Courseiva

LPIC-1 Linux Installation and Package Management Practice Question

Exhibit

Name        : kernel-core
Version     : 4.18.0
Release     : 348.el8
Architecture: x86_64
Install Date: Mon 10 Jan 2022 10:00:00 AM EST
Group       : System Environment/Kernel
Size        : 73456789
License     : GPLv2
Signature   : RSA/SHA256, Mon 10 Jan 2022 09:00:00 AM EST, Key ID 12345678
Source RPM  : kernel-4.18.0-348.el8.src.rpm
Build Date  : Mon 10 Jan 2022 08:00:00 AM EST
Build Host  : x86-02.mbox.example.com
URL         : http://www.kernel.org/
Summary     : The kernel core image
Description : This package contains the kernel core image.

Refer to the exhibit. An administrator wants to verify the integrity of the kernel-core package by checking its signature. Which command is used?

⚠ Common exam trap

Watch out — candidates often confuse `rpm -V` (verify installed files) with `rpm -K` (verify package signature), as both involve 'verification' but operate on different targets and use different mechanisms.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

`rpm -K kernel-core`

`rpm -K` (or `rpm --checksig`) is the command used to verify the GPG signature of an RPM package, ensuring its integrity and authenticity. This checks the package's cryptographic signature against the imported GPG key, confirming it has not been tampered with.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    `rpm -qa kernel-core`

    Why it's wrong here

    `rpm -qa kernel-core` only queries whether the package is installed and lists its version; it performs no signature or integrity check. It is tempting because -q queries package metadata, but verification requires the -V or --checksig options instead.

  • ✗

    `rpm -q --changelog kernel-core`

    Why it's wrong here

    The --changelog query lists package change history, not cryptographic signature data, so integrity cannot be verified. It tempts because it inspects package metadata, but signature checking requires rpm --checksig (or -K) against the package file.

  • ✓

    `rpm -K kernel-core`

    Why this is correct

    The -K flag performs a signature and digest verification on the named package, checking its GPG signature against the imported Red Hat keys. This directly satisfies the requirement to verify kernel-core's integrity, unlike -V, which only compares installed file attributes against the RPM database.

  • ✗

    `rpm -V kernel-core`

    Why it's wrong here

    `rpm -V kernel-core` verifies installed file attributes against the RPM database, detecting modified files, but it does not check the package's GPG signature. It is tempting because -V is a verification command, yet signature validation needs --checksig on the package file.

About these practice questions

This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.