Courseiva

LPIC-1 Devices, Filesystems and FHS Practice Question

After running 'df -h', the administrator sees that /dev/sda1 is 100% used. 'du -sh /mountpoint' shows only 50% used. What is the most likely cause?

⚠ Common exam trap

Candidates often assume 'du' and 'df' should always match, overlooking the fact that 'du' cannot account for space used by unlinked files still held open by processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A large file was deleted but a process still holds it open

When a file is deleted but a process still holds an open file descriptor to it, the kernel does not release the disk space until the process closes the file. The 'df' command reports space usage based on the filesystem's superblock, which still counts the deleted file's blocks. 'du' calculates space by traversing the directory tree and summing file sizes, so it does not see the unlinked file. This discrepancy explains why 'df' shows 100% usage while 'du' shows only 50%.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The disk has bad blocks

    Why it's wrong here

    Bad blocks cause read/write failures and I/O errors, and are handled by remapping or fsck, not by inflating df's block count. This is the right diagnosis when SMART data or kernel logs report medium errors on the device.

  • ✓

    A large file was deleted but a process still holds it open

    Why this is correct

    Deleting a file removes its directory entry but the inode and data blocks persist while a process keeps the file descriptor open. df counts allocated blocks, so usage stays at 100% until that process closes or restarts.

  • ✗

    There is a hard link that du does not count

    Why it's wrong here

    Hard links share one inode, so du counts the data once while df counts the allocated blocks once too; hard links cannot create a 50% gap. This would be relevant when reconciling du totals across directories that reference the same inode.

  • ✗

    The filesystem is corrupted and needs fsck

    Why it's wrong here

    Filesystem corruption would typically produce I/O errors or an unmountable volume, not a consistent 50% gap between df and du. Running fsck is correct when metadata inconsistencies, orphaned inodes or journal errors are reported, not for this discrepancy.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.