Courseiva

LPIC-1 Essential System Services and Networking Practice Question

An administrator wants systemd-journald logs to persist across reboots. What must be created?

⚠ Common exam trap

Many exam-takers assume editing the configuration file /etc/journald.conf is sufficient, but without the actual directory /var/log/journal existing, systemd-journald will not switch to persistent storage unless Storage=persistent is explicitly set and the directory is created.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The directory /var/log/journal

By default, systemd-journald stores logs in a volatile tmpfs at /run/log/journal, which is cleared on reboot. To make logs persistent, the directory /var/log/journal must be created. When systemd-journald detects this directory exists, it automatically switches to persistent storage, writing logs to /var/log/journal and preserving them across reboots.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The directory /run/log/journal

    Why it's wrong here

    /run is a tmpfs cleared at every boot, so journal files written there vanish on restart. It is tempting because journald does use /run/log/journal for volatile storage, and that path would be correct when only current-boot logs are wanted, not persistence.

  • ✗

    The file /etc/journald.conf

    Why it's wrong here

    journald.conf configures storage mode, retention, and forwarding, but the file alone does not create persistent storage; the directory /var/log/journal must exist. It is tempting because Storage=persistent is set there, and editing that file would be correct once the journal directory is already present.

  • ✓

    The directory /var/log/journal

    Why this is correct

    Journald writes to /run/log/journal (tmpfs) by default, so logs vanish on reboot. Creating /var/log/journal on disk switches storage to persistent mode, satisfying the requirement that entries survive restarts. The directory must exist before journald starts using it.

  • ✗

    The directory /var/spool/journal

    Why it's wrong here

    journald never reads /var/spool/journal; its persistent storage location is /var/log/journal, so creating this directory changes nothing. It is tempting because /var/spool holds other daemons' queued data, and a spool path would be correct for a service that queues jobs rather than storing journals.

About these practice questions

This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.