Courseiva

LPIC-1 Devices, Filesystems and FHS Practice Question

Network Topology
-rw-rr$ df -h /var/log$ ls -lh /var/log/syslog

Refer to the exhibit. The system administrator notices the /var/log partition is nearly full. The syslog file is 2GB. Which command will safely reduce the size of this log file without stopping the logging daemon?

⚠ Common exam trap

A common mix-up: candidates confuse truncating a file with deleting or moving it, not realizing that the logging daemon holds an open file descriptor tied to the inode, so only in-place truncation preserves continuous logging without a restart.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

> /var/log/syslog

Using the shell redirection operator `> /var/log/syslog` truncates the file to zero length without deleting or closing its file descriptor. The syslog daemon (rsyslogd or syslogd) continues writing to the same inode, so no service interruption occurs. This is the safest method to free disk space while maintaining continuous logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    cp /dev/null /var/log/syslog

    Why it's wrong here

    Truncating via cp /dev/null keeps the same inode, so the daemon's open file descriptor continues writing at its old offset, leaving a sparse 2GB file. It is tempting because it avoids a restart, and it would be correct for a file no process holds open.

  • ✗

    rm /var/log/syslog && touch /var/log/syslog

    Why it's wrong here

    Deleting and recreating the file breaks the daemon's open file descriptor, so syslog keeps writing to the unlinked inode and the space is never reclaimed until restart. Truncation with : > /var/log/syslog or logrotate copytruncate preserves the descriptor. Removing the file is tempting because it appears to free space immediately.

  • ✓

    > /var/log/syslog

    Why this is correct

    The shell redirection operator truncates the file to zero bytes in place, preserving the inode and open file descriptor, so syslogd continues writing without restart. That satisfies the stem's requirement to reduce the 2 GB file safely without stopping the logging daemon.

  • ✗

    mv /var/log/syslog /var/log/syslog.old

    Why it's wrong here

    Renaming leaves the daemon writing to the same inode under a new path, so /var/log/syslog.old keeps growing and space is not freed. It is tempting because it preserves the old log, and it would be correct if the daemon were then signalled to reopen its files.

About these practice questions

This LPIC-1 question is part of Courseiva's 402-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.