Courseiva

Linux Foundation Certified System Administrator LFCS (LFCS) — Questions 376–406

406 questions total · 6pages · All types, answers revealed

Page 5

Page 6 of 6

376
Multi-Selecthard

An administrator manages a server with several iSCSI LUNs attached. The server reboots after a kernel update, and one of the LUNs, which previously appeared as /dev/sdc, is now enumerated as /dev/sdd, breaking an /etc/fstab entry that references /dev/sdc. The administrator wants to make the mount configuration resilient to device-name changes and to avoid boot delays if the LUN is temporarily missing. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Add the nofail mount option to the /etc/fstab entry for that filesystem.
B.Add the _netdev mount option to the /etc/fstab entry and rely on the device name /dev/sdc.
C.Replace the /dev/sdc reference in /etc/fstab with a persistent identifier such as /dev/disk/by-uuid/<uuid> or /dev/disk/by-path/<path>.
D.Change the mount point to use the device-mapper path /dev/mapper/sdc1 instead of /dev/sdc.
E.Create a udev rule that renames the LUN to /dev/sdc every time it is detected.
AnswersA, C

The nofail option tells systemd and mount to treat a missing device as a non-fatal condition during boot. Without it, a temporarily absent iSCSI LUN can drop the system into emergency mode or cause long timeouts. With nofail, the boot continues and the mount is simply skipped, which is the desired behavior for storage that may not always be present at boot time. It is commonly paired with persistent identifiers.

Why this answer

Persistent identifiers such as UUIDs or by-path symlinks decouple the mount configuration from the kernel's enumeration order, and nofail prevents a temporarily missing iSCSI LUN from delaying or blocking boot. Together they make the fstab entry resilient to device renumbering. Changing to a device-mapper path, adding _netdev, or forcing a udev rename do not address enumeration stability and can introduce new problems.

Exam trap

The trap here is believing that a udev rename or a device-mapper path provides stable naming, when the supported and reliable approach is to use the existing by-uuid or by-path symlinks plus nofail.

377
Multi-Selectmedium

Which THREE commands can be used to view the contents of a file?

Select 3 answers
A.grep
B.find
C.cat
D.head
E.less
AnswersC, D, E

Concatenates and displays file contents.

Why this answer

The `cat` command (option C) is a standard Unix utility that reads files sequentially and outputs their contents to the standard output. It is one of the most basic and direct ways to view the entire content of a file in the terminal.

Exam trap

The trap here is that candidates may confuse `grep` (which can display matching lines) with a file-viewing command, or think `find` can show file contents because it locates files, but neither is designed for that purpose.

378
Multi-Selecthard

Which THREE files are directly related to user and group management in a Linux system? (Select three.)

Select 3 answers
A./etc/sudoers
B./etc/login.defs
C./etc/group
D./etc/passwd
E./etc/shadow
AnswersC, D, E

/etc/group stores group names, GIDs and membership lists, forming the core database consulted by group management tools. It is directly related to user and group management, unlike unrelated system files such as /etc/fstab or /etc/hosts.

Why this answer

The three files directly related to user and group management are /etc/group (C), /etc/passwd (D), and /etc/shadow (E). /etc/passwd stores user account entries with UID, GID, home directory, and login shell, making it a core user-management file. /etc/group defines group names, GIDs, and group membership lists, so it is essential for group management. /etc/shadow stores encrypted password hashes and password-aging fields for local users, which is a fundamental part of user account administration. /etc/sudoers (A) controls sudo privilege delegation, and /etc/login.defs (B) sets defaults for login and user-creation tools; both are related to authentication or account policy, but they are not the primary user/group database files.

Exam trap

The trap here is that candidates may confuse configuration files like /etc/sudoers or /etc/login.defs with the actual user/group database files, but the question specifically asks for files 'directly related to user and group management'—meaning the files that store the user and group records themselves, not files that configure how those records are created or used.

379
MCQeasy

A system administrator needs to find all files in /var/log that have been modified in the last 7 days. Which command accomplishes this?

A.find /var/log -type f -atime -7
B.find /var/log -type f -ctime -7
C.find /var/log -type f -mtime +7
D.find /var/log -type f -mtime -7
AnswerD

Correct: -mtime -7 means modified less than 7 days ago.

Why this answer

The `find` command with `-mtime -7` searches for files whose modification time (content change) is less than 7 days ago, which matches the requirement of 'modified in the last 7 days'. The `-type f` restricts the search to regular files, and `/var/log` is the target directory.

Exam trap

The trap here is confusing `-mtime` (modification time) with `-ctime` (inode change time) or `-atime` (access time), as candidates often mistakenly think 'changed' refers to content modification rather than metadata changes.

How to eliminate wrong answers

Option A is wrong because `-atime -7` searches for files accessed (read) in the last 7 days, not modified; this tests access time, not content change. Option B is wrong because `-ctime -7` searches for files whose metadata (inode change) was modified in the last 7 days, such as permissions or ownership changes, not file content modification. Option C is wrong because `-mtime +7` finds files modified more than 7 days ago (older than 7 days), which is the opposite of the requirement.

380
Matchingmedium

Match each systemd unit type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manages a daemon or service

Interprocess communication socket

Schedules and activates other units

Controls mount points

Groups units for synchronization

Why these pairings

Correct matches: service manages processes, socket handles socket activation, timer schedules events, target groups units. Common confusion: mixing socket and timer responsibilities is typical.

381
MCQeasy

A system administrator notices that '/var/log/syslog' has grown very large and is consuming significant disk space. The administrator wants to identify the largest log files in the '/var/log' directory hierarchy. Which command should the administrator use?

A.find /var/log -size +100M -exec ls -lh {} \;
B.du -ah /var/log | sort -hr | head -10
C.df -h /var/log
D.ls -lhS /var/log
AnswerB

`du -ah` reports apparent sizes for every file and directory under /var/log, then `sort -hr` orders them largest-first by human-readable size and `head -10` shows the top ten. This directly satisfies the goal of identifying the largest log files within the hierarchy.

Why this answer

`du -ah /var/log` calculates the disk usage of all files and directories in `/var/log` in human-readable format, then `sort -hr` sorts them by size in descending order, and `head -10` shows the top 10 largest entries. This directly identifies the largest log files in the hierarchy, which is exactly what the administrator needs.

Exam trap

The trap here is that candidates often choose `ls -lhS /var/log` (option D) because it sorts by size, but they overlook that it does not recurse into subdirectories, missing large files in subfolders like `/var/log/apache2/` or `/var/log/journal/`.

How to eliminate wrong answers

Option A is wrong because `find /var/log -size +100M` only finds files larger than 100 MB, missing any large files under that threshold, and it does not sort or limit results, so it may not show the largest files overall. Option C is wrong because `df -h /var/log` shows the total disk usage and available space of the filesystem containing `/var/log`, not the sizes of individual files or directories. Option D is wrong because `ls -lhS /var/log` lists only the immediate contents of `/var/log` sorted by size, but it does not recurse into subdirectories, so it misses large files deeper in the hierarchy.

382
MCQmedium

A system administrator is troubleshooting a production web server running CentOS 7 that became unresponsive. The server is still pingable, but SSH connections timeout. The admin performs an out-of-band console login. The server appears frozen; typing commands shows no output. The admin is able to trigger a Magic SysRq key sequence (Alt+SysRq+f) to kill the hung processes. After that, the server resumes normal operation. However, the admin wants to understand the root cause. Upon checking 'dmesg', they see repeated messages: 'NMI watchdog: BUG: soft lockup - CPU#0 stuck for 22s!' followed by stack traces from a kernel thread. Which action should the admin take to prevent recurrence while maintaining system stability?

A.Replace the power supply unit to ensure stable power.
B.Increase the soft lockup threshold via sysctl to reduce false positives.
C.Add 'nosoftlockup' to the kernel boot parameters.
D.Update the server's BIOS/firmware and check for kernel updates.
AnswerD

Soft lockups in kernel threads typically stem from firmware bugs or kernel defects rather than user processes, so the Magic SysRq kill only masks symptoms. Updating BIOS/firmware and applying kernel updates addresses the underlying CPU or scheduler defect that caused the 22-second stall, preventing recurrence.

Why this answer

Soft lockup errors on CentOS 7 often indicate kernel bugs or hardware/firmware issues that cause CPUs to stall for extended periods. Updating the BIOS/firmware can resolve underlying hardware timing problems, while kernel updates may include patches for known soft lockup bugs. This approach addresses the root cause without disabling or weakening the watchdog mechanism, preserving system stability.

Exam trap

The trap here is that candidates may think soft lockup errors are false positives or can be safely ignored by increasing thresholds or disabling the watchdog, when in fact they indicate a genuine kernel or hardware issue that requires a proper fix.

How to eliminate wrong answers

Option A is wrong because a failing power supply typically causes random crashes or power-offs, not soft lockup errors in a single CPU core with a stuck kernel thread. Option B is wrong because increasing the soft lockup threshold merely masks the symptom by allowing longer stalls before detection, which can lead to worse system degradation and does not fix the underlying cause. Option C is wrong because adding 'nosoftlockup' disables the NMI watchdog entirely, removing the ability to detect and recover from soft lockups, which compromises system stability and is not a proper fix.

383
MCQeasy

A junior administrator needs to identify the filesystem type of the device /dev/nvme0n1p2 on a running Linux server without mounting it or modifying any metadata. Which command should be used?

A.blkid /dev/nvme0n1p2
B.lsblk -f
C.mount /dev/nvme0n1p2 /mnt
D.fdisk -l /dev/nvme0n1p2
AnswerA

blkid probes the device for filesystem signatures and prints attributes such as TYPE and UUID. It reads the superblock directly and does not mount the filesystem or change anything on disk. This makes it the appropriate, low-risk tool for identifying whether /dev/nvme0n1p2 holds XFS, ext4, swap, or another filesystem, which is precisely what the administrator needs in this situation.

Why this answer

blkid reads filesystem superblocks and reports the type without mounting or altering the device, making it the safest and most direct way to identify the filesystem on /dev/nvme0n1p2. fdisk shows partition-table type codes rather than real filesystem metadata, mounting is unnecessarily invasive, and lsblk -f is a broader listing that is less targeted for a single-device query.

Exam trap

The trap here is confusing the partition-table type code shown by fdisk with the actual filesystem type, which only a superblock probe such as blkid can confirm.

384
Multi-Selecteasy

Which TWO commands can be used to resolve a hostname to an IP address?

Select 2 answers
A.host
B.traceroute
C.ping
D.nslookup
E.ifconfig
AnswersA, D

This is a DNS lookup utility.

Why this answer

The `host` command is a simple DNS lookup utility that queries DNS servers to resolve a hostname to an IP address. It directly performs forward DNS resolution using the system's configured resolvers and returns the A or AAAA record for the given name.

Exam trap

The trap here is that candidates often think `ping` is a valid name resolution tool because it can accept a hostname and display the resolved IP in its output, but `ping` relies on the system resolver and does not perform its own DNS query—it only displays the IP after the system has already resolved it, making it a connectivity test, not a resolution command.

385
MCQmedium

A support engineer must copy the file /etc/hosts to /tmp/hosts.backup but only if /tmp/hosts.backup does not already exist, so that an existing backup is never overwritten. Which command performs this conditionally?

A.cp --no-clobber /etc/hosts /tmp/hosts.backup
B.cp --update /etc/hosts /tmp/hosts.backup
C.cp --backup /etc/hosts /tmp/hosts.backup
D.cp --preserve=all /etc/hosts /tmp/hosts.backup
AnswerA

The --no-clobber option instructs cp not to overwrite an existing destination file. If /tmp/hosts.backup is already present, cp skips the copy and exits without replacing it, preserving the old backup. If the destination is absent, the file is copied normally. This precisely implements the required conditional copy and avoids destroying any existing backup content.

Why this answer

The --no-clobber option makes cp skip the operation entirely when the destination already exists, leaving the existing backup intact while still performing the copy when the destination is absent. The other options either ignore existence altogether, base the decision on timestamps, or rename the old file, all of which still result in the destination being replaced.

Exam trap

The trap here is confusing --update with --no-clobber; --update compares timestamps and can still overwrite a backup, whereas --no-clobber keys purely on whether the destination already exists.

386
MCQmedium

A Linux administrator is configuring a systemd service unit for a custom application. The application requires that the /opt/app/data directory exists and is writable before the service starts. The administrator wants to ensure this directory is created automatically if it does not exist. Which systemd directive should be added to the [Service] section to achieve this?

A.ExecStartPre=/bin/mkdir -p /opt/app/data
B.StateDirectory=app/data
C.RuntimeDirectory=app/data
D.WorkingDirectory=/opt/app/data
AnswerA

ExecStartPre specifies a command to run before the main ExecStart command. Using /bin/mkdir -p /opt/app/data ensures the directory exists and creates parent directories as needed. This is a flexible and direct way to meet the requirement, as it can create any path and set permissions if needed. It is the correct approach for this scenario.

Why this answer

The ExecStartPre directive allows running a command before the main service starts. Using /bin/mkdir -p /opt/app/data will create the directory and any missing parent directories, ensuring it exists before the application starts. Other directives like StateDirectory and RuntimeDirectory only manage directories in specific system locations (/var/lib and /run, respectively).

WorkingDirectory merely sets the working directory but does not create it. Thus, ExecStartPre is the correct solution for creating a custom directory under /opt.

Exam trap

The trap here is assuming that StateDirectory or RuntimeDirectory can create arbitrary directories, when they are restricted to /var/lib and /run respectively.

387
MCQeasy

A junior administrator needs to add user 'mchen' to the supplementary group 'developers' without removing existing group memberships. Which command should be used?

A.usermod -aG developers mchen
B.usermod -G developers mchen
C.groupmod -a -U mchen developers
D.gpasswd -a mchen developers
AnswerA

The -aG option appends the specified group to the user's supplementary group list. Without -a, usermod -G would replace all existing supplementary groups. This command preserves current memberships and adds 'developers', which is exactly what is needed.

Why this answer

To add a user to a supplementary group while preserving existing memberships, use usermod with the -a (append) and -G (supplementary groups) options. Without -a, the -G option replaces all supplementary groups. This command safely adds the new group without affecting others, ensuring the user retains all necessary access.

Exam trap

The trap here is forgetting the -a flag, which leads to replacing all supplementary groups instead of appending.

388
MCQeasy

To check the details of a failed systemd service unit, including the last log entries, which command is most appropriate?

A.systemctl status service
B.systemctl list-units --failed
C.systemctl is-failed service
D.systemctl show service
AnswerA

'systemctl status' shows the unit's state, exit code and the most recent journal entries, giving both failure details and last log lines in one view. It satisfies the requirement to inspect a failed unit without a separate journalctl invocation.

Why this answer

`systemctl status service` is the most appropriate command because it displays the current state of the service unit, including whether it is active, failed, or inactive, along with the last several log entries from the journal for that unit. This provides both the failure status and the contextual log output needed to diagnose why the service failed, all in a single command.

Exam trap

The trap here is that candidates often confuse `systemctl is-failed` (which only checks the failure state) with `systemctl status` (which provides both the state and the logs), leading them to choose a command that gives insufficient diagnostic information for the question's requirement of 'including the last log entries'.

How to eliminate wrong answers

Option B is wrong because `systemctl list-units --failed` only lists all failed units without showing the detailed status or log entries for a specific service. Option C is wrong because `systemctl is-failed service` only returns a simple exit code or string ('failed' or 'active') indicating whether the unit is in a failed state, but it does not provide any log entries or detailed failure information. Option D is wrong because `systemctl show service` displays all unit properties (such as environment variables, resource limits, and dependency information) in a structured key-value format, but it does not include the recent log entries needed for troubleshooting a failure.

389
Multi-Selectmedium

An administrator needs to add a new swap space to a running Linux server without rebooting. The server has a free partition /dev/sdc1 and an existing file /swapfile. Which two commands or steps are required to activate the new swap partition /dev/sdc1 immediately? (Choose two.)

Select 2 answers
A.swapoff /dev/sdc1
B.mount -t swap /dev/sdc1 /mnt
C.echo '/dev/sdc1 none swap sw 0 0' >> /etc/fstab
D.swapon /dev/sdc1
E.mkswap /dev/sdc1
AnswersD, E

swapon activates the swap partition, making it available to the kernel for paging. After mkswap has initialized the partition, swapon enables it immediately without a reboot. This is the second required step to bring the new swap space online.

Why this answer

To activate a new swap partition immediately, you must first initialize it with mkswap, then enable it with swapon. These two commands prepare and activate the swap space without requiring a reboot. Adding an fstab entry is for persistence across reboots, and swapoff or mount are not appropriate for enabling swap.

Exam trap

The trap here is confusing the steps for immediate activation with the steps for persistent configuration, such as editing /etc/fstab.

390
Multi-Selecteasy

Which TWO commands can be used to display listening TCP ports on a Linux system?

Select 2 answers
A.ss -tln
B.netstat -tln
C.nmap -sT localhost
D.iptables -L
E.lsof -i TCP
AnswersA, B

ss -tln lists listening TCP ports (t for TCP, l for listening, n for numeric).

Why this answer

The `ss -tln` command displays listening TCP sockets by using the `-t` flag for TCP, `-l` for listening sockets, and `-n` to show numeric addresses and ports without resolving service names. It reads socket information directly from the kernel's netlink interface, making it the modern replacement for netstat on Linux systems.

Exam trap

The trap here is that candidates often assume `lsof -i TCP` shows only listening ports, but without the `-sTCP:LISTEN` filter it displays all TCP sockets, including established connections, making it incorrect for the specific requirement of listing only listening TCP ports.

391
MCQeasy

A system administrator needs to prevent a service named backup.service from starting automatically at boot, while keeping it available for manual start. The service is currently enabled. Which command should the administrator run?

A.systemctl stop backup.service
B.systemctl mask backup.service
C.systemctl disable backup.service
D.systemctl kill backup.service
AnswerC

Disabling a service removes the symlinks that cause it to start at boot, but the unit file remains available. The administrator can still start it manually with systemctl start. This matches the requirement to prevent automatic startup while allowing manual activation.

Why this answer

To prevent automatic startup while retaining the ability to start manually, the service must be disabled. Disabling removes the boot-time symlinks but leaves the unit file intact. Masking would prevent manual start, and stopping or killing only affects the current runtime state.

Exam trap

The trap here is confusing disabling a service with masking it, or thinking that stopping a service also disables it from starting at boot.

392
MCQmedium

A Linux server has a DNS resolver configuration in /etc/resolv.conf. You need to add a new DNS server at 8.8.8.8 and ensure it is used before the existing server. Which line should you add to the top of /etc/resolv.conf?

A.dns 8.8.8.8
B.nameserver 8.8.8.8:53
C.search 8.8.8.8
D.nameserver 8.8.8.8
AnswerD

The 'nameserver' directive specifies a DNS server. Placing 'nameserver 8.8.8.8' at the top of /etc/resolv.conf makes it the first server queried. The resolver tries nameservers in the order they appear, so this ensures it is used before the existing server. This is the correct syntax and placement.

Why this answer

The correct line is 'nameserver 8.8.8.8'. The resolver reads nameserver entries in order, so placing it at the top makes it the first server used. The other options use invalid keywords or syntax that would not be recognized by the resolver.

Exam trap

The trap here is using incorrect keywords such as 'dns' or adding a port number to the nameserver IP, which are invalid in /etc/resolv.conf.

393
MCQhard

An administrator needs to add a new 8 GB swap area on a server that already has a 2 GB swap partition. The system has free space in the volume group vg_sys. Which command creates a logical volume named lv_swap of exactly 8 GB and prepares it for swap use?

A.lvcreate -L 8G -n lv_swap vg_sys && mkswap /dev/vg_sys/lv_swap && swapon /dev/vg_sys/lv_swap
B.vgcreate -L 8G -n lv_swap vg_sys && mkswap /dev/vg_sys/lv_swap && swapon /dev/vg_sys/lv_swap
C.lvcreate -L 8G -n lv_swap vg_sys && mkfs.swap /dev/vg_sys/lv_swap && swapon /dev/vg_sys/lv_swap
D.lvcreate -l 8 -n lv_swap vg_sys && mkswap /dev/vg_sys/lv_swap && swapon -a
AnswerA

lvcreate -L 8G -n lv_swap vg_sys creates the 8 GB logical volume in the specified volume group, mkswap writes the swap signature, and swapon activates it immediately. This is the complete correct sequence for adding a swap LV. To persist across reboots, an entry in /etc/fstab would also be needed, but the question asks about creating and preparing the area.

Why this answer

The correct procedure is to create the logical volume with lvcreate -L 8G -n lv_swap vg_sys, initialize it with mkswap, and activate it with swapon. The -L option specifies an absolute size in gigabytes, which matches the 8 GB requirement. Persistent activation requires an /etc/fstab entry, but the immediate creation and activation sequence is as shown.

Exam trap

The trap here is confusing the lvcreate -l (lowercase, extents) and -L (uppercase, size) options, which leads to creating a volume far smaller than intended.

394
Multi-Selecthard

An administrator needs to inspect the first few lines of a very large log file /var/log/syslog without loading the entire file into memory, and also needs to follow new entries as they are appended in real time. Which TWO commands or command combinations satisfy these requirements? (Choose two.)

Select 2 answers
A.wc -l /var/log/syslog
B.head -n 20 /var/log/syslog
C.tail -f /var/log/syslog
D.grep -r '' /var/log/syslog
E.cat /var/log/syslog | less
AnswersB, C

head reads only the requested number of lines from the start of the file and then exits, so it does not load the entire log into memory. For a first-lines inspection of a large file, this is efficient and appropriate, satisfying the requirement to view the beginning without processing the whole file.

Why this answer

Viewing the start of a large file efficiently calls for head, which stops after the requested lines. Following appended entries in real time calls for tail -f, which keeps the file open and prints new data. Commands that scan the entire file, such as cat piped to less, grep over the whole file, or wc, do not meet the efficiency or following requirements.

Exam trap

The trap here is treating any pager or search tool as equivalent to a true follow mode, when only tail -f keeps watching for new content.

395
MCQeasy

Refer to the exhibit. The administrator attempted to create a user 'newuser' but received an error. Which command should be used to check if the user already exists?

A.cat /etc/passwd | grep newuser
B.passwd -S newuser
C.usermod -c newuser
D.userdel -v newuser
AnswerA

Searching `/etc/passwd` for the string `newuser` directly confirms whether the account already exists, since local users are recorded there. Piping `cat` into `grep` satisfies the stem's requirement to check for a pre-existing user before retrying `useradd`, which failed because the name was already taken.

Why this answer

The /etc/passwd file stores all user account information, and using cat to pipe its contents through grep allows the administrator to search for the specific username 'newuser'. If the user exists, grep will output the matching line; if not, no output is returned. This is a standard, quick method to verify user existence without modifying system state.

Exam trap

The trap here is that candidates may choose a command that seems related to user management (like passwd or usermod) without realizing those commands assume the user already exists and will produce errors or unintended side effects when used for existence verification.

How to eliminate wrong answers

Option B is wrong because 'passwd -S newuser' displays the status of a user's password (e.g., locked, password set), but it will fail with an error if the user does not exist, making it unsuitable for checking existence without causing an error. Option C is wrong because 'usermod -c newuser' attempts to modify the comment field of an existing user named 'newuser', which will fail if the user does not exist; the -c flag expects a comment string, not a username to check. Option D is wrong because 'userdel -v newuser' attempts to delete the user 'newuser' with verbose output, which will fail with an error if the user does not exist, and it is a destructive command that should not be used for mere existence checks.

396
MCQmedium

A storage administrator is preparing a 4 TB USB 3.0 external drive to hold large backup archives. The drive must be usable on Linux, Windows, and macOS workstations, and single files will occasionally exceed 4 GB. Which filesystem should be created on the single partition /dev/sdb1?

A.mkfs.exfat /dev/sdb1
B.mkfs.vfat -F 32 /dev/sdb1
C.mkfs.ext4 /dev/sdb1
D.mkfs.xfs /dev/sdb1
AnswerA

exFAT is the only filesystem in this list natively read/written by current Linux, Windows, and macOS releases, and it supports files far larger than 4 GB, which FAT32 cannot. It is the correct choice for a shared external backup drive that must move between all three platforms without extra drivers.

Why this answer

exFAT was designed for flash and removable media and is supported out of the box by modern Linux, Windows, and macOS. It also has no 4 GB per-file ceiling, unlike FAT32, so it satisfies both the cross-platform and large-file requirements. The other filesystems either impose a size limit or lack native support on one of the required operating systems.

Exam trap

The trap here is assuming that any cross-platform filesystem will do and picking FAT32, forgetting its 4 GiB per-file limit.

397
MCQmedium

A server has a new disk /dev/sdd that must be mounted at /backup and automatically mounted at boot. The administrator creates a GPT partition table, a single partition /dev/sdd1, and an ext4 filesystem. Which /etc/fstab entry correctly uses a persistent identifier for the filesystem?

A.LABEL=backup /backup xfs defaults 0 2
B.UUID=1234-abcd /backup ext4 defaults 0 2
C./dev/sdd1 /backup ext4 defaults 0 2
D.UUID=1234-abcd /backup ext4 noauto 0 2
AnswerB

Using UUID= in /etc/fstab references the filesystem by its unique identifier, which remains stable even if device names change or disks are reordered. The mount point, filesystem type, options, and dump/pass fields are all valid. The pass value of 2 schedules fsck after the root filesystem during boot, which is appropriate for a non-root filesystem.

Why this answer

Persistent mounting in /etc/fstab should use a stable identifier such as UUID= or LABEL= rather than a kernel device name. The entry must also specify the correct filesystem type and avoid options like noauto that prevent boot-time mounting. The UUID form with ext4 and a pass value of 2 satisfies all requirements.

Exam trap

The trap here is choosing a device path like /dev/sdd1, which looks simple and works immediately but is not persistent across hardware changes.

398
MCQeasy

An administrator needs to compress a directory named 'project' into a tarball with maximum compression using gzip. Which command is appropriate?

A.tar -cjvf archive.tar.bz2 project
B.tar -czvf archive.tar.gz project
C.tar -cJvf archive.tar.xz project
D.tar -cvf archive.tar project
AnswerB

The -z flag pipes the archive through gzip, -c creates it, -v lists files and -f names archive.tar.gz. This produces a gzip-compressed tarball of the project directory, satisfying the maximum-compression gzip requirement, though -9 would be needed for maximum level.

Why this answer

The `-z` flag tells tar to compress the archive using gzip. The `-c` flag creates a new archive, `-v` provides verbose output, and `-f` specifies the archive filename. The `.tar.gz` extension is the conventional extension for a gzip-compressed tarball.

Although other tools like bzip2 or xz can achieve higher compression ratios, the question explicitly asks for using gzip.

Exam trap

The trap here is that candidates often confuse the compression flags (`-z` for gzip, `-j` for bzip2, `-J` for xz) and may pick option A or C thinking they provide 'maximum compression' without realizing the question specifically requires gzip, not just any compression.

How to eliminate wrong answers

Option A is wrong because the `-j` flag compresses with bzip2, not gzip, and the `.tar.bz2` extension indicates bzip2 compression, which is not what the question asks for. Option C is wrong because the `-J` flag compresses with xz, not gzip, and the `.tar.xz` extension indicates xz compression, which is a different algorithm. Option D is wrong because it creates an uncompressed tarball (no compression flag), resulting in a `.tar` file, which does not satisfy the requirement for gzip compression.

399
MCQeasy

An administrator wants to ensure that a service is listening on TCP port 8080 and accessible from remote hosts. Which command will confirm that the service is listening on the correct interface?

A.iptables -L
B.netstat -i
C.ss -tlnp
D.ip addr
AnswerC

The ss -tlnp command lists TCP listening sockets with numeric ports and the owning process, showing which interface each service binds to. This confirms whether the service listens on port 8080 and is reachable remotely, satisfying the stem's verification requirement.

Why this answer

The `ss -tlnp` command displays listening (`-l`) TCP (`-t`) sockets with numeric addresses (`-n`) and the associated process (`-p`), which directly confirms that a service is bound to TCP port 8080 on a specific interface (e.g., 0.0.0.0:8080 or 192.168.1.10:8080). This ensures the service is listening on the correct interface and is reachable from remote hosts.

Exam trap

The trap here is that candidates confuse commands that show network configuration or firewall rules with those that show actual listening sockets, leading them to pick `iptables -L` or `ip addr` instead of `ss -tlnp`.

How to eliminate wrong answers

Option A is wrong because `iptables -L` lists firewall rules, not listening sockets; it cannot confirm whether a service is listening on a specific port or interface. Option B is wrong because `netstat -i` displays interface statistics (packets, errors, etc.), not listening sockets or port bindings. Option D is wrong because `ip addr` shows IP addresses assigned to network interfaces, not the listening state of services or TCP ports.

400
MCQeasy

A junior administrator needs to display the first 10 lines of a file named 'data.csv'. Which command should they use?

A.head data.csv
B.less data.csv
C.tail data.csv
D.cat data.csv
AnswerA

head prints the first ten lines of a file by default, satisfying the requirement to display only the opening portion of data.csv. No flags are needed since ten lines is the built-in default, unlike cat, which would output the entire file.

Why this answer

The `head` command is specifically designed to display the first 10 lines of a file by default. Running `head data.csv` will output the first 10 lines of the CSV file, making it the correct choice for this task.

Exam trap

The trap here is that candidates may confuse `head` with `tail` or `less`, thinking any command that displays file content can be used, but the exam specifically tests knowledge of the default behavior of each command for displaying the first lines of a file.

How to eliminate wrong answers

Option B is wrong because `less` is a pager that displays the file interactively, starting from the first line but requiring user input to scroll, and does not automatically show only the first 10 lines. Option C is wrong because `tail` displays the last 10 lines of a file by default, not the first 10 lines. Option D is wrong because `cat` outputs the entire file contents to the terminal, which is inefficient and does not limit output to the first 10 lines.

401
MCQhard

An administrator is investigating why the 'tomcat' service fails to start on a RHEL 8 server. The output of 'systemctl status tomcat' shows: 'Loaded: loaded (/etc/systemd/system/tomcat.service; enabled; vendor preset: disabled) Active: failed (Result: exit-code) since ... Process: 4567 ExecStart=/opt/tomcat/bin/startup.sh (code=exited, status=1/FAILURE)'. The 'journalctl -u tomcat' shows: 'Error: JAVA_HOME is not defined correctly, cannot execute /usr/lib/jvm/java-11-openjdk/bin/java'. The admin checks /opt/tomcat/bin/startup.sh and sees it references JAVA_HOME. The admin verifies that Java 11 is installed at /usr/lib/jvm/java-11-openjdk. Which action should the admin take to fix the service?

A.Edit /opt/tomcat/bin/startup.sh and hardcode JAVA_HOME.
B.Add 'Environment=JAVA_HOME=/usr/lib/jvm/java-11-openjdk' to the [Service] section of /etc/systemd/system/tomcat.service and run 'systemctl daemon-reload && systemctl restart tomcat'.
C.Run the startup script manually with 'bash /opt/tomcat/bin/startup.sh'.
D.Set JAVA_HOME globally using 'export JAVA_HOME=/usr/lib/jvm/java-11-openjdk' in /etc/profile.
AnswerB

The unit runs startup.sh without a shell profile, so JAVA_HOME is unset in the service environment, causing the exit-code 1 failure. Declaring Environment=JAVA_HOME in the [Service] section injects the variable directly into the unit's environment, satisfying the script's requirement; daemon-reload applies the change.

Why this answer

Systemd services can have environment variables set via the `Environment=` directive in the unit file. Adding `JAVA_HOME=/usr/lib/jvm/java-11-openjdk` to the `[Service]` section ensures the variable is available to the `ExecStart` process. Running `systemctl daemon-reload` reloads the unit definition, and `systemctl restart tomcat` applies the change.

This is the proper method for configuring environment variables for systemd-managed services on RHEL 8.

Exam trap

The trap here is that candidates assume setting environment variables in shell profile files (like `/etc/profile`) will affect systemd services, but systemd does not source these files; the correct method is to use the `Environment=` directive in the unit file.

How to eliminate wrong answers

Option A is wrong because hardcoding `JAVA_HOME` in the startup script is fragile and not the standard approach; it breaks updates or script reuse and does not leverage systemd's environment management. Option C is wrong because manually running the script bypasses systemd's service management, logging, and dependency handling, and does not fix the underlying environment variable issue for the service. Option D is wrong because setting `JAVA_HOME` in `/etc/profile` only affects login shells, not the systemd service environment; systemd services do not source profile files.

402
MCQmedium

A user reports that a script fails with 'Permission denied' when executed. The script has permissions -rw-r--r-- and is owned by the user. Which command should the user run to make the script executable for the owner only?

A.chmod u+s script.sh
B.chmod u+x script.sh
C.chown :users script.sh
D.chmod +x script.sh
AnswerB

The file lacks execute permission for the owner, producing 'Permission denied'. chmod u+x adds execute only for the owner, matching the requirement to make it executable for the owner alone without altering group or other permissions.

Why this answer

The script currently has permissions `-rw-r--r--`, meaning the owner has read and write but not execute permission. The `chmod u+x` command adds the execute permission for the owner only, which is exactly what the user needs to run the script without affecting group or others.

Exam trap

The trap here is that candidates may confuse the setuid bit (`u+s`) with the execute bit (`u+x`), or assume that `chmod +x` is equivalent to `chmod u+x`, when in fact the former grants execute to all users, which is not what the question asks.

How to eliminate wrong answers

Option A is wrong because `chmod u+s` sets the setuid bit, which allows the script to run with the owner's privileges when executed, but does not add execute permission; the script would still fail with 'Permission denied' if the execute bit is missing. Option C is wrong because `chown :users script.sh` changes the group ownership to 'users', which does not grant execute permission to the owner or anyone else. Option D is wrong because `chmod +x` adds execute permission for all three categories (owner, group, others), which is broader than the requirement to make it executable for the owner only.

403
Multi-Selecthard

Which THREE of the following statements about the user private group (UPG) scheme are true?

Select 3 answers
A.It is the default scheme in Red Hat-based distributions.
B.The umask 0027 ensures files created are NOT readable by the group.
C.The primary group of a user is a system group with GID less than 1000.
D.It ensures that new files have a default group of the user's private group.
E.Each user is assigned a unique group with the same name as the username.
AnswersA, D, E

Red Hat-based distributions like RHEL, CentOS, and Fedora use User Private Groups (UPG) by default, where each user is assigned a unique private group with the same name as the username.

Why this answer

Options A, D, and E are true. A: It is the default scheme in Red Hat-based distributions. D: It ensures that new files have a default group of the user's private group.

E: Each user is assigned a unique group with the same name as the username. B is false because umask 0027 gives group read permission, not denies it. C is false because the primary group is the user's private group, not a system group.

404
MCQhard

A Linux router has two interfaces: eth0 (203.0.113.10/24) connected to the internet and eth1 (10.10.0.1/24) connected to an internal network. Internal clients can ping the router's eth1 address but cannot reach external websites. IP forwarding is enabled, and no firewall rules are present. Which command will allow the internal clients to reach the internet by masquerading their traffic?

A.iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
B.iptables -t nat -A PREROUTING -i eth1 -j MASQUERADE
C.iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
D.iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
AnswerC

This rule adds a source NAT (masquerade) rule to the POSTROUTING chain for packets leaving via eth0. It rewrites the source address of internal packets to the router's external IP, allowing return traffic to be routed back. This is the standard way to provide internet access for a private subnet when the external address is dynamic or when using a single public IP.

Why this answer

For internal clients to reach the internet through a router, their private source addresses must be translated to the router's public address. This is done with a MASQUERADE rule in the nat table's POSTROUTING chain, applied to packets leaving the external interface. The other options either use the wrong chain, only permit forwarding without translation, or masquerade in the wrong direction.

Exam trap

The trap here is placing MASQUERADE in PREROUTING or on the internal interface, confusing the direction of source NAT.

405
MCQhard

An administrator is configuring an NFS server and wants to export /srv/data to a specific client, 192.168.10.25, with read-write access, while ensuring that the client's root user is mapped to the anonymous user for security. Which entry should be placed in /etc/exports?

A./srv/data 192.168.10.25(rw,no_root_squash)
B./srv/data *(rw,root_squash)
C./srv/data 192.168.10.25(ro,root_squash)
D./srv/data 192.168.10.25(rw,root_squash)
AnswerD

This entry grants read-write access to the specified client and enables root_squash, which maps the client's root user to the anonymous user (typically nobody). This is the default behavior in many NFS implementations, but explicitly specifying it ensures security. It correctly restricts access to the single client and applies the required root squashing.

Why this answer

The correct export entry must specify the exact client, grant read-write access, and enable root squashing. The entry /srv/data 192.168.10.25(rw,root_squash) accomplishes all three requirements. root_squash is the default, but explicitly including it ensures the security policy is applied even if defaults change.

Exam trap

The trap here is confusing root_squash with no_root_squash, or using a wildcard that opens the export to all clients instead of restricting it to the specified host.

406
Multi-Selectmedium

Which THREE steps are required to create a new ext4 filesystem on /dev/sdc1 and ensure it is automatically mounted at /mnt/data at boot? (Choose three.)

Select 3 answers
A.e2label /dev/sdc1 data
B.mkfs.ext4 /dev/sdc1
C.mkdir /mnt/data
D.mount /dev/sdc1 /mnt/data
E.add entry to /etc/fstab for /dev/sdc1
AnswersB, C, E

Running `mkfs.ext4 /dev/sdc1` writes a fresh ext4 superblock, inode tables and journal directly onto the partition, satisfying the stem's requirement to create the filesystem. Without this formatting step, no ext4 structure exists for the later mount at /mnt/data, so the remaining steps would fail.

Why this answer

Option B (mkfs.ext4 /dev/sdc1) is correct because mkfs.ext4 is the command that actually creates a new ext4 filesystem on the specified partition, which is the core requirement of the task. Option C (mkdir /mnt/data) is correct because the mount point directory must exist before the filesystem can be mounted there, and /mnt/data is not guaranteed to exist by default. Option E (add entry to /etc/fstab for /dev/sdc1) is correct because /etc/fstab is the system configuration file that defines filesystems to be mounted automatically at boot, so an entry mapping /dev/sdc1 to /mnt/data is required for persistent mounting.

Option A (e2label /dev/sdc1 data) is not required because labeling the filesystem is optional and not necessary to create or auto-mount it. Option D (mount /dev/sdc1 /mnt/data) is not required as a step for boot-time mounting, since the fstab entry handles mounting at boot; a manual mount would only be needed to use it immediately without rebooting.

Exam trap

The trap here is that candidates often confuse the temporary `mount` command (which does not persist across reboots) with the permanent configuration required in /etc/fstab, and may also mistakenly think setting a filesystem label is a required step for creating or mounting a filesystem.

Page 5

Page 6 of 6

All pages