios, but a script might exit with status 0 even after an internal error.

255
MCQmedium

A system administrator needs to list all files in the current directory, including hidden files, in a long listing format sorted by modification time (oldest first). Which command achieves this?

A.ls -lihrt
B.ls -lart
C.ls -lat
D.ls -lrt
AnswerB

Correct: long, all, reverse, time.

Why this answer

`ls -lart` combines the `-l` (long listing), `-a` (include hidden files starting with dot), `-r` (reverse order), and `-t` (sort by modification time, newest first). The reverse flag flips the sort to oldest first, meeting the requirement exactly.

Exam trap

The trap here is that candidates often remember `-lt` for time-sorted listing but forget that `-a` is required to include hidden files, or they confuse the order and omit `-r` to reverse to oldest first.

How to eliminate wrong answers

Option A is wrong because `ls -lihrt` includes `-i` (inode number) and `-h` (human-readable sizes), which are not requested, and while it sorts by time and reverses, it lacks `-a` so hidden files are omitted. Option C is wrong because `ls -lat` sorts by modification time but newest first, not oldest first, as the `-r` flag is missing. Option D is wrong because `ls -lrt` sorts by time and reverses to oldest first, but it lacks `-a`, so hidden files are not listed.

256
MCQeasy

A system administrator wants to configure a custom service to start automatically at boot. Which command accomplishes this?

A.systemctl daemon-reload custom.service
B.systemctl enable custom.service
C.systemctl reenable custom.service
D.systemctl start custom.service
AnswerB

`systemctl enable custom.service` creates a symlink from the service unit file in `/etc/systemd/system` into the appropriate multi-user.target.wants directory, which instructs systemd to start the service automatically at boot. This satisfies the stem’s requirement for a custom service to be launched during the boot sequence without manual intervention, leveraging systemd’s dependency-based parallel startup mechanism.

Why this answer

The `systemctl enable custom.service` command creates the necessary symlinks in the systemd unit file directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) so that the service is automatically started at boot. This is the correct method to configure a custom service for automatic startup in a systemd-based Linux distribution.

Exam trap

The trap here is that candidates confuse `systemctl start` (immediate runtime start) with `systemctl enable` (boot-time persistence), leading them to select option D when the question specifically asks for automatic boot-time configuration.

How to eliminate wrong answers

Option A is wrong because `systemctl daemon-reload` reloads the systemd manager configuration after unit files have been changed, but it does not enable a service to start at boot. Option C is wrong because `systemctl reenable` removes and then recreates the enablement symlinks, which is useful for resetting the enablement state but is not the standard command for initially enabling a service. Option D is wrong because `systemctl start` immediately starts the service in the current session but does not configure it to start automatically at boot.

257
MCQmedium

A server is experiencing high load, and the administrator suspects a runaway process is consuming excessive CPU. The administrator wants to identify the top CPU-consuming processes and then terminate the most resource-intensive one. Which sequence of commands should the administrator use?

A.Run 'vmstat 1' to identify the PID, then run 'pkill -f <process_name>'.
B.Run 'ps aux --sort=-%mem' to find the top CPU process, then run 'kill -15 <PID>'.
C.Run 'iostat -c' to identify the PID, then run 'killall <process_name>'.
D.Run 'top' to identify the PID with highest CPU usage, then run 'kill -9 <PID>'.
AnswerD

top provides a real-time, sorted view of processes by CPU usage, making it easy to spot the top consumer. Once the PID is known, kill -9 sends SIGKILL, which forcibly terminates the process. This combination directly addresses the goal of identifying and stopping the runaway process, though SIGKILL should be used as a last resort.

Why this answer

To find the process consuming the most CPU, a tool that shows per-process CPU usage sorted dynamically is needed. top provides that view and allows the administrator to note the PID. Once the PID is known, kill -9 sends SIGKILL to forcibly terminate it. The other options either use tools that lack per-process CPU details or send signals that may not stop a runaway process, and they do not correctly identify the top CPU consumer.

Exam trap

The trap here is confusing tools that show system-wide CPU statistics with those that show per-process CPU usage, and assuming a graceful signal will always stop a runaway process.

258
MCQhard

A system running RHEL 8 experiences intermittent crashes. After reboot, 'journalctl -p err -b -1' outputs: 'PID 1234 (myapp) ended due to signal: KILL'. Which diagnostic step should the administrator perform next?

A.Review logrotate configuration for myapp logs.
B.Run strace to capture system calls of myapp before restarting.
C.Enable core dumps and reproduce issue.
D.Check journalctl for 'oom-kill' entries or use 'dmesg | grep -i oom'.
AnswerD

SIGKILL combined with intermittent crashes points to the kernel OOM killer terminating myapp. Checking journalctl for oom-kill entries or grepping dmesg confirms whether memory exhaustion, not an application fault, caused the kill, directing the next diagnostic step.

Why this answer

The 'PID ended due to signal: KILL' message indicates the process was terminated by a SIGKILL (signal 9), which is commonly sent by the Out-Of-Memory (OOM) killer when the system runs low on memory. Checking journalctl for 'oom-kill' entries or using 'dmesg | grep -i oom' directly confirms whether the OOM killer was responsible, making D the correct next diagnostic step.

Exam trap

The trap here is that candidates may confuse 'signal: KILL' with a manual kill command or a segmentation fault, leading them to choose core dumps (C) or strace (B), when the specific signal name 'KILL' (SIGKILL) points directly to the OOM killer or an explicit kill -9, and the OOM killer is the most common cause in intermittent crash scenarios.

How to eliminate wrong answers

Option A is wrong because logrotate configuration affects log rotation and compression, not process termination causes; it would not help diagnose why myapp was killed. Option B is wrong because strace captures system calls of a running process, but myapp has already crashed and cannot be traced without reproducing the issue first; this is a premature step before confirming the root cause. Option C is wrong because enabling core dumps and reproducing the issue is useful for debugging segmentation faults or other signals (e.g., SIGSEGV), but SIGKILL cannot be caught or handled by the process, so no core dump is generated; this step would be ineffective here.

259
MCQeasy

Which command can be used to display the UUID of a filesystem on /dev/sdb1?

A.blkid /dev/sdb1
B.tune2fs -l /dev/sdb1
C.df -h /dev/sdb1
D.lsblk /dev/sdb1
AnswerA

`blkid /dev/sdb1` queries the block device directly, reading the filesystem superblock to report its UUID, TYPE and LABEL. Because it inspects the device itself rather than mount tables, it satisfies the stem's requirement to display the UUID of the filesystem on that specific unmounted partition.

Why this answer

The blkid command is specifically designed to locate and print block device attributes, including the UUID and filesystem type. When run against a device like /dev/sdb1, it queries the kernel's device mapper and reads the filesystem superblock to extract the universally unique identifier (UUID). This is the most direct and reliable method for displaying a filesystem's UUID.

Exam trap

The trap here is that candidates often assume tune2fs -l is the universal UUID display tool, but it only works on ext2/3/4 filesystems, whereas blkid works across all Linux filesystem types and is the standard command for this task.

How to eliminate wrong answers

Option B (tune2fs -l /dev/sdb1) is wrong because tune2fs is an ext2/ext3/ext4 filesystem tuning tool; while it can display the UUID in its output, it only works on ext2/3/4 filesystems and will fail or produce no UUID for other types like XFS or Btrfs. Option C (df -h /dev/sdb1) is wrong because df reports disk space usage for mounted filesystems, not UUIDs; it shows mount points and capacity, not block device attributes. Option D (lsblk /dev/sdb1) is wrong because lsblk lists block devices and their partitions, but by default it does not display UUIDs unless the -f or -o UUID option is used; without those flags, it shows only device names, sizes, and mount points.

260
MCQeasy

A user needs to view the contents of a large text file one screen at a time. Which command is best for this?

A.nl file.txt
B.more file.txt
C.cat file.txt
D.less file.txt
AnswerD

'less' opens the file in a pager, letting the user scroll forward and backward one screen at a time without loading the whole file into memory. This suits large files where 'cat' would flood the terminal.

Why this answer

`less` is a terminal pager that allows forward and backward navigation through a file, making it ideal for viewing large text files one screen at a time. Unlike `more`, `less` supports scrolling both up and down, and it does not load the entire file into memory, which is efficient for large files.

Exam trap

The trap here is that candidates often confuse `more` and `less` because both display content one screen at a time, but `less` is the more powerful and recommended tool for interactive viewing, and the LFCS exam expects you to know that `less` is the best choice for this task.

How to eliminate wrong answers

Option A is wrong because `nl` numbers lines and outputs the entire file to stdout without pausing, so it is not suitable for viewing one screen at a time. Option B is wrong because while `more` does display content one screen at a time, it only allows forward navigation (space bar) and cannot scroll backward, making it less flexible than `less` for interactive viewing. Option C is wrong because `cat` concatenates and outputs the entire file to stdout at once, which will flood the terminal and is not designed for paging.

261
MCQmedium

A Linux server has a volume group named vg_data that contains a logical volume lv_archive currently formatted with XFS and mounted at /archive. The administrator needs to shrink the logical volume to free space for a new logical volume. Which command sequence correctly reduces the size of lv_archive?

A.umount /archive; xfs_growfs -D 20G /dev/vg_data/lv_archive; lvreduce -L 20G /dev/vg_data/lv_archive; mount /archive
B.umount /archive; lvreduce -L 20G /dev/vg_data/lv_archive; lvresize -r -L 20G /dev/vg_data/lv_archive; mount /archive
C.umount /archive; backup data; lvremove /dev/vg_data/lv_archive; lvcreate -L 20G -n lv_archive vg_data; mkfs.xfs /dev/vg_data/lv_archive; restore data; mount /archive
D.umount /archive; lvreduce -r -L 20G /dev/vg_data/lv_archive; mount /archive
AnswerC

Because XFS does not support shrinking, the only way to reduce the size of an XFS logical volume is to back up the data, remove the logical volume, create a smaller one, make a new XFS filesystem, and restore the data. This sequence correctly performs those steps. The other options incorrectly assume XFS can be shrunk in place, which is not supported.

Why this answer

XFS filesystems cannot be shrunk. To reduce the size of an XFS logical volume, the administrator must back up the data, remove the logical volume, create a new smaller logical volume, format it with XFS, and restore the data. Any attempt to use lvreduce with -r or xfs_growfs to shrink will fail because XFS only supports growing.

Exam trap

The trap here is assuming that XFS can be shrunk like ext4, or that lvreduce -r can handle XFS shrinking, when in fact XFS does not support shrink operations at all.

262
MCQeasy

A junior administrator needs to mount an ISO image located at /opt/install.iso to the /mnt/iso directory to access its contents. Which command accomplishes this?

A.mount --bind /opt/install.iso /mnt/iso
B.losetup /dev/loop0 /opt/install.iso && mount /dev/loop0 /mnt/iso
C.mount -t iso9660 /opt/install.iso /mnt/iso
D.mount -o loop /opt/install.iso /mnt/iso
AnswerD

The -o loop option tells mount to associate the ISO file with a loop device, making it accessible as a block device. This allows the filesystem inside the ISO (usually ISO9660) to be mounted at the specified directory. It is the standard and correct way to mount an ISO image on Linux without burning it to physical media.

Why this answer

Mounting an ISO file requires the loop option so that the kernel treats the file as a block device. The command mount -o loop /opt/install.iso /mnt/iso creates a loop device automatically and mounts the ISO9660 filesystem, making the contents accessible. This is the standard method for accessing ISO images without burning them.

Exam trap

The trap here is forgetting the loop option and specifying only the filesystem type, which fails because mount expects a block device, not a regular file.

263
MCQmedium

A process (PID 1234) is hung and cannot be killed with SIGTERM. To force termination, which signal should be sent?

A.kill -9 1234 (SIGKILL)
B.kill -15 1234 (SIGTERM)
C.kill -2 1234 (SIGINT)
D.kill -1 1234 (SIGHUP)
AnswerA

SIGKILL (signal 9) cannot be caught, blocked or ignored by the process, so the kernel terminates it immediately without waiting for handler cleanup. SIGTERM is catchable, which is why the hung process survived the earlier attempt.

Why this answer

SIGKILL (signal 9) is the correct choice because it cannot be caught, blocked, or ignored by the process. Unlike SIGTERM, which allows the process to perform cleanup, SIGKILL immediately terminates the process at the kernel level, making it the only reliable way to force-kill a hung process that ignores other signals.

Exam trap

The trap here is that candidates often confuse SIGTERM (15) as a 'force kill' signal, not realizing that a hung process can ignore it, while SIGKILL (9) is the only signal that guarantees termination.

How to eliminate wrong answers

Option B (SIGTERM, signal 15) is wrong because it is the default polite termination signal that the process can catch and ignore, which is exactly why it failed to kill the hung process. Option C (SIGINT, signal 2) is wrong because it is typically generated by Ctrl+C and can be caught or ignored by the process, making it ineffective for a hung process. Option D (SIGHUP, signal 1) is wrong because it is primarily used to notify a process of terminal disconnection or to reload configuration, and it can also be caught or ignored, so it will not force termination.

264
MCQhard

A Linux router has two interfaces: wan0 with address 198.51.100.10/24 and lan0 with address 10.10.0.1/24. Hosts on 10.10.0.0/24 can ping the router's lan0 address but cannot reach any Internet host. The administrator has already enabled net.ipv4.ip_forward=1. Which command is required to allow the internal hosts to reach external networks?

A.iptables -t nat -A POSTROUTING -s 10.10.0.0/24 -o wan0 -j MASQUERADE
B.iptables -A FORWARD -i lan0 -o wan0 -j ACCEPT
C.ip route add default via 198.51.100.1 dev lan0
D.iptables -t nat -A PREROUTING -i wan0 -j DNAT --to-destination 10.10.0.1
AnswerA

Because the internal hosts use private addresses that are not routable on the Internet, the router must translate their source addresses to its public wan0 address. A POSTROUTING MASQUERADE rule on the outbound interface performs this source NAT, so return traffic can be de-NATed and delivered back to the internal hosts.

Why this answer

Forwarding lets packets pass between interfaces, but private RFC 1918 sources cannot traverse the public Internet. The router must rewrite the source address of outbound packets to its public address, which is done with source NAT. A POSTROUTING MASQUERADE rule on the WAN interface accomplishes this dynamically, using the interface's current address, and enables return traffic to be mapped back to the correct internal host.

Exam trap

The trap here is believing that enabling ip_forward or adding a FORWARD accept rule is sufficient, when private source addresses must also be translated before they can reach the Internet.

265
Multi-Selectmedium

Which THREE of the following are valid directives for the [Service] section of a systemd unit file?

Select 3 answers
A.Type
B.Requires
C.User
D.ExecStart
E.Description
AnswersA, C, D

Type is a valid [Service] directive controlling how systemd judges the unit started, with values such as simple, forking, oneshot, notify and dbus. It belongs in [Service], not [Unit] or [Install], so it satisfies the stem's section constraint.

Why this answer

Option A (Type) is correct because Type is a [Service]-section directive that tells systemd how to start and track the process (e.g., simple, forking, oneshot, notify, dbus, idle), which is essential for correct service supervision. Option C (User) is correct because User is a [Service]-section directive that sets the UNIX account the service process runs as, a common hardening and permission control. Option D (ExecStart) is correct because ExecStart is a [Service]-section directive that specifies the command line to launch the service, and it is the primary way systemd knows what to execute.

Option B (Requires) does not belong because Requires is a dependency directive valid in the [Unit] section, not [Service]. Option E (Description) does not belong because Description is a metadata directive valid in the [Unit] section, not [Service].

Exam trap

The trap here is that candidates often confuse `[Unit]` directives (like `Requires`, `Description`, `After`) with `[Service]` directives, leading them to select options that are valid in other sections but not in the `[Service]` block.

266
Multi-Selecthard

Which THREE commands can change the priority of an already running process?

Select 3 answers
A.kill -STOP
B.top (press 'r')
C.chrt
D.nice
E.renice
AnswersB, C, E

Pressing 'r' inside top prompts for a PID and a nice value, then calls setpriority() on that running process. This satisfies the stem's requirement to alter priority of an already running process, unlike commands that only set priority at launch.

Why this answer

Option B (top, press 'r') is correct because within the interactive top utility, pressing 'r' prompts for a PID and a new nice value, allowing you to renice an already running process on the fly. Option C (chrt) is correct because chrt sets or changes the scheduling policy and real-time priority of a running process by PID (e.g., chrt -p -f 10 <pid>), directly altering its priority attributes. Option E (renice) is correct because renice is specifically designed to change the nice value of one or more running processes (renice -n 5 -p <pid>), which adjusts their CPU scheduling priority.

Option A (kill -STOP) is incorrect because it only suspends a process with SIGSTOP and does not modify its priority. Option D (nice) is incorrect because nice only launches a new command with a specified nice value; it cannot change the priority of an already running process.

Exam trap

The trap here is that candidates often confuse `nice` (which only sets priority for new processes) with `renice` (which modifies running processes), or mistakenly think `kill -STOP` changes priority when it actually halts the process.

267
MCQmedium

What is the purpose of the chmod 755 command in this exhibit?

A.Add execute permission for the owner only
B.Remove write permission for others
C.Set the setuid bit
D.Set permissions to rwxr-xr-x
AnswerD

Numeric mode 755 grants the owner read, write and execute (7), and group and others read and execute (5), producing rwxr-xr-x. This satisfies the requirement to translate the octal permission value into its symbolic equivalent.

Why this answer

The chmod 755 command sets the file permissions to rwxr-xr-x, meaning the owner has read, write, and execute permissions (7), while the group and others have read and execute permissions (5). This is a common permission set for executable scripts and directories to allow execution without granting write access to non-owners.

Exam trap

The trap here is that candidates often confuse the octal value 755 with adding execute only for the owner (option A) or think it removes write for others (option B), when in fact 755 sets a specific permission mask that includes execute for all and write only for the owner.

How to eliminate wrong answers

Option A is wrong because chmod 755 adds execute permission for the owner, group, and others, not just the owner. Option B is wrong because chmod 755 does not remove write permission for others; it sets the others permission to r-x (read and execute), which already excludes write, but the command is not specifically removing write—it is setting the entire permission triad. Option C is wrong because the setuid bit is set using chmod 4xxx (e.g., chmod 4755), not chmod 755, which uses the octal value 0 for the setuid/setgid/sticky bits.

268
MCQeasy

A Linux administrator needs to temporarily stop a service named 'httpd' without disabling it from starting automatically on subsequent boots. Which command should be used?

A.systemctl stop httpd
B.systemctl mask httpd
C.systemctl disable httpd
D.systemctl kill httpd
AnswerA

`systemctl stop httpd` halts the running unit immediately while leaving its enablement state untouched, so the symlinks in the multi-user.target.wants directory remain intact and the service still starts on subsequent boots. This satisfies the stem's requirement to stop temporarily without disabling autostart, unlike `systemctl disable`, which removes those symlinks.

Why this answer

The `systemctl stop httpd` command sends a SIGTERM signal to the main process of the httpd service, causing it to stop immediately. This action does not modify the service's enablement state, so the service will still start automatically on subsequent boots if it is enabled. This is the correct way to temporarily stop a service without altering its boot-time behavior.

Exam trap

The trap here is that candidates confuse 'stop' with 'disable' or 'mask', thinking that stopping a service also prevents it from starting at boot, when in fact 'stop' only affects the current runtime state and has no effect on boot-time enablement.

How to eliminate wrong answers

Option B is wrong because `systemctl mask httpd` creates a symlink to /dev/null, which prevents the service from being started manually or automatically, even by dependencies, and is not temporary — it requires unmasking to reverse. Option C is wrong because `systemctl disable httpd` removes the symlinks that cause the service to start at boot, permanently altering its enablement state until re-enabled. Option D is wrong because `systemctl kill httpd` sends a signal (default SIGTERM) to the service's control group, but it is not the standard command for stopping a service; it is used for sending arbitrary signals or killing specific processes, and it does not manage the service's unit state or dependencies properly.

269
MCQmedium

A server running Ubuntu 20.04 uses netplan for network configuration. The admin wants to set a static IP address 10.0.0.100/24 on interface enp0s3 with gateway 10.0.0.1 and DNS servers 8.8.8.8 and 8.8.4.4. Which YAML configuration is correct?

A.network: version: 2 ethernets: enp0s3: addresses: - 10.0.0.100/24 gateway: 10.0.0.1 nameservers: addresses: [8.8.8.8, 8.8.4.4]
B.network: version: 2 ethernets: enp0s3: address: 10.0.0.100/24 gateway4: 10.0.0.1 dns-nameservers: 8.8.8.8 8.8.4.4
C.network: ethernets: enp0s3: addresses: 10.0.0.100/24 gateway4: 10.0.0.1 nameservers: addresses: [8.8.8.8, 8.8.4.4]
D.network: version: 2 ethernets: enp0s3: addresses: - 10.0.0.100/24 gateway4: 10.0.0.1 nameservers: addresses: [8.8.8.8, 8.8.4.4]
AnswerD

Correct. Proper Netplan YAML: 'version: 2', 'addresses' as a list, 'gateway4' for IPv4 default gateway, and 'nameservers' with 'addresses' list for DNS servers. All required fields are present and correctly formatted.

Why this answer

It uses the proper Netplan YAML syntax: `addresses` as a list, `gateway4` for the IPv4 default gateway, and `nameservers` with an `addresses` list. This matches the required static IP 10.0.0.100/24, gateway 10.0.0.1, and DNS servers 8.8.8.8 and 8.8.4.4.

Exam trap

The trap here is that candidates confuse the legacy ifupdown syntax (e.g., `address`, `dns-nameservers`) with the required Netplan YAML structure, or forget the mandatory `version: 2` field.

How to eliminate wrong answers

Option A is wrong because it uses `gateway` instead of `gateway4`; Netplan requires `gateway4` for IPv4 gateways. Option B is wrong because it uses `address` (singular) instead of `addresses` (plural list), and `dns-nameservers` is a legacy ifupdown syntax not valid in Netplan. Option C is wrong because it omits the required `version: 2` field, which Netplan mandates for the configuration to be recognized.

270
MCQeasy

A system administrator wants to change the default runlevel (target) of a Linux system from graphical.target to multi-user.target. Which command should they use?

A.systemctl set-default multi-user.target
B.systemctl default multi-user.target
C.systemctl isolate multi-user.target
D.systemctl enable multi-user.target
AnswerA

systemctl set-default multi-user.target changes the default target that systemd boots into. It creates a symbolic link /etc/systemd/system/default.target pointing to multi-user.target. This is the correct and persistent way to change the default runlevel on a systemd-based system. It takes effect on the next boot.

Why this answer

The default target is set by the /etc/systemd/system/default.target symlink. The systemctl set-default command manages this symlink, pointing it to the desired target. isolate switches the current runtime state but does not persist. enable is for enabling units to start automatically, not for setting the boot target. Therefore, set-default is the correct command.

Exam trap

The trap here is confusing the temporary isolate command with the persistent set-default command.

271
MCQeasy

Which of the following commands can be used to display the total, used, and available space for all mounted ext4 filesystems?

A.lsblk
B.fdisk -l
C.df -hT
D.tune2fs -l /dev/sda1
AnswerC

The `-T` flag adds a filesystem type column, letting you filter the output to ext4 only, while `-h` presents total, used, and available space in human-readable units. Plain `df` omits the type column, so it cannot isolate ext4 mounts as the question requires.

Why this answer

The `df -hT` command displays disk space usage for all mounted filesystems, with the `-h` flag providing human-readable sizes (e.g., GB, MB) and the `-T` flag showing the filesystem type (e.g., ext4). This directly meets the requirement to show total, used, and available space for all mounted ext4 filesystems.

Exam trap

The trap here is that candidates often confuse `lsblk` or `fdisk -l` as disk space commands, but these tools show partition layout or device information, not filesystem-level usage statistics like total, used, and available space.

How to eliminate wrong answers

Option A is wrong because `lsblk` lists block devices (e.g., disks and partitions) but does not display filesystem usage statistics like total, used, or available space. Option B is wrong because `fdisk -l` shows partition table information (e.g., start/end sectors, partition types) for disks, not mounted filesystem space usage. Option D is wrong because `tune2fs -l /dev/sda1` displays ext4 filesystem parameters (e.g., block count, reserved blocks) from the superblock, but it only applies to a single specified device and does not show used or available space for all mounted filesystems.

272
Multi-Selectmedium

Which THREE of the following are valid Linux filesystem types that can be used for root partitions on a modern Linux system?

Select 3 answers
A.XFS
B.NTFS
C.FAT32
D.Btrfs
E.ext4
AnswersA, D, E

XFS is a mature, high-performance 64-bit journaling filesystem, and every mainstream distribution supports it as a root partition, including GRUB and initramfs tooling. It satisfies the stem's requirement for a valid modern Linux root filesystem type.

Why this answer

XFS (A) is a valid Linux native filesystem, long supported as a root filesystem and the default on RHEL/CentOS, so it is correct. Btrfs (D) is a modern Linux copy-on-write filesystem with full root-partition support (including subvolumes and snapshots), making it correct. ext4 (E) is the long-standing default Linux filesystem and fully supports being mounted as the root partition, so it is correct. NTFS (B) is Microsoft's Windows filesystem and FAT32 (C) is a legacy FAT variant; although Linux can mount them via drivers, neither is a valid native Linux filesystem type for a root partition on a modern system.

Exam trap

The trap here is that candidates may confuse filesystems that Linux can read/write (like NTFS or FAT32) with native Linux filesystems that are suitable for root partitions, or they may overlook that Btrfs, while less common, is fully supported and valid for root on modern distributions.

273
Multi-Selecteasy

Which TWO commands can be used to mount a filesystem on /dev/sdb1 to /mnt/data?

Select 2 answers
A.mount /mnt/data /dev/sdb1
B.mount /dev/sdb1 /mnt/data
C.mount -t ext4 /dev/sdb1 /mnt/data
D.mount -o loop /dev/sdb1 /mnt/data
E.mount -t auto /dev/sdb1 /mnt/data -o loop
AnswersB, C

The two-argument form lets mount auto-detect the filesystem type from the device's superblock, then attach /dev/sdb1 at /mnt/data. No type or options are required, satisfying the requirement to mount that specific block device at that mount point.

Why this answer

Option B is correct because the standard mount syntax is `mount <device> <mountpoint>`, so `mount /dev/sdb1 /mnt/data` mounts the block device /dev/sdb1 onto the existing directory /mnt/data. Option C is also correct because adding `-t ext4` explicitly specifies the filesystem type, and the device-then-mountpoint order remains valid, so `mount -t ext4 /dev/sdb1 /mnt/data` successfully mounts the ext4 filesystem. Option A is wrong because it reverses the arguments, treating /mnt/data as the device and /dev/sdb1 as the mountpoint.

Option D is wrong because `-o loop` is used to mount a regular file as a loopback device, not a real block device like /dev/sdb1. Option E is wrong because it combines an unnecessary `-t auto` with `-o loop`, which is inappropriate for mounting a physical partition.

Exam trap

Linux Foundation often tests the argument order of the mount command, trapping candidates who confuse the device and mount point positions, especially when combined with options like `-t` or `-o`.

274
Multi-Selectmedium

A system administrator needs to change the group ownership of a file to 'developers' and set the setgid bit on a directory. Which two commands accomplish these tasks? (Choose two.)

Select 2 answers
A.chmod g+s dir
B.chmod u+s dir
C.chown developers: file
D.chown :developers file
E.chmod g+s file
AnswersA, D

The setgid bit on a directory is set with chmod g+s, which makes new files inherit the directory's group. This satisfies the requirement to set the setgid bit on the directory, distinct from changing group ownership of a file.

Why this answer

Option A, 'chmod g+s dir', is correct because the g+s symbolic mode sets the setgid bit on the directory, causing new files and subdirectories created inside it to inherit the directory's group ownership. Option D, 'chown :developers file', is correct because omitting the user and specifying only ':developers' changes the file's group ownership to the 'developers' group while leaving the owner unchanged. Option B, 'chmod u+s dir', is wrong because u+s sets the setuid bit on the owner, not the setgid bit, and setuid on a directory is generally ignored on Linux.

Option C, 'chown developers: file', is wrong because it sets the user owner to 'developers' rather than the group owner. Option E, 'chmod g+s file', is wrong because the task requires setting setgid on a directory, not on a file.

Exam trap

Linux Foundation often tests the distinction between setting the setgid bit on a directory versus a file, and the correct syntax for changing group ownership with `chown :group` versus `chown group:`.

275
MCQeasy

A user reports that they can access websites by IP address but not by domain name. Which command should the administrator use to diagnose the issue?

A.dig google.com
B.netstat -r
C.traceroute 8.8.8.8
D.ping google.com
AnswerA

Name resolution is the failing layer, since IP connectivity works. dig queries DNS directly for google.com, revealing whether the resolver returns an answer, times out, or reports SERVFAIL, isolating DNS from routing or firewall faults.

Why this answer

The user can access websites by IP address but not by domain name, indicating a DNS resolution failure. The `dig` command is the correct diagnostic tool because it directly queries DNS servers to test domain name resolution, bypassing the system's resolver cache and configuration. This allows the administrator to isolate whether the issue lies with DNS resolution or other network layers.

Exam trap

The trap here is that candidates often choose `ping google.com` (Option D) because it's a common connectivity test, but they fail to recognize that the symptom (access by IP but not name) specifically points to DNS, making `dig` the targeted diagnostic tool.

How to eliminate wrong answers

Option B is wrong because `netstat -r` displays the routing table, which is unrelated to DNS resolution; it would not help diagnose why domain names fail to resolve. Option C is wrong because `traceroute 8.8.8.8` tests network path connectivity to an IP address, which is already working per the user's report, and does not involve DNS. Option D is wrong because `ping google.com` would fail due to the same DNS resolution issue, making it useless for diagnosis; it would not reveal whether the problem is with DNS or something else.

276
MCQhard

A Linux administrator is creating a custom systemd timer unit named backup.timer to schedule a daily backup script. The administrator wants the timer to trigger the backup service exactly at 2:00 AM every day, regardless of when the system was last booted. Which timer directive should be used in the [Timer] section of backup.timer?

A.OnStartupSec=2h
B.OnCalendar=*-*-* 02:00:00
C.OnUnitActiveSec=24h
D.OnBootSec=2h
AnswerB

The OnCalendar directive defines a calendar-based schedule using systemd's calendar event format. Specifying *-*-* 02:00:00 means every day at 2:00 AM. This is independent of boot time and ensures the timer triggers at the exact wall-clock time. This is the correct directive for the scenario.

Why this answer

To schedule a task at a specific time of day, such as 2:00 AM daily, the OnCalendar directive is used with a calendar expression. The expression *-*-* 02:00:00 matches every day at 2:00 AM. Other timer directives like OnBootSec, OnStartupSec, and OnUnitActiveSec are monotonic and relative to events like boot or last activation, so they cannot guarantee a fixed wall-clock time.

Therefore, OnCalendar is the correct choice for this scenario.

Exam trap

The trap here is selecting a monotonic timer directive like OnBootSec, which seems to schedule a daily event but actually depends on boot time and will drift if the system is rebooted at different times.

277
MCQeasy

A Linux server needs to resolve the hostname db.internal.example.com to an IP address. The administrator wants to query the DNS server directly without relying on the local resolver cache. Which command should be used?

A.hostname -f
B.ping db.internal.example.com
C.dig db.internal.example.com
D.cat /etc/resolv.conf
AnswerC

The dig command queries DNS servers directly and displays the full response, including the answer, authority, and additional sections. It bypasses the local resolver cache by sending a query to the configured DNS server. This makes it ideal for troubleshooting DNS resolution for a specific hostname.

Why this answer

The dig command is the standard tool for querying DNS servers directly. It sends a DNS query and displays the response, bypassing local caching mechanisms like nscd or systemd-resolved. Other commands either rely on the system resolver, display local host information, or show configuration files without performing a lookup.

Exam trap

The trap here is assuming that any command that resolves a hostname queries DNS directly, when most use the system resolver and cache.

278
MCQeasy

A junior administrator has installed a new 4 TB SATA disk as /dev/sdb on a RHEL 9 server and wants to use it as a single XFS filesystem mounted at /data. The disk currently has no partition table. Which command should be run first to create an XFS filesystem directly on the whole device?

A.mkfs -t xfs /dev/sdb1
B.xfs_growfs /dev/sdb
C.fdisk /dev/sdb && mkfs.xfs /dev/sdb
D.mkfs.xfs /dev/sdb
AnswerD

mkfs.xfs creates an XFS filesystem directly on the named block device, so running it against /dev/sdb formats the entire raw disk without requiring a partition table. This matches the requirement of one XFS filesystem on the whole 4 TB disk. Note that mkfs.xfs refuses to overwrite an existing filesystem unless -f is supplied, but here the disk is empty.

Why this answer

Creating an XFS filesystem on a raw block device is done with mkfs.xfs followed by the device path. Because the new 4 TB disk has no partition table and the requirement is a single filesystem spanning the entire device, targeting /dev/sdb directly is correct. Partitioning is optional when the whole disk is dedicated to one filesystem.

Exam trap

The trap here is assuming that a partition must always be created before formatting, which leads to choosing a command that targets a nonexistent /dev/sdb1.

279
MCQhard

A system administrator is creating a systemd service unit for a custom application. The application requires that a specific environment variable, APP_ENV=production, be set before the service starts. The administrator wants this variable to be available only to this service, not system-wide. Which directive should be used in the service unit file?

A.Environment=APP_ENV=production
B.PassEnvironment=APP_ENV
C.EnvironmentFile=/etc/sysconfig/myapp
D.SetEnvironment=APP_ENV=production
AnswerA

Environment= sets environment variables for the executed process. It can be used multiple times to set multiple variables. This directive applies only to the service unit, not system-wide, and is the correct way to set a service-specific environment variable. It is placed in the [Service] section of the unit file.

Why this answer

The Environment= directive in a systemd service unit sets environment variables specifically for that service. It does not affect the system-wide environment. EnvironmentFile= requires an external file, SetEnvironment= is not a valid directive, and PassEnvironment= only forwards existing variables from the manager.

Therefore, Environment= is the correct choice.

Exam trap

The trap here is confusing Environment= with PassEnvironment=, or assuming EnvironmentFile= is required for any environment variable.

280
MCQeasy

A developer needs to temporarily allow incoming TCP connections on port 8080 for testing. Which iptables command adds a rule to the INPUT chain to accept this traffic?

A.iptables -A OUTPUT -p tcp --sport 8080 -j ACCEPT
B.iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
C.iptables -A FORWARD -p tcp --dport 8080 -j ACCEPT
D.iptables -I INPUT 1 -p tcp --dport 8080 -j DROP
AnswerB

The -A INPUT flag appends a rule to the INPUT chain, -p tcp matches the protocol, --dport 8080 targets the destination port, and -j ACCEPT sets the verdict. This permits inbound TCP connections on port 8080 without altering existing rules.

Why this answer

The INPUT chain processes traffic destined for the local system, and the `--dport 8080` flag matches incoming TCP packets with destination port 8080. The `-j ACCEPT` target allows these packets through, which is exactly what is needed to temporarily permit incoming TCP connections on port 8080 for testing.

Exam trap

The trap here is that candidates often confuse the INPUT chain with the FORWARD chain, or mistakenly think that `--sport` (source port) is appropriate for incoming traffic, when `--dport` (destination port) is required for packets arriving at the local system.

How to eliminate wrong answers

Option A is wrong because it adds a rule to the OUTPUT chain (which handles outgoing traffic) and uses `--sport 8080` (source port), which would match outgoing packets originating from port 8080, not incoming connections. Option C is wrong because the FORWARD chain handles traffic routed through the system, not traffic destined for the local host; adding a rule there would not affect incoming connections to the local system. Option D is wrong because it uses `-j DROP` to reject traffic, and while `-I INPUT 1` inserts the rule at the top, the action is to drop, not accept, the incoming TCP connections on port 8080.

281
MCQmedium

A Linux server's root filesystem is filling up quickly. You suspect that a user's process is writing a large log file and that the file has been deleted, but the space is still held. Which command will show the deleted file and the process holding it open?

A.df -h
B.lsof +L1
C.du -sh /var/log
D.fuser -m /
AnswerB

The lsof +L1 command lists open files with a link count less than 1, which indicates files that have been unlinked (deleted) but are still held open by a process. This directly reveals the deleted file and the process ID, allowing you to restart the process and reclaim space.

Why this answer

The correct tool is lsof +L1, which specifically finds open files with a link count of zero, meaning they have been deleted but are still held open by a process. This is the standard method to identify the culprit consuming disk space invisibly to df and du.

Exam trap

The trap here is assuming that df and du should always match; they diverge when deleted files are held open, and only lsof +L1 reveals the discrepancy.

282
MCQmedium

A system administrator needs to create a new ext4 filesystem on /dev/sdb1 with a reserved block percentage of 2% instead of the default 5%. Which command should be used?

A.mkfs.ext4 -m 2 /dev/sdb1
B.mkfs.ext4 -R 2 /dev/sdb1
C.mkfs.ext4 -r 2 /dev/sdb1
D.tune2fs -m 2 /dev/sdb1
AnswerA

The `-m` flag sets the reserved-blocks percentage, so `-m 2` allocates exactly 2% for root rather than the ext4 default of 5%, satisfying the stem's constraint. Running `mkfs.ext4` also creates the filesystem on the specified partition, `/dev/sdb1`, in a single command.

Why this answer

The `-m` flag in `mkfs.ext4` sets the reserved block percentage for the superuser, and specifying `-m 2` overrides the default of 5% to reserve only 2% of the blocks on the new ext4 filesystem on /dev/sdb1.

Exam trap

The trap here is that candidates confuse `-m` (reserved block percentage) with `-r` (revision number) or `-R` (RAID stride), or they incorrectly choose `tune2fs` which modifies an existing filesystem rather than creating a new one.

How to eliminate wrong answers

Option B is wrong because `-R` is not a valid flag for `mkfs.ext4`; it is used with `mkfs.ext2` for RAID stride options, not for reserved block percentage. Option C is wrong because `-r` in `mkfs.ext4` specifies the filesystem revision number, not the reserved block percentage. Option D is wrong because `tune2fs` modifies an existing filesystem's parameters (including reserved block percentage with `-m`), but the question explicitly asks for creating a new filesystem, not tuning an existing one.

283
Multi-Selecthard

Which TWO commands can be used to display the current working directory? (Choose exactly two.)

Select 2 answers
A.ls
B.echo $PWD
C.pwd
D.dirname
E.cd
AnswersB, C

Correct: prints the PWD variable.

Why this answer

The shell stores the current working directory path in the environment variable `$PWD`, and `echo $PWD` prints its value. This is a reliable way to display the current directory, as the shell updates `PWD` automatically on every `cd` command.

Exam trap

The trap here is that candidates may confuse `ls` (which lists files) with displaying the current directory path, or think `dirname` or `cd` can show the current directory without additional arguments.

284
MCQhard

A security audit reveals that a sensitive file '/etc/shadow' has been modified. The file's permissions are set to 600 and owned by root. However, the audit logs show that a service account 'webapp' was able to read the file. The 'webapp' user is not in the root group. Which of the following is the most likely method the 'webapp' user used to read the file?

A.The file is a hard link to another file that is readable by 'webapp'.
B.The 'webapp' user exploited a SUID binary that reads the file.
C.The file has an Access Control List (ACL) granting read permission to 'webapp'.
D.The 'webapp' user used 'sudo' to read the file as root.
AnswerC

Standard mode bits grant root read access only, and webapp is not in the root group, so the read must come from an extended permission. A POSIX ACL entry granting webapp read on /etc/shadow explains the access without changing ownership or mode.

Why this answer

An Access Control List (ACL) can grant specific permissions to a user or group beyond the traditional Unix permission model. Even though the file's mode is 600 (owner read/write only) and owned by root, a setfacl command could have added an ACL entry (e.g., 'u:webapp:r') that explicitly allows the 'webapp' user to read /etc/shadow. This is a common method to give a service account access to a sensitive file without changing its ownership or group membership.

Exam trap

The trap here is that candidates assume traditional Unix permissions (owner/group/other) are the only way to control access, overlooking that ACLs can grant specific users read permission even when the file's mode appears restrictive (e.g., 600).

How to eliminate wrong answers

Option A is wrong because a hard link shares the same inode and permissions as the original file; if /etc/shadow is mode 600 and owned by root, any hard link to it would also be mode 600 and owned by root, so 'webapp' could not read it via a hard link unless an ACL or other mechanism grants access. Option B is wrong because a SUID binary runs with the effective UID of the binary's owner (typically root), but the audit logs show 'webapp' read the file, not a SUID binary; the question asks how 'webapp' read the file, not how a binary accessed it on behalf of 'webapp'. Option D is wrong because using 'sudo' to read a file as root would require the 'webapp' user to have sudo privileges (e.g., an entry in /etc/sudoers), which is a separate configuration; the question does not indicate any sudo access, and the most likely method given the scenario is an ACL, not sudo.

285
MCQmedium

A Linux administrator is configuring a custom systemd service called backup.service. The service should run a backup script only when the server is connected to AC power and not running on battery. Which condition directive should be added to the [Unit] section of backup.service?

A.ConditionACPower=true
B.ConditionKernelCommandLine=ac
C.ConditionCapability=CAP_SYS_ADMIN
D.ConditionPathExists=/sys/class/power_supply/AC/online
AnswerA

ConditionACPower=true ensures the unit runs only when the system is on AC power. In this scenario, the administrator wants the backup to execute only when the server is not on battery, so this directive precisely matches the requirement. It is a condition, not a dependency, so if the condition is not met, the unit is skipped without failure.

Why this answer

ConditionACPower=true is the correct directive because it directly checks whether the system is running on AC power. When the system is on battery, the condition fails, and systemd skips the unit. This prevents the backup from running and draining battery.

Other conditions check file existence, kernel command line, or capabilities, none of which reliably indicate AC power status.

Exam trap

The trap here is confusing ConditionACPower with a generic file existence check, leading to the use of ConditionPathExists on a power supply path.

286
MCQeasy

Which command displays the current status of all active services?

A.systemctl list-units --type=service --state=active
B.systemctl status --all
C.systemctl show --type=service
D.systemctl list-unit-files --type=service
AnswerA

`systemctl list-units --type=service --state=active` queries systemd's unit manager directly, filtering loaded units by the service type and the active runtime state. This satisfies the stem's requirement to display every currently running service, unlike `systemctl status` (single unit) or `--state=running` (excludes active-but-exited ones).

Why this answer

`systemctl list-units --type=service --state=active` filters systemd units to show only those of type 'service' that are currently in the 'active' state (i.e., running or exited but still considered active). This is the precise command to list all active services without showing inactive or failed units.

Exam trap

The trap here is that candidates often confuse `systemctl status --all` (which shows all units regardless of state) with listing only active services, or they mistakenly think `systemctl list-unit-files` shows current runtime status instead of disk-based enablement configuration.

How to eliminate wrong answers

Option B is wrong because `systemctl status --all` shows the status of all units (including non-service types like sockets, timers, and mounts) and includes inactive and failed units, not just active services. Option C is wrong because `systemctl show --type=service` displays detailed properties/parameters of service units (like environment variables or resource limits) rather than their current runtime status. Option D is wrong because `systemctl list-unit-files --type=service` lists the enablement state (enabled/disabled/static) of service unit files on disk, not their current active/inactive runtime status.

287
MCQeasy

An administrator wants to view the current memory usage in a human-readable format, showing totals for used and free memory. Which command should be used?

A.vmstat
B.free -h
C.top
D.cat /proc/meminfo
AnswerB

`free -h` reads `/proc/meminfo` and prints used, free, shared, buff/cache and available memory, with the `-h` flag scaling values into human-readable units such as MiB and GiB. This directly satisfies the stem's requirement for totals in a readable format, unlike `-b`, `-k` or `-m`, which force fixed byte, KiB or MiB units.

Why this answer

The `free -h` command displays memory usage in a human-readable format (e.g., MiB, GiB) and shows totals for used and free memory, including buffers/cache and swap. This directly matches the requirement for a quick, readable summary of memory usage.

Exam trap

The trap here is that candidates may choose `cat /proc/meminfo` because it contains all memory details, but they overlook the requirement for a human-readable format and totals, which `free -h` provides directly.

How to eliminate wrong answers

Option A is wrong because `vmstat` reports virtual memory statistics, process, CPU, and I/O activity, but it does not present totals for used and free memory in a human-readable format by default; its output is in raw numbers and requires interpretation. Option C is wrong because `top` provides a real-time, dynamic view of system processes and memory usage, but it is interactive and not designed for a single, static human-readable summary of total used and free memory. Option D is wrong because `cat /proc/meminfo` outputs raw kernel memory statistics in kilobytes, which is not human-readable and requires manual calculation to derive totals for used and free memory.

288
MCQmedium

A security analyst needs to search for the literal string 'error: failed to connect' in all .log files under /var/log, including subdirectories. The search should be case-insensitive and display line numbers. Which command should they use?

A.grep -rin "error: failed to connect" /var/log/*.log
B.grep -rin "error: failed to connect" /var/log --exclude='*.log'
C.grep -rl "error: failed to connect" /var/log
D.grep -rin "error: failed to connect" /var/log --include='*.log'
AnswerD

grep -r searches recursively, -i ignores case, and -n shows line numbers. The --include option limits the search to files matching the glob '*.log', which precisely targets .log files in /var/log and its subdirectories. This satisfies all requirements: case-insensitive, recursive, and line numbers.

Why this answer

To recursively search only .log files with case-insensitivity and line numbers, use grep with -r, -i, -n, and --include. The --include='*.log' ensures only files with that extension are processed, while -r traverses subdirectories. This combination meets all stated requirements.

Exam trap

The trap here is assuming that a shell glob like /var/log/*.log works recursively; it does not, so --include is needed.

289
MCQhard

An administrator needs to allow incoming SSH connections on port 22 from the 192.168.50.0/24 subnet while blocking all other incoming SSH traffic, without disrupting existing established connections. Which command sequence using nftables accomplishes this?

A.nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept; nft add rule inet filter input tcp dport 22 drop
B.nft add rule inet filter input tcp dport 22 drop; nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 accept
C.nft add rule inet filter input tcp dport 22 ip saddr 192.168.50.0/24 drop; nft add rule inet filter input tcp dport 22 accept
D.nft add rule inet filter input ip saddr 192.168.50.0/24 tcp dport 22 accept; nft add rule inet filter input tcp dport 22 reject
AnswerA

The first rule accepts SSH from the specified subnet, and the second drops all other SSH traffic. Because rules are evaluated in order, allowed sources match the accept rule before reaching the drop rule. Established connections are unaffected if the input chain already accepts them earlier.

Why this answer

nftables evaluates rules in the order they appear within a chain. To allow a specific source and block the rest, the accept rule for that source must precede the drop rule for the port. Reversing the order or inverting the match conditions produces the opposite of the desired policy.

Exam trap

The trap here is assuming that nftables reorders rules or that a later accept can override an earlier drop; rule order is strictly sequential.

290
MCQmedium

A Linux server has its time zone set to UTC, but the administrator wants the system clock to be synchronized by an internal NTP server at 10.0.0.10. The system uses systemd and chrony is already installed. Which command should the administrator run to configure the NTP server and make it persistent?

A.timedatectl set-timezone America/New_York
B.chronyc sources add 10.0.0.10
C.Edit /etc/chrony.conf to include 'server 10.0.0.10 iburst' and restart chronyd
D.systemctl enable --now ntp.service
AnswerC

The correct method is to edit the chrony configuration file, typically /etc/chrony.conf, and add a server directive pointing to 10.0.0.10. The 'iburst' option speeds up initial synchronization. After saving the file, restarting the chronyd service applies the change and ensures it persists across reboots. This directly fulfills the administrator's goal.

Why this answer

Configuring chrony requires editing its configuration file, usually /etc/chrony.conf, to specify the NTP server, and then restarting the chronyd service to apply the changes. This makes the configuration persistent. The other options either change the time zone, use an incorrect chronyc subcommand, or attempt to use the wrong service, none of which set the NTP server as needed.

Exam trap

The trap here is confusing chrony configuration with time zone changes or using chronyc interactively instead of editing the persistent configuration file.

291
MCQeasy

A junior administrator needs to create a symbolic link named /usr/local/bin/editor that points to /opt/tools/vim.bin. The link must be created without overwriting any existing file at the destination. Which command accomplishes this?

A.ln /opt/tools/vim.bin /usr/local/bin/editor
B.ln -sf /opt/tools/vim.bin /usr/local/bin/editor
C.cp -s /opt/tools/vim.bin /usr/local/bin/editor
D.ln -s /opt/tools/vim.bin /usr/local/bin/editor
AnswerD

The ln -s command creates a symbolic link, and because the destination path does not exist yet, the link is created cleanly without touching any existing file. This matches the requirement exactly: a symbolic link at the specified path pointing to the target binary, with no overwrite behavior needed.

Why this answer

Creating a symbolic link is done with ln -s target linkname. Because the destination does not exist, no force flag is required and the command completes without overwriting anything. The hard-link variant lacks -s and would not produce a symbolic link, while the forced variant introduces overwrite risk that the scenario explicitly forbids.

Exam trap

The trap here is assuming that ln without -s still creates a symbolic link, when it actually creates a hard link.

292
MCQeasy

Based on the tcpdump output in the exhibit, what can be concluded about the TCP handshake?

A.The connection attempt failed because only three packets are shown.
B.The connection was reset by the remote host.
C.The handshake is incomplete because there is no ACK from the server.
D.The TCP three-way handshake completed successfully.
AnswerD

The capture shows SYN, SYN-ACK and ACK exchanged in sequence between the hosts, confirming the three-way handshake completed and the connection entered ESTABLISHED state. This satisfies the exhibit evidence, ruling out a reset, refused connection or incomplete handshake.

Why this answer

The TCP three-way handshake completes successfully when three packets are exchanged: SYN, SYN-ACK, and ACK. The tcpdump output shows exactly these three packets, confirming a successful handshake. The presence of the final ACK from the client to the server's SYN-ACK indicates that the connection is established.

Exam trap

The trap here is that candidates may mistakenly think a three-packet handshake is incomplete or failed, when in fact the TCP three-way handshake is defined as exactly three packets, and the final ACK from the client completes it.

How to eliminate wrong answers

Option A is wrong because a successful TCP three-way handshake consists of exactly three packets (SYN, SYN-ACK, ACK), so seeing three packets does not indicate failure. Option B is wrong because a reset (RST) packet would appear in the output if the connection were reset by the remote host, but no RST flag is shown. Option C is wrong because the handshake is complete; the server sends a SYN-ACK (the second packet), and the client responds with an ACK (the third packet), which is the expected final step.

293
MCQmedium

A developer wants to change the ownership of a directory and all its contents recursively to user 'appuser' and group 'appgroup'. Which command accomplishes this?

A.chown -R appuser:appgroup /app
B.chown -R appuser /app && chgrp appgroup /app
C.chgrp -R appgroup /app && chown appuser /app
D.chown -R appuser: /app && chgrp -R appgroup /app
AnswerA

The -R flag applies chown recursively to the directory and every file and subdirectory beneath it, while appuser:appgroup sets both owner and group in one operation. This matches the requirement to change ownership of all contents.

Why this answer

The `chown -R appuser:appgroup /app` command recursively changes both the user and group ownership of the `/app` directory and all its contents. The `-R` flag ensures recursion, and the colon-separated `user:group` syntax sets both ownership attributes in a single command.

Exam trap

The trap here is that candidates often forget the `-R` flag on the second command in compound solutions, or they mistakenly believe `chown user:` sets a specific group rather than the user's default group, leading them to choose options that only partially apply the ownership change.

How to eliminate wrong answers

Option B is wrong because `chown -R appuser /app` changes only the user ownership recursively, but `chgrp appgroup /app` without `-R` changes only the group ownership of the `/app` directory itself, not its contents. Option C is wrong because `chgrp -R appgroup /app` changes group ownership recursively, but `chown appuser /app` without `-R` changes only the user ownership of the top-level directory, leaving all contents with the original user. Option D is wrong because `chown -R appuser: /app` sets the group to the user's default group (not `appgroup`), and the subsequent `chgrp -R appgroup /app` would override that group, but the first command already incorrectly sets the group.

294
Multi-Selecteasy

A user wants to view the contents of a compressed file file.txt.gz without decompressing it permanently. Which two commands can be used? (Choose two.)

Select 2 answers
A.gunzip -c file.txt.gz
B.zcat file.txt.gz
C.gzip -l file.txt.gz
D.gzip -d file.txt.gz
E.gzip -k file.txt.gz
AnswersA, B

`gunzip -c` writes the decompressed stream to standard output, leaving file.txt.gz untouched on disk. The `-c` flag satisfies the stem's requirement to view contents without permanent decompression, since no `.gz` file is removed or replaced. Piping to a pager such as `less` lets the user read it.

Why this answer

Option A, gunzip -c file.txt.gz, is correct because the -c (--stdout) flag writes the decompressed output to standard output, allowing the user to view the contents while leaving the original .gz file intact on disk. Option B, zcat file.txt.gz, is correct because zcat is functionally equivalent to gunzip -c, decompressing the gzip file to stdout without removing or modifying the compressed file. Option C, gzip -l file.txt.gz, only lists metadata such as compressed size, uncompressed size, and ratio, so it does not show the file's contents.

Option D, gzip -d file.txt.gz, actually decompresses and deletes the .gz file, which is a permanent decompression, not a view-only operation. Option E, gzip -k file.txt.gz, compresses a file while keeping the original, so it does not display the contents of an already compressed file.

Exam trap

The trap here is that candidates confuse `gzip -d` (which permanently decompresses) with `gunzip -c` (which outputs to stdout), or mistakenly think `gzip -l` shows file contents instead of metadata.

295
MCQhard

An administrator is auditing a server and needs to list only the users whose primary group is 'developers'. The system has many users, and the administrator wants a precise, scriptable one-liner that parses /etc/passwd. Which command accomplishes this?

A.getent passwd | awk -F: '$4=="'"$(getent group developers | cut -d: -f3)"'" {print $1}'
B.grep developers /etc/passwd
C.getent passwd | awk -F: '$4=="developers" {print $1}'
D.getent group developers
AnswerA

This command first resolves the numeric GID of the 'developers' group via getent group, then filters /etc/passwd entries whose fourth field (GID) equals that number, printing the username. It is precise, uses NSS-aware getent, and correctly compares numeric GIDs as stored in the passwd database.

Why this answer

The passwd database stores the primary group as a numeric GID in the fourth field, so the reliable approach is to resolve the group name to its GID and compare numerically. Using getent keeps the query consistent with NSS sources such as LDAP or SSSD, which plain file greps would miss.

Exam trap

The trap here is comparing the numeric GID field against a group name string, or assuming the group database lists primary-group members, when primary membership lives in the passwd entry.

296
MCQeasy

A user needs to see the contents of a gzip-compressed file 'data.txt.gz' without decompressing it. Which command is appropriate?

A.gunzip data.txt.gz
B.zcat data.txt.gz
C../data.txt.gz
D.gzcat data.txt.gz
AnswerB

zcat streams the decompressed contents of data.txt.gz directly to standard output, leaving the original compressed file untouched on disk. This satisfies the stem's constraint of viewing the file without decompressing it, since no .gz-to-plain extraction occurs. gzip's own -c flag could also write to stdout, but zcat is the purpose-built tool.

Why this answer

The `zcat` command reads a gzip-compressed file and outputs its decompressed content to stdout without modifying the original file. This allows the user to view the contents of 'data.txt.gz' without permanently decompressing it.

Exam trap

The trap here is that candidates may confuse `zcat` with `gunzip` or assume `gzcat` is the correct command, but the LFCS exam expects knowledge of the standard `zcat` utility for viewing compressed files without decompression.

How to eliminate wrong answers

Option A is wrong because `gunzip` decompresses the file and replaces the .gz file with the uncompressed version, which does not meet the requirement to view contents without decompressing. Option C is wrong because attempting to execute a compressed file with `./data.txt.gz` will fail as it is not an executable binary and the shell cannot interpret the compressed data. Option D is wrong because `gzcat` is not a standard Linux command; while some systems may have it as an alias, the standard command on Linux is `zcat`.

297
Multi-Selectmedium

A Linux administrator needs to ensure that the 'httpd' service starts automatically at boot and is currently running. The system uses systemd. Which two commands should the administrator use to achieve this? (Choose two.)

Select 2 answers
A.systemctl enable httpd
B.systemctl reload httpd
C.systemctl start httpd
D.systemctl status httpd
E.systemctl is-enabled httpd
AnswersA, C

This command creates the necessary symbolic links to enable the httpd service to start automatically at boot. It does not start the service immediately, but it ensures persistence across reboots. Combined with a command to start the service now, it fulfills the requirement. It is a standard systemd command for enabling a unit.

Why this answer

To make httpd start at boot and be currently running, the administrator must enable it for automatic start with 'systemctl enable httpd' and start it immediately with 'systemctl start httpd'. These two actions are independent and both necessary. The other commands either check status, reload configuration, or verify enablement, but none of them both enable and start the service.

Exam trap

The trap here is confusing enabling a service with starting it; enabling only affects boot behavior, while starting affects the current runtime state.

298
MCQmedium

An administrator needs to set the reserved block percentage on an ext4 filesystem to 1% for a non-root filesystem. Which command accomplishes this?

A.tune2fs -m 0.5 /dev/sdb1
B.tune2fs -m 1 /dev/sdb1
C.tune2fs -r 1% /dev/sdb1
D.tune2fs -c 1 /dev/sdb1
AnswerB

`tune2fs -m 1 /dev/sdb1` sets the reserved block percentage directly on the ext4 filesystem, satisfying the 1% requirement. The `-m` flag adjusts the percentage of blocks reserved for root, and unlike `-r`, it accepts a percentage rather than a block count. This applies immediately without unmounting.

Why this answer

The `tune2fs -m` command sets the reserved block percentage for an ext4 filesystem, and `-m 1` sets it to exactly 1%. This is the standard way to adjust reserved space on a non-root ext4 filesystem, as root filesystems typically have a default of 5% reserved for system processes.

Exam trap

The trap here is confusing the `-m` (percentage) and `-r` (absolute blocks) options, leading candidates to incorrectly use `-r` with a percentage value like `1%`.

How to eliminate wrong answers

Option A is wrong because `-m 0.5` sets the reserved block percentage to 0.5%, not 1%. Option C is wrong because `-r` expects an absolute number of reserved blocks, not a percentage; the syntax `-r 1%` is invalid and would cause an error. Option D is wrong because `-c 1` sets the maximum mount count between filesystem checks, not the reserved block percentage.

299
Multi-Selectmedium

A system administrator needs to identify which processes are consuming the most CPU and memory on a Linux server. Which TWO commands can provide a real-time, interactive view of process resource usage? (Choose two.)

Select 2 answers
A.vmstat 1
B.top
C.ps aux --sort=-%cpu
D.htop
E.iostat -x 1
AnswersB, D

top displays a dynamic, real-time view of running processes, sorted by CPU usage by default. It shows memory usage, load average, and allows interactive commands like sorting by memory (M) or killing processes (k). It is a standard tool for live process monitoring.

Why this answer

top and htop are interactive, real-time process viewers that show CPU and memory usage per process. top is universally available, while htop offers enhanced usability. The other commands provide snapshots or system-wide statistics without per-process, real-time interactivity, so they do not meet the requirement.

Exam trap

The trap here is confusing system-wide statistics tools like vmstat or iostat with per-process interactive monitors.

300
MCQmedium

An administrator needs to mount an XFS filesystem with options to optimize for a database workload. Which mount option would reduce metadata updates to improve performance?

A.noexec
B.nodiratime
C.relatime
D.noatime
AnswerD

noatime suppresses access-time updates on every file read, eliminating a metadata write per read. For a database workload performing constant reads, this reduces journal and metadata overhead on the XFS filesystem, improving throughput without affecting data integrity.

Why this answer

The `noatime` mount option disables updates to the inode access time (atime) on every file read. For database workloads, this eliminates a significant source of metadata write I/O, reducing disk contention and improving overall performance by avoiding unnecessary journal updates on XFS.

Exam trap

The trap here is that candidates confuse `relatime` (which reduces but does not eliminate atime updates) with `noatime`, or incorrectly assume `nodiratime` is sufficient for database optimization, when only `noatime` fully removes metadata write overhead for all files.

How to eliminate wrong answers

Option A is wrong because `noexec` prevents execution of binaries on the filesystem, which does not affect metadata updates or database I/O performance. Option B is wrong because `nodiratime` only disables atime updates for directories, not for regular files, so it provides only partial reduction in metadata writes. Option C is wrong because `relatime` updates atime only if the previous atime is older than the mtime or ctime, which still generates some metadata writes and is less aggressive than `noatime` for write-heavy database workloads.

Page 3

Page 4 of 6

Page 5

All pages