Courseiva

CCNA Essential Commands Questions

75 of 86 questions · Page 1/2 · Essential Commands · Answers revealed

1
MCQhard

An administrator needs to combine two sorted text files, /tmp/a.txt and /tmp/b.txt, into a single sorted stream on standard output while also removing duplicate lines that appear in both files. Which command should be used?

A.sort -m /tmp/a.txt /tmp/b.txt
B.comm -12 /tmp/a.txt /tmp/b.txt
C.sort -u /tmp/a.txt /tmp/b.txt
D.uniq /tmp/a.txt /tmp/b.txt
AnswerC

Passing both files as arguments to sort merges them into one input stream, and -u suppresses duplicate lines after sorting. Because the input files are already sorted, the result is a single ordered stream with duplicates from either file removed, which is exactly the stated goal.

Why this answer

Sorting both files together with duplicate suppression yields the union of their lines in order, which matches the request. Merge mode preserves duplicates, uniq cannot read two inputs and would clobber the second path, and comm -12 returns only the shared lines, so none of those alternatives produce the required combined, deduplicated stream.

Exam trap

The trap here is assuming uniq can accept two files and merge them, when its second argument is an output file.

2
MCQeasy

A user wants to find all files in /var/log that have been modified within the last 2 days. Which command should they use?

A.find /var/log -mtime -2
B.find /var/log -mmin -2880
C.find /var/log -mtime +2
D.find /var/log -mtime 2
AnswerA

The -mtime test compares each file's modification time against 24-hour periods, so -2 selects files changed less than two days ago. This directly satisfies the stem's 'within the last 2 days' constraint, whereas -mtime +2 would return older files.

Why this answer

The `find` command with `-mtime -2` searches for files whose content was last modified less than 2 days ago (i.e., within the last 48 hours). The minus sign before the number indicates 'less than' or 'within the last N days', which matches the user's requirement to find files modified within the last 2 days.

Exam trap

The trap here is that candidates often confuse the meaning of the plus (+) and minus (-) signs with `-mtime`, mistakenly thinking `+2` means 'within the last 2 days' or that `-mtime 2` (without sign) means 'within 2 days', when in fact the signs control the direction of the time comparison.

How to eliminate wrong answers

Option B is wrong because `-mmin -2880` would find files modified within the last 2880 minutes (which is exactly 2 days), but the question asks for files modified within the last 2 days, not exactly 2 days ago; however, the more precise issue is that `-mmin` counts minutes, not days, and while 2880 minutes equals 2 days, the command would work but is not the standard or expected answer for this context. Option C is wrong because `-mtime +2` finds files modified more than 2 days ago (greater than 48 hours), which is the opposite of what is needed. Option D is wrong because `-mtime 2` (without a plus or minus sign) finds files modified exactly 2 days ago (i.e., between 48 and 72 hours ago), not within the last 2 days.

3
Multi-Selectmedium

Which THREE of the following statements about Linux file permissions are correct?

Select 3 answers
A.The command 'chmod a+w file' removes write permission for all.
B.The command 'chmod 400 secret.txt' sets read-only permission for the owner only.
C.The command 'chmod 755 file' sets permissions to rwxr-xr-x.
D.The command 'chmod u+x script.sh' adds execute permission for the owner.
E.The command 'chmod 644 file' sets permissions to rw-rw-rw-.
AnswersB, C, D

Setting mode 400 grants the owner read permission while clearing write and execute for owner, group and others, satisfying the stem's requirement for owner-only read access. The leading digit 4 maps to read in the octal notation, and the two trailing zeros deny all group and other permissions.

Why this answer

Option B is correct because chmod 400 secret.txt assigns the octal value 4 (read) to the owner and 0 (no permissions) to group and others, producing r--------, i.e., read-only for the owner only. Option C is correct because chmod 755 file sets owner to 7 (rwx), group to 5 (r-x), and others to 5 (r-x), yielding rwxr-xr-x. Option D is correct because chmod u+x script.sh uses the symbolic mode u+x to add execute permission for the file's owner without altering other permission bits.

Option A is wrong because a+w adds write permission for all (user, group, other), not removes it; removal would be a-w. Option E is wrong because chmod 644 yields rw-r--r--, not rw-rw-rw- (which would be 666).

Exam trap

The trap here is that candidates often confuse the numeric permission values (e.g., thinking 644 gives rw-rw-rw- instead of rw-r--r--) or misinterpret the symbolic mode syntax, such as assuming 'a+w' removes write permission when it actually adds it.

4
MCQhard

A DevOps engineer wants to list all running processes sorted by memory usage in descending order. Which command should be used?

A.ps aux --sort=-%mem
B.ps aux --sort=%mem
C.ps aux --sort=+mem
D.ps aux --sort=-%cpu
AnswerA

`ps aux --sort=-%mem` lists every process with user, CPU and memory columns, then orders by the `%mem` field. The leading minus reverses the default ascending sort, placing the heaviest memory consumers first, which satisfies the descending-order requirement. `aux` also captures processes beyond the current terminal, so nothing running is omitted.

Why this answer

`ps aux` lists all running processes, and `--sort=-%mem` sorts them by memory usage in descending order (the minus sign indicates descending). This is the standard way to identify memory-heavy processes for troubleshooting or resource monitoring.

Exam trap

The trap here is that candidates often confuse `%mem` with `mem` or `%cpu` with `%mem`, and may overlook the minus sign for descending order, leading them to pick ascending sort options or the wrong resource metric.

How to eliminate wrong answers

Option B is wrong because `--sort=%mem` sorts by memory usage in ascending order (lowest first), not descending as required. Option C is wrong because `--sort=+mem` uses an invalid sort key; the correct key is `%mem` (with percent sign), and the plus sign is redundant but would still sort ascending if the key were valid. Option D is wrong because `--sort=-%cpu` sorts by CPU usage descending, not memory usage, which does not meet the requirement.

5
Multi-Selectmedium

Which THREE of the following commands can be used to view the contents of a compressed file named 'file.gz' without permanently decompressing it? (Choose exactly three.)

Select 3 answers
A.gzip file.gz
B.zmore file.gz
C.gunzip file.gz
D.zcat file.gz
E.zless file.gz
AnswersB, D, E

zmore pipes the gzip stream through a pager, decompressing on the fly to standard output while leaving file.gz untouched on disk. That satisfies the constraint of viewing contents without permanently decompressing, and it paginates long output.

Why this answer

Option B (zmore file.gz) is correct because zmore is a filter that pipes the decompressed output of gzip-compressed files through more, letting you page through the contents without writing a decompressed file to disk. Option D (zcat file.gz) is correct because zcat decompresses the file to standard output, displaying its contents on screen while leaving the original file.gz intact. Option E (zless file.gz) is correct because zless uses less to page through the decompressed stream of a gzip file, again without permanently decompressing it.

Option A (gzip file.gz) is wrong because gzip is used to compress files (and would actually try to compress file.gz further), not to view contents. Option C (gunzip file.gz) is wrong because gunzip permanently decompresses the file, replacing file.gz with an uncompressed file, which is exactly what the question excludes.

Exam trap

The trap here is that candidates mistakenly think `gunzip` or `gzip` can be used to view file contents without permanent decompression, confusing compression/decompression commands with viewing utilities like `zcat`, `zmore`, and `zless`.

6
Multi-Selecteasy

Which TWO commands can display the current environment variables?

Select 2 answers
A.set
B.echo $HOME
C.env
D.export
E.printenv
AnswersC, E

env prints all exported environment variables for the current shell session, listing each name-value pair. It satisfies the requirement to display the current environment without arguments, unlike set, which also includes shell functions and non-exported variables.

Why this answer

The `env` command (option C) is correct because it prints all current environment variables and their values to standard output when run without arguments. The `printenv` command (option E) is also correct because it displays the values of all environment variables (or a specified one) in the current shell environment. Option A, `set`, is not marked correct because although it lists shell variables, it also includes shell functions and local variables, not strictly the environment variables.

Option B, `echo $HOME`, is not marked correct because it only displays the value of the single HOME variable rather than the current environment variables as a whole. Option D, `export`, is not marked correct because it is used to mark variables for export to child processes, not to display the environment.

Exam trap

The trap here is that candidates often confuse `set` (which shows all shell variables) with `env` (which shows only environment variables), or they think `echo $HOME` is a way to list all variables, when it only shows one specific variable.

7
MCQhard

Refer to the exhibit. The output of 'ps aux' shows a process named 'process_hog' with PID 1234 consuming 99.5% CPU. The process is stuck in an infinite loop and does not respond to SIGTERM. Which signal should be used to forcefully terminate it?

A.kill -2 1234
B.kill -9 1234
C.kill -15 1234
D.kill -19 1234
AnswerB

SIGKILL, signal 9, cannot be caught or ignored, so the kernel terminates the process immediately. SIGTERM is handled or blocked by the looping process, which is why it survived. kill -9 1234 forcefully ends it.

Why this answer

SIGKILL (signal 9) cannot be caught, blocked, or ignored by a process, making it the only reliable way to terminate a process that is stuck in an infinite loop and unresponsive to SIGTERM. Since the process does not respond to SIGTERM (signal 15), a forceful kill with kill -9 is necessary.

Exam trap

In LFCS, the key distinction is between termination signals (SIGTERM, SIGKILL) and stop signals (SIGSTOP). SIGTERM allows graceful shutdown, but if ignored, SIGKILL is the only way to force termination. Some candidates incorrectly use SIGSTOP (pause) or confuse SIGTERM with a guaranteed kill.

How to eliminate wrong answers

Option A is wrong because kill -2 sends SIGINT, which is a polite interrupt signal that can be caught or ignored by the process, and it will not force-terminate a process stuck in an infinite loop. Option C is wrong because kill -15 sends SIGTERM, which is the default termination signal that requests graceful shutdown, but the process is already unresponsive to it as stated in the question. Option D is wrong because kill -19 sends SIGSTOP, which pauses the process but does not terminate it, leaving it in a stopped state and still consuming resources.

8
MCQhard

You are managing a Linux server that hosts a critical web application. The server is running low on disk space in the root filesystem, and you need to free up space urgently. You run 'df -h' and see that /dev/sda1 is mounted on / and is 95% full. You also notice that /var/log/messages is over 2 GB in size. The application writes logs to /var/log/app.log, which is also large. The server has a separate /var partition that has plenty of free space. The application must continue running with minimal downtime. You need to compress and rotate logs without losing any data, and ensure that the root filesystem has at least 10% free space. Which of the following actions should you take first to achieve this goal?

A.Delete /var/log/app.log and /var/log/messages to free space quickly.
B.Stop the application, truncate /var/log/app.log, then restart the application.
C.Use logrotate with the 'copytruncate' option to rotate /var/log/app.log and move the rotated file to /var/old_logs/.
D.Compress /var/log/app.log using gzip and keep it in place.
AnswerC

This rotates the log without interrupting the application and moves it to a partition with space, freeing root.

Why this answer

Logrotate with the 'copytruncate' option allows the application to continue writing to the same file descriptor while the current log is copied and then truncated to zero length. This avoids any application downtime and the rotated log can be moved to the separate /var partition (which has free space) for compression or archiving, freeing space on the root filesystem without data loss.

Exam trap

The trap here is that candidates often choose to delete or truncate logs directly, not realizing that running processes hold file descriptors and that truncation does not immediately free disk space until the file descriptor is closed, or they overlook the 'copytruncate' option which allows zero-downtime rotation.

How to eliminate wrong answers

Option A is wrong because deleting log files while the application is running can cause the application to lose its file handle, potentially crash or stop logging, and data is permanently lost. Option B is wrong because stopping the application causes downtime, which violates the 'minimal downtime' requirement, and truncating the file in place does not free disk space until the file descriptor is released (the space is still held by the running process). Option D is wrong because compressing the log file in place does not free space on the root filesystem (the compressed file still occupies space on /), and the application may still be writing to the file, causing data loss or corruption.

9
MCQmedium

A system administrator needs to change the ownership of the file /var/www/html/index.html from user alice to user bob, and also change the group to webdev. Which command should they use?

A.chmod bob:webdev /var/www/html/index.html
B.usermod -o bob:webdev /var/www/html/index.html
C.chgrp bob:webdev /var/www/html/index.html
D.chown bob:webdev /var/www/html/index.html
AnswerD

The chown command changes file owner and group. Using the syntax user:group, it sets the owner to bob and the group to webdev in a single operation. This exactly matches the requirement without affecting other metadata like permissions.

Why this answer

The chown command is specifically designed to change file owner and group. Using the colon-separated syntax user:group sets both in one step. chmod deals with permissions, chgrp only changes group, and usermod manages user accounts. Thus, chown with bob:webdev is the correct and efficient solution.

Exam trap

The trap here is confusing chmod with chown, or thinking chgrp can change both owner and group when it only affects the group.

10
MCQhard

A cron job runs a script every hour but sometimes fails because the script cannot find commands like 'tar' and 'gzip'. The script works when run manually from a terminal. What is the best fix?

A.Run the cron job as root.
B.Modify the script to source the user's .bashrc.
C.Use absolute paths for all commands in the script.
D.Add a PATH statement to the cron job definition.
AnswerC

Cron runs with a minimal PATH, so commands resolve differently than in an interactive shell. Using absolute paths such as /bin/tar and /bin/gzip removes that dependency, guaranteeing the script finds each binary regardless of the invoking environment.

Why this answer

Cron jobs run in a minimal environment with a restricted PATH (often just /usr/bin:/bin). When the script uses commands like 'tar' and 'gzip' without absolute paths, the shell cannot locate them. Using absolute paths (e.g., /bin/tar, /bin/gzip) ensures the script always finds the commands regardless of the environment.

Exam trap

The trap here is that candidates think adding a PATH to the cron job definition (Option D) is the best fix, but the LFCS exam emphasizes absolute paths as the more robust and portable solution for scripts run by cron.

How to eliminate wrong answers

Option A is wrong because running as root does not fix the PATH issue; root also has a minimal PATH in cron and this unnecessarily escalates privileges. Option B is wrong because sourcing .bashrc may not work reliably in cron (non-interactive shell) and .bashrc often contains interactive-only aliases or functions that can break the script. Option D is wrong because adding a PATH statement to the cron job definition (e.g., PATH=/usr/local/bin:/usr/bin:/bin) is a valid alternative but is not the 'best fix' — absolute paths are more explicit, avoid dependency on the cron environment, and are the recommended best practice for scripts run by cron.

11
MCQmedium

An administrator is diagnosing disk space and wants to see the total size of the /var/log directory and all its contents in human-readable units, without listing every individual file. Which command provides exactly this summary?

A.du -ah /var/log
B.du -sh /var/log
C.ls -lh /var/log
D.df -h /var/log
AnswerB

The du command estimates file space usage, the -s option summarizes only the total for the specified directory rather than every subdirectory, and -h prints sizes in human-readable units such as K, M, and G. This produces a single concise line showing the total space consumed by /var/log and everything beneath it, exactly as requested.

Why this answer

The du -sh combination reports a single human-readable total for the specified directory tree, which is precisely the summary needed. The other commands either report filesystem-level capacity, list individual entries, or enumerate every file, none of which deliver a concise total for /var/log.

Exam trap

The trap here is reaching for df because it also reports space; df describes the filesystem, while du describes the directory tree, and only the latter summarizes /var/log itself.

12
MCQhard

A system administrator wants to kill a process with PID 1234 that is not responding to SIGTERM. Which command will forcefully terminate it?

A.kill -1 1234
B.kill -15 1234
C.kill -SIGTERM 1234
D.kill -9 1234
AnswerD

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 1234 immediately without waiting for cleanup. This satisfies the stem's requirement for forceful termination when SIGTERM (signal 15) has already failed to stop the unresponsive process.

Why this answer

Kill -9 (SIGKILL) sends signal 9, which cannot be caught, blocked, or ignored by the process. Unlike SIGTERM (signal 15), SIGKILL forces the kernel to immediately terminate the process without allowing it to clean up, making it the appropriate choice when a process is unresponsive to SIGTERM.

Exam trap

The trap here is that candidates often confuse signal numbers or assume that SIGTERM (signal 15) is always sufficient, not realizing that a process can mask or ignore it, while SIGKILL (signal 9) is the only signal that cannot be handled.

How to eliminate wrong answers

Option A is wrong because kill -1 sends SIGHUP (hangup signal), which typically causes a process to reload its configuration or terminate gracefully, not forcefully terminate. Option B is wrong because kill -15 sends SIGTERM, which is the default polite termination signal that the process can catch and ignore, so it is ineffective when the process is not responding to SIGTERM. Option C is wrong because kill -SIGTERM is equivalent to kill -15, sending the same signal that the process is already ignoring, so it will not forcefully terminate it.

13
MCQeasy

A user wants to continuously monitor a log file that is being written to by a running service. Which command achieves this?

A.head -20 /var/log/syslog
B.less /var/log/syslog
C.tail -f /var/log/syslog
D.cat /var/log/syslog
AnswerC

`tail -f` keeps the file descriptor open and polls for appended data, printing new lines as the service writes them, so monitoring continues indefinitely. The `-f` (follow) flag directly satisfies the stem's requirement for continuous monitoring of a live log, unlike a one-off read that exits immediately.

Why this answer

The `tail -f` command displays the last 10 lines of a file by default and then continues to output new lines as they are appended, making it ideal for real-time monitoring of a growing log file. The `-f` flag (follow) keeps the file open and polls for changes, typically using inotify on Linux, to output new data immediately.

Exam trap

The trap here is that candidates may confuse `tail -f` with options that only show static content, such as `head` (which shows the beginning of a file) or `tail` without `-f` (which shows the end but does not follow).

How to eliminate wrong answers

Option A is wrong because `head -20` displays the first 20 lines of the file, not the last lines, and it does not continuously monitor for new entries. Option B is wrong because `less` opens the file for interactive viewing and does not automatically follow new lines unless used with the `+F` option (which enables follow mode), but the plain `less` command does not provide continuous monitoring. Option D is wrong because `cat` outputs the entire file content to the terminal and then exits, with no ability to watch for updates or limit output to the last lines.

14
MCQhard

Based on the exhibit, which process will be affected if the root user runs 'kill 5678'?

A.The www-data process with PID 5678
B.The root process (PID 1234)
C.All www-data processes
D.No process, because root cannot kill www-data processes
AnswerA

Sending SIGTERM to PID 5678 terminates the process owned by www-data, since kill defaults to signal 15 and root bypasses ownership restrictions. This satisfies the exhibit's constraint: the target PID belongs to the www-data user, so root's kill affects that specific process rather than any other.

Why this answer

The 'kill 5678' command sends the default SIGTERM (signal 15) to the process with PID 5678. Since the root user has the CAP_KILL capability and is not subject to the ordinary permission checks that restrict non-root users, root can send signals to any process, including those owned by www-data. Therefore, the www-data process with PID 5678 will be terminated.

Exam trap

The trap here is that candidates may mistakenly believe root cannot kill processes owned by other users, or they may confuse the PID argument with a process name, thinking 'kill 5678' affects all processes of a given user or name.

How to eliminate wrong answers

Option B is wrong because 'kill 5678' targets the process with PID 5678, not PID 1234; the root process (PID 1234) is unaffected unless it coincidentally has PID 5678. Option C is wrong because 'kill 5678' sends a signal only to the specific process with PID 5678, not to all www-data processes; to target all www-data processes, one would need to use a command like 'killall www-data' or 'pkill -u www-data'. Option D is wrong because root can indeed kill any process on the system, including those owned by www-data, due to the superuser's unrestricted signal capability.

15
MCQmedium

A user 'dba' tries to login via SSH and fails. Based on the exhibit, what is the most likely cause?

A.The file /home/dba/file.txt is corrupt.
B.The user 'dba' has an invalid login shell.
C.The user 'dba' is not in the 'docker' group.
D.The home directory /home/dba does not have correct permissions.
AnswerB

SSH refuses interactive logins when the account's shell is not listed in /etc/shells or is set to a non-interactive value such as /sbin/nologin, terminating the session immediately. The exhibit's shell entry confirms this rather than a password or key problem.

Why this answer

The exhibit shows that the user 'dba' has an invalid login shell (e.g., /sbin/nologin or /bin/false). When the login shell is set to a non-interactive shell, SSH authentication succeeds but the session immediately closes, preventing the user from logging in. This is a common configuration for system accounts or users who should not have interactive shell access.

Exam trap

The trap here is that candidates often assume SSH login failures are always due to authentication (password/key) or file permissions, but the LFCS exam frequently tests the subtle point that an invalid login shell causes a successful authentication followed by an immediate session termination, which appears as a login failure.

How to eliminate wrong answers

Option A is wrong because a corrupt file in the user's home directory does not prevent SSH login; SSH authentication and session establishment occur before any user files are accessed. Option C is wrong because group membership (e.g., 'docker') is irrelevant to SSH login; SSH only checks the user's authentication credentials and shell validity. Option D is wrong because incorrect home directory permissions would cause issues after login (e.g., unable to read .bashrc), but they do not prevent the SSH authentication process itself; SSH only requires the home directory to exist and be accessible for reading the user's SSH configuration files like ~/.ssh/authorized_keys.

16
MCQmedium

A DevOps engineer wants to measure how long a specific command takes to execute. Which command should be used?

A.date
B.uptime
C.wall
D.time
AnswerD

The time shell keyword reports real, user and system execution durations for the following command, directly measuring elapsed runtime. Other tools such as date only bracket execution manually, and strace traces syscalls rather than timing the whole command.

Why this answer

The `time` command is specifically designed to measure the execution duration of a command, reporting real time, user CPU time, and system CPU time. It wraps the target command and tracks the elapsed wall-clock time and resource usage, making it the precise tool for benchmarking command performance.

Exam trap

The trap here is that candidates may confuse `time` with `date` or `uptime` because they all display time-related information, but only `time` measures the execution duration of a specific command.

How to eliminate wrong answers

Option A is wrong because `date` displays or sets the system date and time, but does not measure the duration of a command's execution. Option B is wrong because `uptime` shows how long the system has been running since last boot, along with load averages, not the execution time of a specific command. Option C is wrong because `wall` sends a message to all logged-in users' terminals and has no timing functionality.

17
MCQeasy

A junior administrator is troubleshooting a server and needs to inspect the manual page for the 'ip' command, but the system is a minimal install where the man pages for that package were not installed. The administrator still wants the short one-line usage summary for 'ip' printed directly to the terminal. Which command should they run?

A.ip --help
B.info ip
C.whatis ip
D.man ip
AnswerA

The --help flag is handled by the utility itself and prints a concise usage summary to standard output, which works even when man pages are absent. It requires no extra packages and exits immediately, making it ideal on a minimal system where documentation was stripped out.

Why this answer

The utility's own --help option is parsed by the binary itself, so it produces usage information regardless of whether any documentation packages exist on the machine. Because the scenario explicitly describes a minimal install with no man pages, the only reliable way to obtain the short usage summary is to invoke the command with its built-in help flag.

Exam trap

The trap here is assuming that documentation commands such as man or whatis can display usage information even when the corresponding documentation packages were never installed.

18
MCQmedium

Refer to the exhibit. The administrator receives alerts that the root filesystem is almost full. Which command could free up space by removing old log files?

A.find /var/log -name '*.log' -mtime +30 -delete
B.truncate -s 0 /var/log/syslog
C.rm -rf /var/log/*
D.du -sh /var/log
AnswerA

This find invocation matches files ending in .log under /var/log whose modification time exceeds 30 days, then unlinks them, directly reclaiming space consumed by stale logs. The -mtime +30 predicate targets only aged files, satisfying the requirement to remove old logs.

Why this answer

The `find` command with `-name '*.log'` targets log files, `-mtime +30` selects files modified more than 30 days ago, and `-delete` removes them. This safely frees space by purging only old logs, preserving recent logs needed for troubleshooting.

Exam trap

Linux Foundation often tests the distinction between commands that merely display disk usage (like `du`) versus those that actually remove files, and the danger of using `rm -rf` with wildcards on system directories like /var/log.

How to eliminate wrong answers

Option B is wrong because `truncate -s 0 /var/log/syslog` empties a single log file but does not remove old log files; it only clears the current syslog, which may still be needed and does not address multiple old log files. Option C is wrong because `rm -rf /var/log/*` deletes all files in /var/log, including critical logs and possibly active log files, which could break logging services and cause data loss. Option D is wrong because `du -sh /var/log` only shows disk usage of the directory; it does not free any space or remove any files.

19
MCQhard

A system administrator needs to create a hard link named /home/user/report_hardlink to an existing file /data/reports/report.txt. Which command should be used?

A.ln /data/reports/report.txt /home/user/report_hardlink
B.ln -s /data/reports/report.txt /home/user/report_hardlink
C.ln -h /data/reports/report.txt /home/user/report_hardlink
D.link -s /data/reports/report.txt /home/user/report_hardlink
AnswerA

The ln command without options creates a hard link. The first argument is the existing target file, and the second is the new link name. This creates a hard link, which shares the same inode and data blocks as the original file, and works as long as both paths are on the same filesystem.

Why this answer

The ln command creates hard links by default. Providing the existing file as the first argument and the new link name as the second creates a hard link. Hard links share the same inode and data, so changes to one are reflected in the other.

They cannot span filesystems. The correct command simply uses ln with the target and link name.

Exam trap

The trap here is assuming that ln always creates symbolic links, or adding unnecessary options like -s that change the link type, when the requirement explicitly asks for a hard link.

20
Matchingmedium

Match each Linux permission type to its symbolic representation.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

r

w

x

s (owner execute)

t (other execute)

Why these pairings

In Linux, standard file permissions are represented by symbols: read (r), write (w), and execute (x). Each permission type maps to a unique symbol. Confusion often arises from swapping these symbols.

21
MCQeasy

A user wants to set the permissions of a file to 'rwxr-xr--'. Which octal permission value should they use with chmod?

A.754
B.755
C.644
D.744
AnswerA

The symbolic mode rwxr-xr-- maps directly to octal 754: owner rwx equals 4+2+1=7, group r-x equals 4+0+1=5, and others r-- equals 4+0+0=4. Passing 754 to chmod therefore sets exactly the requested permission bits on the file.

Why this answer

The permissions 'rwxr-xr--' mean that the owner has read, write, and execute (rwx = 7), the group has read and execute (r-x = 5), and others have only read (r-- = 4). Therefore, the correct octal value is 754. Option A is correct.

Option B (755) gives others execute, option C (644) gives owner no execute and group no execute, and option D (744) gives group no execute.

Exam trap

Candidates often miscompute the octal digits by forgetting that each class (owner, group, others) is calculated independently. Common errors include picking 755 (adding execute for others) or 744 (forgetting group execute). The new option C (644) also shows a mistake where both owner and group execute are omitted.

How to eliminate wrong answers

Option B (755) is wrong because it sets others to r-x (5) instead of r-- (4), granting execute permission to others unnecessarily. Option D (744) is wrong because it sets group to r-- (4) instead of r-x (5), denying group execute permission. Option A and C are identical and both correct; the duplication is an artifact of the answer choices.

22
MCQeasy

An administrator needs to change the ownership of the directory /srv/www to user webadmin and group webteam, including all existing files and subdirectories. Which command accomplishes this?

A.chown -R webadmin:webteam /srv/www
B.chmod -R webadmin:webteam /srv/www
C.usermod -R webadmin:webteam /srv/www
D.chown webadmin:webteam /srv/www
AnswerA

The chown command changes file owner and group. The -R option applies the change recursively to all files and subdirectories under /srv/www. Specifying webadmin:webteam sets both the user and group in a single command, which exactly meets the requirement without needing a separate chgrp invocation.

Why this answer

The chown command changes file ownership, and the -R flag applies the change recursively. Specifying both user and group as webadmin:webteam in one invocation sets the owner and group for the directory and everything beneath it. This is the standard, efficient way to recursively reassign ownership for a web directory.

Exam trap

The trap here is confusing chown with chmod, assuming that a permission command can also set ownership, or forgetting that recursive changes require the -R option.

23
MCQhard

A process is consuming 99% CPU and is unresponsive to normal shutdown requests. After running 'top', you see the PID is 1234. What is the most appropriate command to stop the process gracefully first?

A.kill -15 1234
B.kill -19 1234
C.kill -2 1234
D.kill -9 1234
AnswerA

SIGTERM (15) requests orderly termination, letting the process release resources and exit cleanly — exactly the graceful first step the stem demands for PID 1234. Escalating straight to SIGKILL (9) would deny that cleanup, so `kill -15 1234` is the appropriate initial action before considering stronger signals.

Why this answer

Kill -15 1234. The SIGTERM signal (15) is the standard way to request a process terminate gracefully, allowing it to clean up resources, close files, and perform shutdown routines. This is the most appropriate first step before escalating to stronger signals, as it gives the process a chance to exit normally.

Exam trap

The trap here is that candidates often jump to kill -9 (SIGKILL) as the first solution when a process is unresponsive, but the LFCS exam emphasizes the principle of escalating signals gracefully, starting with SIGTERM.

How to eliminate wrong answers

Option B is wrong because kill -19 sends SIGSTOP, which pauses the process but does not terminate it; the process remains in memory and can be resumed with SIGCONT, so it does not stop the process gracefully. Option C is wrong because kill -2 sends SIGINT, which is typically used to interrupt a foreground process from the terminal (like Ctrl+C) and may not be effective for a background or daemon process that is unresponsive to normal shutdown requests. Option D is wrong because kill -9 sends SIGKILL, which forcefully terminates the process without allowing any cleanup; this should be a last resort after graceful methods fail, not the first attempt.

24
MCQmedium

A user needs to locate all regular files under /etc that are larger than 1 MB and have not been accessed in the last 30 days. Which command finds these files?

A.find /etc -type f -size +1M -mtime +30
B.locate /etc -type f -size +1M -atime +30
C.find /etc -type f -size 1M -atime 30
D.find /etc -type f -size +1M -atime +30
AnswerD

The find command with -type f limits results to regular files. The -size +1M matches files larger than 1 megabyte. The -atime +30 selects files whose last access time is more than 30 days ago. This combination precisely meets the requirement of locating large, infrequently accessed files under /etc.

Why this answer

The find command is the correct tool for complex file searches based on metadata. The -type f option restricts to regular files, -size +1M selects files larger than 1 MB, and -atime +30 identifies files not accessed in over 30 days. Together, these criteria match the administrator's needs exactly.

Exam trap

The trap here is confusing access time (-atime) with modification time (-mtime), or forgetting that find requires a plus sign to indicate 'greater than' for numeric comparisons.

25
MCQeasy

To display the first 10 lines of a file named 'log.txt', which command is correct?

A.less log.txt
B.tail log.txt
C.head log.txt
D.cat log.txt
AnswerC

head reads from the start of the file and, with no -n option, defaults to ten lines, printing them to standard output. That default exactly matches the stem's requirement to display the first 10 lines of log.txt.

Why this answer

The `head` command is designed to display the first 10 lines of a file by default. Running `head log.txt` outputs the first 10 lines of the file without any additional options, making it the correct choice for this task.

Exam trap

The trap here is that candidates often confuse `head` with `tail` or assume `less` or `cat` are appropriate for displaying only the first few lines, when in fact `head` is the specific command for that purpose.

How to eliminate wrong answers

Option A is wrong because `less` is a pager that displays the file interactively, allowing scrolling both forward and backward, but it does not default to showing only the first 10 lines; it shows the beginning of the file and waits for user input. Option B is wrong because `tail` displays the last 10 lines of a file by default, not the first 10 lines. Option D is wrong because `cat` outputs the entire contents of the file to the terminal, not just the first 10 lines.

26
MCQmedium

A system administrator wants to display a list of all currently running processes with their parent process IDs. Which command is most appropriate?

A.pstree
B.jobs
C.top
D.ps -ef
AnswerD

`ps -ef` lists every running process with full details, including the PPID column, satisfying the requirement to show parent process IDs. The `-e` flag selects all processes system-wide, while `-f` produces the full-format listing containing UID, PID, PPID, C, STIME, TTY, TIME and CMD.

Why this answer

(ps -ef) is correct because the 'ps' command with the '-e' flag displays all processes, and the '-f' flag provides a full-format listing that includes the PPID (parent process ID) in the output. This directly meets the requirement to list all currently running processes with their parent process IDs.

Exam trap

The trap here is that candidates may confuse 'pstree' (which shows parent-child relationships visually) with 'ps -ef' (which lists numeric PPIDs), or assume 'top' is suitable for a static list, when the question specifically asks for a list with parent process IDs, not a tree or dynamic view.

How to eliminate wrong answers

Option A is wrong because pstree displays processes in a tree hierarchy showing parent-child relationships, but it does not show the numeric parent process ID (PPID) in its default output; it focuses on the tree structure rather than a list with PPIDs. Option B is wrong because the 'jobs' command lists only background jobs associated with the current shell session, not all running processes on the system. Option C is wrong because 'top' provides a dynamic, real-time view of running processes and can display PPID if configured, but it is not a static list command and does not output a simple list of all processes with their PPIDs by default.

27
MCQeasy

A system administrator notices that the disk space on the root filesystem is at 95% usage. After investigating, they find that a large log file named 'access.log' in /var/log is taking up significant space. The administrator deletes the file using 'rm /var/log/access.log' but the disk usage remains at 95%. Running 'df -h' still shows the same usage. What is the most likely cause and the correct next step?

A.The file is compressed and needs to be decompressed. Use 'gzip -d access.log' first.
B.The filesystem is marked as full in the superblock. Use 'fsck' to repair the filesystem.
C.The file is still open by a process. Use 'lsof | grep access.log' to identify the process and restart it.
D.The file has multiple hard links. Use 'find / -links +1' to locate all hard links and delete them.
AnswerC

Deleting a file only unlinks its directory entry; the inode and its blocks persist while a process holds the descriptor open, so df still reports the space. lsof identifies that holding process, and restarting it releases the descriptor, reclaiming the space.

Why this answer

When a file is deleted with 'rm' while it is still open by a running process, the file's directory entry is removed, but the inode and data blocks remain allocated until the process closes the file descriptor. This causes 'df' to still report the space as used. The correct next step is to use 'lsof' to find the process holding the file open and restart it, which releases the file descriptor and frees the disk space.

Exam trap

The trap here is that candidates assume 'rm' immediately frees disk space, but they overlook that open file descriptors by running processes (e.g., syslog, Apache) keep the data blocks allocated until the process is restarted or the descriptor is closed.

How to eliminate wrong answers

Option A is wrong because the file was already deleted, not compressed; 'gzip -d' would fail on a removed file and does not address the open file handle issue. Option B is wrong because the filesystem is not marked as full in the superblock; 'fsck' repairs filesystem metadata corruption, not space accounting for open deleted files. Option D is wrong because hard links would cause the file to still exist under another name, but 'rm' would only remove one link; however, 'df' would show freed space only after all links are removed, but the question states the file was deleted and space remains, which points to an open file descriptor, not multiple hard links.

28
MCQeasy

A system administrator needs to identify the absolute path of the executable that would be run when typing the command 'ls'. Which command should they use?

A.find / -name ls
B.whereis ls
C.which ls
D.locate ls
AnswerC

The which command searches the directories listed in the PATH environment variable and displays the full path of the executable that would be executed. It is the standard tool for locating a command's binary in the user's path.

Why this answer

The which command is designed to search the PATH and report the full path of the executable that would be run. whereis, locate, and find do not respect the PATH or executable resolution order, so they cannot reliably answer which binary would execute. Thus, which is the correct choice.

Exam trap

The trap here is assuming that any file-finding command can determine which executable runs, when only which considers the PATH and execution order.

29
MCQeasy

A user wants to view the contents of a compressed log file /var/log/syslog.2.gz without decompressing it first. Which command should they use?

A.gunzip /var/log/syslog.2.gz
B.cat /var/log/syslog.2.gz
C.zcat /var/log/syslog.2.gz
D.less /var/log/syslog.2.gz
AnswerC

zcat streams the decompressed contents of gzip-compressed files straight to standard output, leaving the original .gz file untouched on disk. This directly satisfies the stem's constraint of viewing /var/log/syslog.2.gz without decompressing it first, unlike gunzip, which would replace the archive with an uncompressed file.

Why this answer

`zcat` is a utility that reads compressed files (typically gzip-compressed) and outputs their decompressed content to standard output without permanently decompressing the file. This allows the user to view the contents of `/var/log/syslog.2.gz` directly in the terminal.

Exam trap

The trap here is that candidates may confuse `zcat` with `gunzip` or assume `less` can handle compressed files natively, but the LFCS exam expects knowledge of the specific command designed for viewing compressed files without decompression.

How to eliminate wrong answers

Option A is wrong because `gunzip` permanently decompresses the file, replacing the `.gz` file with an uncompressed version, which is not what the user wants. Option B is wrong because `cat` cannot interpret gzip compression; it will output raw binary data, which is unreadable. Option D is wrong because `less` does not natively handle gzip-compressed files; it would display binary garbage unless used with a wrapper like `zless` or a pipe from `zcat`.

30
MCQmedium

An administrator must change the ownership of /srv/project and every file and directory beneath it to user alice and group devs, without altering permissions. Which command should be used?

A.chmod -R alice:devs /srv/project
B.chgrp -R alice:devs /srv/project
C.usermod -R alice:devs /srv/project
D.chown -R alice:devs /srv/project
AnswerD

This is correct because chown changes file owner and group, and the -R flag applies the change recursively through the directory tree. The syntax user:group sets both owner and group in one operation. Permissions are untouched, satisfying the requirement to change ownership only for /srv/project and everything beneath it.

Why this answer

Changing both owner and group recursively is the job of chown with the -R flag and the user:group syntax. This updates ownership metadata on every file and directory under the target path while leaving permission bits intact. chmod, usermod, and chgrp each address different attributes and cannot fulfill the combined owner-and-group requirement.

Exam trap

The trap here is assuming chmod can set ownership because both commands modify file metadata.

31
MCQeasy

A user reports that they cannot delete a file named 'important.txt' located in their home directory. The file is owned by the user and the user has write permission on the directory. Running 'rm important.txt' produces the error: 'rm: cannot remove 'important.txt': Operation not permitted'. The user has also tried using 'sudo rm' but gets the same error. Which of the following is the most likely cause and correct solution?

A.The file has an ACL that denies deletion. Use 'setfacl -b important.txt' to remove ACLs.
B.The file has the immutable attribute set. Use 'lsattr important.txt' and if the 'i' attribute is present, remove it with 'chattr -i important.txt'.
C.The file is currently in use by another process. Use 'lsof' to find the process and kill it.
D.The directory has the sticky bit set, preventing deletion. Use 'chmod o-t .' to remove the sticky bit.
AnswerB

The immutable attribute (i) prevents deletion even by root, which explains why 'sudo rm' also fails despite directory write permission. Checking with 'lsattr' and clearing it via 'chattr -i important.txt' directly resolves the "Operation not permitted" error, satisfying the scenario's constraint that ownership and permissions are already correct.

Why this answer

The error 'Operation not permitted' despite the user owning the file and having write permission on the directory indicates a filesystem-level restriction rather than a permission or ACL issue. The immutable attribute (i) on the file prevents any modification, including deletion, even by the root user. Running 'lsattr' reveals the attribute, and 'chattr -i' removes it, allowing deletion.

Exam trap

The trap here is that candidates confuse 'Operation not permitted' with standard permission errors, overlooking the immutable attribute as a filesystem-level override that affects even root and is not visible with 'ls -l'.

How to eliminate wrong answers

Option A is wrong because ACLs (Access Control Lists) do not produce an 'Operation not permitted' error for a file owner; they would show 'Permission denied' if applicable, and 'setfacl -b' removes all ACLs, which is unnecessary here. Option C is wrong because a file in use by another process would typically give a 'Text file busy' or 'Device or resource busy' error, not 'Operation not permitted', and killing the process would not resolve an immutable attribute. Option D is wrong because the sticky bit on a directory affects deletion of files owned by other users, not the file owner; the user owns the file, so the sticky bit does not block deletion, and 'chmod o-t' removes the sticky bit from the current directory, which is not the issue.

32
MCQeasy

A user reports that a shell script 'backup.sh' in /home/user/scripts fails to execute. What is the most likely cause?

A.The script is not in the user's PATH.
B.The script does not have execute permission for the user.
C.The script must be owned by root.
D.The script does not have a shebang line (#!/bin/bash) at the top.
AnswerB

Without execute permission, the kernel refuses to run the file as a program, returning "Permission denied" even though the script's contents are readable. The stem specifies a script that fails to execute, and this is the most common cause; `chmod +x backup.sh` resolves it.

Why this answer

The most likely cause is that the script lacks execute permission for the user. In Linux, a file must have the execute bit set (e.g., `chmod +x backup.sh`) to be run as a script. Without it, the shell will refuse to execute the file, even if the user has read access and the script is syntactically correct.

Exam trap

The trap here is that candidates often assume a missing shebang (Option D) is the primary cause, but the LFCS exam tests that execute permission is the fundamental requirement for running any script directly.

How to eliminate wrong answers

Option A is wrong because the script is being executed directly (e.g., `./backup.sh` or via a full path), so PATH is irrelevant; PATH only matters when invoking a command by name without a path. Option C is wrong because script ownership does not affect execution; any user with execute permission can run it, regardless of owner. Option D is wrong because while a shebang is good practice, the shell will still attempt to execute the script using the default shell (usually /bin/sh) if no shebang is present; the script would run, not fail to execute entirely.

33
MCQeasy

An administrator needs to change the group ownership of the directory /srv/project and all of its existing contents to the group developers, without altering the user ownership. Which command should be used?

A.chmod -R g+developers /srv/project
B.usermod -g developers /srv/project
C.chown -R developers /srv/project
D.chgrp -R developers /srv/project
AnswerD

chgrp changes group ownership and the -R flag applies the change recursively to the directory and all existing contents. It leaves user ownership untouched, which matches the requirement exactly, and it is the purpose-built command for changing group ownership on Linux systems.

Why this answer

Changing group ownership recursively is the job of chgrp -R. It applies only the group change and leaves user ownership intact, which is precisely what the scenario requires. chown with a bare name targets the user, chmod alters permissions rather than ownership, and usermod operates on account definitions instead of filesystem objects.

Exam trap

The trap here is assuming chown with a single name sets the group, when it actually sets the user owner.

34
Multi-Selecteasy

Which TWO commands can be used to display the current working directory?

Select 2 answers
A.which pwd
B.pwd
C.date
D.echo $PWD
E.whoami
AnswersB, D

pwd is the shell builtin that prints the absolute pathname of the current working directory, directly satisfying the requirement to display it. It reads the shell's tracked directory state rather than resolving a path argument.

Why this answer

Option B, `pwd`, is correct because it is the dedicated shell builtin/utility that prints the absolute pathname of the current working directory. Option D, `echo $PWD`, is correct because the shell maintains the `PWD` environment variable holding the current working directory, and `echo` expands it to display that path. Option A, `which pwd`, only locates the executable or builtin for `pwd` and prints its path rather than the working directory.

Option C, `date`, displays the current system date and time, and option E, `whoami`, prints the effective username — neither relates to the working directory.

Exam trap

Linux Foundation often tests the distinction between commands that display the working directory and commands that merely locate or describe other things, tricking candidates into selecting `which pwd` because it contains the letters 'pwd'.

35
MCQmedium

A technician must create a hard link named 'report_link' to an existing file '/data/report.txt'. Which command should be used?

A.cp /data/report.txt report_link
B.ln /data/report.txt report_link
C.mv /data/report.txt report_link
D.ln -s /data/report.txt report_link
AnswerB

Without any options, ln creates a hard link. This command creates a hard link named report_link that points to the same inode as /data/report.txt. Both names refer to the same file data, and changes through either name are reflected in the other.

Why this answer

The ln command without options creates a hard link by default. This results in two directory entries pointing to the same inode, which is exactly what a hard link is. The other commands either create symbolic links, copies, or rename the file, none of which produce a hard link as required.

Exam trap

The trap here is assuming that ln always creates symbolic links; actually, the -s option is needed for symbolic links, while the default is hard links.

36
MCQmedium

A system administrator has a cron job that runs a backup script. The script requires the variable BACKUP_DIR to be set, but the administrator cannot modify the script. Which is the most appropriate place to define the variable for cron?

A.In the crontab file with the line 'BACKUP_DIR=/var/backups' before the command
B.In /etc/profile.d/backup.sh
C.In /etc/environment
D.In ~/.bash_profile
AnswerA

Crontab variable assignments are parsed by cron itself and exported into the job's environment, so BACKUP_DIR reaches the script without editing it. Shell profile files are not sourced for cron jobs, and the script cannot be modified per the stem's constraint.

Why this answer

Cron jobs run in a minimal environment and do not source shell profiles or login scripts. Defining BACKUP_DIR directly in the crontab file before the command ensures the variable is set in the cron execution context, which is the only reliable way to pass environment variables to cron without modifying the script.

Exam trap

The trap here is that candidates assume cron inherits the user's login environment or sources profile files, but cron explicitly does not, making inline crontab variable definitions the only correct approach.

How to eliminate wrong answers

Option B is wrong because /etc/profile.d/ scripts are sourced only by interactive login shells, not by cron, which uses a non-interactive, non-login shell. Option C is wrong because /etc/environment is read by PAM (pam_env.so) during login sessions, but cron does not use PAM for environment setup. Option D is wrong because ~/.bash_profile is sourced only for interactive login shells, and cron does not invoke a login shell.

37
MCQhard

You are a system administrator for a company that runs a web server on a Linux system. The web server logs are stored in /var/log/nginx/access.log. The log file grows rapidly and rotates weekly via logrotate. The system has been running for several months. Recently, the development team reported that the web server is responding slowly. You suspect that the disk I/O might be high due to log file activity. You check the disk usage and find that /var/log/nginx/access.log is 4 GB, and the rotated logs (access.log.1.gz, access.log.2.gz, etc.) total another 10 GB. The /var partition has 20 GB total, so it's 70% full. You decide to reduce the disk usage by compressing the current log file and truncating it without stopping the nginx service. Which command sequence should you use to safely achieve this?

A.:> /var/log/nginx/access.log && cp /var/log/nginx/access.log /var/log/nginx/access.log.bak && gzip /var/log/nginx/access.log.bak
B.cp /var/log/nginx/access.log /var/log/nginx/access.log.bak && :> /var/log/nginx/access.log && gzip /var/log/nginx/access.log.bak
C.rm /var/log/nginx/access.log && touch /var/log/nginx/access.log && chmod 644 /var/log/nginx/access.log
D.mv /var/log/nginx/access.log /var/log/nginx/access.log.bak && touch /var/log/nginx/access.log && gzip /var/log/nginx/access.log.bak
AnswerB

Copying the log preserves its contents, then truncating with ':>' empties the original inode while nginx keeps writing to it, and gzip compresses the backup. This satisfies the constraint of compressing and truncating without stopping nginx, avoiding the inode-swap problem that 'mv' would cause.

Why this answer

It first copies the current log file to a backup, then truncates the original file in place using the shell null command (`:>`) without stopping nginx, and finally compresses the backup. This ensures nginx continues writing to the same inode (file descriptor remains valid) and the disk space is reclaimed after compression.

Exam trap

The trap here is that candidates often choose `mv` and `touch` (Option D) thinking it's the standard logrotate method, but without signaling nginx, the old file descriptor remains attached to the moved file, causing the new empty file to be ignored and log data to be written to the renamed file instead.

How to eliminate wrong answers

Option A is wrong because it truncates the log file before copying it, resulting in an empty backup and loss of log data. Option C is wrong because `rm` removes the file entirely, breaking nginx's open file descriptor and causing it to log to a deleted inode until restarted; `touch` creates a new file with a different inode, and the permission reset is unnecessary. Option D is wrong because `mv` moves the file to a new name, which changes the inode; nginx continues writing to the old inode (now renamed), and the new `touch`ed file is not used until nginx is restarted or signaled, causing log loss or misdirection.

38
MCQmedium

A backup script must create a compressed archive of the /etc directory, preserving file permissions and timestamps. Which command should be used?

A.gzip -r /etc > backup.tar.gz
B.cpio -ov < /etc > backup.cpio
C.rsync -av /etc /backup/etc
D.tar -czvf backup.tar.gz /etc
AnswerD

tar with -czvf creates a gzipped archive preserving permissions and timestamps.

Why this answer

The `tar -czvf` command creates a compressed archive (via gzip) that preserves file permissions and timestamps by default when run as root. The `-c` flag creates the archive, `-z` compresses it with gzip, `-v` provides verbose output, and `-f` specifies the archive filename. Tar is the standard Unix tool for bundling files into a single archive while retaining metadata like ownership, permissions, and timestamps.

Exam trap

The trap here is that candidates confuse `gzip` (which compresses individual files) with `tar` (which archives directories), or they think `rsync` creates an archive file when it actually creates a directory copy, not a compressed archive.

How to eliminate wrong answers

Option A is wrong because `gzip -r` recursively compresses individual files in place, not creating a single archive; it would replace each file with a .gz version, losing the directory structure and not preserving permissions in a bundled format. Option B is wrong because `cpio -ov < /etc` reads from stdin, but `/etc` is a directory, not a file list; cpio requires a list of files piped via `find` or similar, and without `--preserve-modification-time` it does not preserve timestamps by default. Option C is wrong because `rsync -av` synchronizes files to a destination directory, not creating a single compressed archive file; it preserves permissions and timestamps but produces a directory copy, not a portable archive like tar.gz.

39
MCQeasy

Which command displays the amount of free and used memory in the system?

A.free -h
B.df -h
C.ps aux
D.netstat -i
AnswerA

`free -h` reads `/proc/meminfo` and reports total, used, free, shared, buffer/cache and available memory, with the `-h` flag scaling values into human-readable units. This directly satisfies the stem's requirement to display free and used memory amounts, unlike commands showing process or disk statistics.

Why this answer

The `free -h` command displays the total, used, and free physical memory (RAM) and swap space in a human-readable format (e.g., GiB, MiB). The `-h` flag converts raw byte counts into appropriate units, making it the correct tool for checking memory usage.

Exam trap

The trap here is that candidates confuse `df` (disk free) with `free` (memory free) due to similar names, or assume `ps aux` shows total memory usage when it only shows per-process values.

How to eliminate wrong answers

Option B is wrong because `df -h` reports disk filesystem usage (mounted partitions), not memory. Option C is wrong because `ps aux` lists running processes and their resource usage (CPU, memory per process), not the system-wide free and used memory totals. Option D is wrong because `netstat -i` displays network interface statistics (packets, errors, collisions), not memory information.

40
MCQeasy

A junior administrator needs to create a new empty file named report.txt in the current working directory. They want to ensure that if the file already exists, its contents are not altered. Which command should they run?

A.mkdir report.txt
B.echo > report.txt
C.cat > report.txt
D.touch report.txt
AnswerD

The touch command updates the access and modification timestamps of report.txt, and if the file does not exist, it creates an empty file. It does not modify the file's contents if it already exists, so it safely meets the requirement without risking data loss.

Why this answer

The touch command is designed to create empty files or update timestamps without modifying existing content. Redirection methods like echo > or cat > would truncate the file if it already exists, risking data loss. mkdir creates a directory, not a file. Therefore, touch is the correct choice for safely creating an empty file.

Exam trap

The trap here is assuming that any command that creates a file will also safely leave existing content untouched, when in fact redirection operators truncate files by default.

41
MCQmedium

An administrator runs `ls -l` and sees a file entry whose permission string begins with a lowercase `l`. What does this indicate about the entry?

A.It is a symbolic link whose target is resolved when the link is accessed.
B.It is a named pipe used for inter-process communication.
C.It is a regular file that has the setuid bit enabled.
D.It is a block device node used for buffered disk access.
AnswerA

A leading l in the file type column denotes a symbolic link, a special file holding a pathname that the kernel resolves at access time. Unlike hard links, a symlink has its own inode and can point across filesystems, and it becomes dangling if the target path no longer exists.

Why this answer

The first character of the permission string encodes file type, and l specifically means symbolic link. Device nodes, regular files, and FIFOs each have their own distinct type character, so recognizing the type column is essential before choosing commands such as readlink, stat, or find -type l.

Exam trap

The trap here is reading the leading character as a permission rather than a file type indicator.

42
MCQmedium

A junior admin runs 'ls -l' and sees permissions '-rwxrwxr-x' on a file. What is the octal representation?

A.755
B.770
C.775
D.777
AnswerC

The symbolic string `-rwxrwxr-x` maps each permission triad to its octal digit: owner `rwx` equals 7, group `rwx` equals 7, and others `r-x` equals 5, giving 775. This directly satisfies the stem's requirement to convert the displayed mode into its octal equivalent.

Why this answer

The permissions '-rwxrwxr-x' break down as: owner (rwx = 4+2+1 = 7), group (rwx = 4+2+1 = 7), others (r-x = 4+0+1 = 5). This gives the octal value 775. Option C is correct because it matches this calculation exactly.

Exam trap

The trap here is that candidates often misread the last three characters 'r-x' as 'rwx' or 'r--', leading them to choose 777 or 755 instead of correctly calculating 775.

How to eliminate wrong answers

Option A (755) is wrong because it represents owner rwx (7), group r-x (5), others r-x (5), which would require group permissions to be r-x, not rwx. Option B (770) is wrong because it represents owner rwx (7), group rwx (7), others --- (0), which would deny all permissions to others, but the file shows r-x for others. Option D (777) is wrong because it represents owner rwx (7), group rwx (7), others rwx (7), which would give write permission to others, but the file shows r-x (no write) for others.

43
Multi-Selecteasy

Which TWO commands can be used to display the contents of a text file that has been compressed with gzip without decompressing it to disk?

Select 2 answers
A.xzcat file.gz
B.gzip -l file.gz
C.zcat file.gz
D.gunzip -c file.gz
E.bzcat file.gz
AnswersC, D

`zcat` decompresses gzip data to standard output, leaving the `.gz` file untouched on disk. This satisfies the stem's constraint of viewing contents without writing a decompressed copy, streaming the uncompressed bytes straight to the terminal for inspection.

Why this answer

Option C, zcat file.gz, is correct because zcat is functionally equivalent to gunzip -c and writes the decompressed contents of a gzip file directly to standard output, leaving no decompressed file on disk. Option D, gunzip -c file.gz, is correct because the -c (--stdout) flag tells gunzip to send the decompressed data to standard output instead of replacing the .gz file with an uncompressed one. Option A, xzcat file.gz, is wrong because xzcat handles files compressed with xz/lzma, not gzip format.

Option B, gzip -l file.gz, is wrong because -l only lists the compressed and uncompressed sizes and ratio; it does not display the file's contents. Option E, bzcat file.gz, is wrong because bzcat decompresses bzip2 files, not gzip files.

Exam trap

The trap here is that candidates often confuse compression tools and their corresponding cat utilities (e.g., `xzcat` for xz, `bzcat` for bzip2, `zcat` for gzip), leading them to select a command that works on a different compression format.

44
MCQmedium

A support engineer must copy the directory /srv/appdata, including every subdirectory, hidden file, and preserved permission bits and timestamps, to /backup/appdata on the same host. Which command accomplishes this?

A.mv /srv/appdata /backup/appdata
B.rsync /srv/appdata /backup/appdata
C.cp -a /srv/appdata /backup/appdata
D.cp -r /srv/appdata /backup/appdata
AnswerC

The -a flag is archive mode, equivalent to -dR --preserve=all, so it recurses into subdirectories, copies symlinks as symlinks, and preserves mode, ownership where permitted, timestamps, and extended attributes. That matches the requirement to retain hidden files, permissions, and times in a single invocation on the same host.

Why this answer

Archive-mode copy is the correct tool when a directory tree must be duplicated with metadata intact, since it combines recursion with preservation of permissions, ownership, timestamps, and symlink structure. Recursive-only copy drops metadata, relocation deletes the source, and a bare rsync invocation without archive or recursive flags will not descend into directories.

Exam trap

The trap here is assuming any recursive copy preserves metadata, when only archive mode does so reliably.

45
Multi-Selectmedium

Which TWO commands can be used to display the contents of a text file page by page? (Select two.)

Select 2 answers
A.cat file.txt
B.head file.txt
C.more file.txt
D.less file.txt
E.tail file.txt
AnswersC, D

`more file.txt` paginates output, displaying one screenful at a time and pausing for user input before continuing. This directly satisfies the stem's requirement to view a text file page by page, unlike non-paginating tools such as `cat`, which dump the entire file at once.

Why this answer

Option C, more file.txt, is correct because more is a pager that displays a text file one screenful at a time, pausing at each page until the user presses Space or Enter to continue. Option D, less file.txt, is also correct because less is a more advanced pager that likewise presents file contents page by page, while additionally allowing backward scrolling and searching. Both commands satisfy the requirement of paging through a file's contents rather than dumping them all at once.

In contrast, A (cat file.txt) writes the entire file to standard output in one continuous stream, B (head file.txt) shows only the first 10 lines by default, and E (tail file.txt) shows only the last 10 lines by default, so none of these paginate the output.

Exam trap

The trap here is that candidates might confuse `cat` (which dumps all content) with a pager, or think `head` or `tail` can show the entire file page by page, but they only show a fixed number of lines from the beginning or end.

46
MCQhard

A systems administrator needs to add a new user 'jdoe' with a home directory in /export/home, a UID of 1500, and an expiry date of 2025-12-31. Which command should they use?

A.useradd -u 1500 -d /export/home/jdoe -e 2025-12-31 jdoe
B.useradd -u 1500 -d /export/home/jdoe -c 2025-12-31 jdoe
C.useradd -u 1500 -m -e 2025-12-31 jdoe
D.useradd -u 1500 -b /export/home -e 2025-12-31 jdoe
AnswerA

useradd accepts -u for the UID, -d for the home directory path and -e for the account expiry date, so all three constraints are set in one invocation. The path must be given explicitly since /export/home is not the default parent.

Why this answer

The `useradd` command with `-u 1500` sets the UID, `-d /export/home/jdoe` explicitly specifies the home directory path (without creating it unless `-m` is also used), and `-e 2025-12-31` sets the account expiry date in YYYY-MM-DD format. This matches all requirements: UID 1500, home directory at /export/home/jdoe, and expiry on 2025-12-31.

Exam trap

The trap here is confusing the `-c` (comment) option with `-e` (expiry) and assuming `-b` (base directory) works the same as `-d` (explicit home directory), leading candidates to pick options that set the wrong field or fail to place the home directory in the specified path.

How to eliminate wrong answers

Option B is wrong because `-c` is used to set the GECOS comment field (e.g., full name), not the expiry date; using `-c 2025-12-31` would incorrectly store the date as a comment. Option C is wrong because `-m` creates the home directory in the default base directory (usually /home), not in /export/home, and omits the explicit `-d` path, so the home directory would be /home/jdoe instead of /export/home/jdoe. Option D is wrong because `-b /export/home` sets the default base directory for new users, but without `-d` the home directory would be /export/home/jdoe only if the default naming convention is used; however, `-b` does not override the need for `-d` to explicitly set the path, and the command as written would still create /export/home/jdoe, but the option `-b` is intended for setting a system-wide default, not for specifying an individual user's home directory — the correct approach for a single user is `-d`.

47
MCQhard

A storage administrator needs to identify which filesystem is mounted at /mnt/data and display the mount options currently in effect for it, using a single command that reads the kernel mount table. Which command should be used?

A.blkid /mnt/data
B.findmnt /mnt/data
C.lsblk /mnt/data
D.df -h /mnt/data
AnswerB

This is correct because findmnt reads /proc/self/mountinfo and prints the matching mount entry, including the source device, filesystem type, and the full option list in the OPTIONS column. It directly answers which filesystem is mounted and what options are active for that specific mount point.

Why this answer

The kernel mount table contains the authoritative record of what is mounted and with which options. findmnt queries that table and filters by mount point, displaying the source, target, filesystem type, and options. df and lsblk report capacity or topology, and blkid identifies filesystem signatures, but none of them show the active mount options for a given mount point.

Exam trap

The trap here is reaching for df to inspect a mount, when df reports space usage rather than the mount options recorded in the kernel table.

48
MCQmedium

A user is unable to write to a file. The output of 'ls -l file' shows '-r--r--r--'. Which command will grant write permission to the owner?

A.chmod o+w file
B.chmod u+w file
C.chmod a+w file
D.chmod g+w file
AnswerB

The file mode `-r--r--r--` gives the owner read-only access, so write permission must be added to the user (owner) class. `chmod u+w file` adds write to the owner triad while leaving group and other bits untouched, satisfying the requirement without altering existing read permissions.

Why this answer

The file's permissions are '-r--r--r--', meaning the owner has only read permission. The 'chmod u+w file' command adds write permission for the owner (u) because 'u' refers to the user/owner. This directly addresses the owner's lack of write access.

Exam trap

The trap here is that candidates often confuse 'u' (owner) with 'o' (others) or mistakenly use 'a' (all) when only owner write is needed, leading to incorrect or overly permissive commands.

How to eliminate wrong answers

Option A is wrong because 'o+w' adds write permission for 'others', not the owner, so the owner still cannot write. Option C is wrong because 'a+w' adds write permission for all categories (owner, group, others), which is overly permissive and not the minimal command to grant write access only to the owner. Option D is wrong because 'g+w' adds write permission for the group, not the owner, leaving the owner's permissions unchanged.

49
MCQmedium

A developer reports that a compiled binary 'app' fails to execute with 'Permission denied' error when run from a mounted directory '/mnt/software'. The binary has execute permissions for all users. What is the most likely cause?

A.SELinux is blocking execution.
B.The binary is linked against missing libraries.
C.The filesystem is mounted with the 'noexec' option.
D.The binary is setuid but owned by a user other than root.
AnswerC

The noexec mount option blocks execution of binaries on that filesystem regardless of their permission bits, producing 'Permission denied'. Since execute permissions are already set for all users, the mount flag is the remaining cause.

Why this answer

The 'noexec' mount option prevents execution of any binary files on the filesystem, regardless of their file permissions. When a filesystem is mounted with 'noexec', the kernel will refuse to execute binaries from that mount point, returning 'Permission denied' even if the binary has execute permissions for all users. This is a common security measure for mounted directories like /mnt/software to prevent unauthorized code execution.

Exam trap

The trap here is that candidates often assume 'Permission denied' always relates to file permissions (chmod) or SELinux, but the LFCS exam tests knowledge of mount options like 'noexec' which silently override file-level permissions at the filesystem level.

How to eliminate wrong answers

Option A is wrong because SELinux blocking execution would typically produce an AVC denial message in the audit log and a different error (e.g., 'Operation not permitted' or 'Permission denied' with a SELinux context mismatch), but the question states the binary has execute permissions for all users, and SELinux would not be the most likely cause without additional context like a targeted policy. Option B is wrong because missing libraries cause a 'cannot open shared object file' or 'No such file or directory' error, not 'Permission denied'. Option D is wrong because a setuid binary owned by a non-root user would still execute (though the setuid bit would be ignored for security reasons), and the error would not be 'Permission denied' unless the binary itself lacks execute permissions, which it does not.

50
MCQeasy

A user wants to find the location of the 'grep' binary. Which command should they use?

A.man grep
B.which grep
C.uname -a
D.grep -r 'grep' /usr/bin
AnswerB

The which command searches the directories listed in the PATH environment variable and returns the full path of the first matching executable. This directly locates the grep binary's filesystem location, satisfying the user's requirement without invoking or executing it.

Why this answer

The 'which' command is specifically designed to locate the binary (executable) of a command by searching the directories listed in the user's PATH environment variable. Option B, 'which grep', will output the full path to the grep binary, such as '/usr/bin/grep', directly answering the user's request.

Exam trap

The trap here is that candidates may confuse documentation commands (man) or system information commands (uname) with binary location commands, or mistakenly think a recursive grep search is an efficient way to find a binary, when 'which' is the standard, straightforward tool for this task.

How to eliminate wrong answers

Option A is wrong because 'man grep' displays the manual page for grep, which provides documentation and usage information, not the filesystem location of the binary. Option C is wrong because 'uname -a' prints system information (kernel name, hostname, kernel release, etc.), which is unrelated to locating a command's binary. Option D is wrong because 'grep -r' performs a recursive text search for the string 'grep' within files under /usr/bin, which is inefficient, may return many irrelevant matches, and does not reliably identify the grep binary itself.

51
MCQeasy

A user needs to view the contents of a compressed log file /var/log/syslog.gz without first decompressing it. Which command should they use?

A.zcat /var/log/syslog.gz
B.gzip -d /var/log/syslog.gz
C.gunzip /var/log/syslog.gz
D.cat /var/log/syslog.gz
AnswerA

`zcat` decompresses gzip data to standard output, so the file's contents appear on screen without altering the original `.gz` file on disk. This satisfies the stem's constraint of viewing without prior decompression, unlike `gunzip`, which removes the archive, or `cat`, which would emit raw compressed bytes.

Why this answer

`zcat` is specifically designed to read the contents of gzip-compressed files without permanently decompressing them. It decompresses the data on the fly and sends the output to stdout, allowing the user to view the log file's contents directly from the terminal.

Exam trap

The trap here is that candidates may confuse commands that permanently decompress files (like `gzip -d` or `gunzip`) with commands that only display the contents, leading them to choose an option that alters the file system state instead of just viewing the data.

How to eliminate wrong answers

Option B is wrong because `gzip -d` permanently decompresses the file, replacing `syslog.gz` with an uncompressed `syslog` file, which alters the original compressed archive. Option C is wrong because `gunzip` is equivalent to `gzip -d` and also permanently decompresses the file, removing the `.gz` version. Option D is wrong because `cat` reads raw binary data and will output garbled, unreadable content when applied to a gzip-compressed file, as it does not perform any decompression.

52
MCQeasy

To compress a file while preserving the original file, which command should be used?

A.gzip file.txt
B.gzip -d file.txt.gz
C.gzip -1 file.txt
D.gzip -k file.txt
AnswerD

The `-k` flag instructs gzip to retain the source file after compression, directly satisfying the stem's requirement to preserve the original. Without it, gzip deletes `file.txt` and leaves only `file.txt.gz`. This makes `gzip -k file.txt` the precise command for producing a compressed copy while keeping the original intact.

Why this answer

The `-k` (or `--keep`) flag in `gzip` instructs the utility to compress the file while retaining the original uncompressed file. By default, `gzip` replaces the original file with a compressed version (appending `.gz`), so `-k` is the explicit option to preserve the source file.

Exam trap

Linux Foundation often tests the default behavior of `gzip` (which deletes the original) versus the `-k` flag, trapping candidates who assume compression always preserves the source file without an explicit option.

How to eliminate wrong answers

Option A is wrong because `gzip file.txt` compresses the file and, by default, deletes the original `file.txt`, leaving only `file.txt.gz`. Option B is wrong because `gzip -d file.txt.gz` decompresses the archive, which does not compress a file and also removes the `.gz` file unless `-k` is used. Option C is wrong because `gzip -1 file.txt` sets the compression level to fastest (level 1), but still removes the original file; the `-1` flag does not affect file preservation.

53
MCQeasy

Refer to the exhibit. The /var partition is 100% full. Which command can be used to find the largest files in /var/log to free up space?

A.ls -lS /var/log
B.find /var/log -size +100M
C.du -ah /var/log | sort -rh | head
D.df -h /var/log
AnswerC

Sorting by human-readable size in reverse order surfaces the largest entries first, satisfying the need to reclaim space in the full /var partition. The -a flag includes files as well as directories, so head returns the biggest space consumers in /var/log.

Why this answer

It uses `du -ah` to list all files and directories in /var/log with human-readable sizes, pipes the output to `sort -rh` to sort them in reverse numerical order (largest first), and then uses `head` to display only the top entries. This combination efficiently identifies the largest files consuming space, allowing the administrator to target specific files for cleanup.

Exam trap

The trap here is that candidates may choose `ls -lS` (option A) because it sorts by size, but they overlook that it does not recurse into subdirectories, making it ineffective for a directory tree like /var/log that typically contains multiple subdirectories.

How to eliminate wrong answers

Option A is wrong because `ls -lS /var/log` lists files sorted by size, but it does not recurse into subdirectories, so it will miss large files in subdirectories like /var/log/journal or /var/log/nginx. Option B is wrong because `find /var/log -size +100M` only finds files larger than 100 MB, but the /var partition could be full due to many smaller files accumulating to fill the space, and it does not sort or prioritize the largest files. Option D is wrong because `df -h /var/log` shows the disk usage of the /var/log filesystem (or partition), not the sizes of individual files, so it cannot identify which files to delete.

54
MCQhard

A system administrator configures a new server with multiple disks. After partitioning and formatting, they mount a partition to /data. Several days later, they notice that the /data filesystem is full, but 'du -sh /data' reports only 2 GB used, while the partition is 100 GB. 'df -h' shows /data is 98% full. What is the most likely cause and the correct action?

A.The filesystem is fragmented. Run 'e4defrag' to defragment.
B.The filesystem has reserved blocks for root. Reduce the reserved percentage with 'tune2fs -m 0'.
C.The 'du' command is not counting hidden files (dot files). Use 'du -sh .*' to include them.
D.There are deleted files still held open by processes. Use 'lsof /data' to find and restart those processes.
AnswerD

Deleted files still held open by running processes keep their blocks allocated, so df reports the space consumed while du cannot see the unlinked inodes. lsof /data identifies the offending processes; restarting them releases the file descriptors and reclaims the 96 GB discrepancy.

Why this answer

When a file is deleted but still held open by a running process, the filesystem does not release the disk blocks until the process closes the file descriptor. This causes 'df' to report the space as used, while 'du' cannot see the deleted file's data, leading to the discrepancy. Using 'lsof /data' identifies the processes holding the deleted files, and restarting them frees the space.

Exam trap

The trap here is that candidates often confuse the 'du' vs 'df' discrepancy with hidden files or reserved blocks, but the key clue is that 'du' shows far less usage than 'df', which points to unlinked but still-open files.

How to eliminate wrong answers

Option A is wrong because filesystem fragmentation does not cause a discrepancy between 'du' and 'df'; fragmentation affects performance, not space accounting. Option B is wrong because reserved blocks for root (default 5% on ext4) are counted as used by 'df' but are not the cause of a 98% full partition when only 2 GB is used; reducing the reserved percentage would free space but does not explain the discrepancy. Option C is wrong because 'du -sh /data' already counts all files including hidden files (dot files) by default; the '-sh' option sums the total size, and hidden files are included in that total.

55
MCQmedium

A system administrator needs to list all files in the current directory, including hidden files, in a long listing format sorted by modification time (oldest first). Which command achieves this?

A.ls -lihrt
B.ls -lart
C.ls -lat
D.ls -lrt
AnswerB

Correct: long, all, reverse, time.

Why this answer

`ls -lart` combines the `-l` (long listing), `-a` (include hidden files starting with dot), `-r` (reverse order), and `-t` (sort by modification time, newest first). The reverse flag flips the sort to oldest first, meeting the requirement exactly.

Exam trap

The trap here is that candidates often remember `-lt` for time-sorted listing but forget that `-a` is required to include hidden files, or they confuse the order and omit `-r` to reverse to oldest first.

How to eliminate wrong answers

Option A is wrong because `ls -lihrt` includes `-i` (inode number) and `-h` (human-readable sizes), which are not requested, and while it sorts by time and reverses, it lacks `-a` so hidden files are omitted. Option C is wrong because `ls -lat` sorts by modification time but newest first, not oldest first, as the `-r` flag is missing. Option D is wrong because `ls -lrt` sorts by time and reverses to oldest first, but it lacks `-a`, so hidden files are not listed.

56
MCQeasy

A user needs to view the contents of a large text file one screen at a time. Which command is best for this?

A.nl file.txt
B.more file.txt
C.cat file.txt
D.less file.txt
AnswerD

'less' opens the file in a pager, letting the user scroll forward and backward one screen at a time without loading the whole file into memory. This suits large files where 'cat' would flood the terminal.

Why this answer

`less` is a terminal pager that allows forward and backward navigation through a file, making it ideal for viewing large text files one screen at a time. Unlike `more`, `less` supports scrolling both up and down, and it does not load the entire file into memory, which is efficient for large files.

Exam trap

The trap here is that candidates often confuse `more` and `less` because both display content one screen at a time, but `less` is the more powerful and recommended tool for interactive viewing, and the LFCS exam expects you to know that `less` is the best choice for this task.

How to eliminate wrong answers

Option A is wrong because `nl` numbers lines and outputs the entire file to stdout without pausing, so it is not suitable for viewing one screen at a time. Option B is wrong because while `more` does display content one screen at a time, it only allows forward navigation (space bar) and cannot scroll backward, making it less flexible than `less` for interactive viewing. Option C is wrong because `cat` concatenates and outputs the entire file to stdout at once, which will flood the terminal and is not designed for paging.

57
Multi-Selecthard

Which THREE commands can change the priority of an already running process?

Select 3 answers
A.kill -STOP
B.top (press 'r')
C.chrt
D.nice
E.renice
AnswersB, C, E

Pressing 'r' inside top prompts for a PID and a nice value, then calls setpriority() on that running process. This satisfies the stem's requirement to alter priority of an already running process, unlike commands that only set priority at launch.

Why this answer

Option B (top, press 'r') is correct because within the interactive top utility, pressing 'r' prompts for a PID and a new nice value, allowing you to renice an already running process on the fly. Option C (chrt) is correct because chrt sets or changes the scheduling policy and real-time priority of a running process by PID (e.g., chrt -p -f 10 <pid>), directly altering its priority attributes. Option E (renice) is correct because renice is specifically designed to change the nice value of one or more running processes (renice -n 5 -p <pid>), which adjusts their CPU scheduling priority.

Option A (kill -STOP) is incorrect because it only suspends a process with SIGSTOP and does not modify its priority. Option D (nice) is incorrect because nice only launches a new command with a specified nice value; it cannot change the priority of an already running process.

Exam trap

The trap here is that candidates often confuse `nice` (which only sets priority for new processes) with `renice` (which modifies running processes), or mistakenly think `kill -STOP` changes priority when it actually halts the process.

58
MCQmedium

What is the purpose of the chmod 755 command in this exhibit?

A.Add execute permission for the owner only
B.Remove write permission for others
C.Set the setuid bit
D.Set permissions to rwxr-xr-x
AnswerD

Numeric mode 755 grants the owner read, write and execute (7), and group and others read and execute (5), producing rwxr-xr-x. This satisfies the requirement to translate the octal permission value into its symbolic equivalent.

Why this answer

The chmod 755 command sets the file permissions to rwxr-xr-x, meaning the owner has read, write, and execute permissions (7), while the group and others have read and execute permissions (5). This is a common permission set for executable scripts and directories to allow execution without granting write access to non-owners.

Exam trap

The trap here is that candidates often confuse the octal value 755 with adding execute only for the owner (option A) or think it removes write for others (option B), when in fact 755 sets a specific permission mask that includes execute for all and write only for the owner.

How to eliminate wrong answers

Option A is wrong because chmod 755 adds execute permission for the owner, group, and others, not just the owner. Option B is wrong because chmod 755 does not remove write permission for others; it sets the others permission to r-x (read and execute), which already excludes write, but the command is not specifically removing write—it is setting the entire permission triad. Option C is wrong because the setuid bit is set using chmod 4xxx (e.g., chmod 4755), not chmod 755, which uses the octal value 0 for the setuid/setgid/sticky bits.

59
Multi-Selectmedium

A system administrator needs to change the group ownership of a file to 'developers' and set the setgid bit on a directory. Which two commands accomplish these tasks? (Choose two.)

Select 2 answers
A.chmod g+s dir
B.chmod u+s dir
C.chown developers: file
D.chown :developers file
E.chmod g+s file
AnswersA, D

The setgid bit on a directory is set with chmod g+s, which makes new files inherit the directory's group. This satisfies the requirement to set the setgid bit on the directory, distinct from changing group ownership of a file.

Why this answer

Option A, 'chmod g+s dir', is correct because the g+s symbolic mode sets the setgid bit on the directory, causing new files and subdirectories created inside it to inherit the directory's group ownership. Option D, 'chown :developers file', is correct because omitting the user and specifying only ':developers' changes the file's group ownership to the 'developers' group while leaving the owner unchanged. Option B, 'chmod u+s dir', is wrong because u+s sets the setuid bit on the owner, not the setgid bit, and setuid on a directory is generally ignored on Linux.

Option C, 'chown developers: file', is wrong because it sets the user owner to 'developers' rather than the group owner. Option E, 'chmod g+s file', is wrong because the task requires setting setgid on a directory, not on a file.

Exam trap

Linux Foundation often tests the distinction between setting the setgid bit on a directory versus a file, and the correct syntax for changing group ownership with `chown :group` versus `chown group:`.

60
Multi-Selecthard

Which TWO commands can be used to display the current working directory? (Choose exactly two.)

Select 2 answers
A.ls
B.echo $PWD
C.pwd
D.dirname
E.cd
AnswersB, C

Correct: prints the PWD variable.

Why this answer

The shell stores the current working directory path in the environment variable `$PWD`, and `echo $PWD` prints its value. This is a reliable way to display the current directory, as the shell updates `PWD` automatically on every `cd` command.

Exam trap

The trap here is that candidates may confuse `ls` (which lists files) with displaying the current directory path, or think `dirname` or `cd` can show the current directory without additional arguments.

61
MCQhard

A security audit reveals that a sensitive file '/etc/shadow' has been modified. The file's permissions are set to 600 and owned by root. However, the audit logs show that a service account 'webapp' was able to read the file. The 'webapp' user is not in the root group. Which of the following is the most likely method the 'webapp' user used to read the file?

A.The file is a hard link to another file that is readable by 'webapp'.
B.The 'webapp' user exploited a SUID binary that reads the file.
C.The file has an Access Control List (ACL) granting read permission to 'webapp'.
D.The 'webapp' user used 'sudo' to read the file as root.
AnswerC

Standard mode bits grant root read access only, and webapp is not in the root group, so the read must come from an extended permission. A POSIX ACL entry granting webapp read on /etc/shadow explains the access without changing ownership or mode.

Why this answer

An Access Control List (ACL) can grant specific permissions to a user or group beyond the traditional Unix permission model. Even though the file's mode is 600 (owner read/write only) and owned by root, a setfacl command could have added an ACL entry (e.g., 'u:webapp:r') that explicitly allows the 'webapp' user to read /etc/shadow. This is a common method to give a service account access to a sensitive file without changing its ownership or group membership.

Exam trap

The trap here is that candidates assume traditional Unix permissions (owner/group/other) are the only way to control access, overlooking that ACLs can grant specific users read permission even when the file's mode appears restrictive (e.g., 600).

How to eliminate wrong answers

Option A is wrong because a hard link shares the same inode and permissions as the original file; if /etc/shadow is mode 600 and owned by root, any hard link to it would also be mode 600 and owned by root, so 'webapp' could not read it via a hard link unless an ACL or other mechanism grants access. Option B is wrong because a SUID binary runs with the effective UID of the binary's owner (typically root), but the audit logs show 'webapp' read the file, not a SUID binary; the question asks how 'webapp' read the file, not how a binary accessed it on behalf of 'webapp'. Option D is wrong because using 'sudo' to read a file as root would require the 'webapp' user to have sudo privileges (e.g., an entry in /etc/sudoers), which is a separate configuration; the question does not indicate any sudo access, and the most likely method given the scenario is an ACL, not sudo.

62
MCQmedium

A security analyst needs to search for the literal string 'error: failed to connect' in all .log files under /var/log, including subdirectories. The search should be case-insensitive and display line numbers. Which command should they use?

A.grep -rin "error: failed to connect" /var/log/*.log
B.grep -rin "error: failed to connect" /var/log --exclude='*.log'
C.grep -rl "error: failed to connect" /var/log
D.grep -rin "error: failed to connect" /var/log --include='*.log'
AnswerD

grep -r searches recursively, -i ignores case, and -n shows line numbers. The --include option limits the search to files matching the glob '*.log', which precisely targets .log files in /var/log and its subdirectories. This satisfies all requirements: case-insensitive, recursive, and line numbers.

Why this answer

To recursively search only .log files with case-insensitivity and line numbers, use grep with -r, -i, -n, and --include. The --include='*.log' ensures only files with that extension are processed, while -r traverses subdirectories. This combination meets all stated requirements.

Exam trap

The trap here is assuming that a shell glob like /var/log/*.log works recursively; it does not, so --include is needed.

63
MCQeasy

A junior administrator needs to create a symbolic link named /usr/local/bin/editor that points to /opt/tools/vim.bin. The link must be created without overwriting any existing file at the destination. Which command accomplishes this?

A.ln /opt/tools/vim.bin /usr/local/bin/editor
B.ln -sf /opt/tools/vim.bin /usr/local/bin/editor
C.cp -s /opt/tools/vim.bin /usr/local/bin/editor
D.ln -s /opt/tools/vim.bin /usr/local/bin/editor
AnswerD

The ln -s command creates a symbolic link, and because the destination path does not exist yet, the link is created cleanly without touching any existing file. This matches the requirement exactly: a symbolic link at the specified path pointing to the target binary, with no overwrite behavior needed.

Why this answer

Creating a symbolic link is done with ln -s target linkname. Because the destination does not exist, no force flag is required and the command completes without overwriting anything. The hard-link variant lacks -s and would not produce a symbolic link, while the forced variant introduces overwrite risk that the scenario explicitly forbids.

Exam trap

The trap here is assuming that ln without -s still creates a symbolic link, when it actually creates a hard link.

64
MCQmedium

A developer wants to change the ownership of a directory and all its contents recursively to user 'appuser' and group 'appgroup'. Which command accomplishes this?

A.chown -R appuser:appgroup /app
B.chown -R appuser /app && chgrp appgroup /app
C.chgrp -R appgroup /app && chown appuser /app
D.chown -R appuser: /app && chgrp -R appgroup /app
AnswerA

The -R flag applies chown recursively to the directory and every file and subdirectory beneath it, while appuser:appgroup sets both owner and group in one operation. This matches the requirement to change ownership of all contents.

Why this answer

The `chown -R appuser:appgroup /app` command recursively changes both the user and group ownership of the `/app` directory and all its contents. The `-R` flag ensures recursion, and the colon-separated `user:group` syntax sets both ownership attributes in a single command.

Exam trap

The trap here is that candidates often forget the `-R` flag on the second command in compound solutions, or they mistakenly believe `chown user:` sets a specific group rather than the user's default group, leading them to choose options that only partially apply the ownership change.

How to eliminate wrong answers

Option B is wrong because `chown -R appuser /app` changes only the user ownership recursively, but `chgrp appgroup /app` without `-R` changes only the group ownership of the `/app` directory itself, not its contents. Option C is wrong because `chgrp -R appgroup /app` changes group ownership recursively, but `chown appuser /app` without `-R` changes only the user ownership of the top-level directory, leaving all contents with the original user. Option D is wrong because `chown -R appuser: /app` sets the group to the user's default group (not `appgroup`), and the subsequent `chgrp -R appgroup /app` would override that group, but the first command already incorrectly sets the group.

65
Multi-Selecteasy

A user wants to view the contents of a compressed file file.txt.gz without decompressing it permanently. Which two commands can be used? (Choose two.)

Select 2 answers
A.gunzip -c file.txt.gz
B.zcat file.txt.gz
C.gzip -l file.txt.gz
D.gzip -d file.txt.gz
E.gzip -k file.txt.gz
AnswersA, B

`gunzip -c` writes the decompressed stream to standard output, leaving file.txt.gz untouched on disk. The `-c` flag satisfies the stem's requirement to view contents without permanent decompression, since no `.gz` file is removed or replaced. Piping to a pager such as `less` lets the user read it.

Why this answer

Option A, gunzip -c file.txt.gz, is correct because the -c (--stdout) flag writes the decompressed output to standard output, allowing the user to view the contents while leaving the original .gz file intact on disk. Option B, zcat file.txt.gz, is correct because zcat is functionally equivalent to gunzip -c, decompressing the gzip file to stdout without removing or modifying the compressed file. Option C, gzip -l file.txt.gz, only lists metadata such as compressed size, uncompressed size, and ratio, so it does not show the file's contents.

Option D, gzip -d file.txt.gz, actually decompresses and deletes the .gz file, which is a permanent decompression, not a view-only operation. Option E, gzip -k file.txt.gz, compresses a file while keeping the original, so it does not display the contents of an already compressed file.

Exam trap

The trap here is that candidates confuse `gzip -d` (which permanently decompresses) with `gunzip -c` (which outputs to stdout), or mistakenly think `gzip -l` shows file contents instead of metadata.

66
MCQeasy

A user needs to see the contents of a gzip-compressed file 'data.txt.gz' without decompressing it. Which command is appropriate?

A.gunzip data.txt.gz
B.zcat data.txt.gz
C../data.txt.gz
D.gzcat data.txt.gz
AnswerB

zcat streams the decompressed contents of data.txt.gz directly to standard output, leaving the original compressed file untouched on disk. This satisfies the stem's constraint of viewing the file without decompressing it, since no .gz-to-plain extraction occurs. gzip's own -c flag could also write to stdout, but zcat is the purpose-built tool.

Why this answer

The `zcat` command reads a gzip-compressed file and outputs its decompressed content to stdout without modifying the original file. This allows the user to view the contents of 'data.txt.gz' without permanently decompressing it.

Exam trap

The trap here is that candidates may confuse `zcat` with `gunzip` or assume `gzcat` is the correct command, but the LFCS exam expects knowledge of the standard `zcat` utility for viewing compressed files without decompression.

How to eliminate wrong answers

Option A is wrong because `gunzip` decompresses the file and replaces the .gz file with the uncompressed version, which does not meet the requirement to view contents without decompressing. Option C is wrong because attempting to execute a compressed file with `./data.txt.gz` will fail as it is not an executable binary and the shell cannot interpret the compressed data. Option D is wrong because `gzcat` is not a standard Linux command; while some systems may have it as an alias, the standard command on Linux is `zcat`.

67
Multi-Selectmedium

A system administrator needs to identify which processes are consuming the most CPU and memory on a Linux server. Which TWO commands can provide a real-time, interactive view of process resource usage? (Choose two.)

Select 2 answers
A.vmstat 1
B.top
C.ps aux --sort=-%cpu
D.htop
E.iostat -x 1
AnswersB, D

top displays a dynamic, real-time view of running processes, sorted by CPU usage by default. It shows memory usage, load average, and allows interactive commands like sorting by memory (M) or killing processes (k). It is a standard tool for live process monitoring.

Why this answer

top and htop are interactive, real-time process viewers that show CPU and memory usage per process. top is universally available, while htop offers enhanced usability. The other commands provide snapshots or system-wide statistics without per-process, real-time interactivity, so they do not meet the requirement.

Exam trap

The trap here is confusing system-wide statistics tools like vmstat or iostat with per-process interactive monitors.

68
MCQhard

An administrator needs to replace all occurrences of the string 'foo' with 'bar' in all files under /etc/config, but only in files ending with .conf. The replacement must be done in-place, and backup copies should be created with a .bak extension. Which command accomplishes this?

A.find /etc/config -name '*.conf' -exec sed -i .bak 's/foo/bar/g' {} +
B.find /etc/config -name '*.conf' -exec sed 's/foo/bar/g' {} \;
C.find /etc/config -name '*.conf' -exec sed -i.bak 's/foo/bar/g' {} +
D.find /etc/config -name '*.conf' -exec sed -i 's/foo/bar/g' {} +
AnswerC

find locates only .conf files, and sed -i.bak edits each in place while writing a .bak backup, with the g flag replacing every occurrence per line. The -exec ... {} + form batches files efficiently, satisfying all stated constraints.

Why this answer

It uses `sed -i.bak` which creates a backup file with the .bak extension before performing the in-place substitution, and the `find -exec ... +` variant efficiently processes multiple files at once. The `-i` option with an argument (no space) specifies the backup suffix directly, satisfying the requirement for backup copies.

Exam trap

The trap here is that candidates confuse the syntax `-i .bak` (with a space, which is incorrect) with `-i.bak` (no space, which is correct), or they forget that `-i` without a suffix does not create backups, leading them to choose options that either fail or omit the required backup step.

How to eliminate wrong answers

Option A is wrong because `-i .bak` (with a space) is interpreted as `-i` with an empty backup suffix and `.bak` as a separate argument, causing sed to fail or behave unexpectedly. Option B is wrong because it lacks the `-i` flag entirely, so changes are written to stdout instead of being saved in-place, and no backups are created. Option D is wrong because `-i` without a suffix does not create backup files, violating the requirement for .bak backups.

69
MCQmedium

To check the disk usage of the /var/log directory in a human-readable format, which command is appropriate?

A.du -sh /var/log
B.ls -lh /var/log
C.df -h /var/log
D.fdisk -l /var/log
AnswerA

du -s summarises total usage for the directory rather than listing every file, and -h converts the block count into human-readable units such as MB or GB. Together they report /var/log's aggregate size readably, matching the requirement.

Why this answer

The `du -sh /var/log` command is correct because `du` (disk usage) estimates file and directory space usage, and the `-s` option summarizes the total for the specified directory, while `-h` prints sizes in human-readable format (e.g., K, M, G). This directly answers the requirement to check disk usage of the /var/log directory in a human-readable form.

Exam trap

The trap here is that candidates confuse `du` (directory usage) with `df` (filesystem usage), or mistakenly think `ls -lh` shows total directory size, when in fact `ls` only lists individual file sizes without summing subdirectory contents.

How to eliminate wrong answers

Option B is wrong because `ls -lh /var/log` lists the contents of the directory with file sizes, not the total disk usage of the directory itself; it does not aggregate space used by subdirectories. Option C is wrong because `df -h /var/log` reports the free and used space on the filesystem that contains /var/log, not the disk usage of the directory itself. Option D is wrong because `fdisk -l /var/log` is used to manipulate or display partition tables on block devices, not to check disk usage of a directory; it would fail on a regular file or directory.

70
MCQhard

An administrator runs 'ls -la' and sees the following entry for a file: 'lrwxrwxrwx 1 root root 24 Jan 10 12:00 link -> /etc/passwd'. If the target file /etc/passwd is deleted, what happens to the link file?

A.The link becomes a hard link to the deleted file's inode
B.The link becomes a broken symbolic link
C.The link becomes a regular file with the same content
D.The link is automatically deleted
AnswerB

A symbolic link stores only the target's pathname, not its inode, so deleting /etc/passwd leaves the link entry intact but unresolvable. Accessing it then fails with ENOENT, and `ls -l` typically renders the dangling target in red. This satisfies the stem's scenario: the symlink persists as a broken link rather than being removed.

Why this answer

The entry 'lrwxrwxrwx' indicates a symbolic link (symlink), which stores a path to the target file rather than sharing its inode. When the target /etc/passwd is deleted, the symlink still exists but points to a non-existent path, making it a broken (dangling) symlink. Accessing it will result in a 'No such file or directory' error.

Exam trap

The trap here is that candidates confuse symbolic links with hard links, assuming the link would become a regular file or automatically delete, when in fact a symlink simply becomes broken and persists until manually removed.

How to eliminate wrong answers

Option A is wrong because a symbolic link does not share the target's inode; only hard links do, and deleting the target does not convert a symlink into a hard link. Option C is wrong because a symbolic link is not a regular file and does not contain the target's content; it only stores a path string, and deleting the target does not copy content into the link. Option D is wrong because symbolic links are not automatically deleted when their target is removed; they persist as broken links until explicitly removed.

71
MCQhard

An administrator wants to print the last field of each line from a CSV file 'data.csv' (comma-separated). Which awk command accomplishes this?

A.awk -F, '{print $NF}' data.csv
B.cut -d, -f2 data.csv
C.cut -d, -f1 data.csv
D.awk '{print $NF}' data.csv
AnswerA

-F, sets the input field separator to a comma, and $NF expands to the index of the final field on each record, so print $NF emits the last comma-separated column. This satisfies the CSV last-field requirement without hardcoding a field number.

Why this answer

`awk -F, '{print $NF}' data.csv` uses `-F,` to set the field separator to comma, and `$NF` represents the value of the last field (NF is the number of fields, so $NF is the last field). This command prints the last column of each line in the CSV file.

Exam trap

The trap here is that candidates often forget to specify the field separator with `-F,` in awk, or they confuse `cut` options (like `-f2` for a specific field instead of `$NF` for the last field), leading them to pick a command that prints a fixed column rather than the last column dynamically.

How to eliminate wrong answers

Option B is wrong because `cut -d, -f2` prints the second field, not the last field. Option C is wrong because `cut -d, -f1` prints the first field, not the last field. Option D is wrong because `awk '{print $NF}'` uses the default field separator (whitespace), not a comma, so it will not correctly parse CSV fields and will likely print the last whitespace-separated token instead of the last comma-separated field.

72
Multi-Selecthard

A technician must locate every regular file beneath /var that is larger than 100 MB and was modified more than 30 days ago, then list them. Which TWO find expressions achieve this? (Choose two.)

Select 2 answers
A.find /var -type f -size +100M -mtime +30 -print
B.find /var -type f -size +100M -atime +30 -print
C.find /var -type f -size +100M -mtime +30
D.find /var -size +100M -mtime +30 -exec ls -l {} \;
E.find /var --type f --size +100M --mtime +30 -print
AnswersA, C

This expression combines the three needed tests: -type f restricts matches to regular files, -size +100M matches files strictly larger than 100 mebibytes, and -mtime +30 matches files whose data was last modified more than 30 full 24-hour periods ago. The default action already prints, and -print makes it explicit.

Why this answer

Two variants are correct because find's implicit print makes -print optional, and both retain the -type f, -size +100M, and -mtime +30 tests. Substituting atime measures access rather than modification, dropping the type test admits non-regular entries, and using double-dash predicates is a syntax error that prevents execution.

Exam trap

The trap here is believing -print is mandatory, so a correct expression without it looks incomplete.

73
Multi-Selectmedium

Which TWO commands can be used to view the last 10 lines of a file and also follow new lines as they are written?

Select 2 answers
A.tail -f -n 10
B.cat -n
C.tail -n 10
D.head -n 10
E.less +F
AnswersA, E

`tail -f -n 10` satisfies both constraints: `-n 10` prints the final ten lines, while `-f` keeps the file descriptor open and streams appended data as it is written. This combination suits live log monitoring, where existing tail content and subsequent writes must both be observed continuously.

Why this answer

Option A, `tail -f -n 10`, is correct because `-n 10` displays the last 10 lines of the file and `-f` (follow) keeps the file open and prints new lines as they are appended, which is exactly the requested behavior. Option E, `less +F`, is correct because the `+F` command starts `less` in follow mode, initially showing the file content (including the tail end) and continuously displaying newly appended lines, similar to `tail -f`. Option B, `cat -n`, only concatenates the file with line numbers and does not follow new lines.

Option C, `tail -n 10`, shows the last 10 lines but lacks the follow capability. Option D, `head -n 10`, shows the first 10 lines and does not follow the file.

Exam trap

Linux Foundation often tests the distinction between `tail -n 10` (static view) and `tail -f -n 10` (dynamic follow), and candidates may overlook the `-f` flag or confuse `head` with `tail`.

74
Multi-Selecthard

Which THREE of the following commands can be used to search for a string in multiple files and display the matching lines?

Select 3 answers
A.find /path -name '*.txt' -type f
B.ack 'pattern' /path
C.grep -r 'pattern' /path
D.rg 'pattern' /path
E.sort /path/file
AnswersB, C, D

ack is a Perl-based grep replacement that recursively searches directory trees by default, printing matching lines with filenames. This satisfies the requirement to search a string across multiple files under /path and display the matches.

Why this answer

Option B, ack 'pattern' /path, is correct because ack is a recursive grep-like search tool that by default searches files under the given path and prints matching lines with filenames. Option C, grep -r 'pattern' /path, is correct because the -r (recursive) flag makes grep descend into directories and display each matching line prefixed by its file. Option D, rg 'pattern' /path, is correct because ripgrep recursively searches the path and outputs matching lines, honoring ignore files by default.

Option A, find /path -name '*.txt' -type f, only locates files by name and type; it does not search file contents or display matching lines. Option E, sort /path/file, merely sorts lines of a single file and performs no pattern search.

Exam trap

The trap here is that candidates may confuse file-location commands like `find` with content-search commands, or assume that `sort` can filter lines based on a pattern, when it only reorders lines.

75
MCQeasy

A junior administrator needs to create a compressed archive of the /etc directory that preserves file ownership and permissions, and writes it to /backup/etc.tar.gz. Which single command accomplishes this?

A.gzip -r /etc > /backup/etc.tar.gz
B.tar -czvf /backup/etc.tar.gz /etc
C.cpio -ov /etc < /backup/etc.tar.gz
D.tar -xzvf /backup/etc.tar.gz /etc
AnswerB

This is correct because tar with the -c flag creates a new archive, -z compresses it with gzip, -v shows progress, and -f specifies the archive filename. By default tar preserves ownership and permission metadata when creating archives as root, exactly matching the requirement to archive /etc into /backup/etc.tar.gz.

Why this answer

Creating a gzip-compressed tarball requires the create, gzip, verbose, and file flags together with the source directory. The combination tar -czvf /backup/etc.tar.gz /etc builds the archive in one pass, preserving metadata, and writes it to the specified path. The other commands either attempt extraction, misuse compression tools, or produce non-tar output.

Exam trap

The trap here is confusing the create flag -c with the extract flag -x when the stem asks to build an archive.

Page 1 of 2 · 86 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Essential Commands questions.