Courseiva

Linux Professional Institute Certification Level 1 LPIC-1 (LPIC-1) — Questions 76–150

402 questions total · 6pages · All types, answers revealed

Page 1

Page 2 of 6

Page 3
76
MCQeasy

A junior admin is tasked with configuring network bonding on a Debian server with two Ethernet interfaces, eth0 and eth1. The goal is to provide link redundancy using active-backup mode. The admin edits /etc/network/interfaces and adds configuration for bond0 with slaves eth0 eth1, then runs 'ifup bond0'. However, the bond interface fails to come up and the error message indicates that the 'bond' kernel module is not loaded. The admin checks with 'lsmod | grep bonding' and finds no output. Which additional step is required to successfully bring up the bond interface? Options: A) Run 'modprobe bonding' before ifup, B) Use ifenslave directly after ifup, C) Reboot the system to load the module, D) Add 'auto bond0' in /etc/network/interfaces.

A.Run 'modprobe bonding' before ifup
B.Use ifenslave directly after ifup
C.Reboot the system to load the module
D.Add 'auto bond0' in /etc/network/interfaces
AnswerA

The bonding driver is built as a loadable module, and ifup does not auto-load it, so the bond0 interface cannot be created. Running modprobe bonding loads the module into the kernel before ifup, satisfying the missing-module constraint reported by lsmod.

Why this answer

The 'bond' kernel module must be loaded before the bonding interface can be created. Running 'modprobe bonding' loads the module into the kernel, making the bonding functionality available. Without this step, 'ifup bond0' fails because the kernel does not recognize the bonding driver.

Exam trap

The trap here is that candidates may think adding 'auto bond0' or rebooting will solve the module loading issue, but the kernel module must be explicitly loaded before the bonding interface can be created.

How to eliminate wrong answers

Option B is wrong because adding 'auto bond0' only configures the interface to start automatically at boot, but does not load the kernel module; the module must be loaded first. Option C is wrong because 'ifenslave' is a tool to attach slaves to an already existing bond interface, but the bond interface itself cannot be created without the bonding module. Option D is wrong because rebooting is unnecessary and inefficient; the module can be loaded dynamically with 'modprobe' without a reboot.

77
Drag & Dropmedium

Order the steps to configure a Linux system to use a proxy server for HTTP.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Proxy configuration involves setting environment variables and application-specific configs.

78
Multi-Selecteasy

Which TWO commands are used to manage Debian packages? (Choose two.)

Select 2 answers
A.zypper
B.apt-get
C.dpkg
D.yum
E.rpm
AnswersB, C

apt-get resolves dependencies and installs, upgrades or removes .deb packages from configured repositories, satisfying the stem's requirement for Debian package management. Unlike dpkg, which handles local archives without dependency resolution, apt-get retrieves dependencies automatically, making it a standard tool for managing Debian systems.

Why this answer

apt-get is the primary command-line tool for handling Debian packages, handling dependency resolution and retrieval from repositories. dpkg is the low-level tool that directly installs, removes, and queries .deb package files without automatic dependency management. Both are essential for Debian-based package management.

Exam trap

The trap here is that candidates often confuse low-level package tools (dpkg, rpm) with high-level ones (apt-get, yum, zypper), or incorrectly associate a tool with the wrong distribution family, especially when multiple package managers are listed.

79
MCQmedium

A Linux administrator is preparing a new server and needs to install a package group called 'Development Tools' on a CentOS 8 system. The administrator wants to see which packages are included in this group before installing. Which command should be used?

A.dnf group info "Development Tools"
B.yum groupinstall "Development Tools"
C.dnf list groups
D.rpm -q --group "Development Tools"
AnswerA

dnf group info displays detailed information about a package group, including the list of mandatory, default, and optional packages. This allows the administrator to see exactly what will be installed. It is the correct command for inspecting a group's contents on CentOS 8.

Why this answer

dnf group info provides a detailed breakdown of a package group, listing the packages that are part of it. This allows the administrator to review the contents before deciding to install. It is the standard way to inspect groups on CentOS 8 and other dnf-based distributions.

Exam trap

The trap here is confusing commands that list all groups or install groups with the command that shows the specific packages within a group.

80
MCQhard

You are a system administrator at a hosting company. A customer reports that their website hosted on a shared LAMP server is returning error 500. The server runs Ubuntu 22.04 with Apache, MySQL, and PHP. You log in and find that the /var partition (on /dev/sda3, ext4) is almost full. You identify that the MySQL database directory /var/lib/mysql contains several large binary logs that are no longer needed. You delete the binary logs using 'rm -f /var/lib/mysql/mysql-bin.*'. However, the available space does not increase. You also notice that an inode leak is suspected. You check inode usage with 'df -i' and see that the partition has plenty of free inodes. You then check with 'lsof | grep deleted' and see several entries for mysqld holding deleted files. What is the correct procedure to free the space?

A.Restart the MySQL service with 'systemctl restart mysql'.
B.Use 'dpkg --purge mysql-server' to completely remove MySQL, then reinstall it.
C.Run 'e2fsck -f /dev/sda3' to reclaim inodes and fix filesystem inconsistencies.
D.Move the binary logs to a different partition using 'mv /var/lib/mysql/mysql-bin.* /tmp/' and then delete them.
AnswerA

mysqld still holds open descriptors to the unlinked binary logs, so the ext4 blocks remain allocated despite the rm. Restarting MySQL closes those handles, releasing the space; free inodes confirm the issue is held descriptors, not inode exhaustion.

Why this answer

When a file is deleted while a process (like mysqld) still holds an open file descriptor to it, the file's inode remains allocated and the disk space is not freed until the process releases the descriptor. Restarting the MySQL service (systemctl restart mysql) causes mysqld to close all open file descriptors, allowing the kernel to release the deleted binary logs' inodes and reclaim the disk space.

Exam trap

The trap here is that candidates assume deleting a file immediately frees disk space, overlooking that processes with open file descriptors prevent the kernel from releasing the inode and data blocks until the descriptor is closed.

How to eliminate wrong answers

Option B is wrong because completely purging and reinstalling MySQL is an unnecessarily destructive and time-consuming procedure; the issue is simply that the MySQL process holds open file descriptors to the deleted logs, not a problem with the MySQL installation itself. Option C is wrong because e2fsck checks and repairs filesystem metadata, but it does not force processes to release open file descriptors; the inodes are already marked as deleted but are still held open by mysqld, so e2fsck cannot reclaim them. Option D is wrong because moving the files to /tmp/ and then deleting them would still leave the MySQL process holding open file descriptors to the moved (and then deleted) files, resulting in the same space-not-freed problem; the core issue is the open file descriptor, not the file's location.

81
MCQmedium

Refer to the exhibit. When will the backup script run?

A.Daily at 4:30 AM
B.Monthly at 4:30 AM on the 1st
C.Yearly at 4:30 AM
D.Weekly at 4:30 AM
AnswerB

The '1' in the day-of-month field indicates the first day of each month.

Why this answer

The cron entry `30 4 1 * * /usr/local/bin/backup.sh` specifies that the script runs when the minute is 30, hour is 4, and day-of-month is 1, with the month and day-of-week fields set to `*` (meaning every month and every day of the week). This results in execution at 4:30 AM on the 1st day of every month, making option B correct.

Exam trap

LPI often tests the misconception that a `*` in the day-of-week field implies 'every day' but candidates forget that the day-of-month field of `1` restricts execution to only the 1st, not daily.

How to eliminate wrong answers

Option A is wrong because 'Daily at 4:30 AM' would require the day-of-month field to be `*` (or a day-of-week field set to `*` with no day-of-month restriction), but here the day-of-month is `1`, limiting execution to only the 1st of each month. Option C is wrong because 'Yearly at 4:30 AM' would typically use a specific month field (e.g., `30 4 1 1 *` for January 1st), but the month field is `*`, meaning every month, not just one month per year. Option D is wrong because 'Weekly at 4:30 AM' would require a specific day-of-week value (e.g., `30 4 * * 0` for Sunday), but the day-of-week field is `*` and the day-of-month is `1`, which does not guarantee a weekly schedule.

82
MCQmedium

After receiving a compressed tarball archive.tar.gz from a colleague, you want to list its contents without extracting. Which command should you use?

A.tar -xzf archive.tar.gz
B.tar -cvf archive.tar.gz
C.gzip -d archive.tar.gz | tar -t
D.tar -tvf archive.tar.gz
AnswerD

The -t flag lists archive contents without extracting, -v shows verbose detail, and -f specifies the archive file. Combined as -tvf, tar reads archive.tar.gz and prints its members, satisfying the requirement to inspect without unpacking.

Why this answer

The `tar -tvf archive.tar.gz` command lists the contents of a compressed tarball without extracting it. The `-t` option tells tar to list the archive's table of contents, `-v` provides verbose output (showing file permissions, ownership, etc.), and `-f` specifies the archive file. Tar automatically detects and decompresses the gzip compression when reading the file, so no separate decompression step is needed.

Exam trap

The trap here is that candidates confuse the `-x` (extract) flag with `-t` (list) because both are used for reading archives, but only `-t` lists without extracting; LPI often tests this by offering `-xzf` as a distractor, assuming candidates will misremember the flag for listing.

How to eliminate wrong answers

Option A is wrong because `tar -xzf archive.tar.gz` extracts the archive (the `-x` flag means extract), not lists its contents. Option B is wrong because `tar -cvf archive.tar.gz` creates a new archive (the `-c` flag means create) from files, which would overwrite the existing file or fail, and does not list contents. Option C is wrong because `gzip -d archive.tar.gz | tar -t` attempts to decompress the file and pipe the output to `tar -t`, but `gzip -d` without `-c` (or `--stdout`) writes the decompressed data to a file (removing the .gz extension) instead of sending it to stdout, so the pipe receives no data and tar fails; even if corrected with `gzip -dc`, it is unnecessarily complex since tar handles decompression natively.

83
MCQmedium

A user complains that a filesystem is reporting 'Disk quota exceeded' even though the user has not stored any new files recently. What could be the cause?

A.Symlinks are counted against the quota
B.Hard links are consuming additional inodes
C.The user has exceeded the inode quota
D.File ownership is misconfigured
AnswerC

Disk quotas limit both blocks and inodes separately. A user can stay under the block quota yet exceed the inode quota by creating many small files or directories, so writes fail with 'Disk quota exceeded' despite no significant new data being stored.

Why this answer

Linux filesystems enforce two types of quotas: block quotas (for disk space) and inode quotas (for the number of files and directories). If the user has not stored new files recently but still receives a 'Disk quota exceeded' error, it is likely that they have exceeded their inode quota, meaning they have created too many files or directories (each consuming an inode), even if those files are small or empty. The error message is generic and can refer to either quota type, so the inode limit is the probable cause when no recent data writes have occurred.

Exam trap

The trap here is that candidates assume 'Disk quota exceeded' always refers to disk space (blocks), but LPIC-1 tests the distinction between block quotas and inode quotas, and that the same error message applies to both.

How to eliminate wrong answers

Option A is wrong because symlinks (symbolic links) are not counted against the quota of the user who owns the symlink; they are separate files that point to another file and do not consume the target's quota. Option B is wrong because hard links do not consume additional inodes; they are additional directory entries pointing to the same inode, so the inode count remains unchanged for the user. Option D is wrong because misconfigured file ownership would cause permission errors (e.g., 'Permission denied'), not a 'Disk quota exceeded' error, which is specifically a quota enforcement mechanism.

84
MCQmedium

A Debian-based server has a custom application installed from a local .deb file that was built in-house. The administrator wants to verify the package's metadata (version, dependencies, and maintainer scripts) before installing it on a production system, but does not want to actually install it. Which command should the administrator use?

A.dpkg --contents application.deb
B.apt-cache show application
C.dpkg --info application.deb
D.dpkg-deb --extract application.deb /tmp/app
AnswerC

The --info (or -I) option to dpkg displays detailed metadata from a .deb archive, including package name, version, architecture, dependencies, and the maintainer scripts, without installing it. This is exactly what the administrator needs to inspect the package before deployment, making it the correct tool for a pre-installation review of an in-house .deb file.

Why this answer

The dpkg --info command reads the control information embedded in a .deb archive, showing the package name, version, architecture, dependencies, and maintainer scripts. It is the standard way to inspect a local package's metadata before installation, which is precisely what the administrator needs to verify the in-house application without modifying the production system.

Exam trap

The trap here is confusing the options that list files inside a package with the option that displays the package's control metadata.

85
MCQhard

A system is running out of disk space on /var. The administrator finds that /var/log/syslog is 4GB. Which of the following is the best course of action to prevent future issues while keeping recent logs?

A.Use 'truncate -s 0 /var/log/syslog' to empty the file.
B.Configure logrotate to rotate and compress logs daily.
C.Configure syslog to stop logging.
D.Delete /var/log/syslog and create an empty file.
AnswerB

logrotate rotates /var/log/syslog on a daily schedule, compressing archived copies and enforcing retention limits, so recent logs remain readable while total size stays bounded. This directly satisfies the stem's constraint of preventing recurrence while preserving recent log data.

Why this answer

Logrotate is the standard Linux utility for managing log file growth. By configuring it to rotate and compress logs daily, the administrator can automatically archive old logs (e.g., /var/log/syslog.1.gz) and keep only recent entries in the active file, preventing disk space exhaustion without losing historical data.

Exam trap

The trap here is that candidates confuse immediate space recovery (truncation/deletion) with sustainable log management, overlooking that logrotate provides automated, policy-driven rotation and compression to prevent recurrence.

How to eliminate wrong answers

Option A is wrong because truncating the file to zero bytes only frees space immediately but does not prevent the file from growing again; it also discards all existing logs, which may violate compliance or troubleshooting needs. Option C is wrong because stopping syslog entirely would halt all system logging, losing critical diagnostic information and potentially violating security auditing requirements. Option D is wrong because deleting and recreating the file is functionally similar to truncation—it frees space now but offers no automated rotation or compression, so the problem will recur.

86
MCQhard

A minimal Linux system boots using a legacy BIOS with GRUB 2 installed in the MBR of /dev/sda. The administrator wants to install a new boot loader configuration that writes the boot code to the MBR and also places core.img in the gap between the MBR and the first partition. Which command accomplishes this?

A.grub-mkconfig -o /boot/grub/grub.cfg
B.grub-install /dev/sda1
C.update-grub
D.grub-install /dev/sda
AnswerD

On a BIOS/MBR system, running grub-install with the disk device as the target embeds the boot image in the MBR and writes core.img into the post-MBR gap, then installs modules under /boot/grub. This matches the administrator's requirement to update both the MBR boot code and the embedded core image for a legacy BIOS boot path.

Why this answer

Installing GRUB 2 for legacy BIOS boot requires writing code to the disk's master boot record and embedding the core image in the space before the first partition. Passing the whole disk device to the installer achieves both. Configuration generators such as grub-mkconfig or its wrapper only rebuild the menu file and never modify the MBR, and targeting a partition instead of the disk writes to the wrong location.

Exam trap

The trap here is treating menu-regeneration commands like update-grub as if they install the boot loader, when only the installer targeting the whole disk writes MBR boot code and embeds core.img.

87
MCQeasy

On a Debian-based system using ifupdown, which file should be edited to configure a static IP address for an interface?

A./etc/systemd/network/50-static.network
B./etc/network/interfaces
C./etc/netplan/01-netcfg.yaml
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerB

On Debian systems using ifupdown, /etc/network/interfaces is the canonical configuration file where interface stanzas define addressing. Editing it to add an iface entry with static address, netmask and gateway satisfies the requirement for persistent static IP configuration applied by ifup at boot.

Why this answer

On Debian-based systems using the traditional ifupdown suite, the file `/etc/network/interfaces` is the central configuration file for defining network interfaces, including static IP addresses. This file is parsed by the `ifup` and `ifdown` commands to bring interfaces up or down with the specified settings, such as `address`, `netmask`, and `gateway`.

Exam trap

The trap here is that candidates often confuse the default network configuration file for Debian-based systems with those used by other distributions (Red Hat) or newer abstraction layers (Netplan, systemd-networkd), leading them to pick a file that is technically valid but not used by the ifupdown tool specified in the question.

How to eliminate wrong answers

Option A is wrong because `/etc/systemd/network/50-static.network` is used by `systemd-networkd`, not by the ifupdown suite; Debian systems using ifupdown do not rely on systemd-networkd for interface configuration. Option C is wrong because `/etc/netplan/01-netcfg.yaml` is the configuration file for Netplan, which is used on Ubuntu (and some other distributions) as a frontend for systemd-networkd or NetworkManager, not for the traditional ifupdown system. Option D is wrong because `/etc/sysconfig/network-scripts/ifcfg-eth0` is the configuration file format used by Red Hat-based distributions (e.g., CentOS, Fedora) with the legacy network service, not by Debian-based systems.

88
MCQmedium

Refer to the exhibit. The system administrator wants to determine which package provides the file /etc/passwd. Based on the output, which command would be most appropriate to find the package?

A.`dpkg -L base-passwd`
B.`apt-file search /etc/passwd`
C.`dpkg -S /etc/passwd`
D.`apt-cache show /etc/passwd`
AnswerC

On Debian-based systems, dpkg -S searches the installed package database for the package owning a given file path, returning the package name directly. The exhibit shows a dpkg-managed system, so this queries the correct local database rather than an RPM or repository index.

Why this answer

`dpkg -S /etc/passwd` queries the dpkg database to find which installed package owns the specified file. This is the standard Debian/Ubuntu command to map an absolute path to its originating package, making it the most appropriate choice for the administrator's goal.

Exam trap

The trap here is that candidates confuse `dpkg -S` (search for file) with `dpkg -L` (list files of a known package), or they incorrectly use `apt-cache` or `apt-file` which operate on repository data rather than the installed package database.

How to eliminate wrong answers

Option A is wrong because `dpkg -L base-passwd` lists all files installed by the `base-passwd` package, but it does not search for which package provides `/etc/passwd`; it assumes the package is already known. Option B is wrong because `apt-file search /etc/passwd` searches the package repository metadata (not the installed package database) for files, which is useful for finding packages that provide a file not yet installed, but the question asks about an installed file. Option D is wrong because `apt-cache show /etc/passwd` is invalid syntax; `apt-cache show` is used to display metadata about a package name, not to search for a file path.

89
MCQeasy

A system administrator notices that the system time is incorrect by several minutes. Which command should be used first to check the status of NTP synchronization?

A.timedatectl
B.ntpdate
C.date
D.hwclock
AnswerA

timedatectl reports the system clock, time zone, and whether NTP synchronisation is active, showing the service state and last sync. It satisfies the stem's requirement to check NTP status first, before adjusting configuration with chronyc or restarting services.

Why this answer

The `timedatectl` command is the correct first step because it shows the current system time, time zone, and NTP synchronization status in a single output. It directly reports whether NTP is active and whether the clock is synchronized, making it the standard diagnostic tool on modern systemd-based Linux distributions.

Exam trap

The trap here is that candidates often confuse `ntpdate` as a diagnostic tool because it can query an NTP server, but it is not designed to show the ongoing synchronization status of the system's NTP service.

How to eliminate wrong answers

Option B is wrong because `ntpdate` is a legacy command used for one-time manual time setting, not for checking synchronization status; it also requires stopping the NTP service first. Option C is wrong because `date` only displays or sets the system time without any NTP status information. Option D is wrong because `hwclock` manages the hardware clock (RTC) and does not show NTP synchronization status.

90
Multi-Selecthard

A Linux administrator needs to create a new ext4 filesystem on a logical volume /dev/vg0/lv_data and mount it persistently at /data. Which TWO of the following steps are required to accomplish this? (Choose two.)

Select 2 answers
A.Run pvcreate /dev/vg0/lv_data
B.Add an entry for /dev/vg0/lv_data in /etc/fstab
C.Run mkfs.ext4 /dev/vg0/lv_data
D.Run mount -a to mount all filesystems
E.Run vgcreate vg0 /dev/vg0/lv_data
AnswersB, C

To mount the filesystem persistently at /data, an entry must be added to /etc/fstab. This ensures the filesystem is mounted automatically at boot or with mount -a. The entry typically includes the device, mount point, filesystem type, and options. Without this, the mount would not persist across reboots.

Why this answer

To create and persistently mount a new ext4 filesystem on an existing logical volume, the administrator must first create the filesystem with mkfs.ext4, then add an entry to /etc/fstab to ensure it mounts at boot. Other commands like pvcreate, vgcreate, and mount -a are either incorrect or not strictly required for this task.

Exam trap

The trap here is confusing LVM creation steps with filesystem creation and persistent mounting, or thinking that mount -a is mandatory.

91
MCQhard

After connecting a USB device, the system does not create a device node in /dev. Which command can be used to trigger udev to re-evaluate the device?

A.modprobe
B.udevadm control --reload
C.udevadm settle
D.udevadm trigger
AnswerD

udevadm trigger requests that udev re-run its rules for existing devices, replaying kernel uevents so device nodes in /dev are recreated. This directly addresses a missing node after USB connection, unlike udevadm info, which only queries.

Why this answer

The correct command is `udevadm trigger`. This command causes udev to re-evaluate all devices by simulating kernel uevents, which forces udev to process rules and create device nodes in /dev for devices that were missed or not properly initialized.

Exam trap

The trap here is confusing `udevadm trigger` with `udevadm control --reload`; candidates often think reloading rules alone will fix missing device nodes, but without re-triggering uevents, udev does not re-evaluate already-connected devices.

How to eliminate wrong answers

Option A is wrong because `modprobe` is used to load or unload kernel modules, not to trigger udev rule processing or device node creation. Option B is wrong because `udevadm control --reload` reloads the udev rules and configuration files but does not re-trigger uevents for existing devices. Option C is wrong because `udevadm settle` waits for the udev event queue to finish processing; it does not initiate new uevents or force device node creation.

92
Multi-Selecthard

Which THREE of the following are valid sources to configure GRUB?

Select 3 answers
A./boot/grub/menu.lst
B./etc/grub.conf
C./boot/grub/grub.cfg
D./etc/default/grub
E./etc/grub.d/
AnswersC, D, E

/boot/grub/grub.cfg is the generated GRUB 2 configuration file, read directly by GRUB at boot. It satisfies the stem's requirement for a valid configuration source, though it is produced by grub-mkconfig from /etc/default/grub and /etc/grub.d scripts, so manual edits are overwritten on regeneration.

Why this answer

Option C, /boot/grub/grub.cfg, is correct because it is the primary GRUB 2 configuration file that grub-mkconfig generates and that GRUB reads at boot time to build the menu. Option D, /etc/default/grub, is correct because it holds user-editable variables such as GRUB_TIMEOUT and GRUB_CMDLINE_LINUX that grub-mkconfig sources when regenerating grub.cfg. Option E, /etc/grub.d/, is correct because it contains the executable scripts (e.g., 00_header, 10_linux, 30_os-prober) whose output is assembled by grub-mkconfig into grub.cfg.

Option A, /boot/grub/menu.lst, is not a valid GRUB 2 source since menu.lst belongs to the legacy GRUB 1 configuration scheme. Option B, /etc/grub.conf, is likewise a legacy GRUB 1 file (often a symlink to menu.lst on older Red Hat systems) and is not used by GRUB 2.

Exam trap

The trap here is that candidates confuse GRUB Legacy files (`menu.lst` or `grub.conf`) with GRUB 2 files, or think `/etc/grub.conf` is a standard GRUB 2 configuration file, when in fact GRUB 2 uses `/etc/default/grub` and `/etc/grub.d/` as sources, with the generated output in `/boot/grub/grub.cfg`.

93
MCQhard

A shell script contains the following line: `find /data -type f -name '*.tmp' -exec rm {} \;`. What is the effect of this command?

A.It removes all empty directories ending with .tmp in /data.
B.It lists all .tmp files in /data without deleting them.
C.It removes all files ending with .tmp in /data and its subdirectories.
D.It removes all files in /data that do not end with .tmp.
AnswerC

The find command searches /data for regular files (-type f) with names ending in .tmp. The -exec rm {} \; executes the rm command on each found file, removing it. The backslash before the semicolon escapes it so that the shell passes the semicolon to find, which uses it to terminate the command. This effectively deletes all .tmp files under /data, including subdirectories.

Why this answer

The find command with -type f -name '*.tmp' -exec rm {} \; locates all regular files with names ending in .tmp under /data and executes rm on each. This deletes those files. The backslash escapes the semicolon to prevent shell interpretation.

This is a common idiom for batch deletion. Other options misinterpret the type, name pattern, or action.

Exam trap

The trap here is misunderstanding the -exec action or the -name pattern, leading to thinking it lists files or affects different files.

94
MCQmedium

Based on the exhibit, which of the following is true about the cleanup.sh job?

A.It runs at 4:30 AM every day
B.It runs at 4:30 AM on Monday through Friday
C.It runs at 4:00 AM on weekdays
D.It runs at 4:30 AM on weekends
AnswerB

The cron schedule encodes minute 30, hour 4, and a day-of-week field restricted to Monday through Friday, so the job executes at 04:30 on weekdays only. This matches the stated behaviour of the cleanup.sh job shown in the exhibit.

Why this answer

The cron expression `30 4 * * 1-5` specifies that the job runs at minute 30, hour 4 (4:30 AM), every day of month (*), every month (*), but only on days of the week 1 through 5 (Monday=1, Tuesday=2, Wednesday=3, Thursday=4, Friday=5). Therefore, the job runs at 4:30 AM on Monday through Friday.

Exam trap

The trap here is that candidates often misread the minute field (30) as the hour or confuse the day-of-week range `1-5` with 'every day', leading them to select 'every day' or 'weekends' instead of the correct weekday-only schedule.

How to eliminate wrong answers

Option A is wrong because it states 'every day', but the day-of-week field `1-5` restricts execution to weekdays only, not all seven days. Option C is wrong because it specifies 4:00 AM, but the minute field is `30`, not `0`, so the job runs at 4:30 AM, not 4:00 AM. Option D is wrong because it says 'on weekends', but the day-of-week range `1-5` explicitly excludes Saturday (6) and Sunday (0 or 7), so the job does not run on weekends.

95
MCQmedium

A system administrator notices that the /tmp directory is filling up quickly, causing applications to fail. The administrator wants to ensure that files in /tmp are automatically cleaned after a certain period. Which of the following is the best approach without installing additional software?

A.Add a cron job that runs 'rm -rf /tmp/*' every hour.
B.Install tmpwatch and configure it to clean files older than 1 day.
C.Set the sticky bit on /tmp to automatically delete old files.
D.Configure the systemd-tmpfiles service with a configuration file to clean /tmp regularly.
AnswerD

Configuring systemd-tmpfiles uses the distribution's built-in age-based cleanup: a drop-in under /etc/tmpfiles.d/ with a `d /tmp 1777 root root 10d` line makes systemd-tmpfiles-clean.timer purge entries older than the specified age. This satisfies the no-additional-software constraint, since systemd already ships with the system.

Why this answer

Systemd-based Linux distributions include the systemd-tmpfiles service, which can be configured via files in /etc/tmpfiles.d/ to automatically clean temporary files based on age, size, or other criteria. This approach uses built-in systemd functionality without requiring additional software, and it is the recommended method for managing /tmp cleanup on modern systems.

Exam trap

The trap here is that candidates may confuse the sticky bit (which only prevents deletion by other users) with automatic cleanup, or assume that a brute-force cron job is acceptable, while the correct answer leverages a built-in systemd service that is already present on most modern Linux distributions.

How to eliminate wrong answers

Option A is wrong because using 'rm -rf /tmp/*' in a cron job is dangerous and unreliable: it will delete all files regardless of age, may fail on hidden files or subdirectories with special characters, and can cause race conditions or data loss for running applications. Option B is wrong because tmpwatch is not installed by default on most modern distributions and the question explicitly states 'without installing additional software'. Option C is wrong because the sticky bit (chmod +t) only prevents users from deleting files they do not own; it does not automatically delete old files.

96
MCQmedium

A Linux administrator needs to create an ext4 filesystem on the second partition of the third SCSI disk, /dev/sdc2. After running mkfs.ext4 /dev/sdc2, the command completes successfully. Which additional step is required before the filesystem can be mounted and used?

A.Create a mount point and mount the filesystem.
B.Run e2fsck /dev/sdc2 to initialize the journal.
C.Add an entry to /etc/fstab to make the filesystem usable immediately.
D.Run partprobe /dev/sdc to update the kernel partition table.
AnswerA

After mkfs.ext4 successfully creates the filesystem, it must be mounted to a directory (mount point) to be accessible. The administrator should create a directory such as /mnt/data and then run mount /dev/sdc2 /mnt/data. Without mounting, the filesystem is not part of the directory tree and cannot be used.

Why this answer

Creating a filesystem with mkfs.ext4 only writes the filesystem metadata and structures onto the partition. To access the filesystem, it must be mounted to a directory in the existing directory tree. The administrator must create a mount point and use the mount command.

Without mounting, the filesystem remains inaccessible to users and applications.

Exam trap

The trap here is assuming that creating a filesystem automatically makes it available, or that editing /etc/fstab mounts it immediately.

97
MCQeasy

You are a junior administrator for a company that uses a standard disk image for all Linux servers. The image is based on CentOS 7. You need to ensure that new servers automatically install all available security updates during the first boot. You plan to run a command in a startup script. Which command should you use?

A.yum check-update
B.yum install yum-cron
C.yum update -y
D.apt-get upgrade -y
AnswerC

yum update -y resolves and installs all available package updates, including security errata, without interactive prompts, so running it from a first-boot startup script satisfies the requirement for unattended patching on the CentOS 7 image.

Why this answer

`yum update -y` installs all available updates, including security updates, without prompting for confirmation. On CentOS 7, this command updates all packages to their latest versions, which encompasses security patches. Running this in a startup script ensures that security updates are applied automatically on first boot.

Exam trap

The trap here is that candidates may confuse the command for listing updates (`check-update`) with the command for installing them, or mistakenly apply a Debian-based command (`apt-get`) to a Red Hat-based system like CentOS 7.

How to eliminate wrong answers

Option A is wrong because `yum check-update` only lists available updates without installing any, so it would not apply security updates. Option B is wrong because `yum install yum-cron` installs the yum-cron package, which is used for automatic periodic updates, but does not itself install updates immediately; it requires configuration and is not a one-time command for first boot. Option D is wrong because `apt-get upgrade -y` is a Debian/Ubuntu package manager command, not applicable to CentOS 7 which uses yum (or dnf in later versions).

98
MCQeasy

Which command lists all installed packages on a Debian-based system by querying the dpkg database?

A.apt-cache search .
B.dpkg -L
C.dpkg --get-selections
D.apt-show-versions
AnswerC

`dpkg --get-selections` reads the local dpkg status database directly, printing every package with its selection state (install, hold, deinstall). This satisfies the stem's requirement to list all installed packages by querying dpkg, unlike `apt list --installed`, which consults APT's extended states rather than the dpkg database itself.

Why this answer

`dpkg --get-selections` queries the dpkg database directly and outputs a list of all installed packages along with their installation state (e.g., 'install'). This command does not rely on remote repositories or cache files, making it a reliable method for listing installed packages on a Debian-based system.

Exam trap

The trap here is that candidates confuse `dpkg -L` (which lists files for a specific package) with a command that lists all installed packages, or they assume `apt-cache search .` shows only installed packages when it actually queries the entire repository cache.

How to eliminate wrong answers

Option A is wrong because `apt-cache search .` searches the APT package cache for packages matching a pattern (the dot matches any character), but it lists all available packages in the repositories, not just those installed. Option B is wrong because `dpkg -L` lists files installed by a specific package (e.g., `dpkg -L bash`), not all installed packages; it requires a package name as an argument. Option D is wrong because `apt-show-versions` is not a standard Debian command; the correct tool for showing installed package versions is `apt list --installed` or `dpkg -l`, and `apt-show-versions` is a third-party script that may not be present by default.

99
MCQeasy

A systems administrator downloads a .deb package file but it fails to install due to unmet dependencies. Which command sequence should be used to resolve the dependencies and complete the installation?

A.apt-get install -f
B.dpkg -i package.deb; apt-get install -f
C.dpkg --configure -a
D.apt-get upgrade
AnswerB

`dpkg -i` installs the local .deb but leaves dependencies unresolved, so `apt-get install -f` then reads the package database, fetches the missing dependencies from configured repositories and configures everything. This two-step sequence satisfies the stem's unmet-dependency constraint, which `dpkg` alone cannot fix.

Why this answer

When a .deb package fails to install due to unmet dependencies, `dpkg -i package.deb` installs the package but leaves dependencies unresolved. Running `apt-get install -f` (or `apt install -f`) then fixes broken dependencies by downloading and installing any missing packages from the configured repositories. This two-step sequence is the standard method for resolving dependency issues after a direct dpkg installation.

Exam trap

The trap here is that candidates assume `apt-get install -f` alone can install the .deb package, but it only fixes dependencies and does not process the original .deb file, so the package must first be installed (even partially) with `dpkg -i`.

How to eliminate wrong answers

Option A is wrong because `apt-get install -f` alone only fixes broken dependencies; it does not install the original .deb package, so the package remains uninstalled. Option C is wrong because `dpkg --configure -a` only reconfigures partially installed or unpacked packages, but it does not download or install missing dependencies from repositories. Option D is wrong because `apt-get upgrade` upgrades all installed packages to their latest versions and does not address unmet dependencies for a specific .deb package that was never fully installed.

100
Multi-Selecteasy

Which three files are essential for network configuration and name resolution on a typical Linux system? (Choose three.)

Select 3 answers
A./etc/network/interfaces
B./etc/hosts
C./etc/sysctl.conf
D./etc/nsswitch.conf
E./etc/resolv.conf
AnswersB, D, E

Maps hostnames to IP addresses locally.

Why this answer

The `/etc/hosts` file provides static hostname-to-IP address mapping, allowing name resolution before DNS is queried. It is essential for local network configuration and fallback resolution, as defined by RFC 952 and the glibc Name Service Switch (NSS) framework.

Exam trap

The trap here is that candidates often confuse distribution-specific network configuration files (like `/etc/network/interfaces`) with essential system-wide name resolution files, leading them to select options that are not universally required across all Linux distributions.

101
MCQmedium

Refer to the exhibit. The system administrator notices the /var/log partition is nearly full. The syslog file is 2GB. Which command will safely reduce the size of this log file without stopping the logging daemon?

A.cp /dev/null /var/log/syslog
B.rm /var/log/syslog && touch /var/log/syslog
C.> /var/log/syslog
D.mv /var/log/syslog /var/log/syslog.old
AnswerC

The shell redirection operator truncates the file to zero bytes in place, preserving the inode and open file descriptor, so syslogd continues writing without restart. That satisfies the stem's requirement to reduce the 2 GB file safely without stopping the logging daemon.

Why this answer

Using the shell redirection operator `> /var/log/syslog` truncates the file to zero length without deleting or closing its file descriptor. The syslog daemon (rsyslogd or syslogd) continues writing to the same inode, so no service interruption occurs. This is the safest method to free disk space while maintaining continuous logging.

Exam trap

The trap here is that candidates confuse truncating a file with deleting or moving it, not realizing that the logging daemon holds an open file descriptor tied to the inode, so only in-place truncation preserves continuous logging without a restart.

How to eliminate wrong answers

Option A is wrong because `cp /dev/null /var/log/syslog` replaces the file with a new inode, which causes the logging daemon to lose its file handle and stop writing until restarted or signaled. Option B is wrong because `rm` followed by `touch` also creates a new inode, breaking the daemon's open file descriptor and requiring a restart or SIGHUP to resume logging. Option D is wrong because `mv` renames the file, but the daemon still holds the old inode; the renamed file remains open and continues to grow, so disk space is not freed until the daemon is restarted or the old file is deleted.

102
MCQeasy

An administrator wants to run a shell script every day at 2:00 AM. Which command should be used to edit the user's personal crontab?

A.crontab -l
B.crontab -e
C.at 2:00 AM
D.vi /var/spool/cron/crontabs/username
AnswerB

crontab -e opens the invoking user's personal crontab in the default editor, letting the administrator add a 0 2 * * * schedule. It edits only that user's own table, matching the requirement for a personal crontab rather than a system-wide file.

Why this answer

The correct command to edit a user's personal crontab is `crontab -e`. This invokes the default text editor (as defined by the EDITOR or VISUAL environment variable) on the user's crontab file, ensuring proper syntax validation and locking to prevent concurrent edits. It is the standard and recommended way to modify cron jobs for the current user.

Exam trap

The trap here is that candidates may think they can directly edit the crontab file in `/var/spool/cron/` with `vi`, but the LPIC-1 exam expects you to know that only the `crontab` command should be used to safely modify user crontabs to avoid syntax errors and file corruption.

How to eliminate wrong answers

Option A is wrong because `crontab -l` lists the current user's crontab entries to standard output, it does not open an editor for modifications. Option C is wrong because `at 2:00 AM` is used for scheduling a one-time job at a specific time, not for recurring daily execution at 2:00 AM; `at` does not edit crontab files. Option D is wrong because directly editing the file `/var/spool/cron/crontabs/username` (or `/var/spool/cron/username` on some systems) bypasses the `crontab` command's syntax checking and locking mechanisms, which can lead to corruption or invalid entries; the `crontab` command should always be used to safely modify these files.

103
MCQeasy

An administrator added a new APT repository to sources.list. Which command must be run to make the system aware of the packages from that repository?

A.apt-get upgrade
B.apt upgrade
C.apt-cache search
D.apt update
AnswerD

`apt update` refreshes the local package index from all configured sources, including the newly added APT repository in sources.list. This satisfies the stem's requirement to make the system aware of the repository's available packages. Without this index refresh, `apt install` cannot see or resolve packages from that source.

Why this answer

After adding a new APT repository to sources.list, you must run 'apt update' (or 'apt-get update') to refresh the local package index from all configured repositories. This command downloads the latest package lists from the repository's Release and Packages files, making the system aware of available packages and their versions. Without this step, APT will not know about the new repository's packages, and subsequent install or upgrade commands will fail to find them.

Exam trap

The trap here is that candidates confuse 'update' (refreshing package lists) with 'upgrade' (installing newer versions of installed packages), leading them to choose 'apt upgrade' or 'apt-get upgrade' thinking it will also fetch new repository data.

How to eliminate wrong answers

Option A is wrong because 'apt-get upgrade' installs newer versions of already-installed packages based on the current package index; it does not refresh the index itself, so it cannot make the system aware of new repository packages. Option B is wrong because 'apt upgrade' is functionally identical to 'apt-get upgrade' (it upgrades installed packages) and does not update the package cache from repositories. Option C is wrong because 'apt-cache search' queries the local package index for package names or descriptions; it does not update the index, so it will not find packages from a newly added repository until the index is refreshed.

104
MCQmedium

A Linux workstation fails to boot and drops to a GRUB prompt. The administrator needs to inspect the available disks and partitions from within the GRUB environment before attempting recovery. Which command lists block devices and partitions recognized by GRUB?

A.ls
B.fdisk -l
C.parted -l
D.lsblk
AnswerA

In the GRUB shell, ls lists devices and partitions that GRUB recognizes, such as (hd0) and (hd0,gpt1). It is the GRUB-native way to inspect available disks and partitions before setting root and loading the kernel, making it the correct tool for this recovery step.

Why this answer

The GRUB shell provides its own command set, and ls enumerates devices and partitions that GRUB can see, such as (hd0,gpt1). Userspace tools like lsblk, fdisk, and parted are not available in that environment. Using ls lets the administrator identify the correct root device before loading the kernel or reinstalling the bootloader.

Exam trap

The trap here is assuming familiar Linux disk utilities work inside the GRUB shell, when GRUB only supports its own built-in commands such as ls.

105
MCQmedium

An administrator needs to copy a directory hierarchy from one server to another over SSH, preserving permissions, ownership, and timestamps. Which command is most appropriate?

A.cp -a /source /mnt/remote
B.tar cf - /source | ssh user@dest "tar xf - -C /target"
C.scp -rp /source user@dest:/target
D.rsync -avz /source user@dest:/target
AnswerB

Preserves all metadata and works over SSH.

Why this answer

It uses `tar` to create an archive of the source directory, pipes it over SSH, and extracts it on the remote server with `tar xf - -C /target`. This method preserves all file metadata (permissions, ownership, timestamps) because `tar` captures and restores these attributes by default, and the pipe over SSH transfers the raw archive without any transformation. Unlike `scp` or `rsync` (without root privileges), this approach can preserve ownership even when the user is not root, as long as the remote `tar` runs with appropriate privileges.

Exam trap

The trap here is that candidates often choose `rsync -avz` (Option D) because it is commonly used for backups, but they overlook that preserving ownership over SSH requires root privileges and the `--numeric-ids` flag, which is not specified in the option, making `tar` the more reliable choice for this specific requirement.

How to eliminate wrong answers

Option A is wrong because `cp -a /source /mnt/remote` assumes the remote directory is mounted locally (e.g., via NFS or SSHFS), not over SSH directly; it does not use SSH for transport and would fail if the remote server is not mounted. Option C is wrong because `scp -rp` does not preserve ownership (it resets ownership to the connecting user) and may not preserve all timestamps in all cases; it also lacks the ability to preserve extended attributes or ACLs that `tar` can handle. Option D is wrong because `rsync -avz` without `--numeric-ids` and running as root on both sides will not preserve ownership (it maps UIDs/GIDs based on the remote user's permissions), and it may alter timestamps if the remote filesystem does not support nanosecond precision; additionally, `rsync` over SSH requires the remote user to have write permissions to the target, and ownership preservation typically requires root privileges.

106
Multi-Selecthard

Which TWO commands can be used to display the current firewall rules in a system using nftables? (Choose two.)

Select 2 answers
A.systemctl status nftables
B.iptables -L -n
C.nft list ruleset
D.nft list table inet filter
E.firewall-cmd --list-all
AnswersC, D

The nft list ruleset command dumps every table, chain and rule in the current nftables ruleset, giving a complete view of active firewall configuration. It directly satisfies the stem's requirement to display current firewall rules without naming a specific table or family.

Why this answer

`nft list ruleset` is the primary command in nftables to display the entire ruleset, including all tables, chains, and rules, regardless of the address family. Option D is also correct because `nft list table inet filter` specifically displays the rules within the 'filter' table of the 'inet' family, which is a valid way to show a subset of the firewall rules. Both commands rely on the nftables framework, which is the modern replacement for iptables on Linux.

Exam trap

The trap here is that candidates may confuse the legacy iptables command (`iptables -L -n`) with nftables, or assume that `systemctl status nftables` shows rules, when in fact it only shows the service's runtime state.

107
Drag & Dropmedium

Arrange the steps to schedule a cron job that runs a script every day at 2 AM.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Crontab -e opens the user's cron file; the syntax minute hour day month weekday command must be correct.

108
MCQmedium

A shell script must exit immediately with a non-zero status if any command fails, and it must also treat an unset variable as an error. Which line should be placed at the top of the script?

A.set -e -u
B.set -u -x
C.set -o errexit -o nounset -o xtrace
D.set -e -x
AnswerA

The -e option makes the shell exit as soon as a command returns non-zero, and -u makes referencing an unset variable an error that triggers that exit. Together they satisfy both stated requirements in a single line. This combination is the conventional safety header for scripts that must fail fast rather than continue with bad state.

Why this answer

The fail-fast requirement maps to errexit (-e) and the unset-variable requirement maps to nounset (-u), so 'set -e -u' is the precise answer. Adding xtrace brings noisy tracing that was not asked for, and omitting either -e or -u leaves one requirement unmet. Short option letters and their long -o equivalents name the same behaviours, so the combined short form is the cleanest expression.

Exam trap

The trap here is assuming that -x and -u are interchangeable safety options, when -x only traces commands and provides no error handling at all.

109
MCQmedium

A Linux administrator is troubleshooting a server that cannot resolve external hostnames. The server has a static IP address and can ping 8.8.8.8 successfully. The administrator checks /etc/resolv.conf and finds only 'nameserver 127.0.0.53'. Which command will best help determine the actual DNS servers being used and the resolution path?

A.cat /etc/nsswitch.conf
B.resolvectl status
C.nslookup google.com
D.dig google.com
AnswerB

resolvectl status displays the current DNS servers, DNS domains, and per-interface configuration managed by systemd-resolved. It reveals the actual upstream DNS servers and whether the stub resolver is functioning correctly, which is essential for diagnosing why external hostnames fail to resolve.

Why this answer

The resolvectl status command provides detailed information about the current DNS servers and resolution configuration for all interfaces, which is crucial for diagnosing why external hostnames cannot be resolved despite network connectivity.

Exam trap

The trap here is assuming that /etc/resolv.conf contains the actual DNS servers, but with systemd-resolved it only shows the stub address, so tools like resolvectl are needed to see the real servers.

110
Matchingmedium

Match each package manager to its associated distribution family.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Debian, Ubuntu

RHEL, CentOS 7

Fedora, RHEL 8+

openSUSE

Arch Linux

Why these pairings

Common package managers and their distribution families: APT (Debian), YUM/DNF (Red Hat), ZYpp (SUSE), pacman (Arch). Distractor options swap these associations.

111
MCQmedium

Which directory under the root filesystem is defined by FHS as containing variable data that may change in size, such as logs and spools?

A./opt
B./var
C./run
D./tmp
AnswerB

/var holds variable data such as logs, spools and mail queues, which grow unpredictably at runtime. FHS reserves it precisely for files whose size changes during normal operation, unlike /usr for static, shareable content. This satisfies the stem's requirement for variable data that may change in size.

Why this answer

The Filesystem Hierarchy Standard (FHS) defines /var as the directory for variable data that changes in size during normal system operation, including log files (e.g., /var/log), spool directories (e.g., /var/spool/mail), and temporary files that persist across reboots. This is distinct from /tmp, which is cleared on reboot, and /run, which holds runtime variable data that is volatile and cleared at boot.

Exam trap

The trap here is that candidates confuse /var with /run or /tmp because both hold variable data, but the FHS specifically assigns persistent variable data (logs, spools) to /var, while /run is for volatile runtime state and /tmp for temporary files that may be cleared on reboot.

How to eliminate wrong answers

Option A is wrong because /opt is reserved for the installation of add-on application software packages, not for variable data like logs or spools. Option C is wrong because /run contains runtime variable data (e.g., PID files, sockets) that is cleared at system boot, whereas /var retains data across reboots. Option D is wrong because /tmp is for temporary files that may be deleted on reboot and is not intended for persistent variable data like logs or spools.

112
MCQeasy

A technician needs to identify the hardware installed on a Linux workstation. The technician runs a command that prints a hierarchical tree of PCI devices showing vendor and device IDs, along with the kernel driver in use. Which command was most likely executed?

A.dmidecode -t memory
B.lsblk -f
C.lsusb -t
D.lspci -k
AnswerD

lspci -k lists PCI devices and, for each, shows the kernel driver and kernel modules in use. This matches the requirement for a hierarchical view of PCI devices with vendor and device IDs and driver information. It reads from /sys and /proc/bus/pci, making it the standard tool for PCI hardware inspection.

Why this answer

The lspci utility enumerates PCI devices, and its -k option adds the kernel driver and modules handling each device. That combination directly satisfies the need to see a PCI device tree with vendor/device IDs and driver information. Storage, USB, and DMI tools cover other hardware classes and do not provide the required PCI driver mapping.

Exam trap

The trap here is confusing tools that enumerate different buses or hardware classes, such as lsusb or lsblk, with the PCI-specific lspci command and its driver-listing option.

113
MCQmedium

A system administrator writes a script that extracts data from a CSV file and inserts it into a database. The script works correctly when run manually but fails when executed by cron. Which environment variable is most likely causing the issue?

A.SHELL
B.LANG
C.HOME
D.PATH
AnswerD

Cron executes jobs with a minimal environment, so PATH typically omits directories available in an interactive shell. Commands resolving manually then fail under cron because the binary cannot be located, unless absolute paths or an explicit PATH are set.

Why this answer

When a script runs manually, the user's interactive shell inherits a fully populated PATH environment variable that includes directories like /usr/local/bin, /usr/bin, and possibly custom script directories. Cron jobs, however, execute with a minimal environment, and the default PATH for cron is often just /usr/bin:/bin. If the script relies on commands (e.g., mysql, psql, or custom scripts) located outside these directories, cron will fail with a 'command not found' error.

Setting the full PATH explicitly inside the script or in the crontab file resolves the issue.

Exam trap

The trap here is that candidates often assume the script's failure is due to a missing HOME or SHELL variable, but the most frequent cron-related issue is the restricted PATH environment, which prevents the script from locating executables.

How to eliminate wrong answers

Option A is wrong because SHELL defines the shell binary used to interpret the script (e.g., /bin/bash), but cron already uses the user's default shell from /etc/passwd; a mismatch would cause syntax errors, not a missing command failure. Option B is wrong because LANG affects locale settings like character encoding and sorting order, which could cause data corruption or sorting issues but not a complete failure to execute commands. Option C is wrong because HOME defines the user's home directory; while some scripts may rely on relative paths or config files in ~, the most common cron failure is due to a truncated PATH, not a missing HOME.

114
MCQmedium

An administrator wants to allow user 'john' to run all commands as root without a password. Which sudoers entry accomplishes this?

A.john ALL=(ALL) NOPASSWD: ALL
B.john ALL=NOPASSWD: /bin/su
C.john ALL=(ALL) ALL
D.john ALL=(ALL) PASSWD: ALL
AnswerA

The entry john ALL=(ALL) NOPASSWD: ALL grants john sudo rights on every host, as every user, for every command, with the NOPASSWD tag suppressing the password prompt. This precisely matches the requirement of passwordless root command execution.

Why this answer

The sudoers entry 'john ALL=(ALL) NOPASSWD: ALL' grants user 'john' permission to run any command as any user (including root) from any host, and the NOPASSWD tag overrides the default password requirement, allowing passwordless execution. This matches the requirement precisely.

Exam trap

The trap here is that candidates often confuse the absence of a TAG (which defaults to requiring a password) with passwordless access, or they mistakenly think that specifying 'ALL' without the NOPASSWD tag implies no password is needed.

How to eliminate wrong answers

Option B is wrong because it restricts john to only running '/bin/su' without a password, not all commands as root. Option C is wrong because it omits the NOPASSWD tag, so john would still be prompted for a password before executing commands as root. Option D is wrong because it explicitly specifies PASSWD: ALL, which forces password authentication, the opposite of the requirement.

115
MCQeasy

A technician is preparing a USB stick that must be readable by both Linux and Windows systems without installing extra drivers. Which filesystem should be created on the stick?

A.ext4
B.XFS
C.Btrfs
D.exFAT
AnswerD

exFAT is supported natively by Windows and by modern Linux kernels through the exfat driver, and it has no 4 GB per-file limit like FAT32. It stores no Unix permissions, which is acceptable for a portable data stick. This makes it the practical choice when a device must move between Linux and Windows without installing additional software on either side.

Why this answer

A USB stick shared between Linux and Windows needs a filesystem both operating systems understand out of the box. exFAT satisfies this: Windows supports it natively, current Linux kernels include an exFAT driver, and unlike FAT32 it does not impose a 4 GB file size ceiling. The Linux-native filesystems ext4, XFS, and Btrfs all require extra software on Windows, so they fail the cross-platform condition.

Exam trap

The trap here is reaching for a feature-rich Linux filesystem like ext4 or Btrfs when portability to Windows, not advanced features, is the actual requirement.

116
MCQmedium

An administrator notices the system clock is drifting. Which command can be used to enable automatic time synchronization using NTP on a system with systemd?

A.ntpdate pool.ntp.org
B.timedatectl set-ntp yes
C.systemctl start ntpd
D.date --set
AnswerB

timedatectl set-ntp yes enables systemd-timesyncd, which starts the NTP synchronisation service and keeps the clock aligned automatically. This directly satisfies the requirement for automatic time synchronisation on a systemd host, correcting the drift without manual intervention.

Why this answer

`timedatectl set-ntp yes` enables automatic time synchronization via NTP on systems using systemd. This command configures the `systemd-timesyncd` service, which is the default NTP client for systemd-based distributions, to synchronize the system clock with remote NTP servers. It is the standard, modern method for managing NTP settings in such environments.

Exam trap

The trap here is that candidates often confuse one-time synchronization commands (like `ntpdate` or `date --set`) with the persistent enabling of automatic NTP synchronization, or they assume starting the `ntpd` service alone is sufficient without using `timedatectl` to manage systemd's time synchronization framework.

How to eliminate wrong answers

Option A is wrong because `ntpdate pool.ntp.org` performs a one-time manual synchronization of the system clock, not enabling automatic time synchronization; it is also deprecated in favor of `timedatectl` and `ntpd` or `chronyd`. Option C is wrong because `systemctl start ntpd` starts the traditional NTP daemon, but this command alone does not enable automatic synchronization at boot or integrate with systemd's timedatectl mechanism; it also requires the `ntpd` service to be installed and configured separately. Option D is wrong because `date --set` manually sets the system clock to a specified value, which does not enable automatic synchronization and is a temporary, non-persistent change.

117
MCQhard

A developer needs to ensure a bash script exits immediately if any command fails, and also prints each command before executing it. Which set of shell options should be used at the beginning of the script?

A.set -ex
B.set -e
C.set -vx
D.set -ux
AnswerA

`set -e` makes the shell exit immediately when any command returns a non-zero status, satisfying the fail-fast requirement. `set -x` enables tracing, printing each command with its expanded arguments to stderr before execution. Combined as `set -ex`, both constraints in the stem are met within a single statement.

Why this answer

`set -ex` combines two essential shell options: `-e` (errexit) causes the script to exit immediately if any command returns a non-zero exit status, and `-x` (xtrace) prints each command (after expansion) to stderr before executing it. This is the standard way to achieve both behaviors in a single line, as required by the question.

Exam trap

The trap here is that candidates often confuse `-v` (verbose, which prints input lines as read) with `-x` (xtrace, which prints commands before execution), or forget that `-e` is required for exit-on-error, leading them to pick `set -vx` or `set -ux` instead of the correct `set -ex`.

How to eliminate wrong answers

Option B is wrong because `set -e` only enables exit-on-error but does not print commands before execution, missing the requirement to print each command. Option C is wrong because `set -vx` enables verbose mode (`-v`, which prints shell input lines as they are read) and xtrace (`-x`), but verbose mode does not print commands before execution in the same way as `-x`; the question specifically asks for printing each command before executing it, which is `-x`'s behavior, and `-v` is redundant or incorrect for this purpose. Option D is wrong because `set -ux` enables nounset (`-u`, which treats unset variables as an error) and xtrace (`-x`), but does not enable exit-on-error (`-e`), so the script will not exit immediately if a command fails.

118
Multi-Selecthard

Which THREE locations are used to configure package repositories on a typical Linux system? (Choose three.)

Select 3 answers
A./etc/zypp/repos.d/
B./etc/apt.conf.d/
C./etc/yum.repos.d/
D./etc/pacman.d/
E./etc/apt/sources.list
AnswersA, C, E

Repository directory for Zypper.

Why this answer

/etc/zypp/repos.d/ is the directory where SUSE's Zypper package manager stores repository configuration files (each .repo file defines a repository's URL, GPG keys, and other settings). This is the standard location for configuring repositories on openSUSE and SUSE Linux Enterprise systems.

Exam trap

The trap here is that candidates confuse the configuration directory for APT (/etc/apt.conf.d/) with the actual repository source location (/etc/apt/sources.list), or assume that all package managers use a repos.d subdirectory pattern, when in fact pacman uses a single configuration file.

119
MCQeasy

A system administrator needs to determine which package owns the file /usr/bin/htop on a Debian-based server. Which command should the administrator use?

A.apt-file search /usr/bin/htop
B.dpkg -L htop
C.dpkg -S /usr/bin/htop
D.rpm -qf /usr/bin/htop
AnswerC

dpkg -S (or --search) searches the installed packages database for the package that owns the specified file. It directly answers the question by returning the package name that contains /usr/bin/htop, making it the correct and efficient tool for this task.

Why this answer

The correct command is dpkg -S, which searches the dpkg database for the package that owns a given file. This is the standard method on Debian-based systems to map a file to its package. The other options either list files from a known package, search repository indexes, or are for a different package management system.

Exam trap

The trap here is confusing dpkg -L (list files of a package) with dpkg -S (search for package owning a file), as both deal with file-package relationships but in opposite directions.

120
MCQmedium

A system is not logging messages to /var/log/syslog. Which command should an administrator use first to diagnose the issue?

A.tail -f /var/log/syslog
B.logger test
C.ps aux | grep syslog
D.systemctl status rsyslog
AnswerD

systemctl status rsyslog reveals whether the rsyslog unit is active, failed or masked, and shows recent journal output explaining why messages stopped reaching /var/log/syslog. This checks the daemon responsible for writing that file before investigating configuration or permissions.

Why this answer

The first step in diagnosing why messages are not appearing in /var/log/syslog is to verify that the rsyslog service is running and active. The 'systemctl status rsyslog' command shows the current service state, recent logs, and any errors that might prevent logging. Without confirming the service status, other diagnostic steps may be misleading.

Exam trap

The trap here is that candidates often jump to testing the logging pipeline (with 'logger') or checking for a process by name, instead of first verifying the service status with systemctl, which is the systematic and most efficient diagnostic step.

How to eliminate wrong answers

Option A is wrong because 'tail -f /var/log/syslog' only monitors the log file for new entries; if no messages are being written, it will simply hang and provide no diagnostic information about why logging has stopped. Option B is wrong because 'logger test' sends a test message to the syslog system, but if the service is not running or misconfigured, the message will not be logged and the command gives no feedback about the underlying issue. Option C is wrong because 'ps aux | grep syslog' only checks for a process named 'syslog' in the process list, but modern systems use rsyslog or syslog-ng, and this command may miss the actual daemon or show unrelated processes, failing to reveal service status or configuration errors.

121
MCQmedium

A Linux system has two network interfaces: eth0 and eth1. The administrator wants to bond them for increased throughput. Which kernel module is required for bonding?

A.aggregation
B.bonding
C.team
D.bond
AnswerB

The bonding kernel module provides the driver that aggregates eth0 and eth1 into a single logical interface, enabling the throughput increase the administrator wants. Loading it is the prerequisite before any bond configuration can be applied.

Why this answer

The bonding driver in Linux allows multiple network interfaces to be aggregated into a single logical interface for increased throughput or redundancy. The correct kernel module is named 'bonding' (loaded via modprobe bonding or compiled into the kernel), which implements the IEEE 802.3ad Link Aggregation standard and other bonding modes. Option B is correct because 'bonding' is the exact module name used in the Linux kernel.

Exam trap

The trap here is that candidates confuse the interface name (bond0) with the kernel module name (bonding), or think 'team' is a synonym for bonding, when in fact they are separate technologies with different kernel modules.

How to eliminate wrong answers

Option A is wrong because 'aggregation' is a generic term for combining links, not a specific Linux kernel module; the actual module is 'bonding'. Option C is wrong because 'team' refers to the libteam project, which is a separate user-space-based teaming solution that uses the 'team' kernel module, not the standard bonding driver. Option D is wrong because 'bond' is a common abbreviation but not the exact kernel module name; the module is loaded as 'bonding' (e.g., modprobe bonding), and the resulting interface is named bond0, bond1, etc.

122
MCQmedium

An administrator runs `mount /dev/sdc1 /mnt/data` and receives the error "mount: /mnt/data: unknown filesystem type 'ntfs'." The partition contains an NTFS volume that must be mounted read-write on a Linux server. Which action resolves the issue?

A.Mount with the -o loop option to force filesystem detection
B.Install the ntfs-3g package and mount with -t ntfs-3g
C.Run mkfs.ntfs on /dev/sdc1 to initialize NTFS support
D.Add the ntfs module to /etc/modules and reboot
AnswerB

The error indicates the kernel has no in-kernel driver registered for the ntfs type. The ntfs-3g package provides a FUSE-based userspace driver that supports reliable read-write access, and mounting explicitly with -t ntfs-3g selects it. This directly supplies the missing filesystem support and satisfies the read-write requirement without altering the volume.

Why this answer

The unknown filesystem type message means no driver is registered for NTFS. Modern Linux systems rely on the userspace ntfs-3g driver from the package of the same name for dependable read-write access; installing it and mounting with -t ntfs-3g supplies that support. Reformatting destroys data, loading a limited legacy module does not grant write access, and loop mounting is irrelevant to a real partition.

Exam trap

The trap here is assuming the legacy in-kernel ntfs module is sufficient, when it offers at best limited read support and not the reliable read-write access the scenario demands.

123
Multi-Selecthard

A system administrator is troubleshooting a package dependency issue on a Debian system. Which three commands can be used to display dependency information for a package? (Choose three.)

Select 3 answers
A.`dpkg --info curl.deb`
B.`apt show curl`
C.`apt-cache depends curl`
D.`dpkg -s curl`
E.`apt-get check`
AnswersB, C, D

Displays package details including dependencies.

Why this answer

The `apt show curl` command displays detailed information about the curl package, including its dependencies, from the APT repository metadata. This is a standard way to view dependency information on Debian-based systems.

Exam trap

The trap here is that candidates may think `dpkg --info` or `apt-get check` are appropriate for displaying dependencies, but `dpkg --info` works on .deb files and `apt-get check` only verifies the database integrity, not specific package dependencies.

124
Multi-Selecthard

Which THREE are valid fields in a GRUB 2 configuration file (grub.cfg) generated by update-grub? (Choose three.)

Select 3 answers
A.set root
B.password
C.chainloader
D.linux
E.menuentry
AnswersA, D, E

This sets the device for the kernel and initrd.

Why this answer

A is correct because 'set root' is a valid GRUB 2 command used in grub.cfg to specify the root device (e.g., 'set root=(hd0,msdos1)') from which GRUB loads kernel and initrd images. This directive is automatically generated by update-grub based on the system's partition layout.

Exam trap

The trap here is that candidates confuse GRUB Legacy syntax (like 'password' or 'chainloader' being common in manual entries) with the auto-generated GRUB 2 configuration, which only includes 'set root', 'linux', and 'menuentry' as core directives produced by update-grub.

125
Drag & Dropmedium

Arrange the steps to troubleshoot a service that fails to start.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Troubleshooting starts with checking status and logs, then examining config files, fixing, and restarting.

126
MCQhard

An administrator ran 'dnf update' and a critical application broke. The administrator wants to undo the last transaction and return to previous state. Which command should be used?

A.dnf undo last
B.dnf rollback
C.yum rollback
D.dnf history undo last
AnswerD

`dnf history undo last` reverses the most recent transaction by replaying its recorded actions in reverse, reinstalling the previous package versions and removing newly added ones. This directly satisfies the requirement to return the system to its pre-update state after the broken `dnf update`.

Why this answer

The correct command is 'dnf history undo last' because DNF maintains a transaction history that can be reverted. The 'undo' subcommand reverses the specified transaction (in this case, the last one) by applying the inverse operations, restoring packages to their previous state. This is the standard way to roll back a DNF transaction without affecting unrelated changes.

Exam trap

The trap here is that candidates confuse 'undo' with 'rollback' or assume DNF uses the same syntax as YUM, leading them to pick 'dnf rollback' or 'yum rollback' instead of the correct 'dnf history undo last'.

How to eliminate wrong answers

Option A is wrong because 'dnf undo last' is not a valid DNF command; DNF requires the 'history' subcommand before 'undo'. Option B is wrong because 'dnf rollback' does not exist; DNF uses 'history undo' or 'history rollback' (the latter reverts to a specific transaction ID, not the last one). Option C is wrong because 'yum rollback' is a legacy YUM command that is not available in DNF; DNF replaced YUM and uses 'dnf history' for transaction management.

127
MCQhard

A Linux administrator needs to change the permissions of a directory named /shared so that only the owner can read, write, and execute, while group members can read and execute but not write, and others have no access. The administrator also wants any new files created inside /shared to inherit the group ownership of /shared. Which command sequence will achieve this?

A.chmod 750 /shared && chmod u+s /shared
B.chmod 755 /shared && chmod g+s /shared
C.chmod 750 /shared && chmod g+s /shared
D.chmod 640 /shared && chmod g+s /shared
AnswerC

The chmod 750 sets permissions to rwxr-x---, giving the owner full control, group read and execute, and no access to others. The chmod g+s sets the setgid bit on the directory, causing new files and subdirectories to inherit the group ownership of /shared. This combination meets both requirements.

Why this answer

Setting permissions to 750 restricts access appropriately: owner rwx, group rx, others none. The setgid bit on a directory ensures that new files and subdirectories inherit the directory's group ownership, which is essential for shared collaborative spaces. The combination of chmod 750 and chmod g+s achieves both the permission and group inheritance goals.

Exam trap

The trap here is confusing setuid and setgid on directories; setuid is ignored on directories, while setgid is used for group inheritance.

128
MCQeasy

An administrator needs to find all files in the /var/log directory that have been modified in the last 24 hours. Which command should be used?

A.find /var/log -ctime 0
B.find /var/log -mtime 0
C.find /var/log -atime 0
D.find /var/log -mmin 1440
AnswerB

The -mtime 0 predicate matches files whose data was modified less than 24 hours ago, since find counts in 24-hour periods and 0 covers the current partial day. This precisely satisfies the requirement to list recently modified files under /var/log.

Why this answer

The `find` command with `-mtime 0` searches for files whose data modification time is within the last 24 hours. The `-mtime` option uses a 24-hour period, and a value of 0 means modified less than 24 hours ago, which matches the requirement to find files modified in the last 24 hours in /var/log.

Exam trap

The trap here is that candidates confuse `-ctime` (inode change time) with `-mtime` (modification time), or mistakenly think `-atime` (access time) is relevant for modification, leading them to pick options that do not match the requirement for content modification.

How to eliminate wrong answers

Option A is wrong because `-ctime 0` checks the inode change time (ctime), which includes metadata changes like permission or ownership changes, not file content modification; this can return files that were not modified in terms of content. Option C is wrong because `-atime 0` checks the access time (atime), which is updated when a file is read, not when it is modified; this would include files that were simply accessed, not modified. Option D is wrong because `-mmin 1440` checks for files modified within the last 1440 minutes (exactly 24 hours), but the question asks for files modified in the last 24 hours, and `-mmin` uses a precise minute count, which is technically correct but less standard for this requirement; however, the primary issue is that the question expects `-mtime 0` as the standard approach, and `-mmin 1440` could miss files modified exactly 1440 minutes ago due to integer rounding behavior in `-mtime` vs `-mmin`.

129
Multi-Selecteasy

Which TWO commands can be used to display the current runlevel of a SysV init system?

Select 2 answers
A.init 3
B.who -r
C.telinit
D.runlevel
E.systemctl get-default
AnswersB, D

The who command with the -r flag queries the utmp database and prints the current runlevel together with the last boot time, reading the same SysV init state that runlevel reports. This directly satisfies the requirement to display the runlevel on a SysV init system.

Why this answer

Option B (who -r) is correct because the who command with the -r flag reads the /var/run/utmp file and prints the current runlevel along with the time it was last changed, making it a valid way to display the runlevel on a SysV init system. Option D (runlevel) is correct because the runlevel command reads /var/run/utmp and outputs the previous and current runlevel (e.g., 'N 3'), directly reporting the system's current runlevel. Option A (init 3) is incorrect because init 3 changes the runlevel to 3 rather than displaying the current one.

Option C (telinit) is incorrect because telinit is used to send control commands to init (such as changing runlevels), not to query the current runlevel. Option E (systemctl get-default) is incorrect because it is a systemd command that shows the default target, not the current runlevel of a SysV init system.

Exam trap

The trap here is that candidates confuse commands that change runlevels (like `init` or `telinit`) with those that display them, or mistakenly apply systemd commands like `systemctl get-default` to SysV init systems.

130
MCQmedium

An administrator wants to add a kernel parameter 'quiet splash' to the default boot entry. Which file should be edited?

A./etc/default/grub
B./etc/grub.d/00_header
C./etc/grub.conf
D./boot/grub/grub.cfg
AnswerA

Editing `/etc/default/grub` sets the `GRUB_CMDLINE_LINUX_DEFAULT` variable, which supplies kernel parameters to the default boot entry. This satisfies the requirement to add `quiet splash` persistently. After editing, run `update-grub` to regenerate `/boot/grub/grub.cfg`, since GRUB reads the generated configuration at boot, not this file directly.

Why this answer

The correct file to edit is /etc/default/grub because it is the main configuration file for GRUB 2 where kernel boot parameters like 'quiet splash' are defined in the GRUB_CMDLINE_LINUX_DEFAULT variable. After editing this file, the administrator must run update-grub (or grub-mkconfig) to regenerate the actual boot configuration file /boot/grub/grub.cfg.

Exam trap

The trap here is that candidates often confuse the auto-generated /boot/grub/grub.cfg (option D) with the source configuration file, or mistakenly think the legacy /etc/grub.conf (option C) is still used in GRUB 2 environments.

How to eliminate wrong answers

Option B is wrong because /etc/grub.d/00_header is a script that generates part of the GRUB 2 configuration, not a file where kernel parameters are directly set; editing it would be overwritten on updates and is not the intended method. Option C is wrong because /etc/grub.conf is a legacy file used by GRUB Legacy (version 0.97) and is not the standard location for GRUB 2 on modern Linux distributions. Option D is wrong because /boot/grub/grub.cfg is the auto-generated boot configuration file; editing it directly is discouraged as changes are overwritten by update-grub and it is not the source of truth for kernel parameters.

131
Multi-Selectmedium

A Linux administrator needs to configure a system to use a proxy server for HTTP and HTTPS traffic for all users. Which TWO environment variables should be set in a system-wide profile script to ensure that command-line tools like curl and wget use the proxy? (Choose two.)

Select 2 answers
A.no_proxy
B.all_proxy
C.ftp_proxy
D.http_proxy
E.https_proxy
AnswersD, E

The http_proxy environment variable specifies the proxy server for HTTP requests. Many command-line tools, including curl and wget, check this variable to determine the proxy for HTTP URLs. Setting it system-wide ensures all users and processes inherit the proxy configuration.

Why this answer

Setting http_proxy and https_proxy in a system-wide profile script ensures that command-line tools like curl and wget route HTTP and HTTPS traffic through the proxy. These variables are widely recognized and provide comprehensive coverage for web traffic.

Exam trap

The trap here is assuming that a single variable like all_proxy or ftp_proxy covers all web traffic, but HTTP and HTTPS require separate variables for reliable proxy configuration.

132
Multi-Selecthard

A Linux administrator is configuring a CentOS 7 server and needs to manage software packages using the native RPM toolset. The administrator wants to perform two tasks: (1) verify the integrity of an installed package against its original metadata, and (2) list all files installed by a specific package. Which TWO commands should the administrator use? (Choose two.)

Select 2 answers
A.rpm -q --changelog package_name
B.rpm -qi package_name
C.rpm -ql package_name
D.rpm -qf /path/to/file
E.rpm -V package_name
AnswersC, E

rpm -ql (or --query --list) lists all files that are installed by the specified package. This directly satisfies the second requirement to enumerate package contents. It queries the RPM database and outputs the full file paths.

Why this answer

The correct commands are rpm -V for verifying package integrity and rpm -ql for listing installed files. These directly address the two tasks: verification checks file attributes against the RPM database, and query list enumerates all files from a package. The other options provide different types of package information and do not fulfill the requirements.

Exam trap

The trap here is mixing up rpm query options: -V verifies, -ql lists files, -qi gives info, and -qf finds owner. Confusing these can lead to selecting commands that do not perform the needed tasks.

133
Drag & Dropmedium

Arrange the steps to configure a static IP address on a Linux system using the command line.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Static IP configuration requires editing the appropriate config file, then restarting networking to apply changes.

134
Multi-Selectmedium

A system administrator is troubleshooting a server that takes a long time to boot. The administrator wants to identify which systemd units are slowing down the boot process. Which TWO of the following commands can be used to analyze boot performance? (Choose two.)

Select 2 answers
A.systemd-analyze critical-chain
B.systemctl list-units --state=failed
C.journalctl -b -p err
D.systemd-analyze blame
E.dmesg | grep -i 'time'
AnswersA, D

systemd-analyze critical-chain displays a tree of units that are on the critical path to reaching the default target, highlighting dependencies that delay boot. It shows the time spent waiting for each unit in the chain, helping pinpoint bottlenecks in the boot sequence.

Why this answer

The systemd-analyze suite provides dedicated subcommands for boot performance. blame ranks units by initialization time, and critical-chain shows the dependency tree that determines total boot time. These tools directly measure and display timing data, unlike log inspection or unit state listing, which focus on errors or failures rather than duration.

Exam trap

The trap here is confusing error diagnosis tools with performance analysis tools, assuming that checking logs or failed units will reveal slow boot causes.

135
Multi-Selecteasy

Which TWO tools can be used to query DNS records? (Choose two.)

Select 2 answers
A.nslookup
B.ss
C.dig
D.ping
E.traceroute
AnswersA, C

Name server lookup, queries DNS.

Why this answer

A is correct because nslookup is a classic DNS query tool that sends DNS queries to name servers to resolve domain names to IP addresses or vice versa. It directly queries DNS records (A, AAAA, MX, CNAME, etc.) using the DNS protocol (UDP/TCP port 53).

Exam trap

The trap here is that candidates may confuse network diagnostic tools (ping, traceroute, ss) with DNS-specific utilities, assuming any tool that tests connectivity can also query DNS records.

136
MCQmedium

The system administrator wants to add a new swap partition on /dev/sdb2. After creating the partition, which command should be used to initialize it as swap?

A.mkfs.ext4 /dev/sdb2
B.fsck /dev/sdb2
C.mkswap /dev/sdb2
D.swapon /dev/sdb2
AnswerC

mkswap writes the swap signature and UUID onto /dev/sdb2, initialising the partition so the kernel can use it as swap space. This satisfies the requirement to prepare the newly created partition before swapon activates it or an /etc/fstab entry mounts it.

Why this answer

The `mkswap` command is specifically designed to initialize a partition or file as a swap area by writing a swap signature (UUID and swap superblock) to the device. After creating the partition, you must run `mkswap /dev/sdb2` to set it up for use as swap before activating it with `swapon`.

Exam trap

The trap here is that candidates often confuse `swapon` (which activates swap) with `mkswap` (which initializes it), mistakenly thinking `swapon` can both prepare and enable the swap area.

How to eliminate wrong answers

Option A is wrong because `mkfs.ext4` creates an ext4 filesystem, which is a standard data filesystem, not a swap area; using it would overwrite the partition with filesystem metadata, making it unusable as swap. Option B is wrong because `fsck` checks and repairs an existing filesystem, but it cannot initialize a partition as swap and would fail on a partition without a recognized filesystem. Option D is wrong because `swapon` activates an already-initialized swap area; it cannot initialize a partition that has not been set up with `mkswap` first.

137
MCQeasy

Which sed command will replace the first occurrence of 'foo' with 'bar' on each line of a file?

A.sed 's/foo/bar/g' file
B.sed 's/foo/bar/0' file
C.sed 's/foo/bar/2' file
D.sed 's/foo/bar/' file
AnswerD

The sed substitute command s/foo/bar/ replaces only the first match per line by default; the g flag is what makes it global. Applied to each line of the file, this expression swaps the initial 'foo' with 'bar' and leaves any later occurrences on that line untouched.

Why this answer

The default behavior of the `s` (substitute) command in sed is to replace only the first occurrence of the pattern on each line. Without a numeric flag, `sed 's/foo/bar/' file` replaces the first 'foo' on each line with 'bar'. The `g` flag would replace all occurrences, not just the first.

Exam trap

The trap here is that candidates often confuse the default behavior of sed's substitute command, assuming it replaces all occurrences unless told otherwise, and thus incorrectly choose the `g` flag option.

How to eliminate wrong answers

Option A is wrong because the `g` flag causes sed to replace all occurrences of 'foo' with 'bar' on each line, not just the first. Option B is wrong because sed does not support a `0` flag for the substitute command; the numeric flag must be a positive integer, and `0` is invalid or ignored. Option C is wrong because the `2` flag replaces the second occurrence of 'foo' on each line, not the first.

138
MCQeasy

An administrator wants to list all lines in a log file that do NOT contain the word 'ERROR'. Which command should be used?

A.grep -i 'ERROR' logfile
B.grep -w 'ERROR' logfile
C.grep -v 'ERROR' logfile
D.grep 'ERROR' logfile
AnswerC

grep -v inverts the match, printing every line that does not contain the pattern 'ERROR'. The pattern is treated as a basic regular expression, and unmatched lines pass through unchanged, which directly satisfies the requirement to list all non-matching lines from the log file.

Why this answer

The `-v` flag inverts the match, causing `grep` to output only lines that do NOT contain the pattern 'ERROR'. This is the standard way to exclude lines matching a pattern in a file.

Exam trap

The trap here is that candidates often confuse the `-v` invert-match flag with other common flags like `-i` (case-insensitive) or `-w` (whole-word), or simply forget that `grep` by default shows matching lines, not excluding them.

How to eliminate wrong answers

Option A is wrong because `-i` performs a case-insensitive search, which would still show lines containing 'ERROR' (or 'error', 'Error', etc.), not exclude them. Option B is wrong because `-w` matches whole words only, but it still selects lines containing 'ERROR', not excludes them. Option D is wrong because it simply prints all lines containing 'ERROR', which is the opposite of what the administrator wants.

139
MCQhard

A Linux system's hostname resolution does not consult /etc/hosts before querying DNS. Which file controls the order of name resolution services?

A./etc/nsswitch.conf
B./etc/host.conf
C./etc/resolv.conf
D./etc/dnsmasq.conf
AnswerA

/etc/nsswitch.conf defines the hosts database entry, listing the order in which resolution services such as files, dns and myhostname are consulted. Editing its hosts line restores /etc/hosts precedence before DNS, directly satisfying the stem's requirement to control name resolution ordering.

Why this answer

The /etc/nsswitch.conf file controls the order of name resolution services by defining the 'hosts' database entry, which specifies the sources (e.g., files, dns) and their lookup order. If the entry is 'hosts: dns files', the system queries DNS before /etc/hosts, bypassing the local file. This file is part of the GNU C Library's Name Service Switch (NSS) framework, which governs all system databases like passwd, group, and hosts.

Exam trap

The trap here is that candidates confuse /etc/nsswitch.conf with /etc/resolv.conf or /etc/host.conf, assuming DNS order is controlled by resolver configuration files rather than the NSS database order.

How to eliminate wrong answers

Option B is wrong because /etc/host.conf is a legacy configuration file used by the old glibc resolver (pre-NSS) to control resolver behavior, such as order (bind, hosts), but it is deprecated and not the primary mechanism on modern Linux systems. Option C is wrong because /etc/resolv.conf only specifies DNS resolver parameters (nameservers, search domains, options) and does not control the order of name resolution services or whether /etc/hosts is consulted. Option D is wrong because /etc/dnsmasq.conf is the configuration file for the dnsmasq DNS forwarder and DHCP server, which is a separate service and does not control the system-wide name resolution order used by the resolver library.

140
Multi-Selecthard

A technician is diagnosing a server that fails to reach the expected multi-user target. The technician wants to gather evidence about kernel ring buffer messages and the systemd journal for the current boot. Which TWO commands provide this diagnostic information? (Choose two.)

Select 2 answers
A.journalctl -b
B.dmesg
C.systemctl status
D.uptime
E.last reboot
AnswersA, B

journalctl -b displays journal entries recorded since the current boot, aggregating kernel and service messages with timestamps and unit context. This lets the technician trace which units failed or timed out before the multi-user target, making it the primary tool for systemd boot diagnostics alongside the kernel ring buffer.

Why this answer

Kernel and service boot messages live in two complementary places on a systemd host. The kernel ring buffer, read with dmesg, holds low-level hardware and driver messages from early boot. The journal, queried with journalctl -b for the current boot, aggregates kernel and unit messages with timestamps and context.

Together they give the technician the evidence needed to find why the multi-user target was not reached.

Exam trap

The trap here is reaching for status or accounting commands like uptime, last reboot, or a bare status call, when actual boot diagnostics require reading the kernel ring buffer and the current-boot journal.

141
Multi-Selecthard

A Linux administrator is troubleshooting a server that intermittently fails to detect a newly installed network card. The administrator suspects the kernel is not loading the correct driver automatically. Which TWO commands should be used to identify the PCI device and then load the appropriate kernel module manually? (Choose two.)

Select 2 answers
A.lspci -nn
B.rmmod
C.ifconfig -a
D.lsusb -v
E.modprobe
AnswersA, E

lspci -nn lists PCI devices with numeric vendor and device IDs, which are essential for identifying an unrecognized network card. The numeric IDs can be matched against driver aliases or the pci.ids database to determine the correct module. This is the first step before loading a driver manually.

Why this answer

To resolve an undetected PCI network card, the administrator must first identify the device with lspci -nn to obtain numeric vendor and device IDs, then load the matching driver with modprobe. This sequence confirms the hardware presence and activates the correct kernel module, after which the interface should appear. USB inspection, interface listing, and module removal do not address a missing PCI driver.

Exam trap

The trap here is reaching for interface-level tools like ifconfig or unrelated buses like USB when the root problem is a PCI device whose kernel driver has not been loaded.

142
MCQeasy

An administrator needs to check the system's load averages without displaying any process information. Which command should be used?

A.w
B.top
C.ps
D.uptime
AnswerD

uptime prints the current time, uptime duration, logged-in user count and the 1-, 5- and 15-minute load averages, then exits. It reads /proc/loadavg without listing processes, unlike top or ps, satisfying the requirement to view load averages without process information.

Why this answer

The `uptime` command displays the current time, how long the system has been running, the number of logged-in users, and the system load averages for the past 1, 5, and 15 minutes. It does not show any process-level information, making it the correct choice for checking load averages alone.

Exam trap

The trap here is that candidates often confuse `uptime` with `w` or `top` because both also display load averages, but the question explicitly requires no process information, which `w` and `top` include.

How to eliminate wrong answers

Option A is wrong because `w` displays load averages but also shows detailed information about currently logged-in users and their processes. Option B is wrong because `top` provides a real-time, dynamic view of running processes along with load averages, which is more than what the question asks for. Option C is wrong because `ps` reports a snapshot of current processes and does not display system load averages at all.

143
MCQmedium

A Linux server acts as a router between an internal network and the internet. After enabling IPv4 forwarding, clients still cannot reach external hosts. The administrator confirms the routing table is correct and the external interface is up. Which command displays the current kernel packet-filter rules so the administrator can verify whether forwarding is being blocked?

A.ip route show
B.ss -tulpn
C.nft list ruleset
D.ip -s link show
AnswerC

nft list ruleset prints every table, chain, and rule in the nftables ruleset, including any forward chain that could be dropping or rejecting traffic. On a modern distribution using nftables as the packet-filter backend, this shows exactly what is filtering forwarded packets, making it the right command to diagnose blocked forwarding.

Why this answer

Forwarded packets traverse the forward path of the packet filter, so a drop or reject rule there prevents transit traffic even when routing and interface state are correct. On a host using the nftables backend, nft list ruleset dumps the entire ruleset, exposing any forward chain rules that block the traffic and allowing the administrator to confirm the cause.

Exam trap

The trap here is assuming that correct routing and an up interface are sufficient for forwarding, when a packet-filter rule in the forward chain can silently drop transit traffic.

144
MCQhard

A systems administrator maintains a Linux web server running Apache HTTP Server (version 2.4) with three virtual hosts. The server logs are stored in /var/log/httpd/ and are rotated using logrotate, which is configured with the default settings that came with the Apache package. The administrator has noticed that after the nightly log rotation, the main access log file (access_log) is empty, while the rotated log files (e.g., access_log.1, access_log.2) contain the previous day's data. Furthermore, new HTTP requests are being logged into the most recent rotated file (access_log.1) instead of the current access_log file. The administrator has verified that the logrotate cron job runs successfully, and that the log files are owned by the root user with read/write permissions for the root group. No errors appear in the system logs. The Apache service continues to run and serve web pages. Which of the following actions should the administrator take to ensure that Apache writes new log entries to the current access_log file after rotation?

A.Modify the Apache configuration to set the 'RotateLogs' directive and restart the service.
B.Add a postrotate script to the logrotate configuration that sends a USR1 or HUP signal to the Apache process to cause it to reopen the log files.
C.Change the logrotate frequency to 'weekly' so that the log is not rotated as often.
D.Set the 'copytruncate' directive in the logrotate configuration to copy the log file and truncate the original, so Apache can continue writing without interruption.
AnswerB

Apache holds the original file descriptor after logrotate renames access_log, so it keeps writing to the renamed inode (access_log.1). Sending USR1 or HUP triggers Apache to close and reopen its log files, binding them to the newly created access_log.

Why this answer

The issue is that after logrotate moves the current access_log to access_log.1, Apache continues writing to the old file descriptor (now pointing to access_log.1) because it never reopened the log file. Sending a USR1 or HUP signal to Apache causes it to close and reopen its log files, creating a new access_log and writing new entries there. This is the standard method for log rotation with Apache and other daemons that keep file handles open.

Exam trap

The trap here is that candidates may think 'copytruncate' is a safe, signal-free solution, but they overlook the risk of data loss between the copy and truncate operations, making the postrotate signal method the correct and reliable choice for Apache.

How to eliminate wrong answers

Option A is wrong because Apache 2.4 does not have a 'RotateLogs' directive; log rotation is handled externally by logrotate, not by Apache itself. Option C is wrong because changing the frequency to weekly does not fix the core problem of Apache writing to the wrong file after rotation; it only delays the issue. Option D is wrong because 'copytruncate' would copy the log and truncate the original, which avoids the need for a signal, but it can cause data loss (entries written between copy and truncate) and is not the standard or recommended approach for Apache; the correct method is to use a postrotate script with a signal.

145
MCQmedium

A technician is troubleshooting a system that fails to boot with the error 'Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. What is the most likely cause?

A.The init binary is missing or corrupted.
B.The root filesystem is corrupted and needs fsck.
C.The kernel lacks the necessary driver for the storage controller.
D.The boot loader is not installed correctly.
AnswerC

The panic occurs because the kernel cannot access the root filesystem, typically when the storage controller driver is built as a module absent from the initramfs. Without that driver, the kernel sees no block device, producing unknown-block(0,0).

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates that the kernel cannot locate or access the root filesystem. This typically occurs because the kernel lacks the necessary driver (module) for the storage controller (e.g., SATA, SCSI, NVMe) that the root device is connected to, so it cannot read the partition table or mount the root filesystem.

Exam trap

The trap here is that candidates often confuse a root filesystem corruption error with a missing storage driver error, because both can prevent booting, but the specific 'unknown-block(0,0)' message uniquely points to the kernel's inability to identify the block device, not a filesystem issue.

How to eliminate wrong answers

Option A is wrong because a missing or corrupted init binary would cause a different error, such as 'Kernel panic - not syncing: No init found' or 'Failed to execute /sbin/init', not a VFS mount failure on unknown-block(0,0). Option B is wrong because a corrupted root filesystem would typically produce filesystem-specific errors (e.g., 'EXT4-fs error') or a kernel panic with a different message, not the unknown-block(0,0) error which indicates the device itself is unrecognized. Option D is wrong because an incorrectly installed boot loader would prevent the kernel from being loaded at all (e.g., 'Missing operating system' or 'GRUB error'), not cause the kernel to fail mounting the root filesystem after it has already started executing.

146
MCQmedium

Refer to the exhibit. A user runs 'python --version' and gets 'Python 3.9.1'. Which command would run Python 2 instead?

A.python --version2
B.python2
C.python3
D.python2 --version
AnswerB

On most Linux distributions Python 2 and Python 3 are installed as separate interpreters, so the versioned binary name selects the major version. Invoking python2 runs the Python 2 interpreter, satisfying the requirement to use Python 2 rather than the default Python 3.9.1.

Why this answer

On many Linux distributions, Python 2 and Python 3 are installed side by side, with the `python` command typically linked to Python 2 (or sometimes Python 3, depending on the distribution). However, in this scenario, `python --version` returns 'Python 3.9.1', indicating that `python` is linked to Python 3. To explicitly run Python 2, you must use the `python2` command, which is the standard binary name for Python 2.x installations.

Exam trap

The trap here is that candidates may assume `python` always refers to Python 2, but the question shows it is Python 3, so they must recognize that `python2` is the explicit command for Python 2, not `python3` or a version flag.

How to eliminate wrong answers

Option A is wrong because `--version2` is not a valid flag for Python; it would cause an error or be ignored. Option C is wrong because `python3` would run Python 3, not Python 2, and the question asks for Python 2. Option D is wrong because while `python2 --version` would display the version of Python 2, the question asks for the command that would run Python 2, not just display its version; the correct command to run Python 2 is simply `python2`.

147
MCQeasy

An administrator needs to inspect the hardware inventory of a server, including details about the motherboard, BIOS, and memory banks, in a structured way. Which command provides this information by reading from the DMI/SMBIOS data?

A.dmidecode
B.lsusb
C.lspci
D.lshw
AnswerA

dmidecode reads the SMBIOS/DMI table presented by the firmware and decodes it into readable sections describing the BIOS, system, baseboard, chassis, processors, and memory devices. Because the administrator wants structured motherboard, firmware, and memory-bank details, this is the correct tool; it requires root privileges to access the raw table and report the full inventory.

Why this answer

The DMI/SMBIOS table is firmware-provided data describing the physical platform. dmidecode decodes that table directly, yielding sections for BIOS, system, baseboard, and memory devices including individual slots. Commands that enumerate buses such as PCI or USB describe attached devices instead, and general-purpose inventory tools aggregate data rather than decoding the firmware table itself.

Exam trap

The trap here is confusing bus-enumeration commands like lspci or lsusb with firmware-table decoders, when only the DMI/SMBIOS reader exposes motherboard, BIOS, and memory-bank details.

148
Multi-Selecteasy

Which TWO commands are used to install packages on a Debian-based system? (Choose two.)

Select 2 answers
A.pacman -S
B.apt-get install
C.dpkg -i
D.rpm -i
E.yum install
AnswersB, C

apt-get install retrieves packages and their dependencies from configured Debian repositories, then invokes dpkg to unpack and configure them. It satisfies the stem's requirement for a Debian-based installation command, handling dependency resolution that the lower-level dpkg tool leaves to the administrator.

Why this answer

B is correct because `apt-get install` is the standard command-line tool for installing packages from Debian repositories, handling dependencies automatically. C is correct because `dpkg -i` installs a local `.deb` package file directly, though it does not resolve dependencies.

Exam trap

The trap here is that candidates often confuse package managers across distributions, mistakenly associating `rpm` or `yum` with Debian systems due to superficial familiarity with Linux package management.

149
MCQhard

A server has an LVM logical volume mounted at /data. The administrator needs to add a new physical disk to the volume group and then extend both the logical volume and the filesystem online, without unmounting. Which sequence of commands achieves this?

A.vgextend data_vg /dev/sdc1; pvcreate /dev/sdc1; lvextend -L +50G /data; resize2fs /data
B.pvcreate /dev/sdc1; vgextend data_vg /dev/sdc1; lvresize -L +50G /data; mount -o remount /data
C.pvcreate /dev/sdc1; vgextend data_vg /dev/sdc1; lvextend -r -L +50G /data
D.pvcreate /dev/sdc1; vgcreate data_vg /dev/sdc1; lvextend -r -L +50G /data
AnswerC

pvcreate initializes the new partition as a physical volume, vgextend adds it to the existing volume group, and lvextend -r -L +50G /data grows the logical volume while the -r flag invokes the appropriate resize tool (resize2fs or xfs_growfs) to expand the filesystem online. This is the correct end-to-end sequence.

Why this answer

Extending LVM storage online requires initializing the new device with pvcreate, adding it to the existing group with vgextend, and growing the logical volume with lvextend while using -r so the filesystem is expanded in the same step. Reversing the first two commands, creating a new volume group, or omitting the filesystem resize all leave the task incomplete or failing outright.

Exam trap

The trap here is assuming that growing a logical volume automatically grows the filesystem it contains, when the two layers must be resized explicitly or via the -r flag.

150
MCQhard

A directory contains files with spaces and special characters in their names. An administrator wants to delete all files older than 30 days using find and xargs. Which command is safe?

A.find /path -type f -mtime +30 -delete
B.find /path -type f -mtime +30 -exec rm {} \;
C.find /path -type f -mtime +30 | xargs rm
D.find /path -type f -mtime +30 -print0 | xargs -0 rm
AnswerD

The -print0 flag terminates each path with a NUL byte, and xargs -0 reads that delimiter, so filenames containing spaces or special characters are passed to rm intact rather than being split into separate arguments.

Why this answer

It uses `-print0` with `find` to output null-delimited filenames, and `xargs -0` to process them safely. This handles spaces, newlines, and special characters in filenames without word-splitting or shell interpretation, ensuring all matching files older than 30 days are deleted reliably.

Exam trap

The trap here is that candidates often choose option C, overlooking the fact that default xargs splits on whitespace and interprets quotes, making it unsafe for filenames with spaces or special characters, while `-print0` and `-0` are the correct safe approach.

How to eliminate wrong answers

Option A is wrong because `-delete` is not a standard POSIX find option and may not be available on all systems; it also does not use xargs as required. Option B is wrong because `-exec rm {} \;` forks a new rm process for each file, which is inefficient and does not use xargs. Option C is wrong because piping `find` output directly to `xargs rm` without `-print0` and `-0` causes filenames with spaces or special characters to be split into multiple arguments, leading to errors or unintended deletions.

Page 1

Page 2 of 6

Page 3

All pages