Courseiva
GNU and Unix Commands →hardMultiple Choice

LPIC-1 GNU and Unix Commands Practice Question

A web server runs Apache and generates extensive access logs. To conserve disk space, an administrator sets up a cron job that runs nightly at 2:00 AM. The job executes a shell script located at /usr/local/bin/rotate_logs.sh. The script is intended to find all .log files in /var/log/apache2/ that are older than 7 days, compress them with gzip, and move the compressed files to /var/log/archive/. However, after several days, the administrator notices that the /var/log partition is nearly full and the logs are not being compressed. The cron log shows the job ran at the scheduled time but produced no terminal output (stdout or stderr). The script itself contains no explicit echo statements or error handling. The administrator has root access and wants to diagnose the problem without disrupting the running web server. Which of the following is the most appropriate first step to identify the failure?

⚠ Common exam trap

The trap here is that candidates may jump to checking permissions or system logs because they assume a permission or system-level error, but the most efficient first step is to reproduce the script's execution with tracing enabled to see exactly what commands run and where they fail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run the script manually with 'bash -x /usr/local/bin/rotate_logs.sh' to observe command execution.

Running the script with 'bash -x' enables execution tracing, which prints each command and its arguments as they are executed. This will reveal exactly where the script fails—whether due to a missing file, permission error, or incorrect path—without modifying the script or disrupting the running web server. Since the cron job produced no output, the script likely encountered a silent failure, and 'bash -x' is the most direct way to diagnose it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run the script manually with 'bash -x /usr/local/bin/rotate_logs.sh' to observe command execution.

    Why this is correct

    Running with 'bash -x' traces each command and its expansion to stderr, exposing where the script fails, such as a wrong find predicate or missing gzip path. It diagnoses without touching the running web server, and the trace output reveals the silent failure.

  • ✗

    Use 'ps -ef | grep compress' to check if the cron job spawned any child processes.

    Why it's wrong here

    The cron job finished before the administrator investigated, so no compress child processes remain to inspect; ps shows only current processes. This check suits diagnosing a script still running or hung, not a completed nightly job whose failure must be traced through its own output.

  • ✗

    Check the file permissions of the archive directory with 'ls -ld /var/log/archive'.

    Why it's wrong here

    Permissions on the archive directory would cause mv to fail, but the script's find/gzip pipeline would still compress files in place, so logs would shrink rather than accumulate. Checking them is tempting because unwritable destinations commonly break rotation scripts, yet here the absence of any compression points to the find or gzip invocation itself.

  • ✗

    Review the system logs in /var/log/syslog for any entries related to gzip or the script.

    Why it's wrong here

    Cron captures the script's stdout and stderr and mails them to the job owner; gzip and shell errors are not written to syslog, so syslog holds no relevant entries. Syslog review suits daemon or kernel failures, whereas this script's silent failure needs its captured cron output examined.

About these practice questions

This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.