Courseiva

CCNA Essential Commands Questions

11 of 86 questions · Page 2/2 · Essential Commands topic · Answers revealed

76
MCQeasy

A user reports that they cannot run a script because it says 'Permission denied'. The script is owned by root and has permissions -rw-r--r--. Which command would allow the user to execute the script?

A.chmod u+s script
B.chmod +x script
C.chmod -w script
D.chown user:user script
AnswerB

chmod +x adds execute permission for user, group and others, addressing the missing execute bit in -rw-r--r--. This satisfies the Permission denied constraint, though the user also needs read access, which the existing permissions already grant.

Why this answer

The script has permissions `-rw-r--r--`, meaning the owner (root) has read/write, but no execute bit is set for any user. Option B (`chmod +x script`) adds the execute permission for all users (owner, group, others), which allows the user to run the script. Without the execute bit, the kernel will refuse to execve() the file, returning EACCES.

Exam trap

The trap here is that candidates may confuse ownership or SUID with the fundamental requirement of the execute bit, thinking that changing the owner or setting the setuid bit will allow execution, when in fact the kernel strictly requires the 'x' bit to be set for the file to be run as a program.

How to eliminate wrong answers

Option A is wrong because `chmod u+s` sets the setuid bit (SUID), which only affects the effective user ID during execution, but does not grant execute permission; the file still lacks the execute bit, so the script cannot be run. Option C is wrong because `chmod -w` removes write permission, which does not solve the missing execute permission; the user already cannot write to the file, and this change would only further restrict access. Option D is wrong because `chown user:user script` changes ownership to the user, which would give the user owner permissions (read/write), but the file still lacks the execute bit; ownership alone does not enable execution.

77
MCQmedium

A DevOps engineer is writing a continuous integration pipeline that runs a script to deploy an application. The script is stored in a Git repository and is executed on a build server. The script works locally on the engineer's workstation, but when executed on the build server, it fails with '/bin/sh: line 12: somecommand: command not found'. The 'somecommand' is a standard Linux tool that is installed on the build server. The build server uses a minimal Docker container. Which of the following is the most likely cause and solution?

A.The PATH environment variable is not set correctly in the non-interactive shell. Use the full path to 'somecommand' or set PATH explicitly in the script.
B.The script does not have execute permissions. Add 'chmod +x' before running the script.
C.The script requires root privileges. Use 'sudo' to run the script.
D.The script is using a different shell than the build server's default. Change the shebang to '#!/bin/sh'.
AnswerA

Non-interactive shells in minimal containers often inherit a stripped PATH lacking the directory holding somecommand, so the lookup fails despite installation. Invoking the absolute path or exporting PATH within the script restores resolution, matching the 'command not found' error on the build server.

Why this answer

The error 'command not found' despite the tool being installed indicates that the shell cannot locate the executable. In a non-interactive shell (like those used in CI/CD pipelines or minimal Docker containers), the PATH environment variable is often not set or is minimal. The fix is to either use the absolute path to the command or explicitly set PATH in the script to include the directory containing the command.

Exam trap

The trap here is that candidates often confuse 'command not found' with missing permissions or wrong shell, but the real issue is the missing or incomplete PATH in non-interactive shells, a classic pitfall in containerized or automated environments.

How to eliminate wrong answers

Option B is wrong because the error message 'command not found' is not related to file execute permissions; a missing execute permission would produce 'Permission denied', not 'command not found'. Option C is wrong because the error is about command resolution, not about insufficient privileges; if root were needed, the error would typically be 'Permission denied' or a different system call failure. Option D is wrong because the error message explicitly shows '/bin/sh' is being used, and the shebang '#!/bin/sh' would not change the fact that the command is not found; the issue is PATH, not the shell interpreter.

78
MCQmedium

A server's root filesystem is filling up. An administrator needs to find the largest regular files under /var, sorted from largest to smallest, while avoiding errors from unreadable directories that are not owned by the administrator. Which command is most appropriate?

A.find /var -type f -printf '%s %p\n' 2>/dev/null | sort -rn | head -n 20
B.find /var -type d -exec du -sh {} + | sort -rh
C.du -ah /var | sort -rh | head -n 20
D.ls -lR /var | sort -k5 -n | tail -n 20
AnswerA

find with -type f restricts results to regular files, -printf outputs size in bytes followed by the path, and redirecting stderr suppresses permission errors from unreadable directories. Piping to sort -rn and head yields the largest files first, exactly matching the scenario's requirements.

Why this answer

The precise approach is to use find restricted to regular files, print size and path, discard error output, then sort numerically in reverse and take the top entries. This avoids directory totals and unreadable-path noise. Recursive ls parsing is unreliable, du shows directory aggregates, and searching only directories answers a different question.

Exam trap

The trap here is using du, which reports directory totals, when the task specifically asks for individual regular files.

79
Multi-Selectmedium

Which THREE commands can be used to view the contents of a file?

Select 3 answers
A.grep
B.find
C.cat
D.head
E.less
AnswersC, D, E

Concatenates and displays file contents.

Why this answer

The `cat` command (option C) is a standard Unix utility that reads files sequentially and outputs their contents to the standard output. It is one of the most basic and direct ways to view the entire content of a file in the terminal.

Exam trap

The trap here is that candidates may confuse `grep` (which can display matching lines) with a file-viewing command, or think `find` can show file contents because it locates files, but neither is designed for that purpose.

80
MCQeasy

A system administrator needs to find all files in /var/log that have been modified in the last 7 days. Which command accomplishes this?

A.find /var/log -type f -atime -7
B.find /var/log -type f -ctime -7
C.find /var/log -type f -mtime +7
D.find /var/log -type f -mtime -7
AnswerD

Correct: -mtime -7 means modified less than 7 days ago.

Why this answer

The `find` command with `-mtime -7` searches for files whose modification time (content change) is less than 7 days ago, which matches the requirement of 'modified in the last 7 days'. The `-type f` restricts the search to regular files, and `/var/log` is the target directory.

Exam trap

The trap here is confusing `-mtime` (modification time) with `-ctime` (inode change time) or `-atime` (access time), as candidates often mistakenly think 'changed' refers to content modification rather than metadata changes.

How to eliminate wrong answers

Option A is wrong because `-atime -7` searches for files accessed (read) in the last 7 days, not modified; this tests access time, not content change. Option B is wrong because `-ctime -7` searches for files whose metadata (inode change) was modified in the last 7 days, such as permissions or ownership changes, not file content modification. Option C is wrong because `-mtime +7` finds files modified more than 7 days ago (older than 7 days), which is the opposite of the requirement.

81
MCQeasy

A system administrator notices that '/var/log/syslog' has grown very large and is consuming significant disk space. The administrator wants to identify the largest log files in the '/var/log' directory hierarchy. Which command should the administrator use?

A.find /var/log -size +100M -exec ls -lh {} \;
B.du -ah /var/log | sort -hr | head -10
C.df -h /var/log
D.ls -lhS /var/log
AnswerB

`du -ah` reports apparent sizes for every file and directory under /var/log, then `sort -hr` orders them largest-first by human-readable size and `head -10` shows the top ten. This directly satisfies the goal of identifying the largest log files within the hierarchy.

Why this answer

`du -ah /var/log` calculates the disk usage of all files and directories in `/var/log` in human-readable format, then `sort -hr` sorts them by size in descending order, and `head -10` shows the top 10 largest entries. This directly identifies the largest log files in the hierarchy, which is exactly what the administrator needs.

Exam trap

The trap here is that candidates often choose `ls -lhS /var/log` (option D) because it sorts by size, but they overlook that it does not recurse into subdirectories, missing large files in subfolders like `/var/log/apache2/` or `/var/log/journal/`.

How to eliminate wrong answers

Option A is wrong because `find /var/log -size +100M` only finds files larger than 100 MB, missing any large files under that threshold, and it does not sort or limit results, so it may not show the largest files overall. Option C is wrong because `df -h /var/log` shows the total disk usage and available space of the filesystem containing `/var/log`, not the sizes of individual files or directories. Option D is wrong because `ls -lhS /var/log` lists only the immediate contents of `/var/log` sorted by size, but it does not recurse into subdirectories, so it misses large files deeper in the hierarchy.

82
MCQmedium

A support engineer must copy the file /etc/hosts to /tmp/hosts.backup but only if /tmp/hosts.backup does not already exist, so that an existing backup is never overwritten. Which command performs this conditionally?

A.cp --no-clobber /etc/hosts /tmp/hosts.backup
B.cp --update /etc/hosts /tmp/hosts.backup
C.cp --backup /etc/hosts /tmp/hosts.backup
D.cp --preserve=all /etc/hosts /tmp/hosts.backup
AnswerA

The --no-clobber option instructs cp not to overwrite an existing destination file. If /tmp/hosts.backup is already present, cp skips the copy and exits without replacing it, preserving the old backup. If the destination is absent, the file is copied normally. This precisely implements the required conditional copy and avoids destroying any existing backup content.

Why this answer

The --no-clobber option makes cp skip the operation entirely when the destination already exists, leaving the existing backup intact while still performing the copy when the destination is absent. The other options either ignore existence altogether, base the decision on timestamps, or rename the old file, all of which still result in the destination being replaced.

Exam trap

The trap here is confusing --update with --no-clobber; --update compares timestamps and can still overwrite a backup, whereas --no-clobber keys purely on whether the destination already exists.

83
Multi-Selecthard

An administrator needs to inspect the first few lines of a very large log file /var/log/syslog without loading the entire file into memory, and also needs to follow new entries as they are appended in real time. Which TWO commands or command combinations satisfy these requirements? (Choose two.)

Select 2 answers
A.wc -l /var/log/syslog
B.head -n 20 /var/log/syslog
C.tail -f /var/log/syslog
D.grep -r '' /var/log/syslog
E.cat /var/log/syslog | less
AnswersB, C

head reads only the requested number of lines from the start of the file and then exits, so it does not load the entire log into memory. For a first-lines inspection of a large file, this is efficient and appropriate, satisfying the requirement to view the beginning without processing the whole file.

Why this answer

Viewing the start of a large file efficiently calls for head, which stops after the requested lines. Following appended entries in real time calls for tail -f, which keeps the file open and prints new data. Commands that scan the entire file, such as cat piped to less, grep over the whole file, or wc, do not meet the efficiency or following requirements.

Exam trap

The trap here is treating any pager or search tool as equivalent to a true follow mode, when only tail -f keeps watching for new content.

84
MCQeasy

An administrator needs to compress a directory named 'project' into a tarball with maximum compression using gzip. Which command is appropriate?

A.tar -cjvf archive.tar.bz2 project
B.tar -czvf archive.tar.gz project
C.tar -cJvf archive.tar.xz project
D.tar -cvf archive.tar project
AnswerB

The -z flag pipes the archive through gzip, -c creates it, -v lists files and -f names archive.tar.gz. This produces a gzip-compressed tarball of the project directory, satisfying the maximum-compression gzip requirement, though -9 would be needed for maximum level.

Why this answer

The `-z` flag tells tar to compress the archive using gzip. The `-c` flag creates a new archive, `-v` provides verbose output, and `-f` specifies the archive filename. The `.tar.gz` extension is the conventional extension for a gzip-compressed tarball.

Although other tools like bzip2 or xz can achieve higher compression ratios, the question explicitly asks for using gzip.

Exam trap

The trap here is that candidates often confuse the compression flags (`-z` for gzip, `-j` for bzip2, `-J` for xz) and may pick option A or C thinking they provide 'maximum compression' without realizing the question specifically requires gzip, not just any compression.

How to eliminate wrong answers

Option A is wrong because the `-j` flag compresses with bzip2, not gzip, and the `.tar.bz2` extension indicates bzip2 compression, which is not what the question asks for. Option C is wrong because the `-J` flag compresses with xz, not gzip, and the `.tar.xz` extension indicates xz compression, which is a different algorithm. Option D is wrong because it creates an uncompressed tarball (no compression flag), resulting in a `.tar` file, which does not satisfy the requirement for gzip compression.

85
MCQeasy

A junior administrator needs to display the first 10 lines of a file named 'data.csv'. Which command should they use?

A.head data.csv
B.less data.csv
C.tail data.csv
D.cat data.csv
AnswerA

head prints the first ten lines of a file by default, satisfying the requirement to display only the opening portion of data.csv. No flags are needed since ten lines is the built-in default, unlike cat, which would output the entire file.

Why this answer

The `head` command is specifically designed to display the first 10 lines of a file by default. Running `head data.csv` will output the first 10 lines of the CSV file, making it the correct choice for this task.

Exam trap

The trap here is that candidates may confuse `head` with `tail` or `less`, thinking any command that displays file content can be used, but the exam specifically tests knowledge of the default behavior of each command for displaying the first lines of a file.

How to eliminate wrong answers

Option B is wrong because `less` is a pager that displays the file interactively, starting from the first line but requiring user input to scroll, and does not automatically show only the first 10 lines. Option C is wrong because `tail` displays the last 10 lines of a file by default, not the first 10 lines. Option D is wrong because `cat` outputs the entire file contents to the terminal, which is inefficient and does not limit output to the first 10 lines.

86
MCQmedium

A user reports that a script fails with 'Permission denied' when executed. The script has permissions -rw-r--r-- and is owned by the user. Which command should the user run to make the script executable for the owner only?

A.chmod u+s script.sh
B.chmod u+x script.sh
C.chown :users script.sh
D.chmod +x script.sh
AnswerB

The file lacks execute permission for the owner, producing 'Permission denied'. chmod u+x adds execute only for the owner, matching the requirement to make it executable for the owner alone without altering group or other permissions.

Why this answer

The script currently has permissions `-rw-r--r--`, meaning the owner has read and write but not execute permission. The `chmod u+x` command adds the execute permission for the owner only, which is exactly what the user needs to run the script without affecting group or others.

Exam trap

The trap here is that candidates may confuse the setuid bit (`u+s`) with the execute bit (`u+x`), or assume that `chmod +x` is equivalent to `chmod u+x`, when in fact the former grants execute to all users, which is not what the question asks.

How to eliminate wrong answers

Option A is wrong because `chmod u+s` sets the setuid bit, which allows the script to run with the owner's privileges when executed, but does not add execute permission; the script would still fail with 'Permission denied' if the execute bit is missing. Option C is wrong because `chown :users script.sh` changes the group ownership to 'users', which does not grant execute permission to the owner or anyone else. Option D is wrong because `chmod +x` adds execute permission for all three categories (owner, group, others), which is broader than the requirement to make it executable for the owner only.

← PreviousPage 2 of 2 · 86 questions total

Ready to test yourself?

Try a timed practice session using only Essential Commands questions.