Courseiva

Linux Professional Institute Certification Level 1 LPIC-1 (LPIC-1) — Questions 1–75

402 questions total · 6pages · All types, answers revealed

Page 1 of 6

Page 2
1
MCQmedium

A senior administrator runs a script that processes a CSV file. The script contains the following snippet: 'for field in $(cat data.csv); do ...'. The data.csv file contains lines like: 'John Doe, 123 Main St, Springfield'. The script fails to process correctly, splitting fields incorrectly and causing errors. Which of the following is the most appropriate fix?

A.Use xargs to process each line
B.Use 'for field in $(<data.csv)' with proper quoting
C.Use 'for field in "$(cat data.csv)"' with double quotes around the substitution
D.Use a while loop with read: 'while IFS= read -r line; do ... done < data.csv'
AnswerD

Unquoted command substitution splits on IFS whitespace, so 'John Doe, 123 Main St' fragments into separate words rather than one record. A while loop with IFS= and read -r preserves each line intact, correctly handling embedded spaces and commas in the CSV.

Why this answer

The script fails due to word splitting and globbing when iterating over the output of `cat data.csv` with a `for` loop. Using `while IFS= read -r line` reads each line verbatim, preserving spaces and commas, and is the standard pattern for processing CSV or delimited files line by line in bash.

Exam trap

The trap here is that candidates often think quoting the command substitution or using `xargs` will fix the splitting issue, but they fail to recognize that `for` inherently splits on IFS, whereas `while read` processes one line at a time without word splitting.

How to eliminate wrong answers

Option A is wrong because `xargs` by default splits input on whitespace and newlines, which would still break fields containing spaces like 'John Doe' and does not address the core issue of reading entire lines. Option B is wrong because `$(<data.csv)` is equivalent to `$(cat data.csv)` and still undergoes word splitting and globbing, so fields with spaces or special characters are incorrectly split. Option C is wrong because double quotes around the command substitution `"$(cat data.csv)"` would treat the entire file as a single string, causing the loop to iterate only once over the whole file content, not per line.

2
MCQmedium

A DHCP server assigns IP addresses to clients, but some clients are not receiving the correct gateway. Which configuration file should be checked on the DHCP server?

A./etc/dhcpd.conf
B./etc/dhcp/dhclient.conf
C./etc/dhcp/dhcpd.conf
D./etc/resolv.conf
AnswerC

dhcpd.conf holds the subnet declarations and their router option values that clients receive as their default gateway. An incorrect or missing router statement there causes clients to obtain addresses without the proper gateway, so this file must be checked.

Why this answer

The DHCP server configuration file on Linux systems is typically located at /etc/dhcp/dhcpd.conf (or /etc/dhcpd.conf on some older distributions). This file contains the subnet declarations, option definitions (such as option routers for the default gateway), and other parameters that the DHCP server uses to assign IP addresses and configuration details to clients. If clients are not receiving the correct gateway, the 'option routers' directive within this file should be checked and corrected.

Exam trap

The trap here is that candidates often confuse the DHCP server configuration file path with the older /etc/dhcpd.conf (option A) or mistakenly think the client configuration file (option B) controls server-side gateway assignment, when in fact the server's gateway is set via 'option routers' in /etc/dhcp/dhcpd.conf.

How to eliminate wrong answers

Option A is wrong because /etc/dhcpd.conf is an older, deprecated path; modern distributions use /etc/dhcp/dhcpd.conf, and the question expects the current standard location. Option B is wrong because /etc/dhcp/dhclient.conf is the client-side configuration file for the DHCP client (dhclient), not the server; it controls how the client requests and applies DHCP options, not how the server assigns them. Option D is wrong because /etc/resolv.conf is the DNS resolver configuration file, which specifies nameservers and search domains for the local system; it has no role in DHCP server gateway assignment.

3
MCQeasy

Which command shows the amount of free and used memory in the system, including swap?

A.top
B.free -h
C.df -h
D.vmstat
AnswerB

`free -h` reads `/proc/meminfo` and reports total, used and available RAM alongside swap usage, with the `-h` flag converting values into human-readable units. This directly satisfies the stem's requirement to display both free and used memory plus swap, unlike `df`, which reports filesystem space instead.

Why this answer

The `free -h` command displays the total, used, and free physical memory (RAM) and swap space in a human-readable format (e.g., GiB, MiB). The `-h` flag ensures output is scaled to appropriate units, making it the direct and correct tool for checking both memory and swap usage.

Exam trap

The trap here is that candidates may confuse `free` with `df` (disk free) or assume `top` provides a simpler memory summary, but only `free` directly and concisely shows both RAM and swap totals in a single, easy-to-read output.

How to eliminate wrong answers

Option A is wrong because `top` shows real-time process activity and memory usage but does not provide a concise summary of total free and used memory including swap; it focuses on per-process and dynamic system load. Option C is wrong because `df -h` reports disk filesystem usage (e.g., partitions and mount points), not memory or swap. Option D is wrong because `vmstat` reports virtual memory statistics, including swap activity, but its output is more granular and less immediately readable for a simple summary of free and used memory; it requires interpretation of columns like `swpd`, `free`, `buff`, and `cache`.

4
MCQeasy

A small office server running Ubuntu 20.04 experiences a gradual time drift. The system clock loses about 2 minutes per week. The hardware clock (RTC) is maintained by the motherboard battery and appears accurate when checked manually. The sysadmin wants to ensure the system clock stays synchronized automatically. Which single action should be taken? Options: A) Run 'timedatectl set-ntp true' to enable systemd-timesyncd, B) Add 'hwclock --hctosys' to /etc/rc.local, C) Install and configure the ntp package with a pool server, D) Use 'cron' to run ntpdate every minute.

A.Run 'timedatectl set-ntp true' to enable systemd-timesyncd
B.Add 'hwclock --hctosys' to /etc/rc.local
C.Install and configure the ntp package with a pool server
D.Use 'cron' to run ntpdate every minute
AnswerA

On Ubuntu 20.04, systemd-timesyncd is the default NTP client. Running 'timedatectl set-ntp true' activates it, which automatically synchronizes the system clock with NTP servers, correcting the gradual drift without needing additional packages or manual cron jobs. This is the simplest and most appropriate single action for automatic time sync on a modern systemd-based distribution.

Why this answer

On Ubuntu 20.04, systemd-timesyncd is the default NTP client. Running 'timedatectl set-ntp true' (option A) activates it, which automatically synchronizes the system clock with NTP servers, correcting the gradual drift without needing additional packages or manual cron jobs. This is the simplest and most appropriate single action for automatic time sync on a modern systemd-based distribution.

Exam trap

The trap here is that candidates may assume the full ntp package is always required for time synchronization, overlooking that systemd-timesyncd is the default and sufficient for basic NTP sync on modern Ubuntu systems.

How to eliminate wrong answers

Option A is wrong because installing and configuring the full ntp package is overkill for a small office server; systemd-timesyncd is already present and sufficient for basic NTP synchronization. Option B is wrong because adding 'hwclock --hctosys' to /etc/rc.local only sets the system clock from the hardware clock at boot, which does not correct ongoing time drift during operation. Option C is wrong because using cron to run ntpdate every minute is inefficient, can cause abrupt time jumps, and ntpdate is deprecated in favor of more gradual synchronization methods like systemd-timesyncd or ntpd.

5
MCQhard

Refer to the exhibit. The process with PID 1234 is in state 'Z'. What is the most likely cause and appropriate action?

A.The process is stopped; use kill -CONT to continue.
B.The process is a daemon; it should be restarted.
C.The process is sleeping; wait for it to become ready.
D.The process is a zombie; the parent process must be killed or wait for it to be reaped.
AnswerD

A 'Z' state means the process has terminated but its exit status remains in the process table because the parent has not called wait(). Killing the parent, or letting it reap the child, removes the zombie entry.

Why this answer

In Linux process states, 'Z' indicates a zombie process, which is a child process that has terminated but whose exit status has not yet been read by its parent process via the wait() system call. The correct action is to either kill the parent process (so that the zombie is reaped by init) or ensure the parent calls wait() to reap the child. Option D correctly identifies this.

Exam trap

The trap here is that candidates confuse zombie ('Z') with stopped ('T') or sleeping ('S') states, leading them to choose a recovery action like sending SIGCONT or simply waiting, rather than recognizing that a zombie requires the parent to reap it or be terminated.

How to eliminate wrong answers

Option A is wrong because a stopped process is indicated by state 'T' (or 't'), not 'Z', and kill -CONT is used to resume a stopped process, not handle a zombie. Option B is wrong because a daemon process typically runs in the background with state 'S' (sleeping) or 'R' (running), and restarting a daemon does not address a zombie; zombies are already dead and waiting to be reaped. Option C is wrong because a sleeping process is indicated by state 'S' or 'D' (uninterruptible sleep), not 'Z', and waiting will not resolve a zombie—the zombie persists until the parent reaps it.

6
MCQmedium

A Linux workstation appears to hang early in the boot process after the initramfs is loaded. The administrator wants to add kernel boot parameters temporarily from the GRUB 2 menu without making a permanent change. Which action should the administrator take?

A.At the GRUB menu, press e to edit the selected entry, append the parameters to the linux line, and press Ctrl+X or F10 to boot.
B.At the GRUB menu, press c to open the command line and run the normal command.
C.Boot normally, then use sysctl -w to apply the parameters and reboot.
D.Edit /etc/default/grub, add the parameters to GRUB_CMDLINE_LINUX, and reboot.
AnswerA

Pressing e at the GRUB 2 menu opens an editable view of the chosen entry, where the kernel command line on the linux line can be modified in memory. Booting with Ctrl+X or F10 uses those edits for that single boot only and does not persist them to disk, exactly matching the request for a temporary kernel parameter change to diagnose the hang.

Why this answer

GRUB 2 allows one-time modification of a boot entry from the menu. Pressing e opens the entry for editing, where the kernel command line can be appended, then Ctrl+X or F10 boots with those in-memory changes. Nothing is written to configuration files, so the modification applies only to that boot, which is ideal for testing parameters during troubleshooting.

Exam trap

The trap here is confusing the persistent configuration files and the GRUB command shell with the menu edit feature, when only editing the selected entry applies a temporary kernel parameter for a single boot.

7
MCQmedium

A system administrator wants to configure log rotation to compress log files daily and keep 30 days of logs. Which of the following configurations achieves this goal?

A.Set the 'maxlogsize' parameter in /etc/rsyslog.conf
B.Add a configuration file in /etc/logrotate.d/ with the contents: '/var/log/mylog { daily rotate 30 compress }'
C.Create a cron job that runs 'gzip /var/log/mylog.*' daily
D.Edit /etc/logrotate.conf to set 'rotate 30 weekly'
AnswerB

The logrotate directive combines daily rotation, rotate 30 retention and compress into one stanza, satisfying both the daily compression and 30-day retention constraints. Placing it in /etc/logrotate.d/ ensures logrotate picks it up automatically via its include directive, so no cron entry is needed.

Why this answer

Logrotate is the standard Linux utility for log rotation, compression, and retention. The configuration directive 'daily rotate 30 compress' in a file under /etc/logrotate.d/ instructs logrotate to rotate logs daily, keep 30 rotated copies, and compress old logs with gzip. This directly meets the requirement of daily compression and 30-day retention.

Exam trap

The trap here is that candidates may confuse logrotate's 'rotate' count with a time-based retention period, or assume that rsyslog or a simple cron+gzip approach can handle rotation and retention, when in fact logrotate is the dedicated tool that manages both rotation and compression with precise control over file naming and retention limits.

How to eliminate wrong answers

Option A is wrong because /etc/rsyslog.conf is the configuration file for rsyslog, the system logging daemon, and it does not have a 'maxlogsize' parameter for log rotation; log rotation is handled by logrotate, not rsyslog. Option C is wrong because a cron job running 'gzip /var/log/mylog.*' would compress all matching files daily but would not perform rotation (renaming the active log) or enforce a retention limit of 30 days, leading to uncontrolled accumulation of compressed files. Option D is wrong because editing /etc/logrotate.conf to set 'rotate 30 weekly' would keep 30 weeks of logs, not 30 days, and the 'weekly' directive contradicts the requirement for daily rotation.

8
MCQeasy

Which hardware component uses a unique address to identify itself on the network at the data link layer?

A.IP address
B.MAC address
C.Hostname
D.Port number
AnswerB

The MAC address is a 48-bit identifier burned into the network interface card, used at the data link layer to distinguish frames between hosts on the same segment. It uniquely satisfies the stem's requirement for a hardware component addressing at layer 2.

Why this answer

The MAC address (Media Access Control) is a unique 48-bit identifier burned into the network interface controller (NIC) by the manufacturer. It operates at Layer 2 (data link layer) of the OSI model, enabling devices on the same local network segment to communicate directly using protocols like Ethernet or Wi-Fi.

Exam trap

The trap here is that candidates often confuse the MAC address with the IP address because both are used for network identification, but the question specifically asks for the data link layer, where only the MAC address (not the IP address) operates.

How to eliminate wrong answers

Option A is wrong because an IP address operates at Layer 3 (network layer) and is used for logical addressing and routing across networks, not for hardware identification at the data link layer. Option C is wrong because a hostname is a human-readable alias resolved to an IP address via DNS or local hosts files, and it has no role in data link layer addressing. Option D is wrong because a port number is a Layer 4 (transport layer) identifier used by TCP or UDP to distinguish application services on a host, not for hardware-level network identification.

9
MCQmedium

An administrator wants systemd-journald logs to persist across reboots. What must be created?

A.The directory /run/log/journal
B.The file /etc/journald.conf
C.The directory /var/log/journal
D.The directory /var/spool/journal
AnswerC

Journald writes to /run/log/journal (tmpfs) by default, so logs vanish on reboot. Creating /var/log/journal on disk switches storage to persistent mode, satisfying the requirement that entries survive restarts. The directory must exist before journald starts using it.

Why this answer

By default, systemd-journald stores logs in a volatile tmpfs at /run/log/journal, which is cleared on reboot. To make logs persistent, the directory /var/log/journal must be created. When systemd-journald detects this directory exists, it automatically switches to persistent storage, writing logs to /var/log/journal and preserving them across reboots.

Exam trap

The trap here is that candidates often assume editing the configuration file /etc/journald.conf is sufficient, but without the actual directory /var/log/journal existing, systemd-journald will not switch to persistent storage unless Storage=persistent is explicitly set and the directory is created.

How to eliminate wrong answers

Option A is wrong because /run/log/journal is the default volatile location for systemd-journald logs; it is automatically created on tmpfs and does not persist across reboots. Option B is wrong because /etc/journald.conf is the configuration file for systemd-journald, but creating it alone does not enable persistence; the key setting is Storage=persistent in that file, but the directory /var/log/journal must also exist (or be created) for persistence to take effect. Option D is wrong because /var/spool/journal is not a standard path used by systemd-journald; the correct persistent directory is /var/log/journal as defined by the journald documentation and the systemd source code.

10
MCQmedium

A systems administrator needs to change the permissions of the file /home/user/script.sh so that the owner can read, write, and execute; the group can read and execute; and others have no access. Which command accomplishes this?

A.chmod 755 /home/user/script.sh
B.chmod 750 /home/user/script.sh
C.chmod 770 /home/user/script.sh
D.chmod 741 /home/user/script.sh
AnswerB

750 gives rwx for owner, r-x for group, and --- for others, matching the requirement.

Why this answer

Chmod 750 sets the permissions to rwxr-x---, which gives the owner read, write, and execute (7), the group read and execute (5), and others no access (0). This matches the requirement exactly.

Exam trap

The trap here is that candidates often confuse the octal values, especially mistaking 755 (which grants others read/execute) for the correct setting, or they forget that 750 denies others access while 755 does not.

How to eliminate wrong answers

Option A is wrong because chmod 755 sets permissions to rwxr-xr-x, which gives others read and execute access, violating the requirement that others have no access. Option C is wrong because chmod 770 sets permissions to rwxrwx---, which gives the group write access in addition to read and execute, exceeding the required group permissions. Option D is wrong because chmod 741 sets permissions to rwxr----x, which gives others only execute access (1) instead of no access, and the group has only read access (4) instead of read and execute.

11
MCQmedium

On a systemd-based system, which file is NOT used for system initialization?

A./etc/fstab
B./etc/systemd/system/default.target
C./etc/inittab
D./lib/systemd/system/sysinit.target
AnswerC

/etc/inittab belongs to the SysV init and Upstart era, where it defined runlevels and spawned getty processes. On a systemd-based system, initialisation is handled by units and targets, so inittab is ignored entirely. This satisfies the stem's constraint of identifying the file not used for system initialisation.

Why this answer

/etc/inittab is the configuration file used by the traditional SysV init system to define runlevels and control terminal getty processes. On a systemd-based system, systemd does not read /etc/inittab; instead, it uses unit files and targets to manage system initialization, making this file unused for that purpose.

Exam trap

The trap here is that candidates familiar with SysV init assume /etc/inittab is still relevant on modern Linux systems, but LPIC-1 tests the distinction between legacy and systemd initialization files.

How to eliminate wrong answers

Option A is wrong because /etc/fstab is still used by systemd (via systemd-fstab-generator) to mount filesystems during boot, so it is involved in system initialization. Option B is wrong because /etc/systemd/system/default.target is a symlink that defines the default boot target (e.g., multi-user.target or graphical.target) and is actively used by systemd to determine the initial system state. Option D is wrong because /lib/systemd/system/sysinit.target is a special target unit that systemd uses to synchronize early boot services and is a core part of the initialization process.

12
MCQmedium

A Linux administrator needs to extract all lines from `/var/log/syslog` that contain the word `error` (case-insensitive) and save them to `errors.txt`. Which command accomplishes this?

A.grep -c error /var/log/syslog > errors.txt
B.grep -i error /var/log/syslog > errors.txt
C.grep -v error /var/log/syslog > errors.txt
D.grep -l error /var/log/syslog > errors.txt
AnswerB

The -i option makes grep ignore case, so it matches error, Error, ERROR, and so on. The redirection operator > sends the matching lines to errors.txt. This is the standard and correct way to perform a case-insensitive search and save the results to a file.

Why this answer

The grep command with -i performs a case-insensitive search, and the > redirection writes the matching lines to a file. The other options either invert the match, count matches, or list filenames, none of which produce the desired output of the matching lines themselves.

Exam trap

The trap here is confusing grep options that alter output format with options that filter content, such as using -c or -l when the actual lines are needed.

13
MCQmedium

An Ubuntu 20.04 server needs a static IP address. The administrator has created a netplan YAML file at /etc/netplan/01-netcfg.yaml. What is the next step to apply the configuration?

A.netplan apply
B.ifconfig eth0 down; ifconfig eth0 up
C.service network-manager restart
D.systemctl restart networking
AnswerA

Netplan reads YAML definitions under /etc/netplan and generates the backend configuration for systemd-networkd or NetworkManager. Running netplan apply commits the new static addressing immediately without a reboot, satisfying the requirement to activate the file the administrator created.

Why this answer

On Ubuntu 20.04, netplan is the default network configuration tool, and the correct command to apply changes from a YAML file in /etc/netplan/ is 'netplan apply'. This command parses the YAML, generates the appropriate backend configuration (systemd-networkd or NetworkManager), and applies it without requiring a reboot. It is the standard, supported method for activating static IP settings on modern Ubuntu systems.

Exam trap

The trap here is that candidates may confuse the legacy 'systemctl restart networking' or 'ifconfig' commands with the modern netplan workflow, assuming any service restart will apply the YAML configuration, but only 'netplan apply' correctly processes the netplan files and triggers the appropriate backend.

How to eliminate wrong answers

Option B is wrong because 'ifconfig eth0 down; ifconfig eth0 up' is a legacy method that does not read netplan YAML files; it only toggles the interface state and may not persist or apply the new static IP configuration. Option C is wrong because 'service network-manager restart' restarts the NetworkManager service, but on Ubuntu 20.04 with netplan, the default backend is systemd-networkd (unless explicitly configured otherwise), and this command may not correctly apply netplan settings or could interfere with the intended backend. Option D is wrong because 'systemctl restart networking' targets the old 'networking' service (used by ifupdown), which is not the active network stack on Ubuntu 20.04; netplan uses systemd-networkd or NetworkManager, so this command is irrelevant and will not apply the netplan configuration.

14
Multi-Selecteasy

Which THREE of the following are correct features of the 'grep' command? (Choose three.)

Select 3 answers
A.-i makes the search case-insensitive
B.-v inverts the match
C.-c counts matching lines
D.-l prints line numbers of matches
E.-r enables regular expression matching
AnswersA, B, C

The `-i` flag instructs `grep` to ignore case distinctions in both the pattern and the input, so "Error", "error" and "ERROR" all match. This directly satisfies the stem's requirement for a genuine `grep` feature, as case-insensitive matching is a documented, standard option across GNU and BSD implementations.

Why this answer

Option A is correct because grep -i performs a case-insensitive search, so patterns like 'error' will also match 'Error' or 'ERROR'. Option B is correct because grep -v inverts the match, printing only the lines that do NOT contain the specified pattern. Option C is correct because grep -c suppresses normal output and instead prints a count of the matching lines.

Option D is not correct because -l lists only the names of files containing matches, while line numbers are shown with -n. Option E is not correct because -r enables recursive searching through directories; regular expression matching is grep's default behavior, not enabled by -r.

Exam trap

The trap here is that candidates confuse `-l` (list filenames) with `-n` (show line numbers) and assume `-r` enables regex, when in fact `-r` is for recursive directory traversal and regex is the default behavior.

15
MCQhard

Refer to the exhibit. After modifying /etc/default/grub to enable serial console output, which command must be run to apply the changes to the GRUB configuration?

A.grub-editenv
B.grub-install
C.grub-set-default
D.update-grub
AnswerD

Running `update-grub` regenerates `/boot/grub/grub.cfg` from `/etc/default/grub` and the scripts in `/etc/grub.d/`, so the serial console parameters take effect on the next boot. On Debian-based systems this wrapper invokes `grub-mkconfig -o /boot/grub/grub.cfg`, satisfying the stem's requirement to apply the edits.

Why this answer

The correct command is `update-grub` (or its equivalent `grub-mkconfig -o /boot/grub/grub.cfg`). After modifying `/etc/default/grub`, you must regenerate the GRUB configuration file (`grub.cfg`) to incorporate the new serial console settings. `update-grub` is a wrapper that runs `grub-mkconfig` and writes the output to the correct location, applying the changes.

Exam trap

The trap here is that candidates confuse commands that modify GRUB's runtime behavior (like `grub-set-default` or `grub-editenv`) with the command that regenerates the static configuration file from the template, leading them to pick a wrong option that does not actually apply changes from `/etc/default/grub`.

How to eliminate wrong answers

Option A is wrong because `grub-editenv` is used to edit the GRUB environment block (e.g., saved default entry or boot counter), not to regenerate the main configuration file from `/etc/default/grub`. Option B is wrong because `grub-install` installs GRUB to a disk or partition (e.g., MBR or EFI system partition) and does not read or apply changes from `/etc/default/grub`. Option C is wrong because `grub-set-default` sets the default boot entry in the GRUB environment block, but it does not regenerate `grub.cfg` from the configuration template.

16
Multi-Selectmedium

A Linux server uses a systemd-based init and has several custom services. The administrator wants to inspect the runtime state and configuration of a unit named backup.service without starting or stopping it. Which TWO commands provide information about this unit? (Choose two.)

Select 2 answers
A.systemctl enable backup.service
B.systemctl restart backup.service
C.systemctl status backup.service
D.systemctl start backup.service
E.systemctl cat backup.service
AnswersC, E

systemctl status backup.service shows the unit's current active state, recent log lines, and key properties such as loaded and enabled status. It is a read-only inspection command that does not start or stop the service, so it directly satisfies the requirement to examine the unit's runtime state and configuration.

Why this answer

Inspecting a systemd unit without altering it calls for read-only commands. systemctl status shows the unit's active state, recent journal entries, and loaded properties, while systemctl cat prints the unit file and any drop-ins that define its effective configuration. Commands such as start, restart, and enable change state or configuration and therefore do not meet the requirement.

Exam trap

The trap here is treating systemctl enable as an inspection command, when it only creates boot-time symlinks and shows nothing about the unit's current runtime state.

17
MCQhard

An administrator is examining a file with 'ls -l' and sees the permission string '-rwSr--r--' on an executable owned by root. What does the capital S in the owner execute position indicate?

A.The file has an extended ACL entry that grants the owner additional rights.
B.The set-user-ID bit is set, but the owner execute bit is not set.
C.The sticky bit is set, and it prevents other users from deleting the file.
D.The set-group-ID bit is set, but the group execute bit is not set.
AnswerB

In the permission string, the owner execute position carries the set-user-ID flag. A lowercase s means both the setuid bit and execute are present, while a capital S means setuid is set but the underlying execute bit is absent. Here the capital S confirms exactly that combination on a root-owned executable.

Why this answer

The execute slot for each permission class also encodes a special bit. For the owner it is set-user-ID, shown as s when execute is also granted and as S when execute is withheld. Seeing '-rwSr--r--' therefore means setuid is set but the owner cannot execute the file, which is an unusual and often ineffective configuration.

Exam trap

The trap here is reading the capital S as an ordinary permission or as an ACL marker instead of recognizing it as a special bit paired with a missing execute bit.

18
MCQhard

After a system upgrade, the server fails to boot with the error: 'ERROR: Failed to mount the real root device.' The root filesystem is on an LVM logical volume. Which recovery step is most appropriate?

A.Boot from a live CD, chroot, and run 'update-initramfs -u -k all' to regenerate the initramfs with lvm2 support
B.Run 'lvchange -ay' to activate all LVs
C.Reinstall GRUB to the MBR
D.Use 'fsck' on the root LV
AnswerA

The upgrade rebuilt the initramfs without the lvm2 hook, so the kernel cannot activate the volume group before mounting root. Booting a live CD and running update-initramfs -u -k all regenerates it with lvm2 support, restoring the ability to assemble the logical volume at boot.

Why this answer

The error 'Failed to mount the real root device' after a system upgrade indicates the initramfs lacks the necessary LVM modules (e.g., lvm2) to activate and mount the root logical volume. Regenerating the initramfs with 'update-initramfs -u -k all' rebuilds it to include LVM support, ensuring the kernel can locate and mount the root filesystem during boot.

Exam trap

The trap here is that candidates confuse a missing initramfs module issue with a logical volume activation problem (Option B), but 'lvchange -ay' is only effective after the initramfs has loaded LVM support; without it, the kernel cannot even see the LVs to activate them.

How to eliminate wrong answers

Option B is wrong because 'lvchange -ay' activates all logical volumes, but this command must be run from a rescue environment (e.g., live CD) and does not address the missing LVM support in the initramfs; the kernel still cannot mount the root LV without proper modules. Option C is wrong because reinstalling GRUB to the MBR only fixes bootloader issues (e.g., missing or corrupted stage files), not the kernel's inability to mount the root filesystem due to missing LVM drivers. Option D is wrong because 'fsck' checks and repairs filesystem integrity, but the error occurs before the filesystem is even mounted; the root cause is the initramfs lacking LVM support, not filesystem corruption.

19
MCQeasy

A technician needs to add the official Debian repository for the 'buster' release. Which line should be added to /etc/apt/sources.list?

A.`deb http://deb.debian.org/debian buster-updates main`
B.`deb-src http://deb.debian.org/debian buster main`
C.`rpm http://deb.debian.org/debian buster main`
D.`deb http://deb.debian.org/debian buster main`
AnswerD

Naming the suite as 'buster' pins APT to that Debian release's package index, while the 'main' component restricts retrieval to officially supported free software. The deb URL form and single-line syntax match /etc/apt/sources.list requirements, satisfying the need to add the official buster repository.

Why this answer

It uses the standard 'deb' prefix for binary packages, points to the official Debian repository at http://deb.debian.org/debian, specifies the release codename 'buster', and includes the required component 'main'. This is the exact format required by APT to fetch packages for the Debian buster release.

Exam trap

The trap here is that candidates may confuse the 'deb' and 'deb-src' prefixes, or mistakenly add '-updates' thinking it is required for the base release, when the question specifically asks for the repository line for the 'buster' release itself, not its updates.

How to eliminate wrong answers

Option A is wrong because it appends '-updates' to the release name, which would configure the buster-updates repository (for package updates after the initial release) rather than the main buster repository. Option B is wrong because it uses 'deb-src' prefix, which is for source packages, not binary packages; the question asks for the repository line to add, and while deb-src is valid for source code, the standard binary repository uses 'deb'. Option C is wrong because it uses 'rpm' prefix, which is the package format for Red Hat-based distributions (like Fedora, CentOS), not for Debian-based systems; APT expects 'deb' or 'deb-src' lines.

20
MCQmedium

A system administrator wants to change the default runlevel of a SysV init-based system to runlevel 3. Which file should be edited to make this change persistent across reboots?

A./etc/init/rc-sysinit.conf
B./etc/rc.d/rc.local
C./etc/inittab
D./etc/systemd/system/default.target
AnswerC

On SysV init systems, the default runlevel is specified in /etc/inittab by the 'initdefault' entry, such as 'id:3:initdefault:'. Editing this file to set the runlevel to 3 changes the default runlevel persistently. This is the correct file for SysV init-based systems.

Why this answer

For SysV init systems, the default runlevel is set in /etc/inittab via the initdefault line. Editing that file to specify runlevel 3 ensures the system boots to runlevel 3 on subsequent reboots. The other files are associated with different init systems or purposes and would not achieve the desired change.

Exam trap

The trap here is mixing up init systems: /etc/inittab is for SysV init, while systemd uses default.target and Upstart uses /etc/init/.

21
Multi-Selectmedium

Which TWO commands can be used to display the current runlevel of a system?

Select 2 answers
A.telinit q
B.systemctl get-default
C.init 3
D.runlevel
E.who -r
AnswersD, E

The `runlevel` command reads `/var/run/utmp` and prints the previous and current runlevel, satisfying the requirement to display the system's current runlevel. It reports both values directly, for example "N 5", making it a valid answer alongside `who -r`.

Why this answer

The `runlevel` command (option D) reads `/var/run/utmp` and prints the previous and current runlevel (e.g., "N 5"), directly reporting the system's current runlevel. The `who -r` command (option E) uses the `-r` flag to display the current runlevel along with the time it was last changed, also deriving this from the utmp record. Option A, `telinit q`, only tells init to re-read its configuration and does not display the runlevel.

Option B, `systemctl get-default`, shows the default target (e.g., graphical.target) that the system boots into, not the currently active runlevel. Option C, `init 3`, is used to change the runlevel to 3, not to display the current one.

Exam trap

The trap here is that candidates may confuse commands that change the runlevel (like `init 3`) with commands that display it, or assume `systemctl get-default` shows the current runlevel when it actually shows the default target for the next boot.

22
MCQeasy

A system administrator is troubleshooting a Linux server that fails to boot. The server has a software RAID 1 configuration using mdadm, with the root filesystem located on /dev/md0. During boot, the system halts with the following error: 'VFS: Unable to mount root fs on unknown-block(0,0)'. The admin verifies that the BIOS recognizes all disks and that the RAID array was properly assembled prior to the last shutdown. The system was working after a recent kernel update, but now fails. Which of the following actions is the most likely solution?

A.Use a live CD to run fsck on /dev/md0.
B.Rebuild the initramfs to include the mdadm module and the RAID metadata.
C.Check the /etc/fstab file for incorrect root device.
D.Reinstall the bootloader on the MBR.
AnswerB

A kernel update can produce an initramfs lacking the mdadm module, so the kernel cannot assemble /dev/md0 and reports unknown-block(0,0). Rebuilding initramfs with mdadm and RAID metadata satisfies the requirement to mount the root filesystem at boot.

Why this answer

After a kernel update, the new kernel may lack the necessary mdadm module or RAID metadata support in the initramfs. The error 'unknown-block(0,0)' indicates the kernel cannot find the root device because the initramfs does not contain the required RAID drivers or assembly instructions. Rebuilding the initramfs with the correct mdadm configuration ensures the kernel can assemble and mount /dev/md0 during boot.

Exam trap

The trap here is that candidates often confuse a root filesystem mount failure with filesystem corruption (fsck) or bootloader issues, but the specific 'unknown-block(0,0)' error points to a missing kernel module or initramfs problem after a kernel update.

How to eliminate wrong answers

Option A is wrong because fsck repairs filesystem corruption, but the error 'unknown-block(0,0)' indicates the kernel cannot locate the block device at all, not that the filesystem is damaged. Option C is wrong because /etc/fstab is read after the root filesystem is mounted; if the root device cannot be found, the system never reaches the point of parsing fstab. Option D is wrong because reinstalling the bootloader on the MBR addresses bootloader issues (e.g., GRUB stage 1), but the error occurs after the kernel is loaded and fails to mount root, indicating a missing driver or module in the initramfs.

23
MCQhard

A company manages a cluster of 50 web servers running Ubuntu 20.04. The servers are configured to synchronize time with an internal NTP server at 10.0.0.100 using the default ntpd. The NTP server itself syncs with external stratum 2 servers. Recently, the security team implemented a restrictive iptables firewall on all servers, allowing only essential services. Several servers in the 10.0.1.0/24 network now report time drift and ntpq -p shows all peers with '?' status. A network engineer runs tcpdump on one affected server and sees no NTP replies from 10.0.0.100. The NTP server's firewall is configured to allow inbound NTP from 10.0.0.0/24 only. The engineer also notes that the server's /etc/ntp.conf contains the line 'restrict 10.0.0.100' (which is incorrect) and that ntpq -crv shows 'sync target not reachable'. Which single action will most directly resolve the synchronization issue for the affected servers?

A.Add an iptables rule on the affected server to accept outbound UDP packets to 10.0.0.100 port 123.
B.Remove the line 'restrict 10.0.0.100' from /etc/ntp.conf.
C.Modify the NTP server's firewall to allow inbound NTP from 10.0.1.0/24.
D.Add a static route on the affected server for 10.0.0.100 via a different gateway.
AnswerC

The NTP server's firewall only permits inbound NTP from 10.0.0.0/24, so replies to the affected 10.0.1.0/24 servers are dropped, explaining the '?' peer status and absent tcpdump replies. Widening the rule to include 10.0.1.0/24 restores the return path, satisfying the reachability constraint that the client-side restrict line cannot fix.

Why this answer

The affected servers are in the 10.0.1.0/24 network, but the NTP server's firewall only allows inbound NTP from 10.0.0.0/24. Even if the client's firewall permits outbound UDP to port 123, the server will drop the requests because they originate from an unauthorized subnet. Therefore, modifying the NTP server's firewall to accept NTP traffic from 10.0.1.0/24 directly resolves the synchronization issue.

Option A (client firewall fix) is necessary but not sufficient because the server will still block the requests. Option B fixes the incorrect restrict line but does not address the firewall. Option D is irrelevant as routing is not the problem.

Exam trap

Candidates often focus on the client's firewall or the incorrect restrict line, but the most direct cause is the NTP server's firewall misconfiguration. Even if the client allows outbound traffic, the server drops requests from the wrong subnet.

How to eliminate wrong answers

Option A is wrong because the problem is not the client's outbound firewall; the client can send NTP requests, but the NTP server's firewall blocks replies to 10.0.1.0/24, so adding an outbound rule on the client does nothing. Option B is wrong because the 'restrict 10.0.0.100' line in /etc/ntp.conf is syntactically incorrect (it should be 'restrict 10.0.0.100 mask 255.255.255.255' or similar) but even if corrected, it controls access to the local NTP service, not the ability to receive replies from the server; the core issue is the server-side firewall. Option D is wrong because the affected server can already reach 10.0.0.100 (it sends requests), and adding a static route does not address the firewall blocking replies; the routing is fine.

24
MCQmedium

A system administrator needs to find out which package installed the file /usr/bin/foo on a Red Hat system. Which command should be used?

A.`rpm -qa /usr/bin/foo`
B.`rpm -qi /usr/bin/foo`
C.`rpm -ql /usr/bin/foo`
D.`rpm -qf /usr/bin/foo`
AnswerD

On Red Hat systems the RPM database records which package owns each installed file. The query flag -f accepts a file path and returns its owning package, directly answering which package installed /usr/bin/foo without scanning the filesystem manually.

Why this answer

The `rpm -qf /usr/bin/foo` command queries the RPM database to determine which installed package owns the specified file. The `-f` (or `--file`) option tells RPM to search for the package that provided that file path, making it the correct choice for this task on a Red Hat system.

Exam trap

The trap here is confusing the direction of the query: candidates often pick `rpm -ql` (list files in a package) instead of `rpm -qf` (find package owning a file), because they misremember which option performs the reverse lookup.

How to eliminate wrong answers

Option A is wrong because `rpm -qa` lists all installed packages, and appending a file path like `/usr/bin/foo` is invalid syntax; it does not query which package owns the file. Option B is wrong because `rpm -qi` displays detailed information about a specified package (e.g., `rpm -qi bash`), not about a file; passing a file path to `-qi` will result in an error or unintended behavior. Option C is wrong because `rpm -ql` lists all files installed by a specified package, not the reverse lookup of which package owns a given file.

25
MCQhard

Refer to the exhibit. A user tries to execute a script on a mounted filesystem but gets a permission denied error. The script has execute permissions. What is the most likely cause?

A.The script is not executable for the user.
B.The user does not have read permission on the script.
C.The filesystem is mounted with the 'noexec' option.
D.The filesystem is full.
AnswerC

The `noexec` mount option instructs the kernel to refuse execution of any binary or script residing on that filesystem, regardless of the file's own execute permission bits. Since the script already has execute permissions, the mount-level restriction is the only remaining cause of the permission denied error.

Why this answer

The 'noexec' mount option prevents execution of any binary or script on the filesystem, regardless of file permissions. Even if the script has execute permissions set, the kernel will refuse to execute it when the filesystem is mounted with 'noexec'. This is a common security measure on filesystems like /tmp or /home to prevent unauthorized code execution.

Exam trap

The trap here is that candidates often assume 'permission denied' always means incorrect file permissions, but the LPIC-1 exam tests the understanding that mount options like 'noexec' can override file-level permissions and cause execution failures.

How to eliminate wrong answers

Option A is wrong because the question explicitly states that the script has execute permissions, so the script is executable for the user. Option B is wrong because read permission is not required to execute a script; execute permission alone is sufficient for execution (though the interpreter needs read access to the script file). Option D is wrong because a full filesystem would cause write failures, not a 'permission denied' error when trying to execute a script.

26
Multi-Selectmedium

On a modern Linux system using systemd-networkd for interface management and systemd-resolved for DNS, which THREE files are typically involved in network configuration and DNS resolution?

Select 3 answers
A./etc/systemd/network/10-static.network
B./etc/network/interfaces
C./etc/resolv.conf
D./etc/hosts
E./etc/sysconfig/network-scripts/ifcfg-eth0
AnswersA, C, D

systemd-networkd uses .network files in this directory.

Why this answer

On a modern Linux system using systemd-networkd, network interface configuration is defined in .network files within /etc/systemd/network/, such as 10-static.network (Option A). systemd-resolved manages DNS resolution and typically writes to /etc/resolv.conf (Option C) as a symlink to its own stub resolver. /etc/hosts (Option D) is a static host-to-IP mapping file that is consulted by the system's resolver before DNS queries, making it a standard part of DNS resolution. Together, these three files are directly involved in network configuration and DNS resolution under systemd.

Exam trap

The trap here is that candidates often assume /etc/network/interfaces or ifcfg-eth0 are still relevant on modern systemd-based distributions, but systemd-networkd uses its own .network files, and the question explicitly specifies systemd-networkd and systemd-resolved.

27
MCQmedium

A technician must determine whether a Linux server's CPU supports hardware-assisted virtualization so the host can run KVM guests. The technician needs to inspect the processor flags exposed by the running kernel. Which command should be used?

A.lsmod
B.uname -a
C.lscpu
D.cat /proc/cpuinfo
AnswerD

The /proc/cpuinfo virtual file is generated by the kernel and reports per-processor details, including the flags line that enumerates capabilities such as vmx on Intel or svm on AMD. Searching that output for the virtualization flag gives definitive evidence that the CPU and kernel expose hardware-assisted virtualization, which is exactly the check the technician needs before enabling KVM guests.

Why this answer

CPU capability flags are exposed by the kernel through the virtual /proc filesystem. Reading /proc/cpuinfo shows the flags line for each logical processor, and the presence of the vendor-specific virtualization flag confirms the hardware supports KVM acceleration. Tools that report loaded modules or kernel build strings describe software state rather than the underlying processor features being investigated.

Exam trap

The trap here is assuming that a loaded kvm module or a friendly CPU summary tool proves the processor has virtualization extensions, when only the kernel-exposed CPU flags definitively confirm it.

28
MCQmedium

Refer to the exhibit. A user gets this error when running a script. What is the most likely cause?

A.The script is missing a shebang line.
B.The script has Windows-style line endings (CRLF).
C.The script does not have execute permission.
D.The script contains a syntax error in line 3.
AnswerB

Windows-style CRLF endings leave a trailing carriage return on the shebang line, so the kernel seeks an interpreter named `/bin/bash\r`, which does not exist, producing the bad interpreter error. Converting the file with `dos2unix` or `sed` restores Unix LF endings and the script runs.

Why this answer

The error message shown in the exhibit (typically '/bin/bash^M: bad interpreter' or similar) indicates that the script contains carriage return characters (CR, \r) at the end of lines, which is characteristic of Windows-style CRLF line endings. When Linux's Bash tries to interpret the shebang line, it sees '/bin/bash^M' as the interpreter path, which does not exist, causing the script to fail. This is a common issue when scripts are created or edited on Windows and then transferred to a Unix-like system without converting line endings.

Exam trap

The LPI exam often tests the distinction between permission errors (chmod) and interpreter errors (shebang/line endings), trapping candidates who assume any script execution failure is due to missing execute permissions.

How to eliminate wrong answers

Option A is wrong because a missing shebang line would cause the script to be executed by the default shell (usually /bin/sh) or produce a different error (e.g., 'command not found'), not the specific 'bad interpreter' error shown. Option C is wrong because missing execute permission would produce a 'Permission denied' error, not an interpreter-related error. Option D is wrong because a syntax error in line 3 would only be detected after the script starts executing, and the error message would reference a syntax issue (e.g., 'syntax error near unexpected token'), not a missing interpreter.

29
MCQmedium

A server's root filesystem is filling up. The administrator suspects that a service is writing large log files to /var/log/journal. Which command displays the total disk space currently used by the systemd journal?

A.journalctl -u systemd-journald --size
B.du -sh /var/log/journal
C.journalctl --disk-usage
D.systemctl status systemd-journald --disk
AnswerC

The --disk-usage option to journalctl reports the total amount of disk space consumed by the journal files. It provides a single summary line, making it ideal for quickly assessing whether the journal is the source of disk pressure. This is the purpose-built command for this exact diagnostic scenario.

Why this answer

The journalctl --disk-usage command is designed specifically to report how much disk space the systemd journal is consuming. It accounts for the journal's internal storage format, including compression, and returns a concise summary. Other commands either query unit status, filter log entries, or measure directory size in a way that may not match the journal's own accounting.

Exam trap

The trap here is reaching for du on the journal directory when journalctl provides an authoritative, journal-aware disk usage report.

30
MCQeasy

A system administrator needs to install a local Debian package file named 'myapp.deb'. Which command should be used?

A.rpm -ivh myapp.deb
B.aptitude install myapp.deb
C.dpkg -i myapp.deb
D.apt-get install myapp.deb
AnswerC

dpkg is Debian's low-level package manager, and the -i flag installs a local .deb archive directly from the filesystem. It satisfies the requirement to install the specified local file without fetching from a repository, unlike apt, which resolves dependencies remotely.

Why this answer

The correct command to install a local Debian package file is `dpkg -i myapp.deb`. The `dpkg` tool is the low-level package manager for Debian-based systems that directly handles `.deb` files, and the `-i` flag triggers installation. Unlike `apt-get` or `aptitude`, `dpkg` does not resolve dependencies automatically, but it is the proper tool for installing a standalone `.deb` file from disk.

Exam trap

The trap here is that candidates confuse `dpkg` with `apt-get` or `aptitude`, assuming that any package manager can install a local file, but only `dpkg` directly handles `.deb` files without requiring a repository lookup.

How to eliminate wrong answers

Option A is wrong because `rpm -ivh` is used for RPM-based distributions (e.g., Red Hat, Fedora) and cannot process `.deb` files; it would fail with an error about an invalid package format. Option B is wrong because `aptitude install` expects a package name from a repository, not a local file path; while `aptitude` can install a `.deb` file with `./myapp.deb` syntax, the standard and most direct command for a local `.deb` is `dpkg -i`. Option D is wrong because `apt-get install` also expects a package name from a repository, not a local file; it would attempt to fetch 'myapp.deb' from configured sources and fail, as it does not accept a file path directly.

31
MCQeasy

A system administrator notices that after updating the kernel, the system fails to boot. The administrator wants to boot the previous kernel. Which GRUB menu option should be selected?

A.Memory test
B.Advanced options for Ubuntu
C.Recovery mode
D.Boot from first hard disk
AnswerB

Selecting "Advanced options for Ubuntu" exposes the GRUB submenu listing every installed kernel version, including the previous one alongside its recovery mode entry. This satisfies the stem's constraint of booting the prior kernel after the update broke boot, since the default top-level entry points only at the newest kernel.

Why this answer

The 'Advanced options for Ubuntu' GRUB menu entry provides access to a submenu listing all installed kernel versions, allowing the administrator to select and boot the previous kernel. This is the standard method to revert to a known-good kernel after a failed update, as GRUB dynamically generates entries for each kernel found in /boot.

Exam trap

The trap here is that candidates may confuse 'Recovery mode' with a kernel version selector, but Recovery mode is a single-kernel boot option for troubleshooting, not a menu for choosing among multiple kernels.

How to eliminate wrong answers

Option A is wrong because 'Memory test' runs a diagnostic memory check (e.g., Memtest86+) and does not allow selecting a different kernel version. Option C is wrong because 'Recovery mode' boots a specific kernel with minimal services and a root shell, but it does not offer a choice of kernel versions; it is used for system repair, not kernel selection. Option D is wrong because 'Boot from first hard disk' bypasses the GRUB menu entirely and boots the default boot loader on the first disk, which would likely load the same problematic kernel.

32
MCQhard

A system administrator runs a script that contains the line: trap 'echo "Cleaning up..."' EXIT. The script is executed and then receives SIGINT (Ctrl+C) before normal completion. What happens?

A.The trap on EXIT is ignored because the script was interrupted by a signal.
B.The trap on EXIT is executed because SIGINT causes the shell to exit.
C.The trap on EXIT is executed only if the script completes normally.
D.The script continues running because SIGINT is trapped and ignored by default.
AnswerB

When a script receives SIGINT, the default action terminates the shell. Because the EXIT trap is set, the shell runs the trap command just before it exits, regardless of the reason for termination. The echo is therefore executed during the SIGINT-triggered exit, matching the described behavior.

Why this answer

The EXIT trap runs when the shell exits, regardless of whether the exit is normal or caused by a signal that terminates the shell. When SIGINT is received and not otherwise trapped, the shell exits, triggering the EXIT trap before termination. This makes EXIT suitable for cleanup actions such as removing temporary files.

Exam trap

The trap here is believing that an EXIT trap only fires on successful completion, when in fact it also runs when the shell is terminated by a signal.

33
MCQmedium

Which command is used to compress a file with the highest compression ratio?

A.gzip -9
B.xz -9
C.bzip2 -9
D.compress
AnswerB

`xz -9` invokes the xz compressor at preset level 9, its maximum setting, which applies the most exhaustive dictionary and match-finding search to yield the smallest output. Lower presets compress faster but produce larger files, so -9 gives the highest ratio.

Why this answer

`xz -9` uses the LZMA2 compression algorithm, which typically achieves a higher compression ratio than gzip (DEFLATE) or bzip2 (Burrows-Wheeler transform) at the cost of slower speed and higher memory usage. The `-9` flag sets the highest compression level, maximizing the ratio.

Exam trap

The trap here is that candidates often assume gzip or bzip2 with `-9` offers the highest compression ratio because they are more common, but xz is the correct answer due to its superior LZMA2 algorithm.

How to eliminate wrong answers

Option A is wrong because gzip uses the DEFLATE algorithm, which generally provides lower compression ratios than xz, especially at level 9. Option C is wrong because bzip2 uses the Burrows-Wheeler transform and Huffman coding, which can achieve good ratios but is typically outperformed by xz's LZMA2 in terms of compression ratio. Option D is wrong because `compress` uses the LZW algorithm, which is outdated and offers significantly lower compression ratios than modern tools like xz.

34
MCQeasy

A user's home directory /home/alice has grown unexpectedly large. The administrator wants to identify which subdirectory consumes the most space, displaying sizes in human-readable format and limiting output to one level deep. Which command is most appropriate?

A.df -h /home/alice
B.du -sh /home/alice/*
C.ls -lR /home/alice | sort -k5 -n
D.find /home/alice -type d -exec du -sh {} \;
AnswerB

The du command estimates file space usage. The -s flag summarizes each argument rather than recursing into every subdirectory, and -h produces human-readable units. Using the glob /home/alice/* passes each top-level item as a separate argument, so the output lists the total size of each immediate child. This directly answers which subdirectory is largest.

Why this answer

To find which immediate subdirectory of a home directory uses the most space, du with the summarize and human-readable flags, applied to a glob of top-level entries, gives exactly one line per child directory. This avoids the noise of recursive output and directly highlights the largest consumer. df would only show partition totals, and recursive listings are far too verbose.

Exam trap

The trap here is confusing disk free space at the filesystem level with per-directory usage, leading to use of df instead of du.

35
MCQhard

Refer to the exhibit. A user reports that the 'myapp' command fails to run. Based on the output, what is the most likely cause?

A.The interpreter path is incorrect.
B.The file is not a valid ELF executable.
C.A required shared library (libfoo.so.1) is missing.
D.The file is not executable for the user.
AnswerC

The dynamic linker resolves libfoo.so.1 at launch; if absent from the library search path, execution aborts before main() runs. The stem's error output confirms a missing dependency rather than a permissions or PATH fault, so installing the package providing libfoo.so.1 restores the command.

Why this answer

The error message 'error while loading shared libraries: libfoo.so.1: cannot open shared object file: No such file or directory' indicates that the dynamic linker cannot locate the required shared library libfoo.so.1. This is the most likely cause because the 'myapp' binary is linked against this library, and without it, the program cannot start.

Exam trap

LPI often tests the distinction between file permissions (executable bit) and runtime library dependencies, leading candidates to mistakenly choose 'file not executable' when the real issue is a missing shared library.

How to eliminate wrong answers

Option A is wrong because the interpreter path (e.g., #!/bin/bash or #!/usr/bin/python) is only relevant for script files, not for ELF binaries; the error message specifically mentions a missing shared library, not an interpreter issue. Option B is wrong because the file is clearly a valid ELF executable (as shown by the 'file' command output 'ELF 64-bit LSB executable'), and the error is about a missing library, not an invalid format. Option D is wrong because the file has execute permissions (as shown by '-rwxr-xr-x'), and the error message does not mention 'Permission denied'; the user can execute the file, but it fails at runtime due to the missing library.

36
MCQhard

A script reads a CSV file where fields may contain commas within quoted strings. Which approach correctly parses such fields?

A.Using 'cut -d',' -f1,2 file'
B.Using 'while IFS= read -r line; do ... done < file' and parsing manually
C.Using 'while IFS=',' read -r f1 f2; do ... done < file'
D.Using awk or a dedicated tool like csvkit
AnswerD

awk handles quoted fields via FPAT or custom field-separator logic, and csvkit implements RFC 4180 quoting rules, so embedded commas inside quotes are not treated as delimiters. Simple cut or IFS-based splitting cannot distinguish quoted commas, so a quote-aware parser is required.

Why this answer

CSV fields containing commas within quoted strings require a parser that understands CSV quoting rules. Awk can be scripted to handle quoted fields, and dedicated tools like csvkit (e.g., csvcut, csvformat) are designed specifically to parse CSV according to RFC 4180, correctly ignoring commas inside double-quoted strings.

Exam trap

The trap here is that candidates assume simple field-splitting tools like 'cut' or 'read' with IFS=',' can handle CSV, but they fail to account for commas inside quoted strings, which is a classic LPIC-1 data management pitfall.

How to eliminate wrong answers

Option A is wrong because 'cut -d',' -f1,2 file' splits on every comma, including those inside quoted strings, corrupting the field boundaries. Option B is wrong because 'while IFS= read -r line; do ... done < file' reads entire lines but manual parsing of quoted commas is error-prone and requires complex state-machine logic, not a simple approach. Option C is wrong because 'while IFS=',' read -r f1 f2; do ... done < file' splits on every comma, treating commas inside quotes as field separators, which breaks the CSV structure.

37
MCQeasy

A developer asks the system administrator to configure a local web server for testing using Apache. The server should serve files from /var/www/test. Which directive must be set in the Apache configuration to set this document root?

A.Alias /test /var/www/test
B.ServerRoot /var/www/test
C.DocumentRoot /var/www/test
D.DirectoryIndex /var/www/test
AnswerC

DocumentRoot defines the directory from which Apache serves files, so setting DocumentRoot /var/www/test makes that path the web root. Requests then resolve against /var/www/test, satisfying the requirement for a local test server serving that location.

Why this answer

The DocumentRoot directive in Apache defines the top-level directory from which it serves files for a given virtual host or the main server. Setting DocumentRoot /var/www/test tells Apache to map incoming HTTP requests to files under that directory, making it the correct choice for serving files from /var/www/test.

Exam trap

The trap here is that candidates confuse DocumentRoot with ServerRoot or Alias, often thinking ServerRoot defines where web files are served from, when in fact it points to Apache's own installation directory.

How to eliminate wrong answers

Option A is wrong because Alias maps a URL path to a filesystem directory but does not set the primary document root; it is used for additional URL-to-directory mappings. Option B is wrong because ServerRoot specifies the directory where Apache's configuration, logs, and modules reside, not the directory for serving web content. Option D is wrong because DirectoryIndex defines the default file (e.g., index.html) to serve when a directory is requested, not the document root path.

38
MCQeasy

A Linux administrator needs to check the current status of the systemd service named sshd, including whether it is active and its recent log entries. Which command should she run?

A.journalctl -u sshd
B.service sshd status
C.systemctl is-active sshd
D.systemctl status sshd
AnswerD

This command displays the current state (active/inactive), the main PID, and the most recent log lines for the sshd service. It directly answers the requirement to check status and recent logs in a single step, making it the correct and efficient choice.

Why this answer

The systemctl status command provides a concise overview of a unit's state, including whether it is active, the main PID, and recent journal entries. It is the standard systemd tool for checking both status and recent logs, making it the most complete and appropriate choice for the administrator's needs.

Exam trap

The trap here is confusing journalctl -u sshd with systemctl status sshd; only the latter shows both the current state and recent logs together.

39
MCQmedium

A Linux server has two hot-swappable SATA drives that are part of a software RAID 1 array. The administrator needs to replace one drive while the system is running, but first wants to verify the current status of the array to ensure it is not degraded. Which command will display the detailed status of the mdadm array?

A.cat /proc/mdstat
B.mdadm --detail /dev/md0
C.smartctl -a /dev/sda
D.fdisk -l /dev/sda
AnswerB

The mdadm --detail command displays comprehensive information about the specified array, including RAID level, array size, state (active/clean, degraded, etc.), UUID, and the status of each component device. This is exactly what the administrator needs to verify the array is not degraded and to confirm which drive can be safely replaced. It is the standard tool for detailed RAID inspection on Linux.

Why this answer

To verify the status of a software RAID array before replacing a drive, the administrator needs detailed information about the array's health and component devices. The mdadm --detail command provides this comprehensive view, including RAID level, state, and per-device status. This ensures the array is not already degraded and that the correct drive can be identified for replacement.

Other commands either show only summary information or focus on physical drives rather than the RAID logical device.

Exam trap

The trap here is assuming that /proc/mdstat provides all necessary details, but it only gives a summary and lacks the detailed component status needed for safe hot-swapping.

40
MCQhard

A company runs a web server using Apache with multiple virtual hosts. The administrator needs to restrict access to a specific virtual host based on the client IP address. Which configuration directive should be placed inside the <VirtualHost> block to deny IP 192.168.1.100?

A.Require host 192.168.1.100
B.Require not ip 192.168.1.100
C.Deny from 192.168.1.100
D.Require valid-user
AnswerB

New syntax: Require not ip denies the specific IP.

Why this answer

In Apache 2.4 and later, access control is managed using the `Require` directive with the `not` modifier to deny specific IP addresses. Placing `Require not ip 192.168.1.100` inside the `<VirtualHost>` block will deny access to that IP while allowing all others, as the default behavior is to require all IPs unless a `Require` directive explicitly grants access.

Exam trap

The trap here is that candidates familiar with Apache 2.2 may choose `Deny from` (Option C), not realizing that LPIC-1 exams focus on Apache 2.4 syntax where `Require` directives are the standard, and legacy directives are deprecated.

How to eliminate wrong answers

Option A is wrong because `Require host` is used to allow or deny based on hostnames (e.g., domain names), not IP addresses; it would attempt a reverse DNS lookup on the client IP, which is not the correct method for IP-based restrictions. Option C is wrong because `Deny from` is a legacy Apache 2.2 directive that is deprecated in Apache 2.4 and may not work unless the `mod_access_compat` module is loaded; it is not the modern recommended approach. Option D is wrong because `Require valid-user` is used for authentication-based access control (requiring a valid user/password), not for IP-based restrictions.

41
MCQeasy

An administrator adds the line 'DenyUsers john' to /etc/ssh/sshd_config and restarts the SSH service. What is the effect?

A.User john cannot log in via SSH.
B.User john can still log in but his commands are logged.
C.User john is denied all shell access, including local and console logins.
D.All users except john cannot log in via SSH.
AnswerA

DenyUsers in /etc/ssh/sshd_config blocks the named account from authenticating over SSH; after the service restart, john's connection attempts are refused. The directive is enforced by sshd itself, so it does not disable the local account or affect console logins.

Why this answer

The 'DenyUsers' directive in /etc/ssh/sshd_config explicitly blocks the specified user(s) from authenticating via SSH. When the SSH service is restarted, the configuration is reloaded, and user 'john' will be denied SSH login attempts at the authentication layer, before any shell or command execution occurs.

Exam trap

The trap here is that candidates often confuse 'DenyUsers' with broader access restrictions like PAM-based account denial or shell-level bans, but 'DenyUsers' is SSH-specific and only affects SSH logins, not console or other remote access methods.

How to eliminate wrong answers

Option B is wrong because 'DenyUsers' does not enable logging of commands; logging of SSH sessions is controlled by directives like 'LogLevel' or 'ForceCommand' with logging wrappers, not by 'DenyUsers'. Option C is wrong because 'DenyUsers' only affects SSH access, not local console logins or other non-SSH shell access; local authentication is handled by PAM or /etc/nologin, not by sshd_config. Option D is wrong because 'DenyUsers' denies only the specified user(s), not all users except that user; the inverse behavior would require 'AllowUsers' with all other users listed.

42
MCQhard

Refer to the exhibit. An admin attempts to execute a shell script located in /tmp but gets 'Permission denied'. Which mount option is most likely causing this?

A.relatime
B.noexec
C.nodev
D.nosuid
AnswerB

The `noexec` mount option prevents execution of any binaries or scripts on that filesystem, directly causing the "Permission denied" error when running the script from /tmp. Since /tmp is frequently mounted with `noexec` for security hardening, this constraint matches the symptom precisely, whereas other options would produce different errors.

Why this answer

The 'noexec' mount option prevents execution of any binary or script directly from the filesystem, regardless of file permissions. Since the script is in /tmp and the admin gets 'Permission denied' despite correct execute bits, the /tmp partition is likely mounted with noexec, which is a common security hardening practice.

Exam trap

The trap here is that candidates assume 'Permission denied' always means missing execute bits (chmod +x), when in fact the noexec mount option silently blocks execution even with correct permissions.

How to eliminate wrong answers

Option A (relatime) is wrong because it only controls how access timestamps are updated on the filesystem, not execution permissions. Option C (nodev) is wrong because it prevents block or character special devices from being interpreted, not script execution. Option D (nosuid) is wrong because it ignores setuid/setgid bits on executables, but does not block execution itself.

43
MCQhard

An RPM-based system has a package 'example-1.0' installed, but a newer version 'example-2.0' is available in a repository. Which command will upgrade the package?

A.rpm -Uvh example-2.0.rpm
B.yum update example
C.yum check-update example
D.yum install example
AnswerB

yum update example resolves the installed package to the newest available version in enabled repositories, upgrading example-1.0 to example-2.0 while handling dependencies. This satisfies the upgrade constraint, unlike yum install, which would report the package already installed.

Why this answer

'yum update example' is the standard command to upgrade a specific package to the latest available version from configured repositories. YUM automatically resolves dependencies and retrieves the newer package from the repository, making it the appropriate tool for upgrading from a repository source.

Exam trap

The trap here is that candidates often confuse 'yum install' (which installs a new package or upgrades if already installed but is not the standard upgrade command) with 'yum update' (the explicit command for upgrading installed packages), or they mistakenly think 'rpm -Uvh' works with repository packages without a local file.

How to eliminate wrong answers

Option A is wrong because 'rpm -Uvh example-2.0.rpm' requires a local RPM file and does not query repositories; it would fail if the file is not present locally, and it bypasses automatic dependency resolution from repositories. Option C is wrong because 'yum check-update example' only lists available updates without performing any upgrade; it is a query command, not an installation command. Option D is wrong because 'yum install example' would install the package if not present, but if the package is already installed, it may not upgrade to a newer version unless the installed version is older; however, 'yum update' is the explicit command for upgrading an already installed package.

44
MCQhard

A server configured with UEFI firmware and GPT partitioning fails to boot after a GRUB package update. The administrator suspects the bootloader is not correctly installed. Which command should be used to reinstall GRUB to the EFI system partition?

A.grub2-install /dev/sda1
B.grub-mkconfig -o /boot/grub/grub.cfg
C.grub-install /dev/sda
D.grub-install --target=x86_64-efi --efi-directory=/boot/efi
AnswerD

On UEFI systems with GPT, GRUB's EFI binary must be written to the EFI System Partition. The --target=x86_64-efi flag selects the EFI platform and --efi-directory=/boot/efi specifies the ESP mount point, satisfying the stem's UEFI firmware and GPT partitioning constraint.

Why this answer

On a UEFI-based system with GPT partitioning, GRUB must be installed as an EFI application to the EFI System Partition (ESP). The `--target=x86_64-efi` flag specifies the EFI firmware target, and `--efi-directory=/boot/efi` points to the mount point of the ESP, ensuring the bootloader files (e.g., `grubx64.efi`) are placed in the correct EFI directory (e.g., `/boot/efi/EFI/GRUB/`).

Exam trap

The trap here is that candidates confuse `grub-install /dev/sda` (which works for BIOS/MBR systems) with the UEFI-specific command, or they mistakenly think regenerating the config file with `grub-mkconfig` reinstalls the bootloader.

How to eliminate wrong answers

Option A is wrong because `grub2-install /dev/sda1` targets a partition (e.g., `/dev/sda1`) rather than the disk device; GRUB installation for BIOS or EFI requires the whole disk (e.g., `/dev/sda`) or specific EFI parameters, and using a partition number is invalid. Option B is wrong because `grub-mkconfig -o /boot/grub/grub.cfg` only regenerates the GRUB configuration file from templates and does not install the bootloader to the disk or ESP; it cannot fix a missing or corrupted bootloader installation. Option C is wrong because `grub-install /dev/sda` without the `--target` and `--efi-directory` flags defaults to installing for BIOS/legacy boot (i386-pc), which writes to the Master Boot Record (MBR) and is incompatible with UEFI firmware that expects an EFI executable on the ESP.

45
MCQhard

A script starts multiple background processes. An administrator wants to wait for all background jobs to complete before proceeding. Which command should be used?

A.jobs -l
B.wait %1
C.wait
D.sleep 5
AnswerC

`wait` with no arguments blocks the calling shell until every background job it spawned has terminated, then returns. This directly satisfies the stem's requirement to pause the script until all background processes finish, unlike `sleep` or polling loops that cannot detect job completion.

Why this answer

The `wait` command without any arguments waits for all background jobs spawned by the current shell to complete before returning control to the script. This is the correct way to synchronize multiple background processes in a shell script, ensuring all child processes finish before proceeding to the next command.

Exam trap

The trap here is that candidates often confuse `wait` with `jobs` or assume that a fixed sleep duration is sufficient, not realizing that `wait` is the only command that dynamically synchronizes with the actual completion of all background jobs.

How to eliminate wrong answers

Option A is wrong because `jobs -l` lists background jobs with their process IDs but does not wait for them to finish; it merely displays their status. Option B is wrong because `wait %1` waits only for the specific job with job specifier `%1` (the first background job), not all background jobs. Option D is wrong because `sleep 5` simply pauses execution for 5 seconds and does not guarantee that any background jobs have completed; it is a fixed delay, not a synchronization mechanism.

46
MCQhard

An RPM-based system reports a file conflict during package installation. Which option to the rpm command will allow the installation to overwrite files from another package?

A.--force
B.--replacefiles
C.--nodeps
D.--justdb
AnswerB

The --replacefiles option instructs rpm to overwrite files owned by other installed packages, resolving the conflict and allowing installation to proceed. Without it, rpm aborts to protect the existing package's files, so the conflict blocks the transaction.

Why this answer

The --replacefiles option tells rpm to overwrite files that already exist on the system from a different package, resolving file conflicts during installation. This is the correct and targeted way to allow overwriting without bypassing other important checks.

Exam trap

The trap here is that candidates often choose --force because it sounds like it would force overwrites, but it is a blunt instrument that also skips dependency checks, which is not what the question asks for.

How to eliminate wrong answers

Option A is wrong because --force is a legacy alias that actually combines --replacepkgs, --replacefiles, and --nodeps, which is overly broad and can mask dependency issues. Option C is wrong because --nodeps skips dependency checks entirely, not file conflict resolution. Option D is wrong because --justdb only updates the RPM database without actually installing or overwriting any files on disk.

47
MCQmedium

A Linux system administrator is tasked with setting up a new server that will host multiple virtual machines using KVM. The server has 64 GB of RAM and two physical CPUs, each with 8 cores (16 threads). The administrator needs to allocate resources efficiently. The VMs will have varying workloads. The administrator wants to ensure that the host system has enough resources for itself and that VMs can use all available CPU cores. Which approach should the administrator take to configure CPU allocation for the host and VMs?

A.Use QEMU emulation instead of KVM to reduce CPU overhead.
B.Pin all physical CPU cores to the VMs using virsh vcpupin, and leave no cores for the host.
C.Use CPU pinning to reserve two physical cores for the host and distribute the remaining cores among VMs using host-passthrough mode.
D.Overcommit CPU resources by assigning 32 vCPUs to each VM, relying on the hypervisor to schedule.
AnswerC

CPU pinning dedicates two physical cores to the host, guaranteeing its resources, while host-passthrough exposes remaining cores so VMs access all available CPU features. This matches the stem's dual constraints: host reservation plus full core availability.

Why this answer

It reserves two physical cores for the host system to ensure its stability and performance, while distributing the remaining cores among VMs using CPU pinning and host-passthrough mode. This approach allows VMs to access the full CPU feature set and all available cores efficiently, balancing host overhead with VM resource needs in a KVM environment.

Exam trap

The trap here is that candidates may assume overcommitting CPU resources is always safe (Option D) or that QEMU emulation is a performance improvement (Option A), when in fact KVM's hardware acceleration and proper pinning are critical for efficient virtualization.

How to eliminate wrong answers

Option A is wrong because QEMU emulation adds significant CPU overhead compared to KVM's hardware-assisted virtualization, which would degrade performance rather than reduce it. Option B is wrong because pinning all physical cores to VMs leaves no CPU resources for the host, causing the host to starve and potentially crash or become unresponsive. Option D is wrong because overcommitting CPU resources by assigning 32 vCPUs per VM (exceeding the total 32 threads) can lead to severe contention and performance degradation, as the hypervisor cannot efficiently schedule such an extreme overcommitment without proper resource limits.

48
MCQmedium

A system administrator wants to monitor a log file in real-time for lines containing 'ERROR' and write them to a separate file. Which command combination is most appropriate?

A.less logfile
B.tail -f logfile | grep 'ERROR' > error.log
C.vi logfile
D.cat logfile | grep 'ERROR' > error.log
AnswerB

`tail -f` follows the file as new lines are appended, satisfying the real-time monitoring constraint, while the pipe feeds each line to `grep 'ERROR'` for filtering. The redirection then writes only matching lines to error.log. Unlike `cat`, which exits at EOF, `tail -f` persists, so continuous logging is captured.

Why this answer

`tail -f logfile` continuously outputs new lines appended to the file, and piping that output into `grep 'ERROR'` filters only lines containing 'ERROR', which are then redirected to `error.log`. This combination achieves real-time monitoring and selective logging without blocking the terminal or requiring manual intervention.

Exam trap

The trap here is that candidates may confuse `cat` with `tail -f`, thinking both can monitor a file in real time, but `cat` only dumps the current content and exits, while `tail -f` actively follows appended data.

How to eliminate wrong answers

Option A is wrong because `less logfile` is a pager for viewing file contents interactively; it does not provide real-time updates and cannot automatically filter lines to a separate file. Option C is wrong because `vi logfile` opens the file in a text editor, which is not designed for real-time monitoring or automated filtering and redirection. Option D is wrong because `cat logfile | grep 'ERROR' > error.log` only processes the current contents of the file at the moment of execution; it does not monitor for new lines appended in real time.

49
MCQeasy

An administrator needs to determine which package owns the file /usr/bin/htop on a Debian-based system so that the package can be reinstalled after corruption. Which command provides this information?

A.dpkg -S /usr/bin/htop
B.dpkg -L htop
C.apt-file search /usr/bin/htop
D.apt-cache show htop
AnswerA

dpkg -S (or --search) queries the local package database for the package that owns a given file path. This is the direct, accurate way to map an installed file back to its package on a Debian-based system, which is exactly what the administrator needs before reinstalling the corrupted package.

Why this answer

On Debian-based systems, the local package database tracks which package installed each file. The dpkg search option queries that database by file path, returning the owning package, which is precisely the reverse lookup needed before reinstallation.

Exam trap

The trap here is confusing the direction of the lookup, using a command that lists a package's files instead of one that finds the package owning a file.

50
MCQmedium

A Linux administrator is responsible for a server that runs a critical database application. The server uses SysV init and the current runlevel is 3. The administrator needs to schedule a maintenance window for next Sunday at 2:00 AM to apply security patches that require a reboot. The administrator wants to ensure that after the reboot, the system returns to runlevel 3 and the database service (db_service) starts automatically. The administrator also wants to log the maintenance actions to /var/log/maintenance.log. Which of the following is the BEST approach to accomplish these tasks?

A.Edit /etc/rc.d/rc.local to start db_service and set runlevel via 'init 3' in the script. Then use 'at 2am Sunday shutdown -r now' to schedule reboot and redirect output to /var/log/maintenance.log.
B.Edit /etc/inittab to change the initdefault line to 'id:3:initdefault:' and create an init script for db_service with appropriate symlinks in /etc/rc.d/rc3.d/. Schedule the reboot using 'shutdown -r 02:00' and configure syslog to capture messages to /var/log/maintenance.log.
C.Use 'systemctl set-default runlevel3.target' and 'systemctl enable db_service' then schedule reboot with 'shutdown -r 02:00' and log with 'logger' to /var/log/maintenance.log.
D.Use 'telinit 3' and 'service db_service start' then run 'reboot' at 2:00 AM. Log actions by appending to /var/log/maintenance.log manually.
AnswerA

rc.local runs after boot, but setting runlevel via 'init 3' in rc.local is redundant and may cause issues. 'shutdown -r now' reboots immediately, not at 2:00.

Why this answer

The best approach because it uses 'at' to schedule the reboot, which can be configured to run at a specific day and time (e.g., 'at 2am Sunday shutdown -r now'), and redirects output to /var/log/maintenance.log for simple logging. Although editing rc.local is not the standard SysV method for persistent service management, it effectively starts the database service and sets the runlevel to 3 upon boot. In contrast, option B's shutdown command does not allow specifying the day 'next Sunday', and configuring syslog for a custom log file is non-trivial.

Options C and D are incorrect due to systemd usage or lack of scheduling.

Exam trap

The trap is that candidates may assume option B is correct because it uses proper SysV init configuration (inittab and init scripts), but they overlook that 'shutdown -r 02:00' cannot schedule for a specific day like 'next Sunday', and that configuring syslog for custom logging is not straightforward. Option A, while using rc.local (a less standard method), provides direct scheduling via 'at' and simple output redirection.

How to eliminate wrong answers

Option A is wrong because editing /etc/rc.d/rc.local to start db_service and run 'init 3' is not the standard SysV method for persistent runlevel or service management; rc.local runs after init scripts and may not execute on all reboots, and redirecting output with '>' in an 'at' job does not capture all boot messages. Option C is wrong because it uses systemctl commands (systemctl set-default, systemctl enable) which are for systemd systems, not SysV init; the server uses SysV init, so these commands are invalid. Option D is wrong because 'telinit 3' and 'service db_service start' only affect the current session and do not persist after reboot; manually appending to the log is error-prone and does not capture system boot messages.

51
Multi-Selectmedium

Which THREE of the following commands can be used to display information about block devices?

Select 3 answers
A.lsblk
B.free
C.fdisk -l
D.blkid
E.ip link
AnswersA, C, D

`lsblk` reads the sysfs and udev databases to list all block devices, showing their names, major and minor numbers, sizes, types and mountpoints in a tree hierarchy. This directly satisfies the stem's requirement to display block device information, unlike commands that report only filesystem usage or partition tables.

Why this answer

lsblk (A) is correct because it reads /sys/block and udev data to list all block devices in a tree, showing names, sizes, types, mountpoints, and major:minor numbers. fdisk -l (C) is correct because it enumerates the partition tables of all detected block devices, printing disk geometry, sector sizes, and partition layouts. blkid (D) is correct because it queries block-device attributes such as UUID, LABEL, and filesystem TYPE from the blkid cache and device superblocks. free (B) is not a block-device tool; it reports RAM and swap usage from /proc/meminfo. ip link (E) is a networking command that lists and manages network interfaces at layer 2, not block devices.

Exam trap

The trap here is that candidates may confuse `free` (memory) or `ip link` (network) with block device commands, or forget that `fdisk -l` and `blkid` also display block device information, not just `lsblk`.

52
MCQmedium

Based on the exhibit, what is the most likely cause of the SSH service failure?

A.The sshd service is disabled.
B.The firewall is blocking port 22.
C.Another service is already listening on port 22.
D.The SSH configuration file has a syntax error.
AnswerC

SSH binds to TCP port 22; if another process already holds that port, sshd cannot bind and fails to start. The exhibit's bind error confirms this conflict, making a competing listener the most likely cause rather than configuration or key issues.

Why this answer

The exhibit shows that the sshd service failed to start because the address (0.0.0.0:22) is already in use. This indicates that another process is already bound to port 22, preventing sshd from binding to it. Therefore, the most likely cause is that another service is already listening on port 22.

Exam trap

The trap here is that candidates often assume SSH failures are always due to firewall rules or disabled services, but the specific error message 'address already in use' directly points to a port conflict, not a firewall or configuration syntax issue.

How to eliminate wrong answers

Option A is wrong because if the sshd service were disabled, the system would not attempt to start it at all, and the error message would not indicate a port conflict. Option B is wrong because a firewall blocking port 22 would not cause sshd to fail to start; the service would still bind to the port, but connections would be dropped by the firewall. Option D is wrong because a syntax error in the SSH configuration file would produce a different error message (e.g., 'sshd: fatal: bad configuration options'), not an 'address already in use' error.

53
MCQmedium

An administrator is preparing a new USB drive for use as a portable ext4 data disk. After writing the partition table, the administrator wants to confirm the partition layout and the filesystem type currently on the device before formatting. Which command displays both the partition table and the detected filesystem types for /dev/sdd?

A.lsblk -f /dev/sdd
B.partprobe /dev/sdd
C.fdisk -l /dev/sdd
D.blkid /dev/sdd
AnswerA

lsblk reads from sysfs and udev to present block device topology. The -f option adds filesystem information including type, label, UUID, and mount point for each partition. Combined with the device argument, it shows the partition layout and detected filesystem types in one view, satisfying both requirements.

Why this answer

Verifying a device before formatting requires both the partition layout and any existing filesystem signatures. lsblk with the -f option merges block device topology from sysfs with filesystem metadata detected by libblkid, showing each partition's type, label, UUID, and mount point in a single tree view, which covers both needs at once.

Exam trap

The trap here is assuming fdisk -l reports filesystem types, when it only reports partition table entries and partition type codes.

54
MCQeasy

Refer to the exhibit. An administrator notices that /proc is mounted with 'noexec'. What is the impact of this mount option?

A.Device files are not interpreted.
B.Setuid programs do not work.
C.No binaries can be executed directly from /proc.
D.The filesystem cannot be written to.
AnswerC

The noexec mount option blocks direct execution of any binary stored on that filesystem, so running an executable file located under /proc fails with a permission error. This satisfies the stem's constraint: /proc is mounted noexec, therefore no binaries can be executed directly from it.

Why this answer

The 'noexec' mount option prevents the direct execution of any binary files located on the mounted filesystem. Since /proc is a virtual filesystem that contains runtime system information and process data, mounting it with 'noexec' means that no binaries can be executed directly from /proc. This is a security measure to prevent malicious code from being run from procfs, as /proc should never contain executable programs in normal operation.

Exam trap

The trap here is that candidates often confuse 'noexec' with 'nosuid' or 'nodev', thinking it affects setuid binaries or device files, when in fact 'noexec' strictly controls whether binary executables can be run directly from the filesystem.

How to eliminate wrong answers

Option A is wrong because device files are not interpreted by the 'noexec' option; device file handling is governed by the 'nodev' mount option, which prevents the interpretation of device files. Option B is wrong because setuid programs are affected by the 'nosuid' mount option, not 'noexec'; 'noexec' only prevents direct execution of binaries, while setuid behavior is controlled separately. Option D is wrong because the ability to write to a filesystem is controlled by the 'ro' (read-only) or 'rw' (read-write) mount options, not by 'noexec', which only affects execution permissions.

55
MCQhard

A server uses systemd-resolved for DNS. Users report that name resolution works for external domains but fails for internal company hostnames. The administrator checks /etc/resolv.conf and sees 'nameserver 127.0.0.53'. Which action will resolve the issue?

A.Set the internal DNS server in /etc/nsswitch.conf by adding 'dns' after 'files' in the hosts line.
B.Add 'search company.internal' to /etc/resolv.conf and run systemd-resolve --flush-caches.
C.Replace 127.0.0.53 with the internal DNS server IP in /etc/resolv.conf and restart the network service.
D.Edit /etc/systemd/resolved.conf and add the internal DNS server to the DNS= line, then restart systemd-resolved.
AnswerD

With systemd-resolved, /etc/resolv.conf points to the stub listener at 127.0.0.53. Actual upstream DNS servers are configured in /etc/systemd/resolved.conf under the DNS= directive. Adding the internal DNS server there and restarting the service will make systemd-resolved forward internal queries to the correct server, fixing resolution for internal hostnames.

Why this answer

systemd-resolved uses a stub listener at 127.0.0.53, and upstream DNS servers are configured in /etc/systemd/resolved.conf. To resolve internal domains, the internal DNS server must be added to the DNS= setting, followed by a restart of systemd-resolved. Editing /etc/resolv.conf directly, adjusting search domains, or modifying nsswitch.conf does not provide the correct upstream server and will not fix internal name resolution.

Exam trap

The trap here is editing /etc/resolv.conf manually on a system where it is a symlink managed by systemd-resolved, which will be overwritten.

56
Multi-Selectmedium

A Debian system has some partially installed packages due to a failed installation. Which TWO commands can help resolve the broken dependencies? (Choose exactly two.)

Select 2 answers
A.apt-get -f install
B.apt-get dist-upgrade
C.apt-get upgrade
D.dpkg --configure -a
E.apt-get remove --purge
AnswersA, D

`apt-get -f install` triggers APT's dependency repair routine, scanning the dpkg database for packages left in a half-configured or unpacked state and attempting to fix broken dependencies by installing missing prerequisites or removing offending packages. This directly satisfies the stem's constraint: a Debian system with partially installed packages after a failed installation.

Why this answer

The `apt-get -f install` command (option A) is specifically designed to fix broken dependencies by attempting to correct a system with unsatisfied dependencies, often by installing missing packages or removing partially installed ones. The `dpkg --configure -a` command (option D) reconfigures any unpacked but not yet configured packages, which is a common state after a failed installation, and can resolve dependency issues by completing the configuration of partially installed packages.

Exam trap

The trap here is that candidates often confuse `apt-get upgrade` or `dist-upgrade` with dependency repair, but only `-f install` and `dpkg --configure -a` are the correct tools for fixing broken dependencies from a failed installation.

57
MCQhard

A Linux server uses a custom udev rule to assign a persistent name to a USB-to-serial adapter. After a kernel update, the adapter is no longer recognized by its custom name, and the administrator finds that the rule file is still present. Which command should be used to reload the udev rules and trigger them for existing devices without rebooting?

A.udevadm info --query=all --name=/dev/ttyUSB0
B.systemctl restart systemd-udevd
C.udevadm monitor --kernel --property
D.udevadm control --reload-rules && udevadm trigger
AnswerD

udevadm control --reload-rules reloads the rules from /etc/udev/rules.d and /lib/udev/rules.d into the running udev daemon. udevadm trigger then replays kernel uevents for existing devices, causing the new rules to be applied. This combination applies rule changes immediately without a reboot, which is essential after modifying udev rules.

Why this answer

To apply modified udev rules to devices that are already connected, the rules must be reloaded into the udev daemon and then existing devices must be re-triggered. The command udevadm control --reload-rules performs the reload, and udevadm trigger replays events for all devices. Together they activate the new rule without requiring a reboot or physical reconnection.

Exam trap

The trap here is assuming that restarting the udev daemon or monitoring events is enough, overlooking that existing devices need an explicit trigger to be re-evaluated.

58
MCQhard

The exhibit shows output from an RPM query on a RHEL 8 system. The installation time is shown as a Unix timestamp. Which command would display the installation date of the openssh-server package in a human-readable format?

A.rpm -q --dump openssh-server
B.rpm -q --changelog openssh-server
C.rpm -qi openssh-server
D.rpm -q --scripts openssh-server
AnswerC

`rpm -qi openssh-server` queries the installed package's metadata, and its output includes the "Install Date" field already rendered in human-readable form, satisfying the stem's requirement to convert the Unix timestamp. The `-q` query mode with `-i` information selector reads from the local RPM database, so no timestamp arithmetic is needed.

Why this answer

`rpm -qi` (query info) displays detailed metadata for the specified package, including the installation date in a human-readable format. The `-i` flag retrieves information such as the installation date, build date, and other package metadata, converting Unix timestamps to a readable date string.

Exam trap

The trap here is that candidates may confuse `--dump` or `--scripts` with displaying metadata, but only `-i` (info) provides the installation date in a human-readable format, while the other options show different types of package data.

How to eliminate wrong answers

Option A is wrong because `rpm -q --dump` outputs file-level metadata (such as size, permissions, and MD5 digests) for each file in the package, not the package installation date. Option B is wrong because `rpm -q --changelog` displays the changelog entries for the package, which list historical changes and dates, but not the installation date of the package itself. Option D is wrong because `rpm -q --scripts` shows the pre-install, post-install, pre-uninstall, and post-uninstall scripts associated with the package, not the installation date.

59
MCQhard

A server has a backup script that runs daily at midnight. The system administrator notices that the script sometimes fails because the filesystem is mounted read-only. Which approach is the best practice to ensure the script runs only when the filesystem is writable?

A.Add a cron job that runs before the backup to remount the filesystem read-write
B.Use anacron to run the job after boot
C.Wrap the backup command in a script that checks if the filesystem is writable before proceeding
D.Change the cron job to run every hour until it succeeds
AnswerC

Testing writability with a command such as touch or mount before invoking the backup prevents failures caused by a read-only remount. The wrapper aborts cleanly instead of leaving a partial archive, directly addressing the intermittent read-only filesystem constraint.

Why this answer

It implements a proactive check within the script itself, using a command like `touch /mountpoint/testfile 2>/dev/null` or checking `/proc/mounts` to verify write access before executing the backup. This avoids unnecessary remounts and ensures the script only proceeds when the filesystem is writable, which is a robust and self-contained solution.

Exam trap

The trap here is that candidates may assume remounting (Option A) is a safe fix, but LPIC-1 emphasizes that a read-only filesystem often indicates a deeper problem, and the best practice is to check state rather than force a change.

How to eliminate wrong answers

Option A is wrong because blindly remounting the filesystem read-write could override a forced read-only state caused by filesystem errors (e.g., from `fsck`), potentially leading to data corruption or system instability. Option B is wrong because anacron is designed to run jobs that were missed due to the system being off, not to handle a filesystem being read-only; it does not check filesystem state before execution. Option D is wrong because running the backup every hour until it succeeds wastes system resources, may cause overlapping backups, and does not address the root cause of the read-only filesystem.

60
MCQeasy

A technician needs to remove a package named 'apache2' along with its configuration files from a Debian system. Which command should be used?

A.dpkg -r apache2
B.apt-get autoremove apache2
C.apt-get purge apache2
D.apt-get remove apache2
AnswerC

`apt-get purge apache2` removes both the package and its configuration files, satisfying the stem's explicit requirement to delete configuration alongside the package. Unlike `remove`, which leaves conffiles on disk, `purge` deletes them, so no residual settings remain on the Debian system.

Why this answer

The 'apt-get purge' command removes the specified package along with its configuration files from a Debian system. Unlike 'remove', which leaves configuration files intact, 'purge' deletes both the package binaries and the associated configuration data from /etc and other locations, fulfilling the requirement to remove 'apache2' completely.

Exam trap

The trap here is that candidates often confuse 'apt-get remove' with 'apt-get purge', mistakenly thinking 'remove' also deletes configuration files, or they incorrectly assume 'dpkg -r' performs a purge, when in fact it only removes the package without configuration cleanup.

How to eliminate wrong answers

Option A is wrong because 'dpkg -r apache2' removes the package but leaves configuration files on the system, which does not meet the requirement to remove configuration files. Option B is wrong because 'apt-get autoremove' is used to remove packages that were automatically installed as dependencies and are no longer needed; it does not accept a package name as an argument to remove a specific package like 'apache2'. Option D is wrong because 'apt-get remove apache2' removes the package binaries but retains configuration files, failing to satisfy the requirement to remove them.

61
Multi-Selectmedium

Which three options are valid ways to install a package 'curl' on a RHEL 8 system? (Choose three.)

Select 3 answers
A.`apt-get install curl`
B.`dnf install curl`
C.`rpm -i curl.rpm`
D.`yum install curl`
E.`zypper install curl`
AnswersB, C, D

Dnf is the default package manager on RHEL 8.

Why this answer

`dnf` is the default package manager on RHEL 8, replacing `yum` for handling RPM packages with automatic dependency resolution. It directly installs the `curl` package from configured repositories.

Exam trap

The trap here is that candidates may think `yum` is obsolete on RHEL 8, but it still works as a compatibility wrapper, while `apt-get` and `zypper` are clearly from different distributions, and `rpm -i` requires a local file, not a package name.

62
MCQhard

A Linux server uses systemd-resolved for DNS resolution. Users report that hostname resolution fails intermittently. The administrator inspects /etc/resolv.conf and finds it is a symlink to /run/systemd/resolve/stub-resolv.conf with nameserver 127.0.0.53. Which command should the administrator use to verify the current DNS servers and resolution status?

A.cat /etc/resolv.conf
B.resolvectl status
C.systemctl status systemd-resolved
D.dig @127.0.0.53 example.com
AnswerB

resolvectl status displays the current DNS servers, DNS domains, and other resolver configuration for each network interface. It shows which DNS servers are being used and can help diagnose intermittent resolution issues by revealing if multiple interfaces have conflicting DNS settings.

Why this answer

The resolvectl status command provides detailed information about the current DNS servers and resolution configuration for all interfaces. This is essential for diagnosing intermittent resolution failures, as it reveals if multiple interfaces are providing conflicting DNS servers or if fallback DNS is misconfigured.

Exam trap

The trap here is relying on /etc/resolv.conf to see DNS servers, but with systemd-resolved it only contains the stub address, not the actual upstream servers.

63
Matchingmedium

Match each Linux runlevel to its typical description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Halt

Single-user mode

Multi-user with networking

Multi-user with GUI

Reboot

Why these pairings

Standard SysV init runlevels: 0 (halt), 1 (single-user), 3 (multi-user with network), 5 (graphical multi-user), 6 (reboot). Common confusions involve swapping definitions between runlevels 3 and 5.

64
MCQhard

An organization uses a custom YUM repository. After adding a new RPM package to the repository, clients running 'yum update' do not see the new package. The repository metadata was regenerated using 'createrepo'. What is the most likely reason the clients are not seeing the update?

A.Clients have cached metadata and need to run 'yum clean all' or wait for cache expiration
B.The 'gpgcheck=1' option in the repo file prevents metadata download
C.The repository metadata was not signed with a GPG key
D.The RPM package version number is lower than the currently installed version
AnswerA

Cached metadata is the culprit: YUM stores repository metadata locally and only refreshes it when the expiry window lapses, so freshly regenerated repodata stays invisible until then. Running 'yum clean all' forces a metadata re-download, immediately exposing the new RPM to 'yum update'.

Why this answer

YUM clients cache repository metadata locally to improve performance. When a new package is added to a repository and 'createrepo' regenerates the metadata, clients will not see the update until they refresh their cached metadata. Running 'yum clean all' removes the cached metadata and forces a fresh download, or the cache will expire based on the 'metadata_expire' setting in the repo configuration (default is 6 hours).

Exam trap

The trap here is that candidates may think GPG signing or version numbers are the cause, but the real issue is that YUM's metadata caching prevents clients from immediately seeing repository changes without a cache refresh.

How to eliminate wrong answers

Option B is wrong because 'gpgcheck=1' only enables GPG signature verification on packages after they are downloaded, it does not prevent metadata download or repository access. Option C is wrong because repository metadata does not need to be signed with a GPG key for clients to download and use it; GPG signing of metadata is optional and not required for 'yum update' to see new packages. Option D is wrong because if the RPM package version number is lower than the currently installed version, YUM would simply not upgrade it, but the client would still see the package in the repository listing; the question states clients do not see the new package at all, indicating a metadata freshness issue, not a version comparison.

65
MCQmedium

After a reboot, a server fails to obtain an IP address on its sole ethernet interface. The administrator checks /etc/netplan/01-netcfg.yaml and finds the configuration looks correct. However, the interface shows no IP. The system uses systemd-networkd. Which command should be run next to apply the configuration and bring up the interface?

A.netplan apply
B.ifup eth0
C.systemctl restart networking
D.systemctl restart systemd-networkd
AnswerA

`netplan apply` parses the YAML and hands the resulting configuration to the systemd-networkd backend, which then brings the interface up and requests a lease. Since the stem confirms systemd-networkd is the renderer and the file is already correct, this regenerates and reloads the network state without a reboot.

Why this answer

The correct command is 'netplan apply' because the system uses netplan to manage network configuration, which generates backend configuration files for systemd-networkd. After editing the YAML file, 'netplan apply' parses the configuration, applies it to the running system, and triggers systemd-networkd to reconfigure the interface without requiring a full restart of the service.

Exam trap

The trap here is that candidates assume 'systemctl restart systemd-networkd' is sufficient, but without running 'netplan apply' first, the backend configuration files are not regenerated from the YAML, so the interface remains unconfigured.

How to eliminate wrong answers

Option B is wrong because 'ifup eth0' is a legacy tool from the ifupdown suite (used with /etc/network/interfaces) and does not interact with netplan or systemd-networkd; it would fail or be ignored on a system using netplan. Option C is wrong because 'systemctl restart networking' targets the legacy 'networking' service (ifupdown), which is not used when systemd-networkd is the backend; it may not be installed or enabled, and restarting it would not apply netplan YAML changes. Option D is wrong because 'systemctl restart systemd-networkd' would restart the service but would not cause netplan to regenerate the backend configuration files; the interface would still use the old or no configuration unless 'netplan apply' is run first to write the new .network files.

66
MCQeasy

Refer to the exhibit. An administrator wants to unset the BASH_ALIASES associative array. Which command will correctly remove it?

A.export -n BASH_ALIASES
B.unset -v BASH_ALIASES
C.delete BASH_ALIASES
D.unset BASH_ALIASES
AnswerD

unset removes a variable or array from the current shell environment. Applying it to BASH_ALIASES clears the associative array, satisfying the stem's requirement to unset it. The command takes the variable name without a dollar sign.

Why this answer

`unset` is the standard Bash built-in command to destroy a variable or function. For an associative array like BASH_ALIASES, `unset BASH_ALIASES` removes the entire array, including all its key-value pairs, from the current shell environment.

Exam trap

The trap here is that candidates may confuse `unset` with `export -n` or think a special flag like `-v` is required, when in fact `unset` alone is the correct and simplest way to remove any variable, including associative arrays.

How to eliminate wrong answers

Option A is wrong because `export -n` removes the export attribute from a variable but does not unset or delete the variable itself; the variable remains in the shell with its value intact. Option B is wrong because `unset -v` is valid for unsetting a variable, but the `-v` flag is unnecessary and not required for associative arrays; the plain `unset` command already handles variables correctly, and adding `-v` does not change behavior but is not the standard form for this task. Option C is wrong because `delete` is not a valid Bash built-in command; it is a common misconception from other shells or programming languages, and Bash has no `delete` command.

67
MCQhard

Refer to the exhibit. The system has multiple SAS drives attached to this controller, but one of them is not detected during boot. Which command is most likely to provide information about the device detection order?

A.cat /proc/scsi/scsi
B.lsblk
C.dmesg | grep -i scsi
D.lsscsi
AnswerC

The kernel ring buffer records SCSI and SAS device discovery, including host, target and LUN assignment order, as the controller probes each disk. Filtering dmesg for SCSI lines reveals which drives were detected and in what sequence, exposing the missing device.

Why this answer

The `dmesg` command displays kernel ring buffer messages, which include hardware detection and initialization logs during boot. By piping to `grep -i scsi`, you filter for SCSI-related messages, revealing the order in which devices were discovered and any errors for undetected drives. This is the most direct way to see why a specific SAS drive failed to appear.

Exam trap

The trap here is that candidates often pick `lsscsi` or `cat /proc/scsi/scsi` because they show SCSI devices, but they fail to realize those commands only show the final state, not the boot-time detection order or failure messages that `dmesg` provides.

How to eliminate wrong answers

Option A is wrong because `cat /proc/scsi/scsi` shows a static list of currently detected SCSI devices, not the boot-time detection order or failure details. Option B is wrong because `lsblk` lists block devices that are already recognized by the kernel, providing no information about the detection sequence or why a drive was missed. Option D is wrong because `lsscsi` displays a snapshot of SCSI devices currently visible to the system, similar to `/proc/scsi/scsi`, and does not reveal the boot-time probe order or errors.

68
MCQmedium

Which configuration file is the primary configuration file for logrotate?

A./var/log/messages
B./etc/logrotate.d/
C./etc/logrotate.conf
D./etc/rsyslog.conf
AnswerC

/etc/logrotate.conf holds the global directives that logrotate reads first, including rotation frequency, retention count and compression defaults, before it processes any per-service drop-in files in /etc/logrotate.d/. This satisfies the stem's requirement for the primary configuration file, since the drop-ins are merely included from it rather than being primary themselves.

Why this answer

The primary configuration file for logrotate is /etc/logrotate.conf. This file sets global options such as rotation frequency, compression, and the number of rotated logs to keep. It also includes configuration snippets from /etc/logrotate.d/ via an include directive, but the main control file is /etc/logrotate.conf.

Exam trap

The trap here is that candidates confuse the directory /etc/logrotate.d/ (which holds supplementary configs) with the primary configuration file /etc/logrotate.conf, or mistake /etc/rsyslog.conf (a logging daemon config) for logrotate's config.

How to eliminate wrong answers

Option A is wrong because /var/log/messages is a system log file managed by rsyslog or syslog-ng, not a configuration file for logrotate. Option B is wrong because /etc/logrotate.d/ is a directory containing per-service configuration snippets that are included by /etc/logrotate.conf, not the primary configuration file itself. Option D is wrong because /etc/rsyslog.conf is the configuration file for the rsyslog daemon, which handles system logging, not log rotation.

69
Multi-Selectmedium

Which TWO of the following are valid methods to view kernel messages on a systemd-based system?

Select 2 answers
A.lsmod
B.journalctl -k
C.cat /var/log/syslog
D.grub-mkconfig
E.dmesg
AnswersB, E

journalctl -k filters the systemd journal to kernel-originated messages only, reading the persistent or volatile journal maintained by systemd-journald. On a systemd-based system this satisfies the requirement to view kernel messages without relying on the legacy ring buffer alone.

Why this answer

Option B (journalctl -k) is correct because on systemd-based systems the journal stores kernel messages, and the -k (or --dmesg) flag filters the journal to show only kernel-ring-buffer entries, making it a native systemd method to view kernel messages. Option E (dmesg) is correct because it directly reads and prints the kernel ring buffer, which contains kernel boot and runtime messages, and it remains valid on systemd systems. Option A (lsmod) is not correct because it only lists currently loaded kernel modules and does not display kernel log messages.

Option C (cat /var/log/syslog) is not correct as a systemd-specific kernel-message method because syslog files are produced by a syslog daemon (and may not even exist on all systemd systems), not by systemd's journal, so it is not a reliable systemd-based way to view kernel messages. Option D (grub-mkconfig) is not correct because it generates GRUB bootloader configuration and has nothing to do with viewing kernel messages.

Exam trap

The trap here is that candidates may think `dmesg` is the only valid method for kernel messages, overlooking that `journalctl -k` is equally valid on systemd-based systems, or they may confuse `lsmod` with kernel message viewing due to its association with kernel information.

70
Multi-Selectmedium

Which TWO commands can be used to set the default boot target (runlevel) in systemd?

Select 2 answers
A.ln -sf /lib/systemd/system/multi-user.target /etc/systemd/system/default.target
B.systemctl isolate multi-user.target
C.systemctl default multi-user.target
D.systemctl enable multi-user.target
E.systemctl set-default multi-user.target
AnswersA, E

Symlinking the desired target unit to /etc/systemd/system/default.target changes the default boot target, satisfying the requirement to set it persistently. systemd resolves this symlink at boot, so multi-user.target replaces the previous default. This mirrors what systemctl set-default performs, making it a valid command for the scenario.

Why this answer

Option E, `systemctl set-default multi-user.target`, is correct because it is the official systemd command that creates or replaces the `/etc/systemd/system/default.target` symlink to point at the desired target, thereby setting the default boot target persistently. Option A, `ln -sf /lib/systemd/system/multi-user.target /etc/systemd/system/default.target`, is also correct because it manually performs the same underlying operation that `set-default` does: replacing the `default.target` symlink so systemd boots into multi-user.target on next boot. Option B, `systemctl isolate multi-user.target`, only switches the running system to that target immediately without changing the persistent default.

Option C, `systemctl default multi-user.target`, is not a valid systemd command syntax for setting a default target. Option D, `systemctl enable multi-user.target`, only enables the unit for activation (creating wants symlinks) and does not change the default boot target.

Exam trap

The trap here is that candidates confuse `systemctl isolate` (which changes the current runlevel immediately) with `systemctl set-default` (which sets the persistent default), or they mistakenly think `systemctl enable` sets the default target when it only enables a unit for automatic startup.

71
Multi-Selecthard

An administrator needs to monitor real-time network bandwidth usage on a Linux server. Which two tools are specifically designed for this purpose? (Choose two.)

Select 2 answers
A.netstat
B.nload
C.traceroute
D.ping
E.iftop
AnswersB, E

nload is a console bandwidth monitor that graphs inbound and outbound traffic per network interface in real time, refreshing continuously. It satisfies the stem's real-time bandwidth requirement directly, reading interface counters without packet capture, unlike general utilities such as netstat or ss.

Why this answer

B (nload) is correct because it is a command-line tool that displays real-time network traffic and bandwidth usage on a per-interface basis, showing incoming and outgoing data rates with a dynamic graph. E (iftop) is correct because it listens to network traffic on a specified interface and displays a real-time table of bandwidth usage per connection, similar to top for processes. Both tools are specifically designed for monitoring live bandwidth consumption, unlike general networking utilities.

Exam trap

The trap here is that candidates often confuse netstat's interface statistics (e.g., -i option) with real-time monitoring, but netstat only provides cumulative byte/packet counts since boot, not live bandwidth rates, making it unsuitable for real-time bandwidth monitoring.

72
MCQeasy

Which directory in the Filesystem Hierarchy Standard (FHS) contains essential user command binaries that are needed in single-user mode?

A./tmp
B./sbin
C./bin
D./boot
AnswerC

/bin holds essential user command binaries required for single-user mode and system repair, such as ls, cp and sh. The FHS designates it specifically for commands needed before other filesystems are mounted, matching the stem's single-user-mode constraint.

Why this answer

The /bin directory contains essential user command binaries (e.g., ls, cp, mv) that are required for system booting and repair in single-user mode. According to the FHS, /bin is intended for commands needed by both the system administrator and users when no other filesystems are mounted, making it critical for single-user mode operations.

Exam trap

The trap here is that candidates confuse /sbin with /bin, assuming that system administration binaries are the essential ones for single-user mode, when in fact /bin provides the user-level commands needed for basic system interaction and recovery.

How to eliminate wrong answers

Option A is wrong because /tmp is a temporary directory for files that may be deleted on reboot, not for essential command binaries. Option B is wrong because /sbin contains system administration binaries (e.g., fdisk, init) intended for the root user, not essential user commands needed in single-user mode. Option D is wrong because /boot contains static boot loader files (e.g., kernel images, initramfs) and not user command binaries.

73
MCQmedium

An administrator needs to install a Debian package file named custom-app.deb that was downloaded from a vendor website. The package has dependencies that are available in the configured repositories. Which command will install the package along with its dependencies?

A.dpkg --install --resolve custom-app.deb
B.dpkg -i custom-app.deb
C.apt-get install custom-app
D.apt install ./custom-app.deb
AnswerD

The apt command can install local .deb files if the path includes a slash or ./ prefix. When given a local package file, apt will resolve and download any missing dependencies from the configured repositories, then install both the package and its dependencies. This is the recommended method for installing a local .deb with dependency resolution.

Why this answer

The apt command, when given a local .deb file path (e.g., ./custom-app.deb), will install the package and automatically download and install any missing dependencies from configured repositories. This is the preferred method for installing local Debian packages that have dependencies available in repositories. dpkg alone does not handle dependencies.

Exam trap

The trap here is assuming that dpkg can resolve dependencies, or that apt can install a local file without specifying the path.

74
MCQeasy

A system administrator runs the command `fdisk -l` and sees the following line: Disk /dev/sda: 1000 GB, 1000204886016 bytes, 1953525168 sectors Based on this output, which statement is true?

A.The disk has write protection enabled
B.The disk has 5 partitions
C.The disk is 1 TB
D.The disk uses GPT partitioning
AnswerC

The kernel reports the disk as 1000204886016 bytes, which is approximately one trillion bytes. Disk manufacturers quote decimal units, so this capacity is marketed and recognised as 1 TB, not 1 TiB, which would be roughly 1.1 trillion bytes.

Why this answer

The output from `fdisk -l` shows the total disk size as 1000 GB, which is 1 TB. Thus, option C is correct. The output does not provide information about write protection, partition count, or partition table type.

Exam trap

The trap here is that candidates might assume the disk has a specific partition table type (like GPT) or partition count based on common defaults, but the output only provides disk size and geometry, not partition details, leading to overinterpretation of the data.

How to eliminate wrong answers

Option A is wrong because write protection is typically indicated by a read-only flag or specific error messages (e.g., 'Read-only file system'), not by the disk size or partition table type shown in the exhibit. Option B is wrong because the exhibit does not list any partitions; it only shows the disk size, so claiming 5 partitions is unsupported by the evidence. Option D is wrong because GPT partitioning is identified by a protective MBR or a 'gpt' label in partition table output, and the exhibit does not provide any partition table information to confirm GPT usage.

75
MCQeasy

A system administrator wants to display all lines in /var/log/syslog that do NOT contain the string 'error'. Which command accomplishes this?

A.grep -v 'error' /var/log/syslog
B.grep -r 'error' /var/log/syslog
C.grep -l 'error' /var/log/syslog
D.grep -i 'error' /var/log/syslog
AnswerA

`grep -v` inverts the match, printing only lines that fail the pattern test, so every line lacking "error" is emitted while matching lines are suppressed. This directly satisfies the stem's requirement to display non-matching lines from /var/log/syslog, with the file passed as grep's final operand.

Why this answer

The `grep -v` option inverts the match, displaying only lines that do NOT contain the pattern. Therefore, `grep -v 'error' /var/log/syslog` outputs all lines from the file that lack the string 'error', which directly fulfills the requirement.

Exam trap

The trap here is that candidates often confuse `-v` (invert match) with `-i` (case-insensitive) or `-r` (recursive), leading them to select options that still show matching lines instead of excluding them.

How to eliminate wrong answers

Option B is wrong because `-r` enables recursive search through directories, not line inversion; it would search for lines containing 'error' in the file and any subdirectories, which is not the intended behavior. Option C is wrong because `-l` lists only filenames (not lines) that contain the pattern, so it would output the filename if 'error' is found anywhere, not the lines without 'error'. Option D is wrong because `-i` performs case-insensitive matching, still showing lines that contain 'error' (or 'Error', 'ERROR', etc.), which is the opposite of what is asked.

Page 1 of 6

Page 2

All pages