Courseiva

Linux Professional Institute Certification Level 1 LPIC-1 (LPIC-1) — Questions 301–375

402 questions total · 6pages · All types, answers revealed

Page 4

Page 5 of 6

Page 6
301
MCQhard

A server in a corporate network uses systemd-resolved for DNS. Internal hostnames (e.g., server.example.lan) fail to resolve, but external names (e.g., google.com) work. The /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf. The administrator checks the systemd-resolved configuration and finds that the internal DNS server is listed globally, but the network interface has no specific DNS set. Which command should be used to assign the internal DNS server to the interface and fix resolution?

A.Add the internal hostnames to /etc/hosts.
B.Run 'resolvectl dns eth0 10.0.0.1' to set the DNS server for the interface.
C.Restart systemd-resolved service.
D.Edit /etc/resolv.conf and add the internal DNS server.
AnswerB

Running `resolvectl dns eth0 10.0.0.1` assigns the internal DNS server to the eth0 interface at runtime, satisfying the stem's constraint that the interface has no per-link DNS configured. systemd-resolved routes queries for internal domains through the link-specific server, so server.example.lan resolves while external lookups continue via the global entry.

Why this answer

`resolvectl dns eth0 10.0.0.1` assigns the internal DNS server specifically to the network interface (eth0), overriding the global setting for that interface. In systemd-resolved, per-interface DNS settings take precedence over global DNS servers, so this command ensures that internal hostnames are resolved by the internal DNS server while external names continue to work via the global configuration.

Exam trap

The trap here is that candidates assume editing /etc/resolv.conf or restarting the service will fix the issue, but they fail to recognize that systemd-resolved requires explicit per-interface DNS assignment via `resolvectl` to override the global setting for a specific network interface.

How to eliminate wrong answers

Option A is wrong because adding hostnames to /etc/hosts is a static workaround that does not fix the underlying DNS resolution issue for dynamic internal hostnames; it is not a scalable solution and does not leverage the DNS server. Option C is wrong because restarting systemd-resolved does not change the configuration; it only reloads the existing settings, which still lack a per-interface DNS server for eth0. Option D is wrong because /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf, which is managed by systemd-resolved; manually editing it would be overwritten by systemd-resolved and is not the correct way to configure per-interface DNS in systemd-resolved.

302
Multi-Selecthard

Which three commands are commonly used to display information about running processes?

Select 3 answers
A.top
B.pkill
C.kill
D.htop
E.ps
AnswersA, D, E

top reads process information from /proc and refreshes it periodically, showing running processes with CPU and memory usage. This satisfies the requirement to display information about running processes, providing a live, interactive view of the process table.

Why this answer

top (A) is correct because it launches an interactive, real-time view of running processes, showing CPU, memory, and load statistics refreshed continuously. htop (D) is correct because it is an enhanced interactive process viewer that displays running processes with colorized, scrollable output and additional metrics like per-core CPU usage. ps (E) is correct because it snapshots the current processes and their details (PID, TTY, time, command), commonly used with options such as aux or -ef. pkill (B) is not a display tool but sends signals to processes by name to terminate them, and kill (C) likewise sends signals to specific PIDs rather than showing process information.

Exam trap

The trap here is that candidates may confuse commands that manipulate processes (like `kill` and `pkill`) with commands that display process information, leading them to incorrectly select those options.

303
Drag & Dropmedium

Order the steps to mount an NFS share from a remote server.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

NFS mounting requires the client package, a local directory, and the mount command with server and export path.

304
MCQmedium

A system administrator suspects that a particular service is failing to start at boot. The service is managed by systemd. Which command will show the current status of the service, including whether it is active, and recent log entries?

A.journalctl -u servicename.service
B.systemctl list-units --type=service
C.systemctl show servicename.service
D.systemctl status servicename.service
AnswerD

systemctl status displays the current state of the service, whether it is active or failed, and includes recent log lines from the journal. It provides a quick overview of the service's health and recent activity. This is the standard command to diagnose service issues on systemd-based systems.

Why this answer

The correct command is systemctl status servicename.service. It provides a concise status summary, including whether the service is active, its main PID, and recent log entries. The other commands either show only properties, only logs, or a list of all services, lacking the combined status and log view needed for quick diagnosis.

Exam trap

The trap here is confusing systemctl status with journalctl -u; while journalctl shows logs, it does not show the current active state, which is crucial for a quick status check.

305
MCQeasy

A user submitted a print job to a CUPS printer but used the wrong options. Which command should the administrator use to cancel the job?

A.lpstat
B.cancel
C.lprm
D.lpadmin
AnswerB

The cancel command is part of CUPS and cancels print jobs.

Why this answer

The `cancel` command is the correct CUPS utility to terminate a print job that has already been submitted. It accepts either a job ID (e.g., `cancel 123`) or a printer name (e.g., `cancel printer-name`) to cancel the currently active job on that printer. This command directly communicates with the CUPS daemon to remove the job from the queue.

Exam trap

The trap here is that candidates familiar with legacy BSD/LPD printing systems may instinctively choose `lprm`, but CUPS uses the `cancel` command as its standard job cancellation tool, and `lprm` is not the correct CUPS command.

How to eliminate wrong answers

Option A is wrong because `lpstat` is used to display the status of printers and print jobs, not to cancel them. Option C is wrong because `lprm` is the BSD/LPD print system command for removing jobs; CUPS does not use `lprm` natively (though it may be aliased for compatibility, the standard CUPS command is `cancel`). Option D is wrong because `lpadmin` is used for printer configuration and administration (adding, removing, or setting default printers), not for canceling individual print jobs.

306
MCQmedium

A junior administrator needs to install the package 'nginx' on an Ubuntu 22.04 server. They download the nginx_1.18.0-6ubuntu14.4_amd64.deb file from a vendor website and run the command 'dpkg -i nginx_1.18.0-6ubuntu14.4_amd64.deb'. The installation fails with an error stating that the package depends on 'libnginx-mod-http-image-filter'. Which command should the administrator run next to resolve the missing dependency?

A.apt-get install -f
B.dpkg -i --force-depends nginx_1.18.0-6ubuntu14.4_amd64.deb
C.apt-get update
D.dpkg --configure -a
AnswerA

Running 'apt-get install -f' (or 'apt --fix-broken install') instructs APT to analyze the package database, identify unmet dependencies like the missing libnginx-mod-http-image-filter, and automatically download and install them from configured repositories. This is the standard method to repair a system left in an inconsistent state by a dpkg installation that failed due to missing dependencies.

Why this answer

When dpkg fails to install a .deb file because of unmet dependencies, the package remains unconfigured and the system package database becomes inconsistent. The recommended fix is to run 'apt-get install -f', which instructs APT to resolve broken dependencies by downloading and installing required packages from the repositories. This restores system consistency and completes the installation.

Exam trap

The trap here is assuming that dpkg can resolve dependencies on its own or that forcing installation will solve the problem, when in fact dpkg only reports dependency errors and requires a higher-level tool like APT to fix them.

307
MCQeasy

Which systemd target corresponds to the traditional runlevel 3?

A.multi-user.target
B.graphical.target
C.emergency.target
D.rescue.target
AnswerA

multi-user.target is systemd's equivalent of traditional runlevel 3, providing a non-graphical multi-user environment with networking and text-mode login. It satisfies the stem's requirement by mapping the SysV runlevel 3 concept onto the corresponding systemd target unit.

Why this answer

In systemd, the 'multi-user.target' corresponds to the traditional SysV runlevel 3, which provides a multi-user, non-graphical environment with networking enabled. This target is the default for headless servers and is equivalent to the old /etc/inittab runlevel 3.

Exam trap

The trap here is that candidates often confuse 'rescue.target' with runlevel 3, when in fact rescue.target is the systemd equivalent of single-user mode (runlevel 1), while multi-user.target is the correct match for runlevel 3.

How to eliminate wrong answers

Option B (graphical.target) is wrong because it corresponds to runlevel 5, which adds a display manager (e.g., GDM, LightDM) on top of multi-user.target, not runlevel 3. Option C (emergency.target) is wrong because it is the most minimal target, starting only a single root shell on the console without networking or multi-user support, analogous to runlevel 1 or S. Option D (rescue.target) is wrong because it corresponds to runlevel 1 (single-user mode), pulling in basic system services but not a full multi-user environment.

308
MCQmedium

A system administrator wants to disable the graphical target and boot to the text mode multi-user.target permanently. Which command should they run?

A.systemctl enable multi-user.target
B.systemctl isolate multi-user.target
C.systemctl set-default multi-user.target
D.systemctl default multi-user.target
AnswerC

systemctl set-default writes the multi-user.target symlink into /etc/systemd/system/default.target, changing the persistent default boot target. This satisfies the requirement for a permanent switch away from graphical.target, unlike isolate or rescue, which affect only the running session.

Why this answer

`systemctl set-default multi-user.target` permanently changes the default systemd target to multi-user.target, ensuring the system boots into text mode (runlevel 3 equivalent) on every subsequent boot. This persists across reboots, unlike temporary switches.

Exam trap

The trap here is confusing runtime isolation (`isolate`) with persistent default setting (`set-default`), leading candidates to choose option B for a permanent change when it only affects the current session.

How to eliminate wrong answers

Option A is wrong because `systemctl enable multi-user.target` enables the target as a unit but does not set it as the default boot target; it only ensures the target is started if something requires it, not that the system boots into it. Option B is wrong because `systemctl isolate multi-user.target` immediately switches the current running target to multi-user.target but does not persist across reboots; it is a runtime change only. Option D is wrong because `systemctl default multi-user.target` is not a valid systemctl command; the correct syntax for resetting to the compiled-in default is `systemctl default` without arguments, and it does not accept a target name.

309
MCQmedium

A Linux system fails to boot with the error: 'Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. What is the most likely cause?

A.Missing root filesystem
B.Corrupt kernel image
C.Damaged bootloader
D.Missing or incorrect initrd
AnswerD

The kernel has mounted neither root nor initramfs, so it cannot load the storage driver needed to reach the root filesystem. A missing or mismatched initrd leaves the kernel without those modules, producing exactly this unknown-block(0,0) panic at boot.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates the kernel cannot locate or access the root filesystem during boot. The most common cause is a missing or incorrect initrd (initial RAM disk) that contains the necessary drivers (e.g., for SCSI, SATA, or filesystem modules) to mount the root partition. Without a proper initrd, the kernel lacks the modules to access the storage device, resulting in this panic.

Exam trap

The LPIC-1 exam often tests the distinction between a missing root filesystem and a missing initrd, trapping candidates who assume the error means the root partition itself is absent, when in fact the kernel cannot access it due to missing drivers in the initrd.

How to eliminate wrong answers

Option A is wrong because a missing root filesystem would typically produce a different error, such as 'No such device' or 'fsck' failures, not a kernel panic referencing 'unknown-block(0,0)', which specifically points to the kernel's inability to find the block device. Option B is wrong because a corrupt kernel image usually causes a panic earlier in the boot process (e.g., 'Kernel panic: Attempted to kill init!' or a crash during decompression), not a VFS mount failure with a block device number. Option C is wrong because a damaged bootloader (e.g., GRUB) would prevent the kernel from being loaded at all, resulting in a blank screen or 'No bootable device' error, not a kernel panic after the kernel has started executing.

310
MCQhard

An administrator needs to extract only the fifth field from a colon-delimited file, but some lines contain fewer than five fields and must be skipped rather than printed as empty. Which awk program accomplishes this?

A.awk -F: '$5 != "" {print $5}' file
B.awk -F: '{print $5}' file | grep -v '^$'
C.awk -F: 'length($5) > 0 {print $5}' file
D.awk -F: 'NF >= 5 {print $5}' file
AnswerD

NF holds the number of fields on the current record, so NF >= 5 selects only lines that actually contain at least five colon-separated fields, and print $5 emits the fifth one. Lines with fewer fields are never printed, exactly matching the requirement to skip short lines rather than emit empty output. This is the idiomatic awk approach.

Why this answer

The requirement is to skip records that lack a fifth field, which is exactly what the NF field-count variable expresses. Testing NF >= 5 before printing $5 rejects short lines at the source, whereas tests on the value or length of $5 conflate an absent field with a present-but-empty one and can silently drop legitimate empty fields. Using NF keeps the decision tied to the record's structure.

Exam trap

The trap here is testing whether $5 is empty instead of testing NF, which cannot distinguish a missing field from a field that exists but contains no characters.

311
MCQhard

An administrator needs to display the current and previous runlevels of a Linux system. Which command provides this information?

A.who -r
B.runlevel
C.telinit 1
D.init 0
AnswerB

runlevel reads /var/run/utmp and prints the previous and current SysV runlevels, matching the requirement to show both. It reports N when no previous level exists, and works only where the legacy runlevel records are maintained.

Why this answer

The `runlevel` command displays both the previous and current runlevels of a Linux system. It outputs two characters: the first indicates the previous runlevel (or 'N' if the runlevel has not changed since boot), and the second indicates the current runlevel. This is the standard tool for querying runlevel information on SysV init systems.

Exam trap

The trap here is that candidates confuse `who -r` with `runlevel` because both display the current runlevel, but `who -r` omits the previous runlevel, which is the key piece of information the question explicitly asks for.

How to eliminate wrong answers

Option A is wrong because `who -r` shows the current runlevel and the time of the last runlevel change, but it does not display the previous runlevel. Option C is wrong because `telinit 1` is used to change the runlevel to single-user mode (runlevel 1), not to display current or previous runlevels. Option D is wrong because `init 0` is used to shut down the system (runlevel 0), not to query runlevel information.

312
Matchingmedium

Match each Linux directory to its standard purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

System configuration files

Variable data (logs, databases)

User-installed software and libraries

Temporary files (often cleared on reboot)

Virtual file system for process and kernel info

Why these pairings

Correct matches: /bin holds essential binaries, /etc stores system configuration, /var contains variable data. Common confusions arise from swapping purposes: /bin is not for variable data, /etc is not for temporary files, and /var does not hold binaries.

313
MCQhard

A system has a software RAID1 array (/dev/md0) with two disks: /dev/sda and /dev/sdb. Disk /dev/sda fails. Which command sequence will replace the failed disk with a new /dev/sdc without stopping the array?

A.mdadm --stop /dev/md0; replace disk; mdadm --assemble /dev/md0 /dev/sdb /dev/sdc
B.mdadm --manage /dev/md0 --fail /dev/sda --remove /dev/sda && mdadm --manage /dev/md0 --add /dev/sdc
C.Shutdown system, physically replace disk, reboot
D.dd if=/dev/sdb of=/dev/sdc bs=64K
AnswerB

mdadm --manage marks the failed member faulty with --fail, then detaches it using --remove, freeing the slot. Adding /dev/sdc with --add triggers the RAID1 rebuild while /dev/md0 stays assembled and serving, satisfying the no-downtime constraint.

Why this answer

Mdadm's --manage mode allows hot-replacement of a failed disk in a RAID1 array without stopping it. The --fail flag marks /dev/sda as faulty, --remove detaches it, and --add incorporates the new /dev/sdc, triggering an automatic rebuild of the mirror.

Exam trap

The trap here is that candidates assume a failed disk requires array shutdown or physical replacement before software reconfiguration, but mdadm's --manage subcommand allows all steps (fail, remove, add) while the array remains active.

How to eliminate wrong answers

Option A is wrong because stopping the array with --stop is unnecessary and disruptive; RAID1 supports online replacement, and reassembling requires all members, risking data loss if the array is degraded. Option C is wrong because shutting down the system is not required; hot-swap capable hardware and mdadm's online management allow disk replacement without downtime. Option D is wrong because dd directly copies /dev/sdb to /dev/sdc, which overwrites the new disk's partition table and metadata, and does not integrate the disk into the RAID array; mdadm --add must be used to incorporate the new disk.

314
Multi-Selectmedium

A system administrator needs to install a new kernel on a Debian-based system. Which TWO commands can be used to achieve this? (Choose TWO.)

Select 2 answers
A.apt-cache search linux-image-5.10.0-20-amd64
B.apt-get update
C.apt-get install linux-image-5.10.0-20-amd64
D.make install
E.dpkg -i linux-image-5.10.0-20-amd64.deb
AnswersC, E

apt-get install linux-image-5.10.0-20-amd64 pulls the prebuilt kernel image package from Debian repositories, installing the kernel and triggering initramfs and bootloader updates. This is the standard package-manager method for adding a new kernel on Debian-based systems.

Why this answer

Option C is correct because apt-get install linux-image-5.10.0-20-amd64 uses APT to resolve dependencies and install the specified kernel package from the configured Debian repositories, which is the standard way to install a new kernel on a Debian-based system. Option E is correct because dpkg -i linux-image-5.10.0-20-amd64.deb installs a locally downloaded kernel .deb package directly, which is a valid method when the package file is already present on the system. Option A is incorrect because apt-cache search only queries the package cache for available packages and does not install anything.

Option B is incorrect because apt-get update merely refreshes the package index metadata from repositories and does not install a kernel. Option D is incorrect because make install is used to install software compiled from source, not to install a prebuilt Debian kernel package.

Exam trap

The trap here is that candidates confuse package management commands (like `apt-cache search` or `apt-get update`) with installation commands, or assume that `make install` is a valid method for installing a precompiled kernel package.

315
MCQmedium

A system administrator needs to ensure that the httpd service starts automatically when the system enters the multi-user.target. Which command should be used?

A.systemctl add-wants multi-user.target httpd.service
B.systemctl enable httpd
C.systemctl start httpd
D.systemctl set-default multi-user.target
AnswerB

`systemctl enable httpd` creates the symlinks under `/etc/systemd/system/multi-user.target.wants/` that pull the unit into the target's dependency graph at boot, satisfying the requirement that httpd start automatically with multi-user.target. It does not start the service now, but persistence across reboots is exactly what the stem demands.

Why this answer

The `systemctl enable httpd` command creates the necessary symlinks in the systemd unit configuration to ensure the httpd service starts automatically when the system enters the multi-user.target. This is the correct method to enable a service to start at boot in a systemd-based Linux system.

Exam trap

The trap here is confusing `systemctl start` (which only runs the service now) with `systemctl enable` (which configures it to start at boot), leading candidates to pick option C.

How to eliminate wrong answers

Option A is wrong because `systemctl add-wants` is not a valid systemd command; the correct command to add a dependency is `systemctl add-wants` (with a hyphen) but it is rarely used directly, and it does not enable the service for automatic start at boot. Option C is wrong because `systemctl start httpd` only starts the service immediately in the current session, but does not configure it to start automatically on subsequent boots. Option D is wrong because `systemctl set-default multi-user.target` sets the default target for the system (e.g., booting into multi-user mode), but does not enable any specific service to start automatically.

316
MCQhard

A developer needs to run a script named `backup.sh` every day at 02:30 using the system-wide cron facility. The system uses a traditional cron daemon and the file `/etc/crontab` contains a `SHELL` and `PATH` line. Which entry in `/etc/crontab` correctly schedules the script to run as user 'backup'?

A.30 2 * * * root run-parts /usr/local/bin/backup.sh
B.30 2 * * * backup /usr/local/bin/backup.sh
C.30 2 * * * backup /bin/sh /usr/local/bin/backup.sh
D.30 2 * * * /usr/local/bin/backup.sh
AnswerB

The system-wide `/etc/crontab` file includes a user field between the time/date fields and the command. The format is minute hour day-of-month month day-of-week user command. `30 2 * * *` means 02:30 every day, `backup` is the user to run as, and the absolute path to the script is given. This is the correct syntax for `/etc/crontab`.

Why this answer

The system-wide `/etc/crontab` file has a distinct format that includes a username field before the command. The correct syntax is: minute hour day-of-month month day-of-week user command. The entry `30 2 * * * backup /usr/local/bin/backup.sh` schedules the script at 02:30 daily and runs it as the 'backup' user.

Entries without the user field are valid only in per-user crontabs created with `crontab -e`.

Exam trap

The trap here is assuming the same crontab syntax applies to both `/etc/crontab` and user crontabs, when in fact the system-wide file requires an extra username field.

317
MCQmedium

A junior administrator needs to extract only the file 'etc/nginx/nginx.conf' from the archive 'backup.tar.bz2' into the current directory, preserving its path structure. Which command should be used?

A.tar -xjf backup.tar.bz2 --strip-components=1 etc/nginx/nginx.conf
B.tar -xjvf backup.tar.bz2 | grep nginx.conf
C.tar -cjvf backup.tar.bz2 etc/nginx/nginx.conf
D.tar -xjvf backup.tar.bz2 etc/nginx/nginx.conf
AnswerD

This command uses tar with -x to extract, -j to filter through bzip2, -v for verbose output, and -f to specify the archive file. The path 'etc/nginx/nginx.conf' selects only that member. Because the stored path is relative, the file is extracted into ./etc/nginx/nginx.conf, preserving the directory structure.

Why this answer

To extract a single file from a bzip2-compressed tarball while keeping its stored path, use tar with -x, -j, -v, and -f, followed by the exact member name. Omitting -j would fail on bzip2 compression, and using -c would create rather than extract. The member name must match the archived path exactly to select only that file.

Exam trap

The trap here is confusing the -c (create) and -x (extract) flags, or forgetting that -j is required for bzip2 and -z for gzip.

318
MCQmedium

A sysadmin notices that after modifying iptables rules, the SSH service is unreachable from a specific subnet (192.168.1.0/24). Which command should be used to view the current rules with line numbers for easier identification?

A.iptables -L
B.iptables -L --line-numbers
C.iptables -t raw -L
D.iptables -t nat -L
AnswerB

The --line-numbers flag appends rule position numbers to each chain's output, letting the sysadmin pinpoint the exact rule blocking 192.168.1.0/24 before deleting or inserting. Plain iptables -L lists rules without numbers, making precise identification and correction harder.

Why this answer

The `iptables -L --line-numbers` command displays all current iptables rules in the default filter table with line numbers prepended to each rule. This allows the sysadmin to easily identify and reference specific rules (e.g., for deletion or insertion) when troubleshooting why SSH traffic from 192.168.1.0/24 is being dropped or rejected.

Exam trap

The trap here is that candidates may choose `iptables -L` (Option A) because it shows rules, but they overlook the `--line-numbers` flag, which is critical for efficient rule management and is a common LPIC-1 exam detail.

How to eliminate wrong answers

Option A is wrong because `iptables -L` lists rules without line numbers, making it harder to pinpoint the exact rule affecting SSH traffic. Option C is wrong because `iptables -t raw -L` shows rules in the raw table, which is used for connection tracking exemptions (e.g., NOTRACK), not for filtering SSH traffic. Option D is wrong because `iptables -t nat -L` shows rules in the NAT table, which handles address translation (SNAT/DNAT) and does not affect packet filtering decisions for SSH reachability.

319
Multi-Selecthard

Which THREE of the following directories are part of the FHS and must be present on a standard Linux system? (Choose three.)

Select 3 answers
A./var
B./etc
C./lost+found
D./bin
E./home
AnswersA, B, D

/var holds variable data such as logs, spools and caches, and the FHS lists it among the directories that must exist on a standard system. Its presence is required even when separate partitions are not used.

Why this answer

The Filesystem Hierarchy Standard (FHS) defines /var (option A) as the directory for variable data such as logs, spool files, and caches, and it is a required top-level directory on a standard Linux system. Option B, /etc, is also mandated by the FHS to hold host-specific system configuration files, making it essential for a functioning system. Option D, /bin, is required by the FHS to contain essential user command binaries needed for single-user mode and system boot.

Option C, /lost+found, is not an FHS-mandated directory; it is created by the e2fsck utility on ext2/ext3/ext4 filesystems to hold recovered files and is filesystem-specific rather than a standard FHS requirement. Option E, /home, while commonly present for user home directories, is not strictly required by the FHS and may be absent or mounted from a remote server in some configurations.

Exam trap

The trap here is that /lost+found appears essential because it is commonly seen on ext filesystems, but it is not part of the FHS mandatory list, and /home is often assumed required due to its ubiquity, yet the FHS does not mandate it for a standard Linux system.

320
MCQmedium

A web server running on this host is not accessible from clients. Based on the exhibit, what is the most likely reason?

A.The FORWARD chain policy is DROP.
B.The OUTPUT chain policy is ACCEPT.
C.Incoming HTTP traffic is blocked by a DROP rule on port 80.
D.SSH traffic is blocked.
AnswerC

A DROP rule on port 80 silently discards inbound HTTP packets before the web server can respond, which matches the exhibit showing no listener reachability from clients. Because DROP gives no rejection response, clients time out rather than receive a connection refused error, confirming the firewall as the blocking constraint.

Why this answer

The exhibit shows a firewall rule set where the INPUT chain has a DROP rule for destination port 80 (HTTP). Since incoming HTTP traffic from clients must traverse the INPUT chain to reach the local web server process, this DROP rule explicitly blocks all inbound HTTP requests, making the web server inaccessible. The FORWARD chain is irrelevant because traffic destined for the local host uses the INPUT chain, not FORWARD.

Exam trap

The trap here is that candidates often confuse the FORWARD chain with the INPUT chain, assuming that blocking traffic to a local service requires a FORWARD rule, when in fact the INPUT chain governs packets destined for the host itself.

How to eliminate wrong answers

Option A is wrong because the FORWARD chain policy only affects traffic routed through the host (e.g., acting as a router), not traffic destined for the local host; the web server is local, so FORWARD is not involved. Option B is wrong because the OUTPUT chain policy being ACCEPT controls outbound traffic from the local host, not inbound HTTP requests from clients; it has no effect on incoming connections. Option D is wrong because SSH traffic (port 22) is not mentioned in the exhibit as being blocked; the issue is specifically HTTP on port 80, and SSH is irrelevant to web server accessibility.

321
MCQmedium

A Linux administrator needs to install a single Debian package file named 'custom-tool_2.1.0_amd64.deb' that was downloaded from a vendor's website. The package has several dependencies that are not currently installed, and the administrator wants the package manager to automatically resolve and install those dependencies from the configured repositories. Which command should the administrator use?

A.dpkg --install --force-depends custom-tool_2.1.0_amd64.deb
B.apt-get install custom-tool
C.apt install ./custom-tool_2.1.0_amd64.deb
D.dpkg -i custom-tool_2.1.0_amd64.deb
AnswerC

apt install with a local .deb file path (prefixed with ./) will install the package and automatically resolve and install its dependencies from configured repositories. This is the modern method that combines local installation with dependency resolution, satisfying the administrator's need.

Why this answer

The correct approach is to use apt install with the local .deb file path, as apt can handle both local package installation and dependency resolution from repositories. Using dpkg alone would install the package but leave dependencies unresolved, while forcing installation ignores the problem. Using apt-get with just the package name would fail because the package is not in a repository.

Exam trap

The trap here is assuming that dpkg -i automatically resolves dependencies from repositories, when it only installs the local package and reports missing dependencies.

322
Multi-Selecteasy

Which TWO of the following are valid methods to change the default runlevel on a SysV init-based system?

Select 2 answers
A.Use the 'runlevel' command to set the default runlevel.
B.Edit /etc/inittab to set the initdefault line.
C.Pass the desired runlevel as a kernel parameter at boot time.
D.Use 'systemctl set-default' to set the default runlevel.
E.Use the 'telinit' command to change the default runlevel.
AnswersB, C

SysV init reads /etc/inittab at startup, and the initdefault line specifies which runlevel init enters by default. Editing that entry directly changes the persistent default runlevel, satisfying the requirement for a valid configuration method on a SysV init-based system.

Why this answer

Option B is correct because on a SysV init-based system the default runlevel is defined in /etc/inittab by the initdefault entry (e.g., id:3:initdefault:), which init reads at startup to determine which runlevel to enter. Option C is correct because passing a runlevel as a kernel boot parameter (e.g., appending '3' or 'single' to the kernel command line) overrides the initdefault setting for that boot, causing init to start in the specified runlevel. Option A is incorrect because the 'runlevel' command only reports the previous and current runlevels; it does not set them.

Option D is incorrect because 'systemctl set-default' is a systemd command for setting the default target, not applicable to SysV init systems. Option E is incorrect because 'telinit' changes the runlevel of the currently running system immediately, but does not persistently alter the default runlevel configured in /etc/inittab.

Exam trap

The trap here is that candidates confuse the 'runlevel' command (which only displays) with a command that can set the default, or they mistakenly apply systemd commands like 'systemctl set-default' to SysV init systems.

323
MCQeasy

A Linux administrator is preparing a new server and needs to create an ext4 filesystem on the /dev/sdb1 partition. Which command should be used?

A.mkfs -t ext4 /dev/sdb1
B.fsck.ext4 /dev/sdb1
C.tune2fs -t ext4 /dev/sdb1
D.mke2fs -j /dev/sdb1
AnswerA

The mkfs command with the -t option specifies the filesystem type. mkfs -t ext4 /dev/sdb1 creates an ext4 filesystem on the partition. This is a standard and correct way to format a partition with a specific filesystem type. The command invokes the appropriate mkfs.ext4 helper.

Why this answer

The mkfs command is the standard utility for creating filesystems. Using mkfs -t ext4 /dev/sdb1 explicitly specifies the ext4 filesystem type. This invokes the mkfs.ext4 program, which writes the ext4 superblock, inode tables, and journal to the partition.

Other commands like fsck and tune2fs are for checking or modifying existing filesystems, not for creation.

Exam trap

The trap here is confusing filesystem creation tools with filesystem checking or tuning tools, or using mke2fs -j which creates ext3.

324
MCQeasy

A user reports that they cannot create new files in their home directory even though the filesystem shows free space. Running df -h shows the filesystem at 100 percent inode usage. Which action most directly resolves the immediate problem?

A.Run resize2fs to expand the filesystem onto additional space.
B.Remount the filesystem with the noatime option to stop inode updates.
C.Delete unneeded files that consume many inodes, such as old session files or cached mail, to free inode entries.
D.Increase the inode count by running tune2fs -i 0 on the mounted filesystem.
AnswerC

A filesystem can run out of inodes while still having free data blocks, and on ext4 the inode count is fixed at mkfs time. Removing large numbers of small files frees inode entries, allowing new files to be created. This addresses the actual exhaustion reported by df -i and restores the ability to create files.

Why this answer

When df -h reports 100 percent inode usage, the filesystem has no free inode entries even though data blocks may remain. Deleting many small files, such as session or cache files, releases inodes and restores file creation. Expanding the filesystem, remounting with noatime, or adjusting the check interval do not increase available inodes and therefore do not fix the immediate issue.

Exam trap

The trap here is reading only the percentage in df -h and assuming block exhaustion, when the same command's inode column reveals the real constraint.

325
MCQeasy

Refer to the exhibit. What is the current state of the SSH service?

A.It is active and running
B.It is inactive
C.It is disabled
D.It has failed
AnswerA

The `systemctl status ssh` output shows "Active: active (running)", confirming the daemon is operational and listening. This satisfies the stem's requirement to identify the service's current state, as opposed to inactive, failed, or masked. The main PID and uptime further corroborate that the SSH service is actively serving connections.

Why this answer

The exhibit shows the output of `systemctl status sshd`, which displays the service state as 'active (running)' in the green text. This indicates that the SSH daemon (sshd) is currently loaded and executing, providing secure shell access to the system. The 'active (running)' state is the normal operational state for a service that has been started and is functioning correctly.

Exam trap

LPI often tests the distinction between a service's current runtime state (active/inactive) and its boot-time enablement (enabled/disabled), causing candidates to confuse 'disabled' with 'inactive' when the question explicitly asks for the current state.

How to eliminate wrong answers

Option B is wrong because 'inactive' would show as 'inactive (dead)' in the systemctl status output, meaning the service is not currently running, but the exhibit clearly shows 'active (running)'. Option C is wrong because 'disabled' refers to the service's startup configuration (whether it starts automatically at boot), not its current runtime state; the exhibit shows the service is enabled for startup, but the question asks about the current state. Option D is wrong because 'failed' would display as 'failed' with a red indicator, indicating the service exited with an error or crashed, which is not shown in the exhibit.

326
Matchingmedium

Match each ACL term to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Permissions for a specific user

Permissions for a specific group

Maximum permissions for named users and groups

Permissions for everyone else

Inherited ACL for new files/directories

Why these pairings

The correct matches: Access ACL applies to files and directories; Default ACL applies to new objects; Mask limits permissions for named users/groups. Common confusions include applying ACLs only to directories or misinterpreting mask as owner permissions.

327
MCQeasy

A user reports that they cannot connect to a remote server using SSH. The administrator checks the SSH server status and it is running. Which of the following is the most likely cause?

A.A firewall is blocking port 22.
B.The client's subnet mask is incorrect.
C.The client cannot resolve the server's hostname.
D.The SSH server is using UDP instead of TCP.
AnswerA

With the SSH daemon confirmed running, a firewall dropping inbound TCP port 22 is the most likely cause, since the service listens but packets never reach it. This directly explains the connection failure despite a healthy server process.

Why this answer

SSH operates over TCP port 22 by default. If the SSH server is running but the client cannot connect, a firewall blocking port 22 is the most likely cause because it would prevent the TCP handshake from completing, even though the SSH daemon (sshd) is active and listening.

Exam trap

The trap here is that candidates may assume a running SSH server guarantees connectivity, overlooking that a firewall can block the port even when the service is active, or they may confuse SSH's TCP usage with UDP-based protocols like DNS.

How to eliminate wrong answers

Option B is wrong because an incorrect subnet mask would prevent the client from reaching any host outside its local subnet, but the question specifies a remote server, so routing or gateway issues would be more relevant; a subnet mask error alone would not selectively block SSH while allowing other traffic. Option C is wrong because if the client cannot resolve the server's hostname, the user would likely receive a 'Name or service not known' error, not a connection failure to a running SSH server; the administrator could test with the server's IP address to isolate DNS issues. Option D is wrong because SSH uses TCP (Transmission Control Protocol) for reliable, connection-oriented communication, not UDP; UDP is used by protocols like DNS or DHCP, and SSH has no UDP mode.

328
MCQhard

A sysadmin wants to prevent an APT package from being upgraded automatically but still allow it to be upgraded manually if needed. Which configuration method best achieves this?

A.Set the package version to a non-existent version in /etc/apt/preferences
B.Use 'apt-mark hold <package>'
C.Add the package to /etc/apt/preferences with Pin-Priority: 1000
D.Remove the package from sources.list
AnswerB

`apt-mark hold` pins the package at its installed version, so `apt upgrade` and `apt-get dist-upgrade` skip it during routine runs. The hold persists until explicitly released, letting the sysadmin run `apt-mark unhold` followed by a manual `apt install` when required — satisfying both the automatic-block and manual-upgrade constraints.

Why this answer

The `apt-mark hold <package>` command marks a package as held back, preventing it from being automatically upgraded during `apt upgrade` or `apt dist-upgrade`, while still allowing manual upgrades via `apt install <package>` or `apt-mark unhold`. This directly meets the requirement of blocking automatic upgrades but permitting manual intervention.

Exam trap

The trap here is that candidates confuse `apt-mark hold` with pinning in `/etc/apt/preferences`, assuming a high Pin-Priority (like 1000) prevents upgrades, when in fact it only sets preference order and does not block automatic upgrades.

How to eliminate wrong answers

Option A is wrong because setting a package version to a non-existent version in `/etc/apt/preferences` does not prevent upgrades; APT will simply ignore the invalid version and may still upgrade the package to the next available version. Option C is wrong because a Pin-Priority of 1000 in `/etc/apt/preferences` forces the package to be installed from a specific release, but it does not prevent automatic upgrades—it actually encourages them by making that version the preferred candidate. Option D is wrong because removing the package from `sources.list` would remove the repository entirely, preventing both automatic and manual upgrades of that package (and all other packages from that repository), which is too broad and does not target a single package.

329
MCQeasy

Refer to the exhibit. The system administrator sees that /var/log is 93% full and the syslog file is nearly 2 GB. What is the most appropriate immediate action to free up disk space without losing any critical log data?

A.Run 'logrotate -f /etc/logrotate.conf' to force log rotation.
B.Increase the size of the /var/log partition using lvextend.
C.Delete /var/log/syslog and restart the syslog daemon.
D.Move /var/log/syslog to /tmp and create a symbolic link.
AnswerA

Forcing logrotate rotates the oversized syslog immediately, compressing or archiving it rather than deleting it, so disk space is reclaimed while the log content is preserved. This satisfies the stem's requirement not to lose critical log data.

Why this answer

'logrotate -f' forces an immediate rotation of all log files as defined in /etc/logrotate.conf, which compresses or archives the current syslog file (e.g., syslog becomes syslog.1) and creates a fresh empty log file. This frees disk space without deleting any data, as the rotated logs remain on disk until the configured retention policy removes them. It is the standard, safe immediate action for a nearly full /var/log partition.

Exam trap

LPI often tests the misconception that deleting or moving log files is acceptable, when in fact the correct immediate action is to use logrotate -f to safely rotate logs without data loss.

How to eliminate wrong answers

Option B is wrong because increasing the partition size with lvextend does not free up existing disk space; it only adds more capacity, which does not address the immediate 93% full condition and may not be possible without available free space in the volume group. Option C is wrong because deleting /var/log/syslog and restarting the syslog daemon permanently loses all current log data, which violates the requirement to not lose any critical log data. Option D is wrong because moving the syslog file to /tmp and creating a symbolic link does not free up space on /var/log (the file still occupies space elsewhere), and /tmp is often a tmpfs filesystem that may lose data on reboot, risking log loss.

330
MCQmedium

To add a kernel parameter temporarily to the kernel command line at boot, what key should be pressed in the GRUB menu?

A.e
B.b
C.r
D.c
AnswerA

Pressing e in the GRUB menu opens the selected entry for editing, exposing the kernel command line where a parameter can be appended for that boot only. This temporary edit is discarded on reboot, unlike changes written to configuration files.

Why this answer

Pressing 'e' in the GRUB menu enters the edit mode for the selected boot entry, allowing you to temporarily modify kernel parameters on the command line (e.g., adding 'single' for single-user mode or 'nomodeset' for graphics issues). These changes apply only to the current boot and are not saved to the GRUB configuration file.

Exam trap

The trap here is that candidates confuse the 'e' (edit) key with 'c' (command line) or 'b' (boot), assuming they can add parameters via the GRUB shell or by simply booting, but only 'e' provides direct access to modify the kernel command line for a single boot.

How to eliminate wrong answers

Option B is wrong because pressing 'b' in GRUB Legacy boots the selected entry immediately without any editing capability; it does not allow adding kernel parameters. Option C is wrong because pressing 'r' is not a standard GRUB key; it has no function in the GRUB menu for editing kernel parameters. Option D is wrong because pressing 'c' opens the GRUB command-line interface (a shell-like environment), not an editor for the kernel command line of a specific boot entry.

331
MCQhard

A dependency analysis shows that removing package 'libfoo' will also remove 'appA' and 'appB' because they depend on libfoo. The administrator wants to remove libfoo but keep appA and appB. What is the best approach?

A.Force removal of libfoo using `dpkg --force-depends`.
B.Recompile appA and appB without the dependency on libfoo.
C.Check if a compatible alternative package exists and install it, then remove libfoo.
D.Use `apt-get remove libfoo --no-dep`
AnswerC

Installing a compatible alternative satisfies the dependency without removing libfoo's dependants, since the package manager resolves appA and appB against the replacement. This preserves both applications while allowing libfoo's removal, meeting the administrator's stated constraint.

Why this answer

The best approach is to find a compatible alternative package that provides the same functionality as libfoo, install it, and then remove libfoo. This satisfies the dependency requirements of appA and appB through the replacement package, allowing libfoo to be removed without breaking the dependent applications. This is the standard, non-destructive way to resolve dependency conflicts on Debian-based systems.

Exam trap

LPIC-1 often tests the temptation to use --force flags to bypass dependency errors — candidates must recognize that forcing removal breaks dependent applications and that the correct approach preserves functionality via a compatible replacement.

How to eliminate wrong answers

Option A is wrong because dpkg --force-depends bypasses dependency checks and leaves appA and appB with unmet dependencies, causing them to fail at runtime — it does not preserve functionality. Option B is wrong because recompiling appA and appB is a drastic, time-consuming action that requires source code, build environments, and testing, and is not the recommended first step. Option D is wrong because apt-get remove does not support a --no-dep flag; this is a fabricated option, and even if it existed, removing libfoo would break the dependents.

332
Multi-Selecteasy

Which TWO of the following are Debian package management tools?

Select 2 answers
A.yum
B.dpkg
C.rpm
D.apt
E.zypper
AnswersB, D

The low-level tool that installs, removes and queries individual .deb packages directly, satisfying the stem's requirement for a Debian package management tool. Unlike apt, dpkg does not resolve dependencies or fetch packages from repositories, but it remains the foundational utility underlying all higher-level Debian package managers.

Why this answer

Option B, dpkg, is correct because it is the low-level Debian package manager that installs, removes, and queries .deb packages on Debian-based systems. Option D, apt, is correct because it is the high-level Debian package management front end that resolves dependencies and works with repositories, typically invoking dpkg underneath. The unmarked options do not belong: yum (A) and rpm (C) are Red Hat–family tools for RPM-based distributions, and zypper (E) is the package manager for SUSE/openSUSE, not Debian.

Exam trap

The trap here is that candidates often confuse package managers by distribution family (e.g., thinking yum or rpm could be Debian tools because they are also 'package managers'), but LPIC-1 tests the specific association of dpkg and apt with Debian-based systems versus rpm-based tools like yum, rpm, and zypper.

333
MCQhard

Based on the exhibit, the 'custom' repository shows 0 packages. What is the most likely cause?

A.The repository is disabled because 'enabled=1' is missing
B.The $releasever or $basearch variables are not expanding correctly, leading to an invalid URL
C.The GPG key is missing, causing yum to ignore the repository
D.The repository metadata is corrupt and needs to be regenerated
AnswerB

DNF substitutes $releasever and $basearch at runtime when constructing repository URLs. If either variable fails to expand, the resulting baseurl points to a non-existent path, so metadata retrieval returns nothing and the repository reports zero packages despite being enabled.

Why this answer

The 'custom' repository shows 0 packages because the $releasever or $basearch variables are not expanding correctly, resulting in an invalid or unreachable repository URL. Yum uses these variables to dynamically construct the baseurl, and if they are undefined or incorrect (e.g., due to a missing or misconfigured /etc/yum/vars/ directory or incorrect release version), the repository metadata cannot be downloaded, so yum reports 0 packages available.

Exam trap

The trap here is that candidates often assume 'enabled=1' is mandatory or that GPG key issues cause repositories to be ignored, but the real culprit is variable expansion failure, which silently yields an empty package list without error messages.

How to eliminate wrong answers

Option A is wrong because 'enabled=1' is not required; the default value for 'enabled' is 1 (enabled) if the directive is omitted, so missing it does not disable the repository. Option C is wrong because a missing GPG key would cause yum to warn or fail on package installation, not ignore the repository entirely or show 0 packages; yum still fetches metadata and lists packages even without a GPG key. Option D is wrong because corrupt repository metadata would typically cause a checksum error or a failure to parse the metadata, not a clean display of 0 packages; yum would report an error rather than silently showing zero packages.

334
MCQeasy

A user downloaded a Debian package file named 'software.deb'. Which command should be used to install it?

A.rpm -ivh software.deb
B.apt install software.deb
C.apt-get install software.deb
D.dpkg -i software.deb
AnswerD

dpkg -i installs a local .deb archive and runs its maintainer scripts, operating directly on the downloaded file. The stem specifies a local Debian package, so dpkg is the correct low-level installer rather than apt, which resolves repositories.

Why this answer

The correct command is `dpkg -i software.deb` because `dpkg` is the low-level package manager for Debian-based systems that directly installs `.deb` files. The `-i` flag tells `dpkg` to install the specified package file from the local filesystem, which is exactly what is needed when you have a downloaded `.deb` file.

Exam trap

The trap here is that candidates confuse `apt`/`apt-get` (which manage packages from repositories) with `dpkg` (which handles local `.deb` files), leading them to incorrectly assume `apt install` can accept a filename directly.

How to eliminate wrong answers

Option A is wrong because `rpm` is the package manager for Red Hat-based systems (e.g., Fedora, CentOS) and cannot install Debian `.deb` packages; it expects `.rpm` files. Option B is wrong because `apt install` expects a package name from a configured repository, not a local `.deb` filename; it will fail with an 'unable to locate package' error. Option C is wrong because `apt-get install` also expects a repository package name, not a local file path; it does not accept `.deb` filenames directly.

335
MCQhard

Refer to the exhibit. An administrator is trying to install Google Chrome but receives a GPG error. Which command should be run to add the repository's GPG key?

A.`wget -qO- https://dl.google.com/linux/linux_signing_key.pub | sudo apt-key add -`
B.`gpg --import https://dl.google.com/linux/linux_signing_key.pub`
C.`apt-key adv --keyserver keyserver.ubuntu.com --recv-keys <keyid>`
D.`dpkg --add-key google`
AnswerA

The pipeline downloads Google's signing key and pipes it into apt-key, adding the public key to APT's trusted keyring so the repository's Release signature verifies. This resolves the GPG error caused by the missing key for that repository.

Why this answer

It downloads the Google Linux signing key from the official URL and pipes it directly into `apt-key add`, which imports the key into APT's trusted keyring. This resolves the GPG error by allowing APT to verify the authenticity of packages from the Google Chrome repository.

Exam trap

The trap here is that candidates may confuse `gpg --import` (which affects the user's personal GPG keyring) with `apt-key add` (which affects the system-wide APT trusted keyring), or assume that any keyserver-based retrieval will work for all repositories.

How to eliminate wrong answers

Option B is wrong because `gpg --import` is used to import keys into the local GPG keyring, not into APT's trusted keyring; APT requires keys to be added via `apt-key` or placed in `/etc/apt/trusted.gpg.d/`. Option C is wrong because it assumes the key is available on a keyserver, but Google's signing key is not published on the Ubuntu keyserver; the command would fail to retrieve the key. Option D is wrong because `dpkg --add-key` is not a valid dpkg command; dpkg does not manage GPG keys for APT repositories.

336
MCQeasy

A user reports that they cannot access the company's web server. The administrator confirms the server is running and network connectivity is fine. Which command should be used to verify that the HTTP service is listening on the correct port?

A.ping 127.0.0.1
B.netstat -rn
C.iperf3 -c localhost
D.ss -tlnp
AnswerD

ss -tlnp lists listening TCP sockets with numeric ports and the owning process, directly confirming whether the HTTP service is bound to the expected port. The -l flag restricts output to listening sockets, satisfying the verification requirement.

Why this answer

`ss -tlnp`, is correct because it lists TCP listening sockets with their port numbers and associated processes. The `-t` flag filters for TCP, `-l` shows only listening sockets, `-n` displays numeric addresses and ports (avoiding DNS lookups), and `-p` reveals the process ID/name. This directly verifies whether the HTTP service (typically port 80 or 443) is actively listening on the expected interface.

Exam trap

The trap here is that candidates may confuse general network connectivity tools (ping, iperf3) or routing commands (netstat -rn) with service-specific port listening checks, failing to recognize that only `ss` (or `netstat -tlnp`) directly confirms the HTTP daemon is bound to the correct port.

How to eliminate wrong answers

Option A is wrong because `ping 127.0.0.1` tests only local loopback connectivity and does not check whether a specific service (like HTTP) is listening on a port. Option B is wrong because `netstat -rn` displays the routing table, not listening sockets or service ports. Option C is wrong because `iperf3 -c localhost` is a network throughput testing tool that measures bandwidth between client and server, not a command to verify whether a specific service is listening on a port.

337
MCQmedium

A junior administrator is monitoring a long-running data migration and wants the 'df -h' output for the /data mount point to refresh automatically on screen every 5 seconds, replacing the previous output each time. Which command accomplishes this?

A.watch -n 5 df -h /data
B.nohup df -h /data &
C.at now + 5 minutes -f df -h /data
D.sleep 5 && df -h /data
AnswerA

The watch utility repeatedly executes the given command and redraws the terminal with the latest output, clearing the screen between runs. The -n 5 flag sets a 5-second interval, so the /data usage refreshes in place. This matches the requirement of an automatic, self-replacing display without manual re-invocation.

Why this answer

The watch command is purpose-built for periodically re-running a program and overwriting the terminal display with its newest output. Supplying -n 5 sets the refresh interval to five seconds, and appending the df invocation with the /data path limits monitoring to that mount point. This satisfies the need for hands-free, continuously updated usage information.

Exam trap

The trap here is assuming that backgrounding a command with an ampersand or using sleep creates a repeating refresh, when only a true loop or watch redraws output.

338
MCQmedium

A system administrator needs to see the boot messages recorded by systemd-journald from the current boot. Which command is most appropriate?

A.journalctl -b
B.dmesg
C.tail -n 50 /var/log/syslog
D.cat /var/log/messages
AnswerA

`journalctl -b` reads the journal for the current boot, satisfying the requirement to view systemd-journald boot messages. The `-b` flag filters entries by boot ID, excluding earlier boots, whereas plain `journalctl` would return the entire persistent journal.

Why this answer

The `journalctl -b` command is the most appropriate because it specifically queries the systemd journal for messages from the current boot. Systemd-journald is the default logging daemon on modern Linux distributions, and `journalctl -b` filters the binary journal to show only entries with a boot ID matching the current boot, which includes kernel messages, service logs, and boot-time events.

Exam trap

The trap here is that candidates often confuse `dmesg` (which shows kernel messages) with the full boot log, or assume traditional syslog files like `/var/log/messages` are still the primary source on systemd-based systems, leading them to overlook the journal-specific `journalctl -b` command.

How to eliminate wrong answers

Option B is wrong because `dmesg` shows only kernel ring buffer messages, not the full set of boot messages recorded by systemd-journald (e.g., service startup logs). Option C is wrong because `tail -n 50 /var/log/syslog` reads a traditional text log file that may not exist on systems using journald, and it shows only the last 50 lines of general system logs, not specifically boot messages from the current boot. Option D is wrong because `/var/log/messages` is a legacy log file used by syslog, not by systemd-journald; on modern systems, this file may be absent or incomplete, and it does not provide a boot-specific filter.

339
MCQhard

Refer to the exhibit. The job runs every hour but the administrator notices that it does not execute on Sundays. Which cron syntax element is responsible?

A.The minute field
B.The hour field
C.The month field
D.The day-of-week field
AnswerD

The day-of-week field restricts execution to specific weekdays, so a value excluding Sunday prevents the hourly job from running that day. Since the stem states the job runs hourly but skips Sundays, this field is the only cron element that can suppress execution on a single weekday while leaving other days unaffected.

Why this answer

The day-of-week field (the 5th field in a cron expression) controls which days of the week the job runs. If this field is set to 1-6 (Monday–Saturday) or explicitly excludes 0/7 (Sunday), the job will not execute on Sundays. Since the job runs every hour but not on Sundays, the day-of-week field is responsible.

Exam trap

The trap here is that candidates often confuse the day-of-month field (3rd field) with the day-of-week field (5th field), or assume the hour field controls daily execution, when in fact the day-of-week field is the only one that can selectively exclude a specific weekday like Sunday.

How to eliminate wrong answers

Option A is wrong because the minute field (1st field) controls the minute within the hour when the job runs, not the day of the week; it would affect timing within each hour, not skip entire days. Option B is wrong because the hour field (2nd field) controls which hours of the day the job runs, not which days of the week; it could restrict execution to certain hours but cannot exclude an entire day like Sunday. Option C is wrong because the month field (4th field) controls which months the job runs, not days of the week; it could skip entire months but not specific weekdays.

340
MCQeasy

A user reports that when they run 'ls -l' in their home directory, they see files but all files have permissions like '-rwxrwxrwx', which is unexpected. The system administrator checks and finds that the user's umask is set to 000. The user wants all new files to be created with default permissions of -rw-r--r-- (644) and directories that are drwxr-xr-x (755). What should the user set their umask to?

A.007
B.022
C.002
D.027
AnswerB

The umask is subtracted from the base permissions 666 for files and 777 for directories. With 022, files become 644 and directories 755, exactly matching the user's requested defaults, replacing the current 000 setting that produced world-writable entries.

Why this answer

The umask is a three-digit octal value that is subtracted from the default base permissions (666 for files, 777 for directories) to determine the default permissions for newly created files and directories. To achieve file permissions of 644 (rw-r--r--) and directory permissions of 755 (rwxr-xr-x), the umask must be 022. This is because 666 - 022 = 644 for files, and 777 - 022 = 755 for directories.

Exam trap

The trap here is that candidates often mistakenly think the umask is added to or directly specifies the permissions, rather than understanding it is subtracted from the default base permissions (666 for files, 777 for directories).

How to eliminate wrong answers

Option A (007) is wrong because it would result in file permissions of 660 (rw-rw----) and directory permissions of 770 (rwxrwx---), which are too restrictive for the desired 644/755. Option C (002) is wrong because it would yield file permissions of 664 (rw-rw-r--) and directory permissions of 775 (rwxrwxr-x), giving group write access, which is not the requested 644/755. Option D (027) is wrong because it would produce file permissions of 640 (rw-r-----) and directory permissions of 750 (rwxr-x---), which are too restrictive for both files and directories.

341
MCQmedium

A system administrator wants to monitor network traffic on a specific port (TCP/443) entering the server. Which command will capture packets on interface eth0 and display them in real-time?

A.netstat -tulpn | grep :443
B.ss -tulpn | grep :443
C.tcpdump -i eth0 port 443
D.iptables -L -n -v
AnswerC

tcpdump captures live packets on a named interface, and the port 443 filter restricts output to TCP/443 traffic, satisfying both the interface and real-time display requirements. Other tools either read saved files or lack equivalent filtering.

Why this answer

C is correct because `tcpdump -i eth0 port 443` captures packets on interface eth0 filtering for TCP port 443 (HTTPS) and displays them in real-time as they arrive. This command uses the libpcap library to intercept raw network frames, making it the standard tool for live packet capture and analysis.

Exam trap

The trap here is that candidates confuse commands that show socket state (netstat/ss) with commands that capture live packets (tcpdump), leading them to pick a command that only lists current connections rather than monitoring traffic in real-time.

How to eliminate wrong answers

Option A is wrong because `netstat -tulpn | grep :443` shows listening sockets and established connections, not live packet capture; it only displays current socket states from /proc/net/tcp, not real-time traffic. Option B is wrong because `ss -tulpn | grep :443` similarly lists socket statistics from kernel data, not packet-level capture; it cannot show individual packets or their contents. Option D is wrong because `iptables -L -n -v` lists firewall rules and their packet/byte counters, but it does not capture or display packet contents in real-time; it only shows accumulated statistics for rules.

342
Multi-Selectmedium

Which three actions can an administrator take to securely erase data on a disk before decommissioning?

Select 3 answers
A.Format the disk with mkfs.
B.Delete the partition and create a new one.
C.Run dd if=/dev/urandom of=/dev/sda.
D.Run shred -n 3 /dev/sda.
E.Use the hdparm command with the --security-erase option.
AnswersC, D, E

Writing pseudorandom bytes from /dev/urandom across the whole block device overwrites every sector, including filesystem metadata, making prior data unrecoverable. This satisfies the secure erasure requirement by destroying the original contents rather than merely unlinking files.

Why this answer

Option C is correct because writing random data from /dev/urandom over the entire raw device /dev/sda with dd overwrites every sector, making the original data unrecoverable. Option D is correct because shred -n 3 /dev/sda performs three passes of overwriting on the block device, which securely destroys the prior contents. Option E is correct because hdparm --security-erase invokes the drive's ATA Secure Erase firmware command, which securely erases all sectors including remapped ones.

Option A is not correct because mkfs only creates a new filesystem and leaves the underlying data blocks intact and recoverable. Option B is not correct because deleting and recreating a partition only modifies the partition table and does not overwrite the data stored on the disk.

Exam trap

The trap here is that candidates often think `mkfs` or partition deletion fully erases data, when in fact they only remove logical pointers, leaving the raw data recoverable with simple forensic tools.

343
MCQmedium

During boot, a server loads the wrong kernel. Which file should the administrator modify to change the default kernel in a standard GRUB 2 configuration?

A./boot/grub/grub.conf
B./etc/grub.d/
C./etc/default/grub
D./boot/grub/grub.cfg
AnswerC

Editing `/etc/default/grub` sets the `GRUB_DEFAULT` variable, which selects the default menu entry by index, title or saved entry. Regenerating `grub.cfg` with `grub-mkconfig` then applies that choice, satisfying the requirement to change the default kernel persistently in a standard GRUB 2 setup.

Why this answer

In a standard GRUB 2 configuration, the default kernel is selected by setting the GRUB_DEFAULT variable in /etc/default/grub. After modifying this file, the administrator must run update-grub (or grub-mkconfig) to regenerate the /boot/grub/grub.cfg file, which is the actual configuration read by the bootloader. This two-step process separates user-facing settings from the bootloader's runtime configuration.

Exam trap

The trap here is that candidates confuse the GRUB 2 configuration file (/etc/default/grub) with the GRUB Legacy file (/boot/grub/grub.conf) or the auto-generated runtime file (/boot/grub/grub.cfg), leading them to pick an option that either belongs to an older bootloader version or is not meant for direct editing.

How to eliminate wrong answers

Option A is wrong because /boot/grub/grub.conf is the configuration file for GRUB Legacy, not GRUB 2; GRUB 2 uses /boot/grub/grub.cfg. Option B is wrong because /etc/grub.d/ is a directory containing scripts that generate parts of the GRUB 2 configuration, but editing these scripts directly is not the standard way to change the default kernel; the correct approach is to set GRUB_DEFAULT in /etc/default/grub. Option D is wrong because /boot/grub/grub.cfg is the auto-generated runtime configuration file; manually editing it is discouraged as changes will be overwritten by update-grub, and the proper method is to modify /etc/default/grub and regenerate the file.

344
MCQhard

A system administrator needs to ensure that a custom kernel module named 'mydriver.ko' is loaded automatically at boot on a system that uses systemd. The module is located in /lib/modules/$(uname -r)/extra/. Which approach is most appropriate?

A.Add the line 'mydriver' to /etc/modules.
B.Insert the module into the initramfs using 'mkinitrd' and rely on it being loaded during early boot.
C.Run 'modprobe mydriver' and add it to /etc/rc.local.
D.Create a file /etc/modules-load.d/mydriver.conf containing the line 'mydriver'.
AnswerD

The systemd-modules-load.service reads configuration files from /etc/modules-load.d/ and loads the listed modules at boot. Placing the module name in a .conf file there ensures it is loaded automatically. This is the systemd-native method for specifying modules to load at startup.

Why this answer

On systemd-based systems, the systemd-modules-load service is responsible for loading modules at boot based on configuration files in /etc/modules-load.d/, /run/modules-load.d/, and /usr/lib/modules-load.d/. Creating a .conf file with the module name in /etc/modules-load.d/ is the correct, supported method. Other approaches may work incidentally but are not the intended mechanism.

Exam trap

The trap here is assuming that any file named /etc/modules will be honored by systemd, when the correct directory is /etc/modules-load.d/.

345
Multi-Selectmedium

An administrator needs to gather detailed information about the partition table and filesystem geometry of /dev/sda before migrating data. Which TWO commands will display the partition layout of the disk? (Choose two.)

Select 2 answers
A.fdisk -l /dev/sda
B.lsblk -f /dev/sda
C.blkid /dev/sda
D.df -h /dev/sda
E.parted /dev/sda print
AnswersA, E

fdisk -l lists the partition table of the specified disk, showing partition numbers, start and end sectors, sizes, and type codes for both MBR and GPT layouts. It reads the on-disk partition table directly, so it reports the actual partition boundaries the administrator needs for migration planning. This is a standard, reliable way to inspect disk partitioning without modifying anything.

Why this answer

Both fdisk -l and parted print read and display the on-disk partition table, enumerating partitions with their start and end positions and the table type. The other tools focus on filesystem identity or capacity rather than partitioning: blkid and lsblk -f describe what filesystems exist, and df reports mount usage. For migration planning that requires partition geometry, the partition-table readers are the correct choices.

Exam trap

The trap here is treating lsblk or blkid as partition-layout tools, when they actually report filesystem and device attributes rather than the partition table itself.

346
MCQmedium

A junior administrator runs `ps aux` and sees a process owned by user 'deploy' with STAT code 'T'. The process is a long-running data migration script. The administrator wants to know what this status means and what will happen if no action is taken. Which statement correctly describes the process state?

A.The process is in an uninterruptible sleep, usually waiting for I/O, and cannot be killed until the I/O completes.
B.The process is stopped (suspended) and will not run until it receives SIGCONT or is resumed.
C.The process is a zombie and its parent has not yet reaped it, so it consumes no CPU but remains in the process table.
D.The process is being traced by a debugger and is currently paused at a breakpoint.
AnswerB

In `ps` output, the STAT code 'T' indicates the process is stopped, typically by a job control signal such as SIGSTOP or SIGTSTP. It remains in memory but is not scheduled for execution. The migration script will not make progress until it is resumed with SIGCONT (e.g., `kill -CONT <pid>`) or brought to the foreground with `fg` if it is a shell job.

Why this answer

The STAT column of `ps` encodes process state. Uppercase 'T' means the process has been stopped by a job-control signal (SIGSTOP, SIGTSTP, or SIGTTIN/SIGTTOU) and is not running. To resume it, send SIGCONT or use shell job control.

Without intervention, a stopped process makes no progress, which can stall a migration indefinitely.

Exam trap

The trap here is confusing the stopped state 'T' with the zombie state 'Z' or the uninterruptible sleep state 'D', because all three indicate a process that is not actively running.

347
MCQmedium

An administrator needs to mount an ISO image file /tmp/image.iso to the directory /mnt/iso. Which command should be used?

A.mount -o loop /tmp/image.iso /mnt/iso
B.mount -o ro /tmp/image.iso /mnt/iso
C.mount -t iso /tmp/image.iso /mnt/iso
D.mount /tmp/image.iso /mnt/iso
AnswerA

The loop option attaches the ISO as a loopback block device, allowing the kernel to read its ISO9660 filesystem and mount it at /mnt/iso. Without -o loop, mount would treat the file as a raw block device and fail.

Why this answer

The `-o loop` option tells the mount command to use a loop device, which is required to mount a file (like an ISO image) as if it were a block device. Without the loop option, mount expects a block device path, not a regular file.

Exam trap

The trap here is that candidates often forget the `-o loop` option and assume mount can directly handle a file path, or they confuse the read-only option (`-o ro`) with the loop option, thinking read-only is sufficient for ISO images.

How to eliminate wrong answers

Option B is wrong because `-o ro` only mounts the filesystem as read-only, but it does not enable loop device support, so mount will fail with an error like 'mount: /tmp/image.iso is not a block device'. Option C is wrong because `-t iso` is not a valid filesystem type; the correct type for ISO images is `iso9660` (or `udf`), and even with the correct type, the loop option is still required. Option D is wrong because without any options, mount expects a block device as the first argument, not a regular file, and will reject the ISO file.

348
MCQeasy

An administrator is configuring a DHCP server to assign IP addresses to clients in the 192.168.10.0/24 subnet. The server should provide the default gateway as 192.168.10.1 and DNS server as 8.8.8.8. Which option in /etc/dhcp/dhcpd.conf defines the default gateway?

A.option subnet-mask 255.255.255.0;
B.option routers 192.168.10.1;
C.option broadcast-address 192.168.10.255;
D.option domain-name-servers 8.8.8.8;
AnswerB

`option routers` is the DHCP parameter that delivers the default gateway address to clients, satisfying the stem's requirement to advertise 192.168.10.1 as the gateway for the 192.168.10.0/24 subnet. The `routers` option maps directly to DHCP option 3, which clients interpret as their default route.

Why this answer

The `option routers` directive in the ISC DHCP server configuration file `/etc/dhcp/dhcpd.conf` explicitly defines the default gateway (router) that clients should use. This directive sends the Router Option (option 3) in the DHCPOFFER and DHCPACK messages, instructing clients to set their default route to the specified IP address.

Exam trap

The trap here is that candidates may confuse the `option routers` directive with `option domain-name-servers` or `option subnet-mask`, especially since all three are commonly used together in a subnet declaration, but only `option routers` sets the default gateway.

How to eliminate wrong answers

Option A is wrong because `option subnet-mask 255.255.255.0;` defines the subnet mask (option 1) for the client, not the default gateway. Option C is wrong because `option broadcast-address 192.168.10.255;` sets the broadcast address (option 28) for the subnet, which is a separate parameter from the router. Option D is wrong because `option domain-name-servers 8.8.8.8;` specifies the DNS server (option 6) for name resolution, not the default gateway.

349
MCQeasy

Which command is used to view the last few lines of a log file and simultaneously follow new entries as they are written?

A.tail -f
B.cat
C.head -n 10
D.less
AnswerA

tail -f keeps the file descriptor open and prints appended lines as they are written, after showing the final lines by default. Other tools such as cat or less do not continuously follow growth, so tail -f satisfies both the initial view and live monitoring requirement.

Why this answer

The `tail -f` command is correct because it displays the last 10 lines of a file by default and then continues to monitor the file for new lines, outputting them as they are appended. This is essential for real-time log monitoring, as it uses inotify or polling to detect file changes without requiring manual re-reading.

Exam trap

The trap here is that candidates may confuse `tail -f` with `less` (which can also follow with `Shift+F`), but the question explicitly asks for the command that 'simultaneously follow new entries as they are written' in its default invocation, making `tail -f` the only correct answer without requiring additional key presses.

How to eliminate wrong answers

Option B (cat) is wrong because it outputs the entire file content at once and then exits, providing no ability to follow new entries. Option C (head -n 10) is wrong because it only shows the first 10 lines of a file and does not monitor for updates. Option D (less) is wrong because while it can view files interactively and with `Shift+F` can follow new entries, the default behavior does not follow; the question specifies 'simultaneously follow new entries as they are written,' which `tail -f` does directly without requiring a special key sequence.

350
MCQeasy

Refer to the exhibit. This line is from /etc/passwd. What does the third field (1001) represent?

A.Home directory UID
B.Group ID (GID)
C.User ID (UID)
D.Login shell number
AnswerC

The third colon-separated field in /etc/passwd holds the numeric user identifier assigned to the account. It is the UID the kernel uses internally for ownership and permission checks, distinct from the username in field one and the GID in field four.

Why this answer

In the /etc/passwd file, the third field is the User ID (UID), a numeric identifier assigned to each user. UID 0 is reserved for root, and values below 1000 are typically system accounts, while 1001 is a regular user UID. This field is used by the kernel to track user ownership of processes and files.

Exam trap

The trap here is that candidates often confuse the order of fields in /etc/passwd, specifically mixing up the UID (third field) with the GID (fourth field), because both are numeric identifiers.

How to eliminate wrong answers

Option A is wrong because the home directory is specified in the sixth field of /etc/passwd, not the third. Option B is wrong because the Group ID (GID) is the fourth field, not the third. Option D is wrong because the login shell is the seventh field, and there is no 'login shell number' field in /etc/passwd.

351
MCQhard

Refer to the exhibit. What is the purpose of the 'test -x /usr/sbin/anacron' command in the cron entries?

A.It checks if anacron is executable and then runs the periodic tasks.
B.It starts anacron if it is not already running.
C.It ensures the periodic tasks are not run if anacron is installed.
D.It logs the output of the periodic tasks to a file.
AnswerC

The `test -x /usr/sbin/anacron` check returns true when the anacron binary exists and is executable, so the following `||` branch runs cron.daily, cron.weekly and cron.hourly only on systems lacking anacron. This prevents duplicate execution of periodic jobs where anacron already schedules them, satisfying the stem's condition of suppressing cron runs when anacron is present.

Why this answer

The 'test -x /usr/sbin/anacron' command checks if the anacron binary exists and is executable. If it is, the test returns true (exit code 0), and the subsequent periodic tasks (e.g., run-parts) are skipped due to the logical NOT operator '!' at the beginning of the cron entry. This prevents duplicate execution of periodic jobs when both cron and anacron are installed, as anacron is designed to handle them for systems that may not be running continuously.

Exam trap

The trap here is that candidates assume 'test -x' runs or starts anacron, when in fact it is a conditional check used with '!' to suppress duplicate job execution.

How to eliminate wrong answers

Option A is wrong because 'test -x' only checks for executability; it does not execute anacron or run any tasks. Option B is wrong because the command does not start anacron; it merely tests its presence, and the cron entry uses '!' to skip tasks if anacron is present, not to launch it. Option D is wrong because the command does not involve logging; it is a simple file test, and any logging would be handled by separate redirection or the cron daemon itself.

352
MCQeasy

An administrator needs to replace all occurrences of 'old_host' with 'new_host' in the file /etc/hosts. Which sed command should be used?

A.sed -n 's/old_host/new_host/gp' /etc/hosts
B.sed -i 's/old_host/new_host/' /etc/hosts
C.sed -i 's/old_host/new_host/g' /etc/hosts
D.sed 's/old_host/new_host/g' /etc/hosts
AnswerC

The `-i` flag edits /etc/hosts in place, satisfying the requirement to replace all occurrences without redirecting to a temporary file. The `g` suffix applies the substitution globally across every match on each line, not merely the first, so multiple instances of 'old_host' are all rewritten to 'new_host'.

Why this answer

The `-i` flag enables in-place editing of the file, and the `g` flag (global) ensures all occurrences on each line are replaced, not just the first. The command `sed -i 's/old_host/new_host/g' /etc/hosts` modifies the file directly, replacing every instance of 'old_host' with 'new_host' throughout the file.

Exam trap

The trap here is that candidates often forget the `g` flag for global replacement or omit the `-i` flag for in-place editing, mistakenly thinking sed modifies files by default.

How to eliminate wrong answers

Option A is wrong because the `-n` flag suppresses automatic printing, and `p` prints only lines where a substitution occurred, but without `-i` the file is not modified, so no changes are saved. Option B is wrong because it omits the `g` flag, so only the first occurrence of 'old_host' on each line is replaced, leaving subsequent occurrences unchanged. Option D is wrong because without `-i`, sed writes the modified output to stdout and does not alter the original file /etc/hosts.

353
Multi-Selectmedium

Which TWO statements about udev rules are correct? (Choose two.)

Select 2 answers
A.Custom udev rules should be placed in /etc/udev/rules.d/.
B.Udev rules are only applied at boot time.
C.Udev rules can be used to schedule periodic tasks via cron.
D.Rules can match on attributes such as vendor ID and product ID.
E.The 'udevadm verify' command tests rule syntax.
AnswersA, D

Placing custom rules in /etc/udev/rules.d/ satisfies the requirement for persistent, administrator-defined device naming that survives package upgrades. Files here are parsed before /usr/lib/udev/rules.d/, so local rules take precedence, and the directory is reserved for local administration rather than vendor-supplied defaults.

Why this answer

Option A is correct because locally administered custom udev rules belong in /etc/udev/rules.d/, which takes precedence over the distribution-supplied rules in /usr/lib/udev/rules.d/ and is the supported location for administrator-defined rules. Option D is correct because udev rules match devices using keys such as ATTRS{idVendor} and ATTRS{idProduct} (or ENV{ID_VENDOR_ID}/ENV{ID_MODEL_ID} from the hardware database), allowing rules to target specific USB vendor and product IDs. Option B is wrong because udev processes events dynamically whenever devices are added or removed at runtime, not only at boot.

Option C is wrong because udev is a device manager for the kernel device model and has no scheduling capability; periodic tasks are handled by cron or systemd timers. Option E is wrong because there is no 'udevadm verify' subcommand; syntax checking is done with 'udevadm test' or 'udevadm test-builtin', while 'udevadm control --reload' reloads rules.

Exam trap

The trap here is that candidates may confuse 'udevadm verify' with a real command, but the LPIC-1 exam tests knowledge of the actual udevadm subcommands, and 'verify' is not one of them.

354
MCQmedium

A system administrator notices that a server with a freshly installed Linux system fails to boot with the error 'No bootable device found'. The server has a single SATA hard disk connected to the motherboard's SATA controller. Which of the following is the most likely cause of this issue?

A.The root filesystem is formatted with an unsupported filesystem type.
B.The kernel module for the SATA controller is not included in the initramfs.
C.The GRUB bootloader configuration file is missing or corrupted.
D.The BIOS boot order is set to a device that does not contain a bootable operating system.
AnswerD

A freshly installed disk with no bootloader leaves the firmware with nothing to hand off to. If the BIOS boot order still prioritises another device, such as the network or optical drive, the system reports 'No bootable device found' rather than reading the SATA disk.

Why this answer

The error 'No bootable device found' occurs during the BIOS/UEFI POST phase, before any bootloader is loaded. This indicates that the system firmware cannot find a valid boot sector on any device in its boot order. Since the server has a single SATA hard disk, the most likely cause is that the BIOS boot order is set to a different device (e.g., a network boot or removable media) that does not contain a bootable operating system, or the hard disk itself is not listed first in the boot priority.

Exam trap

The trap here is that candidates often confuse a pre-boot firmware error with a bootloader or kernel issue, leading them to incorrectly select options related to GRUB configuration or initramfs modules, when the actual problem is a simple BIOS boot order misconfiguration.

How to eliminate wrong answers

Option A is wrong because an unsupported root filesystem type would cause a kernel panic or mount failure during the boot process, not a 'No bootable device found' error, which occurs before the kernel is loaded. Option B is wrong because a missing SATA controller kernel module in the initramfs would result in a kernel panic or inability to mount the root filesystem after the bootloader loads, not a pre-boot firmware error. Option C is wrong because a missing or corrupted GRUB configuration file would cause GRUB to drop to a rescue shell or display a GRUB-specific error, not a 'No bootable device found' message, which is issued by the BIOS/UEFI before any bootloader is executed.

355
Multi-Selecthard

Which THREE of the following are characteristics of UEFI firmware compared to legacy BIOS? (Select exactly 3.)

Select 3 answers
A.Supports booting from disks larger than 2 TB.
B.Provides a graphical user interface during firmware setup.
C.Supports Secure Boot to prevent unauthorized operating systems from loading.
D.Uses the Master Boot Record partition table.
E.Requires a boot loader stored in the Master Boot Record.
AnswersA, B, C

UEFI uses GPT which supports large disks.

Why this answer

UEFI firmware uses the GUID Partition Table (GPT) instead of MBR, which supports 64-bit logical block addressing (LBA). This allows addressing disks larger than 2 TB, as the MBR scheme is limited to 32-bit LBA and a maximum addressable size of approximately 2.2 TB. Therefore, option A is correct.

Exam trap

The trap here is that candidates often confuse UEFI's support for GPT with MBR, incorrectly assuming UEFI still uses MBR for partition tables or boot loaders, leading them to select D or E as correct.

356
MCQeasy

Which of the following commands displays the amount of free disk space on all mounted filesystems in a human-readable format?

A.df -i
B.df -h
C.du -sh
D.df -T
AnswerB

The -h flag makes df print sizes in powers of 1024 with human-readable suffixes (K, M, G), satisfying the human-readable requirement. Without it, df reports raw 1K blocks across all mounted filesystems, which is harder to interpret.

Why this answer

The `df -h` command displays disk space usage for all mounted filesystems with sizes in human-readable units (e.g., KB, MB, GB). The `-h` flag converts raw block counts into powers of 1024 with appropriate suffixes, making the output easy to interpret at a glance.

Exam trap

The trap here is that candidates often confuse `df -h` (free disk space) with `du -sh` (used space for a directory) or `df -i` (inode usage), because all three involve storage-related metrics but serve fundamentally different purposes.

How to eliminate wrong answers

Option A is wrong because `df -i` shows inode usage, not disk space; it reports the number of used and free inodes on each filesystem, which is a separate resource from data blocks. Option C is wrong because `du -sh` estimates the total disk space used by a specific directory or file (defaulting to the current directory), not free space across all mounted filesystems. Option D is wrong because `df -T` displays the filesystem type (e.g., ext4, xfs) in addition to disk usage, but does not enable human-readable formatting; it still outputs sizes in 1K blocks unless combined with `-h`.

357
MCQeasy

A Linux administrator needs to view the current kernel ring buffer messages to diagnose a hardware issue that occurred during boot. Which command will display these messages?

A.journalctl -k
B.tail -f /var/log/syslog
C.dmesg
D.cat /var/log/messages
AnswerC

The dmesg command displays the kernel ring buffer, which contains messages from the kernel, including hardware detection, driver loading, and boot-time messages. It is the standard tool to view these messages in real time or from the last boot. The administrator can use dmesg to diagnose hardware issues by examining the output for errors or warnings related to devices.

Why this answer

The kernel ring buffer stores messages generated by the kernel, including hardware detection and driver initialization. The dmesg command is specifically designed to read and display this buffer. Other commands like journalctl -k or log files may contain overlapping information but are not guaranteed to show the full ring buffer, especially for early boot messages.

Therefore, dmesg is the most direct and reliable choice.

Exam trap

The trap here is confusing the kernel ring buffer with general system logs, leading to commands that may not show all hardware messages.

358
MCQeasy

During the boot process, the system stops at a GRUB prompt. Which command should be typed to continue booting?

A.quit
B.start
C.exit
D.boot
AnswerD

At the GRUB prompt, the boot command instructs GRUB to load the configured kernel and initrd and transfer control to the kernel, continuing the boot process. Other commands such as ls or set merely inspect configuration and do not initiate loading, so boot is required to proceed.

Why this answer

The 'boot' command at the GRUB prompt instructs the bootloader to load the selected kernel and initramfs, then transfer control to the kernel to continue the boot process. This is the standard way to proceed from the GRUB command-line interface when the system halts at a GRUB prompt.

Exam trap

A common misconception is that typing 'exit' or 'quit' will resume the boot process, but in GRUB, only 'boot' triggers the actual kernel execution.

How to eliminate wrong answers

Option A is wrong because 'quit' is not a valid GRUB command; it would be ignored or cause an error. Option B is wrong because 'start' is not a GRUB command; GRUB uses 'boot' to initiate the boot process. Option C is wrong because 'exit' is not a valid GRUB command; in GRUB, you use 'boot' to continue booting, not 'exit'.

359
MCQhard

A medium-sized company runs a web application on a Linux server. The server uses systemd and has the following configuration: the web application service (webapp.service) is configured to start after network.target and requires a database service (database.service) to be running. The database service has a Restart=on-failure directive. Recently, the server experienced a power outage. Upon reboot, the system administrator notices that the web application fails to start because the database service is in a failed state. The administrator checks the status of database.service and sees 'inactive (dead)' with no recent attempts to restart. The journal shows that the database service failed to start because a required filesystem (mounted at /var/lib/database) was not mounted when the database service tried to start. The filesystem is listed in /etc/fstab with the nofail option. The administrator wants to ensure that in future reboots, the database service starts successfully and the web application comes up without manual intervention. Which of the following is the best course of action?

A.Change the Restart directive in database.service to 'always'
B.Remove the nofail option from /etc/fstab for /var/lib/database
C.Modify the database.service unit file to add 'After=var-lib-database.mount' and 'Requires=var-lib-database.mount'
D.Modify the webapp.service unit file to add 'After=database.service' and 'Requires=database.service'
AnswerC

Because /var/lib/database is mounted with nofail, boot proceeds without it, so database.service starts before the mount exists and fails. Adding After= and Requires=var-lib-database.mount creates an ordering and dependency link, forcing systemd to mount the filesystem first.

Why this answer

The database service failed due to a missing mount at /var/lib/database. By adding 'After=var-lib-database.mount' and 'Requires=var-lib-database.mount' to the database.service unit, systemd will ensure the mount unit is started before the database service and that the database service is stopped if the mount fails. This directly addresses the root cause—the filesystem not being ready—without altering the restart behavior or the fstab nofail option, which is appropriate for allowing the system to boot even if the mount fails.

Exam trap

The trap here is that candidates often focus on restart policies (Option A) or fstab options (Option B) without realizing that systemd's dependency system must be used to enforce ordering between services and mount units, especially when nofail is present.

How to eliminate wrong answers

Option A is wrong because changing Restart to 'always' would cause the database service to restart indefinitely even after successful runs, but it does not solve the underlying issue of the mount not being ready; the service would still fail on the first attempt if the mount is missing, and Restart=on-failure already handles restarts after failure, but the service never got a chance to restart because it was never started again after the initial failure. Option B is wrong because removing the nofail option from /etc/fstab would cause the system to fail to boot entirely if the filesystem cannot be mounted, which is worse than the current behavior; the nofail option is correctly used to allow boot to proceed, but the dependency must be expressed in systemd units. Option D is wrong because webapp.service already has 'After=database.service' and 'Requires=database.service' (implied by the requirement that the database service must be running), so adding them again does nothing; the problem is that database.service itself fails due to the mount, not that webapp.service lacks ordering or dependency on database.service.

360
MCQeasy

Refer to the exhibit. An administrator wants to verify the integrity of the kernel-core package by checking its signature. Which command is used?

A.`rpm -qa kernel-core`
B.`rpm -q --changelog kernel-core`
C.`rpm -K kernel-core`
D.`rpm -V kernel-core`
AnswerC

The -K flag performs a signature and digest verification on the named package, checking its GPG signature against the imported Red Hat keys. This directly satisfies the requirement to verify kernel-core's integrity, unlike -V, which only compares installed file attributes against the RPM database.

Why this answer

`rpm -K` (or `rpm --checksig`) is the command used to verify the GPG signature of an RPM package, ensuring its integrity and authenticity. This checks the package's cryptographic signature against the imported GPG key, confirming it has not been tampered with.

Exam trap

The trap here is confusing `rpm -V` (verify installed files) with `rpm -K` (verify package signature), as both involve 'verification' but operate on different targets and use different mechanisms.

How to eliminate wrong answers

Option A is wrong because `rpm -qa kernel-core` lists all installed packages matching the name 'kernel-core', but does not verify any signature. Option B is wrong because `rpm -q --changelog kernel-core` displays the changelog of the installed package, which is unrelated to signature verification. Option D is wrong because `rpm -V kernel-core` verifies the installed files' attributes (size, permissions, checksums) against the RPM database, but does not check the package's cryptographic signature.

361
Multi-Selectmedium

A Linux administrator needs to configure a new system to automatically mount an NFS share at boot. The share is exported from server 'nfs.example.com' as '/export/data'. The mount point '/mnt/data' already exists. Which TWO actions are required to ensure the share is mounted automatically and persistently? (Choose two.)

Select 2 answers
A.Install the NFS client utilities (e.g., nfs-common or nfs-utils).
B.Run 'mount -a' to mount all entries in /etc/fstab.
C.Ensure the 'nfs' service is running on the client.
D.Add the NFS share to /etc/exports.
E.Add an entry to /etc/fstab with the NFS share and mount point.
AnswersA, E

To mount an NFS share, the client system needs the appropriate NFS client utilities installed, such as nfs-common on Debian-based systems or nfs-utils on Red Hat-based systems. These packages provide the mount.nfs helper and other tools needed to mount NFS filesystems. Without them, the mount command will fail.

Why this answer

To automatically mount an NFS share at boot, you must add an entry to /etc/fstab and ensure the NFS client utilities are installed. The fstab entry defines the mount, and the utilities provide the necessary mount.nfs helper. Other actions like running mount -a are for immediate mounting, modifying /etc/exports is for servers, and running the nfs service is not required on the client.

Exam trap

The trap here is confusing client and server roles, or thinking that the nfs service must run on the client; actually, only the client utilities are needed.

362
MCQmedium

An administrator plans to back up the /home filesystem using dump. Which option to dump is required to perform a full backup?

A.-f /dev/st0
B.-u
C.-0
D.-1
AnswerC

Dump level 0 copies every inode and block regardless of prior dumps, producing a complete backup. Higher levels (1-9) are incremental, capturing only changes since the last lower-level dump, so -0 is required for the full backup the administrator plans.

Why this answer

The dump utility uses dump levels (0-9) to control backup depth. A level 0 dump performs a full backup of the specified filesystem, copying all files regardless of modification time. This is the required option for a complete backup of /home.

Exam trap

The trap here is that candidates confuse the -0 option with a generic flag or think -1 is the full backup because it is the lowest non-zero number, but dump levels start at 0 for full backups.

How to eliminate wrong answers

Option A is wrong because -f /dev/st0 specifies the output device (tape drive), not the backup level; it is optional and not required for a full backup. Option B is wrong because -u updates the /etc/dumpdates file with the backup timestamp, but does not control whether the backup is full or incremental. Option D is wrong because -1 specifies an incremental backup level 1, which only backs up files changed since the last lower-level dump (e.g., level 0), not a full backup.

363
MCQmedium

Refer to the exhibit. Which statement is true about SSH root login on this server?

A.Root can log in only from localhost.
B.Root cannot log in at all.
C.Root can log in using a public key.
D.Root can log in with a password.
AnswerC

The sshd_config directive PermitRootLogin is set to prohibit-password, which blocks password authentication for root while still allowing public-key authentication. Root therefore cannot log in with a password but can authenticate using an authorised key pair.

Why this answer

The exhibit shows that `PermitRootLogin` is set to `prohibit-password` in the SSH server configuration. This setting explicitly disables password-based authentication for root, but allows root login using public key authentication. Therefore, root can log in only by presenting a valid private key that matches an authorized public key, making option C correct.

Exam trap

The trap here is that candidates often misinterpret `prohibit-password` as a complete ban on root login, when in fact it only blocks password-based authentication and still allows key-based login.

How to eliminate wrong answers

Option A is wrong because `PermitRootLogin prohibit-password` does not restrict root to localhost; it only prohibits password authentication, not key-based authentication from any host. Option B is wrong because root can still log in using public key authentication, so a complete login ban is not in effect. Option D is wrong because `prohibit-password` explicitly disables password-based login for root, so root cannot log in with a password.

364
MCQeasy

A script contains the following line: for i in $(cat file.txt); do echo $i; done. The file file.txt contains a single line with multiple words. How many times will the loop execute?

A.Equal to the number of lines in the file
B.Equal to the number of words in the file
C.Once
D.The loop will not execute
AnswerB

Command substitution splits on IFS whitespace, so each word from the single line becomes a separate argument to `for`. The loop therefore iterates once per word, satisfying the stem's constraint of one line containing multiple words. Word count, not line count, determines execution.

Why this answer

The command substitution $(cat file.txt) expands to the content of file.txt, which is a single line with multiple words. The for loop iterates over each word (separated by whitespace) in the expanded string, not over lines. Therefore, the loop executes once per word in the file.

Exam trap

The trap here is that candidates often assume $(cat file.txt) preserves line boundaries, but the for loop splits the output by whitespace, so the number of iterations equals the number of words, not lines.

How to eliminate wrong answers

Option A is wrong because the loop iterates over words, not lines; $(cat file.txt) splits the output by whitespace (default IFS), so the number of iterations equals the number of words, not lines. Option C is wrong because the loop does not execute once; it executes multiple times, once for each word in the single line. Option D is wrong because the loop will execute; file.txt exists and contains data, so the command substitution produces a non-empty string, causing the loop to run.

365
MCQhard

A company runs a legacy application on a Linux server. The application fails to start after a reboot, claiming a 'cannot open shared object file' error. The system administrator checks the library path and finds that the required library is present in /usr/local/lib but the application cannot find it. The administrator has verified that the library file exists and is readable. Which of the following is the most likely cause and solution?

A.The library has insufficient execute permissions; add execute bit.
B.The application is setuid root and the library path is ignored; use $LD_LIBRARY_PATH.
C.The library path is not in /etc/ld.so.conf; run ldconfig after adding it.
D.The library is compiled for a different architecture; recompile the library.
AnswerC

The dynamic linker only searches directories listed in /etc/ld.so.conf and its includes, plus the cache built by ldconfig. Adding /usr/local/lib to that configuration and running ldconfig registers the library in the cache, letting the application resolve the shared object at startup.

Why this answer

The dynamic linker/loader (ld.so) uses the cache file /etc/ld.so.cache to resolve shared library dependencies at runtime. Although the library exists in /usr/local/lib, that path is not listed in /etc/ld.so.conf (or a file included by it), so the linker never scans it. Running ldconfig rebuilds the cache and makes the library discoverable, which resolves the 'cannot open shared object file' error.

Exam trap

The trap here is that candidates assume a library found in a standard-looking path like /usr/local/lib is automatically searched, but the dynamic linker only uses paths explicitly listed in /etc/ld.so.conf (or its included files) after running ldconfig.

How to eliminate wrong answers

Option A is wrong because shared object files require read permission, not execute permission, for the dynamic linker to load them; execute permission is irrelevant for libraries. Option B is wrong because setuid binaries do ignore LD_LIBRARY_PATH for security reasons, but the proper solution is to add the path to /etc/ld.so.conf and run ldconfig, not to rely on LD_LIBRARY_PATH which is insecure and not persistent. Option D is wrong because a library compiled for a different architecture would cause a different error (e.g., 'wrong ELF class' or 'cannot load shared object file: No such file or directory' due to ABI mismatch), not a simple 'cannot open' error when the file exists and is readable.

366
Multi-Selecteasy

Which TWO commands can be used to display the amount of free and used memory on a Linux system? (Select exactly 2.)

Select 2 answers
A.vmstat
B.du
C.cat /proc/meminfo
D.free
E.top
AnswersC, D

Directly reads kernel memory information.

Why this answer

`/proc/meminfo` is a virtual file maintained by the kernel that provides detailed, real-time memory statistics, including total, free, available, and used memory. Reading this file with `cat` directly displays the current memory usage without any additional processing.

Exam trap

The trap here is that candidates may confuse `du` (disk usage) with memory reporting, or assume `vmstat` or `top` are primary tools for a simple free/used memory display, when `free` and `/proc/meminfo` are the direct and standard answers.

367
Multi-Selectmedium

Which TWO of the following commands can be used to replace text patterns in a file and output the result?

Select 2 answers
A.awk
B.grep
C.sed
D.tr
E.cut
AnswersA, C

awk processes input line by line, and its gsub() function substitutes every match of a pattern within a field or record, writing the modified text to standard output. This satisfies the requirement to replace text patterns and output the result without altering the source file.

Why this answer

Option A, awk, is correct because awk is a full text-processing language that supports substitution via the gsub() function (e.g., awk '{gsub(/old/,"new"); print}' file), which replaces matching patterns and prints the modified result to standard output. Option C, sed, is correct because sed is the classic stream editor whose s/// substitution command (e.g., sed 's/old/new/g' file) replaces text patterns and writes the transformed content to stdout without altering the original file. Option B, grep, is not correct because grep only searches for and prints lines matching a pattern; it does not replace text.

Option D, tr, is not correct because tr translates or deletes individual characters rather than replacing multi-character text patterns. Option E, cut, is not correct because cut extracts selected fields or columns from each line and performs no substitution.

Exam trap

The trap here is that candidates often confuse grep's pattern-matching capability with text replacement, assuming it can modify content, when in fact grep only filters lines and does not alter or output transformed text.

368
MCQeasy

A small business uses a Linux server running CUPS to share a network printer. For several months, all employees could print successfully. Today, an employee in a different subnet reports that printing does not work. The administrator checks the server: cupsd is running, the printer is configured with an IPP URI pointing to the printer's IP address, and the printer is idle. The administrator can ping the printer from the server. The administrator checks the CUPS error log and sees the following line multiple times: 'E [04/Oct/2024:10:15:22 -0400] [Client 5] client-error-not-authorized'. Which of the following actions should the administrator take to resolve the issue?

A.Change the printer's URI from ipp:// to socket://
B.Add the employee's username to the lpadmin group
C.Restart the cupsd service with 'systemctl restart cupsd'
D.Add 'Allow from 192.168.2.0/24' to the appropriate policy in /etc/cups/cupsd.conf
AnswerD

The error 'client-error-not-authorized' shows CUPS is rejecting the client's IP via its access control policy. Since the employee sits in a different subnet, adding an Allow directive for 192.168.2.0/24 to the relevant Location or policy block in cupsd.conf restores authorisation.

Why this answer

The error 'client-error-not-authorized' in CUPS indicates that the client's request was denied due to access control restrictions in cupsd.conf. Since the employee is in a different subnet (e.g., 192.168.2.0/24), the default CUPS policy likely only allows local subnet access. Adding 'Allow from 192.168.2.0/24' to the appropriate policy (e.g., under <Policy default>) grants printing access from that subnet, resolving the authorization failure.

Exam trap

The trap here is that candidates confuse 'client-error-not-authorized' with authentication issues (e.g., missing username/password) or service problems, when it is actually an IP-based access control restriction in CUPS' policy configuration.

How to eliminate wrong answers

Option A is wrong because changing the URI from ipp:// to socket:// would bypass CUPS' job management and authentication, but the error is about authorization, not protocol mismatch; the printer is reachable via ping, so the URI is not the issue. Option B is wrong because the lpadmin group is for printer administration (e.g., adding/removing printers), not for granting print access to users; the error is a client authorization failure, not a group membership issue. Option C is wrong because restarting cupsd would not change the access control rules; the service is already running and the error persists, indicating a configuration problem, not a service state issue.

369
MCQmedium

A user compiling software from source successfully runs './configure' and 'make', but the resulting binaries are not in the PATH. Which command should be run to install them system-wide?

A.make
B.make all
C.make clean
D.make install
AnswerD

'make' compiles but does not place binaries in system directories. 'make install' runs the install target defined in the Makefile, copying the built binaries to their configured system-wide locations such as /usr/local/bin, making them available on the PATH.

Why this answer

After './configure' and 'make' compile the source code, the binaries are built but remain in the local build directory. The 'make install' target copies the compiled binaries, libraries, and configuration files to their system-wide destinations (typically /usr/local/bin, /usr/local/lib, etc.) as defined by the Makefile's install prefix. Without running 'make install', the binaries exist only in the source tree and are not accessible via PATH.

Exam trap

LPIC-1 often tests the confusion between the compile stage ('make') and the install stage ('make install'), catching candidates who assume that a successful 'make' automatically places binaries in PATH.

How to eliminate wrong answers

Option A is wrong because 'make' alone (without a target) runs the default target, which is usually 'all' — it compiles the software but does not install it system-wide; the user already ran 'make' successfully. Option B is wrong because 'make all' is typically the same as the default build target, which compiles all components but still does not copy binaries to system directories. Option C is wrong because 'make clean' deletes compiled object files and binaries from the build directory — it is the opposite of installing and would actually remove the compiled output.

370
MCQhard

A small business runs a Linux server hosting a web application and a PostgreSQL database. The server uses LVM for storage, with a single volume group vg_data containing two logical volumes: lv_web (50GB) and lv_db (100GB). The root filesystem is on a separate disk. The administrator receives alerts that the database volume is at 95% capacity. The server has additional unused space from a recently added disk that was added to the volume group as an additional physical volume, but the space has not been allocated. The administrator runs 'vgs' which shows VG vg_data with total size 500GB, allocated 150GB, and free 350GB. The administrator wants to increase the size of lv_db by 50GB. Which course of action should the administrator take?

A.Run 'lvresize -L 50G /dev/vg_data/lv_db' and then 'xfs_growfs /mount/point'.
B.Run 'lvcreate -L 50G -n lv_backup vg_data' and mount it.
C.Run 'lvextend -L +50G /dev/vg_data/lv_db' and then 'resize2fs /dev/vg_data/lv_db' (if filesystem is ext4).
D.Run 'vgextend vg_data /dev/sdb1' and then 'lvextend -L 50G /dev/vg_data/lv_db'.
AnswerC

lvextend -L +50G grows lv_db using the volume group's 350GB free space, then resize2fs expands the ext4 filesystem to fill the new extents. Both steps are required because extending the logical volume alone leaves the filesystem unaware of the added capacity.

Why this answer

The administrator needs to extend the existing logical volume lv_db by 50GB using 'lvextend -L +50G /dev/vg_data/lv_db' (the '+' is critical for relative growth), and then if the filesystem is ext4, 'resize2fs /dev/vg_data/lv_db' resizes the filesystem to use the newly allocated space. The volume group already has 350GB free, so no new physical volume needs to be added.

Exam trap

The trap here is that candidates often forget the '+' sign in 'lvextend -L +50G' (which means add 50GB) versus '-L 50G' (which sets absolute size to 50GB), and they may also incorrectly assume a new physical volume must be added even when free space already exists in the volume group.

How to eliminate wrong answers

Option A is wrong because 'lvresize -L 50G' sets the absolute size to 50GB, which would shrink the volume from its current size (likely 100GB) to 50GB, causing data loss; also, xfs_growfs is only for XFS filesystems, not ext4. Option B is wrong because creating a new logical volume (lv_backup) does not increase the size of lv_db; it only adds a separate volume, leaving the database volume still at 95% capacity. Option D is wrong because 'vgextend' is unnecessary—the volume group already has 350GB free space—and 'lvextend -L 50G' without the '+' sign would set the absolute size to 50GB, potentially shrinking the volume.

371
Multi-Selectmedium

Which THREE of the following are valid files or directories used by the Domain Name System (DNS) resolution process on a Linux system?

Select 3 answers
A./etc/host.conf
B./etc/resolv.conf
C./etc/named.conf
D./etc/sysconfig/network
E./etc/nsswitch.conf
AnswersA, B, E

/etc/host.conf configures the order in which the resolver consults sources such as hosts, bind and nis, satisfying the stem's requirement for a valid DNS resolution file. It is read by glibc's resolver, letting administrators prioritise local /etc/hosts entries over DNS queries or vice versa.

Why this answer

Option A, /etc/host.conf, is correct because it is a legacy configuration file that tells the resolver library the order in which resolution services are queried (e.g., 'order hosts,bind'), directly affecting how hostnames are resolved. Option B, /etc/resolv.conf, is correct because it defines the DNS resolver configuration, listing nameserver IP addresses, the search domain, and options such as ndots and timeout used by the resolver. Option E, /etc/nsswitch.conf, is correct because its 'hosts:' line specifies the Name Service Switch order (e.g., 'files dns') that determines whether /etc/hosts, DNS, or other sources are consulted during name resolution.

Option C, /etc/named.conf, is not part of the client resolution process; it is the main configuration file for the BIND (named) DNS server daemon. Option D, /etc/sysconfig/network, is a Red Hat-style file for general network settings like hostname and gateway, not a DNS resolver file.

Exam trap

The trap here is that candidates confuse server-side DNS configuration files (like `/etc/named.conf`) with client-side resolution files, or they overlook `/etc/host.conf` and `/etc/nsswitch.conf` as essential parts of the DNS resolution chain.

372
Multi-Selectmedium

An administrator needs to restart the SSH service after a configuration change. Which TWO commands can accomplish this on a systemd-based system?

Select 2 answers
A.initctl restart sshd
B.rc.d restart sshd
C.systemctl restart sshd
D.service sshd restart
E./etc/init.d/sshd restart
AnswersC, D

`systemctl restart sshd` stops and starts the SSH daemon in one operation, applying the edited configuration immediately. It satisfies the systemd-based constraint by communicating directly with the service manager, which tracks the unit and its dependencies. Unlike `systemctl reload`, it fully terminates existing sessions, guaranteeing the new configuration is read.

Why this answer

Option C, systemctl restart sshd, is correct because systemctl is the native control utility for systemd, and 'restart' stops and starts the sshd unit in one operation, applying the new configuration. Option D, service sshd restart, is also correct because the service wrapper script on systemd-based distributions translates the request into the appropriate systemctl restart sshd call, so it works on such systems. Option A, initctl restart sshd, belongs to Upstart and is not the systemd interface.

Option B, rc.d restart sshd, is not a valid command form for the BSD-style rc.d mechanism. Option E, /etc/init.d/sshd restart, invokes a legacy SysV init script directly, which may exist for compatibility but is not the systemd method and is not guaranteed to be present or functional.

Exam trap

Candidates may incorrectly assume that only `systemctl` works on systemd, but the `service` command is also valid as a compatibility wrapper. Conversely, commands like `initctl` (Upstart) or `/etc/init.d/` script (SysV) are not correct for systemd.

373
MCQmedium

A system administrator wants to configure NTP client on a server running systemd and using systemd-timesyncd. Which file should be edited to set the NTP server?

A./etc/chrony.conf
B./etc/systemd/timesyncd.conf
C./etc/ntp.conf
D./etc/ntp/ntp.conf
AnswerB

Editing /etc/systemd/timesyncd.conf sets the NTP servers used by systemd-timesyncd, satisfying the stem's systemd constraint. The NTP= directive under the [Time] section specifies upstream servers, after which the service is restarted. Unlike chrony's /etc/chrony.conf or ntpd's /etc/ntp.conf, this file belongs solely to systemd-timesyncd.

Why this answer

On a system using systemd-timesyncd, the NTP server configuration is stored in /etc/systemd/timesyncd.conf. This file is read by the systemd-timesyncd service to determine which NTP servers to synchronize with. Editing this file is the correct method for configuring NTP clients under systemd.

Exam trap

The trap here is that candidates often confuse the configuration files for different NTP implementations (ntpd, chrony, and systemd-timesyncd) and may default to the traditional /etc/ntp.conf without recognizing that systemd-timesyncd uses its own dedicated file.

How to eliminate wrong answers

Option A is wrong because /etc/chrony.conf is the configuration file for chrony, a different NTP implementation, not for systemd-timesyncd. Option C is wrong because /etc/ntp.conf is the configuration file for the traditional ntpd service, not for systemd-timesyncd. Option D is wrong because /etc/ntp/ntp.conf is an alternative path for ntpd configuration (often used on some distributions like FreeBSD), but it is not used by systemd-timesyncd.

374
MCQeasy

A technician is repairing a system and needs to mount the root filesystem from a different disk to /mnt/sysroot. The partition is /dev/sda2 with an ext4 filesystem. Which command should be used?

A.mount -o loop /dev/sda2 /mnt/sysroot
B.mount -a
C.mount -t ext4 /dev/sda2 /mnt
D.mount /dev/sda2 /mnt/sysroot
AnswerD

Mounting requires the device node and target directory only; ext4 is auto-detected, so no -t flag is needed. This command attaches /dev/sda2 at /mnt/sysroot, satisfying the requirement to mount the root filesystem from a different disk.

Why this answer

The `mount` command with the device and mount point as arguments automatically detects the filesystem type (e.g., ext4) and mounts the partition at the specified directory. This is the standard way to mount a root filesystem from a different disk for repair purposes.

Exam trap

The trap here is that candidates may confuse the `-o loop` option with mounting a partition, or assume that `-t ext4` is always required, when in fact `mount` auto-detects the filesystem type for common formats like ext4.

How to eliminate wrong answers

Option A is wrong because the `-o loop` option is used for mounting a file as a loop device (e.g., an ISO image), not a block device like `/dev/sda2`. Option B is wrong because `mount -a` mounts all filesystems listed in `/etc/fstab`, not a specific partition to a custom mount point. Option C is wrong because it specifies the mount point as `/mnt` instead of `/mnt/sysroot`, which does not match the required target directory.

375
MCQmedium

A server has a dedicated disk /dev/sdc that will store application logs. The administrator wants the filesystem to be checked automatically only after 30 mounts or 60 days, whichever comes first, and wants to reduce the reserved block percentage to 1 percent. Which single command accomplishes both changes on the existing ext4 filesystem?

A.dumpe2fs -c 30 -i 60d -m 1 /dev/sdc
B.e2fsck -c 30 -i 60d -m 1 /dev/sdc
C.tune2fs -c 30 -i 60d -m 1 /dev/sdc
D.mkfs.ext4 -c 30 -i 60d -m 1 /dev/sdc
AnswerC

tune2fs modifies ext2/ext3/ext4 superblock parameters on an existing filesystem. The -c option sets the mount count threshold, -i sets the interval between checks, and -m sets the reserved block percentage. All three requested changes are applied in one operation, making this the correct command.

Why this answer

Adjusting existing ext filesystem behavior is the job of tune2fs, which writes superblock fields such as maximum mount count, check interval, and reserved block percentage. Formatting tools would destroy data, and checking or reporting tools cannot alter policy. The single command combining -c, -i, and -m meets both requirements.

Exam trap

The trap here is reaching for mkfs.ext4 or e2fsck when the filesystem already exists and only superblock policy values need to change.

Page 4

Page 5 of 6

Page 6

All pages