Courseiva

Linux Professional Institute Certification Level 1 LPIC-1 (LPIC-1) — Questions 376–402

402 questions total · 6pages · All types, answers revealed

Page 5

Page 6 of 6

376
MCQhard

In the /etc/shadow file, a user's password hash begins with '$6$'. What hash algorithm does this prefix indicate?

A.SHA-512
B.SHA-256
C.MD5
D.Blowfish
AnswerA

The `$6$` prefix in `/etc/shadow` specifies SHA-512, as defined by the crypt(3) scheme identifiers. This satisfies the stem's requirement to identify the algorithm from the hash prefix, distinguishing it from `$1$` (MD5), `$5$` (SHA-256) and `$2$` (bcrypt).

Why this answer

The prefix '$6$' in the /etc/shadow file indicates that the password hash was generated using the SHA-512 (Secure Hash Algorithm 512-bit) algorithm. This is defined in the crypt(3) function's modular crypt format, where $1$ is MD5, $5$ is SHA-256, and $6$ is SHA-512. SHA-512 is the strongest of the commonly used hash algorithms in Linux password hashing, providing a 512-bit digest.

Exam trap

The trap here is that candidates often confuse the prefix '$6$' with SHA-256 (which uses '$5$') or mistakenly associate '$6$' with Blowfish due to similar numbering, but the correct mapping is $1$=MD5, $5$=SHA-256, $6$=SHA-512.

How to eliminate wrong answers

Option B (SHA-256) is wrong because SHA-256 uses the prefix '$5$', not '$6$'. Option C (MD5) is wrong because MD5 uses the prefix '$1$', and it is considered cryptographically broken for password storage. Option D (Blowfish) is wrong because Blowfish-based bcrypt uses the prefix '$2a$', '$2b$', or '$2y$', not '$6$'.

377
MCQhard

An administrator suspects that a critical system file has been modified after installation. Which command can be used to verify the integrity of all installed RPM packages on a RHEL system?

A.`rpm -K`
B.`rpm --verify`
C.`rpm -V all`
D.`rpm -Va`
AnswerD

`rpm -Va` verifies every installed package by comparing each file's size, MD5 checksum, permissions, type, owner and group against the RPM database metadata, flagging any discrepancies. This directly satisfies the stem's requirement to check all packages for post-installation modification, rather than querying a single package or file.

Why this answer

(`rpm -Va`) is correct because it verifies all installed RPM packages against their original metadata, checking file sizes, permissions, checksums, and other attributes. The `-V` flag triggers verification, and `-a` applies it to every installed package, making it the proper command to detect modifications to critical system files.

Exam trap

The trap here is that candidates confuse `rpm -K` (key verification of package files) with `rpm -V` (verification of installed packages), or assume `--verify` alone works without the `-a` flag to target all packages.

How to eliminate wrong answers

Option A is wrong because `rpm -K` checks the GPG signature and digest of an RPM package file (not installed packages) to verify its authenticity and integrity before installation, not to detect post-installation modifications. Option B is wrong because `rpm --verify` is a valid syntax but is incomplete; it requires a package name or `-a` to act on all packages, so without `-a` it does not verify all installed packages. Option C is wrong because `rpm -V all` is invalid syntax; `-V` expects a package name or the `-a` flag, and `all` is not a recognized argument, causing an error.

378
Multi-Selectmedium

Which THREE of the following are types of expansion performed by the bash shell during command parsing?

Select 3 answers
A.Parameter expansion
B.Tilde expansion
C.Brace expansion
D.Variable assignment
E.Alias expansion
AnswersA, B, C

Parameter expansion substitutes a variable's value, such as $HOME or ${name}, into the command line before execution. Bash performs it during word splitting and expansion, making it one of the shell's documented expansion types alongside tilde, brace, command and arithmetic expansion.

Why this answer

Parameter expansion (A) is a genuine bash expansion type: the shell replaces constructs like $var, ${var}, or ${var:-default} with their values during command parsing. Tilde expansion (B) is also a real expansion: a leading ~ is replaced with the current user's home directory (or ~user with that user's home), as in ~/file becoming /home/user/file. Brace expansion (C) is likewise a bash expansion type: patterns such as {a,b,c} or {1..5} are expanded into multiple words before other expansions like parameter and command substitution.

Variable assignment (D) is not an expansion but a shell operation that stores a value in a variable, and alias expansion (E) is not one of bash's documented expansion stages; aliases are substituted earlier during tokenization/alias lookup, not as a formal expansion type.

Exam trap

The trap here is that candidates may confuse alias expansion (which occurs during tokenization) with the formal expansion phases listed in the bash manual, or mistake variable assignment as an expansion type when it is actually a separate parsing step.

379
MCQmedium

A system administrator wants to install custom scripts that should be available to all users. The scripts are not part of any package and should be placed under the Filesystem Hierarchy Standard (FHS). Which directory is most appropriate?

A./var
B./opt
C./usr/local/bin
D./home
AnswerC

/usr/local/bin is reserved by the FHS for locally compiled or custom executables outside the package manager, exactly matching scripts that belong to no package. Placing them here keeps them on the default PATH for all users, satisfying the requirement that the scripts be globally available without distribution interference.

Why this answer

/usr/local/bin because the Filesystem Hierarchy Standard (FHS) designates /usr/local as the location for locally installed software not managed by the system's package manager. Placing custom scripts in /usr/local/bin ensures they are in the default PATH for all users, while keeping them separate from system binaries in /usr/bin and /bin.

Exam trap

The trap here is that candidates often confuse /opt with /usr/local, but /opt is designed for self-contained third-party application packages (each in its own subdirectory), not for individual scripts that need to be directly in the PATH.

How to eliminate wrong answers

Option A is wrong because /var is intended for variable data files such as logs, spools, and temporary files, not for executable scripts. Option B is wrong because /opt is reserved for add-on application software packages, typically installed in their own subdirectory tree, not for individual scripts meant to be directly executable from the PATH. Option D is wrong because /home contains user home directories and is not part of the default system PATH; scripts placed there would not be accessible to all users without explicit path configuration.

380
MCQmedium

Refer to the exhibit. An administrator wants to mount /dev/sda4 persistently by its UUID. Which line should be added to /etc/fstab?

A.UUID=abc-123 /mnt/data ext4 defaults 0 2
B.UUID=abc-123 /mnt/data ext4 noauto 0 2
C.LABEL=data /mnt/data ext4 defaults 0 2
D./dev/sda4 /mnt/data ext4 defaults 0 2
AnswerA

The UUID= form identifies the filesystem independently of device name ordering, which /dev/sda4 cannot guarantee across reboots. Field six set to 2 schedules fsck after root, and ext4 with defaults matches the filesystem, giving a persistent, correctly ordered mount.

Why this answer

It uses the UUID= syntax to identify the filesystem by its universally unique identifier, which is the persistent method requested. The mount point is /mnt/data, the filesystem type is ext4, the mount options are defaults, and the dump and fsck order values (0 and 2) are appropriate for a non-root filesystem. This line ensures the device is mounted automatically at boot regardless of device name changes.

Exam trap

The trap here is that candidates often choose the device path option (D) out of habit, forgetting that device names are not persistent, or they confuse the 'noauto' option (B) as a valid way to mount persistently, when in fact it prevents automatic mounting.

How to eliminate wrong answers

Option B is wrong because it uses the 'noauto' mount option, which prevents the filesystem from being mounted automatically at boot, contradicting the requirement for persistent mounting. Option C is wrong because it uses LABEL=data instead of UUID=abc-123; while LABEL can be used for persistent mounting, the question explicitly specifies mounting by UUID. Option D is wrong because it uses the device path /dev/sda4, which is not persistent and can change across reboots (e.g., if disks are added or removed), failing the requirement to mount by UUID.

381
MCQmedium

An administrator needs to create a new ext4 filesystem on /dev/sdb1 and wants to reserve 2% of the blocks for the root user. Which command should be used?

A.mkfs.ext4 -m 2 /dev/sdb1
B.tune2fs -m 2 /dev/sdb1
C.mke2fs -r 2 /dev/sdb1
D.mkfs.ext4 -R 2 /dev/sdb1
AnswerA

The `-m` flag on `mkfs.ext4` sets the percentage of filesystem blocks reserved for root, so `-m 2` reserves exactly 2%, satisfying the stem's constraint. It creates the ext4 filesystem on /dev/sdb1 in one step, unlike `tune2fs -m`, which only adjusts reservation on an existing filesystem.

Why this answer

The `-m` flag in `mkfs.ext4` specifies the percentage of filesystem blocks reserved for the root user (superuser). By default, ext4 reserves 5% of blocks; using `-m 2` reduces this to 2%, as required. This command creates a new ext4 filesystem on `/dev/sdb1` with the specified reserved block percentage.

Exam trap

The trap here is that candidates confuse `-m` (reserved block percentage) with `-r` (revision level) or assume `tune2fs` can be used to create a filesystem, when in fact `tune2fs` only modifies existing filesystems.

How to eliminate wrong answers

Option B is wrong because `tune2fs` modifies parameters on an existing ext2/3/4 filesystem, but the question asks to create a new filesystem; `tune2fs` cannot create a filesystem. Option C is wrong because `mke2fs -r 2` sets the filesystem revision level (e.g., revision 1 or 2), not the reserved block percentage; the correct flag for reserved blocks is `-m`. Option D is wrong because `mkfs.ext4 -R 2` is invalid; `-R` is not a recognized option in `mkfs.ext4` (the correct flag is `-m`), and this would likely produce an error or be ignored.

382
MCQeasy

A system administrator needs to determine which package owns the file /usr/bin/htop on a Debian-based system. Which command will provide this information?

A.apt-file search /usr/bin/htop
B.dpkg -L /usr/bin/htop
C.dpkg -S /usr/bin/htop
D.apt-cache search /usr/bin/htop
AnswerC

The dpkg -S command searches for the package that owns a specified file. It queries the dpkg database for installed packages and returns the package name that contains the given file path. This is the correct tool for identifying package ownership on Debian-based systems.

Why this answer

The dpkg -S command is used to find the package that owns a specific file on a Debian-based system. It searches the dpkg database of installed packages. The other commands either list files of a package, search repository contents, or search package descriptions, none of which directly answer the question for an installed file.

Exam trap

The trap here is confusing the -S (search) and -L (list) options of dpkg, or using apt-file which queries repositories rather than installed packages.

383
Multi-Selectmedium

Which TWO of the following are valid methods to reduce boot time on a Linux system? (Select exactly 2.)

Select 2 answers
A.Disable unnecessary systemd services.
B.Use an initramfs with minimal drivers.
C.Replace a hard disk drive with a solid-state drive.
D.Increase the kernel log level to debug.
E.Use ext2 instead of ext4 as the root filesystem.
AnswersA, C

Reduces the number of processes started sequentially.

Why this answer

Disabling unnecessary systemd services reduces the number of processes that must be started during boot, directly decreasing the time spent in the target phase of systemd's parallel service activation. Each disabled service eliminates its own dependency resolution, unit loading, and execution overhead, which is especially impactful on systems with many enabled services.

Exam trap

The trap here is that candidates often confuse 'reducing boot time' with 'reducing kernel size' or 'removing features,' but the two most effective methods are eliminating unnecessary startup processes (services) and upgrading the storage hardware to reduce I/O wait, not tweaking filesystem types or kernel logging verbosity.

384
MCQhard

A system boots in UEFI mode, and the administrator wants to add a new kernel entry to the EFI boot manager. Which tool should be used?

A.efibootmgr
B.grub2-install
C.lilo
D.mknbi
AnswerA

`efibootmgr` manipulates the UEFI firmware boot manager variables directly from Linux, creating and ordering boot entries stored in NVRAM. Since the system boots in UEFI mode, this satisfies the requirement to add a kernel entry to the EFI boot manager, unlike BIOS-era tools such as `grub-install` alone.

Why this answer

In UEFI mode, the system's boot manager is stored in NVRAM, and `efibootmgr` is the standard Linux tool for creating, deleting, and modifying boot entries in the UEFI Boot Manager. It directly manipulates the UEFI Boot Manager variables (e.g., BootOrder, Boot####) via the efivars kernel interface, allowing the administrator to add a new kernel entry without relying on a bootloader like GRUB.

Exam trap

The trap here is that candidates often confuse `grub2-install` (which installs a bootloader) with `efibootmgr` (which manages UEFI boot entries), mistakenly thinking that installing GRUB is the only way to add a kernel entry in UEFI mode.

How to eliminate wrong answers

Option B is wrong because `grub2-install` installs the GRUB2 bootloader to a disk or partition (e.g., the EFI System Partition) and updates the UEFI boot entry for GRUB itself, but it does not add arbitrary kernel entries to the UEFI boot manager; it is a bootloader installation tool, not a boot manager entry editor. Option C is wrong because `lilo` is a legacy bootloader for BIOS/MBR systems and does not support UEFI boot manager manipulation; it is obsolete for UEFI environments. Option D is wrong because `mknbi` is a tool for creating network boot images (e.g., for PXE or Etherboot), not for managing UEFI NVRAM boot entries.

385
MCQmedium

A system administrator suspects a failing power supply because the server randomly reboots. Which command can be used to check hardware health and event logs?

A.ipmitool sensor list
B.sensors -u
C.lspci -v
D.dmidecode -t baseboard
AnswerA

ipmitool sensor list queries the BMC over the IPMI interface, reporting voltages, temperatures, fan speeds and power supply status independently of the operating system. This satisfies the hardware-health requirement, since random reboots caused by a failing PSU appear in BMC sensor and event logs.

Why this answer

The `ipmitool sensor list` command queries the Baseboard Management Controller (BMC) via the IPMI protocol to retrieve real-time sensor readings (e.g., voltages, temperatures, fan speeds) and system event logs (SEL). This is the correct tool for diagnosing hardware-level issues like a failing power supply, as it provides direct access to the server's hardware health monitoring subsystem, independent of the operating system.

Exam trap

The trap here is that candidates confuse `sensors -u` (a user-space tool for reading motherboard sensors via kernel drivers) with IPMI-based hardware monitoring, not realizing that `sensors` cannot access the BMC or event logs, and thus cannot diagnose random reboots caused by power supply issues.

How to eliminate wrong answers

Option B is wrong because `sensors -u` reads from kernel-based sensor drivers (e.g., lm-sensors) and only reports current sensor values in a raw format; it does not access the BMC or event logs, and it cannot detect power supply failures that cause random reboots if the OS is already unstable. Option C is wrong because `lspci -v` lists PCI devices and their configuration details, but it does not monitor hardware health, sensor data, or event logs; it is purely for enumerating the PCI bus. Option D is wrong because `dmidecode -t baseboard` decodes DMI/SMBIOS tables to show motherboard information (e.g., manufacturer, serial number), but it provides no dynamic sensor readings or event log history; it is static hardware inventory data, not a health monitoring tool.

386
Multi-Selecteasy

Which TWO of the following are valid methods to list currently loaded kernel modules?

Select 2 answers
A.dmesg | grep module
B.lsmod
C.modprobe -l
D.cat /proc/modules
E.modinfo
AnswersB, D

lsmod reads /proc/modules and prints currently loaded kernel modules in a formatted table with size and usage counts. It satisfies the requirement to list loaded modules without loading or unloading anything, unlike modprobe or insmod.

Why this answer

Option B (lsmod) is correct because lsmod reads /proc/modules and prints the currently loaded kernel modules along with their size and usage count, making it the standard tool for this task. Option D (cat /proc/modules) is also correct because /proc/modules is the kernel-provided virtual file that lists all loaded modules, so displaying it directly shows the same information lsmod parses. Option A (dmesg | grep module) only filters kernel ring-buffer log messages and does not enumerate loaded modules.

Option C (modprobe -l) lists available module files on disk rather than loaded modules, and the -l option is deprecated/removed in modern kmod. Option E (modinfo) displays metadata about a specific module file or name, not a list of currently loaded modules.

Exam trap

The trap here is that candidates confuse commands that list available modules (like modprobe -l or find /lib/modules) with commands that list currently loaded modules, or they assume dmesg is a valid module listing tool because it shows kernel messages related to module loading.

387
MCQhard

A server has two disk drives: /dev/sda (SSD) and /dev/sdb (HDD). The administrator wants to place frequently accessed files on the SSD for performance. Which approach best achieves this using Linux filesystem features?

A.Create separate LVM logical volumes on each disk and mount them at different mount points.
B.Configure RAID 0 across both disks to combine speed.
C.Use symbolic links to redirect file access to the SSD.
D.Use a union mount to overlay the SSD on top of the HDD.
AnswerA

LVM lets you carve separate logical volumes from each physical disk and mount them at distinct paths, so frequently accessed data lives on the SSD while bulk data stays on the HDD. This satisfies the performance placement requirement without exotic tiering software.

Why this answer

LVM allows the administrator to create separate logical volumes on each physical disk (/dev/sda and /dev/sdb) and mount them at distinct mount points. By placing frequently accessed files on the SSD logical volume and less critical data on the HDD logical volume, the administrator can directly control which files benefit from the SSD's faster performance without mixing data or requiring complex overlays.

Exam trap

The trap here is that candidates may confuse RAID 0's speed benefits with the goal of isolating hot data, failing to recognize that RAID 0 mixes all data across both disks, preventing the administrator from selectively placing frequently accessed files on the faster SSD.

How to eliminate wrong answers

Option B is wrong because RAID 0 stripes data across both disks, combining their storage capacity and speed but also mixing frequently and infrequently accessed data on both the SSD and HDD, which negates the goal of isolating hot data on the faster SSD. Option C is wrong because symbolic links redirect file access at the filesystem level but do not provide a mechanism to automatically or efficiently place frequently accessed files on the SSD; they require manual management and do not leverage any filesystem feature for performance tiering. Option D is wrong because a union mount overlays one filesystem on top of another, but it does not intelligently direct frequently accessed files to the SSD; it simply merges directories, and writes typically go to the top layer, which could be the HDD, defeating the purpose.

388
MCQmedium

A data center server with two NICs (eth0 and eth1) is configured for network bonding in mode 1 (active-backup). The admin notices that after a cable pull on eth0, the bond interface fails over to eth1 as expected. However, when the cable is reconnected to eth0, the bond remains on eth1 indefinitely. The admin checks /proc/net/bonding/bond0 and sees that eth0 is marked as 'up' but not as 'active'. Which parameter is most likely missing from the bond configuration? Options: A) 'miimon=100' to enable link monitoring, B) 'downdelay=0', C) 'updelay=0', D) 'primary=eth0' to prefer eth0 as the active slave.

A.updelay=0
B.downdelay=0
C.miimon=100
D.primary=eth0
AnswerD

Active-backup mode does not automatically fail back; without the primary=eth0 parameter, the bond keeps using whichever slave is currently active. Setting primary=eth0 makes the bond prefer eth0 as the active slave once its link returns, restoring the original path.

Why this answer

The bond is in active-backup mode (mode 1) and eth0 is marked as 'up' but not 'active' after reconnection. Without the 'primary=eth0' parameter, the bond does not automatically switch back to the preferred slave (eth0) once it becomes available; it only fails over to eth1 when eth0 goes down. Setting 'primary=eth0' ensures that eth0 is always preferred as the active slave when it is in 'up' state, triggering a failback.

Exam trap

The trap here is that candidates assume 'miimon' alone handles both failover and failback, but in active-backup mode, failback to a preferred slave requires the explicit 'primary' parameter.

How to eliminate wrong answers

Option A is wrong because 'miimon=100' enables link monitoring via MII, which is already functioning (the bond detected the cable pull and failed over), so it is not the missing parameter. Option B is wrong because 'downdelay=0' (default) controls the delay before deactivating a slave after link loss; the issue is about failback, not failover timing. Option C is wrong because 'updelay=0' (default) controls the delay before considering a link as up after reconnection; the bond already sees eth0 as 'up', so the problem is not a delay but the lack of a preference to switch back.

389
MCQeasy

Refer to the exhibit. How much unpartitioned space is available on /dev/sda?

A.256G
B.5.5G
C.6G
D.150G
AnswerB

Unpartitioned space is the gap between the end of the last partition and the disk's total capacity. Reading the partition table, the final partition ends at 5.5G short of the full device size, so that remainder is unallocated.

Why this answer

The output of `fdisk -l /dev/sda` shows partitions sda1 (0.5G), sda2 (100G), and sda3 (150G), summing to 250.5G. The total disk size is 256G, so the unpartitioned space is 256G - 250.5G = 5.5G. Candidates often misread the partition sizes or add them incorrectly, leading to wrong answers.

Exam trap

The trap is that candidates may misread the partition sizes from the exhibit or incorrectly sum them. The exhibit shows sda1=0.5G, sda2=100G, sda3=150G, totaling 250.5G, leaving 5.5G unpartitioned. Picking 6G comes from assuming all partitions are round numbers or misremembering the total.

How to eliminate wrong answers

Option A is wrong because 256G is the total disk size, not the unpartitioned space; it ignores that partitions already occupy 250 GB. Option C is wrong because 6G is the raw difference between total size and partition sum (256 - 250 = 6), but it fails to account for the extended partition's metadata overhead (e.g., extended boot record), which reduces usable unpartitioned space to about 5.5 GB. Option D is wrong because 150G is the size of a single partition (sda3), not the unpartitioned space; it likely confuses a partition's size with free space.

390
MCQmedium

A system administrator wants to ensure a service named 'app.service' starts automatically on boot in a systemd-based system. Which command should be used?

A.systemctl start app.service
B.systemctl enable app.service
C.chkconfig app.service on
D.update-rc.d app.service enable
AnswerB

systemctl enable creates the symlink from the multi-user.target (or other install target) wants directory to the unit file, so systemd pulls app.service in at boot. Starting it now is separate; enable satisfies the automatic-start-on-boot requirement.

Why this answer

The correct command is 'systemctl enable app.service' because in systemd-based systems, 'enable' creates the necessary symlinks in the filesystem (typically under /etc/systemd/system/multi-user.target.wants/) to ensure the service starts automatically at boot. In contrast, 'systemctl start' only activates the service immediately without affecting its boot-time behavior.

Exam trap

The trap here is that candidates confuse 'start' (immediate activation) with 'enable' (boot-time activation), or mistakenly apply legacy SysV commands like 'chkconfig' or 'update-rc.d' to a systemd environment, which is a common pitfall in LPIC-1 exams.

How to eliminate wrong answers

Option A is wrong because 'systemctl start app.service' only starts the service immediately in the current session, but does not configure it to start automatically on boot. Option C is wrong because 'chkconfig' is a legacy tool for SysV init systems (e.g., RHEL/CentOS 6 and earlier), not for systemd-based systems; it would not work or would be deprecated. Option D is wrong because 'update-rc.d' is a Debian/Ubuntu-specific command for managing SysV init scripts, not for systemd services; it would not properly enable a systemd unit.

391
MCQmedium

A system administrator notices that the system boots to the graphical interface but wants to change it to boot to a non-graphical multi-user target. Which command will make this change persistent?

A.systemctl set-default multi-user.target
B.systemctl isolate multi-user.target
C.systemctl enable multi-user.target
D.systemctl start multi-user.target
AnswerA

systemctl set-default multi-user.target rewrites the default.target symlink in /etc/systemd/system, so the non-graphical multi-user target persists across reboots. The isolation and get-default subcommands only affect the running session or read state, so they cannot satisfy the persistence requirement.

Why this answer

`systemctl set-default multi-user.target` changes the default systemd target to `multi-user.target`, which boots to a non-graphical multi-user environment. This change is persistent across reboots, as it updates the symlink `/etc/systemd/system/default.target` to point to `multi-user.target`.

Exam trap

The trap here is that candidates confuse `isolate` (which changes the current target but is not persistent) with `set-default` (which makes the change permanent), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option B is wrong because `systemctl isolate multi-user.target` immediately switches the current running target to `multi-user.target`, but this change is not persistent; it only affects the current session and does not modify the default target for future boots. Option C is wrong because `systemctl enable multi-user.target` is not a valid systemd command for setting the default target; `enable` is used to enable services or units at boot, not to set the default target. Option D is wrong because `systemctl start multi-user.target` starts the target immediately but does not make it the default for subsequent boots; it only activates the target in the current session.

392
MCQmedium

A junior administrator needs to add a new user account named 'tester' to a Linux server. The account must have a home directory created at /home/tester, and the default shell should be set to /bin/bash. The administrator runs 'useradd tester' but later finds that no home directory was created and the shell is /bin/sh. Which command should have been used to meet both requirements?

A.usermod -m -s /bin/bash tester
B.useradd -d /home/tester -s /bin/bash tester
C.adduser tester --home /home/tester --shell /bin/bash
D.useradd -m -s /bin/bash tester
AnswerD

The -m option instructs useradd to create the user's home directory if it does not exist, and -s /bin/bash sets the login shell to bash. This directly fulfills both requirements in a single command. Without -m, no home directory is created; without -s, the system default shell (often /bin/sh) is used. This is the correct and efficient solution.

Why this answer

The correct command is useradd -m -s /bin/bash tester. The -m flag ensures the home directory is created, and -s specifies the login shell. Other options either fail to create the home directory, use non-standard syntax, or attempt to modify a non-existent user.

This single command meets both stated requirements.

Exam trap

The trap here is assuming that useradd automatically creates a home directory; by default, it does not unless the -m option is given or the CREATE_HOME variable is set in /etc/login.defs.

393
MCQeasy

A system administrator needs to locate the largest directories under /var to free up disk space. Which command is most appropriate?

A.df -h /var
B.find /var -size +100M
C.ls -lS /var
D.du -sk /var/* | sort -rn
AnswerD

du -sk reports each /var subdirectory's size in kilobytes without descending into individual files, and sort -rn orders them largest first. This directly identifies the biggest space consumers, satisfying the requirement to find the largest directories.

Why this answer

`du -sk /var/* | sort -rn` calculates the disk usage in kilobytes for each top-level item under /var, then sorts them numerically in reverse order, showing the largest directories first. This directly addresses the need to locate the largest directories to free up space, as `du` reports actual disk usage (including subdirectories) rather than file sizes.

Exam trap

The trap here is that candidates often confuse `df` (filesystem-level usage) with `du` (directory-level usage), or mistakenly think `ls -lS` can show directory sizes, when in fact `ls` only shows the size of the directory entry itself (typically 4 KB), not its contents.

How to eliminate wrong answers

Option A is wrong because `df -h /var` shows the total disk usage and free space on the filesystem mounted at /var, not the sizes of individual directories or files within it. Option B is wrong because `find /var -size +100M` finds files larger than 100 MB, not directories, and does not aggregate sizes of directory contents. Option C is wrong because `ls -lS /var` lists the immediate contents of /var sorted by file size, but it does not recurse into subdirectories and cannot show the total size of directories, which is needed to identify large directories.

394
Drag & Dropmedium

Order the steps to create and apply a file system permission using ACLs.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

ACLs require the filesystem to be mounted with the acl option, then setfacl applies rules, and getfacl verifies them.

395
MCQmedium

A company is deploying a new web application and needs to ensure high availability. They have two web servers and want to use DNS round-robin. Which DNS record type is most appropriate?

A.MX
B.PTR
C.CNAME
D.A
AnswerD

An A record maps a hostname directly to an IPv4 address. Publishing multiple A records with the same name, one per web server, lets DNS return the addresses in rotating order, distributing client requests across both servers and satisfying the round-robin high-availability requirement.

Why this answer

DNS round-robin distributes traffic across multiple servers by returning multiple A records for a single hostname in a rotating order. An A record maps a hostname to an IPv4 address, so using multiple A records for the same name is the standard method for DNS-based load balancing. This allows each web server to be reached via its own IP address, enabling high availability without additional hardware or software.

Exam trap

The trap here is that candidates may confuse CNAME records with A records, thinking a CNAME can point to multiple servers, but CNAMEs are single-target aliases and cannot provide round-robin distribution.

How to eliminate wrong answers

Option A is wrong because MX records are used for mail exchange routing, specifying mail servers for a domain, not for web server load balancing. Option B is wrong because PTR records perform reverse DNS lookups (IP to hostname), which are irrelevant for distributing web traffic. Option C is wrong because CNAME records create an alias from one hostname to another, but they cannot point to multiple IP addresses or provide round-robin functionality; they only map a name to a single canonical name.

396
MCQhard

An administrator must grant a contractor temporary, passwordless sudo access to run only /usr/bin/systemctl restart nginx on a production web server. Which entry in a file under /etc/sudoers.d/ best meets this requirement while limiting privilege escalation?

A.contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx
B.contractor ALL=(ALL) NOPASSWD: /usr/bin/systemctl
C.contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart *
D.%contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx
AnswerA

This rule permits the named user to run exactly that command as root without a password and nothing else. Because sudo matches the command line against the specified path and arguments, unrelated systemctl subcommands are denied, which satisfies the least-privilege requirement for temporary contractor access.

Why this answer

Least privilege requires specifying both the permitted binary and its exact arguments. Listing the full command with its unit argument confines the contractor to restarting nginx as root without a password, while the absence of wildcards prevents reusing the rule for other services. A dedicated file under /etc/sudoers.d keeps the change auditable and easy to revoke.

Exam trap

The trap here is forgetting that a sudoers command without its arguments allows every subcommand of that binary, so omitting "restart nginx" silently grants far more than intended.

397
MCQeasy

Refer to the exhibit. When will the cron job execute?

A.Every minute of every hour, but only weekdays.
B.Every day at midnight.
C.Every minute.
D.Every hour.
AnswerC

The schedule field of five asterisks matches every minute of every hour, day and month, so cron launches the job once per minute. Each asterisk means the full range for that field, giving the highest possible frequency.

Why this answer

The cron job entry `* * * * *` specifies five fields (minute, hour, day of month, month, day of week), each set to `*`, meaning 'every'. This results in the job executing every minute of every hour, every day of the month, every month, and every day of the week — i.e., every minute without restriction.

Exam trap

The trap here is that candidates often misinterpret `* * * * *` as 'every hour' or 'every day at midnight' because they focus on the asterisks without understanding that each field must be evaluated independently — every asterisk means 'every possible value' for that field, leading to execution every minute.

How to eliminate wrong answers

Option A is wrong because 'every minute of every hour, but only weekdays' would require the day-of-week field to be set to 1-5 (or MON-FRI), not `*`. Option B is wrong because 'every day at midnight' would require the minute and hour fields to be `0 0`, not `* *`. Option D is wrong because 'every hour' would require the minute field to be a specific value (e.g., `0`) and the hour field to be `*`, but here both minute and hour are `*`, which means every minute, not just every hour.

398
MCQeasy

Which command adds a new group named 'developers' to the system?

A.addgroup developers
B.groupadd developers
C.newgroup developers
D.groupadd -r developers
AnswerB

groupadd creates a new group entry in /etc/group with the specified name, so 'groupadd developers' adds the developers group. It does not assign users or set passwords, which require separate commands such as usermod or gpasswd.

Why this answer

The correct command to add a new group on a Linux system is `groupadd developers`. This command creates a new group entry in the system's group database (typically /etc/group). The `groupadd` utility is the standard tool for this task in Linux, and it is part of the shadow-utils package.

Exam trap

The trap here is that candidates may confuse `groupadd` with distribution-specific wrappers like `addgroup` (Debian/Ubuntu) or think that `newgroup` is a valid command, or they may overlook the significance of the `-r` flag which creates a system group instead of a regular group.

How to eliminate wrong answers

Option A is wrong because `addgroup` is not a standard Linux command; it is a Debian/Ubuntu-specific wrapper that may not exist on all distributions, and the standard command is `groupadd`. Option C is wrong because `newgroup` is not a valid Linux command; the correct command is `groupadd`. Option D is wrong because `groupadd -r developers` creates a system group (with a GID in the system range, typically below 1000), not a regular group named 'developers' as required by the question.

399
MCQhard

A system administrator is troubleshooting a server where the /var partition is full, causing services to fail. The administrator deletes old log files in /var/log, but the available space does not increase. Which step should be taken next?

A.Run 'sync; echo 3 > /proc/sys/vm/drop_caches' to clear cache.
B.Remount the /var partition with the 'noatime' option.
C.Use 'lsof /var/log' to find processes holding deleted file handles, then restart those processes.
D.Run 'df -i' to check inode usage.
AnswerC

Deleting log files unlinks directory entries, but processes still holding open file descriptors keep the inodes allocated, so space is not reclaimed. lsof /var/log identifies those processes; restarting them releases the handles and frees the blocks.

Why this answer

When a file is deleted while a process still holds an open file descriptor to it, the file's data blocks are not freed until that process releases the handle. The `lsof /var/log` command identifies such processes, and restarting them forces the kernel to release the deleted inodes, thereby reclaiming the disk space. This is why option C is the correct next step.

Exam trap

The trap here is that candidates assume deleting files immediately frees space, but they overlook that processes can keep deleted files open, and they confuse memory caches (cleared by drop_caches) with disk space.

How to eliminate wrong answers

Option A is wrong because writing to `/proc/sys/vm/drop_caches` clears kernel page cache, dentries, and inode caches, which frees memory but does not affect disk space; the /var partition remains full. Option B is wrong because remounting with `noatime` prevents future access time updates, which can reduce write overhead but does not recover already consumed disk space. Option D is wrong because `df -i` checks inode usage (the number of files/directories), not block usage; the problem is the partition is full due to block exhaustion, not inode exhaustion.

400
MCQmedium

An administrator needs to extend a logical volume by 10GB. The volume group has available physical extents. Which command should be used?

A.lvcreate -L 10G /dev/vg/lv
B.vgextend /dev/vg/lv -L +10G
C.lvextend -L +10G /dev/vg/lv
D.lvresize -L 10G /dev/vg/lv
AnswerC

`lvextend -L +10G /dev/vg/lv` grows the logical volume by exactly 10GB using free physical extents already present in the volume group, satisfying the stem's constraint that no additional physical volumes are required. The `+` prefix adds to the current size rather than setting an absolute value, and `-L` specifies size in gigabytes.

Why this answer

The `lvextend` command with the `-L +10G` flag increases the size of the existing logical volume `/dev/vg/lv` by exactly 10 GB, using available physical extents from the volume group. This is the standard LVM command for extending a logical volume without recreating it.

Exam trap

The trap here is that candidates confuse `lvcreate` with `lvextend` or forget the `+` sign in `lvresize`, leading them to choose an option that either creates a new volume or sets an absolute size instead of incrementing it.

How to eliminate wrong answers

Option A is wrong because `lvcreate` creates a new logical volume, not extends an existing one; using it would attempt to create a separate 10 GB LV, not modify the target LV. Option B is wrong because `vgextend` is used to add a physical volume to a volume group, not to extend a logical volume; the syntax and purpose are entirely mismatched. Option D is wrong because `lvresize -L 10G` sets the absolute size of the logical volume to exactly 10 GB, which would shrink it if it were larger than 10 GB, rather than adding 10 GB; the `+` sign is required for an extension operation.

401
MCQmedium

An administrator notices that a large file on an ext4 filesystem is taking up more disk space than expected based on its size. Which command would show the actual disk usage (block allocation) of the file?

A.ls -l
B.df -h
C.du -h
D.stat
AnswerC

du reports allocated blocks, including indirect blocks and filesystem overhead, so it reveals the real space consumed. ls -l shows only apparent file length, which explains why the file appears larger on disk than its logical size suggests.

Why this answer

(du -h) is correct because du (disk usage) reports the actual disk space consumed by a file, including allocated blocks, which can be larger than the file's logical size due to block size overhead, fragmentation, or sparse file handling. On ext4, the default block size is 4096 bytes, so a 1-byte file occupies 4096 bytes on disk, and du reflects this allocation.

Exam trap

The trap here is that candidates confuse logical file size (shown by ls -l) with actual disk block allocation, assuming they are identical, and overlook that du accounts for filesystem overhead like block size rounding and sparse file handling.

How to eliminate wrong answers

Option A (ls -l) is wrong because it shows the logical file size (st_size), not the actual disk blocks allocated; it does not account for block size overhead or sparse file holes. Option B (df -h) is wrong because it reports filesystem-wide free and used space, not per-file disk usage. Option D (stat) is wrong because while it displays the file's size and blocks allocated (in 512-byte units), it does not directly show human-readable disk usage like du does; stat is more for inode metadata, not a quick usage summary.

402
MCQhard

A database server on a Linux system is configured to listen on TCP port 3306. The administrator wants to restrict access to the database server to only the local network (192.168.1.0/24) using iptables. Which of the following iptables rules achieves this?

A.iptables -A INPUT -p tcp --dport 3306 -d 192.168.1.0/24 -j DROP
B.iptables -A OUTPUT -p tcp --dport 3306 -d 192.168.1.0/24 -j ACCEPT
C.iptables -A INPUT -p tcp --dport 3306 -s 192.168.1.0/24 -j ACCEPT
D.iptables -A OUTPUT -p tcp --sport 3306 -s 192.168.1.0/24 -j ACCEPT
AnswerC

This rule matches TCP destination port 3306 with source 192.168.1.0/24 and accepts it, restricting database access to the local subnet. Other traffic to that port falls through to subsequent rules, satisfying the stem's local-network-only constraint.

Why this answer

It adds an INPUT chain rule that accepts TCP traffic destined for port 3306 only when the source address is within the 192.168.1.0/24 subnet. This effectively restricts incoming database connections to the local network, while all other sources are implicitly dropped by the default INPUT policy or subsequent rules.

Exam trap

The trap here is confusing the -s (source) and -d (destination) flags, leading candidates to pick Option A which drops traffic to the local network instead of accepting traffic from it.

How to eliminate wrong answers

Option A is wrong because it uses the -d (destination) flag instead of -s (source), and then jumps to DROP, which would block traffic destined for the 192.168.1.0/24 network (i.e., traffic going out to that subnet) rather than restricting incoming connections from it. Option B is wrong because it applies to the OUTPUT chain, which controls outgoing traffic; restricting access to an incoming database server requires an INPUT chain rule, not OUTPUT. Option D is wrong because it uses the OUTPUT chain with --sport 3306 (source port) and -s (source address), which would match outgoing packets originating from port 3306 with a source address in 192.168.1.0/24 — this is irrelevant for controlling incoming connections to the database server.

Page 5

Page 6 of 6

All pages