LPIC-1 Devices, Filesystems and FHS Practice Question
A system administrator is troubleshooting a server where the /var partition is full, causing services to fail. The administrator deletes old log files in /var/log, but the available space does not increase. Which step should be taken next?
⚠ Common exam trap
Test-takers frequently assume deleting files immediately frees space, but they overlook that processes can keep deleted files open, and they confuse memory caches (cleared by drop_caches) with disk space.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use 'lsof /var/log' to find processes holding deleted file handles, then restart those processes.
When a file is deleted while a process still holds an open file descriptor to it, the file's data blocks are not freed until that process releases the handle. The `lsof /var/log` command identifies such processes, and restarting them forces the kernel to release the deleted inodes, thereby reclaiming the disk space. This is why option C is the correct next step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run 'sync; echo 3 > /proc/sys/vm/drop_caches' to clear cache.
Why it's wrong here
Dropping page cache frees reclaimable memory, not disk blocks; deleted files still held open by a process keep their space allocated. Clearing caches is tempting as a generic 'free resources' reflex, but the actual fix is restarting or truncating the process holding the deleted file.
- ✗
Remount the /var partition with the 'noatime' option.
Why it's wrong here
noatime suppresses access-time metadata writes, reducing future I/O; it cannot reclaim space already consumed by deleted-but-open files. It is tempting because mount options commonly address disk-pressure symptoms, but the correct step is finding the process still holding the unlinked file via lsof or /proc.
- ✓
Use 'lsof /var/log' to find processes holding deleted file handles, then restart those processes.
Why this is correct
Deleting log files unlinks directory entries, but processes still holding open file descriptors keep the inodes allocated, so space is not reclaimed. lsof /var/log identifies those processes; restarting them releases the handles and frees the blocks.
- ✗
Run 'df -i' to check inode usage.
Why it's wrong here
df -i reports inode exhaustion, which produces 'no space left' errors while df -h shows free blocks; here blocks were freed by deletion yet not reclaimed, indicating open file handles. Checking inodes is tempting because it explains some full-partition cases, but the stem's symptom points elsewhere.
Visual reference
Go deeper
Related to this question
About these practice questions
This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.