Courseiva

Linux Foundation Certified System Administrator LFCS (LFCS) — Questions 301–375

406 questions total · 6pages · All types, answers revealed

Page 4

Page 5 of 6

Page 6
301
MCQhard

An administrator needs to replace all occurrences of the string 'foo' with 'bar' in all files under /etc/config, but only in files ending with .conf. The replacement must be done in-place, and backup copies should be created with a .bak extension. Which command accomplishes this?

A.find /etc/config -name '*.conf' -exec sed -i .bak 's/foo/bar/g' {} +
B.find /etc/config -name '*.conf' -exec sed 's/foo/bar/g' {} \;
C.find /etc/config -name '*.conf' -exec sed -i.bak 's/foo/bar/g' {} +
D.find /etc/config -name '*.conf' -exec sed -i 's/foo/bar/g' {} +
AnswerC

find locates only .conf files, and sed -i.bak edits each in place while writing a .bak backup, with the g flag replacing every occurrence per line. The -exec ... {} + form batches files efficiently, satisfying all stated constraints.

Why this answer

It uses `sed -i.bak` which creates a backup file with the .bak extension before performing the in-place substitution, and the `find -exec ... +` variant efficiently processes multiple files at once. The `-i` option with an argument (no space) specifies the backup suffix directly, satisfying the requirement for backup copies.

Exam trap

The trap here is that candidates confuse the syntax `-i .bak` (with a space, which is incorrect) with `-i.bak` (no space, which is correct), or they forget that `-i` without a suffix does not create backups, leading them to choose options that either fail or omit the required backup step.

How to eliminate wrong answers

Option A is wrong because `-i .bak` (with a space) is interpreted as `-i` with an empty backup suffix and `.bak` as a separate argument, causing sed to fail or behave unexpectedly. Option B is wrong because it lacks the `-i` flag entirely, so changes are written to stdout instead of being saved in-place, and no backups are created. Option D is wrong because `-i` without a suffix does not create backup files, violating the requirement for .bak backups.

302
MCQhard

A server runs a custom application that listens on TCP port 8080. The administrator wants to ensure the application starts automatically on boot and restarts if it crashes. Which systemd unit file directive should be used to achieve the restart behavior?

A.RestartSec=5
B.Type=notify
C.RemainAfterExit=yes
D.Restart=on-failure
AnswerD

`Restart=on-failure` restarts the service only when it exits with a non-zero status, is killed by a signal, or times out — satisfying the crash-recovery requirement without restarting after a clean stop. Paired with `WantedBy=multi-user.target`, it also covers automatic start at boot for the port 8080 application.

Why this answer

The `Restart=on-failure` directive in a systemd unit file instructs systemd to automatically restart the service unit when it exits with a non-zero exit code, is terminated by a signal (including SIGKILL), or times out. This directly satisfies the requirement for the application to restart if it crashes, as a crash typically results in an unclean exit that triggers the restart condition.

Exam trap

The trap here is that candidates often confuse `RestartSec` with the restart policy itself, or assume `Type=notify` or `RemainAfterExit=yes` imply automatic restart behavior, when in fact only `Restart=` directives control restart logic.

How to eliminate wrong answers

Option A is wrong because `RestartSec=5` specifies a delay (5 seconds) before attempting a restart, but it does not enable restart behavior on its own; it only modifies the timing if a restart is already configured via `Restart=`. Option B is wrong because `Type=notify` tells systemd that the service will send a notification (via sd_notify) when it is fully started, but it has no effect on restart behavior after a crash. Option C is wrong because `RemainAfterExit=yes` makes systemd consider the service as active even after the main process exits, which is used for one-shot services that set up state; it does not cause automatic restarts on failure.

303
MCQeasy

A system administrator needs to configure a static IP address on a CentOS 7 server. Which file should be edited to set the IP address permanently?

A./etc/netplan/01-netcfg.yaml
B./etc/network/interfaces
C./etc/hostname
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerD

On CentOS 7, NetworkManager and the legacy network service read per-interface configuration from /etc/sysconfig/network-scripts/ifcfg-eth0, so editing this file sets a persistent static address. Changes survive reboot, unlike runtime ip commands, satisfying the stem's requirement for permanent configuration.

Why this answer

On CentOS 7, network interfaces are configured via scripts located in /etc/sysconfig/network-scripts/, with each interface having a file named ifcfg-<interface>. The ifcfg-eth0 file stores static IP settings such as IPADDR, NETMASK, and GATEWAY, which are read by the network service (network.service) to apply persistent configuration.

Exam trap

The trap here is that candidates familiar with Ubuntu or Debian systems may incorrectly choose /etc/network/interfaces (Option B) or /etc/netplan/01-netcfg.yaml (Option A), forgetting that CentOS 7 uses the Red Hat-style ifcfg scripts in /etc/sysconfig/network-scripts/.

How to eliminate wrong answers

Option A is wrong because /etc/netplan/01-netcfg.yaml is used by Netplan, a network configuration utility for Ubuntu (starting from 17.10) and not by CentOS 7, which uses the legacy ifcfg system. Option B is wrong because /etc/network/interfaces is the configuration file for Debian/Ubuntu systems using ifupdown, not for CentOS 7. Option C is wrong because /etc/hostname only sets the system's hostname, not IP address configuration; it contains a single line with the hostname and has no effect on network interface addressing.

304
MCQmedium

To check the disk usage of the /var/log directory in a human-readable format, which command is appropriate?

A.du -sh /var/log
B.ls -lh /var/log
C.df -h /var/log
D.fdisk -l /var/log
AnswerA

du -s summarises total usage for the directory rather than listing every file, and -h converts the block count into human-readable units such as MB or GB. Together they report /var/log's aggregate size readably, matching the requirement.

Why this answer

The `du -sh /var/log` command is correct because `du` (disk usage) estimates file and directory space usage, and the `-s` option summarizes the total for the specified directory, while `-h` prints sizes in human-readable format (e.g., K, M, G). This directly answers the requirement to check disk usage of the /var/log directory in a human-readable form.

Exam trap

The trap here is that candidates confuse `du` (directory usage) with `df` (filesystem usage), or mistakenly think `ls -lh` shows total directory size, when in fact `ls` only lists individual file sizes without summing subdirectory contents.

How to eliminate wrong answers

Option B is wrong because `ls -lh /var/log` lists the contents of the directory with file sizes, not the total disk usage of the directory itself; it does not aggregate space used by subdirectories. Option C is wrong because `df -h /var/log` reports the free and used space on the filesystem that contains /var/log, not the disk usage of the directory itself. Option D is wrong because `fdisk -l /var/log` is used to manipulate or display partition tables on block devices, not to check disk usage of a directory; it would fail on a regular file or directory.

305
MCQhard

An administrator runs 'ls -la' and sees the following entry for a file: 'lrwxrwxrwx 1 root root 24 Jan 10 12:00 link -> /etc/passwd'. If the target file /etc/passwd is deleted, what happens to the link file?

A.The link becomes a hard link to the deleted file's inode
B.The link becomes a broken symbolic link
C.The link becomes a regular file with the same content
D.The link is automatically deleted
AnswerB

A symbolic link stores only the target's pathname, not its inode, so deleting /etc/passwd leaves the link entry intact but unresolvable. Accessing it then fails with ENOENT, and `ls -l` typically renders the dangling target in red. This satisfies the stem's scenario: the symlink persists as a broken link rather than being removed.

Why this answer

The entry 'lrwxrwxrwx' indicates a symbolic link (symlink), which stores a path to the target file rather than sharing its inode. When the target /etc/passwd is deleted, the symlink still exists but points to a non-existent path, making it a broken (dangling) symlink. Accessing it will result in a 'No such file or directory' error.

Exam trap

The trap here is that candidates confuse symbolic links with hard links, assuming the link would become a regular file or automatically delete, when in fact a symlink simply becomes broken and persists until manually removed.

How to eliminate wrong answers

Option A is wrong because a symbolic link does not share the target's inode; only hard links do, and deleting the target does not convert a symlink into a hard link. Option C is wrong because a symbolic link is not a regular file and does not contain the target's content; it only stores a path string, and deleting the target does not copy content into the link. Option D is wrong because symbolic links are not automatically deleted when their target is removed; they persist as broken links until explicitly removed.

306
MCQeasy

A user reports that they cannot reach a remote server by hostname but can reach it by IP address. Which configuration file is most likely misconfigured?

A./etc/resolv.conf
B./etc/sysconfig/network
C./etc/hosts
D./etc/nsswitch.conf
AnswerA

Hostname resolution relies on the DNS servers listed in /etc/resolv.conf; reaching the server by IP proves network connectivity is fine. A missing or incorrect nameserver entry there prevents the resolver from translating the hostname, matching the stem's symptom exactly.

Why this answer

The /etc/resolv.conf file configures the system's DNS resolver, specifying the nameservers to query for hostname-to-IP resolution. If a user can reach a server by IP but not by hostname, it indicates that DNS resolution is failing, which is most commonly due to a missing or incorrect nameserver entry in /etc/resolv.conf.

Exam trap

The trap here is that candidates often confuse /etc/resolv.conf with /etc/hosts or /etc/nsswitch.conf, thinking that a hostname resolution failure must be due to a missing static entry or a misconfigured lookup order, rather than the fundamental DNS resolver configuration.

How to eliminate wrong answers

Option B is wrong because /etc/sysconfig/network is a Red Hat/CentOS-specific file for setting global network parameters (e.g., hostname, gateway), not for DNS resolver configuration. Option C is wrong because /etc/hosts provides static hostname-to-IP mappings; if it were misconfigured, the user might not reach the server by hostname, but the fact that they can reach it by IP suggests DNS is the issue, not a missing or incorrect static entry. Option D is wrong because /etc/nsswitch.conf controls the order of name service lookups (e.g., 'hosts: files dns'), but a misconfiguration here would affect the lookup order, not the actual DNS resolver configuration; the core problem is the resolver itself, not the order.

307
MCQeasy

A system administrator needs to check the current CPU load and memory usage on a Linux server. Which command should be used to display a dynamic, real-time view of running processes and system resource utilization?

A.uptime
B.top
C.ps aux
D.free -h
AnswerB

top provides a continuously refreshing, real-time view of running processes alongside CPU load averages and memory utilisation, updating by default every few seconds. This satisfies the dynamic, real-time requirement, unlike one-shot tools such as free or vmstat.

Why this answer

(top) is correct because it provides a dynamic, real-time view of running processes and system resource utilization, including CPU load, memory usage, and process details. It updates continuously by default, making it ideal for monitoring live system performance.

Exam trap

The trap here is that candidates may confuse static commands like ps aux or free -h with the dynamic, real-time requirement, or assume uptime provides process-level detail, when only top (or similar tools like htop) continuously updates process and resource data.

How to eliminate wrong answers

Option A (uptime) is wrong because it only displays how long the system has been running, the number of users, and load averages for 1, 5, and 15 minutes; it does not show a dynamic, real-time view of processes or memory usage. Option C (ps aux) is wrong because it provides a static snapshot of all running processes at the moment of execution, not a continuously updating real-time display. Option D (free -h) is wrong because it shows memory and swap usage in a human-readable format, but it is a static report and does not display running processes or CPU load in real time.

308
MCQmedium

A Linux server running NetworkManager has a Wi-Fi interface wlp3s0 that must connect to the corporate WPA2-Enterprise network 'CorpNet' with 802.1X PEAP authentication, using identity 'jdoe' and password 'S3cr3t!'. The administrator wants to create and activate this connection entirely from the command line without editing configuration files manually. Which sequence of commands will accomplish this?

A.nmcli con add type ethernet ifname wlp3s0 con-name CorpNet, then nmcli con up CorpNet
B.nmcli con add type wifi ifname wlp3s0 con-name CorpNet ssid CorpNet wifi-sec.key-mgmt wpa-psk wifi-sec.psk 'S3cr3t!'
C.nmcli con add type wifi ifname wlp3s0 con-name CorpNet ssid CorpNet, then nmcli con modify CorpNet wifi-sec.key-mgmt wpa-eap 802-1x.eap peap 802-1x.identity jdoe 802-1x.password 'S3cr3t!', then nmcli con up CorpNet
D.nmcli dev wifi connect CorpNet password 'S3cr3t!'
AnswerC

This is the correct sequence: 'nmcli con add type wifi' creates the profile with the given ssid and interface, 'nmcli con modify' sets the key management to wpa-eap and the 802.1X parameters including eap method, identity, and password, and 'nmcli con up' activates it. All required fields for WPA2-Enterprise are supplied, so the connection will authenticate and associate without manual file editing.

Why this answer

The correct approach uses 'nmcli con add type wifi' to create a profile, then 'nmcli con modify' to set 'wifi-sec.key-mgmt wpa-eap' and the 802.1X parameters (EAP method, identity, password), and finally 'nmcli con up' to activate it. WPA2-Enterprise requires 802.1X/EAP configuration, not a pre-shared key, and the connection type must match the wireless interface for NetworkManager to manage it properly.

Exam trap

The trap here is assuming that a simple 'nmcli dev wifi connect' with a password is sufficient for any secured Wi-Fi network, when enterprise networks require explicit 802.1X/EAP parameters.

309
MCQhard

An administrator wants to print the last field of each line from a CSV file 'data.csv' (comma-separated). Which awk command accomplishes this?

A.awk -F, '{print $NF}' data.csv
B.cut -d, -f2 data.csv
C.cut -d, -f1 data.csv
D.awk '{print $NF}' data.csv
AnswerA

-F, sets the input field separator to a comma, and $NF expands to the index of the final field on each record, so print $NF emits the last comma-separated column. This satisfies the CSV last-field requirement without hardcoding a field number.

Why this answer

`awk -F, '{print $NF}' data.csv` uses `-F,` to set the field separator to comma, and `$NF` represents the value of the last field (NF is the number of fields, so $NF is the last field). This command prints the last column of each line in the CSV file.

Exam trap

The trap here is that candidates often forget to specify the field separator with `-F,` in awk, or they confuse `cut` options (like `-f2` for a specific field instead of `$NF` for the last field), leading them to pick a command that prints a fixed column rather than the last column dynamically.

How to eliminate wrong answers

Option B is wrong because `cut -d, -f2` prints the second field, not the last field. Option C is wrong because `cut -d, -f1` prints the first field, not the last field. Option D is wrong because `awk '{print $NF}'` uses the default field separator (whitespace), not a comma, so it will not correctly parse CSV fields and will likely print the last whitespace-separated token instead of the last comma-separated field.

310
MCQmedium

A network interface eth0 is not receiving an IP address via DHCP. Which command can be used to troubleshoot the DHCP client process?

A.dhclient -v eth0
B.systemctl status dhcpd
C.nmcli dev show eth0
D.dhcpd -t
AnswerA

Running dhclient with -v on eth0 forces the DHCP client into verbose foreground mode, printing each DHCPDISCOVER, DHCPOFFER, DHCPREQUEST and DHCPACK exchange. This exposes whether the client transmits, receives offers, or fails, directly troubleshooting the DHCP client process.

Why this answer

The `dhclient -v eth0` command runs the DHCP client in verbose mode on interface eth0, which is the correct tool to troubleshoot the DHCP client process. It shows detailed messages about the DHCPDISCOVER, DHCPOFFER, DHCPREQUEST, and DHCPACK exchange, helping identify where the process fails. This directly addresses the issue of the interface not receiving an IP address via DHCP.

Exam trap

The trap here is confusing the DHCP client process (dhclient) with the DHCP server process (dhcpd), leading candidates to choose options that manage or test the server instead of the client.

How to eliminate wrong answers

Option B is wrong because `systemctl status dhcpd` checks the status of the DHCP server daemon (dhcpd), not the DHCP client process; the client process is managed by dhclient or NetworkManager, not dhcpd. Option C is wrong because `nmcli dev show eth0` displays the current configuration and state of the interface as managed by NetworkManager, but it does not initiate or debug the DHCP client transaction itself. Option D is wrong because `dhcpd -t` tests the syntax of the DHCP server configuration file (typically /etc/dhcp/dhcpd.conf), which is irrelevant to troubleshooting the client-side DHCP process.

311
MCQeasy

A junior administrator has written a custom systemd service unit file named backup.service in /etc/systemd/system/. The unit is intended to run a backup script once per day. After placing the file, the administrator runs systemctl start backup.service, but systemd reports 'Unit backup.service not found.' The file exists and has correct syntax. Which command should the administrator run to make systemd aware of the new unit file?

A.systemctl reload backup.service
B.systemctl daemon-reload
C.systemctl reset-failed backup.service
D.systemctl enable backup.service
AnswerB

systemd caches unit files and does not automatically detect new or changed units in /etc/systemd/system/. Running systemctl daemon-reload forces systemd to re-scan all unit directories and rebuild its dependency tree, making backup.service available for systemctl start. Without this, systemctl start fails with 'Unit not found' even though the file is present and valid.

Why this answer

systemd maintains an in-memory cache of unit files and does not watch /etc/systemd/system/ for new files. After adding or modifying a unit, systemctl daemon-reload must be run so systemd re-reads unit definitions and rebuilds dependencies. Only then does systemctl start recognize the new backup.service unit.

Exam trap

The trap here is assuming that placing a unit file in /etc/systemd/system/ is immediately recognized by systemd without a daemon-reload.

312
MCQmedium

A temporary contractor 'contractor1' has left the company. The administrator needs to remove the user account and all associated files in the home directory. Which command accomplishes this?

A.userdel contractor1
B.passwd -d contractor1
C.userdel -r contractor1
D.deluser --remove-home contractor1
AnswerC

`userdel -r contractor1` deletes the account and recursively removes the home directory with its mail spool, satisfying the requirement to erase all associated files. Plain `userdel` would leave `/home/contractor1` intact, so the `-r` flag is essential here.

Why this answer

The `userdel -r contractor1` command removes the user account and, with the `-r` flag, also deletes the user's home directory and mail spool. This is the standard Linux command to completely remove a user and their associated files, as required by the scenario.

Exam trap

The trap here is that candidates may choose Option A, thinking `userdel` alone removes everything, or Option D, assuming `deluser` is universally available, when the LFCS exam tests the standard `userdel -r` command that works across all major Linux distributions.

How to eliminate wrong answers

Option A is wrong because `userdel contractor1` removes the user account but leaves the home directory and its files intact, failing to meet the requirement to remove all associated files. Option B is wrong because `passwd -d contractor1` only deletes the user's password, allowing password-less login, and does not remove the account or any files. Option D is wrong because `deluser --remove-home contractor1` is a Debian/Ubuntu-specific command, not a standard command on all Linux distributions (e.g., RHEL/CentOS), and the LFCS exam expects distribution-agnostic commands like `userdel -r`.

313
MCQmedium

A Linux server has a single XFS filesystem mounted at /data on /dev/sdb1. The storage array behind /dev/sdb1 is expanded and the block device is now 2 TB instead of 1 TB. The administrator confirms that the kernel sees the larger device with blockdev --getsize64 /dev/sdb1. Which command should be run to make the additional space usable by the mounted /data filesystem?

A.xfs_growfs /data
B.growpart /dev/sdb 1
C.resize2fs /dev/sdb1
D.xfs_repair /dev/sdb1
AnswerA

xfs_growfs is the correct tool for expanding a mounted XFS filesystem. It takes the mount point as its argument, not the block device, and it communicates with the running XFS kernel module to extend the filesystem into the additional space that the underlying block device now exposes. Running it on /data grows the live filesystem without unmounting it, which is exactly what this scenario requires.

Why this answer

XFS filesystems are extended with the xfs_growfs command, which operates on a mounted filesystem using its mount point. Because the block device already reports the larger size, the only remaining step is to grow the XFS filesystem into that free space. Tools such as resize2fs target ext-family filesystems, while xfs_repair and growpart address different problems, so they cannot satisfy this requirement.

Exam trap

The trap here is assuming that any resize utility works on any filesystem, when XFS must be grown with xfs_growfs on the mount point rather than resize2fs on the device.

314
MCQmedium

A Linux server has a single network interface enp3s0 that must obtain its IPv4 address automatically from a DHCP server on the local subnet. The administrator prefers to manage this connection with NetworkManager and wants the setting to persist across reboots. Which command will configure the connection profile named 'Wired connection 1' to use DHCP?

A.nmcli dev connect enp3s0
B.ip addr add dev enp3s0 dhcp
C.nmcli con mod 'Wired connection 1' ipv4.method manual
D.nmcli con mod 'Wired connection 1' ipv4.method auto
AnswerD

This command modifies the existing NetworkManager connection profile to use automatic IPv4 configuration (DHCP). The 'ipv4.method auto' setting tells NetworkManager to request an address from a DHCP server, and because it modifies the persistent profile, the change survives reboots. It is the correct way to enable DHCP on a specific connection.

Why this answer

NetworkManager stores connection settings in profiles, and the ipv4.method property controls how IPv4 addressing is obtained. Setting it to auto enables DHCP for that profile. Modifying the profile with nmcli con mod makes the change persistent, unlike temporary ip commands.

The other options either configure static addressing, use an invalid command syntax, or only activate an existing profile without changing its addressing method.

Exam trap

The trap here is confusing device activation with configuration, assuming that connecting a device automatically sets it to DHCP.

315
Multi-Selecthard

A technician must locate every regular file beneath /var that is larger than 100 MB and was modified more than 30 days ago, then list them. Which TWO find expressions achieve this? (Choose two.)

Select 2 answers
A.find /var -type f -size +100M -mtime +30 -print
B.find /var -type f -size +100M -atime +30 -print
C.find /var -type f -size +100M -mtime +30
D.find /var -size +100M -mtime +30 -exec ls -l {} \;
E.find /var --type f --size +100M --mtime +30 -print
AnswersA, C

This expression combines the three needed tests: -type f restricts matches to regular files, -size +100M matches files strictly larger than 100 mebibytes, and -mtime +30 matches files whose data was last modified more than 30 full 24-hour periods ago. The default action already prints, and -print makes it explicit.

Why this answer

Two variants are correct because find's implicit print makes -print optional, and both retain the -type f, -size +100M, and -mtime +30 tests. Substituting atime measures access rather than modification, dropping the type test admits non-regular entries, and using double-dash predicates is a syntax error that prevents execution.

Exam trap

The trap here is believing -print is mandatory, so a correct expression without it looks incomplete.

316
MCQeasy

A system administrator notices that a process is consuming 100% CPU and is unresponsive. Which command should be used to immediately stop the process if the PID is 2345?

A.kill -9 2345
B.pkill -9 processname
C.systemctl stop processname
D.kill -15 2345
AnswerA

Sending SIGKILL (signal 9) to PID 2345 forces immediate termination at the kernel level, since the process cannot catch, block or ignore this signal. This satisfies the stem's requirement to stop an unresponsive process immediately, whereas gentler signals such as SIGTERM may be ignored by a hung process.

Why this answer

`kill -9 2345` sends the SIGKILL signal (signal 9) to process ID 2345, which immediately terminates the process without allowing it to clean up or ignore the signal. This is the appropriate action for an unresponsive process consuming 100% CPU, as SIGKILL cannot be caught or blocked by the process.

Exam trap

The trap here is that candidates may choose `kill -15` (SIGTERM) thinking it is safer, but the question explicitly requires immediate stoppage of an unresponsive process, where only SIGKILL guarantees termination.

How to eliminate wrong answers

Option B is wrong because `pkill -9 processname` would require the process name, not the PID, and the question specifies that the PID is known (2345); using `pkill` with a name could accidentally terminate other processes with similar names. Option C is wrong because `systemctl stop processname` is used to manage systemd services, not arbitrary user processes, and it sends SIGTERM (signal 15) which the unresponsive process may ignore. Option D is wrong because `kill -15 2345` sends SIGTERM, which requests graceful termination but can be ignored or blocked by a process that is stuck or unresponsive, making it ineffective for immediate stoppage.

317
MCQhard

An admin notices a PV in a VG has failed. The VG is still accessible with redundancy. Which command sequence should be used to replace the faulty PV with a new one (/dev/sde) while the VG is active and without data loss?

A.pvcreate /dev/sde; vgreduce VG_name /dev/sdb; vgextend VG_name /dev/sde; pvmove /dev/sdb
B.pvcreate /dev/sde; pvmove /dev/sdb /dev/sde; vgextend VG_name /dev/sde; vgreduce VG_name /dev/sdb
C.pvcreate /dev/sde; vgextend VG_name /dev/sde; pvmove /dev/sdb /dev/sde; vgreduce VG_name /dev/sdb
D.vgreduce --removemissing VG_name; pvcreate /dev/sde; vgextend VG_name /dev/sde; pvmove /dev/sde
AnswerC

Initialising /dev/sde with pvcreate, then vgextend adds it to the active VG, satisfying the no-downtime constraint. pvmove migrates extents off the faulty /dev/sdb to the new PV while the VG stays online, preserving redundancy. vgreduce finally removes /dev/sdb, completing replacement without data loss.

Why this answer

It first creates the new PV on /dev/sde, extends the VG to include it, then uses pvmove to migrate data from the failing PV (/dev/sdb) to the new PV while the VG is active, and finally removes the faulty PV from the VG with vgreduce. This sequence ensures no data loss and maintains VG availability throughout the replacement process.

Exam trap

The trap here is that candidates often try to remove the failed PV first (using vgreduce or vgreduce --removemissing) before adding the new one, not realizing that data must be migrated off the failing PV while it is still in the VG to avoid data loss.

How to eliminate wrong answers

Option A is wrong because it attempts to reduce the VG before moving data off the failing PV, which would cause data loss if the PV still holds logical volumes. Option B is wrong because it tries to pvmove data from /dev/sdb to /dev/sde before /dev/sde is added to the VG, which will fail since pvmove requires both source and target PVs to be members of the same VG. Option D is wrong because it uses vgreduce --removemissing to forcibly remove the failing PV without first migrating its data, leading to data loss, and also attempts pvmove on the new PV (/dev/sde) which has no data to move.

318
MCQmedium

After extending the logical volume, the df output still shows 100G. What is the most likely reason?

A.The filesystem on the logical volume has not been resized.
B.lvresize must be used instead of lvextend.
C.The kernel has not detected the new size; reboot required.
D.The mount point must be remounted with the 'remount' option.
AnswerA

Extending the logical volume only enlarges the block device; the filesystem on top retains its original size until explicitly grown. Since df reports filesystem capacity, not volume size, it still shows 100G. Resizing the filesystem (for example with resize2fs or xfs_growfs) is required to reflect the added space.

Why this answer

`lvextend` only increases the size of the logical volume at the block device level. The filesystem (e.g., ext4, XFS) still sees the original size until it is explicitly resized with a command like `resize2fs` (for ext4) or `xfs_growfs` (for XFS). The `df` command reports filesystem usage, not the underlying block device size, so the filesystem must be grown to match the LV.

Exam trap

The trap here is that candidates assume extending the logical volume automatically resizes the filesystem, but the LFCS exam tests the explicit two-step process: LV extension followed by filesystem resize.

How to eliminate wrong answers

Option B is wrong because `lvresize` and `lvextend` are functionally equivalent for increasing LV size; both require a subsequent filesystem resize. Option C is wrong because the kernel detects the new LV size immediately via device-mapper; no reboot is needed, and `df` still shows the old size only because the filesystem hasn't been resized. Option D is wrong because remounting does not resize the filesystem; it only changes mount options, and the filesystem metadata remains unchanged.

319
MCQmedium

A Linux administrator is configuring a custom systemd service that must not start until a network share is mounted. The mount is managed by a systemd mount unit named mnt-data.mount. Which directive should be added to the [Unit] section of the service unit to enforce this ordering?

A.Before=mnt-data.mount
B.After=mnt-data.mount
C.Wants=mnt-data.mount
D.Requires=mnt-data.mount
AnswerB

After= ensures that the service starts only after mnt-data.mount has finished activating. This is the correct directive for ordering, as it tells systemd to delay the service start until the specified unit is active, which is exactly what is needed for the mount to be available.

Why this answer

The service must wait for the mount unit to be active before starting. The After= directive explicitly defines ordering, ensuring the service starts only after mnt-data.mount has activated. Requiring the mount alone does not guarantee order, and Before= would reverse the desired sequence.

Exam trap

The trap here is confusing a dependency directive like Requires= with an ordering directive like After=, assuming that requiring a unit also ensures it starts first.

320
MCQmedium

A systems administrator is troubleshooting a server that runs a database application. The server has 64 GB of RAM and 16 CPU cores. The administrator notices that the system is using a significant amount of swap space even though there is plenty of free memory. The 'free -m' command shows: total memory = 65536, used = 50000, free = 15536, buffers/cache = 10000, swap total = 8192, swap used = 6000. Which of the following is the most likely cause?

A.The vm.dirty_ratio and vm.dirty_background_ratio are set too high.
B.The vm.swappiness value is set too high.
C.The database is configured to use huge pages, which are not swappable.
D.The vm.vfs_cache_pressure is set too low.
AnswerB

A high vm.swappiness value makes the kernel aggressively reclaim anonymous pages to swap even when free memory remains, matching the observed 6 GB swap usage alongside 15 GB free. Lowering swappiness keeps pages resident until memory pressure genuinely demands swapping.

Why this answer

A high vm.swappiness value (default 60) causes the kernel to aggressively swap out anonymous pages even when ample free memory exists. With 15 GB free and 10 GB in buffers/cache, the system should not be using 6 GB of swap unless swappiness is set too high, forcing premature swapping.

Exam trap

Linux Foundation often tests the misconception that swap usage only occurs when memory is full, but the trap here is that vm.swappiness can cause swapping even with abundant free memory, leading candidates to overlook the kernel's proactive swapping behavior.

How to eliminate wrong answers

Option A is wrong because vm.dirty_ratio and vm.dirty_background_ratio control when dirty pages are written to disk, not swap usage; they affect I/O performance, not memory pressure. Option C is wrong because huge pages are locked in memory and not swappable, so they would reduce swap usage, not increase it. Option D is wrong because vm.vfs_cache_pressure controls the tendency to reclaim dentry/inode caches, not anonymous page swapping; a low value would preserve cache, not cause swap usage.

321
Multi-Selectmedium

A Linux server is experiencing performance degradation. The administrator suspects that a process is consuming excessive CPU. Which two commands can be used to identify the top CPU-consuming processes in real-time? (Choose two.)

Select 2 answers
A.top
B.vmstat 1
C.free -m
D.ps aux --sort=-%cpu
E.iostat -c
AnswersA, D

The top command provides a dynamic, real-time view of running processes, sorted by CPU usage by default. It displays %CPU, making it easy to identify processes consuming the most CPU. It also allows interactive sorting and killing of processes. This is a standard tool for performance troubleshooting.

Why this answer

To identify top CPU-consuming processes, tools that show per-process CPU usage are needed. top provides a real-time, interactive view, while ps aux --sort=-%cpu gives a sorted snapshot. Both allow the administrator to see which processes are using the most CPU. vmstat and iostat show system-wide CPU statistics but not per-process details, and free is for memory. Therefore, top and ps with sorting are the correct choices.

Exam trap

The trap here is thinking that any command showing CPU statistics will identify the specific process; only per-process tools like top or ps do that.

322
Multi-Selectmedium

Which TWO commands can be used to display the group membership of a user? (Choose two.)

Select 2 answers
A.id -Gn username
B.cat /etc/passwd | grep username
C.id -g username
D.groups username
E.grep username /etc/group
AnswersA, D

id -Gn username prints only the supplementary group names for that user, one line of space-separated groups, which directly answers the membership query. It reads the same account database entries as id without the numeric UID and GID output.

Why this answer

Option A, 'id -Gn username', is correct because the -G flag lists all group IDs the user belongs to and -n converts those GIDs to group names, so it prints every group name the user is a member of. Option D, 'groups username', is correct because the groups command prints the group names that the specified user belongs to, directly showing group membership. Option B, 'cat /etc/passwd | grep username', only shows the user's passwd entry, which contains the primary GID but not supplementary group memberships.

Option C, 'id -g username', prints only the primary group ID (or name with -n), not the full set of groups. Option E, 'grep username /etc/group', only finds groups where the username appears in the member list and misses the user's primary group, so it does not reliably display complete group membership.

Exam trap

The trap is picking file-based commands (/etc/passwd, /etc/group) that only show partial membership, instead of the NSS-aware commands (id -Gn, groups) that report complete group membership.

323
MCQeasy

An administrator needs to assign a temporary IPv4 address of 10.20.30.40/24 to interface enp0s3 for immediate testing. The change should not persist after a reboot. Which command accomplishes this?

A.nmcli con mod enp0s3 ipv4.addresses 10.20.30.40/24
B.ifconfig enp0s3 10.20.30.40 netmask 255.255.255.0 up
C.ip addr add 10.20.30.40/24 dev enp0s3
D.ip route add 10.20.30.40/24 dev enp0s3
AnswerC

The `ip addr add` command adds an address to an interface in the running kernel and does not modify any configuration file, so the address disappears after a reboot. This matches the requirement for a temporary address used only for testing.

Why this answer

Temporary address changes are made directly in the kernel with the `ip` utility. Adding an address with `ip addr add` affects only the current runtime state, so a reboot restores the previous configuration. Persistent tools such as NetworkManager or editing configuration files are used when the change must survive restarts.

Exam trap

The trap here is choosing a persistent configuration tool such as NetworkManager when the scenario explicitly requires the change to be non-persistent.

324
Multi-Selecthard

Which THREE actions will affect the state of a systemd service that is currently running? (Choose three.)

Select 3 answers
A.systemctl kill myapp.service
B.systemctl reload myapp.service
C.systemctl disable myapp.service
D.systemctl daemon-reload
E.systemctl stop myapp.service
AnswersA, B, E

Sending a signal via systemctl kill terminates or signals the running process, immediately altering the unit's active state. It satisfies the stem's requirement for an action affecting a currently running service, unlike query or enable operations that leave runtime state untouched.

Why this answer

Option A, `systemctl kill myapp.service`, is correct because it sends a signal (SIGTERM by default) to the service's processes, which changes the running state by terminating or signaling them. Option B, `systemctl reload myapp.service`, is correct because it triggers the service's ExecReload action, causing the running process to reload its configuration without stopping, thus affecting its runtime state. Option E, `systemctl stop myapp.service`, is correct because it explicitly stops the running service, transitioning it from active to inactive.

Option C, `systemctl disable myapp.service`, only removes the service's autostart symlinks and does not affect a currently running instance. Option D, `systemctl daemon-reload`, only reloads systemd manager configuration and does not alter the state of any running service.

Exam trap

The trap here is that candidates often confuse `disable` (which only affects future boots) with `stop` (which affects the current runtime state), or think `daemon-reload` immediately impacts running services when it only updates unit definitions for subsequent operations.

325
MCQmedium

An administrator has enabled quotas on the /home filesystem by adding usrquota,grpquota to /etc/fstab and remounting. Then ran quotacheck -cug /home and it completed successfully. However, users are still able to write beyond their assigned soft limits. What step is missing?

A.Setting limits with edquota.
B.Running repquota to view quotas.
C.Setting limits with setquota.
D.Running quotaon to activate quotas.
AnswerD

Quotas remain inactive until explicitly enabled; `quotacheck` only builds the quota database files (aquota.user, aquota.group), it does not enforce limits. Running `quotaon /home` activates enforcement, satisfying the stem's requirement to stop users writing beyond their soft limits.

Why this answer

The missing step is activating quotas with `quotaon`. Even after configuring `/etc/fstab` with `usrquota,grpquota`, remounting the filesystem, and running `quotacheck -cug` to create the quota database files (`aquota.user` and `aquota.group`), quotas remain inactive until explicitly enabled with `quotaon`. Without this command, the kernel does not enforce quota limits, allowing users to exceed soft limits without warning.

Exam trap

The trap here is that candidates assume running `quotacheck -cug` both creates the quota database and activates quotas, but `quotacheck` only scans and builds the database, while `quotaon` is a separate mandatory step to enable enforcement.

How to eliminate wrong answers

Option A is wrong because `edquota` is used to set quota limits for users or groups interactively, but the question states that users can write beyond soft limits, implying limits may already be set or the issue is that quotas are not active at all. Option B is wrong because `repquota` is a reporting tool to view current quota usage and limits; it does not enable quota enforcement. Option C is wrong because `setquota` is a command-line tool to set quota limits non-interactively, but like `edquota`, it only configures limits and does not activate the quota system; the missing step is `quotaon`.

326
MCQmedium

You are managing a Linux server that hosts a shared project directory /projects/alpha, owned by the group 'alpha' (GID 2001). The directory has permissions 2770 (setgid, rwx for owner and group, no access for others). User 'jane' (UID 1501) has a primary group 'staff' (GID 1001) and is not in the 'alpha' group. She reports being unable to list or modify files in /projects/alpha. You need to give her access as a member of the 'alpha' group without changing her primary group. Which command sequence should you use?

A.usermod -aG alpha jane; usermod -G '' jane; usermod -aG alpha jane
B.usermod -aG alpha jane
C.usermod -g alpha jane
D.usermod -G alpha jane
AnswerB

usermod -aG alpha jane appends jane to the alpha supplementary group without altering her primary group staff, satisfying the constraint. The setgid bit on /projects/alpha then grants group access, letting her list and modify files after re-login.

Why this answer

The command `usermod -aG alpha jane` appends jane to the supplementary group 'alpha' without altering her primary group 'staff'. Because /projects/alpha is group-owned by alpha with 2770 permissions, group membership grants rwx access, and the setgid bit ensures new files inherit the alpha group. This satisfies the requirement of granting access without changing her primary group.

Exam trap

LFCS often tests the difference between `-g` (change primary group) and `-aG` (append supplementary group) — candidates who omit `-a` accidentally wipe existing supplementary memberships.

How to eliminate wrong answers

Option A is wrong because it needlessly removes jane from all supplementary groups (`usermod -G '' jane`) before re-adding alpha, which strips any other group memberships she legitimately needs and is destructive. Option C is wrong because `usermod -g alpha jane` changes her primary group to alpha, which the question explicitly forbids. Option D is wrong because `usermod -G alpha jane` (without -a) replaces her entire supplementary group list with only alpha, silently removing her from all other supplementary groups.

327
Multi-Selectmedium

Which TWO commands can be used to view the last 10 lines of a file and also follow new lines as they are written?

Select 2 answers
A.tail -f -n 10
B.cat -n
C.tail -n 10
D.head -n 10
E.less +F
AnswersA, E

`tail -f -n 10` satisfies both constraints: `-n 10` prints the final ten lines, while `-f` keeps the file descriptor open and streams appended data as it is written. This combination suits live log monitoring, where existing tail content and subsequent writes must both be observed continuously.

Why this answer

Option A, `tail -f -n 10`, is correct because `-n 10` displays the last 10 lines of the file and `-f` (follow) keeps the file open and prints new lines as they are appended, which is exactly the requested behavior. Option E, `less +F`, is correct because the `+F` command starts `less` in follow mode, initially showing the file content (including the tail end) and continuously displaying newly appended lines, similar to `tail -f`. Option B, `cat -n`, only concatenates the file with line numbers and does not follow new lines.

Option C, `tail -n 10`, shows the last 10 lines but lacks the follow capability. Option D, `head -n 10`, shows the first 10 lines and does not follow the file.

Exam trap

Linux Foundation often tests the distinction between `tail -n 10` (static view) and `tail -f -n 10` (dynamic follow), and candidates may overlook the `-f` flag or confuse `head` with `tail`.

328
MCQmedium

Based on the exhibit, which process is using the most physical memory (RES)?

A.mysqld (PID 9101)
B.Not determinable from exhibit
C.nginx (PID 5678)
D.systemd (PID 1234)
AnswerA

The RES column in top reports resident set size, the non-swapped physical memory a process currently occupies. Comparing RES values across the exhibit, mysqld at PID 9101 holds the largest figure, so it consumes the most physical memory.

Why this answer

The exhibit shows the output of the `top` command, where the RES column indicates the resident memory (physical RAM) used by each process. mysqld (PID 9101) has a RES value of 2.5g, which is significantly higher than nginx (PID 5678) with 128m and systemd (PID 1234) with 48m, making it the process using the most physical memory.

Exam trap

The trap here is that candidates may confuse the VIRT (virtual memory) column with RES, or assume that a process with a higher PID or name familiarity uses more memory, rather than reading the RES values directly from the exhibit.

How to eliminate wrong answers

Option B is wrong because the exhibit clearly displays the RES column for each process, allowing direct comparison of physical memory usage. Option C is wrong because nginx (PID 5678) shows only 128m in the RES column, which is far less than mysqld's 2.5g. Option D is wrong because systemd (PID 1234) has only 48m in the RES column, the smallest value among the listed processes.

329
MCQmedium

You administer a Linux server that acts as a network gateway. It has two network interfaces: eth0 (external, with IP 203.0.113.10/24, gateway 203.0.113.1) and eth1 (internal, with IP 192.168.1.1/24). The server is running firewalld and has IP forwarding enabled. Internal hosts (192.168.1.0/24) can access the internet through NAT, which is configured using firewalld's masquerade on the external zone. However, you need to allow a specific internal server (192.168.1.100) to be reachable from the internet on TCP port 443 (HTTPS). You add a port forwarding rule using firewall-cmd: 'firewall-cmd --zone=external --add-forward-port=port=443:proto=tcp:toport=443:toaddr=192.168.1.100'. After reloading the firewall, external users still cannot connect to 203.0.113.10:443. You verify that the internal server is running HTTPS and that its local firewall allows port 443. What is the most likely reason the port forwarding is not working?

A.The port forwarding rule should be added to the internal zone instead of the external zone.
B.The internal server has a different default gateway.
C.The rule needs to include masquerade for the destination address; use a rich rule with 'masquerade'.
D.IP forwarding is not enabled on the system.
AnswerC

In firewalld, simple port forwarding often does not work without masquerade on the external zone. A rich rule with 'masquerade' is required, e.g., 'firewall-cmd --add-rich-rule="rule family=ipv4 destination address=203.0.113.10 forward-port port=443 protocol=tcp to-port=443 to-addr=192.168.1.100"' which implicitly uses masquerade? Actually standard practice is to use a rich rule. Option C is the best answer.

Why this answer

A simple port forward rule in firewalld does not automatically rewrite the source IP address for return traffic. Without masquerade on the forwarded traffic, the internal server sees the original external source IP and sends its response directly to that IP, bypassing the gateway. Adding a rich rule with 'masquerade' for the destination address ensures that the gateway performs SNAT on the forwarded packets, so the internal server sees the gateway as the source and returns traffic through it.

Exam trap

The trap here is that candidates assume a port forward rule alone is sufficient for bidirectional communication, overlooking the need for source NAT (masquerade) on the forwarded traffic to ensure proper return path routing.

How to eliminate wrong answers

Option A is wrong because port forwarding for externally initiated connections must be placed in the zone associated with the incoming interface (external), not the internal zone; the internal zone handles traffic from the internal network. Option B is wrong because the internal server's default gateway is irrelevant for inbound connections that are forwarded by the gateway; the server only needs to respond to the gateway's IP (192.168.1.1) for the return path to work. Option D is wrong because the question states that IP forwarding is enabled and internal hosts already access the internet through NAT, confirming that forwarding is active.

330
MCQeasy

A junior administrator needs to verify that the host can resolve the name db.internal.example.com to an IPv4 address before deploying a database client. The system uses systemd-resolved. Which command queries the configured resolver and displays the answer without relying on the local nsswitch.conf ordering?

A.dig db.internal.example.com
B.host db.internal.example.com
C.getent hosts db.internal.example.com
D.resolvectl query db.internal.example.com
AnswerD

resolvectl query sends the name to systemd-resolved and reports the answer along with which link and DNS server provided it. This directly exercises the resolver configured on the system, bypassing nsswitch.conf ordering, and is the correct tool on systemd-resolved hosts. It also shows whether the answer came from cache, DNS, or another source, which is valuable for troubleshooting.

Why this answer

resolvectl query is the native client for systemd-resolved. It sends the query through the resolver daemon, showing the answer, the link used, and the DNS server that responded. This isolates DNS resolution from nsswitch.conf sources like /etc/hosts, which is exactly what is needed to confirm the configured resolver can resolve the name.

Exam trap

The trap here is assuming that any lookup tool tests the configured resolver, when tools like getent and host actually follow nsswitch.conf and may return /etc/hosts entries instead.

331
MCQmedium

A Linux server hosts a shared project workspace at /srv/design. The directory is owned by root and currently has permissions 0775 with group ownership set to the 'designers' group. A new file was just created inside /srv/design by user 'mira' (a member of designers), and the file's group is showing as 'mira' instead of 'designers'. The team lead wants every NEW file and subdirectory created under /srv/design to automatically inherit the 'designers' group, while leaving existing files untouched. Which command should the administrator run?

A.chmod g+s /srv/design
B.chgrp -R designers /srv/design
C.setfacl -R -m g:designers:rwx /srv/design
D.chmod +t /srv/design
AnswerA

Setting the setgid bit on a directory (chmod g+s) causes all newly created files and subdirectories within it to inherit the directory's group instead of the creating user's primary group. This matches the requirement exactly and does not modify existing file ownership or group memberships.

Why this answer

The setgid bit on a directory is the standard mechanism for group inheritance: any file or subdirectory created inside the directory takes the directory's group as its own group. Using chmod g+s on /srv/design applies this behavior without touching existing files or changing individual user group memberships.

Exam trap

The trap here is assuming that adding an ACL or recursively changing group ownership will make future files inherit the group, when only the directory setgid bit provides persistent group inheritance.

332
MCQmedium

A server must resolve internal hostnames using a DNS server at 10.0.0.53 before falling back to public resolvers. The administrator edits /etc/systemd/resolved.conf and sets DNS=10.0.0.53 and FallbackDNS=8.8.8.8. After restarting systemd-resolved, queries for internal names still fail. Which additional step is most likely required?

A.Ensure /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf or /run/systemd/resolve/resolv.conf.
B.Add the search domain to /etc/hosts so internal names resolve locally.
C.Run resolvectl flush-caches to clear stale entries.
D.Set DNSSEC=no in resolved.conf because DNSSEC validation is blocking internal responses.
AnswerA

systemd-resolved only serves queries through its stub listener if /etc/resolv.conf points to the stub resolver file. If it still points to a static file or a different target, applications bypass systemd-resolved and the configured DNS servers are never used. Correcting the symlink makes the configuration effective.

Why this answer

systemd-resolved reads DNS server settings from resolved.conf, but applications reach it through /etc/resolv.conf. If that file is not symlinked to the stub or full resolv.conf generated by systemd-resolved, the configured servers are ignored. Recreating the symlink ensures queries go through systemd-resolved and reach 10.0.0.53.

Exam trap

The trap here is assuming that editing resolved.conf is sufficient, when the /etc/resolv.conf symlink determines whether systemd-resolved is actually used.

333
MCQeasy

An administrator needs to view the current IPv4 addresses, link state, and interface names on a Linux server without making any changes. Which command provides this information in a single invocation?

A.ip addr show
B.ifconfig -a
C.ss -tuln
D.ip route show
AnswerA

ip addr show displays all interfaces with their link state and assigned IPv4 and IPv6 addresses. It is the standard, non-disruptive command to inspect current addressing and interface status, exactly matching the requirement to view addresses and link state without modifying configuration.

Why this answer

The ip command from iproute2 is the current standard for network configuration and inspection. ip addr show lists every interface with its operational state, MAC address, and assigned IPv4/IPv6 addresses, which is precisely the information requested. The other commands either show unrelated data or belong to deprecated tooling.

Exam trap

The trap here is reaching for the deprecated ifconfig -a out of habit instead of the current ip addr show.

334
MCQmedium

A server needs to forward packets between two networks: 10.0.1.0/24 on eth0 and 10.0.2.0/24 on eth1. Which sysctl parameter must be enabled?

A.net.ipv4.conf.all.rp_filter = 1
B.net.ipv4.ip_forward = 1
C.net.ipv4.conf.all.accept_source_route = 1
D.net.ipv4.conf.all.send_redirects = 0
AnswerB

Setting net.ipv4.ip_forward to 1 enables the kernel to route packets between interfaces rather than dropping them, which is exactly what forwarding between eth0's 10.0.1.0/24 and eth1's 10.0.2.0/24 requires. Without it, the server cannot act as a router.

Why this answer

Enabling `net.ipv4.ip_forward = 1` allows the Linux kernel to forward IP packets between network interfaces, which is required for a server to route traffic between the 10.0.1.0/24 and 10.0.2.0/24 subnets. Without this parameter, the kernel drops any packet not destined for the local system, preventing inter-network communication.

Exam trap

The trap here is that candidates often confuse security-related sysctl parameters (like rp_filter or send_redirects) with the actual forwarding control, or mistakenly think that enabling source route acceptance is needed for routing between subnets.

How to eliminate wrong answers

Option A is wrong because `net.ipv4.conf.all.rp_filter = 1` enables reverse path filtering, which helps prevent IP spoofing by dropping packets that arrive on an interface that is not the best route back to the source; it does not enable packet forwarding. Option C is wrong because `net.ipv4.conf.all.accept_source_route = 1` allows the system to process IPv4 source-routed packets, a security risk that is unrelated to forwarding between networks. Option D is wrong because `net.ipv4.conf.all.send_redirects = 0` disables the sending of ICMP redirect messages, which is a security hardening measure but does not enable or disable packet forwarding.

335
MCQhard

A Linux administrator is configuring a systemd service that must only start after the network is fully online and must stop if the network goes down. The unit file currently has After=network.target. However, the service sometimes starts before DNS resolution is available, causing failures. Which target should the administrator use instead to ensure the network is fully configured and DNS is available?

A.network.target
B.multi-user.target
C.basic.target
D.network-online.target
AnswerD

network-online.target is a special target that waits until the network is actually configured and reachable, not just the network management stack started. Using After=network-online.target and Wants=network-online.target ensures the service starts only after the network is online, which includes DNS resolution. This directly addresses the premature start issue.

Why this answer

network-online.target is designed specifically to wait until the network is fully operational, including DNS resolution. By using After=network-online.target and Wants=network-online.target, the service will not start until the network is truly online. This is the correct target for services that require actual network connectivity, unlike network.target which only signals that the network stack has started.

Exam trap

The trap here is confusing network.target with network-online.target; the former only indicates the network stack is up, while the latter waits for actual connectivity.

336
MCQhard

An administrator needs to add a 2 GB swap area that persists across reboots on a server with no free partition space, using a file at /swapfile on the root filesystem. After creating the file with fallocate and running mkswap /swapfile, which additional actions are required to activate it now and at every boot?

A.Run swapon /swapfile and add the line '/swapfile none swap sw 0 0' to /etc/fstab.
B.Run swapon /swapfile and add the line '/swapfile none swap defaults,nofail 0 2' to /etc/fstab.
C.Run mount /swapfile and add the line '/swapfile none swap sw 0 0' to /etc/fstab.
D.Run mkswap --activate /swapfile and add the line '/swapfile swap swap sw 0 0' to /etc/fstab.
AnswerA

swapon /swapfile activates the swap area immediately for the running system, and the /etc/fstab entry with filesystem type swap and options sw ensures the kernel enables it during boot. Both steps are necessary: without swapon it is inactive now, and without the fstab line it is lost after reboot. This matches the persistence requirement.

Why this answer

A swap file is activated in the running system with swapon and made persistent by adding an fstab entry whose filesystem type is swap and whose dump and pass fields are both zero. Using mount instead of swapon, inventing a mkswap activation flag, or supplying a nonzero pass field all fail to produce a correctly activated and persistent swap area.

Exam trap

The trap here is assuming swap is enabled like a normal filesystem with mount, when the kernel uses the dedicated swapon mechanism.

337
Multi-Selecthard

Which THREE of the following commands can be used to search for a string in multiple files and display the matching lines?

Select 3 answers
A.find /path -name '*.txt' -type f
B.ack 'pattern' /path
C.grep -r 'pattern' /path
D.rg 'pattern' /path
E.sort /path/file
AnswersB, C, D

ack is a Perl-based grep replacement that recursively searches directory trees by default, printing matching lines with filenames. This satisfies the requirement to search a string across multiple files under /path and display the matches.

Why this answer

Option B, ack 'pattern' /path, is correct because ack is a recursive grep-like search tool that by default searches files under the given path and prints matching lines with filenames. Option C, grep -r 'pattern' /path, is correct because the -r (recursive) flag makes grep descend into directories and display each matching line prefixed by its file. Option D, rg 'pattern' /path, is correct because ripgrep recursively searches the path and outputs matching lines, honoring ignore files by default.

Option A, find /path -name '*.txt' -type f, only locates files by name and type; it does not search file contents or display matching lines. Option E, sort /path/file, merely sorts lines of a single file and performs no pattern search.

Exam trap

The trap here is that candidates may confuse file-location commands like `find` with content-search commands, or assume that `sort` can filter lines based on a pattern, when it only reorders lines.

338
MCQeasy

A junior administrator needs to create a compressed archive of the /etc directory that preserves file ownership and permissions, and writes it to /backup/etc.tar.gz. Which single command accomplishes this?

A.gzip -r /etc > /backup/etc.tar.gz
B.tar -czvf /backup/etc.tar.gz /etc
C.cpio -ov /etc < /backup/etc.tar.gz
D.tar -xzvf /backup/etc.tar.gz /etc
AnswerB

This is correct because tar with the -c flag creates a new archive, -z compresses it with gzip, -v shows progress, and -f specifies the archive filename. By default tar preserves ownership and permission metadata when creating archives as root, exactly matching the requirement to archive /etc into /backup/etc.tar.gz.

Why this answer

Creating a gzip-compressed tarball requires the create, gzip, verbose, and file flags together with the source directory. The combination tar -czvf /backup/etc.tar.gz /etc builds the archive in one pass, preserving metadata, and writes it to the specified path. The other commands either attempt extraction, misuse compression tools, or produce non-tar output.

Exam trap

The trap here is confusing the create flag -c with the extract flag -x when the stem asks to build an archive.

339
MCQhard

An administrator wants to limit the CPU usage of a service to at most 50% of a single CPU core. Which directive should be set in the [Service] section of the unit file?

A.CPUQuota=50%
B.CPUAccounting=true
C.CPUWeight=100
D.CPUShares=512
AnswerA

CPUQuota=50% caps the service's aggregate CPU time at half of one core, enforced by the cgroup v2 cpu.max controller. This directly satisfies the stem's 50%-of-a-single-core ceiling, unlike CPUShares or Nice, which only weight scheduling priority without imposing a hard bandwidth limit.

Why this answer

`CPUQuota=` is the systemd directive that limits the CPU time a service can use, expressed as a percentage of a single CPU core. Setting `CPUQuota=50%` restricts the service to at most 50% of one core's time, effectively capping its CPU usage to half a core.

Exam trap

The trap here is that candidates often confuse relative CPU shares (like `CPUWeight` or `CPUShares`) with absolute CPU limits (`CPUQuota`), or mistakenly think `CPUAccounting=true` alone restricts CPU usage.

How to eliminate wrong answers

Option B is wrong because `CPUAccounting=true` enables CPU usage tracking and accounting for the unit, but it does not impose any limit on CPU usage. Option C is wrong because `CPUWeight=100` sets the relative weight for CPU time distribution among competing services under the CFS scheduler, not a hard limit. Option D is wrong because `CPUShares=512` is a legacy cgroup v1 parameter that also controls relative CPU share, not an absolute cap, and is deprecated in favor of `CPUWeight` in cgroup v2.

340
MCQhard

A Linux server is configured with two network interfaces: eth0 (192.168.1.10/24) and eth1 (10.0.0.10/24). The default route is via 192.168.1.1. A network administrator wants to ensure that traffic to the 10.0.0.0/24 network uses eth1 and that the source address for that traffic is 10.0.0.10. Which command will achieve this?

A.ip route add 10.0.0.0/24 via 10.0.0.1 dev eth1
B.ip route add 10.0.0.0/24 dev eth1
C.ip route add 10.0.0.0/24 dev eth1 src 10.0.0.10
D.ip route add default via 10.0.0.1 dev eth1
AnswerC

This command adds a route for the 10.0.0.0/24 network directly via eth1 and specifies the source address 10.0.0.10. It ensures that packets to that network are sent out eth1 with the correct source IP, meeting the administrator's requirement without needing a gateway.

Why this answer

To direct traffic for a specific directly attached network out a particular interface and use a specific source address, the ip route add command with the dev and src options is used. This ensures packets to 10.0.0.0/24 leave via eth1 with source 10.0.0.10, fulfilling the requirement without affecting other traffic.

Exam trap

The trap here is forgetting to specify the source address or incorrectly using a gateway for a directly attached network.

341
Drag & Dropmedium

Order the steps to configure a static IP address on a CentOS/RHEL 7 system using ifcfg files.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Static IP configuration requires editing the ifcfg file, restarting network, and verification.

342
MCQeasy

A Linux administrator needs to schedule a backup script to run every day at 2:30 AM. The script is located at /usr/local/bin/backup.sh. Which command should the administrator use to edit the crontab for the root user?

A.systemctl edit cron.service
B.vi /etc/crontab
C.crontab -l
D.crontab -e
AnswerD

Running 'crontab -e' as root opens the root user's crontab in the default editor, allowing the administrator to add the schedule for the backup script. This is the standard method to create or modify a user's cron jobs. It ensures the job runs with root privileges and is the correct command for this scenario.

Why this answer

The command 'crontab -e' opens the crontab file for the current user (root in this case) in an editor, allowing the administrator to add the line '30 2 * * * /usr/local/bin/backup.sh'. This is the standard and safest way to schedule a recurring job. Other options either list jobs, edit a system file inappropriately, or modify the service unit, none of which achieve the goal.

Exam trap

The trap here is thinking that editing /etc/crontab directly is equivalent to using crontab -e, but the system-wide file requires a username field and is not the recommended method for user-specific jobs.

343
Multi-Selecthard

An administrator is preparing a new server with two unused disks, /dev/sdb and /dev/sdc, for a software RAID 1 array that will hold customer data. Which two commands are required to create the array and make it usable? (Choose two.)

Select 2 answers
A.mdadm --create /dev/md0 --level=1 --raid-devices=2 /dev/sdb /dev/sdc
B.mdadm --detail /dev/md0
C.pvcreate /dev/sdb /dev/sdc
D.mdadm --assemble /dev/md0 /dev/sdb /dev/sdc
E.mkfs.ext4 /dev/md0
AnswersA, E

This mdadm command creates a RAID 1 array named /dev/md0 using the two specified disks as members. It is the essential step that assembles the array. After creation, the array appears as a block device that can be partitioned or formatted. Without this command, no RAID device exists, so the remaining steps would have nothing to act on.

Why this answer

Creating a usable software RAID 1 array requires two actions: mdadm --create to build the array from the member disks, and a filesystem creation command such as mkfs.ext4 on the resulting /dev/md0 device. Assembly is only for reactivating existing arrays, and pvcreate belongs to LVM. Verification with mdadm --detail is optional.

Exam trap

The trap here is confusing mdadm --create with mdadm --assemble, since both produce an active /dev/md device but only one works on blank disks.

344
Multi-Selectmedium

Which two statements are true about LVM snapshots? (Choose two.)

Select 2 answers
A.Snapshots require the same amount of space as the original volume.
B.Snapshots are read-only by default.
C.Snapshots use copy-on-write technology.
D.Snapshots can be used to restore the original volume.
E.Snapshots are only supported on ext4 filesystems.
AnswersC, D

LVM snapshots employ copy-on-write: when a block on the origin changes, its original contents are copied to the snapshot before the write proceeds. This preserves a point-in-time view while consuming space only for modified blocks.

Why this answer

Option C is correct because LVM snapshots are implemented using copy-on-write (COW): when data on the origin logical volume is modified, the original block is copied to the snapshot's COW space before being overwritten, so the snapshot preserves the point-in-time state. Option D is correct because a snapshot can be mounted and its contents copied back to the origin (or the origin can be reverted from the snapshot with lvconvert --merge), making it a valid mechanism for restoring the original volume. Option A is wrong because a snapshot only needs enough space to hold changed blocks, not a full copy of the origin.

Option B is wrong because LVM snapshots are writable by default, though they are typically used read-only. Option E is wrong because LVM snapshots operate at the block-device layer and are filesystem-agnostic, working with ext4, XFS, and others.

Exam trap

The trap here is that candidates often assume snapshots are read-only (like many other snapshot implementations) or that they require full duplication of the source volume, but LVM snapshots are read-write by default and use copy-on-write to minimize space usage.

345
MCQeasy

A technician needs to view the current IPv4 addresses, netmasks, and interface states for all network interfaces on a Linux server. Which command displays this information in a structured, modern format?

A.netstat -rn
B.ss -tuln
C.ifconfig -a
D.ip addr show
AnswerD

The ip addr show command (or its shorthand ip a) displays IPv4 and IPv6 addresses, netmasks in CIDR notation, and interface operational states for all interfaces. It is part of the iproute2 suite and is the modern replacement for ifconfig. It provides exactly the structured output needed to inspect addressing and link status.

Why this answer

The ip addr show command is the standard modern tool for displaying interface addresses, netmasks, and states. It is part of iproute2 and provides both IPv4 and IPv6 details in a structured format. The other commands either show routing tables, socket statistics, or rely on deprecated tools that do not present the requested information in the required format.

Exam trap

The trap here is reaching for ifconfig out of habit, even though it is deprecated and does not show CIDR netmasks or IPv6 by default.

346
Multi-Selecteasy

A system administrator needs to check the firewall rules on a Linux server using firewalld. Which two commands can be used to list the current rules? (Choose two.)

Select 2 answers
A.systemctl status firewalld
B.iptables -S
C.iptables -L
D.firewall-cmd --list-all-zones
E.firewall-cmd --list-all
AnswersD, E

Correct. This command displays the firewall rules for all zones configured in firewalld, including services, ports, and rules per zone.

Why this answer

`firewall-cmd --list-all-zones` displays the firewall rules for all zones configured in firewalld, showing services, ports, and rules per zone. Option E is correct because `firewall-cmd --list-all` lists the rules for the default zone, providing a concise view of active firewall configuration. Both commands are native to firewalld and directly query its runtime and permanent rules via D-Bus.

Exam trap

The trap here is that candidates confuse legacy iptables commands with firewalld's native tools, assuming `iptables -L` or `-S` are equivalent to listing firewalld rules, when in fact they bypass firewalld's zone abstraction and may not reflect the current dynamic configuration.

347
MCQmedium

Scenario: You are managing a Linux server that hosts a web application. The application runs under the user 'webapp' and the group 'webgroup'. Recently, a new intern 'john' (username 'john') needs to be able to view and modify files in /var/www/html, which is owned by root:webgroup with permissions 775. John is currently a member of the group 'staff', but not 'webgroup'. The security policy requires that John must be able to edit files without using sudo, and his primary group must remain 'staff'. Which of the following actions should you take to meet the requirements?

A.Add John to the 'webgroup' supplementary group with 'usermod -a -G webgroup john'.
B.Change the group ownership of /var/www/html to 'staff' and set the setgid bit.
C.Change John's primary group to 'webgroup' with 'usermod -g webgroup john'.
D.Set the setgid bit on /var/www/html with 'chmod g+s /var/www/html'.
AnswerA

Adding john to webgroup as a supplementary group grants him the group write permission on /var/www/html (775, root:webgroup) without sudo, while his primary group stays staff. This satisfies both the editing requirement and the policy that his primary group remain unchanged.

Why this answer

Adding John to the 'webgroup' supplementary group with `usermod -a -G webgroup john` grants him group-level access to /var/www/html (owned by root:webgroup with permissions 775) without changing his primary group 'staff'. This allows him to view and modify files as a member of 'webgroup', satisfying the security policy that he must not use sudo and his primary group must remain unchanged.

Exam trap

The trap here is that candidates may confuse the setgid bit (Option D) with granting group membership, or incorrectly assume that changing the primary group (Option C) is acceptable despite the explicit requirement to keep it as 'staff'.

How to eliminate wrong answers

Option B is wrong because changing the group ownership of /var/www/html to 'staff' would grant access to all members of 'staff', which violates the principle of least privilege and does not specifically give John access as a member of 'webgroup'. Option C is wrong because changing John's primary group to 'webgroup' with `usermod -g webgroup john` would violate the requirement that his primary group must remain 'staff'. Option D is wrong because setting the setgid bit on /var/www/html with `chmod g+s /var/www/html` only ensures new files inherit the group ownership of the directory, but does not grant John membership in 'webgroup' or access to the directory itself.

348
Multi-Selecthard

Which THREE files or directories are commonly used to configure network interfaces on a RHEL/CentOS system?

Select 3 answers
A./etc/rc.d/rc.local
B./etc/resolv.conf
C./etc/sysconfig/network
D./etc/sysconfig/network-scripts/
E./etc/nsswitch.conf
AnswersB, C, D

This file configures DNS resolver settings.

Why this answer

/etc/resolv.conf is the primary configuration file for DNS resolver settings on RHEL/CentOS systems. It specifies the nameserver IP addresses, search domains, and resolver options used by the system's glibc resolver library to perform DNS lookups. Without this file, domain name resolution will fail, making it essential for network interface configuration.

Exam trap

The trap here is that candidates often confuse /etc/resolv.conf as a static configuration file, but on modern systems it is frequently auto-generated by NetworkManager or dhclient, leading to the misconception that it is not a 'commonly used' configuration file for network interfaces.

349
MCQeasy

A junior administrator needs to check the current system time and date on a Linux server. Which command will display this information?

A.hwclock
B.uptime
C.date
D.timedatectl status
AnswerC

The date command displays the current system date and time according to the system clock. It can also be used to set the date, but without arguments it simply prints the current date and time in the default format.

Why this answer

The date command is the standard utility to display the current system date and time. It is simple, universally available, and directly outputs the information requested without additional details.

Exam trap

The trap here is overcomplicating a basic task; while other commands show time-related information, only date is dedicated to displaying the system date and time.

350
MCQhard

A storage administrator is troubleshooting a system where a new SCSI disk is detected by the kernel but not visible in /dev/disk/by-id/. What is the most likely cause?

A.The device mapper target is not set for the disk.
B.The disk does not have a valid partition table.
C.The scsi_mod kernel module is not loaded.
D.The udev daemon has not processed the device yet; run 'udevadm trigger' to generate links.
AnswerD

udev creates the persistent /dev/disk/by-id/ symlinks asynchronously after the kernel emits a uevent for the new SCSI device. The disk appearing in kernel logs confirms detection, but the by-id links only materialise once udev processes that event; running 'udevadm trigger' forces reprocessing, generating the missing symlinks.

Why this answer

When a new SCSI disk is detected by the kernel, the kernel creates the device node (e.g., /dev/sdb), but the symbolic links under /dev/disk/by-id/ are generated by udev based on the device's WWID or other identifiers. If udev has not yet processed the uevent for the new disk, those persistent by-id links will not exist. Running 'udevadm trigger' forces udev to reprocess all pending or missed uevents, which creates the missing links.

Exam trap

The trap here is that candidates assume a missing partition table or device mapper target is the cause, but the question explicitly states the disk is detected by the kernel, meaning the issue is with udev link creation, not with kernel-level detection or partitioning.

How to eliminate wrong answers

Option A is wrong because the device mapper target (e.g., dm-linear, dm-crypt) is only relevant for logical volumes or mapped devices, not for a raw SCSI disk being detected by the kernel; by-id links are created by udev for any block device regardless of device mapper. Option B is wrong because a missing partition table does not prevent the kernel from creating the base device node or udev from generating by-id links for the whole disk (e.g., /dev/disk/by-id/wwn-0x...); partition tables affect partition-level links, not the disk-level by-id links. Option C is wrong because if the scsi_mod kernel module were not loaded, the kernel would not detect the SCSI disk at all; the question states the disk is detected by the kernel, so the module must be loaded.

351
Multi-Selectmedium

An administrator is configuring LVM and wants to display information about physical volumes, volume groups, and logical volumes. Which two commands provide this information? (Choose two.)

Select 2 answers
A.pvscan, vgscan, lvscan
B.pvck, vgck, lvck
C.pvcreate, vgcreate, lvcreate
D.pvdisplay, vgdisplay, lvdisplay
E.pvs, vgs, lvs
AnswersD, E

pvdisplay, vgdisplay and lvdisplay report detailed per-object attributes for physical volumes, volume groups and logical volumes respectively, including sizes, UUIDs and allocation policy. They satisfy the requirement to inspect all three LVM layers, though the question expects only two commands.

Why this answer

Option D is correct because pvdisplay, vgdisplay, and lvdisplay are the LVM reporting commands that print detailed information about physical volumes, volume groups, and logical volumes respectively, including attributes such as size, UUID, PE size, and allocation policy. Option E is also correct because pvs, vgs, and lvs are the LVM reporting commands that produce concise, column-oriented summaries of physical volumes, volume groups, and logical volumes, making them ideal for quickly displaying this information. Option A is incorrect because pvscan, vgscan, and lvscan scan for and activate LVM metadata/devices rather than displaying detailed configuration information.

Option B is incorrect because pvck, vgck, and lvck check and repair LVM metadata consistency, not report volume information. Option C is incorrect because pvcreate, vgcreate, and lvcreate create physical volumes, volume groups, and logical volumes rather than displaying information about them.

Exam trap

The trap here is that candidates often confuse the 'scan' commands (option A) with 'display' commands, assuming that scanning also shows detailed information, when in fact `pvscan` only lists discovered PVs without showing attributes like PE size or free space.

352
MCQeasy

A junior administrator needs to add a new 2 TiB disk, /dev/sdc, to a server and create a single GPT partition that spans the entire disk. The disk currently has no partition table. Which command will create the GPT partition table and the partition in one interactive session?

A.gdisk /dev/sdc
B.fdisk /dev/sdc
C.mkfs.gpt /dev/sdc
D.parted /dev/sdc mklabel msdos
AnswerA

gdisk is an interactive GPT fdisk utility. It can create a new GPT partition table and then create a partition spanning the entire disk. It is designed specifically for GPT and handles large disks over 2 TiB. This is the appropriate tool for the scenario.

Why this answer

To create a GPT partition table and a full-disk partition on /dev/sdc, gdisk is the dedicated interactive tool. It supports GPT natively and handles large disks. fdisk may work but is traditionally MBR-oriented, mkfs.gpt is nonexistent, and the parted command shown creates an MBR label instead of GPT. gdisk is the correct choice.

Exam trap

The trap here is choosing a familiar partitioning tool without confirming it can create GPT, or mistaking GPT for a filesystem.

353
MCQeasy

A user reports that they cannot run a script because it says 'Permission denied'. The script is owned by root and has permissions -rw-r--r--. Which command would allow the user to execute the script?

A.chmod u+s script
B.chmod +x script
C.chmod -w script
D.chown user:user script
AnswerB

chmod +x adds execute permission for user, group and others, addressing the missing execute bit in -rw-r--r--. This satisfies the Permission denied constraint, though the user also needs read access, which the existing permissions already grant.

Why this answer

The script has permissions `-rw-r--r--`, meaning the owner (root) has read/write, but no execute bit is set for any user. Option B (`chmod +x script`) adds the execute permission for all users (owner, group, others), which allows the user to run the script. Without the execute bit, the kernel will refuse to execve() the file, returning EACCES.

Exam trap

The trap here is that candidates may confuse ownership or SUID with the fundamental requirement of the execute bit, thinking that changing the owner or setting the setuid bit will allow execution, when in fact the kernel strictly requires the 'x' bit to be set for the file to be run as a program.

How to eliminate wrong answers

Option A is wrong because `chmod u+s` sets the setuid bit (SUID), which only affects the effective user ID during execution, but does not grant execute permission; the file still lacks the execute bit, so the script cannot be run. Option C is wrong because `chmod -w` removes write permission, which does not solve the missing execute permission; the user already cannot write to the file, and this change would only further restrict access. Option D is wrong because `chown user:user script` changes ownership to the user, which would give the user owner permissions (read/write), but the file still lacks the execute bit; ownership alone does not enable execution.

354
MCQhard

A Linux server's root filesystem is running out of space. The administrator needs to identify which directory under /var is consuming the most disk space. Which command should the administrator use?

A.ls -lR /var | sort -k5 -n
B.df -h /var
C.find /var -type d -exec du -sh {} \;
D.du -sh /var/*
AnswerD

The command 'du -sh /var/*' summarizes the disk usage of each item directly under /var in human-readable format. It shows the total size of each directory or file, allowing the administrator to quickly identify which subdirectory is largest. This directly answers the question of which directory under /var consumes the most space. It is efficient and does not require recursive listing of all files.

Why this answer

The command 'du -sh /var/*' provides a concise summary of disk usage for each top-level item in /var, making it easy to spot the largest directory. It uses the -s option to summarize and -h for human-readable output. Other commands either show filesystem-level usage, list individual files, or produce excessive output, none of which efficiently identify the largest directory under /var.

Exam trap

The trap here is using df to check filesystem usage instead of du to find directory sizes; df shows the whole filesystem, not the breakdown within it.

355
MCQmedium

A DevOps engineer is writing a continuous integration pipeline that runs a script to deploy an application. The script is stored in a Git repository and is executed on a build server. The script works locally on the engineer's workstation, but when executed on the build server, it fails with '/bin/sh: line 12: somecommand: command not found'. The 'somecommand' is a standard Linux tool that is installed on the build server. The build server uses a minimal Docker container. Which of the following is the most likely cause and solution?

A.The PATH environment variable is not set correctly in the non-interactive shell. Use the full path to 'somecommand' or set PATH explicitly in the script.
B.The script does not have execute permissions. Add 'chmod +x' before running the script.
C.The script requires root privileges. Use 'sudo' to run the script.
D.The script is using a different shell than the build server's default. Change the shebang to '#!/bin/sh'.
AnswerA

Non-interactive shells in minimal containers often inherit a stripped PATH lacking the directory holding somecommand, so the lookup fails despite installation. Invoking the absolute path or exporting PATH within the script restores resolution, matching the 'command not found' error on the build server.

Why this answer

The error 'command not found' despite the tool being installed indicates that the shell cannot locate the executable. In a non-interactive shell (like those used in CI/CD pipelines or minimal Docker containers), the PATH environment variable is often not set or is minimal. The fix is to either use the absolute path to the command or explicitly set PATH in the script to include the directory containing the command.

Exam trap

The trap here is that candidates often confuse 'command not found' with missing permissions or wrong shell, but the real issue is the missing or incomplete PATH in non-interactive shells, a classic pitfall in containerized or automated environments.

How to eliminate wrong answers

Option B is wrong because the error message 'command not found' is not related to file execute permissions; a missing execute permission would produce 'Permission denied', not 'command not found'. Option C is wrong because the error is about command resolution, not about insufficient privileges; if root were needed, the error would typically be 'Permission denied' or a different system call failure. Option D is wrong because the error message explicitly shows '/bin/sh' is being used, and the shebang '#!/bin/sh' would not change the fact that the command is not found; the issue is PATH, not the shell interpreter.

356
MCQhard

A large e-commerce platform runs on a database server that uses LVM thin provisioning. The thin pool is overcommitted at 200% (pool size 1TB, thin volumes total 2TB). Suddenly, the database reports write errors and performance degrades drastically. The administrator checks the system and finds that the thin pool is completely full. What is the immediate effect on the thin volumes, and what should the administrator do to restore normal operation without data loss?

A.The volumes continue to operate but with severe slowdown; administrator must delete unnecessary snapshots.
B.The volumes become corrupted; administrator must restore from backup.
C.The volumes become read-only; administrator must add more physical storage to the volume group and extend the thin pool.
D.The volumes automatically extend the pool using metadata space; no action needed.
AnswerC

When a thin pool is exhausted, the kernel queues further writes and returns errors, effectively freezing thin volumes until space is reclaimed. Extending the pool with additional physical extents from the volume group restores write capability immediately, preserving existing data because thin volumes themselves remain intact.

Why this answer

When an LVM thin pool is completely full, the kernel cannot allocate new blocks for any thin volume, so all thin volumes in that pool are automatically switched to read-only mode to prevent data corruption. The immediate fix is to add physical storage to the volume group (e.g., vgextend) and then extend the thin pool (lvextend) so that new blocks can be allocated. This restores write capability without data loss because the volumes were never corrupted—they were simply protected by the read-only state.

Exam trap

LFCS often tests the misconception that thin pools can be overcommitted indefinitely without consequences, or that volumes become corrupted rather than read-only when the pool fills.

How to eliminate wrong answers

Option A is wrong because thin volumes do not continue to operate with severe slowdown when the pool is full; they become read-only, and deleting snapshots may free space but is not the immediate action to restore write capability. Option B is wrong because the volumes are not corrupted; LVM thin provisioning sets them read-only to prevent corruption, so a backup restore is unnecessary. Option D is wrong because metadata space is not used to automatically extend the pool; metadata is separate and does not provide data blocks, and no automatic extension occurs.

357
MCQmedium

A system administrator needs to create a shared group 'projectx' and add existing users 'bob' and 'carol' to it. The users need to collaborate on files in a directory /projectx. What is the correct sequence of commands to set up the group and ensure new files created in /projectx are automatically owned by the group 'projectx'?

A.groupadd projectx; usermod -G projectx bob carol; chmod 2770 /projectx
B.addgroup projectx; adduser bob projectx; adduser carol projectx; chmod u+s /projectx
C.groupadd projectx; usermod -aG projectx bob; usermod -aG projectx carol; chmod g+s /projectx
D.groupadd projectx; usermod -G projectx bob; usermod -G projectx carol; chmod g+s /projectx
AnswerC

groupadd creates the group, usermod -aG appends bob and carol as supplementary members without disturbing their primary groups, and chmod g+s sets the setgid bit on /projectx so new files inherit the projectx group rather than each creator's primary group.

Why this answer

It uses `groupadd` to create the group, `usermod -aG` to append users to the group without removing them from other groups, and `chmod g+s` to set the setgid bit on the directory. The setgid bit ensures that new files created in /projectx inherit the group ownership of the directory (projectx), enabling collaboration.

Exam trap

The trap here is that `usermod -G` without `-a` overwrites the user's supplementary groups, and candidates often forget the `-a` flag, leading to accidental removal of existing group memberships.

How to eliminate wrong answers

Option A is wrong because `usermod -G` without `-a` replaces the user's supplementary group list, removing any existing supplementary groups, which can cause loss of access. Option B is wrong because `adduser` and `addgroup` are distribution-specific (Debian/Ubuntu) and not standard on all Linux systems; also `chmod u+s` sets the setuid bit (affects user ownership, not group), which does not enforce group ownership inheritance. Option D is wrong because `usermod -G` without `-a` overwrites the user's supplementary groups, potentially removing them from other groups they need.

358
MCQhard

After deleting user 'alice', the system administrator wants to also remove the home directory and mail spool. Which command should be used?

A.userdel -Z alice
B.userdel -r alice
C.userdel -f alice
D.userdel --remove alice
AnswerB

`userdel -r alice` removes the account plus its home directory and mail spool in one pass, satisfying the stem's requirement to clear both artefacts after deletion. The `-r` flag triggers that cleanup; plain `userdel` leaves `/home/alice` and `/var/mail/alice` intact.

Why this answer

The correct option is B, userdel -r alice. The -r flag removes the user's home directory and mail spool, along with the user account. This is the standard flag for removing user data along with the account.

359
Matchingmedium

Match each Linux boot component to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Boot loader that loads the kernel

Initial RAM filesystem used before root is mounted

Init system and service manager

Core of the operating system

Program that loads the OS into memory

Why these pairings

The correct matches are: BIOS/UEFI initializes hardware and loads the bootloader; Initramfs is the temporary root filesystem; Systemd is the init system. Common confusions occur between kernel and bootloader roles.

360
MCQhard

Given the network interface configuration in the exhibit, which command should be run to apply the configuration without rebooting?

A.systemctl restart network
B.ifup eth0
C.ifconfig eth0 down && ifconfig eth0 up
D.ip link set eth0 up
AnswerB

Brings up the interface with the configuration in ifcfg-eth0.

Why this answer

The `ifup eth0` command reads the configuration file for the eth0 interface (typically `/etc/sysconfig/network-scripts/ifcfg-eth0` on RHEL/CentOS) and applies the settings (IP address, netmask, gateway, etc.) without requiring a system reboot. This is the standard way to activate a network interface with its configured parameters on Linux systems using the legacy network scripts.

Exam trap

The trap here is that candidates confuse bringing an interface up with applying its configuration, assuming that `ip link set eth0 up` or toggling `ifconfig` will also restore IP settings, when in fact those commands only affect the link state and do not read the persistent configuration file.

How to eliminate wrong answers

Option A is wrong because `systemctl restart network` restarts the entire network service, which can disrupt all active connections and is unnecessary for applying a single interface's configuration; it also may not be available on systems using NetworkManager. Option C is wrong because `ifconfig eth0 down && ifconfig eth0 up` only toggles the interface link state without reading the configuration file, so it will not apply any new settings (e.g., a changed IP address) and may leave the interface with stale parameters. Option D is wrong because `ip link set eth0 up` only brings the interface administratively up at Layer 2, but does not assign any IP address or apply Layer 3 configuration from the interface's config file.

361
MCQeasy

A junior administrator needs to mount the XFS filesystem on /dev/sdb1 at /srv/files for the current session only, without creating a persistent entry. Which command accomplishes this?

A.systemctl start srv-files.mount
B.mount -t xfs /dev/sdb1 /srv/files
C.mount /dev/sdb1 /srv/files >> /etc/fstab
D.mkfs.xfs /dev/sdb1 /srv/files
AnswerB

mount attaches the filesystem on /dev/sdb1 at the /srv/files directory for the running session, and -t xfs explicitly selects the XFS driver. Because no entry is added to /etc/fstab, the mount disappears after reboot, matching the 'current session only' requirement. The mount point must already exist as a directory.

Why this answer

A one-off mount for the current session is performed with the mount command, specifying the device, the existing mount point, and optionally the filesystem type via -t. No fstab entry is created, so the mount does not survive a reboot. Formatting tools, shell redirection into fstab, and starting nonexistent systemd units do not mount a filesystem for the current session.

Exam trap

The trap here is mixing up mounting a filesystem with persistently configuring it in /etc/fstab or a systemd mount unit.

362
MCQmedium

A Linux server uses NetworkManager and has a wired connection profile named 'Wired connection 1'. The administrator needs to set a static IPv4 address 10.20.30.40/24 with gateway 10.20.30.1, and ensure the change persists across reboots. Which sequence of commands accomplishes this?

A.nmcli dev modify eth0 ipv4.addresses 10.20.30.40/24 ipv4.gateway 10.20.30.1 ipv4.method manual
B.nmcli con mod 'Wired connection 1' ipv4.addresses 10.20.30.40/24 ipv4.gateway 10.20.30.1 ipv4.method manual && nmcli con up 'Wired connection 1'
C.ip addr add 10.20.30.40/24 dev eth0 && ip route add default via 10.20.30.1
D.nmcli con add type ethernet con-name 'Wired connection 1' ifname eth0 ip4 10.20.30.40/24 gw4 10.20.30.1
AnswerB

This is correct because 'nmcli con mod' modifies the persistent connection profile, setting the static address, gateway, and method to manual, and 'nmcli con up' reactivates the profile to apply the changes immediately. NetworkManager stores the configuration in its connection files, so the settings survive reboots.

Why this answer

The correct approach uses 'nmcli con mod' to alter the existing connection profile's IPv4 settings and set the method to manual, then brings the connection up to apply the changes. This persists the static address and gateway in NetworkManager's configuration, satisfying the reboot requirement. Lower-level ip commands are temporary and do not modify profiles, while creating a duplicate profile or using an invalid command would not achieve the goal.

Exam trap

The trap here is assuming that ip addr and ip route commands persist across reboots or that 'nmcli dev modify' is a valid way to change persistent settings.

363
MCQmedium

A system administrator needs to ensure that the /dev/sdb1 filesystem is automatically mounted at /data with the noatime option at boot. The filesystem's UUID is known. Which entry in /etc/fstab is correct?

A.UUID=1234-5678 /data ext4 defaults,noatime 0 2
B.UUID=1234-5678 /data ext4 noatime 0 2
C./dev/sdb1 /data ext4 defaults,noatime 0 1
D.UUID=1234-5678 /data ext4 defaults,noatime 1 2
AnswerA

This entry uses the UUID to identify the filesystem, specifies the mount point /data, the filesystem type ext4, and includes the noatime option along with defaults. The dump field is 0 and the pass field is 2, which is appropriate for a non-root filesystem. This ensures the filesystem is mounted at boot with the desired option.

Why this answer

The correct /etc/fstab entry must use the UUID for stable identification, specify the mount point, filesystem type, include defaults and noatime in the options, and set the dump and pass fields appropriately (0 and 2 for a non-root filesystem). The entry with UUID, defaults,noatime, 0, and 2 meets all these criteria.

Exam trap

The trap here is forgetting to include defaults alongside noatime, or using the wrong pass number (1 instead of 2) for a non-root filesystem, which can cause boot issues.

364
MCQmedium

A server's root filesystem is filling up. An administrator needs to find the largest regular files under /var, sorted from largest to smallest, while avoiding errors from unreadable directories that are not owned by the administrator. Which command is most appropriate?

A.find /var -type f -printf '%s %p\n' 2>/dev/null | sort -rn | head -n 20
B.find /var -type d -exec du -sh {} + | sort -rh
C.du -ah /var | sort -rh | head -n 20
D.ls -lR /var | sort -k5 -n | tail -n 20
AnswerA

find with -type f restricts results to regular files, -printf outputs size in bytes followed by the path, and redirecting stderr suppresses permission errors from unreadable directories. Piping to sort -rn and head yields the largest files first, exactly matching the scenario's requirements.

Why this answer

The precise approach is to use find restricted to regular files, print size and path, discard error output, then sort numerically in reverse and take the top entries. This avoids directory totals and unreadable-path noise. Recursive ls parsing is unreliable, du shows directory aggregates, and searching only directories answers a different question.

Exam trap

The trap here is using du, which reports directory totals, when the task specifically asks for individual regular files.

365
MCQeasy

An administrator wants to see the disk usage of the /var directory in a human-readable format. Which command should be used?

A.du -sh /var
B.df -h /var
C.fdisk -l /var
D.ls -lh /var
AnswerA

The -s flag summarises /var into a single total, while -h renders sizes in human-readable units such as K, M and G. Together they satisfy the stem's requirement for human-readable disk usage of that directory.

Why this answer

The `du -sh /var` command is correct because `du` (disk usage) estimates file and directory space usage, and the `-s` flag summarizes the total for `/var` while `-h` provides human-readable output (e.g., KiB, MiB, GiB). This directly shows the disk space consumed by the `/var` directory and its contents.

Exam trap

The trap here is confusing `du` (directory usage) with `df` (filesystem usage), leading candidates to pick `df -h /var` because it shows space in human-readable format, but it does not measure the directory's own consumption.

How to eliminate wrong answers

Option B is wrong because `df -h /var` shows the free and used space on the filesystem where `/var` is mounted, not the disk usage of the `/var` directory itself. Option C is wrong because `fdisk -l /var` is invalid; `fdisk` operates on block devices (e.g., `/dev/sda`), not directories, and will produce an error. Option D is wrong because `ls -lh /var` lists the contents of `/var` with file sizes, but does not aggregate or summarize the total disk usage of the directory tree.

366
Multi-Selecthard

An administrator is troubleshooting DNS resolution and wants to query the SOA record for a domain. Which three commands can be used? (Choose three.)

Select 3 answers
A.nslookup -type=soa example.com
B.host -t SOA example.com
C.dig example.com SOA
D.nmcli dev show
E.getent hosts example.com
AnswersA, B, C

nslookup can query SOA records.

Why this answer

The `nslookup -type=soa` command queries the DNS for the Start of Authority (SOA) record of a domain. The `-type=soa` flag explicitly sets the query type to SOA, which returns authoritative information about the zone, including the primary name server and administrator email.

Exam trap

The trap here is that candidates may confuse `getent hosts` with DNS lookup tools, not realizing it bypasses DNS resolution and only checks local name resolution sources.

367
MCQmedium

A server has two NICs bonded in mode 1 (active-backup). If the active NIC fails, what occurs?

A.Both NICs continue to pass traffic simultaneously
B.Traffic automatically switches to the backup NIC with minimal interruption
C.The bond interface goes down until an administrator intervenes
D.The system disables the bond and uses a single NIC
AnswerB

Mode 1 active-backup bonding keeps the backup NIC passive until the active link fails. Failover detection then moves the MAC and traffic to the backup interface, maintaining connectivity with only brief interruption, satisfying the redundancy requirement.

Why this answer

In bonding mode 1 (active-backup), only one NIC is active at a time while the other remains in standby. When the active NIC fails, the bonding driver automatically fails over to the backup NIC by reassigning the MAC address and IP to the backup interface, typically within a few milliseconds. This ensures minimal interruption to network traffic without requiring manual intervention.

Exam trap

The trap here is that candidates often confuse active-backup (mode 1) with balance-rr (mode 0) or assume that both NICs must be active for redundancy, leading them to incorrectly select Option A.

How to eliminate wrong answers

Option A is wrong because in active-backup mode, only one NIC passes traffic at any given time; both NICs never pass traffic simultaneously. Option C is wrong because the bond interface does not go down; the failover is automatic and does not require administrator intervention. Option D is wrong because the bond interface remains operational and continues to use the backup NIC; the system does not disable the bond or revert to a single un-bonded NIC.

368
MCQeasy

An administrator needs to configure a service to run as a non-root user for security reasons. Which systemd unit file directive accomplishes this?

A.AmbientCapabilities=CAP_NET_BIND_SERVICE
B.DynamicUser=yes
C.User=myuser
D.Group=myuser
AnswerC

`User=` drops privileges to the named account before the service's main process starts, satisfying the stem's non-root requirement. systemd performs the setuid itself, so no shell wrapper or `su` is needed. Pair it with `Group=` for full control over the process credentials.

Why this answer

The `User=` directive in a systemd unit file specifies the user (by name or UID) under which the service process runs. By setting `User=myuser`, the service executes with the privileges of that non-root user, reducing the attack surface and adhering to the principle of least privilege. This is the standard systemd mechanism for dropping root privileges for a service.

Exam trap

The trap here is that candidates often confuse `User=` with `Group=` or assume that `DynamicUser=yes` is the only way to run as a non-root user, missing that `User=` directly specifies a static, named user account.

How to eliminate wrong answers

Option A is wrong because `AmbientCapabilities=CAP_NET_BIND_SERVICE` grants a specific capability (binding to privileged ports below 1024) to the service, but it does not change the user context; the service would still run as root unless a `User=` directive is also used. Option B is wrong because `DynamicUser=yes` creates a transient, ephemeral user and group for the service, but it does not allow you to specify a particular non-root user like 'myuser'; it is intended for services that need isolated, temporary credentials. Option D is wrong because `Group=myuser` sets the group ID for the service but does not change the user; the service would still run as root (or whatever user is set by `User=`) unless `User=` is also specified.

369
MCQeasy

A junior administrator has a USB flash drive at /dev/sdb that will be used exclusively as a data disk on a Linux server. They need to create an XFS filesystem on the whole device (no partitions). Which command accomplishes this?

A.xfs_growfs /dev/sdb
B.mkfs -t xfs -c /dev/sdb
C.xfs_repair /dev/sdb
D.mkfs.xfs /dev/sdb
AnswerD

mkfs.xfs is the correct tool to create an XFS filesystem, and it accepts a whole block device such as /dev/sdb as its target. XFS supports being created directly on an unpartitioned device, which is valid for dedicated data disks. This command writes the XFS superblock and metadata to /dev/sdb, making it immediately mountable.

Why this answer

Creating an XFS filesystem on a whole block device is done with the mkfs.xfs command followed by the device path. XFS is commonly used for data volumes and supports being placed directly on an unpartitioned disk. The other commands either grow or repair an existing XFS filesystem and cannot initialize a new one.

Exam trap

The trap here is assuming that a filesystem must always be created on a partition rather than directly on a whole block device.

370
MCQmedium

A Linux server has a single network interface ens3. You need to assign the static address 10.10.10.5/24 with gateway 10.10.10.1 using NetworkManager. The connection profile is named 'static-ens3'. Which command correctly applies the IPv4 address, disables DHCP, and sets the gateway, all in one step?

A.nmcli con mod static-ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method manual
B.nmcli con mod static-ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method auto
C.nmcli con up static-ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method manual
D.nmcli con add type ethernet ifname ens3 ipv4.addresses 10.10.10.5/24 ipv4.gateway 10.10.10.1 ipv4.method manual
AnswerA

This nmcli command modifies the existing connection profile named static-ens3, setting the IPv4 address, gateway, and switching the method to manual. It is the correct and idiomatic way to configure a static address with NetworkManager. After this command, you would need to bring the connection up (or reactivate it) for the changes to take effect.

Why this answer

The correct command uses 'nmcli con mod' to modify the existing connection profile named static-ens3. It sets the IPv4 address, gateway, and changes the method to manual, which disables DHCP. This is the standard way to apply a static configuration with NetworkManager.

After modification, the connection must be reactivated for the changes to take effect.

Exam trap

The trap here is confusing 'nmcli con mod' (modify existing profile) with 'nmcli con add' (create new profile) or 'nmcli con up' (activate profile), and forgetting that 'ipv4.method manual' is required to disable DHCP.

371
MCQeasy

A junior administrator must temporarily assign the address 172.16.5.20/24 to interface eth1 on a running server so that a migration can be tested, and the change must not survive a reboot. Which command accomplishes this?

A.ip addr add 172.16.5.20/24 dev eth1
B.ip link set eth1 up && ip route add 172.16.5.20/24 dev eth1
C.ifconfig eth1 172.16.5.20 netmask 255.255.255.0
D.nmcli con mod eth1 ipv4.addresses 172.16.5.20/24 && nmcli con up eth1
AnswerA

The ip addr add command assigns the address to the interface immediately in the running kernel. Because it only modifies runtime state and does not write any configuration file, the address disappears on reboot, which matches the requirement for a temporary change during migration testing.

Why this answer

Temporary address changes are made directly in the kernel with the iproute2 ip addr add command. This affects the running system only and is lost on reboot, which is exactly what the migration test requires. Persistent configuration tools such as NetworkManager profiles or network configuration files would write the change to disk and reapply it at boot.

Exam trap

The trap here is choosing a NetworkManager or configuration-file method, which makes the address persistent and therefore violates the explicit requirement that the change not survive a reboot.

372
MCQmedium

Existing user 'jdoe' is a member of groups 'users' (primary) and 'staff'. The administrator needs to add 'jdoe' to group 'projectx' while preserving existing supplementary group memberships. Which command achieves this?

A.usermod -g projectx -G projectx jdoe
B.usermod -g projectx jdoe
C.usermod -G projectx jdoe
D.usermod -a -G projectx jdoe
AnswerD

The -a flag appends projectx to jdoe's supplementary group list, while -G specifies the group. Omitting -a would overwrite the existing supplementary membership, dropping staff. This preserves users and staff while adding projectx, exactly as the stem requires.

Why this answer

The `-a` (append) flag combined with `-G` (supplementary groups) adds the user to the specified group without removing existing supplementary group memberships. Without `-a`, the `-G` flag replaces all supplementary groups with the listed ones, which would remove the 'staff' group membership.

Exam trap

The trap here is that candidates forget the `-a` flag is required with `-G` to append groups, assuming `-G` alone adds groups instead of replacing them.

How to eliminate wrong answers

Option A is wrong because it sets the primary group to 'projectx' with `-g` and also sets supplementary groups to only 'projectx' with `-G`, which would remove 'staff' and change the primary group from 'users'. Option B is wrong because `-g` changes only the primary group to 'projectx', leaving supplementary groups unchanged but incorrectly altering the primary group. Option C is wrong because `-G projectx` without `-a` replaces all supplementary group memberships with only 'projectx', removing 'staff'.

373
Multi-Selecthard

A Linux server is configured as a router with IP forwarding enabled. It has two interfaces: eth0 (203.0.113.5/24) and eth1 (192.168.1.1/24). Clients on 192.168.1.0/24 need to reach the internet via eth0. The administrator has set up NAT using iptables with the rule: iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE. However, clients cannot access external websites. Which two actions should the administrator take to resolve the issue? (Choose two.)

Select 2 answers
A.Add a SNAT rule instead of MASQUERADE for better performance.
B.Disable the firewall on the clients to allow outbound connections.
C.Verify that IP forwarding is enabled by checking the value of net.ipv4.ip_forward.
D.Ensure that the FORWARD chain policy is ACCEPT or add rules to allow forwarding from eth1 to eth0.
E.Configure a default route on the router pointing to the ISP gateway.
AnswersC, D

NAT alone does not enable routing. The kernel must have IP forwarding enabled, typically via sysctl net.ipv4.ip_forward=1. If this is disabled, packets from the internal network will not be forwarded to the external interface, causing the connectivity failure described.

Why this answer

For a Linux router to forward traffic between interfaces, IP forwarding must be enabled, and the FORWARD chain must permit the traffic. Even with MASQUERADE configured, if either condition is not met, packets will be dropped. The administrator should verify net.ipv4.ip_forward and ensure FORWARD rules allow traffic from the internal to external interface.

Exam trap

The trap here is focusing solely on NAT configuration while overlooking the need for IP forwarding and FORWARD chain rules.

374
MCQmedium

An administrator is troubleshooting a server with a software RAID 1 array on /dev/md0. One disk, /dev/sdc, has failed and been replaced. The administrator runs `mdadm /dev/md0 --add /dev/sdc1` and sees the array rebuilding, but after a reboot the new disk is no longer part of the array. Which action should the administrator take to ensure the replacement disk is automatically reassembled into the array at boot?

A.Add an entry for /dev/sdc1 to /etc/fstab with the `nofail` option.
B.Run `mdadm --grow /dev/md0 --raid-devices=2` to force the array to accept the new disk.
C.Run `mdadm --assemble --scan` and rely on the kernel to remember the array across reboots.
D.Run `mdadm --detail --scan >> /etc/mdadm.conf` and update the initramfs.
AnswerD

The mdadm.conf file tells the initramfs and mdadm which arrays to assemble at boot. Appending the current scan output records the new array UUID and device list, and updating the initramfs embeds that configuration so the array is reassembled with the replacement disk after a reboot.

Why this answer

Software RAID arrays are reassembled at boot from configuration stored in /etc/mdadm.conf and embedded in the initramfs. After adding a replacement disk, the administrator must regenerate that configuration and rebuild the initramfs so the new member is recognized. Growing the array, adding the component to fstab, or relying on a manual assemble command does not provide persistent boot-time assembly.

Exam trap

The trap here is assuming that adding a disk to a running array automatically updates the boot-time assembly configuration.

375
MCQhard

An administrator is troubleshooting a server where the root filesystem is on an LVM logical volume. The system fails to boot and drops to an initramfs prompt with the error 'Volume group "vg_root" not found'. The administrator verifies that the physical volumes are present and the volume group exists when booting from a rescue disk. Which action is most likely to resolve the boot issue?

A.Edit /etc/lvm/lvm.conf to set the 'locking_type' to 0 and rebuild the initramfs.
B.Run vgchange -ay vg_root from the initramfs prompt and then continue booting.
C.Recreate the initramfs with the appropriate LVM configuration and modules included.
D.Add the volume group to /etc/fstab with the 'noauto' option to prevent automatic activation.
AnswerC

The error indicates that the initramfs cannot find the volume group, likely because the LVM configuration or modules are missing from the initramfs. Rebuilding the initramfs with the correct LVM support, such as using dracut or update-initramfs, will ensure that the volume group is activated during early boot. This resolves the root cause permanently.

Why this answer

The error indicates that the initramfs is not activating the volume group during early boot. This usually happens when the initramfs was built without the necessary LVM modules or configuration, or after a kernel update that did not include LVM support. Rebuilding the initramfs with the correct LVM configuration ensures the volume group is found and activated, allowing the system to boot.

Exam trap

The trap here is thinking that manually activating the volume group from the initramfs prompt is a permanent fix, when it only temporarily bypasses the real issue of missing LVM support in the initramfs.

Page 4

Page 5 of 6

Page 6

All pages