Courseiva

CCNA Operation of Running Systems Questions

52 questions · Operation of Running Systems · All types, answers revealed

1
MCQmedium

An administrator wants to ensure that a service starts automatically after a system crash. Which systemd command should be used?

A.systemctl daemon-reload
B.systemctl enable service
C.systemctl mask service
D.systemctl start service
AnswerB

systemctl enable creates the symlinks that pull the unit into the appropriate target's wants directory, so systemd starts the service automatically at boot, including after a crash-induced reboot. Starting it now would not survive a restart.

Why this answer

The `systemctl enable service` command creates the necessary symlinks in the systemd unit configuration directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) so that the service is automatically started at boot. This includes recovery after a system crash, because the crash triggers a reboot, and the enabled service will be started as part of the normal boot process.

Exam trap

The trap here is that candidates confuse `systemctl start` (immediate, one-time start) with `systemctl enable` (persistent boot-time start), leading them to choose option D, which does not survive a reboot or crash.

How to eliminate wrong answers

Option A is wrong because `systemctl daemon-reload` only reloads the systemd manager configuration and unit files, but does not change the enablement state of any service; it cannot ensure a service starts after a crash. Option C is wrong because `systemctl mask service` creates a strong symlink to `/dev/null`, which prevents the service from being started manually or automatically, even by dependencies or boot; this is the opposite of what is needed. Option D is wrong because `systemctl start service` only starts the service immediately in the current session; it does not create any boot-time or crash-recovery enablement, so the service will not start automatically after a reboot or crash.

2
MCQeasy

A developer reports that a custom daemon fails to start after a reboot. The daemon's unit file is located in /etc/systemd/system/custom.service. Which of the following is the most likely cause?

A.The service was not started manually after installation.
B.The service is not enabled.
C.The SELinux policy blocks the service.
D.A firewall rule is blocking inbound connections.
AnswerB

An enabled unit creates the symlink under the target's `.wants` directory, which is what triggers the start at boot; a unit merely present in `/etc/systemd/system` is loaded but never pulled in. Since the daemon runs fine manually, only the missing enablement explains the reboot-specific failure.

Why this answer

The most likely cause is that the service is not enabled (systemctl enable). Even though the unit file exists in /etc/systemd/system, systemd only starts services automatically at boot if they are enabled. Option B is correct.

Option A is incorrect because manually starting the service after installation would work but does not affect boot behavior. Option C is unlikely because SELinux policy blocks would produce a different error (e.g., denial messages). Option D is incorrect because firewall rules do not prevent systemd from starting a service; they affect network connectivity.

3
MCQhard

A system administrator needs to ensure that the 'nginx' service starts automatically after a reboot on a system using systemd. The service unit file exists and is currently disabled. Which command should be used?

A.systemctl start nginx
B.systemctl daemon-reload
C.systemctl enable --now nginx
D.systemctl enable nginx
AnswerD

The systemctl enable nginx command creates symbolic links from the systemd system configuration directory to the nginx.service unit file, ensuring the service is started at boot. It does not start the service immediately, but sets it to start automatically on the next boot.

Why this answer

The systemctl enable nginx command is the correct way to configure a service to start automatically at boot. It creates the necessary symlinks without starting the service now, which matches the requirement to ensure automatic startup after a reboot.

Exam trap

The trap here is confusing starting a service with enabling it; starting affects only the current runtime, while enabling controls boot-time behavior.

4
Multi-Selecthard

Which TWO of the following are correct statements about systemd journald configuration?

Select 2 answers
A.The 'MaxRetentionSec' directive sets the maximum time to retain journal entries.
B.The 'RuntimeMaxUse' directive applies to the journal stored in /var/log/journal.
C.The 'SystemMaxUse' directive in journald.conf limits the maximum disk space used by the journal.
D.The 'Compress' directive is set to 'no' by default.
E.The 'ForwardToSyslog' directive is set to 'yes' by default.
AnswersA, C

MaxRetentionSec specifies the maximum time (in seconds) that journal entries are kept. Older entries are deleted.

Why this answer

The 'MaxRetentionSec' directive in journald.conf specifies the maximum time (in seconds) that journal entries are retained before they are deleted. This is a time-based retention policy, distinct from size-based limits, and is used to automatically prune old log entries to manage disk usage.

Exam trap

The trap here is that candidates often confuse 'RuntimeMaxUse' with persistent storage limits, or assume 'ForwardToSyslog' is enabled by default because of legacy syslog integration, but systemd journald isolates logs by default.

5
Multi-Selectmedium

Which THREE commands can display the current CPU utilization statistics on a Linux system?

Select 3 answers
A.free
B.top
C.sar -u
D.mpstat -P ALL
E.uptime
AnswersB, C, D

`top` provides a live, continuously refreshing view of per-process and aggregate CPU utilisation, satisfying the requirement to display current statistics. Its interactive display reads directly from `/proc`, showing user, system, nice, idle and wait percentages. Unlike `uptime`, which reports only load averages, `top` gives instantaneous utilisation figures.

Why this answer

Option B, top, is correct because it is an interactive process viewer that continuously reports CPU utilization statistics, including per-core and aggregate usage, load average, and per-process CPU consumption. Option C, sar -u, is correct because the -u flag of the sar command from the sysstat package reports CPU utilization statistics (user, system, iowait, idle percentages) either for the current day or a specified interval. Option D, mpstat -P ALL, is correct because mpstat from the sysstat package with -P ALL displays per-processor CPU utilization statistics, showing each individual CPU core's usage percentages.

Option A, free, is incorrect because it only reports memory and swap usage, not CPU statistics. Option E, uptime, is incorrect because it only shows the current time, system uptime, number of logged-in users, and load averages, without detailed CPU utilization percentages.

Exam trap

The trap here is that candidates may confuse `free` or `uptime` with CPU monitoring tools, but `free` is strictly memory-focused and `uptime` only shows load averages, not actual CPU utilization percentages.

6
MCQhard

An e-commerce company runs a critical application on a Linux server that occasionally becomes unresponsive. The server has 64GB RAM and runs a Java application. The operations team notices that during peak hours, the system becomes very slow and eventually the application crashes with 'OutOfMemoryError'. After restart, it works fine for a while. They suspect a memory leak but also want to ensure the system does not go down during peak hours. The system uses systemd to manage the Java service. The administrator needs to implement a solution that: (1) automatically restarts the service if it becomes unresponsive, (2) limits the memory usage of the service to prevent OOM kills on the system, and (3) provides early warning of high memory usage. Which of the following approaches best meets these requirements?

A.Set up a cron job to run every minute that checks memory usage with free and if > 90%, restart the service with systemctl restart. Also configure MemoryMax=32G in the systemd unit.
B.Configure sysctl vm.overcommit_memory=2 to prevent overcommit, and allocate huge pages for Java. Also set Restart=always in the systemd unit.
C.Use ulimit -v 33554432 in the service script to limit virtual memory, and set Restart=always. Also configure a cron job to send alerts when dmesg shows OOM.
D.Configure systemd service with WatchdogSec=30, Restart=on-failure, MemoryMax=32G. Also set up a log watcher that alerts when memory usage exceeds 28G via journalctl and a custom script.
AnswerD

WatchdogSec=30 restarts the service when it stops responding, Restart=on-failure handles crashes, and MemoryMax=32G caps consumption below the 64GB total, preventing system-wide OOM kills. The journalctl watcher alerts before the 28G threshold, meeting all three requirements.

Why this answer

It uses systemd's WatchdogSec to detect unresponsiveness and Restart=on-failure to automatically restart the service, while MemoryMax=32G enforces a hard memory limit via cgroups to prevent OOM kills. The custom log watcher provides early warning by alerting when memory usage exceeds 28G, satisfying all three requirements.

Exam trap

The trap here is that candidates often confuse ulimit or sysctl settings with cgroup-based memory limits, or assume cron-based polling is sufficient for unresponsiveness detection, overlooking systemd's built-in WatchdogSec mechanism.

How to eliminate wrong answers

Option A is wrong because using a cron job to check memory usage every minute is inefficient and may miss transient spikes, and MemoryMax=32G alone does not provide early warning. Option B is wrong because sysctl vm.overcommit_memory=2 and huge pages do not limit memory usage or provide automatic restart on unresponsiveness; Restart=always only restarts on exit, not on hang. Option C is wrong because ulimit -v limits virtual memory but does not prevent the Java process from exhausting physical memory and causing system-wide OOM; it also lacks early warning and WatchdogSec for unresponsiveness detection.

7
MCQhard

Based on the journalctl output, what is the most likely cause of the service failure?

A.Another process is already using port 8080.
B.The service configuration file has a syntax error.
C.The system is out of memory.
D.The service is trying to write to a read-only filesystem.
AnswerA

The journal shows the service failed to bind its listening socket because port 8080 was already held by another process, producing an address-already-in-use error. This satisfies the stem by identifying port contention, not a configuration or permission fault, as the cause.

Why this answer

The journalctl output shows a bind error on port 8080 with 'Address already in use'. This indicates that another process is already listening on that port, preventing the service from starting. In systemd, such a failure is logged with the specific errno EADDRINUSE, which directly points to a port conflict.

Exam trap

The trap here is that candidates may confuse a bind error with a configuration syntax error, but the specific 'Address already in use' message uniquely identifies a port conflict, not a parsing issue.

How to eliminate wrong answers

Option B is wrong because a syntax error in the service configuration file would typically produce a parse error or 'Failed to parse' message in journalctl, not a bind error. Option C is wrong because an out-of-memory condition would manifest as an OOM killer event or memory allocation failure, not a specific port bind error. Option D is wrong because a read-only filesystem would produce a 'Read-only file system' error (EROFS) when attempting to write, not an 'Address already in use' error.

8
MCQhard

Based on the exhibit, what is the most likely cause of the blocked task?

A.CPU starvation
B.Memory leak
C.Disk I/O bottleneck or hung storage
D.Network congestion
AnswerC

A blocked task in uninterruptible sleep (D state) typically indicates the process is waiting on storage I/O that never completes. Since the exhibit shows the task stuck rather than terminated, a hung disk or saturated I/O queue is the most likely cause, directly satisfying the blocked-task symptom.

Why this answer

The exhibit shows a process in 'D' state (uninterruptible sleep), which typically indicates the process is waiting for I/O completion from a block device. When a task is blocked in this state for an extended period, it is most likely due to a disk I/O bottleneck or hung storage, as the kernel cannot interrupt this wait. CPU starvation (run queue) and memory leaks (OOM or swapping) produce different process states, making disk I/O the primary suspect.

Exam trap

The trap here is that candidates confuse a process in 'D' state (uninterruptible sleep, I/O wait) with a process that is simply sleeping or waiting on CPU, leading them to incorrectly choose CPU starvation or memory issues instead of recognizing the classic symptom of a disk I/O bottleneck.

How to eliminate wrong answers

Option A is wrong because CPU starvation manifests as processes in 'R' state (runnable) or high load averages with low CPU idle, not as a task stuck in uninterruptible sleep ('D' state). Option B is wrong because a memory leak typically leads to high memory usage, swapping, or OOM killer activity, which would show processes in 'S' (interruptible sleep) or 'R' state, not a blocked 'D' state. Option D is wrong because network congestion causes socket waits and timeouts, reflected in 'S' state or network-related kernel threads, not a task blocked on block I/O in 'D' state.

9
MCQmedium

A system administrator notices that a web server process (PID 1234) is consuming excessive CPU. They want to trace its system calls to identify the cause. Which command should be used?

A.ltrace -p 1234
B.perf record -p 1234
C.gdb -p 1234
D.strace -p 1234
AnswerD

strace attaches to a running process via -p and reports each system call it makes, exposing where PID 1234 spends time in kernel operations. This directly addresses tracing syscalls of an existing high-CPU process without restarting it.

Why this answer

The correct command is `strace -p 1234`, which attaches to the running process (PID 1234) and intercepts all system calls (e.g., read, write, open) made by that process. This allows the administrator to see exactly what the web server is doing at the kernel level, such as excessive file I/O or network operations, which can pinpoint the cause of high CPU usage. Other tools like ltrace, perf, or gdb serve different purposes (library calls, profiling, debugging) and do not directly trace system calls.

Exam trap

The trap here is that candidates confuse `strace` (system calls) with `ltrace` (library calls), as both trace function calls but at different layers of the software stack, leading them to pick the wrong tool for kernel-level analysis.

How to eliminate wrong answers

Option A is wrong because `ltrace -p 1234` traces library calls (e.g., functions from libc), not system calls; it would show calls like `malloc` or `printf` but miss kernel-level operations like `read` or `write`. Option B is wrong because `perf record -p 1234` is a performance profiling tool that samples hardware events (e.g., CPU cycles, cache misses) and does not trace individual system calls; it provides statistical analysis, not a per-call log. Option C is wrong because `gdb -p 1234` is a debugger that allows interactive inspection of the process's memory and execution, but it is not designed for tracing system calls and would require manual breakpoints and significant overhead.

10
Drag & Dropmedium

Order the steps to recover a forgotten root password on a Linux system using single-user mode.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To recover a forgotten root password on Linux using single-user mode, you must first boot into single-user mode (e.g., by adding 'single' to the kernel command line). At the root prompt, the filesystem is mounted read-only, so you must remount it as read-write with 'mount -o remount,rw /'. Then use 'passwd root' to set a new password.

Finally, reboot the system. Attempting to change the password without remounting or rebooting prematurely will cause the recovery to fail.

11
Matchingmedium

Match each file system type to its typical use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

General-purpose Linux file system

High-performance for large files

Copy-on-write with snapshots

Virtual memory paging

Temporary file system in RAM

Why these pairings

Common file systems in Linux include ext4 for general use, XFS for high-performance and large files, and Btrfs for advanced features like snapshots. Swapping definitions is a common error.

12
MCQhard

A system with systemd experiences a service that fails to start due to a 'Failed to start' error with status 203/EXEC. What is the most likely cause?

A.The system has run out of memory
B.The service unit file has a missing or incorrect ExecStart command
C.The service is already running
D.The service requires a dependency that hasn't started
AnswerB

Status 203/EXEC means systemd could not execute the binary specified in ExecStart, typically because the path is wrong, the file lacks execute permission, or the interpreter is missing. Correcting the ExecStart directive resolves the failure.

Why this answer

Status 203/EXEC in systemd indicates that the service manager failed to execute the command specified in the service unit file. The most common cause is a missing or incorrect ExecStart directive, such as a typo in the binary path, a missing executable, or incorrect syntax. This error is specific to execution failures, not resource or dependency issues.

Exam trap

The trap here is that candidates confuse status 203/EXEC with a generic 'service failed to start' and incorrectly attribute it to dependencies or resource exhaustion, rather than recognizing it as a specific indicator of an exec() failure in the ExecStart directive.

How to eliminate wrong answers

Option A is wrong because out-of-memory conditions typically cause OOM kills (status 137/SIGKILL) or systemd service cgroup memory limit violations, not status 203/EXEC. Option C is wrong because if the service is already running, systemd would report a 'start-limit-hit' or 'already running' error, not an EXEC failure. Option D is wrong because dependency failures result in status 203/EXEC only if the dependency itself causes the ExecStart to fail; normally, unmet dependencies produce 'dependency failed' or 'timeout' errors, not an EXEC code.

13
MCQeasy

A junior administrator needs to check the current runlevel and then change the system to runlevel 3 (multi-user, no GUI) on a SysVinit-based system. Which command sequence will accomplish this?

A.runlevel; init 3
B.telinit -q; telinit 3
C.chkconfig --list; init 3
D.systemctl get-default; systemctl isolate multi-user.target
AnswerA

'runlevel' displays the previous and current runlevel, and 'init 3' changes the system to runlevel 3. On SysVinit systems, runlevel 3 is typically multi-user mode without a graphical interface. This sequence is correct for checking and changing runlevels on a SysVinit-based distribution.

Why this answer

On SysVinit systems, the 'runlevel' command displays the current and previous runlevel, and 'init 3' changes to runlevel 3 (multi-user, no GUI). The other options use systemd commands or incorrect utilities that do not fulfill both requirements.

Exam trap

The trap here is assuming that 'chkconfig --list' shows the current runlevel, when it actually lists service configuration across runlevels.

14
MCQeasy

A system administrator wants to view the last 10 lines of the system log file '/var/log/syslog' and continue to watch for new lines as they are appended. Which command should be used?

A.tail -n 10 /var/log/syslog
B.less /var/log/syslog
C.tail -n 10 -f /var/log/syslog
D.head -n 10 /var/log/syslog
AnswerC

The -n 10 flag prints the final ten lines, and -f keeps the file descriptor open, streaming appended lines to standard output as they are written. This combination satisfies both viewing historical entries and live monitoring of /var/log/syslog in one command.

Why this answer

The `tail -n 10 -f /var/log/syslog` command first displays the last 10 lines of the file and then uses the `-f` (follow) flag to continuously monitor the file for new appended lines, outputting them in real time. This matches the requirement to both view the last 10 lines and watch for new entries.

Exam trap

The trap here is that candidates often confuse `tail -n 10` (static view) with `tail -f` (follow mode), or mistakenly think `less` with its Shift+F feature is the default answer, but the question explicitly requires a single command that both shows the last 10 lines and continuously watches for new lines.

How to eliminate wrong answers

Option A is wrong because `tail -n 10 /var/log/syslog` only shows the last 10 lines and then exits, without continuing to watch for new lines. Option B is wrong because `less /var/log/syslog` opens the file for interactive paging but does not automatically show only the last 10 lines or follow new appends without manual intervention (e.g., pressing Shift+F). Option D is wrong because `head -n 10 /var/log/syslog` shows the first 10 lines of the file, not the last 10, and does not follow new lines.

15
MCQeasy

A Linux server is configured with a custom systemd service unit for a backup script. After editing /etc/systemd/system/backup.service to add an EnvironmentFile directive, the administrator runs 'systemctl start backup' but systemctl status shows the unit still using the old environment. Which command should the administrator run to apply the unit file changes?

A.systemctl reenable backup
B.systemctl daemon-reload
C.systemctl restart backup
D.systemctl reload backup
AnswerB

systemd reads unit files into memory when it starts or when a unit is first loaded. After modifying a unit file, systemd must reload its configuration to pick up changes. Without daemon-reload, systemctl start uses the cached unit definition and ignores the new EnvironmentFile, so the service continues with the old environment.

Why this answer

After editing a systemd unit file, systemd continues using the previously loaded definition until it is told to reload. The daemon-reload subcommand makes systemd re-parse all unit files, applying changes such as new EnvironmentFile directives. Only then will a subsequent start or restart use the updated environment.

The other subcommands act on the running service or enablement state without refreshing the unit definition.

Exam trap

The trap here is assuming that restarting a service after editing its unit file is enough to apply the changes, when systemd must first reload its configuration.

16
MCQmedium

A process is stuck in an uninterruptible sleep (D state) and cannot be killed. What is the most likely cause?

A.The process has been stopped by a signal
B.The process is waiting for a network response
C.The process is waiting for I/O from a failing disk
D.The process is waiting for CPU
AnswerC

D state means the process is blocked in an uninterruptible kernel wait, typically pending I/O completion. A failing disk never returns that I/O, so the process cannot be signalled or killed until the device responds or is reset.

Why this answer

A process in uninterruptible sleep (D state) is typically waiting for I/O from a block device, such as a disk. When a disk is failing or unresponsive, the kernel cannot complete the I/O request, and the process cannot be killed because doing so would risk data corruption or filesystem inconsistency. This state is a kernel-level wait that ignores signals, including SIGKILL.

Exam trap

Linux Foundation often tests the misconception that any 'stuck' process is due to network issues, but the D state specifically indicates block I/O, not network I/O, which uses interruptible sleep (S state).

How to eliminate wrong answers

Option A is wrong because a process stopped by a signal enters a T state (stopped), not D state; such processes can be resumed or killed. Option B is wrong because waiting for a network response typically results in interruptible sleep (S state), as network I/O can be interrupted by signals; D state is reserved for block I/O operations. Option D is wrong because waiting for CPU is represented by the R state (runnable) or S state (sleeping while waiting for CPU), not D state.

17
Multi-Selecthard

A Linux server has a filesystem mounted at /data that is running out of space. The administrator needs to identify which directories under /data are consuming the most disk space and then safely remove old log files. Which two commands should the administrator use? (Choose two.)

Select 2 answers
A.df -h /data
B.du -sh /data/*
C.ls -lR /data | less
D.find /data -type f -name '*.log' -mtime +30 -delete
E.rm -rf /data/*
AnswersB, D

du -sh /data/* summarizes the disk usage of each immediate item under /data in human-readable form, quickly revealing which directories are largest. This directly addresses the need to identify space consumers without listing every file, making it efficient for locating the problematic directory.

Why this answer

To find which directories are using the most space, du -sh /data/* provides a per-directory summary. After identifying the culprit, find can precisely locate and delete old log files based on age, avoiding accidental removal of recent data. df only shows filesystem totals, ls -lR is too verbose, and rm -rf is destructive and indiscriminate.

Exam trap

The trap here is using df to try to find which directories are large, when df only reports filesystem-level usage, not directory breakdowns.

18
MCQhard

A system has a process stuck in uninterruptible sleep (D state). The administrator wants to identify which kernel function it is waiting on. Which tool should be used?

A.cat /proc/PID/stack
B.gdb -p PID
C.perf top -p PID
D.strace -p PID
AnswerA

A task in D state is blocked inside a kernel call, and /proc/PID/stack exposes the kernel stack trace showing the exact function it sleeps in. Userspace tools such as ps or top only report the state, not the waiting function.

Why this answer

Reading /proc/PID/stack directly shows the kernel stack trace of the process, revealing the exact kernel function or wait queue the process is blocked on while in uninterruptible sleep (D state). This is the only tool listed that can inspect the kernel-side call stack without attaching a debugger or altering process state.

Exam trap

The trap here is that candidates often confuse strace (user-space syscall tracing) with kernel stack inspection, assuming strace can show kernel internals, but strace only traces syscall entry/exit and cannot reveal the internal kernel function where the process is blocked.

How to eliminate wrong answers

Option B (gdb -p PID) is wrong because gdb attaches to a user-space process and inspects user-space memory and registers; it cannot access the kernel stack or show which kernel function caused the D state. Option C (perf top -p PID) is wrong because perf top samples performance counters and shows hot functions in user and kernel space, but it does not display the current blocked stack trace for a process in D state. Option D (strace -p PID) is wrong because strace traces system calls, but a process in uninterruptible sleep is already inside a kernel function and not making new system calls; strace will hang or show no output.

19
Drag & Dropmedium

Order the steps to set up a LVM logical volume from a new disk.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for setting up an LVM logical volume from a new disk is: first create a physical volume (PV) using pvcreate, then create a volume group (VG) with vgcreate, then create a logical volume (LV) with lvcreate, then format the LV with a filesystem using mkfs, and finally mount it to a directory. This order ensures all dependencies are satisfied: the VG requires the PV, the LV requires the VG, and the filesystem requires the LV.

20
MCQmedium

A Linux server is configured to boot into a graphical target, but after a recent kernel update, the system hangs at a black screen after the GRUB menu. You can still access a rescue shell via the installation media. Which command should you use to make the system boot into a multi-user text target by default, allowing you to troubleshoot?

A.systemctl isolate multi-user.target
B.grub2-mkconfig -o /boot/grub2/grub.cfg
C.systemctl set-default multi-user.target
D.systemctl enable multi-user.target
AnswerC

This command sets the default boot target to multi-user.target, which starts a text-based multi-user environment without a graphical display manager. It is the correct approach to bypass the graphical target and gain a usable console for troubleshooting. The change is persistent and can be reverted once the issue is resolved.

Why this answer

The default systemd target is managed via the default.target symbolic link. To change it persistently, the systemctl set-default command is used. Setting it to multi-user.target ensures the system boots to a text console, allowing the administrator to diagnose the graphical failure.

This is the standard method for altering the default runlevel equivalent in systemd-based distributions.

Exam trap

The trap here is confusing systemctl isolate (runtime change) with systemctl set-default (persistent change).

21
MCQmedium

A server runs out of inodes. The administrator needs to find which filesystem is exhausted and which directory has the most files. Which command sequence best accomplishes this?

A.df -i; find / -type f | wc -l
B.df -i; find / -xdev -type f -printf '%h\0' | sort -z | uniq -c -z | sort -rn | head
C.df -i; du --inodes /
D.df -h; du -sh /
AnswerB

`df -i` reports inode usage per filesystem, isolating the exhausted mount. The `find` pipeline then counts files per directory: `-xdev` prevents crossing into other filesystems, `-printf '%h\0'` emits each file's directory NUL-separated, and `sort -z | uniq -c -z | sort -rn` ranks directories by file count.

Why this answer

`df -i` first checks inode usage across all mounted filesystems to identify which one is exhausted. Then the `find / -xdev -type f -printf '%h\0' | sort -z | uniq -c -z | sort -rn | head` command counts files per directory on the root filesystem only (due to `-xdev`), using null-delimited output to handle special characters in filenames, and sorts to show the directory with the most files. This directly addresses both parts of the problem: identifying the exhausted filesystem and the directory with the most files.

Exam trap

The trap here is that candidates often confuse inode exhaustion with disk space exhaustion and choose `df -h` and `du -sh` (Option D), or they use a recursive file count without restricting to a single filesystem (Option A), failing to isolate the problematic filesystem and directory.

How to eliminate wrong answers

Option A is wrong because `find / -type f | wc -l` counts all files across all mounted filesystems (including network and virtual filesystems), which can be misleading and does not restrict to the exhausted filesystem; it also does not group files by directory, so it cannot identify which directory has the most files. Option C is wrong because `du --inodes /` is not a valid option in standard `du`; the `--inodes` flag is not supported by GNU `du` (it is a `df` option), and even if it were, it would not provide per-directory file counts. Option D is wrong because `df -h` shows disk space usage, not inode usage, and `du -sh /` shows total disk space used by the root filesystem, which is irrelevant to an inode exhaustion problem.

22
MCQhard

Refer to the exhibit. What is the most likely security issue?

A.SSH service is not running.
B.The root account is disabled.
C.Someone is attempting to brute-force the root password.
D.The firewall is blocking SSH.
AnswerC

Repeated failed root logins from a single source in the authentication log indicate a brute-force attempt against the root account. The pattern of many rapid failures, rather than a single error, distinguishes deliberate password guessing from ordinary mistyped credentials.

Why this answer

The exhibit shows multiple failed SSH login attempts for the root user from the same IP address in quick succession, as seen in the auth.log or secure log entries. This pattern indicates a brute-force attack, where an attacker systematically tries different passwords to gain unauthorized root access. Option C is correct because the repeated 'Failed password for root' messages are the hallmark of a brute-force attempt.

Exam trap

The trap here is that candidates may see 'SSH' and 'root' and incorrectly assume the service is down or the account is disabled, rather than recognizing the pattern of repeated failed login attempts as a brute-force attack.

How to eliminate wrong answers

Option A is wrong because the SSH service is clearly running and accepting connections, as evidenced by the log entries showing SSH authentication attempts. Option B is wrong because the root account is not disabled; if it were disabled, the log would show 'User root not allowed because account is locked' or similar, not 'Failed password' attempts. Option D is wrong because the firewall is not blocking SSH; if it were, the connection attempts would not reach the SSH daemon to generate authentication failure logs.

23
MCQmedium

A Linux server's boot process fails after a kernel upgrade. The GRUB2 menu appears, but selecting the newest kernel panics. You need to boot the previous kernel temporarily to recover the system. Which command should you use at the GRUB2 menu to edit the selected entry's boot parameters?

A.Press 'a' to append parameters to the kernel line, then press Enter to boot.
B.Press 'e' to edit the selected menu entry, then modify the 'linux' line and press Ctrl+X to boot.
C.Press 'c' to enter the GRUB command line, then run 'boot' with the previous kernel path.
D.Press 'Tab' to list available kernels, then type the kernel version and press Enter.
AnswerB

In GRUB2, pressing 'e' allows editing the selected menu entry. You can modify the kernel command line on the 'linux' line, for example to change the root device or add 'systemd.unit=rescue.target'. After editing, Ctrl+X boots the modified entry. This is the standard method to temporarily alter boot parameters without making permanent changes.

Why this answer

To temporarily modify boot parameters in GRUB2, you edit the menu entry by pressing 'e', adjust the kernel command line, and boot with Ctrl+X. This allows booting an older kernel or adding options like 'systemd.unit=emergency.target' without permanent changes. The other methods are either for GRUB Legacy or incorrect for this purpose.

Exam trap

The trap here is confusing GRUB Legacy's 'a' key for appending parameters with GRUB2's 'e' key for editing the entire entry.

24
Multi-Selectmedium

A Linux server is experiencing performance issues. You need to identify which processes are consuming the most CPU and memory in real-time. Which two commands can provide this information interactively? (Choose two.)

Select 2 answers
A.iostat
B.top
C.vmstat
D.htop
E.ps aux
AnswersB, D

top is an interactive process viewer that displays a real-time list of processes sorted by CPU usage by default. It shows CPU and memory usage per process and updates periodically. It allows interactive commands like sorting by memory (press M) and killing processes. This directly meets the requirement for real-time monitoring of CPU and memory.

Why this answer

top and htop are interactive process viewers that display real-time CPU and memory usage per process. vmstat and iostat provide system-wide statistics but lack per-process detail and interactivity. ps aux gives a static snapshot, not real-time updates. Therefore, top and htop are the correct choices.

Exam trap

The trap here is assuming that ps aux provides real-time updates, when it only shows a static snapshot at the moment of execution.

25
Multi-Selectmedium

Which TWO commands can be used to display real-time process resource usage on a Linux system? (Choose two.)

Select 2 answers
A.vmstat 1
B.htop
C.ps -aux
D.free -h
E.top
AnswersB, E

htop provides an interactive, colour-coded real-time view of per-process CPU, memory and swap consumption, refreshing continuously. It satisfies the stem's requirement to display live process resource usage, unlike static tools such as ps, which capture only a single snapshot.

Why this answer

Option B (htop) is correct because htop is an interactive process viewer that continuously refreshes and displays real-time CPU, memory, and per-process resource usage, updating by default every second. Option E (top) is correct because top is the classic interactive monitor that dynamically refreshes process and resource statistics in real time, also defaulting to a periodic update interval. Option A (vmstat 1) reports virtual memory, CPU, and I/O statistics every 1 second, but it summarizes system-wide counters rather than per-process resource usage, so it does not display process-level real-time usage.

Option C (ps -aux) is a snapshot command that lists processes at the moment of execution and then exits, providing no continuous real-time updates. Option D (free -h) only shows current memory and swap utilization in human-readable units and does not display process resource usage at all.

Exam trap

The trap here is that candidates often confuse static commands like ps and free with real-time monitoring tools, mistakenly thinking that any command showing resource data qualifies as real-time, when only those with continuous updates (like top and htop) meet the requirement.

26
MCQeasy

A user reports that a background process (PID 3456) is consuming 95% of CPU and causing system slowness. The process name is 'crypto-miner'. The administrator needs to immediately stop this process and ensure it does not restart. Which set of commands should the administrator execute?

A.kill -9 3456, then locate the cron job or systemd service that starts it, and disable/remove it.
B.renice -n 19 -p 3456 and let it run with lower priority.
C.kill -9 3456 and then notify the user.
D.kill -15 3456 and hope it terminates.
AnswerA

SIGKILL (kill -9) cannot be caught or ignored, so PID 3456 terminates immediately despite consuming 95% CPU. Removing the cron job or disabling the systemd unit eliminates the persistence mechanism, satisfying the requirement that the process must not restart.

Why this answer

It addresses both immediate termination and persistence removal. The SIGKILL signal (kill -9) immediately terminates the process, and disabling the cron job or systemd service prevents automatic restart, which is critical for a malicious or unwanted process like 'crypto-miner'.

Exam trap

The trap here is that candidates focus only on stopping the process immediately (kill -9) and overlook the requirement to ensure it does not restart, leading them to choose an option that fails to address persistence.

How to eliminate wrong answers

Option B is wrong because renice only lowers CPU priority; it does not stop the process, and a CPU-intensive process can still consume 95% CPU if no other processes compete, so system slowness persists. Option C is wrong because killing the process without disabling its restart mechanism (e.g., cron or systemd) allows it to respawn immediately, failing to ensure it does not restart. Option D is wrong because SIGTERM (kill -15) requests graceful termination, which the process may ignore or trap, especially if it is malicious or designed to evade termination, leaving it running.

27
MCQhard

An administrator is troubleshooting a server that runs a critical application. The server has 16 GB of RAM and 8 CPU cores. The administrator notices that the server becomes very slow during peak hours. Analysis of 'iostat -x 1' shows that the average wait time (await) for the main disk (sda) is consistently above 1000 ms, while the average service time (svctm) is around 5 ms. What is the most likely cause?

A.The CPU is overloaded, causing processes to wait for CPU time.
B.The system is using swap space heavily, causing disk I/O.
C.The disk is experiencing hardware errors.
D.There is a large queue of I/O requests waiting to be serviced.
AnswerD

Await of 1000ms against svctm of 5ms means requests spend almost all their time queued rather than being serviced. The disk itself is fast; the bottleneck is the backlog of pending I/O requests exceeding what sda can dispatch concurrently.

Why this answer

The 'await' value in iostat represents the average time (in milliseconds) for I/O requests to be serviced, including time spent waiting in the queue. With 'await' at 1000+ ms and 'svctm' at only 5 ms, the vast majority of the time is spent waiting, not being serviced. This indicates a large queue of pending I/O requests, which is the direct cause of the slowdown.

Exam trap

The trap here is that candidates confuse 'await' with 'svctm' or assume high 'await' always means slow disk hardware, when in fact the low 'svctm' proves the disk is fast but overwhelmed by queue depth.

How to eliminate wrong answers

Option A is wrong because CPU overload would show high CPU utilization or run queue length in 'top' or 'vmstat', not a high 'await' with low 'svctm'. Option B is wrong because heavy swap usage would increase I/O but would also typically show high 'svctm' due to random access patterns, and the 'await' vs 'svctm' disparity here points to queue depth, not swap. Option C is wrong because hardware errors would manifest as I/O errors in system logs or increased 'svctm' due to retries, not a consistent 5 ms service time with a 1000+ ms wait.

28
MCQeasy

To view the system's default runlevel (target) at boot, which command is used on a systemd-based system?

A.systemd-analyze
B.systemctl get-default
C.runlevel
D.cat /etc/inittab
AnswerB

`systemctl get-default` queries systemd's default target directly, reading the symlink at `/etc/systemd/system/default.target`. This satisfies the stem's requirement to view the boot target on a systemd-based system, returning values such as `graphical.target` or `multi-user.target` without altering configuration.

Why this answer

On systemd-based systems, the default target (analogous to runlevel) is managed by systemctl. The command `systemctl get-default` queries the symlink at `/etc/systemd/system/default.target` to display which target is set to boot by default, making it the correct way to view the system's default boot target.

Exam trap

The trap here is that candidates familiar with SysVinit may instinctively choose `runlevel` or `cat /etc/inittab`, not realizing that systemd replaces these with `systemctl` commands and uses target units instead of runlevels.

How to eliminate wrong answers

Option A is wrong because `systemd-analyze` is used to analyze system boot performance and show timing details, not to display the default target. Option C is wrong because `runlevel` is a legacy SysVinit command that reads `/var/run/utmp` to show the current and previous runlevels; it does not work on systemd systems to show the default boot target. Option D is wrong because `/etc/inittab` is the configuration file for SysVinit that defines runlevels; systemd-based systems do not use this file, and it is typically absent or ignored.

29
MCQhard

After a kernel update, a service fails to start with 'cannot allocate memory'. The system has 16GB RAM and 8GB swap. Which command should the administrator run first to diagnose potential memory limits?

A.free -m
B.ulimit -a
C.cat /proc/meminfo
D.sysctl vm.overcommit_memory
AnswerB

ulimit -a prints all current shell resource limits, including virtual memory and max memory size, revealing whether a restrictive cap prevents the service from allocating memory despite ample physical RAM and swap. It is the fastest first diagnostic step.

Why this answer

`ulimit -a` displays all current user-level resource limits, including `max memory size`, `max processes`, and `max locked memory`. After a kernel update, the service may be hitting a newly enforced or reduced `ulimit` (e.g., `RLIMIT_AS` or `RLIMIT_DATA`), which can cause 'cannot allocate memory' even when system memory is abundant. This command is the fastest way to check if a per-process limit is the culprit.

Exam trap

The trap here is that candidates see 'cannot allocate memory' and immediately think of system memory exhaustion, leading them to choose `free -m` or `/proc/meminfo`, but the LFCS exam tests the distinction between system-wide memory and per-process resource limits enforced by `ulimit`.

How to eliminate wrong answers

Option A is wrong because `free -m` shows overall system memory and swap usage, but the error 'cannot allocate memory' can occur even with plenty of free RAM if a per-process limit is imposed; `free` does not reveal user limits. Option C is wrong because `cat /proc/meminfo` provides detailed kernel memory statistics (e.g., MemTotal, MemFree, Committed_AS) but does not show per-process resource limits enforced by the shell or PAM; it cannot diagnose a `ulimit` restriction. Option D is wrong because `sysctl vm.overcommit_memory` controls the kernel's memory overcommit policy (0=heuristic, 1=always, 2=never overcommit), but the error 'cannot allocate memory' from a service is typically a per-process limit issue, not a system-wide overcommit setting; changing this sysctl is a more advanced step after confirming limits.

30
MCQeasy

A server is running out of disk space. Which command will show the disk usage of the root filesystem in a human-readable format?

A.ls -lh /
B.df -h /
C.fdisk -l /
D.du -sh /
AnswerB

The -h flag converts raw block counts into human-readable units such as G and M, while the / argument restricts output to the root filesystem alone, directly satisfying the scenario's need to identify space consumption there.

Why this answer

The `df -h /` command displays disk usage for the root filesystem (`/`) in a human-readable format (e.g., GB, MB) by using the `-h` flag. This is the standard tool for checking filesystem-level disk space, not directory-level usage.

Exam trap

The trap here is that candidates confuse `du` (directory usage) with `df` (filesystem usage), often picking `du -sh /` because it shows a large number, but they fail to realize it does not report filesystem capacity or available space, which is what the question explicitly asks for.

How to eliminate wrong answers

Option A is wrong because `ls -lh /` lists the contents of the root directory with sizes in human-readable format, but it does not show disk usage of the filesystem itself—it only shows file and directory sizes, which is not the same as filesystem capacity or usage. Option C is wrong because `fdisk -l /` is used to manipulate or display the partition table of a disk device (e.g., `/dev/sda`), not to show filesystem disk usage; passing `/` as an argument is invalid and will produce an error. Option D is wrong because `du -sh /` calculates the total disk usage of all files and directories under `/` (i.e., the entire filesystem tree), but it does not show the filesystem's total capacity or available space; it also takes significantly longer to run and is not the intended command for checking filesystem-level disk usage.

31
MCQhard

A Linux server is experiencing performance issues. The administrator suspects that a process is causing excessive disk I/O. Which command should the administrator use to identify the process with the highest disk I/O usage in real-time?

A.iotop
B.vmstat 1
C.top
D.iostat -x 1
AnswerA

iotop is a specialized tool that displays real-time disk I/O usage by process. It shows which processes are reading from or writing to disk, along with the amount of I/O. This directly addresses the administrator's need to identify the process with the highest disk I/O. Running iotop (often with sudo) provides a top-like interface for I/O, making it the correct choice.

Why this answer

The tool iotop is designed to monitor disk I/O usage per process in real-time. It displays a list of processes sorted by I/O, allowing the administrator to quickly identify the culprit. Other tools like top, iostat, and vmstat provide system-wide or per-device statistics but lack per-process I/O attribution, making them less effective for this specific troubleshooting task.

Exam trap

The trap here is assuming that top or iostat can show per-process disk I/O by default, but they do not; only iotop provides that granularity.

32
MCQeasy

Which command shows the default target for systemd?

A.systemctl show default
B.systemctl list-default
C.systemctl get-default
D.systemctl default
AnswerC

`systemctl get-default` queries systemd's default target directly, printing the target name that `default.target` symlinks to, such as `graphical.target` or `multi-user.target`. This satisfies the stem's requirement to show, rather than change, the boot default, unlike `systemctl isolate` or `set-default`, which alter runtime or persistent state.

Why this answer

The correct command to display the default target (the systemd unit that the system boots into by default) is `systemctl get-default`. This command reads the symlink at `/etc/systemd/system/default.target` and outputs its target, such as `multi-user.target` or `graphical.target`. Option C is correct because it directly queries systemd for the current default boot target.

Exam trap

The trap here is that candidates confuse `systemctl get-default` with `systemctl default` (which activates the default target) or with non-existent commands like `systemctl list-default`, leading them to pick a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because `systemctl show default` is not a valid systemctl subcommand; `systemctl show` is used to display properties of a unit (e.g., `systemctl show sshd.service`), not to retrieve the default target. Option B is wrong because `systemctl list-default` does not exist; the correct subcommand for listing targets is `systemctl list-units --type=target`, which shows all loaded target units, not the default one. Option D is wrong because `systemctl default` is a valid command but it changes the current target to the default target (i.e., it activates the default boot target), not displays it.

33
MCQmedium

A user reports that they cannot log in via SSH, but other users can. The administrator checks /var/log/auth.log and sees 'Failed password for invalid user'. What is the most likely cause?

A.The user's SSH key is not authorized
B.The user account is locked
C.The user does not exist on the system
D.The user's password has expired
AnswerC

The message 'Failed password for invalid user' is emitted by sshd when the supplied username is absent from the local account database, so authentication fails before any password comparison. Other users succeed because their accounts exist, matching the stem's selective failure.

Why this answer

The log message 'Failed password for invalid user' specifically indicates that the username presented during the SSH authentication attempt does not correspond to any account in the system's user database (e.g., /etc/passwd). This is distinct from a valid user failing authentication; the SSH server (sshd) rejects the session at the authentication stage because the user does not exist. Therefore, the most likely cause is that the user account does not exist on the system.

Exam trap

The trap here is that candidates confuse 'invalid user' (non-existent account) with 'valid user, wrong credentials' (e.g., locked account, expired password, or bad key), but the log message explicitly distinguishes between these two cases.

How to eliminate wrong answers

Option A is wrong because an SSH key not being authorized would generate a 'Failed publickey for <valid_user>' message, not 'invalid user'. Option B is wrong because a locked account (e.g., via `passwd -l` or expired password) would produce a 'Failed password for <valid_user>' or 'Authentication failure' log entry, not 'invalid user'. Option D is wrong because an expired password triggers a password change prompt or a 'Password expired' message during authentication, and the log would still reference a valid username, not 'invalid user'.

34
MCQhard

A system administrator needs to schedule a one-time task that will run at 2:30 AM on July 15. Which command should be used to create this job?

A.at 2:30 AM July 15
B.crontab -e
C.systemd-run --on-calendar="*-07-15 02:30:00"
D.batch
AnswerA

The at command schedules a one-time task at a specified time and date. Running at 2:30 AM July 15 enters an interactive prompt where the command can be typed, and it will execute once at that time. This is the correct tool for one-time scheduling.

Why this answer

The at command is specifically designed for scheduling one-time tasks at a precise date and time. Using at 2:30 AM July 15 allows the administrator to queue a command that will execute once at that moment, fulfilling the requirement.

Exam trap

The trap here is confusing one-time scheduling with recurring jobs; cron is for recurring tasks, while at handles single executions.

35
MCQhard

An administrator needs to ensure that a custom service, /usr/local/bin/monitor.sh, starts automatically at boot and is restarted if it crashes. The service should run as user 'monitor' and should not depend on network being online. Which systemd unit file configuration is most appropriate?

A.Create a unit file with [Service] Type=simple, ExecStart=/usr/local/bin/monitor.sh, Restart=on-abnormal, User=monitor, and [Install] WantedBy=multi-user.target.
B.Create a unit file with [Service] Type=simple, ExecStart=/usr/local/bin/monitor.sh, Restart=always, User=monitor, and [Install] WantedBy=multi-user.target.
C.Create a unit file with [Service] Type=simple, ExecStart=/usr/local/bin/monitor.sh, Restart=always, User=monitor, and [Install] WantedBy=graphical.target.
D.Create a unit file with [Service] Type=forking, ExecStart=/usr/local/bin/monitor.sh, Restart=on-failure, User=monitor, and [Install] WantedBy=network-online.target.
AnswerB

This configuration defines a simple service that runs the script, restarts on any exit, runs as the specified user, and is enabled at boot via multi-user.target. It meets all requirements: automatic start, restart on crash, user context, and no network dependency. The Type=simple is appropriate for a script that does not fork.

Why this answer

A systemd service unit must specify the correct Type, ExecStart, Restart policy, User, and installation target. For a script that runs in the foreground, Type=simple is suitable. Restart=always ensures the service is restarted regardless of exit status, providing resilience.

User=monitor runs it with least privilege. WantedBy=multi-user.target enables start at boot without network dependency. This combination satisfies all stated requirements.

Exam trap

The trap here is assuming that Restart=on-failure covers all crash scenarios, but a script might exit with status 0 even after an internal error.

36
MCQmedium

A server is experiencing high load, and the administrator suspects a runaway process is consuming excessive CPU. The administrator wants to identify the top CPU-consuming processes and then terminate the most resource-intensive one. Which sequence of commands should the administrator use?

A.Run 'vmstat 1' to identify the PID, then run 'pkill -f <process_name>'.
B.Run 'ps aux --sort=-%mem' to find the top CPU process, then run 'kill -15 <PID>'.
C.Run 'iostat -c' to identify the PID, then run 'killall <process_name>'.
D.Run 'top' to identify the PID with highest CPU usage, then run 'kill -9 <PID>'.
AnswerD

top provides a real-time, sorted view of processes by CPU usage, making it easy to spot the top consumer. Once the PID is known, kill -9 sends SIGKILL, which forcibly terminates the process. This combination directly addresses the goal of identifying and stopping the runaway process, though SIGKILL should be used as a last resort.

Why this answer

To find the process consuming the most CPU, a tool that shows per-process CPU usage sorted dynamically is needed. top provides that view and allows the administrator to note the PID. Once the PID is known, kill -9 sends SIGKILL to forcibly terminate it. The other options either use tools that lack per-process CPU details or send signals that may not stop a runaway process, and they do not correctly identify the top CPU consumer.

Exam trap

The trap here is confusing tools that show system-wide CPU statistics with those that show per-process CPU usage, and assuming a graceful signal will always stop a runaway process.

37
MCQhard

A system running RHEL 8 experiences intermittent crashes. After reboot, 'journalctl -p err -b -1' outputs: 'PID 1234 (myapp) ended due to signal: KILL'. Which diagnostic step should the administrator perform next?

A.Review logrotate configuration for myapp logs.
B.Run strace to capture system calls of myapp before restarting.
C.Enable core dumps and reproduce issue.
D.Check journalctl for 'oom-kill' entries or use 'dmesg | grep -i oom'.
AnswerD

SIGKILL combined with intermittent crashes points to the kernel OOM killer terminating myapp. Checking journalctl for oom-kill entries or grepping dmesg confirms whether memory exhaustion, not an application fault, caused the kill, directing the next diagnostic step.

Why this answer

The 'PID ended due to signal: KILL' message indicates the process was terminated by a SIGKILL (signal 9), which is commonly sent by the Out-Of-Memory (OOM) killer when the system runs low on memory. Checking journalctl for 'oom-kill' entries or using 'dmesg | grep -i oom' directly confirms whether the OOM killer was responsible, making D the correct next diagnostic step.

Exam trap

The trap here is that candidates may confuse 'signal: KILL' with a manual kill command or a segmentation fault, leading them to choose core dumps (C) or strace (B), when the specific signal name 'KILL' (SIGKILL) points directly to the OOM killer or an explicit kill -9, and the OOM killer is the most common cause in intermittent crash scenarios.

How to eliminate wrong answers

Option A is wrong because logrotate configuration affects log rotation and compression, not process termination causes; it would not help diagnose why myapp was killed. Option B is wrong because strace captures system calls of a running process, but myapp has already crashed and cannot be traced without reproducing the issue first; this is a premature step before confirming the root cause. Option C is wrong because enabling core dumps and reproducing the issue is useful for debugging segmentation faults or other signals (e.g., SIGSEGV), but SIGKILL cannot be caught or handled by the process, so no core dump is generated; this step would be ineffective here.

38
MCQmedium

A process (PID 1234) is hung and cannot be killed with SIGTERM. To force termination, which signal should be sent?

A.kill -9 1234 (SIGKILL)
B.kill -15 1234 (SIGTERM)
C.kill -2 1234 (SIGINT)
D.kill -1 1234 (SIGHUP)
AnswerA

SIGKILL (signal 9) cannot be caught, blocked or ignored by the process, so the kernel terminates it immediately without waiting for handler cleanup. SIGTERM is catchable, which is why the hung process survived the earlier attempt.

Why this answer

SIGKILL (signal 9) is the correct choice because it cannot be caught, blocked, or ignored by the process. Unlike SIGTERM, which allows the process to perform cleanup, SIGKILL immediately terminates the process at the kernel level, making it the only reliable way to force-kill a hung process that ignores other signals.

Exam trap

The trap here is that candidates often confuse SIGTERM (15) as a 'force kill' signal, not realizing that a hung process can ignore it, while SIGKILL (9) is the only signal that guarantees termination.

How to eliminate wrong answers

Option B (SIGTERM, signal 15) is wrong because it is the default polite termination signal that the process can catch and ignore, which is exactly why it failed to kill the hung process. Option C (SIGINT, signal 2) is wrong because it is typically generated by Ctrl+C and can be caught or ignored by the process, making it ineffective for a hung process. Option D (SIGHUP, signal 1) is wrong because it is primarily used to notify a process of terminal disconnection or to reload configuration, and it can also be caught or ignored, so it will not force termination.

39
MCQmedium

A Linux server's root filesystem is filling up quickly. You suspect that a user's process is writing a large log file and that the file has been deleted, but the space is still held. Which command will show the deleted file and the process holding it open?

A.df -h
B.lsof +L1
C.du -sh /var/log
D.fuser -m /
AnswerB

The lsof +L1 command lists open files with a link count less than 1, which indicates files that have been unlinked (deleted) but are still held open by a process. This directly reveals the deleted file and the process ID, allowing you to restart the process and reclaim space.

Why this answer

The correct tool is lsof +L1, which specifically finds open files with a link count of zero, meaning they have been deleted but are still held open by a process. This is the standard method to identify the culprit consuming disk space invisibly to df and du.

Exam trap

The trap here is assuming that df and du should always match; they diverge when deleted files are held open, and only lsof +L1 reveals the discrepancy.

40
MCQeasy

An administrator wants to view the current memory usage in a human-readable format, showing totals for used and free memory. Which command should be used?

A.vmstat
B.free -h
C.top
D.cat /proc/meminfo
AnswerB

`free -h` reads `/proc/meminfo` and prints used, free, shared, buff/cache and available memory, with the `-h` flag scaling values into human-readable units such as MiB and GiB. This directly satisfies the stem's requirement for totals in a readable format, unlike `-b`, `-k` or `-m`, which force fixed byte, KiB or MiB units.

Why this answer

The `free -h` command displays memory usage in a human-readable format (e.g., MiB, GiB) and shows totals for used and free memory, including buffers/cache and swap. This directly matches the requirement for a quick, readable summary of memory usage.

Exam trap

The trap here is that candidates may choose `cat /proc/meminfo` because it contains all memory details, but they overlook the requirement for a human-readable format and totals, which `free -h` provides directly.

How to eliminate wrong answers

Option A is wrong because `vmstat` reports virtual memory statistics, process, CPU, and I/O activity, but it does not present totals for used and free memory in a human-readable format by default; its output is in raw numbers and requires interpretation. Option C is wrong because `top` provides a real-time, dynamic view of system processes and memory usage, but it is interactive and not designed for a single, static human-readable summary of total used and free memory. Option D is wrong because `cat /proc/meminfo` outputs raw kernel memory statistics in kilobytes, which is not human-readable and requires manual calculation to derive totals for used and free memory.

41
MCQmedium

A Linux server has its time zone set to UTC, but the administrator wants the system clock to be synchronized by an internal NTP server at 10.0.0.10. The system uses systemd and chrony is already installed. Which command should the administrator run to configure the NTP server and make it persistent?

A.timedatectl set-timezone America/New_York
B.chronyc sources add 10.0.0.10
C.Edit /etc/chrony.conf to include 'server 10.0.0.10 iburst' and restart chronyd
D.systemctl enable --now ntp.service
AnswerC

The correct method is to edit the chrony configuration file, typically /etc/chrony.conf, and add a server directive pointing to 10.0.0.10. The 'iburst' option speeds up initial synchronization. After saving the file, restarting the chronyd service applies the change and ensures it persists across reboots. This directly fulfills the administrator's goal.

Why this answer

Configuring chrony requires editing its configuration file, usually /etc/chrony.conf, to specify the NTP server, and then restarting the chronyd service to apply the changes. This makes the configuration persistent. The other options either change the time zone, use an incorrect chronyc subcommand, or attempt to use the wrong service, none of which set the NTP server as needed.

Exam trap

The trap here is confusing chrony configuration with time zone changes or using chronyc interactively instead of editing the persistent configuration file.

42
Multi-Selectmedium

A Linux administrator needs to ensure that the 'httpd' service starts automatically at boot and is currently running. The system uses systemd. Which two commands should the administrator use to achieve this? (Choose two.)

Select 2 answers
A.systemctl enable httpd
B.systemctl reload httpd
C.systemctl start httpd
D.systemctl status httpd
E.systemctl is-enabled httpd
AnswersA, C

This command creates the necessary symbolic links to enable the httpd service to start automatically at boot. It does not start the service immediately, but it ensures persistence across reboots. Combined with a command to start the service now, it fulfills the requirement. It is a standard systemd command for enabling a unit.

Why this answer

To make httpd start at boot and be currently running, the administrator must enable it for automatic start with 'systemctl enable httpd' and start it immediately with 'systemctl start httpd'. These two actions are independent and both necessary. The other commands either check status, reload configuration, or verify enablement, but none of them both enable and start the service.

Exam trap

The trap here is confusing enabling a service with starting it; enabling only affects boot behavior, while starting affects the current runtime state.

43
MCQeasy

A system administrator needs to check the current CPU load and memory usage on a Linux server. Which command should be used to display a dynamic, real-time view of running processes and system resource utilization?

A.uptime
B.top
C.ps aux
D.free -h
AnswerB

top provides a continuously refreshing, real-time view of running processes alongside CPU load averages and memory utilisation, updating by default every few seconds. This satisfies the dynamic, real-time requirement, unlike one-shot tools such as free or vmstat.

Why this answer

(top) is correct because it provides a dynamic, real-time view of running processes and system resource utilization, including CPU load, memory usage, and process details. It updates continuously by default, making it ideal for monitoring live system performance.

Exam trap

The trap here is that candidates may confuse static commands like ps aux or free -h with the dynamic, real-time requirement, or assume uptime provides process-level detail, when only top (or similar tools like htop) continuously updates process and resource data.

How to eliminate wrong answers

Option A (uptime) is wrong because it only displays how long the system has been running, the number of users, and load averages for 1, 5, and 15 minutes; it does not show a dynamic, real-time view of processes or memory usage. Option C (ps aux) is wrong because it provides a static snapshot of all running processes at the moment of execution, not a continuously updating real-time display. Option D (free -h) is wrong because it shows memory and swap usage in a human-readable format, but it is a static report and does not display running processes or CPU load in real time.

44
MCQeasy

A system administrator notices that a process is consuming 100% CPU and is unresponsive. Which command should be used to immediately stop the process if the PID is 2345?

A.kill -9 2345
B.pkill -9 processname
C.systemctl stop processname
D.kill -15 2345
AnswerA

Sending SIGKILL (signal 9) to PID 2345 forces immediate termination at the kernel level, since the process cannot catch, block or ignore this signal. This satisfies the stem's requirement to stop an unresponsive process immediately, whereas gentler signals such as SIGTERM may be ignored by a hung process.

Why this answer

`kill -9 2345` sends the SIGKILL signal (signal 9) to process ID 2345, which immediately terminates the process without allowing it to clean up or ignore the signal. This is the appropriate action for an unresponsive process consuming 100% CPU, as SIGKILL cannot be caught or blocked by the process.

Exam trap

The trap here is that candidates may choose `kill -15` (SIGTERM) thinking it is safer, but the question explicitly requires immediate stoppage of an unresponsive process, where only SIGKILL guarantees termination.

How to eliminate wrong answers

Option B is wrong because `pkill -9 processname` would require the process name, not the PID, and the question specifies that the PID is known (2345); using `pkill` with a name could accidentally terminate other processes with similar names. Option C is wrong because `systemctl stop processname` is used to manage systemd services, not arbitrary user processes, and it sends SIGTERM (signal 15) which the unresponsive process may ignore. Option D is wrong because `kill -15 2345` sends SIGTERM, which requests graceful termination but can be ignored or blocked by a process that is stuck or unresponsive, making it ineffective for immediate stoppage.

45
MCQmedium

A systems administrator is troubleshooting a server that runs a database application. The server has 64 GB of RAM and 16 CPU cores. The administrator notices that the system is using a significant amount of swap space even though there is plenty of free memory. The 'free -m' command shows: total memory = 65536, used = 50000, free = 15536, buffers/cache = 10000, swap total = 8192, swap used = 6000. Which of the following is the most likely cause?

A.The vm.dirty_ratio and vm.dirty_background_ratio are set too high.
B.The vm.swappiness value is set too high.
C.The database is configured to use huge pages, which are not swappable.
D.The vm.vfs_cache_pressure is set too low.
AnswerB

A high vm.swappiness value makes the kernel aggressively reclaim anonymous pages to swap even when free memory remains, matching the observed 6 GB swap usage alongside 15 GB free. Lowering swappiness keeps pages resident until memory pressure genuinely demands swapping.

Why this answer

A high vm.swappiness value (default 60) causes the kernel to aggressively swap out anonymous pages even when ample free memory exists. With 15 GB free and 10 GB in buffers/cache, the system should not be using 6 GB of swap unless swappiness is set too high, forcing premature swapping.

Exam trap

Linux Foundation often tests the misconception that swap usage only occurs when memory is full, but the trap here is that vm.swappiness can cause swapping even with abundant free memory, leading candidates to overlook the kernel's proactive swapping behavior.

How to eliminate wrong answers

Option A is wrong because vm.dirty_ratio and vm.dirty_background_ratio control when dirty pages are written to disk, not swap usage; they affect I/O performance, not memory pressure. Option C is wrong because huge pages are locked in memory and not swappable, so they would reduce swap usage, not increase it. Option D is wrong because vm.vfs_cache_pressure controls the tendency to reclaim dentry/inode caches, not anonymous page swapping; a low value would preserve cache, not cause swap usage.

46
Multi-Selectmedium

A Linux server is experiencing performance degradation. The administrator suspects that a process is consuming excessive CPU. Which two commands can be used to identify the top CPU-consuming processes in real-time? (Choose two.)

Select 2 answers
A.top
B.vmstat 1
C.free -m
D.ps aux --sort=-%cpu
E.iostat -c
AnswersA, D

The top command provides a dynamic, real-time view of running processes, sorted by CPU usage by default. It displays %CPU, making it easy to identify processes consuming the most CPU. It also allows interactive sorting and killing of processes. This is a standard tool for performance troubleshooting.

Why this answer

To identify top CPU-consuming processes, tools that show per-process CPU usage are needed. top provides a real-time, interactive view, while ps aux --sort=-%cpu gives a sorted snapshot. Both allow the administrator to see which processes are using the most CPU. vmstat and iostat show system-wide CPU statistics but not per-process details, and free is for memory. Therefore, top and ps with sorting are the correct choices.

Exam trap

The trap here is thinking that any command showing CPU statistics will identify the specific process; only per-process tools like top or ps do that.

47
MCQmedium

Based on the exhibit, which process is using the most physical memory (RES)?

A.mysqld (PID 9101)
B.Not determinable from exhibit
C.nginx (PID 5678)
D.systemd (PID 1234)
AnswerA

The RES column in top reports resident set size, the non-swapped physical memory a process currently occupies. Comparing RES values across the exhibit, mysqld at PID 9101 holds the largest figure, so it consumes the most physical memory.

Why this answer

The exhibit shows the output of the `top` command, where the RES column indicates the resident memory (physical RAM) used by each process. mysqld (PID 9101) has a RES value of 2.5g, which is significantly higher than nginx (PID 5678) with 128m and systemd (PID 1234) with 48m, making it the process using the most physical memory.

Exam trap

The trap here is that candidates may confuse the VIRT (virtual memory) column with RES, or assume that a process with a higher PID or name familiarity uses more memory, rather than reading the RES values directly from the exhibit.

How to eliminate wrong answers

Option B is wrong because the exhibit clearly displays the RES column for each process, allowing direct comparison of physical memory usage. Option C is wrong because nginx (PID 5678) shows only 128m in the RES column, which is far less than mysqld's 2.5g. Option D is wrong because systemd (PID 1234) has only 48m in the RES column, the smallest value among the listed processes.

48
MCQeasy

A Linux administrator needs to schedule a backup script to run every day at 2:30 AM. The script is located at /usr/local/bin/backup.sh. Which command should the administrator use to edit the crontab for the root user?

A.systemctl edit cron.service
B.vi /etc/crontab
C.crontab -l
D.crontab -e
AnswerD

Running 'crontab -e' as root opens the root user's crontab in the default editor, allowing the administrator to add the schedule for the backup script. This is the standard method to create or modify a user's cron jobs. It ensures the job runs with root privileges and is the correct command for this scenario.

Why this answer

The command 'crontab -e' opens the crontab file for the current user (root in this case) in an editor, allowing the administrator to add the line '30 2 * * * /usr/local/bin/backup.sh'. This is the standard and safest way to schedule a recurring job. Other options either list jobs, edit a system file inappropriately, or modify the service unit, none of which achieve the goal.

Exam trap

The trap here is thinking that editing /etc/crontab directly is equivalent to using crontab -e, but the system-wide file requires a username field and is not the recommended method for user-specific jobs.

49
MCQeasy

A junior administrator needs to check the current system time and date on a Linux server. Which command will display this information?

A.hwclock
B.uptime
C.date
D.timedatectl status
AnswerC

The date command displays the current system date and time according to the system clock. It can also be used to set the date, but without arguments it simply prints the current date and time in the default format.

Why this answer

The date command is the standard utility to display the current system date and time. It is simple, universally available, and directly outputs the information requested without additional details.

Exam trap

The trap here is overcomplicating a basic task; while other commands show time-related information, only date is dedicated to displaying the system date and time.

50
MCQhard

A Linux server's root filesystem is running out of space. The administrator needs to identify which directory under /var is consuming the most disk space. Which command should the administrator use?

A.ls -lR /var | sort -k5 -n
B.df -h /var
C.find /var -type d -exec du -sh {} \;
D.du -sh /var/*
AnswerD

The command 'du -sh /var/*' summarizes the disk usage of each item directly under /var in human-readable format. It shows the total size of each directory or file, allowing the administrator to quickly identify which subdirectory is largest. This directly answers the question of which directory under /var consumes the most space. It is efficient and does not require recursive listing of all files.

Why this answer

The command 'du -sh /var/*' provides a concise summary of disk usage for each top-level item in /var, making it easy to spot the largest directory. It uses the -s option to summarize and -h for human-readable output. Other commands either show filesystem-level usage, list individual files, or produce excessive output, none of which efficiently identify the largest directory under /var.

Exam trap

The trap here is using df to check filesystem usage instead of du to find directory sizes; df shows the whole filesystem, not the breakdown within it.

51
MCQmedium

A system administrator is troubleshooting a production web server running CentOS 7 that became unresponsive. The server is still pingable, but SSH connections timeout. The admin performs an out-of-band console login. The server appears frozen; typing commands shows no output. The admin is able to trigger a Magic SysRq key sequence (Alt+SysRq+f) to kill the hung processes. After that, the server resumes normal operation. However, the admin wants to understand the root cause. Upon checking 'dmesg', they see repeated messages: 'NMI watchdog: BUG: soft lockup - CPU#0 stuck for 22s!' followed by stack traces from a kernel thread. Which action should the admin take to prevent recurrence while maintaining system stability?

A.Replace the power supply unit to ensure stable power.
B.Increase the soft lockup threshold via sysctl to reduce false positives.
C.Add 'nosoftlockup' to the kernel boot parameters.
D.Update the server's BIOS/firmware and check for kernel updates.
AnswerD

Soft lockups in kernel threads typically stem from firmware bugs or kernel defects rather than user processes, so the Magic SysRq kill only masks symptoms. Updating BIOS/firmware and applying kernel updates addresses the underlying CPU or scheduler defect that caused the 22-second stall, preventing recurrence.

Why this answer

Soft lockup errors on CentOS 7 often indicate kernel bugs or hardware/firmware issues that cause CPUs to stall for extended periods. Updating the BIOS/firmware can resolve underlying hardware timing problems, while kernel updates may include patches for known soft lockup bugs. This approach addresses the root cause without disabling or weakening the watchdog mechanism, preserving system stability.

Exam trap

The trap here is that candidates may think soft lockup errors are false positives or can be safely ignored by increasing thresholds or disabling the watchdog, when in fact they indicate a genuine kernel or hardware issue that requires a proper fix.

How to eliminate wrong answers

Option A is wrong because a failing power supply typically causes random crashes or power-offs, not soft lockup errors in a single CPU core with a stuck kernel thread. Option B is wrong because increasing the soft lockup threshold merely masks the symptom by allowing longer stalls before detection, which can lead to worse system degradation and does not fix the underlying cause. Option C is wrong because adding 'nosoftlockup' disables the NMI watchdog entirely, removing the ability to detect and recover from soft lockups, which compromises system stability and is not a proper fix.

52
MCQhard

An administrator is investigating why the 'tomcat' service fails to start on a RHEL 8 server. The output of 'systemctl status tomcat' shows: 'Loaded: loaded (/etc/systemd/system/tomcat.service; enabled; vendor preset: disabled) Active: failed (Result: exit-code) since ... Process: 4567 ExecStart=/opt/tomcat/bin/startup.sh (code=exited, status=1/FAILURE)'. The 'journalctl -u tomcat' shows: 'Error: JAVA_HOME is not defined correctly, cannot execute /usr/lib/jvm/java-11-openjdk/bin/java'. The admin checks /opt/tomcat/bin/startup.sh and sees it references JAVA_HOME. The admin verifies that Java 11 is installed at /usr/lib/jvm/java-11-openjdk. Which action should the admin take to fix the service?

A.Edit /opt/tomcat/bin/startup.sh and hardcode JAVA_HOME.
B.Add 'Environment=JAVA_HOME=/usr/lib/jvm/java-11-openjdk' to the [Service] section of /etc/systemd/system/tomcat.service and run 'systemctl daemon-reload && systemctl restart tomcat'.
C.Run the startup script manually with 'bash /opt/tomcat/bin/startup.sh'.
D.Set JAVA_HOME globally using 'export JAVA_HOME=/usr/lib/jvm/java-11-openjdk' in /etc/profile.
AnswerB

The unit runs startup.sh without a shell profile, so JAVA_HOME is unset in the service environment, causing the exit-code 1 failure. Declaring Environment=JAVA_HOME in the [Service] section injects the variable directly into the unit's environment, satisfying the script's requirement; daemon-reload applies the change.

Why this answer

Systemd services can have environment variables set via the `Environment=` directive in the unit file. Adding `JAVA_HOME=/usr/lib/jvm/java-11-openjdk` to the `[Service]` section ensures the variable is available to the `ExecStart` process. Running `systemctl daemon-reload` reloads the unit definition, and `systemctl restart tomcat` applies the change.

This is the proper method for configuring environment variables for systemd-managed services on RHEL 8.

Exam trap

The trap here is that candidates assume setting environment variables in shell profile files (like `/etc/profile`) will affect systemd services, but systemd does not source these files; the correct method is to use the `Environment=` directive in the unit file.

How to eliminate wrong answers

Option A is wrong because hardcoding `JAVA_HOME` in the startup script is fragile and not the standard approach; it breaks updates or script reuse and does not leverage systemd's environment management. Option C is wrong because manually running the script bypasses systemd's service management, logging, and dependency handling, and does not fix the underlying environment variable issue for the service. Option D is wrong because setting `JAVA_HOME` in `/etc/profile` only affects login shells, not the systemd service environment; systemd services do not source profile files.

Ready to test yourself?

Try a timed practice session using only Operation of Running Systems questions.