Courseiva

LPIC-1 Linux Installation and Package Management Practice Question

An administrator suspects that a critical system file has been modified after installation. Which command can be used to verify the integrity of all installed RPM packages on a RHEL system?

⚠ Common exam trap

Candidates often confuse `rpm -K` (key verification of package files) with `rpm -V` (verification of installed packages), or assume `--verify` alone works without the `-a` flag to target all packages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

`rpm -Va`

(`rpm -Va`) is correct because it verifies all installed RPM packages against their original metadata, checking file sizes, permissions, checksums, and other attributes. The `-V` flag triggers verification, and `-a` applies it to every installed package, making it the proper command to detect modifications to critical system files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    `rpm -K`

    Why it's wrong here

    `rpm -K` checks the cryptographic signature of an RPM package file, confirming its origin and integrity before installation, not the on-disk state of installed files. It is tempting because signature checking sounds like integrity verification, and it would be correct when validating a downloaded package prior to installing it.

  • ✗

    `rpm --verify`

    Why it's wrong here

    `rpm --verify` checks file attributes of installed packages but requires package names as arguments; without them it verifies nothing, so it cannot scan all packages. It is tempting because verification is exactly the right function, and `rpm -Va` would be correct for checking every installed package.

  • ✗

    `rpm -V all`

    Why it's wrong here

    `rpm -V all` treats "all" as a literal package name, which does not exist, so the command errors instead of verifying anything. It is tempting because the intent matches the task, and the correct syntax `rpm -Va` would verify every installed package.

  • ✓

    `rpm -Va`

    Why this is correct

    `rpm -Va` verifies every installed package by comparing each file's size, MD5 checksum, permissions, type, owner and group against the RPM database metadata, flagging any discrepancies. This directly satisfies the stem's requirement to check all packages for post-installation modification, rather than querying a single package or file.

About these practice questions

One of 402 original LPIC-1 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.