Courseiva

Linux Professional Institute Certification Level 1 LPIC-1 (LPIC-1) — Questions 226–300

402 questions total · 6pages · All types, answers revealed

Page 3

Page 4 of 6

Page 5
226
MCQhard

Refer to the exhibit. A Linux system fails to boot with a kernel panic. The dmesg output shows the disk is detected and partitions are recognized. Which of the following is the most likely cause of the kernel panic?

A.The root filesystem cannot be mounted because the root= kernel parameter points to a non-existent or incorrect device.
B.The kernel module for the SATA controller is missing from the initramfs.
C.The SATA controller is not supported by the kernel.
D.The disk has bad sectors causing read errors during boot.
AnswerA

Kernel panic after disk and partition detection indicates the kernel cannot mount the root filesystem. An incorrect root= parameter points to a non-existent device, so the kernel halts with a panic once it fails to locate the root filesystem.

Why this answer

A is correct because the kernel panic occurs after the disk and partitions are detected, indicating the kernel can see the hardware but cannot mount the root filesystem. The most common cause is an incorrect or missing `root=` kernel parameter in the bootloader configuration (e.g., GRUB), which specifies the root device (e.g., `/dev/sda1` or `UUID=...`). If this parameter points to a non-existent or wrong partition, the kernel cannot pivot to the root filesystem, leading to a panic.

Exam trap

The trap here is that candidates see the disk is detected and assume hardware is fine, then incorrectly blame the SATA controller or initramfs, missing the subtle point that the kernel panic occurs specifically because the root filesystem cannot be mounted due to a misconfigured `root=` parameter.

How to eliminate wrong answers

Option B is wrong because if the SATA controller module were missing from the initramfs, the disk would not be detected at all, but the dmesg output shows the disk is detected and partitions are recognized. Option C is wrong because the SATA controller is clearly supported by the kernel, as the disk is detected and partitions are recognized, contradicting a lack of support. Option D is wrong because bad sectors causing read errors would typically produce I/O errors or filesystem corruption messages, not a kernel panic at the stage where the root filesystem cannot be mounted; the panic occurs before any filesystem read attempts.

227
MCQeasy

A junior administrator is asked to verify which TCP ports are listening on a Linux server and which processes own them. Which command provides this information directly?

A.netstat -r
B.lsof -i :22
C.ip link show
D.ss -tulpn
AnswerD

ss is the modern replacement for netstat. The flags -t (TCP), -u (UDP), -l (listening), -p (processes), and -n (numeric) together show all listening TCP and UDP sockets with numeric ports and the associated process. This directly answers which ports are open and which programs own them.

Why this answer

The ss command with -tulpn is the standard tool on modern Linux to list listening TCP and UDP sockets, show numeric addresses, and map them to owning processes. Netstat -r shows routes, ip link show displays interface state, and lsof -i :22 is limited to a single port. Only ss -tulpn provides a comprehensive view of all listening ports and their processes.

Exam trap

The trap here is assuming any netstat or ip command will show listening ports, when only specific flags like -tulpn or ss -tulpn do so.

228
MCQmedium

Based on the dpkg -l output in the exhibit, what does the 'rc' status indicate for the apache2 package?

A.The package was removed but configuration files remain.
B.The package is unpacked but not configured.
C.The package is installed and configured.
D.The package is completely purged.
AnswerA

In dpkg status output, the first letter 'r' means the package was removed, and the second letter 'c' means only its configuration files remain on the system. This matches the 'rc' state shown for apache2.

Why this answer

In dpkg, the 'rc' status means the package has been removed (the 'r' flag) but its configuration files remain on the system (the 'c' flag). This occurs when you use 'apt-get remove' or 'dpkg -r' without the --purge option, leaving behind files like /etc/apache2/*. The 'c' indicates that the package's conffiles (as listed in its control data) have not been deleted, allowing for potential reinstallation with previous settings preserved.

Exam trap

The trap here is that candidates confuse 'rc' with a fully removed or purged state, not realizing that the 'c' flag specifically means configuration files persist, which is a common oversight when interpreting dpkg status output.

How to eliminate wrong answers

Option B is wrong because 'unpacked but not configured' is represented by 'iU' (intended to be unpacked) or 'u' (unpacked) in dpkg status, not 'rc'. Option C is wrong because 'installed and configured' is shown as 'ii' (both flags set to 'i' for installed and configured), not 'rc'. Option D is wrong because 'completely purged' would show a blank status or 'pn' (purged and not installed), meaning no package files or configuration files remain; 'rc' explicitly indicates configuration files are still present.

229
Matchingmedium

Match each Linux command to its primary function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Search text using patterns

Change file permissions

Report snapshot of current processes

Archive files

Stream editor for filtering and transforming text

Why these pairings

The correct matches are: cp for copying files, grep for searching text, and chmod for changing permissions. Common confusions include mixing these commands due to similar syntax or overlapping contexts.

230
MCQhard

An ext4 filesystem is experiencing performance degradation due to very frequent small writes. Which tune2fs option can help by reserving a percentage of blocks for the root user to prevent fragmentation?

A.-i 0
B.-g root
C.-c 0
D.-m 0
AnswerB

The -g option sets the group that can use the reserved blocks. Specifying 'root' ensures that the reserved blocks are available to the root group, which can help prevent fragmentation by keeping free space contiguous for root's small writes.

Why this answer

The -g option in tune2fs sets the group that can use the reserved blocks. By specifying 'root', it assigns the reserved blocks to the root group, ensuring that the root user can access this reserved space. This helps prevent fragmentation by keeping free blocks available for root's small writes, rather than allowing the filesystem to become completely full.

Options A and C are unrelated to block reservation. Option D sets the reserved block percentage to 0, which does not reserve any blocks and can actually increase fragmentation.

Exam trap

The trap is that candidates often think -m 0 helps by removing reserved blocks, but the question specifically asks for an option that reserves a percentage. The correct answer is -g root, which works in conjunction with the default or set reserved blocks to ensure they are available for root.

How to eliminate wrong answers

Option A is wrong because `-i 0` disables the filesystem check interval (i.e., maximum time between checks), which does not affect block reservation or fragmentation from small writes. Option B is wrong because `-g root` is not a valid tune2fs option; the `-g` option is used to specify a group for reserved blocks, but it requires a group ID or name, and 'root' is not a valid group specification in this context. Option C is wrong because `-c 0` sets the maximum mount count between filesystem checks to 0, disabling checks based on mount count, which has no impact on block reservation or fragmentation.

231
MCQeasy

Refer to the exhibit. What is the file permission in numeric mode for /etc/crontab?

A.644
B.600
C.444
D.755
AnswerA

Numeric 644 grants the owner read and write (4+2), group read (4) and others read (4), matching the exhibit's rw-r--r-- permissions on /etc/crontab. This satisfies the requirement to express that file's permission in numeric mode.

Why this answer

The /etc/crontab file is a system-wide configuration file for cron jobs. It must be readable by all users to allow cron to read the scheduled tasks, but only writable by root to prevent unauthorized modifications. The standard permission is 644 (owner read/write, group read, others read).

Exam trap

The trap here is that candidates often confuse the permissions for /etc/crontab with those for user crontab files (which are stored in /var/spool/cron/ and typically have 600 permissions) or mistakenly think that execute permission is needed for configuration files.

How to eliminate wrong answers

Option B (600) is wrong because it would make the file readable only by root, preventing the cron daemon from reading the file when it runs as a non-root user. Option C (444) is wrong because it removes write permission for the owner (root), making it impossible to edit the crontab file without changing permissions first. Option D (755) is wrong because it grants execute permission to all users, which is unnecessary and a security risk for a text configuration file.

232
MCQhard

A system has multiple APT repositories configured. The administrator needs to ensure that for a specific package, the version from a particular repository is always preferred over others, regardless of version number. Which configuration would achieve this?

A.Editing /etc/apt/sources.list and setting the release in sources.list
B.Using apt-mark hold on the package after installing from desired repository
C.Creating a file in /etc/apt/preferences.d/ with a high Pin-Priority for that package and origin
D.Adding the repository and using apt-get install -t release package
AnswerC

APT pinning uses Pin-Priority values in /etc/apt/preferences.d/ to override version comparison. Assigning a high priority to a specific package and origin forces that repository's version to be selected regardless of whether another repository offers a numerically higher version.

Why this answer

APT's pinning mechanism, configured via files in /etc/apt/preferences.d/, allows an administrator to assign a high Pin-Priority to a specific package from a particular origin (repository). This ensures that version is always preferred during dependency resolution and upgrades, overriding the default version comparison logic.

Exam trap

The trap here is that candidates confuse apt-mark hold (which only freezes the installed version) with APT pinning (which controls version selection from repositories), leading them to choose option B instead of the correct pinning configuration.

How to eliminate wrong answers

Option A is wrong because editing /etc/apt/sources.list to set the release only controls which distribution release is used for all packages, not pinning a specific package from a specific repository. Option B is wrong because apt-mark hold prevents the package from being upgraded or changed, but it does not enforce a preference for a particular repository's version; it simply locks the current installed version. Option D is wrong because apt-get install -t release package temporarily targets a specific release for installation, but it does not create a persistent preference for that repository's version over others in future operations.

233
MCQmedium

An administrator needs to mount an ISO image located at /tmp/install.iso to the directory /mnt/iso. Which command will accomplish this?

A.mount --bind /tmp/install.iso /mnt/iso
B.mount -o remount,loop /tmp/install.iso /mnt/iso
C.mount -o loop /tmp/install.iso /mnt/iso
D.mount -t iso9660 /tmp/install.iso /mnt/iso
AnswerC

The -o loop option tells mount to use a loop device, which allows a file to be mounted as a block device. This is the standard way to mount an ISO image. The command mounts the ISO to the specified directory, making its contents accessible.

Why this answer

Mounting an ISO image requires the loop option to associate the file with a loop device, which the kernel then treats as a block device. The mount command with -o loop is the correct syntax. Other options either omit loop, use bind incorrectly, or attempt to remount a non-mounted filesystem.

Exam trap

The trap here is forgetting that regular files require the loop option to be mounted as filesystems.

234
MCQhard

Refer to the exhibit. The 'mount -a' command fails for the NFS mount. What is the most likely cause?

A.The local mount point /mnt/nfs does not exist.
B.The filesystem type 'nfs' is not supported by the kernel.
C.The NFS server is not exporting the directory or is unreachable.
D.The 'defaults' option is missing for the NFS entry.
AnswerC

The mount fails because the client cannot reach the server or the export is absent; 'mount -a' relies on the server's export list and network reachability. Neither /etc/fstab syntax nor local mount options cause this, so an unexported or unreachable NFS server is the likely cause.

Why this answer

The 'mount -a' command reads /etc/fstab and attempts to mount all entries. For an NFS mount, the most common failure is that the NFS server is not exporting the specified directory or is unreachable, which causes the mount to fail with an error like 'mount.nfs: access denied by server while mounting' or 'mount.nfs: No route to host'. This is the correct answer because network-based filesystem mounts depend on server availability and export configuration.

Exam trap

LPI exams frequently test the distinction between local mount point existence and network service availability, tricking candidates into thinking a missing mount point is the cause when the real issue is server-side or network connectivity.

How to eliminate wrong answers

Option A is wrong because if the local mount point /mnt/nfs did not exist, the mount command would fail with a 'mount point does not exist' error, but the question states the failure is specifically for the NFS mount, implying other mounts succeed, and a missing mount point would affect any mount, not just NFS. Option B is wrong because if the kernel did not support the 'nfs' filesystem type, the mount would fail for all NFS mounts, but the question implies a specific NFS entry fails, and modern kernels typically include NFS support as a module or built-in; a missing kernel module would produce a 'mount: unknown filesystem type' error, which is not the most likely cause in a typical scenario. Option D is wrong because the 'defaults' option is not required for NFS mounts; it is a shorthand for a set of default mount options (like rw, suid, dev, exec, auto, nouser, async) but omitting it does not cause the mount to fail—the mount will still proceed with explicit options or defaults from the kernel.

235
MCQhard

A system administrator wants to ensure that the syslog service starts automatically on boot and is running immediately without a reboot. Which command sequence should be used?

A.systemctl start syslog && systemctl enable syslog
B.systemctl start --enable syslog
C.systemctl enable syslog && systemctl start syslog
D.systemctl enable --now syslog
AnswerD

`systemctl enable --now syslog` satisfies both constraints in one invocation: `enable` creates the persistent symlink so the unit starts at every boot, while `--now` additionally starts it immediately in the current session, avoiding the reboot the stem forbids.

Why this answer

`systemctl enable --now syslog` combines enabling the service to start automatically on boot and starting it immediately in a single command. The `--now` flag triggers an immediate start after enabling, fulfilling both requirements without needing a reboot.

Exam trap

The trap here is that candidates may think they need to use two separate commands (enable and start) in a specific order, but the `--now` flag is a single-command shortcut that systemd provides, and LPI often tests this to see if you know the combined option exists.

How to eliminate wrong answers

Option A is wrong because it starts the service before enabling it; while this works, it is less efficient than using `--now`, and the order is not the issue—the command sequence is valid but not the best practice. Option B is wrong because `systemctl start --enable` is not a valid syntax; `--enable` is not a flag for `start`, and this command would fail. Option C is wrong because it enables the service first and then starts it, which is functionally correct but less efficient than using `--now`; however, the question asks for the command sequence that should be used, and `systemctl enable --now` is the idiomatic, single-command solution.

236
MCQmedium

A junior administrator needs to extract only the lines containing the word 'ERROR' from /var/log/syslog, but the log may have inconsistent casing (e.g., 'ERROR', 'Error', 'error'). Which command will print all such lines while ignoring case?

A.grep -v 'ERROR' /var/log/syslog
B.grep -i 'ERROR' /var/log/syslog
C.grep 'ERROR' /var/log/syslog
D.grep -c 'ERROR' /var/log/syslog
AnswerB

The -i option makes grep perform a case-insensitive match, so it will match 'ERROR', 'Error', 'error', and any other casing. This directly satisfies the requirement to catch inconsistent casing without needing multiple patterns or preprocessing. Other options either do not ignore case or misinterpret the pattern.

Why this answer

To extract lines with any casing of 'ERROR', the case-insensitive option -i must be used with grep. This allows matching 'ERROR', 'Error', 'error', etc., in a single command. The other grep invocations either do not ignore case, invert the match, or count lines instead of displaying them, so they fail to meet the scenario's need.

Exam trap

The trap here is assuming that grep is case-insensitive by default or that a simple pattern without flags will catch all casings.

237
MCQmedium

Refer to the exhibit. What will be the default permissions of a newly created file using the touch command?

A.-rw-r--r--
B.-rw-rw-rw-
C.-rwxr-xr-x
D.-rw-rw-r--
AnswerA

A newly created file receives the base mode 666 masked by the umask. With the default umask 022, write permission for group and others is removed, leaving rw- for the owner and r-- for group and others, giving -rw-r--r--.

Why this answer

The `touch` command creates a file with default permissions determined by the current umask value. On most Linux systems, the default umask is 0022, which subtracts write permissions for group and others from the base permissions of 0666 (rw-rw-rw-), resulting in 0644 (rw-r--r--). Thus, option A is correct.

Exam trap

The trap here is that candidates often confuse the base permissions (0666) with the final permissions, forgetting to apply the umask, or they mistakenly think touch sets execute bits like a directory creation would.

How to eliminate wrong answers

Option B is wrong because -rw-rw-rw- (0666) would require a umask of 0000, which is not the default; it represents the base permissions before umask is applied. Option C is wrong because -rwxr-xr-x (0755) is a typical permission set for directories or executable files, not for a new file created by touch, which never sets execute bits by default. Option D is wrong because -rw-rw-r-- (0664) would result from a umask of 0002, common in some environments but not the default umask of 0022 on most Linux distributions.

238
MCQhard

A system administrator needs to perform incremental backups of a large directory /data. The backup strategy requires a full backup every Sunday and incremental backups on weekdays. Which tar command satisfies this requirement using the --listed-incremental option?

A.Full: tar -czvf /backup/full.tar.gz /data; Incremental: tar -czvf /backup/incr.tar.gz --after-date '1 day ago' /data
B.Full: tar -cvf /backup/full.tar /data; Incremental: tar -cvf /backup/incr.tar -N 'last Sunday' /data
C.Full: tar -cvf /backup/full.tar --newer /data; Incremental: tar -cvf /backup/incr.tar --newer /backup/full.tar /data
D.Full: tar -cvf /backup/full.tar -g /var/backup/snapshot /data; Incremental: tar -cvf /backup/incr.tar -g /var/backup/snapshot /data
AnswerD

The -g flag with a shared snapshot file lets tar record file states, so the first run captures everything and later runs store only changes since that snapshot. Reusing /var/backup/snapshot across both commands satisfies the full-then-incremental requirement.

Why this answer

The `--listed-incremental` (or `-g`) option in tar creates and uses a snapshot file to track changes between backups. By specifying the same snapshot file for both the full and incremental backups, tar automatically records which files have changed since the last full backup, enabling proper incremental backups without relying on timestamps or file modification times.

Exam trap

The trap here is that candidates often confuse timestamp-based options like `--newer` or `-N` with the snapshot-based `--listed-incremental` mechanism, assuming any time-based filter can achieve incremental backups, but only `-g` provides the metadata tracking needed for proper incremental archives.

How to eliminate wrong answers

Option A is wrong because `--after-date` is not a valid tar option; the correct option for time-based filtering is `--newer` or `-N`, and using a relative time like '1 day ago' does not integrate with the `--listed-incremental` mechanism for reliable incremental backups. Option B is wrong because `-N 'last Sunday'` uses a timestamp-based filter that does not create a snapshot file, so subsequent incremental backups would not correctly track changes relative to the full backup; also, the full backup command lacks the `-g` option needed for incremental tracking. Option C is wrong because `--newer` compares file modification times against a file's timestamp, not against a snapshot; using `--newer /backup/full.tar` would include any file modified after the full archive was created, but it does not handle deletions or renames and is not the intended use of `--listed-incremental`.

239
MCQeasy

An administrator needs to install a package named 'nginx' on a Debian system, but the package is already installed. The administrator wants to ensure that the latest available version from the configured repository is installed, upgrading if necessary. Which command should be used?

A.dpkg -i nginx
B.apt-get reinstall nginx
C.apt-get install nginx
D.apt-get upgrade nginx
AnswerC

apt-get install will check if nginx is already installed and, if a newer version is available in the repository, it will upgrade to that version. If no newer version exists, it reports that the package is already the newest version. This satisfies the requirement to install or upgrade as needed.

Why this answer

apt-get install nginx will install the package if not present, or upgrade it to the newest version if one is available in the repositories. It automatically handles dependencies and is the standard method for ensuring a package is at the latest available version on Debian systems.

Exam trap

The trap here is assuming that apt-get install will skip an already installed package, when in fact it will upgrade it if a newer version is available.

240
MCQmedium

An administrator needs to downgrade a package from version 2.0 to version 1.9. Which apt-get command can be used to perform this action?

A.`apt-get downgrade package=1.9`
B.`apt-get upgrade package=1.9`
C.`apt-get dist-upgrade package=1.9`
D.`apt-get install package=1.9`
AnswerD

`apt-get install package=1.9` pins the exact version by appending `=1.9` to the package name, so APT resolves and installs 1.9 even though 2.0 is already present and newer. This satisfies the downgrade requirement directly, since APT permits installing an older version when the version is explicitly specified.

Why this answer

The correct command is `apt-get install package=1.9` because in APT, the `install` command is used not only to install new packages but also to downgrade an existing package to a specific version by appending `=version` to the package name. This instructs APT to resolve dependencies and perform the downgrade, overriding the currently installed version.

Exam trap

The trap here is that candidates often assume a dedicated `downgrade` command exists (Option A) or confuse `upgrade`/`dist-upgrade` with the ability to specify a version, when in fact `apt-get install` is the universal command for installing, upgrading, or downgrading a package to a specific version.

How to eliminate wrong answers

Option A is wrong because `apt-get downgrade` is not a valid APT command; APT does not have a dedicated `downgrade` subcommand. Option B is wrong because `apt-get upgrade` only upgrades packages to the latest version available in the repository and does not accept a version specifier; it cannot be used to downgrade. Option C is wrong because `apt-get dist-upgrade` (now `full-upgrade`) handles dependency changes during major upgrades but does not accept a version specifier and is not intended for downgrading a single package to a specific version.

241
Multi-Selecthard

Which THREE statements are true about the sed command?

Select 3 answers
A.sed 's/old/new/g' file.txt permanently changes the file.
B.sed -i 's/foo/bar/g' file.txt replaces all occurrences of foo with bar in the file.
C.sed uses extended regular expressions by default.
D.sed '/^#/d' file.txt deletes lines that start with #.
E.sed -n '3,5p' file.txt prints lines 3 to 5 of file.txt.
AnswersB, D, E

The `-i` flag edits file.txt in place, so no redirection or temporary file is needed. Combined with the `g` substitution flag, sed replaces every occurrence of foo on each matched line, not merely the first. This satisfies the requirement of replacing all occurrences directly within the file.

Why this answer

Option B is correct because the -i flag enables in-place editing, so sed -i 's/foo/bar/g' file.txt rewrites file.txt directly, replacing every occurrence of foo with bar due to the g (global) flag. Option D is correct because the address /^#/ matches lines beginning with # and the d command deletes them, so sed '/^#/d' file.txt removes comment lines from the output. Option E is correct because -n suppresses default output and the address range 3,5 with the p command prints only lines 3 through 5.

Option A is wrong because without -i sed writes results to stdout, leaving file.txt unchanged. Option C is wrong because sed uses basic regular expressions by default; extended regex requires the -E or -r option.

Exam trap

The trap here is that candidates often assume sed always modifies files in place, forgetting that without `-i`, sed only outputs to stdout, and that sed defaults to basic regular expressions, not extended ones.

242
MCQhard

An administrator is troubleshooting a DNS issue. The command 'dig @8.8.8.8 example.com' returns a response, but 'host example.com' returns 'Host not found'. Which of the following is the most likely cause?

A.The network interface is down.
B.The /etc/hosts file is corrupt.
C.The DNS server at 8.8.8.8 is not responding.
D.The /etc/resolv.conf file is misconfigured.
AnswerD

The `host` command queries the resolver configured in /etc/resolv.conf, whereas `dig @8.8.8.8` bypasses that file by querying the specified server directly. Since the explicit query succeeds, the resolver configuration must be faulty, satisfying the stem's constraint that only the default lookup path fails.

Why this answer

The command 'dig @8.8.8.8 example.com' succeeds, proving that the DNS server at 8.8.8.8 is reachable and functional, and that network connectivity is fine. However, 'host example.com' fails because it uses the system's default resolver, which reads /etc/resolv.conf to determine which DNS server to query. If /etc/resolv.conf is misconfigured (e.g., missing or incorrect nameserver entries), the resolver cannot reach a valid DNS server, resulting in 'Host not found'.

Exam trap

The trap here is that candidates see a successful 'dig' and assume DNS is fully working, not realizing that 'dig' with an explicit server bypasses the local resolver configuration, while 'host' relies on /etc/resolv.conf.

How to eliminate wrong answers

Option A is wrong because if the network interface were down, 'dig @8.8.8.8' would also fail (no route to host). Option B is wrong because the /etc/hosts file is used for local hostname resolution before DNS; a corrupt file could cause incorrect mappings but would not cause a 'Host not found' error when the DNS query itself fails—the resolver would still attempt DNS. Option C is wrong because the 'dig @8.8.8.8' command succeeded, directly proving that 8.8.8.8 is responding.

243
MCQeasy

A user wants to view the contents of a large text file one page at a time, with the ability to scroll both forward and backward. Which command should the user employ?

A.tail
B.head
C.cat
D.less
AnswerD

The less command is a pager that displays text one screen at a time and allows scrolling forward and backward using arrow keys, Page Up/Down, and search. It is designed for viewing large files without loading the entire file into memory, making it the ideal choice for this scenario.

Why this answer

The less command is specifically designed for paging through text files, allowing forward and backward scrolling, searching, and other navigation. Unlike cat, which dumps the entire file, or head/tail, which show only portions, less provides an interactive viewing experience ideal for large files. It is a standard tool in Linux environments.

Exam trap

The trap here is assuming that cat or head/tail can provide interactive paging; they cannot, as they output content without user-controlled scrolling.

244
MCQhard

Based on the exhibit, what will happen if the syslog service is stopped?

A.Apache2 will be stopped because it depends on syslog
B.The system will prompt to restart syslog before stopping
C.Apache2 will be automatically restarted because it requires syslog
D.Apache2 will continue running because the dependency is a soft dependency
AnswerD

Stopping syslog does not halt Apache2 because systemd's `After=` and `Wants=` directives create only ordering and soft dependency relationships, not hard `Requires=` bindings. Apache2 therefore continues running and serving requests; only log delivery via syslog is lost. This satisfies the stem's constraint that the web service remains available.

Why this answer

In Linux, services managed by systemd can have dependencies declared as 'Requires' (hard) or 'Wants' (soft). A soft dependency means that the dependent service (Apache2) does not require the target service (syslog) to be running; it will continue to operate even if syslog is stopped. The exhibit likely shows a 'Wants' directive, which does not enforce a strict ordering or runtime requirement.

Exam trap

The trap here is that candidates confuse 'Wants' (soft dependency) with 'Requires' (hard dependency), assuming any dependency means the dependent service will be stopped or restarted when the target service changes.

How to eliminate wrong answers

Option A is wrong because Apache2 will not be stopped when syslog is stopped; a soft dependency (Wants) does not cause cascading stops. Option B is wrong because systemd does not prompt the user to restart a service before stopping another; it simply proceeds with the stop operation. Option C is wrong because Apache2 will not be automatically restarted when syslog is stopped; soft dependencies do not trigger restarts of dependent units.

245
MCQeasy

A Linux system fails to boot after installing a new kernel. Which step should be taken first to recover the system?

A.Edit GRUB configuration at boot to select the old kernel
B.Reinstall the original kernel using a live CD
C.Boot into single-user mode to fix the kernel
D.Use the rescue mode from installation media
AnswerA

Selecting the previous kernel from the GRUB menu at boot bypasses the faulty new kernel, restoring a bootable system immediately. This is the fastest recovery step, since the old kernel and its modules remain intact on disk, allowing later diagnosis of the new kernel.

Why this answer

When a new kernel fails to boot, the quickest recovery method is to select the previous working kernel from the GRUB boot menu. GRUB typically retains the old kernel entry in its menu (e.g., 'Advanced options for Ubuntu' or a similar submenu), allowing you to boot the system without any external media or reinstallation. This approach avoids the overhead of using a live CD or rescue mode and directly restores functionality.

Exam trap

The trap here is that candidates often assume a failed kernel boot requires external recovery media (live CD or rescue mode) or single-user mode, forgetting that GRUB’s boot menu already provides direct access to the old kernel without any additional tools.

How to eliminate wrong answers

Option B is wrong because reinstalling the original kernel using a live CD is unnecessary and time-consuming; the old kernel is already present on the disk and accessible via GRUB. Option C is wrong because single-user mode still requires a bootable kernel; if the new kernel fails to load, you cannot reach single-user mode without first selecting a working kernel. Option D is wrong because rescue mode from installation media is a valid recovery method but is a more drastic step that should only be used if the GRUB menu itself is corrupted or the old kernel entry is missing.

246
MCQmedium

A technician is tasked with installing a package from a third-party repository on a CentOS 7 system. What is the correct first step to add the repository?

A.Run 'yum localinstall' with the repository URL.
B.Create a .repo file in /etc/yum.repos.d/.
C.Edit /etc/yum.conf and add the repository URL.
D.Use 'yum-config-manager --add-repo' without any further steps.
AnswerB

CentOS 7 uses YUM/DNF, which reads repository definitions from .repo files under /etc/yum.repos.d/. Creating that file with the repository's baseurl and GPG settings registers the third-party source, making its packages installable. This is the prerequisite before any install command.

Why this answer

On CentOS 7, third-party repositories are added by placing a .repo file in /etc/yum.repos.d/. This file defines the repository ID, name, baseurl, and GPG check settings. Yum reads all .repo files in this directory at runtime, making it the standard and correct first step for adding a repository.

Exam trap

The trap here is that candidates confuse editing /etc/yum.conf (which is for global yum options, not repository definitions) with the correct method of adding a .repo file, or they assume 'yum localinstall' can add a repository when it only installs a single package.

How to eliminate wrong answers

Option A is wrong because 'yum localinstall' installs a local RPM package, not a repository; it does not add a repository URL. Option C is wrong because /etc/yum.conf is the main configuration file for yum, but it is not designed to hold repository definitions—those belong in separate .repo files under /etc/yum.repos.d/. Option D is wrong because 'yum-config-manager --add-repo' is a valid command on CentOS 7, but it requires the repository URL as an argument (e.g., 'yum-config-manager --add-repo http://example.com/repo.repo') and does not work 'without any further steps'; the option incorrectly implies it can be used without specifying the URL.

247
Multi-Selecthard

Which THREE of the following are valid symbolic mode expressions for the chmod command?

Select 3 answers
A.u+x
B.755
C.a+rwx
D.c+r
E.g-w
AnswersA, C, E

`u+x` grants execute permission to the file's owner, using the symbolic form `[ugoa][+-=][rwxXst]`. It satisfies the stem's requirement for a valid symbolic mode expression, since `u` selects user class, `+` adds permission, and `x` specifies execute.

Why this answer

Option A (u+x) is a valid symbolic mode because it specifies the user class 'u' and adds (+) the execute permission, which is standard chmod symbolic syntax. Option C (a+rwx) is valid because 'a' represents all three permission classes (user, group, and other) and +rwx grants read, write, and execute to each. Option E (g-w) is valid because it targets the group class 'g' and removes (-) the write permission.

Option B (755) is not a symbolic mode but an octal (numeric) mode, which uses digits rather than letters and operators. Option D (c+r) is invalid because 'c' is not a recognized permission class in chmod; the valid classes are u, g, o, and a.

Exam trap

The trap here is that candidates may confuse numeric (octal) modes with symbolic modes, or assume that any single-letter class like 'c' is valid, when only u, g, o, and a are recognized by the chmod command.

248
MCQeasy

Refer to the exhibit. An administrator installed a new command in /opt/bin/ but cannot run it without specifying the full path. What is the likely cause?

A.The command is not in the PATH.
B.The command is an alias that conflicts.
C.The command has no execute permission.
D.The command is a function that overrides.
AnswerA

The shell searches only directories listed in PATH when resolving bare command names. Since /opt/bin is absent from PATH, the binary is unfindable without its full path. Adding that directory to PATH restores normal lookup.

Why this answer

The administrator installed the command in /opt/bin/, but the shell cannot find it without the full path because /opt/bin/ is not listed in the PATH environment variable. The PATH variable defines the directories the shell searches for executable commands; if a directory is omitted, commands within it must be invoked with an absolute or relative path.

Exam trap

The trap here is that candidates may confuse a missing PATH entry with a permission issue, but the key clue is that the command runs when the full path is specified, which rules out permission problems and points directly to the PATH variable.

How to eliminate wrong answers

Option B is wrong because an alias conflict would cause the shell to run a different command or produce an error when the alias is defined, but it would not prevent running the command by its full path; the issue here is that the command is not found at all without the full path. Option C is wrong because if the command lacked execute permission, running it with the full path would produce a 'Permission denied' error, not a 'command not found' error; the administrator can run it with the full path, so execute permission is present. Option D is wrong because a function override would replace a command name in the shell session, but the command would still be executable by its full path; the problem is that the shell cannot locate the command in the default search path.

249
MCQeasy

Refer to the exhibit. Based on the apt-cache showpkg output, which version of vim would be installed if the administrator runs 'apt-get install vim' without specifying a version?

A.2:8.2.3995-1ubuntu1 from focal-updates
B.2:8.2.3995-1ubuntu2.1 from focal
C.2:8.2.3995-1ubuntu1 from focal
D.2:8.2.3995-1ubuntu2.1 from focal-updates
AnswerD

Newest version available.

Why this answer

When no version is specified, apt-get install selects the highest version number from the highest-priority repository. Here, version 2:8.2.3995-1ubuntu2.1 is higher than 2:8.2.3995-1ubuntu1, and focal-updates typically has a higher priority than focal (unless overridden by pinning). Therefore, the candidate version from focal-updates (option D) is installed.

Exam trap

The trap here is that candidates often assume the repository with the highest priority (e.g., focal-updates) always wins, but APT actually selects the highest version number first, and only uses priority as a tiebreaker when versions are equal.

How to eliminate wrong answers

Option A is wrong because version 2:8.2.3995-1ubuntu1 from focal-updates is lower than 2:8.2.3995-1ubuntu2.1, so apt would prefer the higher version. Option B is wrong because version 2:8.2.3995-1ubuntu2.1 from focal is the same version as the correct answer but from the wrong repository (focal instead of focal-updates); apt selects the highest version from the highest-priority repository, and focal-updates typically has higher priority than focal. Option C is wrong because version 2:8.2.3995-1ubuntu1 from focal is both a lower version and from a lower-priority repository compared to the correct answer.

250
MCQhard

A web server runs Apache and generates extensive access logs. To conserve disk space, an administrator sets up a cron job that runs nightly at 2:00 AM. The job executes a shell script located at /usr/local/bin/rotate_logs.sh. The script is intended to find all .log files in /var/log/apache2/ that are older than 7 days, compress them with gzip, and move the compressed files to /var/log/archive/. However, after several days, the administrator notices that the /var/log partition is nearly full and the logs are not being compressed. The cron log shows the job ran at the scheduled time but produced no terminal output (stdout or stderr). The script itself contains no explicit echo statements or error handling. The administrator has root access and wants to diagnose the problem without disrupting the running web server. Which of the following is the most appropriate first step to identify the failure?

A.Run the script manually with 'bash -x /usr/local/bin/rotate_logs.sh' to observe command execution.
B.Use 'ps -ef | grep compress' to check if the cron job spawned any child processes.
C.Check the file permissions of the archive directory with 'ls -ld /var/log/archive'.
D.Review the system logs in /var/log/syslog for any entries related to gzip or the script.
AnswerA

Running with 'bash -x' traces each command and its expansion to stderr, exposing where the script fails, such as a wrong find predicate or missing gzip path. It diagnoses without touching the running web server, and the trace output reveals the silent failure.

Why this answer

Running the script with 'bash -x' enables execution tracing, which prints each command and its arguments as they are executed. This will reveal exactly where the script fails—whether due to a missing file, permission error, or incorrect path—without modifying the script or disrupting the running web server. Since the cron job produced no output, the script likely encountered a silent failure, and 'bash -x' is the most direct way to diagnose it.

Exam trap

The trap here is that candidates may jump to checking permissions or system logs because they assume a permission or system-level error, but the most efficient first step is to reproduce the script's execution with tracing enabled to see exactly what commands run and where they fail.

How to eliminate wrong answers

Option B is wrong because 'ps -ef | grep compress' only checks for currently running processes named 'compress'; the cron job has already finished, so no child processes would exist, and this does not help diagnose why the script failed. Option C is wrong because checking permissions of /var/log/archive is a secondary step; the script may fail before even attempting to move files (e.g., due to a missing source directory or incorrect find command), and permissions alone cannot reveal the root cause of a silent failure. Option D is wrong because reviewing system logs like /var/log/syslog may show gzip-related errors only if the script actually ran gzip and logged errors; since the script has no error handling and produced no output, there may be no relevant entries, making this an inefficient first step.

251
Multi-Selectmedium

A user needs to find all lines in a file that contain the word `error` while ignoring case, and also print the line number for each match. Which TWO `grep` invocations accomplish this? (Choose two.)

Select 2 answers
A.grep -l -i error file.log
B.grep -c -n error file.log
C.grep -in error file.log
D.grep -v -n error file.log
E.grep -i -n error file.log
AnswersC, E

The `-i` option makes matching case-insensitive, and `-n` prefixes each matching line with its line number. Combined in `-in`, both requirements are met in a single concise invocation. This is the conventional short-option form and works on all POSIX-compatible grep implementations.

Why this answer

Case-insensitive matching is enabled by `-i`, and line numbers are added by `-n`. Whether written as `-in` or as separate `-i -n` options, both forms satisfy the requirement to list matching lines with their line numbers. The other options invert the match, print only a count, or print only filenames, none of which meets the stated goal.

Exam trap

The trap here is that `-c` and `-l` look like they add useful information, but they replace the normal matching-line output instead of supplementing it.

252
MCQeasy

What is stored in the first sector of a hard disk (Master Boot Record)?

A.The Master Boot Record (boot loader and partition table)
B.The partition table only
C.The Linux kernel
D.The root filesystem
AnswerA

The first sector of a hard disk holds the Master Boot Record, comprising 446 bytes of boot loader code, a 64-byte partition table describing up to four primary partitions, and a 2-byte boot signature. This layout matches the question's description of the MBR contents.

Why this answer

The Master Boot Record (MBR) occupies the first sector (sector 0, 512 bytes) of a hard disk and contains both the boot loader code (first 446 bytes) and the partition table (next 64 bytes), plus a 2-byte signature (0x55AA). This structure is essential for BIOS-based booting, as the BIOS loads the MBR into memory and executes the boot loader, which then uses the partition table to locate the active partition and load the operating system.

Exam trap

The trap here is that candidates often confuse the MBR with the entire boot process, mistakenly thinking the kernel or root filesystem is directly stored in the first sector, when in reality the MBR only contains minimal boot code and partition metadata.

How to eliminate wrong answers

Option B is wrong because the partition table alone is only part of the MBR; the MBR also includes the boot loader code and the signature, so the partition table is not stored in isolation. Option C is wrong because the Linux kernel is never stored in the MBR; it resides on a filesystem (e.g., /boot) and is loaded later by a boot loader like GRUB. Option D is wrong because the root filesystem is a mounted filesystem (e.g., ext4) containing system directories and files, not a 512-byte sector; it is stored on a partition, not in the MBR.

253
MCQeasy

On a Fedora system, which command is used to update all installed packages to their latest versions?

A.`dnf upgrade`
B.`dnf check-update`
C.`dnf update all`
D.`dnf install update`
AnswerA

On Fedora, dnf is the default package manager, and dnf upgrade resolves dependencies and installs the newest versions of all installed packages. It satisfies the stem's requirement to update everything, unlike dnf install, which targets specified packages only.

Why this answer

On Fedora, `dnf upgrade` is the correct command to update all installed packages to their latest versions. It synchronizes the local package database with the repositories and upgrades every installed package that has a newer version available, handling dependencies automatically.

Exam trap

The trap here is that candidates may confuse `dnf check-update` (which only checks for updates) with the actual update command, or assume that `dnf update all` is valid syntax based on a literal reading of 'update all packages'.

How to eliminate wrong answers

Option B is wrong because `dnf check-update` only lists available updates without performing any upgrades; it is used for informational purposes. Option C is wrong because `dnf update all` is not a valid DNF command; the correct syntax is `dnf upgrade` (or `dnf update`, which is an alias for `upgrade`). Option D is wrong because `dnf install update` attempts to install a package named 'update' rather than upgrading existing packages; it does not perform a system-wide update.

254
MCQhard

Refer to the exhibit. A system administrator finds this line in /etc/rsyslog.conf. What is the effect of this configuration?

A.Only messages with facility *.info are forwarded.
B.All syslog messages are forwarded via TCP to the server.
C.All syslog messages are forwarded via UDP to the server at 192.168.1.100 on port 514.
D.Only authentication-related messages are forwarded.
AnswerC

The selector * matches every facility and severity, and the single @ prefix specifies forwarding over UDP to 192.168.1.100 on the default syslog port 514. This satisfies the exhibit's requirement to relay all messages to that remote collector.

Why this answer

The line `*.* @192.168.1.100:514` in rsyslog.conf uses the `@` symbol to indicate UDP forwarding. The `*.*` selector means all facilities and all priorities, so every syslog message is forwarded via UDP to the server at 192.168.1.100 on port 514. This is a standard rsyslog syntax for remote logging.

Exam trap

The trap here is that candidates confuse the single `@` (UDP) with double `@@` (TCP), or misinterpret `*.*` as a specific facility filter rather than the universal wildcard for all syslog messages.

How to eliminate wrong answers

Option A is wrong because `*.*` does not restrict to facility `*.info`; it includes all facilities and all priorities, not just info-level messages. Option B is wrong because the single `@` specifies UDP, not TCP; TCP forwarding would use two `@@` symbols (e.g., `*.* @@192.168.1.100:514`). Option D is wrong because `*.*` covers all facilities, not just authentication-related (auth, authpriv); there is no facility filter applied.

255
MCQhard

Refer to the exhibit. An administrator runs this command expecting to capture both stdout and stderr into output.txt. However, the file contains only stdout. What is the error?

A.The file already exists and is not writable.
B.The stdout redirection should be 1> instead of >.
C.The 2>&1 should appear after the > output.txt.
D.The command must be run as root.
AnswerC

Redirection order determines descriptor duplication: writing 2>&1 before > output.txt duplicates stderr onto the terminal's stdout, which the later redirection does not inherit. Placing 2>&1 after > output.txt makes stderr point at the file, satisfying the stem's requirement to capture both streams.

Why this answer

The error is that the `2>&1` redirection appears before the `> output.txt` on the command line. In bash, redirections are evaluated left to right. When `2>&1` is placed first, it redirects stderr (file descriptor 2) to the current target of stdout (file descriptor 1), which at that point is still the terminal, not the file.

The subsequent `> output.txt` redirects only stdout to the file, leaving stderr still going to the terminal. To capture both, `2>&1` must appear after `> output.txt`, so that stderr is redirected to the file descriptor that now points to the file.

Exam trap

The trap here is that candidates often assume the order of redirections doesn't matter, but the shell processes them left to right, so placing `2>&1` before the file redirection causes stderr to be redirected to the terminal instead of the file.

How to eliminate wrong answers

Option A is wrong because if the file already exists and is not writable, the shell would produce an error message (e.g., 'permission denied') and the command would fail entirely, not silently capture only stdout. Option B is wrong because `>` is equivalent to `1>` in bash; both redirect stdout, so using `1>` would not change the behavior. Option D is wrong because root privileges are not required for standard output redirection; any user with write permission on the target directory can redirect output.

256
MCQhard

A system takes a long time to boot due to a service that fails to start. Which systemd command can be used to identify the service causing the delay?

A.journalctl -u service
B.systemctl status
C.systemd-analyze critical-chain
D.systemd-analyze blame
AnswerD

`systemd-analyze blame` lists each unit's initialisation time in descending order, directly exposing the service whose startup delay dominates the boot. It satisfies the stem's requirement to identify the specific failing service, since the slowest unit appears at the top of the output.

Why this answer

The `systemd-analyze blame` command prints a list of all running units, sorted by the time they took to initialize, making it the direct tool to identify which service is causing a boot delay. Unlike other options, it specifically measures and displays the initialization time of each unit, allowing you to pinpoint the slowest service.

Exam trap

The trap here is that candidates confuse `systemd-analyze critical-chain` (which shows the longest dependency chain) with `systemd-analyze blame` (which shows the actual time each unit took to start), leading them to choose C when D is the correct tool for identifying the specific slow service.

How to eliminate wrong answers

Option A is wrong because `journalctl -u service` shows the log entries for a specific service, but it does not provide a summary of boot-time durations or identify which service is slow; it requires you already know the service name. Option B is wrong because `systemctl status` shows the current status and recent logs of a service, but it does not display boot-time analysis or comparative initialization times. Option C is wrong because `systemd-analyze critical-chain` prints the critical chain of units that took the longest to boot, but it focuses on the chain of dependencies rather than listing all services sorted by their individual initialization time, so it may not directly show the single slowest service if it is not on the critical path.

257
MCQeasy

Which of the following commands will display the default gateway of a Linux system?

A.arp -a
B.netstat -i
C.ip route show
D.ifconfig
AnswerC

The ip route show command prints the kernel routing table, whose default entry (destination 0.0.0.0/0) lists the gateway address. This directly satisfies the stem's requirement to display the default gateway, unlike ip addr, which only shows interface addressing.

Why this answer

The `ip route show` command displays the kernel routing table, which includes the default gateway as a default route (typically `default via <gateway-IP>`). This is the standard modern tool for viewing routing information on Linux systems.

Exam trap

The trap here is that candidates often confuse `netstat -r` (which does show the routing table) with `netstat -i` (which only shows interface statistics), leading them to incorrectly select option B.

How to eliminate wrong answers

Option A is wrong because `arp -a` displays the ARP cache (IP-to-MAC address mappings), not routing information or the default gateway. Option B is wrong because `netstat -i` shows network interface statistics (packets, errors, etc.), not the routing table or default gateway. Option D is wrong because `ifconfig` displays network interface configuration (IP address, netmask, etc.) but does not show routing information or the default gateway.

258
MCQhard

A developer downloads the source code for a kernel module and attempts to compile it using `make`. The compilation fails with an error indicating that the kernel header files are missing. Which package should be installed to provide the necessary headers on a Debian system?

A.`linux-headers-$(uname -r)`
B.`kernel-headers-generic`
C.`build-essential`
D.`linux-kernel-headers`
AnswerA

The linux-headers package matching the running kernel via uname -r supplies the exact header files and build scripts the module's make process requires. Installing headers for a different kernel version would not resolve the missing-header compilation failure.

Why this answer

The correct package is `linux-headers-$(uname -r)` because kernel modules must be compiled against headers that match the exact running kernel version. The `$(uname -r)` command substitution dynamically inserts the current kernel release string (e.g., `5.10.0-28-amd64`), ensuring the headers correspond to the active kernel. On Debian, these headers are provided by the `linux-headers-<version>` package, which includes the necessary `Kbuild`, `Kconfig`, and header files under `/usr/src/linux-headers-<version>`.

Exam trap

The trap here is that candidates confuse the generic 'build-essential' meta-package (which is needed for compiling any C code) with the kernel-specific headers package, or they assume a generic package name like 'kernel-headers-generic' exists on Debian, when in fact Debian uses version-specific `linux-headers-*` packages and the `-generic` flavor is Ubuntu-specific.

How to eliminate wrong answers

Option B is wrong because `kernel-headers-generic` is not a valid Debian package name; Debian uses `linux-headers-<flavor>` (e.g., `linux-headers-amd64`) and the `-generic` suffix is specific to Ubuntu kernels. Option C is wrong because `build-essential` provides compilers (gcc, make) and libraries (libc6-dev) but does not include kernel headers; it is a prerequisite for compiling any C program but not sufficient for kernel module compilation. Option D is wrong because `linux-kernel-headers` is not a real Debian package; the correct naming convention is `linux-headers-*` (e.g., `linux-headers-5.10.0-28-amd64`), and the package `linux-kernel-headers` does not exist in Debian repositories.

259
MCQmedium

An organization's DNS server (BIND) is authoritatively serving the example.com zone. The administrator needs to add a mail exchange record for mail.example.com with priority 10. Which resource record should be added to the zone file?

A.example.com. IN MX 10 mail.example.com.
B.mail.example.com. IN A 192.168.1.10
C.mail.example.com. IN CNAME example.com.
D.example.com. IN TXT "v=spf1 mx -all"
AnswerA

The MX record must sit at the zone apex (example.com.) with preference 10 and point to mail.example.com., the mail server's FQDN. Placing the owner name at mail.example.com. would instead declare a mail exchanger for that host, not the domain.

Why this answer

An MX record specifies the mail exchange server for a domain, and the syntax 'example.com. IN MX 10 mail.example.com.' defines a priority of 10 for the mail server mail.example.com. This record tells other mail servers to deliver email for @example.com to mail.example.com, with lower priority values preferred.

Exam trap

The trap here is that candidates often confuse the purpose of MX records with A or CNAME records, or mistakenly think an SPF TXT record is the correct way to designate a mail server, when in fact MX records are the standard mechanism for mail routing.

How to eliminate wrong answers

Option B is wrong because it adds an A record for mail.example.com, which maps a hostname to an IP address, but the question specifically asks for a mail exchange record (MX), not an address record. Option C is wrong because it creates a CNAME alias from mail.example.com to example.com, which would cause mail delivery issues (RFC 1034 prohibits CNAME records at the same node as other record types like MX). Option D is wrong because it adds a TXT record with an SPF policy, which is used for sender policy framework to prevent email spoofing, not for routing mail to a specific server.

260
MCQeasy

Refer to the exhibit. Based on the dpkg output, what is the status of the 'ftp' package?

A.Removed but configuration files remain.
B.Half-configured.
C.Installed and up-to-date.
D.Not installed at all.
AnswerA

The 'rc' status indicates removed with config files.

Why this answer

The 'dpkg' output shows 'rc' in the status field, which stands for 'removed' (the package has been deleted) but 'config-files' remain. This means the package was removed using 'dpkg --purge' or 'apt-get remove' without the '--purge' option, leaving behind configuration files in /etc.

Exam trap

LPI often tests the distinction between 'removed' (package binary gone) and 'purged' (everything gone), where candidates mistakenly think 'rc' means the package is still installed or that config files are automatically removed.

How to eliminate wrong answers

Option B is wrong because 'half-configured' would show 'hc' in the dpkg status, indicating the package was partially configured after unpacking but the configuration script failed. Option C is wrong because 'installed and up-to-date' would show 'ii' (installed and ok) in the status, not 'rc'. Option D is wrong because 'not installed at all' would show 'un' (unknown/not installed) or no entry at all, not the 'rc' status which explicitly indicates the package was once installed and its config files persist.

261
MCQeasy

A user wants to view the first 10 lines of a log file named /var/log/syslog. Which command should they use?

A.tail /var/log/syslog
B.cat /var/log/syslog | more
C.head /var/log/syslog
D.less /var/log/syslog
AnswerC

The head command by default displays the first 10 lines of a file. This is exactly what the user needs. It is a simple and efficient way to peek at the beginning of a file without loading the entire file into memory. This command is part of coreutils and is commonly used in shell scripting and daily administration for quickly inspecting file contents.

Why this answer

The head command is designed to output the first part of files, with a default of 10 lines. It is the correct choice for viewing the first 10 lines of a log file. The tail command shows the last lines, while cat and less display the entire file or allow interactive viewing without limiting to the first 10 lines.

This is a basic file inspection task in Linux.

Exam trap

The trap here is confusing head and tail, or thinking that a pager like less automatically limits output to the first 10 lines.

262
MCQhard

A company is setting up a database server that requires high reliability and support for snapshots. The storage will be on a single large disk. Which filesystem is best suited for this requirement?

A.ext4
B.NTFS
C.XFS
D.btrfs
AnswerD

btrfs provides copy-on-write snapshots and checksummed data with RAID support on a single disk, directly meeting the stated reliability and snapshot requirements. ext4 lacks native snapshots, and XFS snapshot support is limited, so btrfs is the best fit.

Why this answer

Btrfs (B-tree filesystem) is best suited for this requirement because it natively supports snapshots, checksumming, and copy-on-write (CoW) for high reliability, all on a single disk. Unlike other Linux filesystems, btrfs provides built-in snapshot and rollback capabilities without requiring an external volume manager, making it ideal for database servers needing consistent point-in-time backups.

Exam trap

The trap here is that candidates often choose XFS for its high performance with large files, but they overlook that XFS lacks native snapshot support, while btrfs is specifically designed for advanced features like snapshots and self-healing on a single disk.

How to eliminate wrong answers

Option A is wrong because ext4 lacks native snapshot support; it relies on external tools like LVM for snapshots, which adds complexity and does not provide filesystem-level checksumming for data integrity. Option B is wrong because NTFS is a Windows filesystem not natively supported on Linux without FUSE or kernel modules, and it is not designed for the Linux environment or LPIC-1 scope. Option C is wrong because XFS does not support snapshots natively; it requires LVM or other volume managers for snapshot functionality, and while it offers high performance for large files, it lacks the integrated snapshot and rollback features of btrfs.

263
MCQmedium

A system administrator wants to compile and install a program from source. After running './configure --prefix=/opt/myapp', the configure script fails with an error about missing 'libssl-dev'. What should the administrator do to resolve this issue?

A.Install the 'libssl-dev' package using the package manager
B.Manually download and place the missing header files in /usr/include
C.Install the 'libssl' runtime library
D.Add the '--disable-ssl' flag to ./configure
AnswerA

The configure script needs the OpenSSL development headers and libraries to compile against. Installing libssl-dev via the package manager provides those headers and the linker files, allowing ./configure to complete and the build to proceed.

Why this answer

The configure script requires the development headers and static libraries for OpenSSL to compile software that uses SSL/TLS. The 'libssl-dev' package provides these headers and the .so symlinks needed during compilation. Installing it via the package manager (e.g., apt, yum) is the correct and standard method to satisfy this build dependency.

Exam trap

The trap here is that candidates confuse runtime libraries (libssl) with development libraries (libssl-dev), or think manually copying headers is a valid workaround, when the package manager's -dev package is the intended solution.

How to eliminate wrong answers

Option B is wrong because manually placing header files in /usr/include is fragile, does not resolve library linking dependencies, and bypasses the package manager's dependency tracking. Option C is wrong because 'libssl' runtime library only provides the shared objects for execution, not the headers or static libraries required during compilation. Option D is wrong because adding '--disable-ssl' would disable SSL support entirely, which may break the program's intended functionality or cause other configure checks to fail if SSL is a hard requirement.

264
Multi-Selecteasy

Which TWO commands can be used to create an ext4 filesystem on a partition?

Select 2 answers
A.mkfs.btrfs /dev/sdb1
B.mkfs.ext4 /dev/sdb1
C.mke2fs -t ext4 /dev/sdb1
D.mkfs.msdos /dev/sdb1
E.mkfs.xfs /dev/sdb1
AnswersB, C

mkfs.ext4 is the ext4-specific front end that invokes mke2fs with the correct type, creating the filesystem directly on the named partition. It satisfies the requirement to build an ext4 filesystem on /dev/sdb1 without extra flags.

Why this answer

Option B, mkfs.ext4 /dev/sdb1, is correct because mkfs.ext4 is the dedicated front-end utility for creating an ext4 filesystem on the specified block device, invoking the ext4 filesystem code directly. Option C, mke2fs -t ext4 /dev/sdb1, is also correct because mke2fs is the underlying ext-family filesystem creation tool, and the -t ext4 flag explicitly selects the ext4 filesystem type, producing the same ext4 result. The unmarked options do not belong: mkfs.btrfs creates a Btrfs filesystem, mkfs.msdos creates a FAT filesystem, and mkfs.xfs creates an XFS filesystem, none of which are ext4.

Exam trap

The trap here is that candidates may think only `mkfs.ext4` is valid, overlooking that `mke2fs -t ext4` is an equivalent command, or they may confuse filesystem-specific mkfs wrappers (like `mkfs.btrfs` or `mkfs.xfs`) as being able to create ext4 filesystems.

265
Multi-Selecteasy

Which TWO commands are commonly used to start, stop, or restart system services on a Linux system that uses systemd as its init system?

Select 2 answers
A.service
B.journalctl
C.chkconfig
D.systemctl
E.init.d
AnswersA, D

service is a legacy wrapper that works with systemd on most distros.

Why this answer

The `service` command is a legacy tool that works with System V init scripts, but on systems using systemd, it is often mapped to `systemctl` via compatibility wrappers. This allows `service` to start, stop, or restart services on systemd-based distributions, making it a commonly used command for these tasks.

Exam trap

The trap here is that candidates may confuse `chkconfig` or `init.d` as valid systemd commands, forgetting that systemd replaced these with `systemctl` and that `service` is only a compatibility wrapper, not a native systemd tool.

266
MCQmedium

In a bash script, a variable 'file' is set to '/var/log/syslog'. Which expansion will yield the string '/var/log'?

A.${file##*/}
B.${file%%/*}
C.${file%/*}
D.${file#*/}
AnswerC

Ly uses ${file%/*} to remove the shortest suffix matching '/*', giving '/var/log'.

Why this answer

The `${file%/*}` expansion uses the `%` operator to remove the shortest suffix matching the pattern `/*`, which matches the last slash and everything after it. Since `file` is `/var/log/syslog`, this removes `/syslog`, leaving `/var/log`. This is a standard parameter expansion in bash for stripping a trailing path component.

Exam trap

The trap here is that candidates often confuse the `%` (remove suffix) and `#` (remove prefix) operators, or mistakenly think `%%` removes the last path component when it actually removes everything from the first slash onward due to longest match behavior.

How to eliminate wrong answers

Option A is wrong because `${file##*/}` uses the `##` operator to remove the longest prefix matching `*/`, which strips everything up to and including the last slash, yielding `syslog` (the filename), not the directory path. Option B is wrong because `${file%%/*}` uses the `%%` operator to remove the longest suffix matching `/*`, which would strip everything from the first slash onward, resulting in an empty string (since the entire string starts with `/`). Option D is wrong because `${file#*/}` uses the `#` operator to remove the shortest prefix matching `*/`, which strips only the first slash and any characters before it, yielding `var/log/syslog` (the path without the leading slash).

267
MCQhard

A sysadmin is troubleshooting a connectivity issue between two servers in different subnets. The output of 'traceroute 192.168.2.10' shows packets reaching a router but not the destination. The router's firewall uses iptables. Which rule would prevent the traceroute from completing?

A.-A INPUT -i lo -j LOG
B.-A INPUT -p udp -j ACCEPT
C.-A INPUT -p tcp --dport 80 -j REJECT
D.-A INPUT -p icmp --icmp-type port-unreachable -j DROP
AnswerD

Blocks ICMP Port Unreachable, which stops traceroute responses.

Why this answer

Traceroute relies on ICMP Time Exceeded messages from intermediate routers and an ICMP Port Unreachable message from the destination to signal completion. Dropping ICMP type 3 (Destination Unreachable) packets, specifically port-unreachable (code 3), prevents the final response from reaching the source, causing traceroute to hang after reaching the last hop.

Exam trap

The trap here is that candidates often focus on blocking the UDP probes themselves (e.g., via -p udp -j DROP) rather than understanding that traceroute completion depends on the ICMP response from the destination, not just the probe packets.

How to eliminate wrong answers

Option A is wrong because logging (-j LOG) does not drop or reject packets; it only records them, so traceroute traffic would still pass. Option B is wrong because accepting UDP packets (-p udp -j ACCEPT) would actually help traceroute, which uses high UDP ports by default, not block it. Option C is wrong because rejecting TCP traffic on port 80 (-p tcp --dport 80 -j REJECT) is unrelated to traceroute, which uses UDP probes (or ICMP on some systems) and does not target port 80.

268
MCQhard

Refer to the exhibit. The root filesystem is nearly full. The administrator needs to increase its size. Which steps should be performed?

A.Use parted to resize the root partition and then mount it
B.Use fdisk to increase the size of /dev/sda1 and then run resize2fs
C.Use lvextend to extend the logical volume and then resize2fs to resize the filesystem
D.Create a new filesystem on /dev/sda2 and mount it to /
AnswerC

lvextend grows the logical volume using free space in its volume group, then resize2fs expands the ext4 filesystem online to occupy that new space. Both steps are required because enlarging the LV alone leaves the filesystem unchanged.

Why this answer

The root filesystem is on an LVM logical volume, as indicated by the exhibit (e.g., /dev/mapper/rootvg-rootlv). To increase its size, you must first extend the logical volume using lvextend, then resize the filesystem with resize2fs. This two-step process ensures the underlying block device and the filesystem are both enlarged to utilize the newly available space.

Exam trap

The trap here is that candidates assume the root filesystem is on a traditional partition and attempt to resize it with fdisk or parted, failing to recognize that LVM requires a different workflow with lvextend and resize2fs.

How to eliminate wrong answers

Option A is wrong because parted resizes partitions, not LVM logical volumes; the root filesystem resides on a logical volume, not a physical partition, so resizing the partition would not affect the LV. Option B is wrong because fdisk operates on physical partitions (e.g., /dev/sda1), but the root filesystem is on an LVM logical volume; increasing /dev/sda1 would not extend the LV, and resize2fs alone cannot expand the LV. Option D is wrong because creating a new filesystem on /dev/sda2 and mounting it to / would replace the existing root filesystem, destroying all data and requiring a complete reinstall or data migration, which is not a valid method to increase the size of the current root filesystem.

269
MCQeasy

Which command displays information about the CPU, including model name, cache size, and flags?

A.uname -a
B.lscpu
C.cat /proc/cpuinfo
D.dmidecode
AnswerB

lscpu reads /proc/cpuinfo and sysfs to report CPU architecture, model name, per-core cache sizes and instruction flags in one view, satisfying the stem's requirement to display all three. Alternatives such as lspci list PCI devices, not processor details.

Why this answer

The `lscpu` command is the correct choice because it is specifically designed to display CPU architecture information, including model name, cache sizes, and flags (such as SSE, AES, etc.), by reading data from sysfs and /proc/cpuinfo in a human-readable format. It provides a concise summary without requiring root privileges, making it the most appropriate tool for this task.

Exam trap

The trap here is that candidates often choose `cat /proc/cpuinfo` because it contains all the raw data, but the exam expects the command that is specifically designed to present CPU information in a readable summary, which is `lscpu`.

How to eliminate wrong answers

Option A is wrong because `uname -a` displays system kernel information (e.g., kernel name, hostname, kernel release, architecture), but it does not show CPU model name, cache size, or flags. Option C is wrong because while `cat /proc/cpuinfo` does contain all the requested CPU details, it outputs raw, verbose data that is not formatted for quick reading; the question asks for a command that 'displays information' in a practical sense, and `lscpu` is the standard utility for this purpose. Option D is wrong because `dmidecode` reads DMI/SMBIOS tables to provide hardware information (e.g., BIOS, motherboard, memory), but it requires root privileges and does not directly output CPU flags or cache details in a straightforward manner.

270
MCQeasy

A user reports that a USB flash drive plugged into a Linux workstation is not automatically mounted. The administrator runs 'lsblk' and sees the device as /dev/sdb1 with no mountpoint. Which command should the administrator use to manually mount the filesystem on /dev/sdb1 to the /mnt/usb directory?

A.mount -t auto /dev/sdb1 /mnt/usb
B.mount /mnt/usb /dev/sdb1
C.mount /dev/sdb1 /mnt/usb
D.mount -o loop /dev/sdb1 /mnt/usb
AnswerC

The mount command with the device and mount point as arguments will mount the filesystem. The system will auto-detect the filesystem type if not specified. This is the correct syntax to manually mount a device to a directory.

Why this answer

The correct command is 'mount /dev/sdb1 /mnt/usb'. This uses the standard syntax of device followed by mount point. The system will auto-detect the filesystem type.

Other options either reverse the arguments, add unnecessary options, or use loop mounting which is not applicable.

Exam trap

The trap here is confusing the order of arguments or adding unnecessary options like -t auto or -o loop, which are not required for a simple manual mount.

271
MCQhard

A company runs a critical database server on Linux. The server has a hardware RAID controller with two logical volumes: one for the operating system (LV1) and one for the database data (LV2). The server uses LVM on top of the RAID volumes. Recently, the database performance has degraded. The administrator suspects that the file system on LV2 is heavily fragmented. The server uses the ext4 filesystem. The administrator wants to check the fragmentation level and, if necessary, defragment the filesystem without unmounting it or causing downtime. What should the administrator do to minimize fragmentation impact while maintaining availability?

A.Create a new filesystem on LV2, copy data back, and symlink the old mount point to the new one.
B.Use tune2fs to set the reserved block percentage to 0 and increase the inode size.
C.Schedule a maintenance window, unmount LV2, run e2fsck -fn, then run e2fsck -D to defragment.
D.Use the e4defrag command with the -v option on the mount point to check and defragment files online.
AnswerD

The e4defrag utility operates on mounted ext4 filesystems, satisfying the no-downtime constraint. Its -v flag reports each file's fragmentation score before and after defragmentation, letting the administrator assess LV2 and defragment online. Note that e4defrag works per-file and cannot defragment directories or free space, unlike offline fsck-based approaches.

Why this answer

e4defrag is a userspace tool that provides online defragmentation for ext4 filesystems. It can check fragmentation levels and defragment files without unmounting the filesystem, thus avoiding downtime. This allows the administrator to minimize fragmentation impact while maintaining availability.

Exam trap

The trap here is that candidates may assume ext4 has no online defragmentation support at all, but e4defrag provides a limited online capability, or they may confuse e4defrag with e2fsck, which requires unmounting.

How to eliminate wrong answers

Option A is wrong because creating a new filesystem and copying data back requires unmounting LV2 or at least remounting it, causing downtime, and symlinking does not solve fragmentation on the original filesystem. Option B is wrong because tune2fs adjusts filesystem parameters like reserved blocks and inode size, but it does not perform defragmentation or check fragmentation levels. Option C is wrong because while e2fsck -D can defragment directories, it requires the filesystem to be unmounted, causing downtime, and the -fn option is for a read-only check, not defragmentation.

272
MCQhard

An openSUSE administrator needs to add a new repository from a URL and refresh the package cache. Which command sequence accomplishes this?

A.zypper install --repo url
B.zypper addrepo url; zypper refresh
C.zypper modifyrepo --add url
D.zypper repos --add url
AnswerB

zypper addrepo registers the URL as a new repository in the openSUSE configuration, then zypper refresh rebuilds the package metadata cache so the new source's packages become installable. Both steps are required to satisfy the stem's add-and-refresh constraint.

Why this answer

`zypper addrepo url` adds a new repository from the specified URL, and `zypper refresh` updates the package cache to include metadata from all configured repositories. This two-step sequence is the standard method in openSUSE for adding a remote repository and making its packages available for installation.

Exam trap

The trap here is that candidates confuse `zypper` with `apt` or `yum` commands, where `add-apt-repository` or `yum-config-manager --add-repo` combine adding and refreshing in one step, but `zypper` requires two separate commands.

How to eliminate wrong answers

Option A is wrong because `zypper install --repo url` attempts to install a package directly from a repository specified by URL, but it does not add the repository permanently; it only uses it for a single installation and does not refresh the cache. Option C is wrong because `zypper modifyrepo --add url` is not a valid command; `zypper modifyrepo` is used to change properties of existing repositories, not to add new ones. Option D is wrong because `zypper repos --add url` is not a valid syntax; `zypper repos` lists repositories, and adding a repository requires the `addrepo` subcommand.

273
MCQhard

A Linux administrator needs to find all files in the /var/log directory that are larger than 10 MB and have not been accessed in the last 30 days. The administrator also wants to delete these files to free up space. Which command will accomplish this safely, prompting for confirmation before each deletion?

A.find /var/log -type f -size +10M -mtime +30 -exec rm -i {} \;
B.find /var/log -type f -size +10M -atime +30 -exec rm -i {} \;
C.find /var/log -type f -size +10M -atime +30 -delete
D.find /var/log -type f -size +10M -ctime +30 -exec rm -i {} \;
AnswerB

This find command selects regular files (-type f) larger than 10 MB (-size +10M) that were last accessed more than 30 days ago (-atime +30). The -exec rm -i {} \; runs rm interactively for each file, prompting the user before deletion. This meets all criteria safely.

Why this answer

The find command with -atime +30 correctly identifies files not accessed in the last 30 days. Combining -size +10M filters for files larger than 10 MB. The -exec rm -i {} \; ensures interactive deletion, prompting for each file.

This satisfies the size, access time, and safety requirements. The other options either use the wrong time attribute or delete without confirmation.

Exam trap

The trap here is mixing up -atime, -mtime, and -ctime; only -atime tracks the last access time as required.

274
MCQmedium

A junior administrator needs to schedule a backup script to run as the user 'backup' every day at 02:30. The script is /usr/local/bin/backup.sh, and output should be discarded. Which crontab entry should the administrator add to the 'backup' user's crontab to accomplish this?

A.30 2 * * * /usr/local/bin/backup.sh >/dev/null 2>&1
B.2 30 * * * /usr/local/bin/backup.sh >/dev/null 2>&1
C.30 2 * * * /usr/local/bin/backup.sh >/dev/null
D.30 2 * * * backup /usr/local/bin/backup.sh >/dev/null 2>&1
AnswerA

This entry runs at 02:30 daily for the user whose crontab contains it. Redirecting stdout to /dev/null and stderr to stdout discards all output, preventing mail. The five time fields are minute, hour, day of month, month, day of week, and the command follows. This is the correct syntax and matches the requirement to run as the 'backup' user when placed in that user's crontab.

Why this answer

The correct entry uses the five time-and-date fields followed by the command. Placing it in the 'backup' user's crontab ensures it runs as that user. The redirection >/dev/null 2>&1 discards both stdout and stderr, meeting the requirement to suppress output.

The other entries either misplace the time fields, omit stderr redirection, or incorrectly add a user field that is invalid in a user crontab.

Exam trap

The trap here is confusing the format of a user crontab with the system crontab (/etc/crontab), which includes a user field before the command.

275
Multi-Selectmedium

Which TWO of the following are required for a system to boot using UEFI?

Select 2 answers
A.The bootloader installed in the ESP
B.An EFI System Partition (ESP) formatted with FAT32
C.The bootloader installed in the Master Boot Record (MBR)
D.A BIOS boot partition
E.A kernel with EFI stub support
AnswersA, B

UEFI firmware reads bootloaders exclusively from the EFI System Partition, a FAT32 partition holding `.efi` executables. Without a bootloader placed there, the firmware finds no boot target, so installation into the ESP is mandatory for UEFI boot.

Why this answer

Option B is correct because UEFI firmware requires an EFI System Partition (ESP) formatted with FAT32 (or FAT16 on removable media) to store and load EFI boot applications. Option A is correct because the bootloader must be installed as an EFI application within the ESP (e.g., \EFI\BOOT\BOOTX64.EFI or a vendor path) for the firmware to locate and execute it. Option C is incorrect because the MBR boot code is a legacy BIOS mechanism, not used by UEFI.

Option D is incorrect because a BIOS boot partition is a GPT partition used by GRUB in BIOS/GPT setups, not by UEFI. Option E is incorrect because EFI stub support is optional; UEFI can boot via a separate bootloader such as GRUB or systemd-boot without a kernel EFI stub.

Exam trap

The trap here is that candidates often confuse UEFI requirements with legacy BIOS requirements, mistakenly thinking the MBR or a BIOS boot partition is needed, or assuming EFI stub support is mandatory when it is only an optional feature for direct kernel booting.

276
MCQmedium

Refer to the exhibit. On boot, which filesystem will be checked first by fsck?

A.The swap partition
B.The root filesystem (/)
C.The CD-ROM device
D.The /boot filesystem
AnswerB

The root filesystem is mounted first during boot, so fsck checks it before any other filesystem. Its pass number in /etc/fstab is typically 1, while other local filesystems use 2, ensuring / is verified ahead of them.

Why this answer

The root filesystem (/) is checked first by fsck because it is mounted read-only during the initial boot phase, and fsck must verify its integrity before the system can proceed to mount other filesystems. The order of filesystem checks is determined by the fs_passno field in /etc/fstab, where the root filesystem typically has a passno of 1, ensuring it is checked before any filesystem with a higher passno value.

Exam trap

The trap here is that candidates often assume the /boot filesystem is checked first because it contains the kernel and bootloader, but the root filesystem is always checked first due to its fs_passno=1 setting in /etc/fstab.

How to eliminate wrong answers

Option A is wrong because swap partitions have a passno of 0 in /etc/fstab, which means they are never checked by fsck; swap is not a mounted filesystem and does not require integrity verification. Option C is wrong because CD-ROM devices are typically not listed in /etc/fstab with a passno greater than 0, and even if they were, they are not mounted at boot time by default; fsck only checks filesystems that are mounted or have a non-zero passno. Option D is wrong because the /boot filesystem, if separate, usually has a passno of 2, meaning it is checked after the root filesystem (passno 1) has been verified.

277
MCQmedium

A backup script stores its log file path in the variable LOGFILE and needs to append a timestamp line to that file. Which command correctly appends the output of the `date` command to the file named in the variable?

A.date >> $LOGFILE
B.date < $LOGFILE
C.date | $LOGFILE
D.date > $LOGFILE
AnswerA

The `>>` operator opens the file in append mode, adding the output of `date` to the end without erasing existing content. Because `$LOGFILE` expands to the stored path, the timestamp is appended to the intended log file. This satisfies the requirement of preserving prior log entries.

Why this answer

Appending output requires the `>>` redirection operator, which opens the destination file for appending rather than truncating it. With the variable expanded to the log path, `date >> $LOGFILE` adds a new timestamp line while keeping all previous entries intact, which is exactly what the backup script needs.

Exam trap

The trap here is confusing `>` with `>>`; the single greater-than sign overwrites the file, silently destroying existing log data.

278
MCQmedium

An administrator wants to change the owner of all files in /data to user 'web' without changing the group. Which command should be used?

A.chown -R web:web /data
B.chown -R web /data
C.chown web /data
D.chown web:web /data
AnswerB

chown -R web /data recursively changes the owner to web while leaving the group untouched, because only the user field is specified. Adding a colon and group, or using chgrp, would alter group ownership, which the scenario forbids.

Why this answer

`chown -R web /data` changes the owner of all files and directories recursively under /data to user 'web' while leaving the group ownership unchanged. The `-R` flag ensures recursion, and omitting a colon or dot after the username means only the owner is modified.

Exam trap

The trap here is that candidates often assume a colon is required or that `chown` without `-R` applies recursively, leading them to pick options that change the group or fail to affect all files.

How to eliminate wrong answers

Option A is wrong because `chown -R web:web /data` changes both the owner and group to 'web', which violates the requirement to not change the group. Option C is wrong because `chown web /data` only changes the owner of the /data directory itself, not its contents, missing the recursive requirement. Option D is wrong because `chown web:web /data` changes both owner and group to 'web' on the single directory, and lacks recursion, so it fails on both counts.

279
MCQmedium

Refer to the exhibit. Which users are allowed to use the 'at' command?

A.No one
B.root and user1
C.All users except user2 and user3
D.Only root
AnswerB

If at.allow exists, only users listed in it can use at.

Why this answer

The 'at' command is controlled by the /etc/at.allow and /etc/at.deny files. If /etc/at.allow exists, only users listed in it (plus root) can use 'at'. The exhibit shows /etc/at.allow contains 'root' and 'user1', so both are allowed.

If /etc/at.allow does not exist, /etc/at.deny is checked; but here the allow file takes precedence.

Exam trap

The key trap is that when /etc/at.allow exists, it takes precedence over /etc/at.deny entirely. Only users listed in the allow file (plus root) are permitted, regardless of any deny file. Many candidates mistakenly think that all users not in a deny list are allowed.

How to eliminate wrong answers

Option A is wrong because root and user1 are explicitly listed in /etc/at.allow, so some users are allowed. Option C is wrong because user2 and user3 are not in /etc/at.allow, and if /etc/at.allow exists, only users in that file (plus root) are permitted; user2 and user3 are denied, but the statement 'All users except user2 and user3' incorrectly implies all other users are allowed, which is false. Option D is wrong because user1 is also listed in /etc/at.allow, so not only root is allowed.

280
MCQeasy

After modifying /etc/fstab, an administrator wants to test if the new mount points can be mounted without rebooting. Which command should be used?

A.systemctl daemon-reload
B.mount -a
C.mount -o remount
D.mount -t ext4
AnswerB

`mount -a` reads /etc/fstab and mounts every entry not already mounted, directly satisfying the requirement to validate the modified configuration without rebooting. It parses each filesystem line, so syntax errors or unreachable devices surface immediately, letting the administrator confirm the new mount points work before a restart.

Why this answer

The `mount -a` command reads /etc/fstab and mounts all filesystems listed there that are not already mounted, making it the correct way to test new entries without rebooting. This command respects the mount options and order defined in fstab, allowing the administrator to verify that the new mount points work correctly.

Exam trap

The trap here is that candidates confuse `systemctl daemon-reload` with a command that applies fstab changes, when in fact it only reloads systemd unit files and has no effect on mount operations defined in /etc/fstab.

How to eliminate wrong answers

Option A is wrong because `systemctl daemon-reload` is used to reload systemd unit files, not to mount filesystems; it does not process /etc/fstab mount entries. Option C is wrong because `mount -o remount` requires a specific device or mount point argument and only remounts an already mounted filesystem, it cannot mount new entries from /etc/fstab. Option D is wrong because `mount -t ext4` specifies the filesystem type but requires explicit device and mount point arguments, it does not read /etc/fstab to mount new entries.

281
Multi-Selectmedium

Which TWO directories are commonly used to store source code before compiling? (Choose two.)

Select 2 answers
A./tmp
B./var/src
C./usr/src
D./usr/local/src
E./opt
AnswersC, D

/usr/src is the conventional Linux location for kernel and package source trees awaiting compilation, satisfying the stem's requirement for a directory used to store source code before building. It is distinct from /usr/local/src, which holds locally compiled software sources.

Why this answer

In Linux, source code for compiling software is conventionally stored in /usr/src (for kernel sources or distribution-provided source packages) and /usr/local/src (for locally compiled software not managed by the package manager). These directories follow the Filesystem Hierarchy Standard (FHS), which designates /usr/src for system-wide source and /usr/local/src for locally installed source code.

Exam trap

The trap here is that candidates may confuse /usr/src with /var/src (which does not exist in the FHS) or assume /tmp is appropriate for source code, overlooking the FHS's explicit design for persistent source storage in /usr/src and /usr/local/src.

282
Multi-Selecteasy

Which TWO commands can be used to display the UUID of a filesystem? (Choose two.)

Select 2 answers
A.df -h
B.mount
C.lsblk -f
D.cat /etc/fstab
E.blkid
AnswersC, E

`lsblk -f` lists block devices with their filesystem type, label, mountpoint and UUID, reading the superblock metadata directly. It satisfies the stem's requirement to display a filesystem UUID without needing the device mounted, unlike `blkid` alternatives that may require root or a populated cache.

Why this answer

Option C, lsblk -f, is correct because the -f (--fs) flag makes lsblk print filesystem information for each block device, including the filesystem type, label, mountpoint, and the UUID column, so it directly displays the UUID of a filesystem. Option E, blkid, is correct because blkid probes block devices and prints their attributes, including UUID and TYPE, by default showing the UUID for each device with a filesystem. Option A, df -h, only reports filesystem disk usage in human-readable sizes and does not show UUIDs.

Option B, mount, lists mounted filesystems and their mount options but does not display filesystem UUIDs. Option D, cat /etc/fstab, shows configured mount entries, which may contain UUID= identifiers if the admin wrote them that way, but it does not query or display the actual UUID of a filesystem.

Exam trap

The trap here is that candidates may confuse `mount` (which shows current mounts) with `blkid` or `lsblk` for UUID display, or think `/etc/fstab` is a command rather than a configuration file.

283
MCQeasy

A junior administrator on a systemd host needs the OpenSSH daemon to start automatically after every reboot and to begin running immediately without rebooting the machine. Which single command accomplishes both requirements?

A.systemctl start sshd.service
B.systemctl enable sshd.service
C.systemctl enable --now sshd.service
D.systemctl daemon-reload
AnswerC

The enable subcommand creates the persistent boot-time symlinks, while the --now flag additionally starts the unit in the running transaction. Both requirements are met in one step: the daemon is active immediately and will be pulled in automatically on subsequent boots. It is the standard idempotent way to activate and persist a service.

Why this answer

Persisting a service across boots requires enabling it so systemd creates the appropriate wants symlinks, while running it right away requires an active start. The enable --now combination performs both operations atomically, so the daemon is active and will also be pulled in at every subsequent boot without an intervening reboot or a second command.

Exam trap

The trap here is treating enable and start as interchangeable, when enable controls boot-time activation and start only affects the current runtime state.

284
MCQhard

A user 'jdoe' already exists. The administrator needs to add 'jdoe' to the 'staff' and 'admin' groups without changing other group memberships. Which command accomplishes this?

A.usermod -a -G staff,admin jdoe
B.sed -i 's/^staff:.*/&jdoe/' /etc/group
C.usermod -G staff,admin jdoe
D.useradd -G staff,admin jdoe
AnswerA

The -a flag appends the listed supplementary groups while preserving jdoe's existing memberships, and -G sets supplementary groups rather than the primary group. Omitting -a would replace all current supplementary groups, so this form satisfies the requirement exactly.

Why this answer

The `usermod -a -G` command appends the user 'jdoe' to the supplementary groups 'staff' and 'admin' without altering existing group memberships. The `-a` (append) flag is essential; without it, `-G` would replace all current supplementary groups with only those listed. This matches the requirement to add the user to new groups while preserving other group memberships.

Exam trap

The trap here is that candidates often forget the `-a` (append) flag with `usermod -G`, assuming `-G` alone adds groups, when in fact it replaces all supplementary group memberships, which is a common cause of accidental privilege removal.

How to eliminate wrong answers

Option B is wrong because `sed -i 's/^staff:.*/&jdoe/' /etc/group` attempts to edit the group file directly but incorrectly appends 'jdoe' to the end of the line without a comma separator, resulting in a malformed entry (e.g., 'staff:x:100:jdoe' instead of 'staff:x:100:jdoe'), and it only modifies the 'staff' group, ignoring 'admin'. Option C is wrong because `usermod -G staff,admin jdoe` without the `-a` flag will replace all of jdoe's current supplementary groups with only 'staff' and 'admin', removing any other group memberships. Option D is wrong because `useradd -G staff,admin jdoe` is used to create a new user and set initial supplementary groups; it will fail or produce an error since the user 'jdoe' already exists, and it does not modify existing users.

285
Multi-Selectmedium

Which TWO statements about GRUB 2 are correct?

Select 2 answers
A.After modifying /etc/default/grub, the command update-grub must be run to regenerate grub.cfg.
B.The GRUB configuration file read at boot is /boot/grub/grub.cfg.
C.GRUB 2 uses a configuration file named menu.lst.
D.The GRUB prompt can be accessed by pressing the 'e' key during boot.
E.The /etc/default/grub file is directly read by GRUB during boot.
AnswersA, B

Editing /etc/default/grub only changes the input variables; GRUB 2 reads the generated grub.cfg at boot, so update-grub (a wrapper for grub-mkconfig) must regenerate that file for the changes to take effect. This satisfies the stem's requirement that the statement accurately describe GRUB 2 behaviour.

Why this answer

Option A is correct because /etc/default/grub is a user-editable configuration file containing variables like GRUB_TIMEOUT and GRUB_CMDLINE_LINUX, and changes to it only take effect after running update-grub (a wrapper for grub-mkconfig) to regenerate the actual boot configuration. Option B is correct because GRUB 2 reads /boot/grub/grub.cfg at boot time, which is the generated file containing menu entries and boot directives. Option C is incorrect because menu.lst belongs to GRUB Legacy, not GRUB 2.

Option D is incorrect because pressing 'e' at the GRUB menu opens an editor for the selected entry, not a GRUB command prompt; the 'c' key accesses the command-line prompt. Option E is incorrect because /etc/default/grub is not read directly by GRUB at boot; it is only consumed by grub-mkconfig/update-grub to produce grub.cfg.

Exam trap

The trap here is that candidates often confuse the GRUB 2 configuration workflow with GRUB Legacy, mistakenly thinking menu.lst is still used, or that pressing 'e' opens the GRUB prompt instead of the entry editor.

286
MCQmedium

An admin runs 'lsblk' and sees that /dev/nvme0n1p1 is listed with size 512M and mounted at /boot/efi. What is the most likely filesystem type?

A.ext4
B.swap
C.xfs
D.vfat
AnswerD

The EFI System Partition must use a FAT variant so UEFI firmware can read it without Linux drivers; vfat is the standard choice. The 512M size and /boot/efi mount point confirm this role, whereas ext4, xfs and swap cannot serve as the ESP.

Why this answer

The /boot/efi partition is the EFI System Partition (ESP), which is required for UEFI boot. The ESP must be formatted with a FAT-based filesystem (typically vfat/FAT32) because the UEFI firmware is designed to read FAT partitions to load boot loaders. The size of 512M is also typical for an ESP.

Exam trap

The trap here is that candidates often assume /boot/efi uses a Linux filesystem like ext4 because it is a Linux mount point, but the UEFI specification mandates FAT for the ESP, making vfat the only correct choice.

How to eliminate wrong answers

Option A is wrong because ext4 is a Linux-native filesystem not supported by UEFI firmware for the ESP; the ESP must use FAT. Option B is wrong because swap is used for virtual memory, not for storing boot files or EFI executables. Option C is wrong because xfs is a high-performance filesystem for large data volumes, but it is not recognized by UEFI firmware for the ESP.

287
Multi-Selecteasy

Which TWO of the following commands output the total number of lines in a file?

Select 2 answers
A.grep -c '.'
B.nl
C.head -n 1
D.sed -n '$='
E.wc -l
AnswersD, E

The sed -n '$=' command suppresses default printing and, at the last line ($), executes the = command, which prints the current line number. For a file, that final number equals the total line count, satisfying the requirement without printing the lines themselves.

Why this answer

Option D, `sed -n '$=',` is correct because sed's `=` command prints the current line number, and with the `$` address it prints only the line number of the last line, which equals the total number of lines in the file. Option E, `wc -l`, is correct because `wc` with the `-l` flag counts and outputs the number of newline characters, which is the standard way to report a file's total line count. Option A, `grep -c '.',` is wrong because it counts only lines containing at least one character (the `.` regex matches any single character), so it omits empty lines and does not give the true total.

Option B, `nl`, is wrong because it numbers and prints every line of the file rather than outputting a single total count. Option C, `head -n 1`, is wrong because it outputs only the first line of the file, not the total number of lines.

Exam trap

The trap here is that candidates may think `grep -c '.'` counts all lines, but it actually excludes empty lines, while `nl` outputs numbered lines rather than a single total count.

288
Multi-Selectmedium

A Linux administrator needs to configure a system to act as a router between two subnets. The system has two network interfaces: eth0 (192.168.1.1/24) and eth1 (10.0.0.1/24). Which TWO steps are required to enable routing between these subnets? (Choose two.)

Select 2 answers
A.Add static routes for each subnet on both interfaces.
B.Set the default gateway on both subnets to point to the router's interface IP.
C.Configure firewall rules to allow forwarding between the interfaces.
D.Enable IP forwarding by setting net.ipv4.ip_forward=1.
E.Enable NAT (masquerading) on the external interface.
AnswersC, D

Even with IP forwarding enabled, firewall rules may block forwarded traffic. By default, many distributions have a default deny policy in the FORWARD chain. The administrator must add rules to allow traffic from eth0 to eth1 and vice versa, such as iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT and the reverse. This ensures that packets are not dropped by the firewall.

Why this answer

To enable a Linux system to route traffic between two directly connected subnets, IP forwarding must be enabled in the kernel, and firewall rules must permit forwarding between the interfaces. Static routes are not needed because the networks are directly connected. NAT is not required for internal routing, and configuring client gateways is done on the clients, not the router.

Exam trap

The trap here is overlooking the need for firewall rules in the FORWARD chain, as many administrators assume enabling IP forwarding is sufficient.

289
MCQeasy

A user needs to schedule a backup script to run every weekday at 2:00 AM. Which command should they use to set up this recurring job?

A.sleep 3600 && ./backup.sh
B.crontab -e and add a line
C.at -f backup.sh 2:00
D.batch
AnswerB

crontab -e opens the user's crontab for editing, where a schedule such as 0 2 * * 1-5 runs the backup script at 02:00 Monday through Friday. This satisfies the weekday-only, recurring requirement, unlike at or systemd timers for one-off jobs.

Why this answer

The cron daemon is the standard Linux tool for scheduling recurring jobs at specific times. Using `crontab -e` allows the user to edit their personal crontab file and add a line like `0 2 * * 1-5 /path/to/backup.sh` to run the script every weekday (Monday through Friday) at 2:00 AM.

Exam trap

The trap here is that candidates confuse `at` (one‑time scheduling) with `cron` (recurring scheduling), or think `sleep` in a loop can replace cron, but cron is the only correct tool for fixed recurring jobs in Linux.

How to eliminate wrong answers

Option A is wrong because `sleep 3600` only pauses execution for 3600 seconds (1 hour) once; it does not create a recurring schedule and would require manual re‑execution or a loop to repeat. Option C is wrong because `at` is designed for one‑time job scheduling at a specified time, not for recurring daily or weekday jobs. Option D is wrong because `batch` schedules a job to run when system load permits, not at a fixed time, and it also does not support recurring execution.

290
MCQeasy

A user wants to set a shell variable named DEPLOY_ENV to the value 'staging' in the current Bash session so that child processes can read it. Which command accomplishes this?

A.DEPLOY_ENV=staging
B.set DEPLOY_ENV=staging
C.export DEPLOY_ENV=staging
D.env DEPLOY_ENV=staging
AnswerC

The export builtin marks the variable for inclusion in the environment of subsequently executed commands. Combining assignment and export in one statement sets the value and makes it available to child processes, exactly matching the scenario's requirement that child processes can read DEPLOY_ENV in the current session.

Why this answer

To make a variable available to child processes, it must be exported into the environment. The export builtin, used together with an assignment, both sets the variable in the current shell and ensures it is inherited by subsequently launched commands. A plain assignment stays local to the shell, set controls shell options, and env without a command only displays the environment.

Exam trap

The trap here is confusing a shell variable with an environment variable and assuming that any assignment automatically makes the value available to child processes.

291
MCQmedium

After running 'df -h', the administrator sees that /dev/sda1 is 100% used. 'du -sh /mountpoint' shows only 50% used. What is the most likely cause?

A.The disk has bad blocks
B.A large file was deleted but a process still holds it open
C.There is a hard link that du does not count
D.The filesystem is corrupted and needs fsck
AnswerB

Deleting a file removes its directory entry but the inode and data blocks persist while a process keeps the file descriptor open. df counts allocated blocks, so usage stays at 100% until that process closes or restarts.

Why this answer

When a file is deleted but a process still holds an open file descriptor to it, the kernel does not release the disk space until the process closes the file. The 'df' command reports space usage based on the filesystem's superblock, which still counts the deleted file's blocks. 'du' calculates space by traversing the directory tree and summing file sizes, so it does not see the unlinked file. This discrepancy explains why 'df' shows 100% usage while 'du' shows only 50%.

Exam trap

The trap here is that candidates assume 'du' and 'df' should always match, overlooking the fact that 'du' cannot account for space used by unlinked files still held open by processes.

How to eliminate wrong answers

Option A is wrong because bad blocks would cause read/write errors and potential data loss, but they would not create a discrepancy between df and du; bad blocks are marked as unusable and do not inflate used space. Option C is wrong because hard links are counted correctly by both df and du; du counts each hard link's contribution to the directory tree, and df accounts for the inode's allocated blocks only once. Option D is wrong because filesystem corruption typically causes inconsistencies in metadata that fsck can repair, but it would not produce a clean df vs du mismatch; corruption often leads to errors or missing files, not a hidden file consuming space.

292
MCQhard

After a failed package upgrade, a Debian system shows 'unmet dependencies' when trying to install any new software. What is the most appropriate command to fix this condition?

A.Edit /var/lib/dpkg/status manually
B.apt-get install -f
C.dpkg --purge $(dpkg -l | grep ^iU | awk '{print $2}')
D.dpkg --force-depends -i *.deb
AnswerB

`apt-get install -f` invokes APT's dependency repair, scanning the dpkg database for broken or unmet dependencies and attempting to configure or remove offending packages. This directly resolves the stem's "unmet dependencies" state, restoring a consistent package set so subsequent installs succeed.

Why this answer

The 'apt-get install -f' command (option B) is the correct fix because it invokes the '--fix-broken' option, which automatically resolves unmet dependencies by either installing missing packages or removing partially installed ones. This is the standard Debian/APT tool for repairing a broken package state after a failed upgrade, as it reads the dpkg database and corrects inconsistencies without manual intervention.

Exam trap

The trap here is that candidates may think manually editing the dpkg database (option A) is a quick fix, but LPIC-1 tests the understanding that APT's built-in repair mechanism is the correct and safe approach, not low-level manual manipulation.

How to eliminate wrong answers

Option A is wrong because manually editing /var/lib/dpkg/status is dangerous and error-prone; it can corrupt the package database and lead to system instability, and it bypasses APT's dependency resolution logic. Option C is wrong because 'dpkg --purge' with a grep for 'iU' (unpacked but not configured) would remove all packages in that state, which is too aggressive and may delete critical system packages that only need reconfiguration, not removal. Option D is wrong because 'dpkg --force-depends -i *.deb' forces installation of all .deb files in the current directory while ignoring dependency checks, which does not fix the underlying broken state and can introduce further inconsistencies.

293
Drag & Dropmedium

Arrange the steps to create a LVM logical volume and mount it.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for creating an LVM logical volume and mounting it is: first create physical volumes (PVs) using pvcreate, then create a volume group (VG) with vgcreate, then create a logical volume (LV) with lvcreate, and finally format the LV with a filesystem (e.g., mkfs) and mount it. This ensures that each step builds on the previous one.

294
MCQhard

Refer to the exhibit. The remount command fails. What is the most likely cause?

A.The filesystem type is wrong.
B.The fstab entry lacks the 'noauto' option but the device is not currently mounted.
C.The filesystem is not mounted.
D.The mount point /data does not exist.
AnswerC

Remounting operates on a filesystem already present in the mount table; if the device was never mounted, or was unmounted beforehand, there is no mount entry to modify. The kernel therefore rejects the remount request, making an unmounted filesystem the likely cause.

Why this answer

The remount command fails because the filesystem is not mounted. 'mount -o remount' only works on filesystems that are already mounted. The lack of the 'noauto' option in the fstab entry is irrelevant; it only affects automatic mounting at boot and does not influence whether a remount can be performed on an unmounted filesystem. Candidates may incorrectly believe that the missing 'noauto' is the cause, but the real issue is that the filesystem needs to be mounted first.

Exam trap

The trap is that candidates may focus on the missing 'noauto' option and think it is the cause of the failure. In reality, the remount command requires the filesystem to be already mounted; the 'noauto' option is irrelevant to the remount operation's success.

How to eliminate wrong answers

Option A is wrong because the filesystem type is typically specified in the fstab entry and, if incorrect, would cause a different error (e.g., 'wrong fs type') rather than a remount failure due to an unmounted device. Option C is wrong because the filesystem is not mounted, which is the direct cause of the remount failure, but this is a symptom, not the root cause described in the fstab entry's missing 'noauto' option. Option D is wrong because if the mount point /data did not exist, the mount command would fail with a 'mount point does not exist' error, not a remount-specific failure.

295
MCQeasy

Refer to the exhibit. How many physical disks are present in the system?

A.3
B.2
C.4
D.1
AnswerB

Two physical disks appear because the exhibit lists two distinct block devices (for example /dev/sda and /dev/sdb), each with its own geometry and partition table. Logical volumes, partitions or RAID members shown beneath those devices are not counted separately, so the total remains two.

Why this answer

The output shows two SCSI disks: /dev/sda and /dev/sdb. Each device file represents a physical disk, so there are exactly two physical disks present. The partitions (sda1, sda2, sdb1) are subdivisions of those disks and do not count as separate physical disks.

Exam trap

The trap here is that candidates often count partition entries (e.g., sda1, sda2, sdb1) as separate physical disks, leading them to overcount the actual number of drives.

How to eliminate wrong answers

Option A is wrong because it likely counts partitions (sda1, sda2, sdb1) as separate disks, but partitions are logical divisions, not physical disks. Option C is wrong because it may misinterpret the number of device files or include non-disk devices (e.g., /dev/sr0 for optical drive) as physical disks. Option D is wrong because it ignores the second disk /dev/sdb, possibly assuming all partitions belong to a single disk.

296
MCQeasy

To enable disk quotas for user quotas on a filesystem, which line should be added to /etc/fstab's mount options?

A.grpquota
B.userquota
C.quota
D.usrquota
AnswerD

usrquota in the mount options column activates per-user quota accounting and enforcement on that filesystem when it is mounted. grpquota covers groups instead, so usrquota is the entry needed, after which quotacheck initialises the quota files.

Why this answer

The 'usrquota' mount option is the standard Linux kernel parameter used to enable user disk quotas on a filesystem. When added to the fourth field of an /etc/fstab entry, it instructs the kernel to track per-user disk usage, allowing the quota system (via quotacheck, edquota, etc.) to enforce limits.

Exam trap

The trap here is that candidates confuse 'usrquota' with the generic term 'quota' or the incorrect 'userquota', assuming any word containing 'quota' will work, but the Linux kernel strictly requires the exact 'usrquota' string for user quotas.

How to eliminate wrong answers

Option A is wrong because 'grpquota' is the mount option for enabling group quotas, not user quotas. Option B is wrong because 'userquota' is not a valid Linux mount option; the correct syntax uses 'usrquota' for users and 'grpquota' for groups. Option C is wrong because 'quota' alone is not a valid mount option in /etc/fstab; the kernel requires the specific 'usrquota' or 'grpquota' strings to activate quota tracking.

297
MCQeasy

A small office has a network printer with IP 192.168.1.100. The printer is shared via CUPS. A user reports that they cannot print a document from their workstation. The printer appears in the list of available printers, but when they try to print, the job hangs in the queue with status 'processing'. The administrator suspects the printer may be offline or the CUPS service is not running. Which command should the administrator run first to gather diagnostic information about the printer and its queue?

A.ping 192.168.1.100
B.lpstat -t
C.lpadmin -p printer -E
D.systemctl restart cups
AnswerB

lpstat -t reports the CUPS scheduler status, default destination, printer states and queued jobs, revealing whether the printer is disabled or the queue is stalled. It gathers the broadest diagnostic picture first, before more targeted checks such as lpinfo or restarting cups.

Why this answer

The `lpstat -t` command shows the complete status of the CUPS print system, including all printers, their queues, and whether they are accepting jobs. Since the job is stuck with 'processing' status, this command will reveal if the printer is idle, disabled, or unreachable, and whether the queue is enabled or paused. It is the first diagnostic step before testing network connectivity or restarting services.

Exam trap

The trap here is that candidates assume a network connectivity test (ping) is the logical first step, but the question specifically asks for diagnostic information about the printer and its queue, which requires CUPS-specific status reporting, not just ICMP reachability.

How to eliminate wrong answers

Option A is wrong because `ping` only tests basic network layer connectivity to 192.168.1.100, but does not provide any information about the CUPS printer queue status, job state, or whether the printer is accepting jobs. Option C is wrong because `lpadmin -p printer -E` enables the printer and sets it as the default, but it does not display diagnostic information; it modifies configuration and could disrupt an existing setup. Option D is wrong because `systemctl restart cups` restarts the CUPS service, which is a troubleshooting action that should only be taken after gathering diagnostic data; it may clear the queue and lose job information without identifying the root cause.

298
Multi-Selectmedium

Which TWO of the following are valid methods to specify a partition in /etc/fstab?

Select 3 answers
A.PARTUUID
B.UUID
C.LABEL
D.DEVPATH
E.ID
AnswersA, B, C

PARTUUID is a partition table UUID, less commonly used in /etc/fstab.

Why this answer

Options A (PARTUUID), B (UUID), and C (LABEL) are all valid device specifiers in the first field of /etc/fstab. UUID= and LABEL= reference the filesystem UUID and filesystem label, while PARTUUID= references the partition-table UUID (GUID) of the partition. For example, 'UUID=1234-ABCD / ext4 defaults 0 1', 'LABEL=root / ext4 defaults 0 1', and 'PARTUUID=12345678-01 / ext4 defaults 0 1' are all valid and resolved at mount time.

Options D (DEVPATH) and E (ID) are not valid fstab device specifiers; they are udev properties and are not recognized fstab tags.

Exam trap

The trap here is that candidates may confuse PARTUUID (a partition table identifier) with UUID (a filesystem identifier), or assume any udev property like DEVPATH or ID is valid in fstab, when only UUID, LABEL, PARTUUID, and device paths are supported.

299
MCQeasy

A junior administrator needs to install the package 'nginx' on an Ubuntu 22.04 server. They want to ensure all required dependencies are automatically resolved and installed. Which command should they use?

A.dpkg -i nginx
B.apt-get install nginx
C.yum install nginx
D.rpm -ivh nginx
AnswerB

The apt-get install command automatically resolves and installs dependencies from configured repositories. On Ubuntu, apt-get is the standard tool for package installation and will download and install nginx along with any required libraries, handling dependency resolution without manual intervention.

Why this answer

The correct answer is apt-get install nginx. On Ubuntu, apt-get is the high-level package manager that downloads packages from repositories and resolves dependencies automatically. It ensures nginx and all required libraries are installed and configured properly.

Exam trap

The trap here is confusing apt-get with dpkg; dpkg installs local .deb files but does not handle dependencies, while apt-get does.

300
Multi-Selectmedium

Which TWO characteristics describe the difference between 'apt-get' and 'aptitude'? (Choose two.)

Select 2 answers
A.Aptitude offers a text-based interactive interface (TUI).
B.Aptitude provides a more sophisticated dependency resolution and can mark packages as automatically installed.
C.Apt-get uses a different package format than aptitude.
D.Apt-get can only be used from the command line, while aptitude only has a text-based interface.
E.Aptitude is an older tool and no longer maintained.
AnswersA, B

You can run aptitude without arguments to enter TUI.

Why this answer

Aptitude includes a text-based interactive interface (TUI) that allows users to browse, search, and manage packages in a menu-driven environment, whereas apt-get is strictly command-line only. This TUI provides features like visual dependency trees and interactive conflict resolution, making aptitude more user-friendly for interactive package management.

Exam trap

The trap here is that candidates often assume apt-get and aptitude are interchangeable or that aptitude is obsolete, but the exam tests the specific technical distinction that aptitude has a TUI and superior dependency resolution, while both use the same package format.

Page 3

Page 4 of 6

Page 5

All pages