Courseiva

Linux Professional Institute Certification Level 1 LPIC-1 (LPIC-1) — Questions 151–225

402 questions total · 6pages · All types, answers revealed

Page 2

Page 3 of 6

Page 4
151
Multi-Selecthard

A Linux server uses nftables as its firewall. The administrator needs to allow incoming SSH (TCP/22) and HTTP (TCP/80) while dropping all other incoming traffic. Which TWO statements about implementing this are correct? (Choose two.)

Select 2 answers
A.Rules must be added to the output chain to allow responses from the server to clients.
B.The rule 'tcp dport { 22, 80 } accept' can be used to allow both SSH and HTTP in a single rule.
C.A base chain must be created with type filter and hook input to process incoming packets.
D.The default policy of the input chain must be set to accept to allow the specified ports.
E.The command 'nft add rule ip filter input tcp dport 22 accept' will persist across reboots by default.
AnswersB, C

nftables supports set-based matching. The syntax 'tcp dport { 22, 80 } accept' matches packets with destination port 22 or 80 and accepts them. This is efficient and concise, reducing the number of rules. It is a valid and recommended way to allow multiple ports.

Why this answer

To filter incoming traffic with nftables, you must create a base chain with type filter and hook input. Allowing multiple ports can be done with a set in a single rule. The default policy should be drop to block other traffic, and connection tracking handles return traffic without output rules.

Rules are not persistent unless saved and loaded at boot.

Exam trap

The trap here is assuming nftables rules persist automatically or that output rules are needed for return traffic, when conntrack handles it and persistence requires saving.

152
MCQeasy

Refer to the exhibit. A system administrator runs 'ip route show default' and gets this output. What does it indicate?

A.The DNS server is 192.168.1.1.
B.The default route points to gateway 192.168.1.1 on interface eth0.
C.The system has no internet access.
D.The IP address of the system is 192.168.1.1.
AnswerB

The default route entry specifies a gateway address of 192.168.1.1 reachable via the eth0 device. Any traffic lacking a more specific matching route is forwarded to that gateway, confirming eth0 as the egress interface for off-subnet destinations.

Why this answer

The command 'ip route show default' displays the default route entry in the kernel routing table. The output shows that the default route (destination 0.0.0.0/0) is via gateway 192.168.1.1 and uses interface eth0, meaning all traffic not matching a more specific route is sent to that gateway on that interface.

Exam trap

The trap here is confusing the default gateway with other network parameters like DNS server or the system's own IP address, leading candidates to incorrectly associate the gateway IP with those unrelated services.

How to eliminate wrong answers

Option A is wrong because the default route specifies a gateway for network traffic, not a DNS server; DNS server configuration is handled in /etc/resolv.conf or via systemd-resolved, not in the routing table. Option C is wrong because having a default route to 192.168.1.1 indicates the system has a path to reach external networks, provided the gateway is operational and the system has proper connectivity. Option D is wrong because the IP address of the system is not shown in the default route output; the system's IP address is typically found using 'ip addr show' or 'ifconfig', and 192.168.1.1 is the gateway address, not the system's own address.

153
MCQhard

A shell script contains a function named `cleanup` that must run automatically when the script exits, whether it finishes normally or is terminated by a signal. Which construct should be used to register this function?

A.cleanup && exit
B.trap cleanup EXIT
C.trap cleanup INT TERM
D.at_exit cleanup
AnswerB

The `trap` builtin with the EXIT pseudo-signal arranges for the named command or function to run when the shell exits, including normal completion and exits triggered by signals that the shell handles. Registering `cleanup` this way ensures the function executes in both scenarios described, making it the correct construct.

Why this answer

The `trap ... EXIT` form registers a handler for the shell's exit event, which fires on normal termination as well as on exits caused by signals the shell processes. That covers both cases in the scenario, whereas trapping only specific signals would miss normal completion and merely calling the function would not defer it.

Exam trap

The trap here is assuming that trapping INT and TERM also covers normal exit; only the EXIT pseudo-signal fires on ordinary script completion.

154
MCQhard

A technician is troubleshooting a server whose /var partition is reported as full by applications, but df -h shows the filesystem at only 40 percent usage. The technician suspects deleted files are still held open by running processes. Which command best identifies the process holding a deleted file open on that filesystem?

A.lsof +L1
B.fuser -m /var
C.df -i /var
D.du -sh /var
AnswerA

The +L1 option to lsof lists files with a link count less than one, which is exactly the state of a file that has been unlinked but is still referenced by an open file descriptor. This reveals the process name and PID holding the space, directly addressing the suspected cause.

Why this answer

When a file is unlinked while a process still holds it open, the blocks remain allocated but the name disappears from the directory tree, so df shows usage that du cannot account for. lsof with the +L1 filter enumerates files whose link count has dropped below one, exposing the process responsible and allowing the administrator to restart it and reclaim space.

Exam trap

The trap here is trusting du output to match df, when unlinked-but-open files are invisible to du yet still consume blocks counted by df.

155
Multi-Selecthard

A backup operator needs to archive the entire /srv/projects tree, preserving permissions, ownership, and directory structure, into a single compressed file that can later be unpacked on another Linux host. Which TWO commands correctly produce such an archive? (Choose two.)

Select 2 answers
A.cp -a /srv/projects projects_copy
B.tar -cjf projects.tbz /srv/projects
C.gzip -r /srv/projects
D.tar -czf projects.tgz /srv/projects
E.dd if=/srv/projects of=projects.img
AnswersB, D

The -j option compresses the archive with bzip2 instead of gzip, and -c, -f behave as usual, capturing the whole tree with metadata intact. The result is still one compressed file that can be extracted on another host. It satisfies the same preservation and packaging goals using a different compressor.

Why this answer

Both tar invocations create a single compressed archive of the whole directory tree while retaining permissions, ownership, and layout. The only difference is the compressor: gzip via -z produces a .tgz, while bzip2 via -j produces a .tbz. Either output can be copied to another Linux system and unpacked to reproduce the original structure, which is exactly what the backup operator needs.

Exam trap

The trap here is confusing metadata-preserving recursive copy or per-file compression with true single-file archiving, which only tar provides.

156
MCQmedium

A Linux server uses chrony for time synchronization. The administrator notices that the system clock is drifting by several seconds per day. Which command should she use to verify which NTP servers are currently selected and the estimated offset?

A.ntpq -p
B.chronyc sources -v
C.timedatectl status
D.chronyc tracking
AnswerB

This command lists all configured time sources, indicates which are selected for synchronization (marked with ^*), and shows the estimated offset, jitter, and other statistics. It directly answers the need to verify server selection and offset, making it the correct choice.

Why this answer

The chronyc sources -v command provides a detailed list of all time sources, including which ones are currently selected for synchronization and their estimated offsets. This is exactly what the administrator needs to diagnose drift and verify server selection. The other commands either show only summary information or are not native to chrony.

Exam trap

The trap here is assuming that chronyc tracking lists the individual NTP servers, when it only shows the currently selected reference and overall offset.

157
MCQmedium

A script needs to read a file line by line, preserving leading and trailing whitespace and backslashes. Which loop construct should be used?

A.while IFS= read -r line; do echo "$line"; done < file.txt
B.while read line; do echo "$line"; done < file.txt
C.while read -r line; do echo "$line"; done < file.txt
D.for line in $(cat file.txt); do echo "$line"; done
AnswerA

Setting IFS to an empty value prevents read from trimming leading and trailing whitespace, and the -r option disables backslash escape processing. Together they preserve the line exactly as it appears in the file, satisfying the requirement to keep whitespace and backslashes intact during iteration.

Why this answer

Reading a file line by line while preserving exact content requires disabling both word splitting and backslash processing. Clearing IFS stops the shell from trimming leading and trailing whitespace, and the -r option stops backslash escapes from being interpreted. Using only one of these settings leaves the other behavior active and alters the data.

Exam trap

The trap here is assuming that the -r option alone preserves all characters, overlooking that IFS still causes leading and trailing whitespace to be stripped.

158
MCQmedium

A Linux administrator is troubleshooting a package dependency issue. When attempting to install package 'foo', the package manager reports a missing dependency 'libbar.so.2'. Which of the following is the most appropriate next step?

A.Run 'ldconfig' to update the library cache
B.Reinstall the 'foo' package using 'rpm -i --force foo.rpm'
C.Run 'rpm -q --whatrequires libbar.so.2'
D.Use 'apt-file search libbar.so.2' or 'dnf provides libbar.so.2' to find the package that contains the file
AnswerD

The missing dependency is a shared library file, not a package name, so the package manager cannot resolve it directly. Querying which package provides libbar.so.2 identifies the correct RPM or DEB to install, satisfying the dependency.

Why this answer

The error indicates that the file 'libbar.so.2' is missing from the system. The most appropriate next step is to identify which package provides this file, so that it can be installed to satisfy the dependency. On Debian-based systems, 'apt-file search' queries the package repository metadata to find the package containing a specific file; on Red Hat-based systems, 'dnf provides' performs the same function.

This targeted search is the correct first troubleshooting step before any installation or library cache update.

Exam trap

The trap here is that candidates may confuse 'ldconfig' (which only updates the cache for already-installed libraries) with a tool that can resolve missing dependencies, or they may think that forcing installation with '--force' is an acceptable workaround, when in fact it bypasses safety checks and can lead to system instability.

How to eliminate wrong answers

Option A is wrong because 'ldconfig' updates the runtime linker cache for shared libraries that are already installed; it cannot install missing libraries or resolve a missing file dependency. Option B is wrong because using 'rpm -i --force' forces installation of the package even if dependencies are missing, which can leave the system in a broken or inconsistent state and is not a proper resolution. Option C is wrong because 'rpm -q --whatrequires libbar.so.2' queries which installed packages depend on that file, but the file is not present on the system, so the command will return nothing useful and does not help locate the missing provider.

159
MCQmedium

An administrator wants to prevent a specific user, 'john', from being able to schedule cron jobs. Which file should the administrator modify?

A./var/spool/cron/crontabs
B./etc/cron.allow
C./etc/crontab
D./etc/cron.deny
AnswerD

Adding john to /etc/cron.deny blocks that named user from submitting jobs via crontab, satisfying the requirement to prevent only him from scheduling cron jobs. The file lists users barred from cron, and it takes effect only while /etc/cron.allow is absent.

Why this answer

The /etc/cron.deny file lists users who are explicitly denied access to schedule cron jobs. If this file exists and the user 'john' is listed in it, he will be prevented from using crontab. This is the standard mechanism for restricting cron access when /etc/cron.allow does not exist.

Exam trap

The trap here is that candidates confuse /etc/cron.allow with /etc/cron.deny, thinking that modifying the allow file is the only way to control access, but the question specifically asks for a file to prevent a user, which is the deny file.

How to eliminate wrong answers

Option A is wrong because /var/spool/cron/crontabs is a directory containing individual user crontab files, not a configuration file for access control. Option B is wrong because /etc/cron.allow is used to explicitly allow users to schedule cron jobs; modifying it would not prevent 'john' unless he is removed from it, but the question asks for a file to prevent him, and /etc/cron.deny is the direct method. Option C is wrong because /etc/crontab is the system-wide cron table for scheduled tasks, not a user access control file.

160
MCQmedium

A Linux administrator needs to create a user account 'jsmith' with a home directory '/home/jsmith' and the default shell '/bin/bash'. The account must be created without creating a group with the same name. Which command accomplishes this?

A.adduser -m -s /bin/bash -N jsmith
B.usermod -m -s /bin/bash -N jsmith
C.useradd -d /home/jsmith -s /bin/bash --no-group jsmith
D.useradd -m -s /bin/bash -N jsmith
AnswerD

The -m flag creates the home directory, -s sets the shell, and -N disables the creation of a user group with the same name. This matches the requirement exactly. Without -N, useradd would create a group 'jsmith' by default, which is not desired here.

Why this answer

The useradd command with -m creates the home directory, -s sets the login shell, and -N prevents the creation of a group with the same name as the user. This satisfies all requirements: new account, specified home directory, specified shell, and no matching group. The other commands either use invalid options, wrong syntax, or are meant for modification rather than creation.

Exam trap

The trap here is assuming that useradd always creates a group with the same name; the -N option is required to suppress that behavior.

161
MCQeasy

Which directory contains information about hardware devices in a hierarchical structure, such as PCI devices and USB devices?

A./sys
B./dev
C./etc
D./proc
AnswerA

/sys is the sysfs pseudo-filesystem, exposing kernel objects as directories and attributes, including PCI and USB device hierarchies. Unlike /dev, which holds device nodes, or /proc, which reports processes and kernel parameters, sysfs is specifically structured for enumerating hardware topology.

Why this answer

The /sys directory (sysfs) is a virtual filesystem that exports information about hardware devices, drivers, and kernel objects in a hierarchical structure. It organizes devices by their bus type (e.g., PCI, USB) and provides detailed attributes such as vendor IDs, device IDs, and power management states, making it the correct location for querying hardware topology.

Exam trap

The trap here is that candidates confuse /proc (which also contains some hardware info like /proc/cpuinfo) with /sys, but /proc lacks the structured, hierarchical device topology that sysfs provides for buses like PCI and USB.

How to eliminate wrong answers

Option B (/dev) is wrong because it contains device special files (e.g., /dev/sda, /dev/ttyUSB0) for accessing hardware via block or character I/O, not a hierarchical representation of device relationships. Option C (/etc) is wrong because it stores system configuration files (e.g., /etc/fstab, /etc/ssh/sshd_config), not dynamic hardware information. Option D (/proc) is wrong because it primarily exposes process and kernel runtime data (e.g., /proc/cpuinfo, /proc/meminfo) in a flat or process-centric structure, not a hierarchical device tree.

162
Multi-Selectmedium

Which TWO of the following are true about the 'source' command in bash?

Select 2 answers
A.It executes a script in a subshell.
B.It is only available in bash and not in POSIX sh.
C.It can be abbreviated as '.' (dot).
D.It executes a script in the current shell.
E.It requires the script to have execute permission.
AnswersC, D

The dot is a synonym for source.

Why this answer

Option C is correct because the dot command (.) is the POSIX-standard abbreviation for source, so `source file` and `. file` are equivalent in bash. Option D is correct because source reads and executes the script's commands in the current shell environment, which is why variables and functions defined in the sourced file persist in the calling shell. Option A is wrong because executing in a subshell is what happens when you run a script normally (e.g., `bash script.sh` or `./script.sh`), not when sourcing it.

Option B is wrong because the dot form is specified by POSIX and works in POSIX sh, even though the name `source` itself is a bash extension. Option E is wrong because source reads the file with the shell, so the script only needs read permission, not execute permission.

Exam trap

The trap here is that candidates often confuse 'source' with executing a script directly (which requires execute permission and runs in a subshell), or mistakenly think the dot abbreviation is a bash-only feature, when it is actually defined by POSIX.

163
Multi-Selecthard

Which TWO of the following are true about the /proc filesystem?

Select 2 answers
A.It is formatted with the ext4 filesystem.
B.It is a network filesystem.
C.It is a pseudo-filesystem that contains runtime system information.
D.It is used to store persistent configuration data.
E.It is typically mounted at boot time.
AnswersC, E

/proc is a virtual, kernel-generated filesystem exposing runtime data such as CPU details, memory usage and process state. Nothing on it occupies disk blocks, satisfying the stem's pseudo-filesystem criterion and distinguishing it from persistent on-disk filesystems.

Why this answer

Option C is correct because /proc is a pseudo-filesystem (a virtual, kernel-generated filesystem) that exposes runtime system and process information such as /proc/cpuinfo, /proc/meminfo, and per-process directories like /proc/PID, rather than storing real data blocks on disk. Option E is correct because /proc is typically mounted automatically at boot time, commonly via an entry like 'proc /proc proc defaults 0 0' in /etc/fstab or by systemd, since many tools and the kernel expect it to be present early in the boot process. Option A is incorrect because /proc is not formatted with ext4 or any on-disk filesystem; it has no persistent backing store.

Option B is incorrect because /proc is not a network filesystem like NFS or CIFS; it is a kernel-internal virtual filesystem. Option D is incorrect because /proc does not store persistent configuration data—it reflects transient kernel and process state, and changes are lost on reboot.

Exam trap

The trap here is that candidates often confuse /proc with a real filesystem stored on disk, leading them to select Option A, or they mistake its runtime nature for persistent storage (Option D), when in fact /proc is a volatile kernel interface that is mounted automatically at boot (Option E).

164
MCQeasy

The administrator wants the sshd service to start automatically at boot. Which command should be used?

A.systemctl start sshd.service
B.systemctl daemon-reload
C.systemctl set-default multi-user.target
D.systemctl enable sshd.service
AnswerD

systemctl enable creates the symlink in the multi-user.target.wants directory, so systemd starts sshd automatically during boot. This satisfies the requirement for automatic startup, whereas systemctl start only launches the service for the current session and does not persist across reboots.

Why this answer

The `systemctl enable sshd.service` command creates the necessary symlinks in the systemd unit configuration directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) so that the sshd service is automatically started when the system boots into its default target. This is the correct way to enable a service to start at boot in a systemd-based Linux distribution.

Exam trap

The trap here is confusing `systemctl start` (immediate, one-time activation) with `systemctl enable` (persistent boot-time activation), leading candidates to choose option A when the question asks for automatic startup at boot.

How to eliminate wrong answers

Option A is wrong because `systemctl start sshd.service` only starts the service immediately in the current session; it does not configure it to start automatically at boot. Option B is wrong because `systemctl daemon-reload` reloads the systemd manager configuration after unit files have been changed, but it does not enable or disable any service for boot-time startup. Option C is wrong because `systemctl set-default multi-user.target` changes the default systemd target (runlevel) that the system boots into, but it does not enable a specific service like sshd to start at boot.

165
MCQhard

A user runs the command 'grep -E '^[[:space:]]*[^#]' /etc/ssh/sshd_config' and receives no output. Which statement best explains this result?

A.The caret ^ inside the bracket expression negates the set, so [^#] matches any character including #, making the pattern match all lines.
B.The character class [[:space:]] includes newline characters, so the pattern matches across multiple lines and produces no output.
C.The regular expression matches lines that start with optional whitespace followed by a non-# character, so no output means every non-empty line begins with # or is empty.
D.The -E option enables extended regular expressions, but the pattern uses basic regex syntax, causing grep to fail silently.
AnswerC

The pattern '^[[:space:]]*[^#]' matches a line beginning with zero or more whitespace characters, then a character that is not '#'. If grep returns nothing, every line either is empty or has '#' as the first non-whitespace character. This is a valid conclusion about the file's content, assuming the file exists and is readable.

Why this answer

The command searches for lines that do not start with a comment character after optional whitespace. No output indicates that all non-empty lines begin with '#'. The -E flag does not alter the meaning of this pattern, and the character class [[:space:]] does not include newline in grep's line-oriented processing.

The negation [^#] correctly excludes '#'.

Exam trap

The trap here is assuming that [[:space:]] matches newlines in grep, or that -E changes the pattern's meaning, when the real explanation is the file's content.

166
MCQeasy

A system administrator needs to check if a filesystem has any errors without actually performing a repair. Which command should be used?

A.fsck -y /dev/sdb1
B.fsck -N /dev/sdb1
C.fsck -n /dev/sdb1
D.e2fsck -p /dev/sdb1
AnswerC

The `-n` flag makes fsck answer "no" to every prompt, so it opens the filesystem read-only and reports errors without writing repairs — satisfying the no-repair constraint. Unlike `-y`, which auto-fixes, `-n` guarantees the check is non-destructive, though it may skip some checks needing write access.

Why this answer

The `-n` option with `fsck` performs a read-only check, displaying any filesystem errors without making any modifications or repairs. This is the correct choice for a non-destructive check that only reports issues.

Exam trap

The trap here is confusing `-N` (which only shows what would be checked without actually scanning) with `-n` (which performs a read-only scan), leading candidates to mistakenly choose the dry-run option instead of the actual read-only check.

How to eliminate wrong answers

Option A is wrong because `fsck -y` automatically answers 'yes' to all repair prompts, which would attempt to fix errors, not just check for them. Option B is wrong because `fsck -N` only shows what would be done (a dry-run) without actually checking the filesystem for errors. Option D is wrong because `e2fsck -p` automatically repairs filesystem issues without prompting, which performs repairs rather than just checking.

167
MCQmedium

Which command can be used to check whether a specific kernel module is currently loaded?

A.modinfo <module>
B.lsmod | grep <module>
C.depmod -a
D.insmod <module>
AnswerB

lsmod reads /proc/modules and lists every currently loaded module with size and usage count. Piping to grep filters that output for the named module, directly answering whether it is loaded — unlike modprobe, which loads modules rather than reporting state.

Why this answer

`lsmod` lists all currently loaded kernel modules by reading the `/proc/modules` file, and piping its output through `grep` filters for the specific module name. This directly shows whether the module is loaded in the running kernel, which is the exact requirement of the question.

Exam trap

The trap here is that candidates confuse `modinfo` (which shows module information from disk) with `lsmod` (which shows runtime load status), leading them to incorrectly select option A.

How to eliminate wrong answers

Option A is wrong because `modinfo` displays metadata about a kernel module (such as description, author, and parameters) from the module file itself, but it does not check whether the module is currently loaded into the kernel. Option C is wrong because `depmod -a` generates dependency files (modules.dep) for all modules in the kernel tree, but it does not report on the current load status of any module. Option D is wrong because `insmod` is used to insert (load) a module into the kernel, not to check if it is already loaded; attempting to load an already-loaded module will typically fail with an error like 'File exists'.

168
MCQmedium

A technician needs to inspect a compressed log archive named app.log.gz without modifying it, and wants to view only the first 20 lines. The archive is 40 MB compressed. Which command accomplishes this most efficiently?

A.tar -xzf app.log.gz -O | head -n 20
B.zcat app.log.gz > app.log; head -n 20 app.log
C.gunzip app.log.gz && head -n 20 app.log
D.gunzip -c app.log.gz | head -n 20
AnswerD

The -c option writes the decompressed stream to standard output without altering the original file, and piping to head reads only the first 20 lines before closing the pipe. This preserves the archive, avoids writing a full decompressed copy to disk, and stops decompression early, making it the most efficient correct approach.

Why this answer

Streaming the decompressed output to standard output with gunzip -c and piping into head reads only as many lines as needed while leaving the archive untouched. This avoids writing a full uncompressed copy and stops work early, which is the efficient and non-destructive way to peek at the start of a compressed log.

Exam trap

The trap here is using plain gunzip, which deletes the original archive and fully expands it, instead of the streaming -c form that preserves the file.

169
Multi-Selectmedium

Which THREE steps are required to configure a network interface with a static IP address using the ip command (assuming interface eth0)? (Choose three.)

Select 3 answers
A.ifconfig eth0 192.168.1.10 netmask 255.255.255.0
B.ip route add default via 192.168.1.1
C.ip addr add 192.168.1.10/24 dev eth0
D.ip link set eth0 up
E.echo 'nameserver 8.8.8.8' > /etc/resolv.conf
AnswersB, C, D

Adds default gateway.

Why this answer

The `ip route add default via 192.168.1.1` command sets the default gateway for the system, which is essential for routing traffic to networks beyond the local subnet. Without a default route, the static IP configuration would only allow communication within the local network (192.168.1.0/24), making this step mandatory for full network connectivity.

Exam trap

The trap here is that candidates often confuse the `ip` command with legacy tools like `ifconfig` (option A) or include DNS configuration (option E) as part of the `ip` command workflow, when in fact DNS is handled by separate system services and not by the `ip` command.

170
Multi-Selectmedium

Which TWO commands can display the UUID of block devices?

Select 2 answers
A.blkid
B.lsblk -f
C.df -T
D.fdisk -l
E.parted /dev/sda print
AnswersA, B

blkid scans block devices and prints their attributes, including the filesystem UUID and TYPE, straight from the superblock. It reports UUIDs for all detected devices by default, satisfying the requirement to display block device UUIDs.

Why this answer

Option A, blkid, is correct because it directly queries block-device metadata and prints each device's UUID (along with TYPE and LABEL) by reading the filesystem superblock, e.g. /dev/sda1: UUID="..." TYPE="ext4". Option B, lsblk -f, is correct because the -f (--fs) flag adds filesystem information columns including UUID, FSTYPE, LABEL, and mountpoint for each block device in a tree view. Option C, df -T, only reports filesystem type, size, and usage per mountpoint, not UUIDs.

Option D, fdisk -l, lists partition tables, sizes, and types but does not display filesystem UUIDs. Option E, parted /dev/sda print, shows the partition table, geometry, and partition types, but not filesystem UUIDs.

Exam trap

The trap here is that candidates confuse commands that display partition table information (like `fdisk` and `parted`) with commands that display filesystem metadata (like `blkid` and `lsblk -f`), leading them to select options that show partition layout but not UUIDs.

171
MCQhard

A server runs systemd-resolved and uses a VPN. DNS queries fail intermittently. The administrator checks /etc/resolv.conf and finds it is a symlink to /run/systemd/resolve/stub-resolv.conf. Which command should be used to view the effective DNS servers and debug the issue?

A.cat /etc/resolv.conf
B.resolvectl status
C.systemctl restart systemd-resolved
D.dig @localhost
AnswerB

`resolvectl status` queries systemd-resolved directly over D-Bus, exposing per-link DNS servers, current DNS server, and DNSSEC settings for each interface. Because /etc/resolv.conf only points at the 127.0.0.53 stub, it hides the VPN link's actual upstream servers, so this command reveals the split-DNS configuration causing the intermittent failures.

Why this answer

B is correct because `resolvectl status` is the native command for querying systemd-resolved's internal state, showing the per-link DNS servers, search domains, and current resolver configuration. Since `/etc/resolv.conf` is a symlink to the stub resolver, `cat /etc/resolv.conf` only shows the stub listener address (127.0.0.53), not the actual upstream DNS servers used by systemd-resolved. `resolvectl status` reveals the effective DNS servers for each network interface, including VPN interfaces, which is essential for debugging intermittent failures.

Exam trap

The trap here is that candidates assume `cat /etc/resolv.conf` shows the real DNS servers, but because it is a symlink to the stub resolver's configuration, it only shows 127.0.0.53, masking the actual upstream servers that systemd-resolved uses.

How to eliminate wrong answers

Option A is wrong because `cat /etc/resolv.conf` only displays the stub resolver's loopback address (127.0.0.53), not the actual upstream DNS servers that systemd-resolved queries; this gives no insight into which DNS servers are failing. Option C is wrong because `systemctl restart systemd-resolved` is a brute-force action that disrupts all active DNS resolution and does not provide diagnostic information about current DNS servers or intermittent failures. Option D is wrong because `dig @localhost` sends queries to the stub resolver on 127.0.0.53, which may succeed even when upstream queries fail, and it does not reveal which upstream servers are configured or their status.

172
MCQeasy

Which command displays information about currently loaded kernel modules?

A.insmod
B.modinfo
C.lsmod
D.modprobe -l
AnswerC

`lsmod` reads `/proc/modules` and lists every kernel module currently loaded, showing name, size and usage count. It directly satisfies the stem's requirement for loaded-module information, unlike `modinfo`, which describes a module file's metadata, or `insmod`, which inserts one.

Why this answer

The `lsmod` command reads the `/proc/modules` file to display a list of all currently loaded kernel modules, showing their name, size, usage count, and dependent modules. This is the standard tool for querying the current module state in the Linux kernel.

Exam trap

The trap here is that candidates confuse `lsmod` (list loaded modules) with `modinfo` (show module metadata) or `modprobe -l` (list available modules), because all three commands relate to kernel modules but serve distinct purposes.

How to eliminate wrong answers

Option A is wrong because `insmod` is used to insert a kernel module into the running kernel, not to display information about loaded modules. Option B is wrong because `modinfo` displays metadata (such as description, author, and parameters) from a module file, not a list of currently loaded modules. Option D is wrong because `modprobe -l` is a deprecated option that listed available module files in the module tree, not currently loaded modules; modern `modprobe` does not support `-l` and it was never used to show loaded modules.

173
MCQhard

Refer to the exhibit. The /var partition is nearly full. Which of the following is the most appropriate first step to free up space?

A.Move some files from /var to / and create a symbolic link.
B.Delete old log files in /var/log and clear package cache.
C.Increase the size of /dev/sdb2 using resize2fs.
D.Add a new disk and mount it to /var.
AnswerB

Deleting rotated logs and clearing the package cache directly reclaims space on the saturated /var filesystem, since both reside there. This targets the actual constraint — a full partition — without touching unrelated data or services, making it the safest immediate remediation before investigating long-term log rotation or retention policies.

Why this answer

The most common cause of a full /var partition is accumulated log files in /var/log and cached package data. Deleting old logs (e.g., via logrotate or manual cleanup) and clearing the package manager cache (e.g., apt-get clean or yum clean all) directly reclaims space without requiring disk resizing or additional hardware. This is the safest and fastest first step before considering more invasive actions.

Exam trap

The trap here is that candidates often jump to resizing the partition or adding a disk (options C and D) because they think the problem requires a hardware or filesystem-level solution, when in fact the simplest and most appropriate first step is to clean up temporary and log files that can be safely removed.

How to eliminate wrong answers

Option A is wrong because moving files from /var to / and creating a symbolic link may break system services that expect specific paths under /var, and it does not address the root cause of space usage; it also risks filling the root partition. Option C is wrong because resize2fs can only increase the size of an ext2/ext3/ext4 filesystem if there is unallocated space on the underlying block device (e.g., after resizing the partition with fdisk or parted), and simply running resize2fs without first expanding the partition will fail or do nothing. Option D is wrong because adding a new disk and mounting it to /var is an overly complex and disruptive first step; it requires repartitioning, formatting, and moving data, which is unnecessary when simple cleanup can free space immediately.

174
MCQmedium

A script uses the command substitution: files=$(ls). Which statement about the resulting value of files is true?

A.The variable files contains the output of ls with newlines replaced by spaces.
B.The variable files contains the exit status of the ls command.
C.The variable files contains the output of ls, with trailing newlines removed.
D.The variable files contains a list of filenames separated by null characters.
AnswerC

Command substitution captures the standard output of the command and strips any trailing newline characters. Internal newlines remain, but the final newline that ls typically outputs is removed. Therefore the variable holds the output with trailing newlines stripped, which is the documented behavior.

Why this answer

Command substitution captures the standard output of the enclosed command and removes trailing newline characters. Internal newlines are retained, but the final newline is stripped. This behavior is consistent across shells and is why using the result unquoted can lead to word splitting on spaces, tabs, and newlines.

Exam trap

The trap here is thinking that command substitution replaces all newlines with spaces or that it captures the exit status rather than the command's output.

175
MCQeasy

A junior administrator needs to create a new ext4 filesystem on the partition /dev/sdb2. The partition already exists but has never been formatted. Which command should the administrator run to create the filesystem?

A.fsck.ext4 /dev/sdb2
B.mount -t ext4 /dev/sdb2 /mnt
C.mkfs.ext4 /dev/sdb2
D.fdisk /dev/sdb2
AnswerC

mkfs.ext4 is the dedicated front-end for creating an ext4 filesystem on a block device; it invokes mke2fs with ext4 defaults, writes the superblock, inode tables, and journal, and is safe to run on a raw partition. Since /dev/sdb2 is unformatted, this is the direct and correct tool.

Why this answer

Creating a filesystem requires a mkfs-family tool, and the ext4-specific front end is mkfs.ext4. Because the partition exists but is blank, no partitioning step is needed and no mount or repair step applies. The command writes the on-disk structures that make /dev/sdb2 mountable as ext4.

Exam trap

The trap here is confusing partition creation tools like fdisk with filesystem creation tools like mkfs.ext4, when the partition already exists and only needs formatting.

176
MCQmedium

Refer to the exhibit. What can be concluded about the cron daemon based on this systemctl output?

A.It is stopped.
B.It is enabled but not currently running.
C.It has failed recently.
D.It is running and will start automatically at system boot.
AnswerD

The `systemctl` output shows the unit state as active (running) with no failure, confirming the cron daemon is currently executing. The "enabled" vendor preset indicates a symlink exists in the multi-user.target.wants directory, so systemd will start cron automatically during boot without manual intervention.

Why this answer

The systemctl output shows 'Loaded: loaded' and 'Active: active (running)' for the cron daemon, which indicates it is currently running. Additionally, the 'enabled' status in the 'Loaded' line means the service is configured to start automatically at system boot. Therefore, option D is correct.

Exam trap

The trap here is that candidates may confuse 'enabled' (start at boot) with 'active' (currently running), leading them to select option B when the service is actually running, or they may misinterpret the absence of explicit 'failed' text as meaning the service is stopped.

How to eliminate wrong answers

Option A is wrong because 'Active: active (running)' explicitly shows the cron daemon is running, not stopped. Option B is wrong because while the service is enabled, it is also currently running, not just enabled but not running. Option C is wrong because there is no indication of a failure; the status shows 'active (running)' with no mention of 'failed' or recent crash logs in the output.

177
Multi-Selecteasy

Which TWO of the following are valid ways to capture the output of a command into a variable in Bash?

Select 2 answers
A.var=`command`
B.var={command}
C.var=$(command)
D.var|command
E.var=command
AnswersA, C

Backticks perform command substitution in Bash, executing the enclosed command and assigning its standard output to the variable. This is a valid capture method, equivalent in effect to the modern $(command) syntax, and works in all POSIX-compliant shells.

Why this answer

Option A, var=`command`, is correct because backticks are the legacy command-substitution syntax in Bash: the shell runs command in a subshell and replaces the backtick expression with its standard output, which is then assigned to var. Option C, var=$(command), is correct because the modern $(...) form performs the same command substitution, capturing command's stdout into var, and is preferred since it nests more cleanly and avoids backtick escaping issues. Option B, var={command}, is not valid because braces are used for brace expansion (e.g., {a,b}) and parameter expansion (${var}), not command substitution.

Option D, var|command, is not valid because it would attempt to pipe the variable name as a command into another command rather than assign output. Option E, var=command, is not valid because it simply assigns the literal string 'command' to var without executing it or capturing any output.

Exam trap

LPI often tests the distinction between command substitution syntax and other shell constructs like brace expansion or simple assignment, leading candidates to confuse var=$(command) with var={command} or var=command.

178
MCQeasy

Which directory contains the kernel modules for the currently running kernel?

A./boot
B./etc/modprobe.d
C./usr/src
D./lib/modules/$(uname -r)
AnswerD

Kernel modules are stored under /lib/modules, with a subdirectory named after the running kernel's release version. Using $(uname -r) resolves that exact version dynamically, satisfying the stem's constraint that the path must reference the currently running kernel.

Why this answer

The kernel modules for the currently running kernel are stored in /lib/modules/$(uname -r). The uname -r command returns the exact kernel release version, and the corresponding directory contains all loadable kernel modules (.ko files) compiled for that specific kernel. This is the standard location used by the kernel and tools like modprobe and insmod to locate and load modules.

Exam trap

The trap here is that candidates confuse the location of kernel modules with the kernel image itself (/boot) or with configuration files (/etc/modprobe.d), failing to recognize that modules are version-specific and stored under /lib/modules.

How to eliminate wrong answers

Option A is wrong because /boot contains the kernel image (vmlinuz), initramfs, and bootloader configuration files, not the kernel modules. Option B is wrong because /etc/modprobe.d contains configuration files for modprobe (e.g., aliases, blacklists, options), not the actual module binaries. Option C is wrong because /usr/src typically contains kernel source code or headers, not compiled modules; modules are built from source but stored separately in /lib/modules.

179
MCQeasy

A help-desk technician must determine which shell built-in will display the absolute path of the directory the user is currently working in, so it can be captured in a support script. Which command should the technician use?

A.dirname
B.ls
C.cd
D.pwd
AnswerD

pwd prints the current working directory as an absolute path and is available both as a shell built-in and as a standalone binary. Capturing its output in a script yields the full path of the directory the user is in, which is precisely what the technician needs for the support record.

Why this answer

pwd is the standard utility for reporting the current working directory as an absolute path. Because it is also implemented as a shell built-in, it reflects the shell's tracked state and works reliably inside scripts. Redirecting or capturing its output gives the technician the exact directory path to include in a support record.

Exam trap

The trap here is assuming that listing the directory contents reveals the directory's own path, when ls shows entries rather than location.

180
MCQeasy

A technician needs to output only the kernel release number. Which command should be used?

A.cat /proc/version
B.uname -r
C.dmesg | head -1
D.lsmod
AnswerB

`uname -r` prints just the kernel release string, such as 6.8.0-45-generic, satisfying the requirement to output only the kernel release number. Other `uname` flags return different fields: `-a` shows everything, `-s` the kernel name, and `-v` the build version, so none isolates the release.

Why this answer

The `uname -r` command specifically prints the kernel release number (e.g., '5.10.0-28-amd64') by querying the `utsname` system call. This is the standard, portable way to retrieve only the kernel release string without additional system information.

Exam trap

The trap here is that candidates confuse `/proc/version` (which shows the full version string) with a command that outputs only the release number, or they assume `dmesg` output is consistent across all systems.

How to eliminate wrong answers

Option A is wrong because `cat /proc/version` outputs the full version string including the kernel release, compiler version, and build timestamp, not just the release number. Option C is wrong because `dmesg | head -1` shows the first line of the kernel ring buffer, which typically includes the kernel version and build info but is not guaranteed to be just the release number and may vary by system or boot. Option D is wrong because `lsmod` lists loaded kernel modules, not the kernel release number.

181
MCQmedium

A Linux administrator needs to archive the /etc directory into a compressed tarball at /backup/etc_backup.tar.bz2. The administrator wants to see the progress of the archiving process as files are added. Which command should be used?

A.tar -czvf /backup/etc_backup.tar.bz2 /etc
B.tar -cvf /backup/etc_backup.tar.bz2 /etc
C.tar -xjvf /backup/etc_backup.tar.bz2 /etc
D.tar -cjvf /backup/etc_backup.tar.bz2 /etc
AnswerD

The -j option tells tar to use bzip2 compression, -c creates a new archive, -v enables verbose output to list files as they are processed, and -f specifies the archive filename. This matches the requirement to create a compressed archive with visible progress, producing a .tar.bz2 file from /etc.

Why this answer

To create a bzip2-compressed tar archive with verbose output, the correct combination is tar -cjvf. The -j flag invokes bzip2, -c creates the archive, -v shows progress, and -f specifies the output file. This ensures the archive is both compressed and the administrator can monitor which files are being added during the process.

Exam trap

The trap here is confusing the -z (gzip) and -j (bzip2) compression flags, especially when the filename extension suggests one format but the command uses another.

182
MCQmedium

A system administrator notices that the system's syslog messages are not being written to /var/log/messages. The rsyslog service is running. The administrator wants to check the configuration syntax of rsyslog. Which command should be used?

A.rsyslogd -d
B.rsyslogd -f
C.rsyslogd -N
D.rsyslogd -v
AnswerC

`rsyslogd -N` runs rsyslog's configuration parser without starting the daemon, validating syntax and reporting errors. This directly satisfies the administrator's stated goal of checking the configuration syntax while the service continues running, since `-N` performs a dry-run check rather than altering logging behaviour or restarting the service.

Why this answer

The correct command is `rsyslogd -N` because the `-N` option performs a configuration syntax check without starting or restarting the rsyslog daemon. This allows the administrator to validate the rsyslog configuration file for errors before applying changes, ensuring that syslog messages will be written correctly to /var/log/messages.

Exam trap

The trap here is that candidates may confuse `-N` with `-d` (debug mode) or `-f` (config file path), assuming that running the daemon with a verbose flag or specifying a file will reveal syntax errors, whereas only `-N` performs a dedicated syntax check without executing the daemon.

How to eliminate wrong answers

Option A is wrong because `rsyslogd -d` runs rsyslogd in debug mode, which outputs verbose debugging information to the terminal but does not specifically check configuration syntax. Option B is wrong because `rsyslogd -f` specifies an alternative configuration file to use, not a syntax check; it would load and use that file, potentially causing issues if the syntax is invalid. Option D is wrong because `rsyslogd -v` displays the version information of rsyslogd and does not perform any configuration validation.

183
MCQmedium

A Linux administrator runs df -h and sees that the /var filesystem is 100% full. The administrator deletes several large log files, but df still shows 100% usage. Which command should the administrator use to identify processes that are holding deleted files open?

A.fdisk -l /dev/sda
B.lsof +L1
C.fsck /dev/sda1
D.du -sh /var
AnswerB

lsof +L1 lists open files that have a link count less than 1, which indicates deleted files still held open by processes. This helps identify which processes are keeping the space allocated. Once identified, the administrator can restart or kill those processes to release the space. This directly solves the problem of df showing full despite deletion.

Why this answer

When a file is deleted but still open by a process, the directory entry is removed, but the inode and data blocks remain allocated until the process closes the file. df reflects the actual blocks allocated, while du only sees directory entries. lsof +L1 lists open files with link count less than 1, identifying deleted files still in use. Restarting the holding process releases the space.

Exam trap

The trap here is assuming that deleting a file immediately frees disk space, when open file descriptors can keep the space allocated.

184
MCQmedium

A server with a udev rule fails to consistently assign a persistent network interface name. What is the most likely cause?

A.The rule uses an incorrect operator.
B.The BIOS device name is configured incorrectly.
C.The kernel module for the NIC is not loaded.
D.The network interface's MAC address is not unique or changes.
AnswerD

udev derives persistent names from stable attributes such as MAC address. If the MAC is duplicated, randomised or changes between boots, the rule matches different devices or none, producing inconsistent naming. Non-unique or volatile MAC addresses are the usual root cause.

Why this answer

Persistent network interface names in Linux rely on udev rules that match attributes like MAC address. If the MAC address is not unique (e.g., due to a virtual machine or cloned NIC) or changes (e.g., after hardware replacement or driver update), the rule will fail to consistently identify the interface, causing the name assignment to be unpredictable.

Exam trap

The trap here is that candidates assume udev rules always work if the syntax is correct, overlooking that dynamic or non-unique MAC addresses undermine the stability of the matching attribute.

How to eliminate wrong answers

Option A is wrong because an incorrect operator (e.g., using '==' instead of '!=') would cause a syntax error or mis-match, but the question describes inconsistent assignment, not a complete failure; the rule still runs but the matching attribute is unreliable. Option B is wrong because BIOS device names (like 'eno1') are a naming scheme, not a cause of udev rule failure; incorrect BIOS configuration might affect the name format but does not prevent consistent assignment if the rule uses a stable attribute. Option C is wrong because if the kernel module for the NIC were not loaded, the interface would not appear at all, leading to a persistent failure rather than inconsistent naming.

185
MCQmedium

Refer to the exhibit. A user tries to write to /mnt/usb/myfile.txt as a non-root user and receives a permission denied error. What is the most likely reason?

A.The filesystem is mounted read-only
B.The vfat filesystem does not support Unix permissions, and the mount options (fmask/dmask) restrict write access to root only
C.The filesystem is mounted with the 'noexec' option, preventing write
D.The file's permissions are 644, so the user does not have write access
AnswerB

Correct. The vfat filesystem does not store Unix permissions; the fmask and dmask options control the permissions shown. With fmask=0022, files get 755 permissions, but the owner is root (default unless uid/gid options are used). So only root can write.

Why this answer

The vfat filesystem does not store Unix-style permissions; instead, it relies on mount options like fmask and dmask to set the effective permissions for all files and directories. If these masks are set to restrict write access to root only (e.g., fmask=0133), non-root users will receive a 'permission denied' error even if the filesystem is mounted read-write. This is a common cause of write failures on USB drives formatted with FAT/VFAT.

Exam trap

The trap here is that candidates assume the 'permission denied' error must be due to file permissions (option D) or a read-only mount (option A), but they overlook that vfat does not store Unix permissions and that mount masks are the actual controlling mechanism.

How to eliminate wrong answers

Option A is wrong because the error would occur regardless of user identity if the filesystem were truly read-only; the question specifies the user is non-root, and a read-only mount would block root as well, which is not the scenario. Option C is wrong because the 'noexec' mount option prevents execution of binaries, not write operations; it has no effect on writing to files. Option D is wrong because on a vfat filesystem, the file's permissions (e.g., 644) are not stored on disk; they are synthesized at mount time via fmask/dmask, so the actual permissions seen by the user depend on those mount options, not on a stored mode.

186
MCQeasy

An administrator needs to identify the device file for the first SATA SSD in a server. Which device file should they use?

A./dev/hda
B./dev/sdb
C./dev/nvme0n1
D./dev/sda
AnswerD

Linux assigns SATA and SCSI disks sequentially as /dev/sda, /dev/sdb and so on, so the first SATA SSD enumerates as /dev/sda. The /dev/sdX naming reflects the detected drive order, satisfying the request for the first device.

Why this answer

The first SATA SSD in a Linux system is typically assigned the device file /dev/sda. SATA drives use the SCSI subsystem via the libata driver, which names them /dev/sdX, with 'a' representing the first detected drive. This is the standard naming convention for SATA SSDs in modern Linux kernels.

Exam trap

The trap here is that candidates often confuse SATA with PATA (IDE) and choose /dev/hda, or mistakenly think SATA SSDs use NVMe naming like /dev/nvme0n1, not realizing that SATA drives are mapped to the SCSI subsystem as /dev/sdX.

How to eliminate wrong answers

Option A is wrong because /dev/hda is used for PATA (IDE) drives, not SATA SSDs; SATA drives are handled by the SCSI subsystem and named /dev/sdX. Option B is wrong because /dev/sdb would be the second SATA drive (or second SCSI device), not the first. Option C is wrong because /dev/nvme0n1 is used for NVMe SSDs, which connect via PCIe and use a different naming scheme (nvme0n1 for the first namespace of the first NVMe controller), not for SATA SSDs.

187
Multi-Selectmedium

Which THREE directories are commonly used for mounting removable media in Linux?

Select 3 answers
A./mnt
B./mount
C./cdrom
D./dev
E./media
AnswersA, C, E

/mnt serves as the conventional mount point for temporarily mounted filesystems, including removable media such as USB drives and optical discs. It satisfies the question's requirement for a standard directory used for removable media mounting, distinct from /media, which desktop environments typically manage automatically for user-mounted devices.

Why this answer

Option A, /mnt, is correct because it is the traditional Filesystem Hierarchy Standard (FHS) mount point for temporarily mounted filesystems, including removable media such as USB drives and external disks. Option C, /cdrom, is correct because it is a conventional mount point historically used by distributions to mount optical media like CD-ROMs and DVDs. Option E, /media, is correct because modern Linux distributions use it as the standard mount point for automatically mounted removable media such as USB sticks, cameras, and optical discs.

Option B, /mount, is not a standard FHS directory and is not used by Linux for mounting removable media. Option D, /dev, is incorrect because it contains device files (e.g., /dev/sdb1) that represent hardware devices, not directories where filesystems are mounted.

Exam trap

Candidates may incorrectly assume that /dev (the device directory) is a mount point, or that /mount is a valid FHS directory. They might also overlook /cdrom as a common mount point for optical media, often symlinked to /media/cdrom. The correct mount point directories for removable media per FHS are /mnt (temporary manual mounts) and /media (automatic mounting), with /cdrom being a widely used legacy or symlink location.

188
MCQeasy

A user runs the command `echo $HOME` in a Bash shell and receives the output `/home/alice`. A colleague later runs the same command in a different shell and gets `/root`. Which type of shell variable is being displayed?

A.A local shell variable
B.An environment variable
C.A special shell parameter
D.A positional parameter
AnswerB

HOME is an environment variable that is exported to child processes. It is set by the login process and reflects the home directory of the user who started the shell. Because it is inherited, a different user or a shell started with a different effective user will show a different value, which explains the observed difference.

Why this answer

HOME is an environment variable that is exported to child processes, so it is inherited by commands run from the shell. It is set at login time based on the user account, which is why different users see different values. Local variables, positional parameters, and special parameters do not behave this way.

Exam trap

The trap here is assuming that any variable set in a shell is automatically an environment variable, when many variables remain local unless exported.

189
MCQmedium

A Linux administrator is managing a server that uses RPM-based package management. They need to find which installed package provides the '/etc/ssh/sshd_config' file. Which command should they use?

A.rpm -qi /etc/ssh/sshd_config
B.rpm -qf /etc/ssh/sshd_config
C.rpm -ql /etc/ssh/sshd_config
D.rpm -qa | grep sshd_config
AnswerB

The -qf flag queries the RPM database for the package owning a specified file path, directly satisfying the need to identify the provider of /etc/ssh/sshd_config. Unlike -ql, which lists files within a named package, -qf works backwards from the file to its owning package.

Why this answer

The correct command is `rpm -qf /etc/ssh/sshd_config`. The `-q` flag queries the RPM database, and `-f` (or `--file`) tells RPM to find which installed package owns the specified file. This is the standard way to map a file back to its originating package in RPM-based systems.

Exam trap

The trap here is that candidates confuse the purpose of RPM query options: `-qi` (package info), `-ql` (file list), and `-qf` (file ownership), and often pick `-ql` thinking it lists files, but fail to realize it requires a package name, not a file path.

How to eliminate wrong answers

Option A is wrong because `rpm -qi` queries package information (like description, version, and architecture) from the RPM database, but it requires a package name as an argument, not a file path; using a file path with `-qi` will fail or produce irrelevant output. Option C is wrong because `rpm -ql` lists all files owned by a specified package; it expects a package name, not a file path, so it cannot be used to find which package owns a given file. Option D is wrong because `rpm -qa | grep sshd_config` lists all installed packages and pipes the output to grep, which would only match if a package name literally contains 'sshd_config' (which is unlikely); it does not query the RPM database's file-to-package mapping and will not reliably find the package that owns the file.

190
Multi-Selecteasy

Which TWO commands can be used to view the contents of a compressed file named archive.tar.gz without extracting it to disk?

Select 2 answers
A.gzip -d archive.tar.gz
B.bunzip2 -c archive.tar.gz | tar -t
C.tar -tzf archive.tar.gz
D.gunzip -l archive.tar.gz
E.zcat archive.tar.gz | tar -t
AnswersC, E

The `-t` flag lists archive contents, while `-z` pipes through gzip decompression and `-f` specifies the filename, so `tar -tzf archive.tar.gz` reads and decompresses the gzip stream in memory. This satisfies the stem's constraint of viewing contents without extracting anything to disk.

Why this answer

Option C, `tar -tzf archive.tar.gz`, is correct because the `-t` flag lists the archive contents, `-z` tells tar to filter through gzip, and `-f` specifies the archive file, so it lists the members of the gzipped tarball without writing them to disk. Option E, `zcat archive.tar.gz | tar -t`, is correct because `zcat` decompresses the gzip stream to standard output and pipes it into `tar -t`, which lists the archive contents from stdin without extracting files to disk. Option A, `gzip -d archive.tar.gz`, is wrong because `-d` decompresses the file, replacing it with `archive.tar` on disk rather than merely viewing contents.

Option B, `bunzip2 -c archive.tar.gz | tar -t`, is wrong because `bunzip2` handles bzip2 compression, not gzip, so it cannot decompress a `.tar.gz` file. Option D, `gunzip -l archive.tar.gz`, is wrong because `gunzip -l` lists compression statistics for the gzip file itself, not the contents of the tar archive inside it.

Exam trap

The trap here is that candidates often confuse `gunzip -l` (which shows compression metadata) with listing the actual file contents, or they mistakenly apply bzip2 tools to gzip archives, forgetting that each compression format requires its own specific decompression utility.

191
MCQmedium

A technician needs to inspect the filesystem type, UUID, and filesystem label of the partition /dev/sdb1 without mounting it. Which command provides all of this information in a single invocation?

A.blkid /dev/sdb1
B.lsblk -f /dev/sdb1
C.tune2fs -l /dev/sdb1
D.fdisk -l /dev/sdb1
AnswerA

blkid queries the libblkid cache and reads superblock metadata to print the UUID, TYPE (filesystem), and LABEL for the specified block device. It works on unmounted partitions, requires no mount, and is the standard tool for retrieving persistent identifiers used in /etc/fstab. This directly satisfies the need to see filesystem type, UUID, and label together.

Why this answer

blkid reads on-disk superblock metadata and reports UUID, TYPE, and LABEL for a block device without requiring a mount. That single invocation answers all three questions the technician has. fdisk shows partition-table data, lsblk -f is less reliable when given a single partition argument, and tune2fs works only on ext-family filesystems, so each of those alternatives leaves part of the requirement unmet.

Exam trap

The trap here is assuming that any tool that lists disks will also surface the filesystem UUID and label, when only tools that read superblock metadata do so.

192
MCQhard

After running 'ip route show default', a system administrator sees no output. Users on that system can only communicate with hosts on the local subnet. What is the most likely cause?

A.DNS is misconfigured
B.A firewall is blocking all traffic
C.The network interface is down
D.The default gateway is missing
AnswerD

With no default route in the routing table, the kernel has no next-hop for off-subnet destinations, so packets are dropped and only local-subnet hosts remain reachable. Adding a default gateway restores forwarding beyond the local subnet.

Why this answer

The `ip route show default` command displays the default gateway entry in the routing table. An empty output indicates that no default route is configured. Without a default gateway, the system cannot route packets to destinations outside its local subnet, which explains why users can only communicate with hosts on the local subnet.

Exam trap

The trap here is that candidates may confuse DNS resolution with routing, assuming that name resolution failure is the root cause, when in fact the absence of a default gateway directly prevents any off-subnet IP communication regardless of DNS status.

How to eliminate wrong answers

Option A is wrong because DNS misconfiguration would affect name resolution, not basic IP connectivity; the system could still reach external IP addresses if a default gateway existed. Option B is wrong because a firewall blocking all traffic would prevent all communication, including local subnet traffic, which is not the case here. Option C is wrong because if the network interface were down, the system would have no network connectivity at all, not just limited to the local subnet.

193
MCQmedium

A server has a partition /dev/sda2 that is almost full. The admin suspects a large file has been deleted but is still held open by a process. Which command can identify such a file?

A.du -sh /
B.find / -size +100M
C.lsof | grep deleted
D.df -h
AnswerC

lsof lists open file descriptors; filtering for deleted shows files unlinked from the directory but still held open, so the space is not reclaimed until the process closes or restarts. This identifies the culprit consuming the partition.

Why this answer

The `lsof` command lists open files and their associated processes. When a file is deleted but still held open by a process, `lsof` shows the filename with a '(deleted)' marker in its output. Piping through `grep deleted` filters for exactly those entries, allowing the admin to identify the file and the process keeping it alive, which is the precise scenario described.

Exam trap

The trap here is that candidates often choose `df -h` or `du` because they show disk usage, but they fail to realize that deleted-but-open files are invisible to those tools, while `lsof` directly reveals the hidden space consumption.

How to eliminate wrong answers

Option A is wrong because `du -sh /` calculates disk usage of the entire root filesystem but does not show which files are deleted and still open; it only reports current space consumption. Option B is wrong because `find / -size +100M` locates files larger than 100 MB on disk, but it cannot detect files that have been unlinked (deleted) from the directory tree, as those files no longer have a directory entry to find. Option D is wrong because `df -h` shows overall filesystem disk usage and free space, but it provides no information about individual files or processes holding deleted files open.

194
MCQhard

A Linux system has a software RAID1 array /dev/md0 consisting of /dev/sda1 and /dev/sdb1. After replacing a failed disk, the administrator runs 'mdadm --manage /dev/md0 --add /dev/sdc1', but the array remains degraded. Which command should be used to check the status of the array?

A.mdadm --examine /dev/sdc1
B.mdadm --version
C.mdadm --detail /dev/md0
D.mdadm --query /dev/md0
AnswerC

`mdadm --detail /dev/md0` reports the array's current state, including which member devices are active, failed or spare, and the overall RAID1 redundancy level. This directly satisfies the stem's requirement to check why the array remains degraded after adding /dev/sdc1, showing whether the new device was actually incorporated.

Why this answer

The `mdadm --detail /dev/md0` command displays the current state of the RAID array, including its status (e.g., degraded, active), the number of active and failed devices, and the sync/resync progress. Since the array remains degraded after adding a new disk, this command will show whether the new disk has been properly integrated or if there is an underlying issue, such as a missing or failed component.

Exam trap

The trap here is that candidates often confuse `--examine` (which inspects a disk's superblock) with `--detail` (which shows the array's overall state), leading them to choose Option A when they need to check the array's degraded status rather than a single disk's metadata.

How to eliminate wrong answers

Option A is wrong because `mdadm --examine /dev/sdc1` reads the superblock on a specific disk to show its metadata and RAID membership, but it does not report the overall array status or whether the array is still degraded. Option B is wrong because `mdadm --version` only prints the version of the mdadm utility and provides no information about the array's state. Option D is wrong because `mdadm --query /dev/md0` gives a brief summary (e.g., 'is not an md array' or a one-line status) but lacks the detailed device-by-device status and resync progress needed to diagnose why the array remains degraded.

195
MCQmedium

Given a file with lines like 'John:23:Engineer', which awk command prints only the name and department (first and third fields) separated by a space?

A.awk -F: '{print $1,$3}' file
B.awk -F: '{print $1,$2}' file
C.awk -F: '{print $1 $3}' file
D.awk -F: '{print $1 $2}' file
AnswerA

-F: sets the input field separator to a colon, so each line splits into name, age and department. The print statement outputs $1 and $3 separated by awk's default output separator, a single space, producing the required name and department pair.

Why this answer

The `-F:` flag sets the field separator to colon, and `{print $1,$3}` prints the first and third fields separated by the default output field separator (a space). This matches the requirement to output the name and department from lines like 'John:23:Engineer'.

Exam trap

The trap here is that candidates often confuse the comma (which inserts the OFS) with concatenation (no comma), leading them to pick options like C or D that produce no space between fields, or they misidentify the field numbers and select B instead of A.

How to eliminate wrong answers

Option B is wrong because `{print $1,$2}` prints the first and second fields (name and age), not the name and department. Option C is wrong because `{print $1 $3}` concatenates the first and third fields with no separator, producing output like 'JohnEngineer' instead of 'John Engineer'. Option D is wrong because `{print $1 $2}` concatenates the first and second fields with no separator, outputting 'John23' instead of the required name and department.

196
Multi-Selecteasy

Which THREE package management tools are native to Debian-based Linux distributions? (Choose exactly three.)

Select 3 answers
A.dpkg
B.rpm
C.yum
D.apt
E.apt-get
AnswersA, D, E

Low-level package manager for Debian.

Why this answer

dpkg is the core low-level package manager for Debian-based distributions, handling the installation, removal, and querying of .deb packages directly. It does not resolve dependencies automatically, making it the foundational tool upon which higher-level tools like APT are built.

Exam trap

The trap here is that candidates often confuse high-level package managers across distributions, mistakenly thinking that tools like yum or rpm are universal, when in fact they are specific to Red Hat-based systems, while Debian-based systems exclusively use dpkg and APT-family tools.

197
MCQmedium

A system administrator needs to ensure that a bash script continues executing even if any command in the script fails. Which of the following should be used at the beginning of the script?

A.set +e
B.trap 'echo error' ERR
C.unset -e
D.set -e
E.# set +e
AnswerA

`set +e` disables the errexit behaviour, so bash continues running subsequent commands after any individual command returns a non-zero exit status. This directly satisfies the stem's requirement that the script keeps executing despite failures, since errexit is off by default but may have been enabled by a prior `set -e`.

Why this answer

`set +e` disables the 'exit on error' behavior in a bash script, allowing the script to continue executing even if a command returns a non-zero exit status. By default, bash scripts do not exit on error, but if `set -e` is used elsewhere, `set +e` explicitly turns that off to ensure the script continues despite failures.

Exam trap

The trap here is that candidates often confuse `set +e` with `set -e`, or think that a comment like `# set +e` would have any effect, when in fact the `+` sign disables the option and the `-` sign enables it.

How to eliminate wrong answers

Option B is wrong because `trap 'echo error' ERR` sets a trap that executes a command when a command fails, but it does not prevent the script from exiting; the script will still exit after the trap runs unless `set +e` is also used. Option C is wrong because `unset -e` is not a valid bash command; `unset` is used to unset variables or functions, not shell options. Option D is wrong because `set -e` enables 'exit on error', which causes the script to terminate immediately when any command fails, which is the opposite of what is needed.

Option E is wrong because `# set +e` is a comment and has no effect on shell behavior; the `#` makes it a comment line.

198
MCQeasy

A Linux administrator is preparing a new Ubuntu 22.04 server and needs to ensure that the package lists are up to date before installing software. Which command should be used to refresh the package index from all configured repositories?

A.apt-get install --refresh
B.apt update
C.apt upgrade
D.apt dist-upgrade
AnswerB

apt update downloads the latest package metadata from all repositories listed in /etc/apt/sources.list and /etc/apt/sources.list.d/. It refreshes the local cache of available packages and their versions but does not install or upgrade any packages. This is the correct first step before installing software to ensure the system is aware of the newest available versions and dependencies.

Why this answer

The apt update command synchronizes the local package index with the repositories, ensuring that subsequent install or upgrade commands operate on the latest metadata. It is a prerequisite for installing new software or applying updates. The other commands either perform upgrades based on stale data or are invalid.

Refreshing the index is a routine maintenance task on Debian-based systems.

Exam trap

The trap here is confusing updating the package index (apt update) with upgrading installed packages (apt upgrade), which are separate operations.

199
MCQmedium

A Red Hat system administrator suspects that the files belonging to the 'openssh-server' package have been modified since installation. Which command verifies the integrity of the installed package files?

A.rpm -K openssh-server
B.rpm -qa | grep openssh
C.rpm -q openssh-server
D.rpm -V openssh-server
AnswerD

`rpm -V openssh-server` compares each installed file's size, MD5 checksum, permissions, type, owner and group against the values recorded in the RPM database at installation, flagging any mismatch. This directly satisfies the stem's requirement to detect post-installation modification of package files.

Why this answer

The `rpm -V` (verify) command checks the integrity of installed package files by comparing their current attributes (size, MD5 checksum, permissions, etc.) against the original metadata stored in the RPM database. This directly answers the question of whether files belonging to the 'openssh-server' package have been modified since installation.

Exam trap

The trap here is confusing `rpm -K` (key/signature verification of a package file) with `rpm -V` (verification of installed files against the database), as both involve 'verification' but serve entirely different purposes.

How to eliminate wrong answers

Option A is wrong because `rpm -K` verifies the cryptographic signature of an RPM package file (e.g., GPG key), not the integrity of already installed files. Option B is wrong because `rpm -qa | grep openssh` simply lists all installed packages whose names contain 'openssh', performing no integrity check. Option C is wrong because `rpm -q openssh-server` only queries whether the package is installed and displays its version/release, without verifying file integrity.

200
MCQeasy

The /proc filesystem is described as a virtual filesystem. Which statement best describes its purpose?

A.It contains configuration files for system services.
B.It provides an interface to kernel data structures and processes.
C.It holds binary executables for system administration.
D.It stores temporary files that survive reboots.
AnswerB

/proc is generated in memory by the kernel, not stored on disk, so it has no persistent backing blocks. It exposes kernel data structures and per-process information through files, satisfying the virtual filesystem definition in the stem.

Why this answer

The /proc filesystem is a virtual filesystem that does not contain actual files on disk but instead provides a runtime interface to kernel data structures, including process information, system memory, CPU details, and hardware configuration. This allows users and system tools (like ps, top, and free) to read kernel state in real time without needing direct kernel memory access.

Exam trap

The trap here is that candidates confuse /proc with a real filesystem for storing configuration or executables, when in fact it is a virtual interface to kernel data structures that contains no persistent files.

How to eliminate wrong answers

Option A is wrong because configuration files for system services are stored in /etc, not in /proc, which is a virtual filesystem with no persistent configuration data. Option C is wrong because binary executables for system administration reside in directories like /bin, /sbin, /usr/bin, or /usr/sbin, while /proc contains no executable binaries. Option D is wrong because temporary files that survive reboots are typically stored in /var/tmp, whereas /proc is a volatile, kernel-generated filesystem that is recreated fresh on every boot and does not persist any data.

201
MCQeasy

A technician is troubleshooting network connectivity. The server's IP is 192.168.1.10/24, and the gateway is 192.168.1.1. The server can ping the gateway but cannot ping 8.8.8.8. Which command is most appropriate to check if the default route is configured?

A.route -n
B.ifconfig eth0
C.ping 192.168.1.1
D.arp -n
AnswerA

The `route -n` command prints the kernel routing table numerically, revealing whether a default route (destination 0.0.0.0) exists via gateway 192.168.1.1. Since the server reaches its local subnet but not 8.8.8.8, a missing default route is the likely fault, and this command directly confirms it.

Why this answer

The `route -n` command displays the kernel IP routing table without resolving hostnames, showing the default route (destination 0.0.0.0) and its gateway. Since the server can ping the gateway but not 8.8.8.8, the issue is likely a missing or incorrect default route, which `route -n` directly reveals.

Exam trap

The trap here is that candidates assume a successful ping to the gateway implies a default route exists, but the gateway being reachable does not mean the server has a route to forward traffic beyond the local subnet.

How to eliminate wrong answers

Option B is wrong because `ifconfig eth0` only shows the IP address, netmask, and MAC of the interface, not the routing table or default gateway. Option C is wrong because `ping 192.168.1.1` was already performed successfully (as stated in the scenario) and only verifies local gateway reachability, not the existence of a default route. Option D is wrong because `arp -n` displays the ARP cache (IP-to-MAC mappings) for local network hosts, which is irrelevant to checking the default route configuration.

202
MCQhard

A system administrator notices that the NTP service on a Linux server is not synchronizing time with external NTP servers. The administrator runs 'ntpq -p' and sees that all servers listed have a 'reach' value of 0. Which of the following is the most likely cause?

A.The system timezone is incorrectly set.
B.The NTP service is configured to use the local clock.
C.A firewall is blocking UDP port 123.
D.The NTP server is using a different NTP version.
AnswerC

A reach value of 0 means no NTP reply packets have been received in the last eight poll intervals. Blocked UDP port 123 prevents the server responses from arriving, so the client cannot synchronise despite the daemon running.

Why this answer

The `reach` value of 0 in `ntpq -p` output indicates that the NTP client has received no responses from any of the configured servers. Since NTP uses UDP port 123 for communication, a firewall blocking this port would prevent the client from sending or receiving NTP packets, resulting in zero reachability. This is the most common cause when all servers show a reach of 0.

Exam trap

The trap here is that candidates may confuse a reach value of 0 with a stratum value of 16 or a synchronization failure due to timezone misconfiguration, but the reach value specifically indicates network-level communication failure, not configuration or version issues.

How to eliminate wrong answers

Option A is wrong because the system timezone setting affects the display of local time, not the synchronization process with NTP servers; NTP works with UTC internally. Option B is wrong because if the NTP service were configured to use the local clock, the `ntpq -p` output would typically show a server entry like `LOCAL(0)` with a reach value greater than 0, not all servers at 0. Option D is wrong because NTP is backward compatible; different NTP versions (v3, v4) can interoperate, and version mismatch would not cause a reach value of 0 for all servers.

203
MCQeasy

A Linux administrator wants to update the local package index from all configured repositories on an Ubuntu system. Which command accomplishes this?

A.dpkg --configure -a
B.apt upgrade
C.apt-get install
D.apt update
AnswerD

Running apt update refreshes the local package index from every repository listed in sources.list, satisfying the requirement to update metadata without installing anything. The related apt upgrade command installs newer package versions, so it does not meet the stated goal of refreshing the index alone.

Why this answer

The `apt update` command (equivalent to `apt-get update`) refreshes the local package index by downloading the latest package lists from all repositories defined in `/etc/apt/sources.list` and `/etc/apt/sources.list.d/`. This is the prerequisite step before any installation or upgrade, ensuring the system knows about the newest available versions and dependencies.

Exam trap

The trap here is confusing `apt update` (which updates the package index) with `apt upgrade` (which upgrades installed packages), a common mix-up that leads candidates to choose the upgrade command instead of the index refresh command.

How to eliminate wrong answers

Option A is wrong because `dpkg --configure -a` is used to finish configuring any packages that were left in an unconfigured state after a partial installation, not to update the package index. Option B is wrong because `apt upgrade` actually installs newer versions of already-installed packages based on the current local index, but it does not refresh that index itself. Option C is wrong because `apt-get install` is used to install or upgrade specific packages, and it does not update the package lists from repositories.

204
Multi-Selectmedium

Which TWO commands can be used to display the contents of a compressed file without decompressing it to disk? (Choose two.)

Select 2 answers
A.zcat file.gz
B.gzip -d file.gz
C.tar -xzf file.tar.gz
D.bzcat file.bz2
E.uncompress file.Z
AnswersA, D

zcat streams the decompressed output of a gzip file straight to standard output, leaving the original file.gz untouched on disk. This directly satisfies the stem's constraint of viewing contents without decompressing to disk, since no extracted file is ever written.

Why this answer

Option A, zcat file.gz, is correct because zcat (equivalent to gzip -dc) decompresses the gzip stream and writes the contents to standard output, so the file is displayed on screen without ever being written back to disk. Option D, bzcat file.bz2, is correct for the same reason with bzip2-compressed files: it decompresses to stdout, letting you view the contents without creating a decompressed file on disk. Option B, gzip -d file.gz, is wrong because the -d flag decompresses the file on disk, replacing file.gz with the uncompressed file rather than displaying it.

Option C, tar -xzf file.tar.gz, is wrong because -x extracts the archive's members to the filesystem, writing files to disk instead of showing them. Option E, uncompress file.Z, is wrong because it restores the original uncompressed file on disk and removes the .Z file, not displaying contents to stdout.

Exam trap

The trap here is that candidates confuse commands that decompress to stdout (like `zcat` and `bzcat`) with commands that decompress to disk (like `gzip -d` or `uncompress`), or they mistakenly think `tar -xzf` only displays the archive contents when it actually extracts them.

205
MCQhard

Refer to the exhibit. An administrator runs 'ntpq -p' and sees the output shown. What is the most likely cause of the '16' stratum and '0.000' delay/offset?

A.The NTP service is not running.
B.The firewall is blocking UDP port 123.
C.The NTP daemon has recently started and has not yet synchronized.
D.The restrict lines are blocking all NTP queries.
AnswerC

A freshly started NTP daemon reports stratum 16, the unsynchronised sentinel, until it completes its first poll and accepts a server. The 0.000 delay and offset values confirm no measurement has yet been taken, satisfying the stem's requirement to explain both anomalies as a single transient startup condition.

Why this answer

The '16' stratum and '0.000' delay/offset values in the 'ntpq -p' output indicate that the NTP daemon has not yet synchronized with any time source. When ntpd starts, it initially sets the stratum to 16 (unsynchronized) and shows zero values for delay and offset until it completes the synchronization process. This is a normal transient state that resolves once the daemon successfully contacts and synchronizes with an NTP server.

Exam trap

The trap here is that candidates often assume a stratum of 16 and zero delay/offset indicate a firewall or service failure, but the correct interpretation is that the NTP daemon has just started and has not yet synchronized, which is a normal temporary state.

How to eliminate wrong answers

Option A is wrong because if the NTP service were not running, the 'ntpq -p' command would typically return an error or show no output, not display a stratum of 16 with zero delay/offset. Option B is wrong because a firewall blocking UDP port 123 would prevent any NTP communication, resulting in no reachable servers or persistent '16' stratum, but the zero delay/offset specifically indicates the daemon has not yet attempted or completed synchronization, not that packets are being dropped. Option D is wrong because restrict lines blocking all NTP queries would cause the daemon to fail to contact servers, leading to a persistent unsynchronized state, but the zero delay/offset is a characteristic of a freshly started daemon that has not yet attempted synchronization, not a permanent restriction issue.

206
MCQmedium

A junior administrator needs to install the package 'nginx' on a Debian 12 server, but the required package file is not available in any configured APT repository. The administrator has downloaded the file 'nginx_1.22.1-9_amd64.deb' to the current directory. Which command should be used to install this local package file while automatically resolving and installing any missing dependencies from the configured repositories?

A.apt install ./nginx_1.22.1-9_amd64.deb
B.apt-get install nginx_1.22.1-9_amd64.deb
C.dpkg -i nginx_1.22.1-9_amd64.deb
D.dpkg --install --force-depends nginx_1.22.1-9_amd64.deb
AnswerA

On Debian 12, apt accepts a local .deb file path (with ./ to distinguish it from a package name) and installs it while automatically resolving and downloading any missing dependencies from the configured repositories. This is the modern replacement for the older gdebi or dpkg followed by apt-get install -f approach, and it performs the entire operation in one step as required.

Why this answer

The apt command can install a local .deb file when given a path that includes a slash (such as ./filename.deb), and it automatically resolves and installs dependencies from configured repositories. This combines the local installation capability of dpkg with the dependency resolution of APT in a single step. The other commands either fail to resolve dependencies, misinterpret the filename as a package name, or force installation while leaving dependencies broken.

Exam trap

The trap here is assuming that dpkg -i is the standard way to install local .deb files, when in fact modern APT can handle local files directly with automatic dependency resolution.

207
Multi-Selectmedium

An administrator must configure persistent mounts for two filesystems on a database server. One is an ext4 volume that should be mounted at boot without failing the whole boot process if it is unavailable. The other is a swap partition that must be activated at boot. Which TWO entries belong in /etc/fstab to meet these requirements? (Choose two.)

Select 2 answers
A.UUID=5678-efgh /data ext4 defaults,nofail 0 2
B.UUID=90ab-cdef none swap sw 0 0
C.UUID=1234-abcd /data ext4 defaults,noauto 0 2
D.UUID=90ab-cdef /swap swap defaults 0 2
E.UUID=5678-efgh /data ext4 defaults 1 1
AnswersA, B

This entry mounts the ext4 volume at boot using its UUID, and the nofail option tells systemd not to treat a mount failure as fatal, so the boot continues if the device is missing. The dump and fsck fields are valid for an ext4 data filesystem, satisfying the first requirement.

Why this answer

Persistent mounts are declared in /etc/fstab using the device, mount point, filesystem type, options, dump, and fsck pass fields. The ext4 volume needs nofail so an unavailable device does not halt boot, while swap uses the mount point none, type swap, and option sw. The two entries matching those patterns are correct.

Exam trap

The trap here is using noauto when nofail is required, since both affect boot behavior but only one keeps the mount automatic while tolerating a missing device.

208
MCQhard

A Linux server has a USB serial adapter that is sometimes detected as /dev/ttyUSB0 and sometimes as /dev/ttyUSB1 after reboot. An administrator wants to create a udev rule that always assigns the name /dev/ttyUSB-radio to this specific adapter based on its serial number. Which udev rule syntax should be used?

A.KERNEL=="ttyUSB*", ATTR{idVendor}=="0403", SYMLINK="ttyUSB-radio"
B.SUBSYSTEM=="tty", ATTRS{serial}=="A50285BI", SYMLINK+="ttyUSB-radio"
C.SUBSYSTEM=="usb", ATTR{serial}=="A50285BI", NAME="ttyUSB-radio"
D.ACTION=="add", SUBSYSTEM=="tty", RUN+="/bin/ln -s /dev/%k /dev/ttyUSB-radio"
AnswerB

This rule matches the tty subsystem and the device's serial attribute, then creates a persistent symbolic link named ttyUSB-radio. Using SYMLINK+ adds a link without removing existing ones, and ATTRS matches attributes of the device or its parents, which is appropriate for USB serial adapters whose serial number appears on the USB device.

Why this answer

A reliable udev rule for a USB serial adapter must match the tty subsystem and a unique attribute such as the adapter's serial number, then create a persistent symlink. ATTRS{serial} searches the device and its parent devices, which is where USB serial numbers are exposed. SYMLINK+ adds the link without disturbing other symlinks, ensuring the adapter is always reachable at /dev/ttyUSB-radio.

Exam trap

The trap here is matching on a non-unique attribute like vendor ID or using a USB subsystem rule, which either affects multiple devices or fails to name the tty node correctly.

209
MCQhard

A script produces both standard output and error messages. An administrator wants to save the output to 'out.log' and the error messages to 'err.log', but also wants to see both on the terminal. Which command achieves this?

A../script.sh 2>&1 | tee out.log 2>&1 | tee err.log
B../script.sh > >(tee out.log) 2> >(tee err.log)
C../script.sh > out.log 2> err.log
D../script.sh 2>&1 | tee out.log
AnswerB

Uses process substitution to duplicate stdout to terminal and out.log, and stderr to terminal and err.log.

Why this answer

Uses process substitution to redirect stdout and stderr into separate tee commands, which both write to files and pass the streams through to the terminal. The syntax `> >(tee out.log)` redirects stdout to a tee process that writes to out.log and also echoes to the terminal, while `2> >(tee err.log)` does the same for stderr. This ensures both streams are saved to separate files and displayed on the terminal simultaneously.

Exam trap

The trap here is that candidates often confuse `2>&1` (which merges stderr into stdout) with separate stream handling, leading them to pick options that either lose terminal output or fail to keep stdout and stderr in distinct files.

How to eliminate wrong answers

Option A is wrong because it redirects stderr to stdout with `2>&1`, then pipes both to `tee out.log`, but the subsequent `2>&1 | tee err.log` is applied to the output of the first tee, not to the original script's stderr; this mixes streams and does not separate stdout and stderr into distinct files. Option C is wrong because `./script.sh > out.log 2> err.log` sends stdout to out.log and stderr to err.log, but neither stream appears on the terminal — the administrator wants to see both on the terminal. Option D is wrong because `2>&1 | tee out.log` merges stderr into stdout and sends the combined stream to tee, which writes to out.log and the terminal, but stderr is not saved separately to err.log.

210
MCQhard

After creating a new user with 'useradd john', the user 'john' cannot log in. What is the most likely cause?

A.The home directory does not exist
B.No password has been set for the user
C.The user's shell is not set
D.The user is not in the sudoers file
AnswerB

useradd creates the account with a locked password field, so authentication fails until one is assigned. Running passwd john sets credentials, satisfying the login requirement; without it the account remains unusable regardless of shell or home directory.

Why this answer

The `useradd` command creates a new user account but does not set a password. Without a password, the system's authentication mechanism (typically PAM) will deny login attempts, as there is no valid password hash in `/etc/shadow`. The user must have a password assigned via `passwd john` before they can authenticate.

Exam trap

The trap here is that candidates assume `useradd` fully provisions an account, overlooking that password assignment is a separate mandatory step, and they may confuse login failure with missing home directory or shell issues.

How to eliminate wrong answers

Option A is wrong because `useradd` by default creates the home directory from `/etc/default/useradd` or `/etc/login.defs` unless explicitly overridden with `-M`; if it did not exist, the user would still be able to log in (though they might get a warning or land in `/`). Option C is wrong because `useradd` assigns a default shell (usually `/bin/sh` or `/bin/bash`) from `/etc/default/useradd`; if the shell is missing or invalid, login might fail, but the default is always set. Option D is wrong because membership in the sudoers file is irrelevant to basic login capability; sudo access is a privilege escalation mechanism, not a prerequisite for authentication.

211
Multi-Selecteasy

Which TWO options in /etc/fstab affect whether a filesystem is mounted at boot? (Choose two.)

Select 2 answers
A.user
B.defaults
C.auto
D.ro
E.noauto
AnswersC, E

The auto option marks the filesystem for mounting by mount -a, which the boot process invokes, so the entry is mounted at startup. Omitting it defaults to auto, but specifying it explicitly confirms boot mounting.

Why this answer

Option C (auto) is correct because it explicitly marks the filesystem as mountable by the mount -a command, which is what the boot process runs to mount all entries in /etc/fstab, so an entry with auto will be mounted at boot. Option E (noauto) is correct because it does the opposite: it tells mount -a to skip that entry, meaning the filesystem will not be mounted automatically at boot and must be mounted manually. The other options do not control boot-time mounting: A (user) permits non-root users to mount the filesystem, B (defaults) is a shorthand for rw,suid,dev,exec,auto,nouser,async (it includes auto but is a general option bundle, not the specific boot-mount toggle), and D (ro) only sets the filesystem read-only, which is unrelated to whether it is mounted at boot.

Exam trap

The trap here is that candidates often confuse 'auto' with 'defaults' or think 'ro' affects boot mounting, when in fact only 'auto' and 'noauto' directly control automatic mounting at boot.

212
MCQmedium

A Linux administrator needs to determine which kernel modules are currently loaded on a running system. The administrator also wants to see the module dependencies and the use count for each module. Which command should be used?

A.lsmod
B.depmod
C.modprobe -l
D.modinfo
AnswerA

lsmod reads /proc/modules and prints the currently loaded modules along with their size, use count, and dependencies. This directly matches the requirement to see loaded modules with dependencies and use counts. It is the standard tool for verifying whether a module such as a filesystem or network driver is active.

Why this answer

lsmod queries the kernel's loaded module list by reading /proc/modules and presents each module with its memory size, use count, and dependencies. That output lets an administrator confirm whether a needed driver is active and whether it is in use. Tools like modinfo and depmod operate on module files and metadata, not on the runtime state of loaded modules.

Exam trap

The trap here is confusing commands that inspect module files and metadata, such as modinfo or depmod, with the command that reports modules currently loaded in the running kernel.

213
MCQeasy

A system administrator wants to ensure that the filesystem on /dev/sdb1 is checked for errors every 30 mounts. Which command accomplishes this?

A.fsck -c 30 /dev/sdb1
B.e2fsck -c 30 /dev/sdb1
C.tune2fs -c 30 /dev/sdb1
D.mount -o errors=remount-ro
AnswerC

`tune2fs -c 30 /dev/sdb1` sets the maximum mount count to 30 on the ext2/3/4 filesystem, satisfying the requirement to trigger `e2fsck` after every 30 mounts. The `-c` flag directly controls this counter, whereas `-i` would set a time-based interval instead.

Why this answer

The `tune2fs` command is used to adjust tunable filesystem parameters on ext2/ext3/ext4 filesystems. The `-c` option sets the maximum mount count between filesystem checks; `tune2fs -c 30 /dev/sdb1` configures the filesystem to trigger an `fsck` check every 30 mounts. This is the correct tool for modifying this persistent setting.

Exam trap

The trap here is confusing the `-c` option of `tune2fs` (set mount count) with the `-c` option of `e2fsck` (bad-block check), leading candidates to mistakenly choose `e2fsck -c 30`.

How to eliminate wrong answers

Option A is wrong because `fsck` is a frontend that runs filesystem checks, not a tool to set mount-count parameters; `fsck -c 30` would attempt to check the filesystem and the `-c` option is not valid for setting mount intervals. Option B is wrong because `e2fsck` is the ext2/ext3/ext4 filesystem checker, and its `-c` option performs a bad-block scan, not a mount-count configuration. Option D is wrong because `mount -o errors=remount-ro` is a mount option that remounts the filesystem as read-only on error, but it does not schedule periodic checks based on mount count.

214
Multi-Selecteasy

Which TWO of the following commands can be used to create a new filesystem on a partition?

Select 2 answers
A.fdisk
B.mkfs.ext4
C.parted
D.fsck
E.mkfs
AnswersB, E

mkfs.ext4 is a filesystem-specific front end that builds an ext4 filesystem directly on a block device, writing superblocks, inode tables and journal structures. It satisfies the stem's requirement to create a new filesystem on a partition.

Why this answer

Option B, mkfs.ext4, is correct because it is a front-end to the mkfs family that specifically writes an ext4 filesystem onto a block device or partition, e.g. mkfs.ext4 /dev/sdb1. Option E, mkfs, is correct because it is the generic filesystem-creation utility that, when invoked with a type such as mkfs -t xfs /dev/sdb1, builds a new filesystem on the target partition. The unmarked options do not belong: fdisk (A) and parted (C) are partitioning tools that create/modify partition tables and partitions, not filesystems, and fsck (D) is a consistency-checking and repair utility for existing filesystems, not a creator.

Exam trap

The trap here is that candidates confuse partition management tools (fdisk, parted) with filesystem creation tools (mkfs), or mistakenly think fsck can create a filesystem because it interacts with filesystem metadata.

215
MCQhard

A systemd service unit file must be configured to automatically restart the service if it exits unexpectedly. Which directive should be used?

A.Type=forking
B.Restart=always
C.RemainAfterExit=yes
D.ExecStop=/bin/true
AnswerB

Restart=always instructs systemd to relaunch the unit whenever its main process terminates, regardless of exit status, satisfying the requirement to recover from unexpected exits. Other Restart values such as on-failure ignore clean exits, so they would not cover every case.

Why this answer

The `Restart=always` directive in a systemd service unit file instructs systemd to automatically restart the service regardless of the exit status, including unexpected crashes or terminations. This ensures high availability by restarting the process whenever it exits, unless explicitly stopped by systemctl. Other directives like `Type=forking` or `RemainAfterExit=yes` do not control restart behavior.

Exam trap

The trap here is that candidates confuse `Restart=always` with `Type=forking` or `RemainAfterExit=yes`, mistakenly thinking these directives handle automatic restarts, when in fact they address process forking or service state after exit.

How to eliminate wrong answers

Option A is wrong because `Type=forking` defines the service's startup behavior (expecting the process to fork and the parent to exit), not its restart policy. Option C is wrong because `RemainAfterExit=yes` tells systemd to consider the service as active even after the main process exits, but it does not trigger automatic restarts. Option D is wrong because `ExecStop=/bin/true` specifies a command to run when stopping the service, not a condition for automatic restart.

216
MCQmedium

A shell script uses the variable expansion ${var:-default} to set a default value for an environment variable. The script prints unexpected output when the variable is set to an empty string. Which expansion should be used to ensure the default is only used when the variable is unset, not when it is empty?

A.${var:-default}
B.${var-default}
C.${var:?default}
D.${var:=default}
AnswerB

${var-default} substitutes the default only when var is unset, whereas ${var:-default} also substitutes when var is set but empty. Using the single-colon-less form satisfies the stem's requirement that the default apply solely to unset variables, preserving intentional empty values.

Why this answer

The expansion `${var-default}` uses the default value only when the variable is unset (i.e., does not exist at all). In contrast, `${var:-default}` also substitutes the default when the variable is set but empty, which causes the unexpected output described in the question. The colon in the expansion is the critical difference: it adds the check for a null or empty string.

Exam trap

The trap here is that candidates often confuse the colon modifier, assuming `${var:-default}` and `${var-default}` behave identically, when in fact the colon adds the empty-string check that causes the unexpected behavior described in the question.

How to eliminate wrong answers

Option A is wrong because `${var:-default}` triggers the default when the variable is unset OR empty, which is exactly the behavior that produces the unexpected output when the variable is set to an empty string. Option C is wrong because `${var:?default}` causes the shell to exit with an error if the variable is unset or empty, rather than providing a default value. Option D is wrong because `${var:=default}` assigns the default value to the variable if it is unset or empty, modifying the variable itself, which is not the same as simply using a default without side effects.

217
MCQmedium

A junior administrator accidentally deleted a large log file that is still being written to by a running process. The file no longer appears in directory listings, but `df -h` shows the filesystem is still nearly full. Which command will reclaim the space without interrupting the running process?

A.Run sync to flush dirty pages and free the deleted file's blocks
B.lsof | grep deleted, then kill the process holding the file
C.truncate -s 0 /proc/<PID>/fd/<FD> using the file descriptor path
D.Run fsck on the filesystem to release orphaned inodes
AnswerC

When a file is unlinked but still open, its data blocks remain allocated until the last file descriptor closes. Truncating through the /proc/<PID>/fd/ path empties the file content while the process keeps its descriptor open, immediately freeing the blocks. The running process continues writing from its current offset, and the filesystem space is reclaimed without any service interruption.

Why this answer

An unlinked file that remains open keeps its inode and data blocks allocated until the last descriptor closes. Truncating the file through its /proc/<PID>/fd/ descriptor zeroes the content and frees the blocks while the process continues running, satisfying the requirement of no interruption. Diagnostics like lsof help locate the descriptor, but the reclamation itself must act on the open file.

Exam trap

The trap here is assuming that a deleted file immediately frees its disk space, when an open file descriptor keeps the blocks allocated until the process closes it or the file is truncated.

218
MCQeasy

A system administrator needs to install the latest version of a package named 'webapp' from a third-party repository that has been added to the system. Which command should be used to update the package list and install the package in one step?

A.apt-get update && apt-get install webapp
B.apt-get upgrade webapp
C.dpkg -i webapp.deb
D.apt-cache search webapp && apt-get install webapp
AnswerA

Chaining apt-get update with apt-get install refreshes the package lists from all configured sources, including the newly added third-party repository, then installs webapp in a single command. Without the update step, apt-get install would use stale metadata and fail to locate the latest version.

Why this answer

It first runs `apt-get update` to refresh the local package index from all configured repositories (including the third-party one), then uses `&&` to conditionally execute `apt-get install webapp` only if the update succeeds. This ensures the latest version available from the third-party repository is fetched and installed in a single command sequence.

Exam trap

The trap here is that candidates may think `apt-get upgrade` can install new packages, but it strictly upgrades existing packages and never installs new ones, while `apt-get install` alone does not refresh the package list, so the latest version from a newly added repository might not be available.

How to eliminate wrong answers

Option B is wrong because `apt-get upgrade` only upgrades already installed packages to their latest versions from the configured repositories; it does not install a new package that is not already present on the system. Option C is wrong because `dpkg -i webapp.deb` installs a local `.deb` file directly, bypassing repository metadata and dependency resolution, and it does not update the package list from a third-party repository. Option D is wrong because `apt-cache search webapp` only searches the local package cache for packages matching the name; it does not update the package list, and the `&&` would attempt `apt-get install webapp` even if the search fails or the cache is outdated.

219
MCQmedium

Refer to the exhibit. An administrator attempts to remount /mnt as read-only but receives the error shown. What is the most likely cause?

A.The /mnt directory is not a mount point
B.The /mnt directory is not empty
C.The /mnt directory does not exist
D.The filesystem is already mounted read-only
AnswerA

Remounting requires an existing mount point; if /mnt is merely an ordinary directory in the root filesystem, the kernel has no mount entry to modify and rejects the remount with an error. This matches the stem's constraint that the remount command fails.

Why this answer

The error 'mount: /mnt is not a mount point' indicates that the administrator attempted to use the `remount` option on a directory that is not currently a mount point. The `mount -o remount` command only works on directories where a filesystem is already mounted; it modifies the mount options of an existing mount, not a regular directory. Since /mnt is not a mount point, the kernel rejects the operation with this specific error.

Exam trap

The trap here is that candidates confuse the `remount` option (which modifies an existing mount) with the `mount` command (which creates a new mount), leading them to think the error is about directory emptiness or existence rather than the mount point status.

How to eliminate wrong answers

Option B is wrong because a non-empty directory can still be a mount point; the error message specifically says 'not a mount point', not 'not empty'. Option C is wrong because if /mnt did not exist, the error would be 'mount: /mnt: No such file or directory', not 'not a mount point'. Option D is wrong because if the filesystem were already mounted read-only, the `remount` command would succeed (it would just be a no-op) or produce a different error like 'mount: /mnt: cannot remount ...' but not 'not a mount point'.

220
MCQhard

When troubleshooting a problem with a Debian package installation, an administrator wants to see which version of a package would be installed from the configured repositories. Which command displays the candidate version?

A.dpkg -l package
B.apt-show-versions package
C.apt-get -s install package
D.apt-cache policy package
AnswerD

apt-cache policy queries the APT cache and prints, for each configured repository, the installed version and the candidate version that would be selected for installation, letting the administrator confirm which version the repositories currently offer.

Why this answer

The `apt-cache policy package` command displays the package's priority, the installed version (if any), and the candidate version (the version that would be installed by default from the configured repositories). This makes it the correct tool for determining which version will be installed from the repositories.

Exam trap

The trap here is that candidates often confuse `apt-get -s install` (a simulation) with the dedicated `apt-cache policy` command for querying the candidate version, or they mistakenly think `dpkg -l` or `apt-show-versions` provide repository-level candidate information.

How to eliminate wrong answers

Option A is wrong because `dpkg -l package` lists the status and version of an installed package, but it does not query repositories or show the candidate version from repositories. Option B is wrong because `apt-show-versions package` shows available and installed versions, but it is not the standard command for displaying the candidate version; `apt-cache policy` is the authoritative tool. Option C is wrong because `apt-get -s install package` performs a dry-run simulation of installation, which can show what would be installed, but it is not the dedicated command for viewing the candidate version; `apt-cache policy` is more direct and standard for this purpose.

221
MCQmedium

A Yellowdog Updater Modified (YUM) transaction that included several package installations and upgrades completed successfully, but a recent change caused a service to break. The administrator wants to revert the entire transaction using its transaction ID. Which command should be used?

A.yum history redo 123
B.yum remove <packages>
C.yum history rollback 123
D.yum history undo 123
AnswerD

`yum history undo 123` reverses every package installation, upgrade and downgrade recorded under transaction ID 123, restoring the exact prior versions in one operation. This directly satisfies the stem's requirement to revert the entire transaction by its ID, rather than selectively removing individual packages.

Why this answer

`yum history undo 123` reverts the specific transaction identified by ID 123, reversing all changes (installs, upgrades, removals) made in that transaction while preserving the current state of other packages. This is the intended command for rolling back a single transaction without affecting subsequent transactions.

Exam trap

The trap here is confusing `undo` (revert a single transaction) with `rollback` (revert all transactions after a given point), leading candidates to choose option C when they only want to reverse one transaction.

How to eliminate wrong answers

Option A is wrong because `yum history redo 123` repeats the actions of transaction 123, which would reapply the same changes that broke the service, not revert them. Option B is wrong because `yum remove <packages>` manually removes specific packages without using the transaction ID, and it cannot revert the entire transaction's set of changes (including upgrades) in one step. Option C is wrong because `yum history rollback 123` reverts all transactions after ID 123, returning the system to the state at the end of transaction 123, which is too aggressive if only that transaction needs to be undone and later transactions should be preserved.

222
MCQeasy

A system administrator needs to schedule a recurring maintenance task that runs every Monday at 3 AM. Which crontab entry is correct?

A.3 0 * * 1 /script.sh
B.0 3 * * 0 /script.sh
C.0 3 * * 7 /script.sh
D.0 3 * * 1 /script.sh
AnswerD

Correct: runs at 3:00 AM on Monday.

Why this answer

The crontab syntax is minute, hour, day of month, month, day of week. Setting minute=0, hour=3, day of week=1 runs the script at 3:00 AM every Monday (day 1 represents Monday in cron).

Exam trap

The trap here is confusing the day-of-week numbering (Monday=1 vs Sunday=0/7) and mixing minute and hour fields, leading candidates to select entries that run at the wrong time or on the wrong day.

How to eliminate wrong answers

Option A is wrong because it sets minute=3 and hour=0, which would run at 12:03 AM, not 3 AM. Option B is wrong because it sets day of week=0, which represents Sunday, not Monday. Option C is wrong because it sets day of week=7, which is not a valid day in standard cron (valid range is 0-6 or 1-7 depending on implementation, but 7 is ambiguous and not universally accepted; the correct Monday value is 1).

223
MCQmedium

A zombie process appears in the process list. The parent process has PID 1234. Which command will most likely remove the zombie?

A.kill -9 1234
B.kill -9 <zombie_pid>
C.wait <zombie_pid>
D.reboot
AnswerA

A zombie is already dead, so signalling it does nothing; only its parent can reap it. Killing PID 1234 with SIGKILL terminates the parent, after which init adopts and reaps the zombie, clearing it from the process table.

Why this answer

A zombie process is a child process that has terminated but whose exit status has not been read by its parent. The zombie cannot be killed directly because it is already dead; it only remains in the process table until the parent calls wait(). Sending SIGKILL (kill -9) to the parent process (PID 1234) causes the parent to terminate, and the zombie child is then adopted by init (PID 1), which automatically reaps it by calling wait().

Exam trap

The trap here is that candidates mistakenly think they can kill the zombie itself with kill -9, not realizing that a zombie is already dead and the only way to remove it is to force its parent to reap it or terminate the parent.

How to eliminate wrong answers

Option B is wrong because kill -9 on the zombie PID has no effect; the zombie is already dead and cannot be signaled. Option C is wrong because wait is a system call used by the parent, not a command that can be run from the shell to reap a zombie belonging to another process. Option D is wrong because rebooting is an extreme and unnecessary measure; it would remove the zombie but also disrupt all running processes and is not the standard or recommended solution.

224
MCQmedium

A system administrator is preparing a custom RPM package for internal distribution. The package must be built from source code and a spec file. Which command should be used to build the binary RPM from the spec file?

A.rpm -bb package.spec
B.rpmbuild -ba package.spec
C.rpmbuild -bb package.spec
D.rpmbuild -bs package.spec
AnswerC

The -bb option tells rpmbuild to build only the binary package from the specified spec file. This is the standard way to produce a binary RPM when the source and spec files are already in place. It performs the build steps defined in the spec's %build section and packages the resulting files according to the %files list.

Why this answer

The rpmbuild command with the -bb option compiles the source and creates a binary RPM from the spec file. This is the correct tool for building packages from source on RPM-based systems. The -ba option would also produce a binary RPM but additionally creates a source RPM, which is not required when only the binary package is needed.

Exam trap

The trap here is confusing the rpm command with rpmbuild, or selecting an option that builds source RPMs instead of binary RPMs.

225
MCQhard

According to FHS, which directory should NOT be mounted on a networked filesystem (e.g., NFS) because it contains host-specific configuration files?

A./home
B./var
C./etc
D./opt
AnswerC

/etc holds host-specific configuration such as fstab, passwd and network settings. Sharing it over NFS would let one machine's configuration override another's, so FHS expects /etc to remain local to each host rather than mounted remotely.

Why this answer

The Filesystem Hierarchy Standard (FHS) specifies that /etc contains host-specific configuration files that must be local to each machine. Mounting /etc over a network filesystem like NFS would cause all clients to share the same configuration, breaking system identity, network settings, and security policies. This violates the FHS requirement that /etc be a local filesystem.

Exam trap

The trap here is that candidates may think /var or /home are the correct answers because they contain user data or logs, but the FHS specifically singles out /etc as the directory that must remain local due to its host-specific configuration files.

How to eliminate wrong answers

Option A is wrong because /home is designed to be shared across networked systems via NFS, allowing user home directories to be accessed from any client. Option B is wrong because /var contains variable data such as logs and spools that can be shared or local, but it is not specifically prohibited from NFS mounting by the FHS. Option D is wrong because /opt is for add-on software packages and can be shared over NFS if the software is identical across hosts, though it is not host-specific like /etc.

Page 2

Page 3 of 6

Page 4

All pages