LFCS Essential Commands Practice Question
You are a system administrator for a company that runs a web server on a Linux system. The web server logs are stored in /var/log/nginx/access.log. The log file grows rapidly and rotates weekly via logrotate. The system has been running for several months. Recently, the development team reported that the web server is responding slowly. You suspect that the disk I/O might be high due to log file activity. You check the disk usage and find that /var/log/nginx/access.log is 4 GB, and the rotated logs (access.log.1.gz, access.log.2.gz, etc.) total another 10 GB. The /var partition has 20 GB total, so it's 70% full. You decide to reduce the disk usage by compressing the current log file and truncating it without stopping the nginx service. Which command sequence should you use to safely achieve this?
⚠ Common exam trap
Watch out — candidates often choose `mv` and `touch` (Option D) thinking it's the standard logrotate method, but without signaling nginx, the old file descriptor remains attached to the moved file, causing the new empty file to be ignored and log data to be written to the renamed file instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cp /var/log/nginx/access.log /var/log/nginx/access.log.bak && :> /var/log/nginx/access.log && gzip /var/log/nginx/access.log.bak
It first copies the current log file to a backup, then truncates the original file in place using the shell null command (`:>`) without stopping nginx, and finally compresses the backup. This ensures nginx continues writing to the same inode (file descriptor remains valid) and the disk space is reclaimed after compression.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
:> /var/log/nginx/access.log && cp /var/log/nginx/access.log /var/log/nginx/access.log.bak && gzip /var/log/nginx/access.log.bak
Why it's wrong here
Truncating first empties the file, so the subsequent copy captures nothing and the original 4 GB of content is lost before compression. The sequence compresses an empty backup. Copying the file to a separate path, then truncating the original and gzipping the copy, preserves the data.
- ✓
cp /var/log/nginx/access.log /var/log/nginx/access.log.bak && :> /var/log/nginx/access.log && gzip /var/log/nginx/access.log.bak
Why this is correct
Copying the log preserves its contents, then truncating with ':>' empties the original inode while nginx keeps writing to it, and gzip compresses the backup. This satisfies the constraint of compressing and truncating without stopping nginx, avoiding the inode-swap problem that 'mv' would cause.
- ✗
rm /var/log/nginx/access.log && touch /var/log/nginx/access.log && chmod 644 /var/log/nginx/access.log
Why it's wrong here
Deleting the file discards all 4 GB of log data and leaves nginx holding the unlinked inode, so space is not freed until restart. It is tempting because removal appears to reclaim space instantly, and would be correct when the logs are genuinely unwanted and no audit retention applies.
- ✗
mv /var/log/nginx/access.log /var/log/nginx/access.log.bak && touch /var/log/nginx/access.log && gzip /var/log/nginx/access.log.bak
Why it's wrong here
Renaming the file leaves nginx writing to the original inode, so the 4 GB is never reclaimed and the new access.log stays empty. This pattern is tempting because it mirrors logrotate's create mode, and would be correct when the daemon reopens its log on SIGHUP or restart.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.