LPIC-1 Linux Installation and Package Management Practice Question
Exhibit
Name : kernel-core Version : 4.18.0 Release : 348.el8 Architecture: x86_64 Install Date: Mon 10 Jan 2022 10:00:00 AM EST Group : System Environment/Kernel Size : 73456789 License : GPLv2 Signature : RSA/SHA256, Mon 10 Jan 2022 09:00:00 AM EST, Key ID 12345678 Source RPM : kernel-4.18.0-348.el8.src.rpm Build Date : Mon 10 Jan 2022 08:00:00 AM EST Build Host : x86-02.mbox.example.com URL : http://www.kernel.org/ Summary : The kernel core image Description : This package contains the kernel core image.
Refer to the exhibit. An administrator wants to verify the integrity of the kernel-core package by checking its signature. Which command is used?
⚠ Common exam trap
Watch out — candidates often confuse `rpm -V` (verify installed files) with `rpm -K` (verify package signature), as both involve 'verification' but operate on different targets and use different mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
`rpm -K kernel-core`
`rpm -K` (or `rpm --checksig`) is the command used to verify the GPG signature of an RPM package, ensuring its integrity and authenticity. This checks the package's cryptographic signature against the imported GPG key, confirming it has not been tampered with.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
`rpm -qa kernel-core`
Why it's wrong here
`rpm -qa kernel-core` only queries whether the package is installed and lists its version; it performs no signature or integrity check. It is tempting because -q queries package metadata, but verification requires the -V or --checksig options instead.
- ✗
`rpm -q --changelog kernel-core`
Why it's wrong here
The --changelog query lists package change history, not cryptographic signature data, so integrity cannot be verified. It tempts because it inspects package metadata, but signature checking requires rpm --checksig (or -K) against the package file.
- ✓
`rpm -K kernel-core`
Why this is correct
The -K flag performs a signature and digest verification on the named package, checking its GPG signature against the imported Red Hat keys. This directly satisfies the requirement to verify kernel-core's integrity, unlike -V, which only compares installed file attributes against the RPM database.
- ✗
`rpm -V kernel-core`
Why it's wrong here
`rpm -V kernel-core` verifies installed file attributes against the RPM database, detecting modified files, but it does not check the package's GPG signature. It is tempting because -V is a verification command, yet signature validation needs --checksig on the package file.
Go deeper
Related to this question
About these practice questions
This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.