Courseiva

CCNA Admin Tasks Questions

56 questions · Admin Tasks topic · All types, answers revealed

1
MCQmedium

A system administrator wants to configure log rotation to compress log files daily and keep 30 days of logs. Which of the following configurations achieves this goal?

A.Set the 'maxlogsize' parameter in /etc/rsyslog.conf
B.Add a configuration file in /etc/logrotate.d/ with the contents: '/var/log/mylog { daily rotate 30 compress }'
C.Create a cron job that runs 'gzip /var/log/mylog.*' daily
D.Edit /etc/logrotate.conf to set 'rotate 30 weekly'
AnswerB

The logrotate directive combines daily rotation, rotate 30 retention and compress into one stanza, satisfying both the daily compression and 30-day retention constraints. Placing it in /etc/logrotate.d/ ensures logrotate picks it up automatically via its include directive, so no cron entry is needed.

Why this answer

Logrotate is the standard Linux utility for log rotation, compression, and retention. The configuration directive 'daily rotate 30 compress' in a file under /etc/logrotate.d/ instructs logrotate to rotate logs daily, keep 30 rotated copies, and compress old logs with gzip. This directly meets the requirement of daily compression and 30-day retention.

Exam trap

The trap here is that candidates may confuse logrotate's 'rotate' count with a time-based retention period, or assume that rsyslog or a simple cron+gzip approach can handle rotation and retention, when in fact logrotate is the dedicated tool that manages both rotation and compression with precise control over file naming and retention limits.

How to eliminate wrong answers

Option A is wrong because /etc/rsyslog.conf is the configuration file for rsyslog, the system logging daemon, and it does not have a 'maxlogsize' parameter for log rotation; log rotation is handled by logrotate, not rsyslog. Option C is wrong because a cron job running 'gzip /var/log/mylog.*' would compress all matching files daily but would not perform rotation (renaming the active log) or enforce a retention limit of 30 days, leading to uncontrolled accumulation of compressed files. Option D is wrong because editing /etc/logrotate.conf to set 'rotate 30 weekly' would keep 30 weeks of logs, not 30 days, and the 'weekly' directive contradicts the requirement for daily rotation.

2
MCQmedium

A system administrator wants to change the default runlevel of a SysV init-based system to runlevel 3. Which file should be edited to make this change persistent across reboots?

A./etc/init/rc-sysinit.conf
B./etc/rc.d/rc.local
C./etc/inittab
D./etc/systemd/system/default.target
AnswerC

On SysV init systems, the default runlevel is specified in /etc/inittab by the 'initdefault' entry, such as 'id:3:initdefault:'. Editing this file to set the runlevel to 3 changes the default runlevel persistently. This is the correct file for SysV init-based systems.

Why this answer

For SysV init systems, the default runlevel is set in /etc/inittab via the initdefault line. Editing that file to specify runlevel 3 ensures the system boots to runlevel 3 on subsequent reboots. The other files are associated with different init systems or purposes and would not achieve the desired change.

Exam trap

The trap here is mixing up init systems: /etc/inittab is for SysV init, while systemd uses default.target and Upstart uses /etc/init/.

3
Multi-Selectmedium

Which TWO commands can be used to display the current runlevel of a system?

Select 2 answers
A.telinit q
B.systemctl get-default
C.init 3
D.runlevel
E.who -r
AnswersD, E

The `runlevel` command reads `/var/run/utmp` and prints the previous and current runlevel, satisfying the requirement to display the system's current runlevel. It reports both values directly, for example "N 5", making it a valid answer alongside `who -r`.

Why this answer

The `runlevel` command (option D) reads `/var/run/utmp` and prints the previous and current runlevel (e.g., "N 5"), directly reporting the system's current runlevel. The `who -r` command (option E) uses the `-r` flag to display the current runlevel along with the time it was last changed, also deriving this from the utmp record. Option A, `telinit q`, only tells init to re-read its configuration and does not display the runlevel.

Option B, `systemctl get-default`, shows the default target (e.g., graphical.target) that the system boots into, not the currently active runlevel. Option C, `init 3`, is used to change the runlevel to 3, not to display the current one.

Exam trap

The trap here is that candidates may confuse commands that change the runlevel (like `init 3`) with commands that display it, or assume `systemctl get-default` shows the current runlevel when it actually shows the default target for the next boot.

4
MCQmedium

A server's root filesystem is filling up. The administrator suspects that a service is writing large log files to /var/log/journal. Which command displays the total disk space currently used by the systemd journal?

A.journalctl -u systemd-journald --size
B.du -sh /var/log/journal
C.journalctl --disk-usage
D.systemctl status systemd-journald --disk
AnswerC

The --disk-usage option to journalctl reports the total amount of disk space consumed by the journal files. It provides a single summary line, making it ideal for quickly assessing whether the journal is the source of disk pressure. This is the purpose-built command for this exact diagnostic scenario.

Why this answer

The journalctl --disk-usage command is designed specifically to report how much disk space the systemd journal is consuming. It accounts for the journal's internal storage format, including compression, and returns a concise summary. Other commands either query unit status, filter log entries, or measure directory size in a way that may not match the journal's own accounting.

Exam trap

The trap here is reaching for du on the journal directory when journalctl provides an authoritative, journal-aware disk usage report.

5
MCQeasy

A user's home directory /home/alice has grown unexpectedly large. The administrator wants to identify which subdirectory consumes the most space, displaying sizes in human-readable format and limiting output to one level deep. Which command is most appropriate?

A.df -h /home/alice
B.du -sh /home/alice/*
C.ls -lR /home/alice | sort -k5 -n
D.find /home/alice -type d -exec du -sh {} \;
AnswerB

The du command estimates file space usage. The -s flag summarizes each argument rather than recursing into every subdirectory, and -h produces human-readable units. Using the glob /home/alice/* passes each top-level item as a separate argument, so the output lists the total size of each immediate child. This directly answers which subdirectory is largest.

Why this answer

To find which immediate subdirectory of a home directory uses the most space, du with the summarize and human-readable flags, applied to a glob of top-level entries, gives exactly one line per child directory. This avoids the noise of recursive output and directly highlights the largest consumer. df would only show partition totals, and recursive listings are far too verbose.

Exam trap

The trap here is confusing disk free space at the filesystem level with per-directory usage, leading to use of df instead of du.

6
MCQeasy

An administrator adds the line 'DenyUsers john' to /etc/ssh/sshd_config and restarts the SSH service. What is the effect?

A.User john cannot log in via SSH.
B.User john can still log in but his commands are logged.
C.User john is denied all shell access, including local and console logins.
D.All users except john cannot log in via SSH.
AnswerA

DenyUsers in /etc/ssh/sshd_config blocks the named account from authenticating over SSH; after the service restart, john's connection attempts are refused. The directive is enforced by sshd itself, so it does not disable the local account or affect console logins.

Why this answer

The 'DenyUsers' directive in /etc/ssh/sshd_config explicitly blocks the specified user(s) from authenticating via SSH. When the SSH service is restarted, the configuration is reloaded, and user 'john' will be denied SSH login attempts at the authentication layer, before any shell or command execution occurs.

Exam trap

The trap here is that candidates often confuse 'DenyUsers' with broader access restrictions like PAM-based account denial or shell-level bans, but 'DenyUsers' is SSH-specific and only affects SSH logins, not console or other remote access methods.

How to eliminate wrong answers

Option B is wrong because 'DenyUsers' does not enable logging of commands; logging of SSH sessions is controlled by directives like 'LogLevel' or 'ForceCommand' with logging wrappers, not by 'DenyUsers'. Option C is wrong because 'DenyUsers' only affects SSH access, not local console logins or other non-SSH shell access; local authentication is handled by PAM or /etc/nologin, not by sshd_config. Option D is wrong because 'DenyUsers' denies only the specified user(s), not all users except that user; the inverse behavior would require 'AllowUsers' with all other users listed.

7
MCQeasy

An administrator needs to determine which package owns the file /usr/bin/htop on a Debian-based system so that the package can be reinstalled after corruption. Which command provides this information?

A.dpkg -S /usr/bin/htop
B.dpkg -L htop
C.apt-file search /usr/bin/htop
D.apt-cache show htop
AnswerA

dpkg -S (or --search) queries the local package database for the package that owns a given file path. This is the direct, accurate way to map an installed file back to its package on a Debian-based system, which is exactly what the administrator needs before reinstalling the corrupted package.

Why this answer

On Debian-based systems, the local package database tracks which package installed each file. The dpkg search option queries that database by file path, returning the owning package, which is precisely the reverse lookup needed before reinstallation.

Exam trap

The trap here is confusing the direction of the lookup, using a command that lists a package's files instead of one that finds the package owning a file.

8
MCQmedium

A Linux administrator is responsible for a server that runs a critical database application. The server uses SysV init and the current runlevel is 3. The administrator needs to schedule a maintenance window for next Sunday at 2:00 AM to apply security patches that require a reboot. The administrator wants to ensure that after the reboot, the system returns to runlevel 3 and the database service (db_service) starts automatically. The administrator also wants to log the maintenance actions to /var/log/maintenance.log. Which of the following is the BEST approach to accomplish these tasks?

A.Edit /etc/rc.d/rc.local to start db_service and set runlevel via 'init 3' in the script. Then use 'at 2am Sunday shutdown -r now' to schedule reboot and redirect output to /var/log/maintenance.log.
B.Edit /etc/inittab to change the initdefault line to 'id:3:initdefault:' and create an init script for db_service with appropriate symlinks in /etc/rc.d/rc3.d/. Schedule the reboot using 'shutdown -r 02:00' and configure syslog to capture messages to /var/log/maintenance.log.
C.Use 'systemctl set-default runlevel3.target' and 'systemctl enable db_service' then schedule reboot with 'shutdown -r 02:00' and log with 'logger' to /var/log/maintenance.log.
D.Use 'telinit 3' and 'service db_service start' then run 'reboot' at 2:00 AM. Log actions by appending to /var/log/maintenance.log manually.
AnswerA

rc.local runs after boot, but setting runlevel via 'init 3' in rc.local is redundant and may cause issues. 'shutdown -r now' reboots immediately, not at 2:00.

Why this answer

The best approach because it uses 'at' to schedule the reboot, which can be configured to run at a specific day and time (e.g., 'at 2am Sunday shutdown -r now'), and redirects output to /var/log/maintenance.log for simple logging. Although editing rc.local is not the standard SysV method for persistent service management, it effectively starts the database service and sets the runlevel to 3 upon boot. In contrast, option B's shutdown command does not allow specifying the day 'next Sunday', and configuring syslog for a custom log file is non-trivial.

Options C and D are incorrect due to systemd usage or lack of scheduling.

Exam trap

The trap is that candidates may assume option B is correct because it uses proper SysV init configuration (inittab and init scripts), but they overlook that 'shutdown -r 02:00' cannot schedule for a specific day like 'next Sunday', and that configuring syslog for custom logging is not straightforward. Option A, while using rc.local (a less standard method), provides direct scheduling via 'at' and simple output redirection.

How to eliminate wrong answers

Option A is wrong because editing /etc/rc.d/rc.local to start db_service and run 'init 3' is not the standard SysV method for persistent runlevel or service management; rc.local runs after init scripts and may not execute on all reboots, and redirecting output with '>' in an 'at' job does not capture all boot messages. Option C is wrong because it uses systemctl commands (systemctl set-default, systemctl enable) which are for systemd systems, not SysV init; the server uses SysV init, so these commands are invalid. Option D is wrong because 'telinit 3' and 'service db_service start' only affect the current session and do not persist after reboot; manually appending to the log is error-prone and does not capture system boot messages.

9
MCQhard

A server has a backup script that runs daily at midnight. The system administrator notices that the script sometimes fails because the filesystem is mounted read-only. Which approach is the best practice to ensure the script runs only when the filesystem is writable?

A.Add a cron job that runs before the backup to remount the filesystem read-write
B.Use anacron to run the job after boot
C.Wrap the backup command in a script that checks if the filesystem is writable before proceeding
D.Change the cron job to run every hour until it succeeds
AnswerC

Testing writability with a command such as touch or mount before invoking the backup prevents failures caused by a read-only remount. The wrapper aborts cleanly instead of leaving a partial archive, directly addressing the intermittent read-only filesystem constraint.

Why this answer

It implements a proactive check within the script itself, using a command like `touch /mountpoint/testfile 2>/dev/null` or checking `/proc/mounts` to verify write access before executing the backup. This avoids unnecessary remounts and ensures the script only proceeds when the filesystem is writable, which is a robust and self-contained solution.

Exam trap

The trap here is that candidates may assume remounting (Option A) is a safe fix, but LPIC-1 emphasizes that a read-only filesystem often indicates a deeper problem, and the best practice is to check state rather than force a change.

How to eliminate wrong answers

Option A is wrong because blindly remounting the filesystem read-write could override a forced read-only state caused by filesystem errors (e.g., from `fsck`), potentially leading to data corruption or system instability. Option B is wrong because anacron is designed to run jobs that were missed due to the system being off, not to handle a filesystem being read-only; it does not check filesystem state before execution. Option D is wrong because running the backup every hour until it succeeds wastes system resources, may cause overlapping backups, and does not address the root cause of the read-only filesystem.

10
MCQmedium

Which configuration file is the primary configuration file for logrotate?

A./var/log/messages
B./etc/logrotate.d/
C./etc/logrotate.conf
D./etc/rsyslog.conf
AnswerC

/etc/logrotate.conf holds the global directives that logrotate reads first, including rotation frequency, retention count and compression defaults, before it processes any per-service drop-in files in /etc/logrotate.d/. This satisfies the stem's requirement for the primary configuration file, since the drop-ins are merely included from it rather than being primary themselves.

Why this answer

The primary configuration file for logrotate is /etc/logrotate.conf. This file sets global options such as rotation frequency, compression, and the number of rotated logs to keep. It also includes configuration snippets from /etc/logrotate.d/ via an include directive, but the main control file is /etc/logrotate.conf.

Exam trap

The trap here is that candidates confuse the directory /etc/logrotate.d/ (which holds supplementary configs) with the primary configuration file /etc/logrotate.conf, or mistake /etc/rsyslog.conf (a logging daemon config) for logrotate's config.

How to eliminate wrong answers

Option A is wrong because /var/log/messages is a system log file managed by rsyslog or syslog-ng, not a configuration file for logrotate. Option B is wrong because /etc/logrotate.d/ is a directory containing per-service configuration snippets that are included by /etc/logrotate.conf, not the primary configuration file itself. Option D is wrong because /etc/rsyslog.conf is the configuration file for the rsyslog daemon, which handles system logging, not log rotation.

11
MCQmedium

Based on the exhibit, which of the following is true about the cleanup.sh job?

A.It runs at 4:30 AM every day
B.It runs at 4:30 AM on Monday through Friday
C.It runs at 4:00 AM on weekdays
D.It runs at 4:30 AM on weekends
AnswerB

The cron schedule encodes minute 30, hour 4, and a day-of-week field restricted to Monday through Friday, so the job executes at 04:30 on weekdays only. This matches the stated behaviour of the cleanup.sh job shown in the exhibit.

Why this answer

The cron expression `30 4 * * 1-5` specifies that the job runs at minute 30, hour 4 (4:30 AM), every day of month (*), every month (*), but only on days of the week 1 through 5 (Monday=1, Tuesday=2, Wednesday=3, Thursday=4, Friday=5). Therefore, the job runs at 4:30 AM on Monday through Friday.

Exam trap

The trap here is that candidates often misread the minute field (30) as the hour or confuse the day-of-week range `1-5` with 'every day', leading them to select 'every day' or 'weekends' instead of the correct weekday-only schedule.

How to eliminate wrong answers

Option A is wrong because it states 'every day', but the day-of-week field `1-5` restricts execution to weekdays only, not all seven days. Option C is wrong because it specifies 4:00 AM, but the minute field is `30`, not `0`, so the job runs at 4:30 AM, not 4:00 AM. Option D is wrong because it says 'on weekends', but the day-of-week range `1-5` explicitly excludes Saturday (6) and Sunday (0 or 7), so the job does not run on weekends.

12
MCQeasy

An administrator wants to run a shell script every day at 2:00 AM. Which command should be used to edit the user's personal crontab?

A.crontab -l
B.crontab -e
C.at 2:00 AM
D.vi /var/spool/cron/crontabs/username
AnswerB

crontab -e opens the invoking user's personal crontab in the default editor, letting the administrator add a 0 2 * * * schedule. It edits only that user's own table, matching the requirement for a personal crontab rather than a system-wide file.

Why this answer

The correct command to edit a user's personal crontab is `crontab -e`. This invokes the default text editor (as defined by the EDITOR or VISUAL environment variable) on the user's crontab file, ensuring proper syntax validation and locking to prevent concurrent edits. It is the standard and recommended way to modify cron jobs for the current user.

Exam trap

The trap here is that candidates may think they can directly edit the crontab file in `/var/spool/cron/` with `vi`, but the LPIC-1 exam expects you to know that only the `crontab` command should be used to safely modify user crontabs to avoid syntax errors and file corruption.

How to eliminate wrong answers

Option A is wrong because `crontab -l` lists the current user's crontab entries to standard output, it does not open an editor for modifications. Option C is wrong because `at 2:00 AM` is used for scheduling a one-time job at a specific time, not for recurring daily execution at 2:00 AM; `at` does not edit crontab files. Option D is wrong because directly editing the file `/var/spool/cron/crontabs/username` (or `/var/spool/cron/username` on some systems) bypasses the `crontab` command's syntax checking and locking mechanisms, which can lead to corruption or invalid entries; the `crontab` command should always be used to safely modify these files.

13
MCQmedium

An administrator wants to allow user 'john' to run all commands as root without a password. Which sudoers entry accomplishes this?

A.john ALL=(ALL) NOPASSWD: ALL
B.john ALL=NOPASSWD: /bin/su
C.john ALL=(ALL) ALL
D.john ALL=(ALL) PASSWD: ALL
AnswerA

The entry john ALL=(ALL) NOPASSWD: ALL grants john sudo rights on every host, as every user, for every command, with the NOPASSWD tag suppressing the password prompt. This precisely matches the requirement of passwordless root command execution.

Why this answer

The sudoers entry 'john ALL=(ALL) NOPASSWD: ALL' grants user 'john' permission to run any command as any user (including root) from any host, and the NOPASSWD tag overrides the default password requirement, allowing passwordless execution. This matches the requirement precisely.

Exam trap

The trap here is that candidates often confuse the absence of a TAG (which defaults to requiring a password) with passwordless access, or they mistakenly think that specifying 'ALL' without the NOPASSWD tag implies no password is needed.

How to eliminate wrong answers

Option B is wrong because it restricts john to only running '/bin/su' without a password, not all commands as root. Option C is wrong because it omits the NOPASSWD tag, so john would still be prompted for a password before executing commands as root. Option D is wrong because it explicitly specifies PASSWD: ALL, which forces password authentication, the opposite of the requirement.

14
MCQmedium

An administrator notices the system clock is drifting. Which command can be used to enable automatic time synchronization using NTP on a system with systemd?

A.ntpdate pool.ntp.org
B.timedatectl set-ntp yes
C.systemctl start ntpd
D.date --set
AnswerB

timedatectl set-ntp yes enables systemd-timesyncd, which starts the NTP synchronisation service and keeps the clock aligned automatically. This directly satisfies the requirement for automatic time synchronisation on a systemd host, correcting the drift without manual intervention.

Why this answer

`timedatectl set-ntp yes` enables automatic time synchronization via NTP on systems using systemd. This command configures the `systemd-timesyncd` service, which is the default NTP client for systemd-based distributions, to synchronize the system clock with remote NTP servers. It is the standard, modern method for managing NTP settings in such environments.

Exam trap

The trap here is that candidates often confuse one-time synchronization commands (like `ntpdate` or `date --set`) with the persistent enabling of automatic NTP synchronization, or they assume starting the `ntpd` service alone is sufficient without using `timedatectl` to manage systemd's time synchronization framework.

How to eliminate wrong answers

Option A is wrong because `ntpdate pool.ntp.org` performs a one-time manual synchronization of the system clock, not enabling automatic time synchronization; it is also deprecated in favor of `timedatectl` and `ntpd` or `chronyd`. Option C is wrong because `systemctl start ntpd` starts the traditional NTP daemon, but this command alone does not enable automatic synchronization at boot or integrate with systemd's timedatectl mechanism; it also requires the `ntpd` service to be installed and configured separately. Option D is wrong because `date --set` manually sets the system clock to a specified value, which does not enable automatic synchronization and is a temporary, non-persistent change.

15
MCQmedium

A system is not logging messages to /var/log/syslog. Which command should an administrator use first to diagnose the issue?

A.tail -f /var/log/syslog
B.logger test
C.ps aux | grep syslog
D.systemctl status rsyslog
AnswerD

systemctl status rsyslog reveals whether the rsyslog unit is active, failed or masked, and shows recent journal output explaining why messages stopped reaching /var/log/syslog. This checks the daemon responsible for writing that file before investigating configuration or permissions.

Why this answer

The first step in diagnosing why messages are not appearing in /var/log/syslog is to verify that the rsyslog service is running and active. The 'systemctl status rsyslog' command shows the current service state, recent logs, and any errors that might prevent logging. Without confirming the service status, other diagnostic steps may be misleading.

Exam trap

The trap here is that candidates often jump to testing the logging pipeline (with 'logger') or checking for a process by name, instead of first verifying the service status with systemctl, which is the systematic and most efficient diagnostic step.

How to eliminate wrong answers

Option A is wrong because 'tail -f /var/log/syslog' only monitors the log file for new entries; if no messages are being written, it will simply hang and provide no diagnostic information about why logging has stopped. Option B is wrong because 'logger test' sends a test message to the syslog system, but if the service is not running or misconfigured, the message will not be logged and the command gives no feedback about the underlying issue. Option C is wrong because 'ps aux | grep syslog' only checks for a process named 'syslog' in the process list, but modern systems use rsyslog or syslog-ng, and this command may miss the actual daemon or show unrelated processes, failing to reveal service status or configuration errors.

16
Drag & Dropmedium

Arrange the steps to troubleshoot a service that fails to start.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Troubleshooting starts with checking status and logs, then examining config files, fixing, and restarting.

17
MCQhard

An administrator ran 'dnf update' and a critical application broke. The administrator wants to undo the last transaction and return to previous state. Which command should be used?

A.dnf undo last
B.dnf rollback
C.yum rollback
D.dnf history undo last
AnswerD

`dnf history undo last` reverses the most recent transaction by replaying its recorded actions in reverse, reinstalling the previous package versions and removing newly added ones. This directly satisfies the requirement to return the system to its pre-update state after the broken `dnf update`.

Why this answer

The correct command is 'dnf history undo last' because DNF maintains a transaction history that can be reverted. The 'undo' subcommand reverses the specified transaction (in this case, the last one) by applying the inverse operations, restoring packages to their previous state. This is the standard way to roll back a DNF transaction without affecting unrelated changes.

Exam trap

The trap here is that candidates confuse 'undo' with 'rollback' or assume DNF uses the same syntax as YUM, leading them to pick 'dnf rollback' or 'yum rollback' instead of the correct 'dnf history undo last'.

How to eliminate wrong answers

Option A is wrong because 'dnf undo last' is not a valid DNF command; DNF requires the 'history' subcommand before 'undo'. Option B is wrong because 'dnf rollback' does not exist; DNF uses 'history undo' or 'history rollback' (the latter reverts to a specific transaction ID, not the last one). Option C is wrong because 'yum rollback' is a legacy YUM command that is not available in DNF; DNF replaced YUM and uses 'dnf history' for transaction management.

18
MCQeasy

An administrator needs to find all files in the /var/log directory that have been modified in the last 24 hours. Which command should be used?

A.find /var/log -ctime 0
B.find /var/log -mtime 0
C.find /var/log -atime 0
D.find /var/log -mmin 1440
AnswerB

The -mtime 0 predicate matches files whose data was modified less than 24 hours ago, since find counts in 24-hour periods and 0 covers the current partial day. This precisely satisfies the requirement to list recently modified files under /var/log.

Why this answer

The `find` command with `-mtime 0` searches for files whose data modification time is within the last 24 hours. The `-mtime` option uses a 24-hour period, and a value of 0 means modified less than 24 hours ago, which matches the requirement to find files modified in the last 24 hours in /var/log.

Exam trap

The trap here is that candidates confuse `-ctime` (inode change time) with `-mtime` (modification time), or mistakenly think `-atime` (access time) is relevant for modification, leading them to pick options that do not match the requirement for content modification.

How to eliminate wrong answers

Option A is wrong because `-ctime 0` checks the inode change time (ctime), which includes metadata changes like permission or ownership changes, not file content modification; this can return files that were not modified in terms of content. Option C is wrong because `-atime 0` checks the access time (atime), which is updated when a file is read, not when it is modified; this would include files that were simply accessed, not modified. Option D is wrong because `-mmin 1440` checks for files modified within the last 1440 minutes (exactly 24 hours), but the question asks for files modified in the last 24 hours, and `-mmin` uses a precise minute count, which is technically correct but less standard for this requirement; however, the primary issue is that the question expects `-mtime 0` as the standard approach, and `-mmin 1440` could miss files modified exactly 1440 minutes ago due to integer rounding behavior in `-mtime` vs `-mmin`.

19
Multi-Selecteasy

Which TWO commands can be used to display the current runlevel of a SysV init system?

Select 2 answers
A.init 3
B.who -r
C.telinit
D.runlevel
E.systemctl get-default
AnswersB, D

The who command with the -r flag queries the utmp database and prints the current runlevel together with the last boot time, reading the same SysV init state that runlevel reports. This directly satisfies the requirement to display the runlevel on a SysV init system.

Why this answer

Option B (who -r) is correct because the who command with the -r flag reads the /var/run/utmp file and prints the current runlevel along with the time it was last changed, making it a valid way to display the runlevel on a SysV init system. Option D (runlevel) is correct because the runlevel command reads /var/run/utmp and outputs the previous and current runlevel (e.g., 'N 3'), directly reporting the system's current runlevel. Option A (init 3) is incorrect because init 3 changes the runlevel to 3 rather than displaying the current one.

Option C (telinit) is incorrect because telinit is used to send control commands to init (such as changing runlevels), not to query the current runlevel. Option E (systemctl get-default) is incorrect because it is a systemd command that shows the default target, not the current runlevel of a SysV init system.

Exam trap

The trap here is that candidates confuse commands that change runlevels (like `init` or `telinit`) with those that display them, or mistakenly apply systemd commands like `systemctl get-default` to SysV init systems.

20
MCQeasy

An administrator needs to check the system's load averages without displaying any process information. Which command should be used?

A.w
B.top
C.ps
D.uptime
AnswerD

uptime prints the current time, uptime duration, logged-in user count and the 1-, 5- and 15-minute load averages, then exits. It reads /proc/loadavg without listing processes, unlike top or ps, satisfying the requirement to view load averages without process information.

Why this answer

The `uptime` command displays the current time, how long the system has been running, the number of logged-in users, and the system load averages for the past 1, 5, and 15 minutes. It does not show any process-level information, making it the correct choice for checking load averages alone.

Exam trap

The trap here is that candidates often confuse `uptime` with `w` or `top` because both also display load averages, but the question explicitly requires no process information, which `w` and `top` include.

How to eliminate wrong answers

Option A is wrong because `w` displays load averages but also shows detailed information about currently logged-in users and their processes. Option B is wrong because `top` provides a real-time, dynamic view of running processes along with load averages, which is more than what the question asks for. Option C is wrong because `ps` reports a snapshot of current processes and does not display system load averages at all.

21
MCQmedium

An administrator wants to prevent a specific user, 'john', from being able to schedule cron jobs. Which file should the administrator modify?

A./var/spool/cron/crontabs
B./etc/cron.allow
C./etc/crontab
D./etc/cron.deny
AnswerD

Adding john to /etc/cron.deny blocks that named user from submitting jobs via crontab, satisfying the requirement to prevent only him from scheduling cron jobs. The file lists users barred from cron, and it takes effect only while /etc/cron.allow is absent.

Why this answer

The /etc/cron.deny file lists users who are explicitly denied access to schedule cron jobs. If this file exists and the user 'john' is listed in it, he will be prevented from using crontab. This is the standard mechanism for restricting cron access when /etc/cron.allow does not exist.

Exam trap

The trap here is that candidates confuse /etc/cron.allow with /etc/cron.deny, thinking that modifying the allow file is the only way to control access, but the question specifically asks for a file to prevent a user, which is the deny file.

How to eliminate wrong answers

Option A is wrong because /var/spool/cron/crontabs is a directory containing individual user crontab files, not a configuration file for access control. Option B is wrong because /etc/cron.allow is used to explicitly allow users to schedule cron jobs; modifying it would not prevent 'john' unless he is removed from it, but the question asks for a file to prevent him, and /etc/cron.deny is the direct method. Option C is wrong because /etc/crontab is the system-wide cron table for scheduled tasks, not a user access control file.

22
MCQmedium

A Linux administrator needs to create a user account 'jsmith' with a home directory '/home/jsmith' and the default shell '/bin/bash'. The account must be created without creating a group with the same name. Which command accomplishes this?

A.adduser -m -s /bin/bash -N jsmith
B.usermod -m -s /bin/bash -N jsmith
C.useradd -d /home/jsmith -s /bin/bash --no-group jsmith
D.useradd -m -s /bin/bash -N jsmith
AnswerD

The -m flag creates the home directory, -s sets the shell, and -N disables the creation of a user group with the same name. This matches the requirement exactly. Without -N, useradd would create a group 'jsmith' by default, which is not desired here.

Why this answer

The useradd command with -m creates the home directory, -s sets the login shell, and -N prevents the creation of a group with the same name as the user. This satisfies all requirements: new account, specified home directory, specified shell, and no matching group. The other commands either use invalid options, wrong syntax, or are meant for modification rather than creation.

Exam trap

The trap here is assuming that useradd always creates a group with the same name; the -N option is required to suppress that behavior.

23
MCQmedium

A technician needs to inspect a compressed log archive named app.log.gz without modifying it, and wants to view only the first 20 lines. The archive is 40 MB compressed. Which command accomplishes this most efficiently?

A.tar -xzf app.log.gz -O | head -n 20
B.zcat app.log.gz > app.log; head -n 20 app.log
C.gunzip app.log.gz && head -n 20 app.log
D.gunzip -c app.log.gz | head -n 20
AnswerD

The -c option writes the decompressed stream to standard output without altering the original file, and piping to head reads only the first 20 lines before closing the pipe. This preserves the archive, avoids writing a full decompressed copy to disk, and stops decompression early, making it the most efficient correct approach.

Why this answer

Streaming the decompressed output to standard output with gunzip -c and piping into head reads only as many lines as needed while leaving the archive untouched. This avoids writing a full uncompressed copy and stops work early, which is the efficient and non-destructive way to peek at the start of a compressed log.

Exam trap

The trap here is using plain gunzip, which deletes the original archive and fully expands it, instead of the streaming -c form that preserves the file.

24
MCQmedium

Refer to the exhibit. What can be concluded about the cron daemon based on this systemctl output?

A.It is stopped.
B.It is enabled but not currently running.
C.It has failed recently.
D.It is running and will start automatically at system boot.
AnswerD

The `systemctl` output shows the unit state as active (running) with no failure, confirming the cron daemon is currently executing. The "enabled" vendor preset indicates a symlink exists in the multi-user.target.wants directory, so systemd will start cron automatically during boot without manual intervention.

Why this answer

The systemctl output shows 'Loaded: loaded' and 'Active: active (running)' for the cron daemon, which indicates it is currently running. Additionally, the 'enabled' status in the 'Loaded' line means the service is configured to start automatically at system boot. Therefore, option D is correct.

Exam trap

The trap here is that candidates may confuse 'enabled' (start at boot) with 'active' (currently running), leading them to select option B when the service is actually running, or they may misinterpret the absence of explicit 'failed' text as meaning the service is stopped.

How to eliminate wrong answers

Option A is wrong because 'Active: active (running)' explicitly shows the cron daemon is running, not stopped. Option B is wrong because while the service is enabled, it is also currently running, not just enabled but not running. Option C is wrong because there is no indication of a failure; the status shows 'active (running)' with no mention of 'failed' or recent crash logs in the output.

25
Multi-Selectmedium

Which THREE directories are commonly used for mounting removable media in Linux?

Select 3 answers
A./mnt
B./mount
C./cdrom
D./dev
E./media
AnswersA, C, E

/mnt serves as the conventional mount point for temporarily mounted filesystems, including removable media such as USB drives and optical discs. It satisfies the question's requirement for a standard directory used for removable media mounting, distinct from /media, which desktop environments typically manage automatically for user-mounted devices.

Why this answer

Option A, /mnt, is correct because it is the traditional Filesystem Hierarchy Standard (FHS) mount point for temporarily mounted filesystems, including removable media such as USB drives and external disks. Option C, /cdrom, is correct because it is a conventional mount point historically used by distributions to mount optical media like CD-ROMs and DVDs. Option E, /media, is correct because modern Linux distributions use it as the standard mount point for automatically mounted removable media such as USB sticks, cameras, and optical discs.

Option B, /mount, is not a standard FHS directory and is not used by Linux for mounting removable media. Option D, /dev, is incorrect because it contains device files (e.g., /dev/sdb1) that represent hardware devices, not directories where filesystems are mounted.

Exam trap

Candidates may incorrectly assume that /dev (the device directory) is a mount point, or that /mount is a valid FHS directory. They might also overlook /cdrom as a common mount point for optical media, often symlinked to /media/cdrom. The correct mount point directories for removable media per FHS are /mnt (temporary manual mounts) and /media (automatic mounting), with /cdrom being a widely used legacy or symlink location.

26
MCQhard

Refer to the exhibit. An administrator runs 'ntpq -p' and sees the output shown. What is the most likely cause of the '16' stratum and '0.000' delay/offset?

A.The NTP service is not running.
B.The firewall is blocking UDP port 123.
C.The NTP daemon has recently started and has not yet synchronized.
D.The restrict lines are blocking all NTP queries.
AnswerC

A freshly started NTP daemon reports stratum 16, the unsynchronised sentinel, until it completes its first poll and accepts a server. The 0.000 delay and offset values confirm no measurement has yet been taken, satisfying the stem's requirement to explain both anomalies as a single transient startup condition.

Why this answer

The '16' stratum and '0.000' delay/offset values in the 'ntpq -p' output indicate that the NTP daemon has not yet synchronized with any time source. When ntpd starts, it initially sets the stratum to 16 (unsynchronized) and shows zero values for delay and offset until it completes the synchronization process. This is a normal transient state that resolves once the daemon successfully contacts and synchronizes with an NTP server.

Exam trap

The trap here is that candidates often assume a stratum of 16 and zero delay/offset indicate a firewall or service failure, but the correct interpretation is that the NTP daemon has just started and has not yet synchronized, which is a normal temporary state.

How to eliminate wrong answers

Option A is wrong because if the NTP service were not running, the 'ntpq -p' command would typically return an error or show no output, not display a stratum of 16 with zero delay/offset. Option B is wrong because a firewall blocking UDP port 123 would prevent any NTP communication, resulting in no reachable servers or persistent '16' stratum, but the zero delay/offset specifically indicates the daemon has not yet attempted or completed synchronization, not that packets are being dropped. Option D is wrong because restrict lines blocking all NTP queries would cause the daemon to fail to contact servers, leading to a persistent unsynchronized state, but the zero delay/offset is a characteristic of a freshly started daemon that has not yet attempted synchronization, not a permanent restriction issue.

27
MCQhard

After creating a new user with 'useradd john', the user 'john' cannot log in. What is the most likely cause?

A.The home directory does not exist
B.No password has been set for the user
C.The user's shell is not set
D.The user is not in the sudoers file
AnswerB

useradd creates the account with a locked password field, so authentication fails until one is assigned. Running passwd john sets credentials, satisfying the login requirement; without it the account remains unusable regardless of shell or home directory.

Why this answer

The `useradd` command creates a new user account but does not set a password. Without a password, the system's authentication mechanism (typically PAM) will deny login attempts, as there is no valid password hash in `/etc/shadow`. The user must have a password assigned via `passwd john` before they can authenticate.

Exam trap

The trap here is that candidates assume `useradd` fully provisions an account, overlooking that password assignment is a separate mandatory step, and they may confuse login failure with missing home directory or shell issues.

How to eliminate wrong answers

Option A is wrong because `useradd` by default creates the home directory from `/etc/default/useradd` or `/etc/login.defs` unless explicitly overridden with `-M`; if it did not exist, the user would still be able to log in (though they might get a warning or land in `/`). Option C is wrong because `useradd` assigns a default shell (usually `/bin/sh` or `/bin/bash`) from `/etc/default/useradd`; if the shell is missing or invalid, login might fail, but the default is always set. Option D is wrong because membership in the sudoers file is irrelevant to basic login capability; sudo access is a privilege escalation mechanism, not a prerequisite for authentication.

28
MCQhard

A systemd service unit file must be configured to automatically restart the service if it exits unexpectedly. Which directive should be used?

A.Type=forking
B.Restart=always
C.RemainAfterExit=yes
D.ExecStop=/bin/true
AnswerB

Restart=always instructs systemd to relaunch the unit whenever its main process terminates, regardless of exit status, satisfying the requirement to recover from unexpected exits. Other Restart values such as on-failure ignore clean exits, so they would not cover every case.

Why this answer

The `Restart=always` directive in a systemd service unit file instructs systemd to automatically restart the service regardless of the exit status, including unexpected crashes or terminations. This ensures high availability by restarting the process whenever it exits, unless explicitly stopped by systemctl. Other directives like `Type=forking` or `RemainAfterExit=yes` do not control restart behavior.

Exam trap

The trap here is that candidates confuse `Restart=always` with `Type=forking` or `RemainAfterExit=yes`, mistakenly thinking these directives handle automatic restarts, when in fact they address process forking or service state after exit.

How to eliminate wrong answers

Option A is wrong because `Type=forking` defines the service's startup behavior (expecting the process to fork and the parent to exit), not its restart policy. Option C is wrong because `RemainAfterExit=yes` tells systemd to consider the service as active even after the main process exits, but it does not trigger automatic restarts. Option D is wrong because `ExecStop=/bin/true` specifies a command to run when stopping the service, not a condition for automatic restart.

29
MCQeasy

A system administrator needs to schedule a recurring maintenance task that runs every Monday at 3 AM. Which crontab entry is correct?

A.3 0 * * 1 /script.sh
B.0 3 * * 0 /script.sh
C.0 3 * * 7 /script.sh
D.0 3 * * 1 /script.sh
AnswerD

Correct: runs at 3:00 AM on Monday.

Why this answer

The crontab syntax is minute, hour, day of month, month, day of week. Setting minute=0, hour=3, day of week=1 runs the script at 3:00 AM every Monday (day 1 represents Monday in cron).

Exam trap

The trap here is confusing the day-of-week numbering (Monday=1 vs Sunday=0/7) and mixing minute and hour fields, leading candidates to select entries that run at the wrong time or on the wrong day.

How to eliminate wrong answers

Option A is wrong because it sets minute=3 and hour=0, which would run at 12:03 AM, not 3 AM. Option B is wrong because it sets day of week=0, which represents Sunday, not Monday. Option C is wrong because it sets day of week=7, which is not a valid day in standard cron (valid range is 0-6 or 1-7 depending on implementation, but 7 is ambiguous and not universally accepted; the correct Monday value is 1).

30
MCQmedium

A zombie process appears in the process list. The parent process has PID 1234. Which command will most likely remove the zombie?

A.kill -9 1234
B.kill -9 <zombie_pid>
C.wait <zombie_pid>
D.reboot
AnswerA

A zombie is already dead, so signalling it does nothing; only its parent can reap it. Killing PID 1234 with SIGKILL terminates the parent, after which init adopts and reaps the zombie, clearing it from the process table.

Why this answer

A zombie process is a child process that has terminated but whose exit status has not been read by its parent. The zombie cannot be killed directly because it is already dead; it only remains in the process table until the parent calls wait(). Sending SIGKILL (kill -9) to the parent process (PID 1234) causes the parent to terminate, and the zombie child is then adopted by init (PID 1), which automatically reaps it by calling wait().

Exam trap

The trap here is that candidates mistakenly think they can kill the zombie itself with kill -9, not realizing that a zombie is already dead and the only way to remove it is to force its parent to reap it or terminate the parent.

How to eliminate wrong answers

Option B is wrong because kill -9 on the zombie PID has no effect; the zombie is already dead and cannot be signaled. Option C is wrong because wait is a system call used by the parent, not a command that can be run from the shell to reap a zombie belonging to another process. Option D is wrong because rebooting is an extreme and unnecessary measure; it would remove the zombie but also disrupt all running processes and is not the standard or recommended solution.

31
MCQeasy

Refer to the exhibit. What is the file permission in numeric mode for /etc/crontab?

A.644
B.600
C.444
D.755
AnswerA

Numeric 644 grants the owner read and write (4+2), group read (4) and others read (4), matching the exhibit's rw-r--r-- permissions on /etc/crontab. This satisfies the requirement to express that file's permission in numeric mode.

Why this answer

The /etc/crontab file is a system-wide configuration file for cron jobs. It must be readable by all users to allow cron to read the scheduled tasks, but only writable by root to prevent unauthorized modifications. The standard permission is 644 (owner read/write, group read, others read).

Exam trap

The trap here is that candidates often confuse the permissions for /etc/crontab with those for user crontab files (which are stored in /var/spool/cron/ and typically have 600 permissions) or mistakenly think that execute permission is needed for configuration files.

How to eliminate wrong answers

Option B (600) is wrong because it would make the file readable only by root, preventing the cron daemon from reading the file when it runs as a non-root user. Option C (444) is wrong because it removes write permission for the owner (root), making it impossible to edit the crontab file without changing permissions first. Option D (755) is wrong because it grants execute permission to all users, which is unnecessary and a security risk for a text configuration file.

32
MCQhard

A system administrator wants to ensure that the syslog service starts automatically on boot and is running immediately without a reboot. Which command sequence should be used?

A.systemctl start syslog && systemctl enable syslog
B.systemctl start --enable syslog
C.systemctl enable syslog && systemctl start syslog
D.systemctl enable --now syslog
AnswerD

`systemctl enable --now syslog` satisfies both constraints in one invocation: `enable` creates the persistent symlink so the unit starts at every boot, while `--now` additionally starts it immediately in the current session, avoiding the reboot the stem forbids.

Why this answer

`systemctl enable --now syslog` combines enabling the service to start automatically on boot and starting it immediately in a single command. The `--now` flag triggers an immediate start after enabling, fulfilling both requirements without needing a reboot.

Exam trap

The trap here is that candidates may think they need to use two separate commands (enable and start) in a specific order, but the `--now` flag is a single-command shortcut that systemd provides, and LPI often tests this to see if you know the combined option exists.

How to eliminate wrong answers

Option A is wrong because it starts the service before enabling it; while this works, it is less efficient than using `--now`, and the order is not the issue—the command sequence is valid but not the best practice. Option B is wrong because `systemctl start --enable` is not a valid syntax; `--enable` is not a flag for `start`, and this command would fail. Option C is wrong because it enables the service first and then starts it, which is functionally correct but less efficient than using `--now`; however, the question asks for the command sequence that should be used, and `systemctl enable --now` is the idiomatic, single-command solution.

33
MCQhard

A system administrator needs to perform incremental backups of a large directory /data. The backup strategy requires a full backup every Sunday and incremental backups on weekdays. Which tar command satisfies this requirement using the --listed-incremental option?

A.Full: tar -czvf /backup/full.tar.gz /data; Incremental: tar -czvf /backup/incr.tar.gz --after-date '1 day ago' /data
B.Full: tar -cvf /backup/full.tar /data; Incremental: tar -cvf /backup/incr.tar -N 'last Sunday' /data
C.Full: tar -cvf /backup/full.tar --newer /data; Incremental: tar -cvf /backup/incr.tar --newer /backup/full.tar /data
D.Full: tar -cvf /backup/full.tar -g /var/backup/snapshot /data; Incremental: tar -cvf /backup/incr.tar -g /var/backup/snapshot /data
AnswerD

The -g flag with a shared snapshot file lets tar record file states, so the first run captures everything and later runs store only changes since that snapshot. Reusing /var/backup/snapshot across both commands satisfies the full-then-incremental requirement.

Why this answer

The `--listed-incremental` (or `-g`) option in tar creates and uses a snapshot file to track changes between backups. By specifying the same snapshot file for both the full and incremental backups, tar automatically records which files have changed since the last full backup, enabling proper incremental backups without relying on timestamps or file modification times.

Exam trap

The trap here is that candidates often confuse timestamp-based options like `--newer` or `-N` with the snapshot-based `--listed-incremental` mechanism, assuming any time-based filter can achieve incremental backups, but only `-g` provides the metadata tracking needed for proper incremental archives.

How to eliminate wrong answers

Option A is wrong because `--after-date` is not a valid tar option; the correct option for time-based filtering is `--newer` or `-N`, and using a relative time like '1 day ago' does not integrate with the `--listed-incremental` mechanism for reliable incremental backups. Option B is wrong because `-N 'last Sunday'` uses a timestamp-based filter that does not create a snapshot file, so subsequent incremental backups would not correctly track changes relative to the full backup; also, the full backup command lacks the `-g` option needed for incremental tracking. Option C is wrong because `--newer` compares file modification times against a file's timestamp, not against a snapshot; using `--newer /backup/full.tar` would include any file modified after the full archive was created, but it does not handle deletions or renames and is not the intended use of `--listed-incremental`.

34
MCQhard

Based on the exhibit, what will happen if the syslog service is stopped?

A.Apache2 will be stopped because it depends on syslog
B.The system will prompt to restart syslog before stopping
C.Apache2 will be automatically restarted because it requires syslog
D.Apache2 will continue running because the dependency is a soft dependency
AnswerD

Stopping syslog does not halt Apache2 because systemd's `After=` and `Wants=` directives create only ordering and soft dependency relationships, not hard `Requires=` bindings. Apache2 therefore continues running and serving requests; only log delivery via syslog is lost. This satisfies the stem's constraint that the web service remains available.

Why this answer

In Linux, services managed by systemd can have dependencies declared as 'Requires' (hard) or 'Wants' (soft). A soft dependency means that the dependent service (Apache2) does not require the target service (syslog) to be running; it will continue to operate even if syslog is stopped. The exhibit likely shows a 'Wants' directive, which does not enforce a strict ordering or runtime requirement.

Exam trap

The trap here is that candidates confuse 'Wants' (soft dependency) with 'Requires' (hard dependency), assuming any dependency means the dependent service will be stopped or restarted when the target service changes.

How to eliminate wrong answers

Option A is wrong because Apache2 will not be stopped when syslog is stopped; a soft dependency (Wants) does not cause cascading stops. Option B is wrong because systemd does not prompt the user to restart a service before stopping another; it simply proceeds with the stop operation. Option C is wrong because Apache2 will not be automatically restarted when syslog is stopped; soft dependencies do not trigger restarts of dependent units.

35
MCQmedium

A junior administrator needs to schedule a backup script to run as the user 'backup' every day at 02:30. The script is /usr/local/bin/backup.sh, and output should be discarded. Which crontab entry should the administrator add to the 'backup' user's crontab to accomplish this?

A.30 2 * * * /usr/local/bin/backup.sh >/dev/null 2>&1
B.2 30 * * * /usr/local/bin/backup.sh >/dev/null 2>&1
C.30 2 * * * /usr/local/bin/backup.sh >/dev/null
D.30 2 * * * backup /usr/local/bin/backup.sh >/dev/null 2>&1
AnswerA

This entry runs at 02:30 daily for the user whose crontab contains it. Redirecting stdout to /dev/null and stderr to stdout discards all output, preventing mail. The five time fields are minute, hour, day of month, month, day of week, and the command follows. This is the correct syntax and matches the requirement to run as the 'backup' user when placed in that user's crontab.

Why this answer

The correct entry uses the five time-and-date fields followed by the command. Placing it in the 'backup' user's crontab ensures it runs as that user. The redirection >/dev/null 2>&1 discards both stdout and stderr, meeting the requirement to suppress output.

The other entries either misplace the time fields, omit stderr redirection, or incorrectly add a user field that is invalid in a user crontab.

Exam trap

The trap here is confusing the format of a user crontab with the system crontab (/etc/crontab), which includes a user field before the command.

36
MCQmedium

An administrator wants to change the owner of all files in /data to user 'web' without changing the group. Which command should be used?

A.chown -R web:web /data
B.chown -R web /data
C.chown web /data
D.chown web:web /data
AnswerB

chown -R web /data recursively changes the owner to web while leaving the group untouched, because only the user field is specified. Adding a colon and group, or using chgrp, would alter group ownership, which the scenario forbids.

Why this answer

`chown -R web /data` changes the owner of all files and directories recursively under /data to user 'web' while leaving the group ownership unchanged. The `-R` flag ensures recursion, and omitting a colon or dot after the username means only the owner is modified.

Exam trap

The trap here is that candidates often assume a colon is required or that `chown` without `-R` applies recursively, leading them to pick options that change the group or fail to affect all files.

How to eliminate wrong answers

Option A is wrong because `chown -R web:web /data` changes both the owner and group to 'web', which violates the requirement to not change the group. Option C is wrong because `chown web /data` only changes the owner of the /data directory itself, not its contents, missing the recursive requirement. Option D is wrong because `chown web:web /data` changes both owner and group to 'web' on the single directory, and lacks recursion, so it fails on both counts.

37
MCQhard

A user 'jdoe' already exists. The administrator needs to add 'jdoe' to the 'staff' and 'admin' groups without changing other group memberships. Which command accomplishes this?

A.usermod -a -G staff,admin jdoe
B.sed -i 's/^staff:.*/&jdoe/' /etc/group
C.usermod -G staff,admin jdoe
D.useradd -G staff,admin jdoe
AnswerA

The -a flag appends the listed supplementary groups while preserving jdoe's existing memberships, and -G sets supplementary groups rather than the primary group. Omitting -a would replace all current supplementary groups, so this form satisfies the requirement exactly.

Why this answer

The `usermod -a -G` command appends the user 'jdoe' to the supplementary groups 'staff' and 'admin' without altering existing group memberships. The `-a` (append) flag is essential; without it, `-G` would replace all current supplementary groups with only those listed. This matches the requirement to add the user to new groups while preserving other group memberships.

Exam trap

The trap here is that candidates often forget the `-a` (append) flag with `usermod -G`, assuming `-G` alone adds groups, when in fact it replaces all supplementary group memberships, which is a common cause of accidental privilege removal.

How to eliminate wrong answers

Option B is wrong because `sed -i 's/^staff:.*/&jdoe/' /etc/group` attempts to edit the group file directly but incorrectly appends 'jdoe' to the end of the line without a comma separator, resulting in a malformed entry (e.g., 'staff:x:100:jdoe' instead of 'staff:x:100:jdoe'), and it only modifies the 'staff' group, ignoring 'admin'. Option C is wrong because `usermod -G staff,admin jdoe` without the `-a` flag will replace all of jdoe's current supplementary groups with only 'staff' and 'admin', removing any other group memberships. Option D is wrong because `useradd -G staff,admin jdoe` is used to create a new user and set initial supplementary groups; it will fail or produce an error since the user 'jdoe' already exists, and it does not modify existing users.

38
MCQeasy

To enable disk quotas for user quotas on a filesystem, which line should be added to /etc/fstab's mount options?

A.grpquota
B.userquota
C.quota
D.usrquota
AnswerD

usrquota in the mount options column activates per-user quota accounting and enforcement on that filesystem when it is mounted. grpquota covers groups instead, so usrquota is the entry needed, after which quotacheck initialises the quota files.

Why this answer

The 'usrquota' mount option is the standard Linux kernel parameter used to enable user disk quotas on a filesystem. When added to the fourth field of an /etc/fstab entry, it instructs the kernel to track per-user disk usage, allowing the quota system (via quotacheck, edquota, etc.) to enforce limits.

Exam trap

The trap here is that candidates confuse 'usrquota' with the generic term 'quota' or the incorrect 'userquota', assuming any word containing 'quota' will work, but the Linux kernel strictly requires the exact 'usrquota' string for user quotas.

How to eliminate wrong answers

Option A is wrong because 'grpquota' is the mount option for enabling group quotas, not user quotas. Option B is wrong because 'userquota' is not a valid Linux mount option; the correct syntax uses 'usrquota' for users and 'grpquota' for groups. Option C is wrong because 'quota' alone is not a valid mount option in /etc/fstab; the kernel requires the specific 'usrquota' or 'grpquota' strings to activate quota tracking.

39
Multi-Selecthard

Which three commands are commonly used to display information about running processes?

Select 3 answers
A.top
B.pkill
C.kill
D.htop
E.ps
AnswersA, D, E

top reads process information from /proc and refreshes it periodically, showing running processes with CPU and memory usage. This satisfies the requirement to display information about running processes, providing a live, interactive view of the process table.

Why this answer

top (A) is correct because it launches an interactive, real-time view of running processes, showing CPU, memory, and load statistics refreshed continuously. htop (D) is correct because it is an enhanced interactive process viewer that displays running processes with colorized, scrollable output and additional metrics like per-core CPU usage. ps (E) is correct because it snapshots the current processes and their details (PID, TTY, time, command), commonly used with options such as aux or -ef. pkill (B) is not a display tool but sends signals to processes by name to terminate them, and kill (C) likewise sends signals to specific PIDs rather than showing process information.

Exam trap

The trap here is that candidates may confuse commands that manipulate processes (like `kill` and `pkill`) with commands that display process information, leading them to incorrectly select those options.

40
MCQmedium

A system administrator suspects that a particular service is failing to start at boot. The service is managed by systemd. Which command will show the current status of the service, including whether it is active, and recent log entries?

A.journalctl -u servicename.service
B.systemctl list-units --type=service
C.systemctl show servicename.service
D.systemctl status servicename.service
AnswerD

systemctl status displays the current state of the service, whether it is active or failed, and includes recent log lines from the journal. It provides a quick overview of the service's health and recent activity. This is the standard command to diagnose service issues on systemd-based systems.

Why this answer

The correct command is systemctl status servicename.service. It provides a concise status summary, including whether the service is active, its main PID, and recent log entries. The other commands either show only properties, only logs, or a list of all services, lacking the combined status and log view needed for quick diagnosis.

Exam trap

The trap here is confusing systemctl status with journalctl -u; while journalctl shows logs, it does not show the current active state, which is crucial for a quick status check.

41
MCQhard

An administrator needs to display the current and previous runlevels of a Linux system. Which command provides this information?

A.who -r
B.runlevel
C.telinit 1
D.init 0
AnswerB

runlevel reads /var/run/utmp and prints the previous and current SysV runlevels, matching the requirement to show both. It reports N when no previous level exists, and works only where the legacy runlevel records are maintained.

Why this answer

The `runlevel` command displays both the previous and current runlevels of a Linux system. It outputs two characters: the first indicates the previous runlevel (or 'N' if the runlevel has not changed since boot), and the second indicates the current runlevel. This is the standard tool for querying runlevel information on SysV init systems.

Exam trap

The trap here is that candidates confuse `who -r` with `runlevel` because both display the current runlevel, but `who -r` omits the previous runlevel, which is the key piece of information the question explicitly asks for.

How to eliminate wrong answers

Option A is wrong because `who -r` shows the current runlevel and the time of the last runlevel change, but it does not display the previous runlevel. Option C is wrong because `telinit 1` is used to change the runlevel to single-user mode (runlevel 1), not to display current or previous runlevels. Option D is wrong because `init 0` is used to shut down the system (runlevel 0), not to query runlevel information.

42
MCQeasy

Refer to the exhibit. What is the current state of the SSH service?

A.It is active and running
B.It is inactive
C.It is disabled
D.It has failed
AnswerA

The `systemctl status ssh` output shows "Active: active (running)", confirming the daemon is operational and listening. This satisfies the stem's requirement to identify the service's current state, as opposed to inactive, failed, or masked. The main PID and uptime further corroborate that the SSH service is actively serving connections.

Why this answer

The exhibit shows the output of `systemctl status sshd`, which displays the service state as 'active (running)' in the green text. This indicates that the SSH daemon (sshd) is currently loaded and executing, providing secure shell access to the system. The 'active (running)' state is the normal operational state for a service that has been started and is functioning correctly.

Exam trap

LPI often tests the distinction between a service's current runtime state (active/inactive) and its boot-time enablement (enabled/disabled), causing candidates to confuse 'disabled' with 'inactive' when the question explicitly asks for the current state.

How to eliminate wrong answers

Option B is wrong because 'inactive' would show as 'inactive (dead)' in the systemctl status output, meaning the service is not currently running, but the exhibit clearly shows 'active (running)'. Option C is wrong because 'disabled' refers to the service's startup configuration (whether it starts automatically at boot), not its current runtime state; the exhibit shows the service is enabled for startup, but the question asks about the current state. Option D is wrong because 'failed' would display as 'failed' with a red indicator, indicating the service exited with an error or crashed, which is not shown in the exhibit.

43
MCQhard

Refer to the exhibit. The job runs every hour but the administrator notices that it does not execute on Sundays. Which cron syntax element is responsible?

A.The minute field
B.The hour field
C.The month field
D.The day-of-week field
AnswerD

The day-of-week field restricts execution to specific weekdays, so a value excluding Sunday prevents the hourly job from running that day. Since the stem states the job runs hourly but skips Sundays, this field is the only cron element that can suppress execution on a single weekday while leaving other days unaffected.

Why this answer

The day-of-week field (the 5th field in a cron expression) controls which days of the week the job runs. If this field is set to 1-6 (Monday–Saturday) or explicitly excludes 0/7 (Sunday), the job will not execute on Sundays. Since the job runs every hour but not on Sundays, the day-of-week field is responsible.

Exam trap

The trap here is that candidates often confuse the day-of-month field (3rd field) with the day-of-week field (5th field), or assume the hour field controls daily execution, when in fact the day-of-week field is the only one that can selectively exclude a specific weekday like Sunday.

How to eliminate wrong answers

Option A is wrong because the minute field (1st field) controls the minute within the hour when the job runs, not the day of the week; it would affect timing within each hour, not skip entire days. Option B is wrong because the hour field (2nd field) controls which hours of the day the job runs, not which days of the week; it could restrict execution to certain hours but cannot exclude an entire day like Sunday. Option C is wrong because the month field (4th field) controls which months the job runs, not days of the week; it could skip entire months but not specific weekdays.

44
Multi-Selectmedium

Which three actions can an administrator take to securely erase data on a disk before decommissioning?

Select 3 answers
A.Format the disk with mkfs.
B.Delete the partition and create a new one.
C.Run dd if=/dev/urandom of=/dev/sda.
D.Run shred -n 3 /dev/sda.
E.Use the hdparm command with the --security-erase option.
AnswersC, D, E

Writing pseudorandom bytes from /dev/urandom across the whole block device overwrites every sector, including filesystem metadata, making prior data unrecoverable. This satisfies the secure erasure requirement by destroying the original contents rather than merely unlinking files.

Why this answer

Option C is correct because writing random data from /dev/urandom over the entire raw device /dev/sda with dd overwrites every sector, making the original data unrecoverable. Option D is correct because shred -n 3 /dev/sda performs three passes of overwriting on the block device, which securely destroys the prior contents. Option E is correct because hdparm --security-erase invokes the drive's ATA Secure Erase firmware command, which securely erases all sectors including remapped ones.

Option A is not correct because mkfs only creates a new filesystem and leaves the underlying data blocks intact and recoverable. Option B is not correct because deleting and recreating a partition only modifies the partition table and does not overwrite the data stored on the disk.

Exam trap

The trap here is that candidates often think `mkfs` or partition deletion fully erases data, when in fact they only remove logical pointers, leaving the raw data recoverable with simple forensic tools.

45
MCQeasy

Which command is used to view the last few lines of a log file and simultaneously follow new entries as they are written?

A.tail -f
B.cat
C.head -n 10
D.less
AnswerA

tail -f keeps the file descriptor open and prints appended lines as they are written, after showing the final lines by default. Other tools such as cat or less do not continuously follow growth, so tail -f satisfies both the initial view and live monitoring requirement.

Why this answer

The `tail -f` command is correct because it displays the last 10 lines of a file by default and then continues to monitor the file for new lines, outputting them as they are appended. This is essential for real-time log monitoring, as it uses inotify or polling to detect file changes without requiring manual re-reading.

Exam trap

The trap here is that candidates may confuse `tail -f` with `less` (which can also follow with `Shift+F`), but the question explicitly asks for the command that 'simultaneously follow new entries as they are written' in its default invocation, making `tail -f` the only correct answer without requiring additional key presses.

How to eliminate wrong answers

Option B (cat) is wrong because it outputs the entire file content at once and then exits, providing no ability to follow new entries. Option C (head -n 10) is wrong because it only shows the first 10 lines of a file and does not monitor for updates. Option D (less) is wrong because while it can view files interactively and with `Shift+F` can follow new entries, the default behavior does not follow; the question specifies 'simultaneously follow new entries as they are written,' which `tail -f` does directly without requiring a special key sequence.

46
MCQeasy

Refer to the exhibit. This line is from /etc/passwd. What does the third field (1001) represent?

A.Home directory UID
B.Group ID (GID)
C.User ID (UID)
D.Login shell number
AnswerC

The third colon-separated field in /etc/passwd holds the numeric user identifier assigned to the account. It is the UID the kernel uses internally for ownership and permission checks, distinct from the username in field one and the GID in field four.

Why this answer

In the /etc/passwd file, the third field is the User ID (UID), a numeric identifier assigned to each user. UID 0 is reserved for root, and values below 1000 are typically system accounts, while 1001 is a regular user UID. This field is used by the kernel to track user ownership of processes and files.

Exam trap

The trap here is that candidates often confuse the order of fields in /etc/passwd, specifically mixing up the UID (third field) with the GID (fourth field), because both are numeric identifiers.

How to eliminate wrong answers

Option A is wrong because the home directory is specified in the sixth field of /etc/passwd, not the third. Option B is wrong because the Group ID (GID) is the fourth field, not the third. Option D is wrong because the login shell is the seventh field, and there is no 'login shell number' field in /etc/passwd.

47
MCQhard

Refer to the exhibit. What is the purpose of the 'test -x /usr/sbin/anacron' command in the cron entries?

A.It checks if anacron is executable and then runs the periodic tasks.
B.It starts anacron if it is not already running.
C.It ensures the periodic tasks are not run if anacron is installed.
D.It logs the output of the periodic tasks to a file.
AnswerC

The `test -x /usr/sbin/anacron` check returns true when the anacron binary exists and is executable, so the following `||` branch runs cron.daily, cron.weekly and cron.hourly only on systems lacking anacron. This prevents duplicate execution of periodic jobs where anacron already schedules them, satisfying the stem's condition of suppressing cron runs when anacron is present.

Why this answer

The 'test -x /usr/sbin/anacron' command checks if the anacron binary exists and is executable. If it is, the test returns true (exit code 0), and the subsequent periodic tasks (e.g., run-parts) are skipped due to the logical NOT operator '!' at the beginning of the cron entry. This prevents duplicate execution of periodic jobs when both cron and anacron are installed, as anacron is designed to handle them for systems that may not be running continuously.

Exam trap

The trap here is that candidates assume 'test -x' runs or starts anacron, when in fact it is a conditional check used with '!' to suppress duplicate job execution.

How to eliminate wrong answers

Option A is wrong because 'test -x' only checks for executability; it does not execute anacron or run any tasks. Option B is wrong because the command does not start anacron; it merely tests its presence, and the cron entry uses '!' to skip tasks if anacron is present, not to launch it. Option D is wrong because the command does not involve logging; it is a simple file test, and any logging would be handled by separate redirection or the cron daemon itself.

48
MCQhard

A medium-sized company runs a web application on a Linux server. The server uses systemd and has the following configuration: the web application service (webapp.service) is configured to start after network.target and requires a database service (database.service) to be running. The database service has a Restart=on-failure directive. Recently, the server experienced a power outage. Upon reboot, the system administrator notices that the web application fails to start because the database service is in a failed state. The administrator checks the status of database.service and sees 'inactive (dead)' with no recent attempts to restart. The journal shows that the database service failed to start because a required filesystem (mounted at /var/lib/database) was not mounted when the database service tried to start. The filesystem is listed in /etc/fstab with the nofail option. The administrator wants to ensure that in future reboots, the database service starts successfully and the web application comes up without manual intervention. Which of the following is the best course of action?

A.Change the Restart directive in database.service to 'always'
B.Remove the nofail option from /etc/fstab for /var/lib/database
C.Modify the database.service unit file to add 'After=var-lib-database.mount' and 'Requires=var-lib-database.mount'
D.Modify the webapp.service unit file to add 'After=database.service' and 'Requires=database.service'
AnswerC

Because /var/lib/database is mounted with nofail, boot proceeds without it, so database.service starts before the mount exists and fails. Adding After= and Requires=var-lib-database.mount creates an ordering and dependency link, forcing systemd to mount the filesystem first.

Why this answer

The database service failed due to a missing mount at /var/lib/database. By adding 'After=var-lib-database.mount' and 'Requires=var-lib-database.mount' to the database.service unit, systemd will ensure the mount unit is started before the database service and that the database service is stopped if the mount fails. This directly addresses the root cause—the filesystem not being ready—without altering the restart behavior or the fstab nofail option, which is appropriate for allowing the system to boot even if the mount fails.

Exam trap

The trap here is that candidates often focus on restart policies (Option A) or fstab options (Option B) without realizing that systemd's dependency system must be used to enforce ordering between services and mount units, especially when nofail is present.

How to eliminate wrong answers

Option A is wrong because changing Restart to 'always' would cause the database service to restart indefinitely even after successful runs, but it does not solve the underlying issue of the mount not being ready; the service would still fail on the first attempt if the mount is missing, and Restart=on-failure already handles restarts after failure, but the service never got a chance to restart because it was never started again after the initial failure. Option B is wrong because removing the nofail option from /etc/fstab would cause the system to fail to boot entirely if the filesystem cannot be mounted, which is worse than the current behavior; the nofail option is correctly used to allow boot to proceed, but the dependency must be expressed in systemd units. Option D is wrong because webapp.service already has 'After=database.service' and 'Requires=database.service' (implied by the requirement that the database service must be running), so adding them again does nothing; the problem is that database.service itself fails due to the mount, not that webapp.service lacks ordering or dependency on database.service.

49
Multi-Selectmedium

A Linux administrator needs to configure a new system to automatically mount an NFS share at boot. The share is exported from server 'nfs.example.com' as '/export/data'. The mount point '/mnt/data' already exists. Which TWO actions are required to ensure the share is mounted automatically and persistently? (Choose two.)

Select 2 answers
A.Install the NFS client utilities (e.g., nfs-common or nfs-utils).
B.Run 'mount -a' to mount all entries in /etc/fstab.
C.Ensure the 'nfs' service is running on the client.
D.Add the NFS share to /etc/exports.
E.Add an entry to /etc/fstab with the NFS share and mount point.
AnswersA, E

To mount an NFS share, the client system needs the appropriate NFS client utilities installed, such as nfs-common on Debian-based systems or nfs-utils on Red Hat-based systems. These packages provide the mount.nfs helper and other tools needed to mount NFS filesystems. Without them, the mount command will fail.

Why this answer

To automatically mount an NFS share at boot, you must add an entry to /etc/fstab and ensure the NFS client utilities are installed. The fstab entry defines the mount, and the utilities provide the necessary mount.nfs helper. Other actions like running mount -a are for immediate mounting, modifying /etc/exports is for servers, and running the nfs service is not required on the client.

Exam trap

The trap here is confusing client and server roles, or thinking that the nfs service must run on the client; actually, only the client utilities are needed.

50
MCQeasy

A small business uses a Linux server running CUPS to share a network printer. For several months, all employees could print successfully. Today, an employee in a different subnet reports that printing does not work. The administrator checks the server: cupsd is running, the printer is configured with an IPP URI pointing to the printer's IP address, and the printer is idle. The administrator can ping the printer from the server. The administrator checks the CUPS error log and sees the following line multiple times: 'E [04/Oct/2024:10:15:22 -0400] [Client 5] client-error-not-authorized'. Which of the following actions should the administrator take to resolve the issue?

A.Change the printer's URI from ipp:// to socket://
B.Add the employee's username to the lpadmin group
C.Restart the cupsd service with 'systemctl restart cupsd'
D.Add 'Allow from 192.168.2.0/24' to the appropriate policy in /etc/cups/cupsd.conf
AnswerD

The error 'client-error-not-authorized' shows CUPS is rejecting the client's IP via its access control policy. Since the employee sits in a different subnet, adding an Allow directive for 192.168.2.0/24 to the relevant Location or policy block in cupsd.conf restores authorisation.

Why this answer

The error 'client-error-not-authorized' in CUPS indicates that the client's request was denied due to access control restrictions in cupsd.conf. Since the employee is in a different subnet (e.g., 192.168.2.0/24), the default CUPS policy likely only allows local subnet access. Adding 'Allow from 192.168.2.0/24' to the appropriate policy (e.g., under <Policy default>) grants printing access from that subnet, resolving the authorization failure.

Exam trap

The trap here is that candidates confuse 'client-error-not-authorized' with authentication issues (e.g., missing username/password) or service problems, when it is actually an IP-based access control restriction in CUPS' policy configuration.

How to eliminate wrong answers

Option A is wrong because changing the URI from ipp:// to socket:// would bypass CUPS' job management and authentication, but the error is about authorization, not protocol mismatch; the printer is reachable via ping, so the URI is not the issue. Option B is wrong because the lpadmin group is for printer administration (e.g., adding/removing printers), not for granting print access to users; the error is a client authorization failure, not a group membership issue. Option C is wrong because restarting cupsd would not change the access control rules; the service is already running and the error persists, indicating a configuration problem, not a service state issue.

51
MCQhard

A small business runs a Linux server hosting a web application and a PostgreSQL database. The server uses LVM for storage, with a single volume group vg_data containing two logical volumes: lv_web (50GB) and lv_db (100GB). The root filesystem is on a separate disk. The administrator receives alerts that the database volume is at 95% capacity. The server has additional unused space from a recently added disk that was added to the volume group as an additional physical volume, but the space has not been allocated. The administrator runs 'vgs' which shows VG vg_data with total size 500GB, allocated 150GB, and free 350GB. The administrator wants to increase the size of lv_db by 50GB. Which course of action should the administrator take?

A.Run 'lvresize -L 50G /dev/vg_data/lv_db' and then 'xfs_growfs /mount/point'.
B.Run 'lvcreate -L 50G -n lv_backup vg_data' and mount it.
C.Run 'lvextend -L +50G /dev/vg_data/lv_db' and then 'resize2fs /dev/vg_data/lv_db' (if filesystem is ext4).
D.Run 'vgextend vg_data /dev/sdb1' and then 'lvextend -L 50G /dev/vg_data/lv_db'.
AnswerC

lvextend -L +50G grows lv_db using the volume group's 350GB free space, then resize2fs expands the ext4 filesystem to fill the new extents. Both steps are required because extending the logical volume alone leaves the filesystem unaware of the added capacity.

Why this answer

The administrator needs to extend the existing logical volume lv_db by 50GB using 'lvextend -L +50G /dev/vg_data/lv_db' (the '+' is critical for relative growth), and then if the filesystem is ext4, 'resize2fs /dev/vg_data/lv_db' resizes the filesystem to use the newly allocated space. The volume group already has 350GB free, so no new physical volume needs to be added.

Exam trap

The trap here is that candidates often forget the '+' sign in 'lvextend -L +50G' (which means add 50GB) versus '-L 50G' (which sets absolute size to 50GB), and they may also incorrectly assume a new physical volume must be added even when free space already exists in the volume group.

How to eliminate wrong answers

Option A is wrong because 'lvresize -L 50G' sets the absolute size to 50GB, which would shrink the volume from its current size (likely 100GB) to 50GB, causing data loss; also, xfs_growfs is only for XFS filesystems, not ext4. Option B is wrong because creating a new logical volume (lv_backup) does not increase the size of lv_db; it only adds a separate volume, leaving the database volume still at 95% capacity. Option D is wrong because 'vgextend' is unnecessary—the volume group already has 350GB free space—and 'lvextend -L 50G' without the '+' sign would set the absolute size to 50GB, potentially shrinking the volume.

52
Multi-Selectmedium

An administrator needs to restart the SSH service after a configuration change. Which TWO commands can accomplish this on a systemd-based system?

Select 2 answers
A.initctl restart sshd
B.rc.d restart sshd
C.systemctl restart sshd
D.service sshd restart
E./etc/init.d/sshd restart
AnswersC, D

`systemctl restart sshd` stops and starts the SSH daemon in one operation, applying the edited configuration immediately. It satisfies the systemd-based constraint by communicating directly with the service manager, which tracks the unit and its dependencies. Unlike `systemctl reload`, it fully terminates existing sessions, guaranteeing the new configuration is read.

Why this answer

Option C, systemctl restart sshd, is correct because systemctl is the native control utility for systemd, and 'restart' stops and starts the sshd unit in one operation, applying the new configuration. Option D, service sshd restart, is also correct because the service wrapper script on systemd-based distributions translates the request into the appropriate systemctl restart sshd call, so it works on such systems. Option A, initctl restart sshd, belongs to Upstart and is not the systemd interface.

Option B, rc.d restart sshd, is not a valid command form for the BSD-style rc.d mechanism. Option E, /etc/init.d/sshd restart, invokes a legacy SysV init script directly, which may exist for compatibility but is not the systemd method and is not guaranteed to be present or functional.

Exam trap

Candidates may incorrectly assume that only `systemctl` works on systemd, but the `service` command is also valid as a compatibility wrapper. Conversely, commands like `initctl` (Upstart) or `/etc/init.d/` script (SysV) are not correct for systemd.

53
MCQhard

In the /etc/shadow file, a user's password hash begins with '$6$'. What hash algorithm does this prefix indicate?

A.SHA-512
B.SHA-256
C.MD5
D.Blowfish
AnswerA

The `$6$` prefix in `/etc/shadow` specifies SHA-512, as defined by the crypt(3) scheme identifiers. This satisfies the stem's requirement to identify the algorithm from the hash prefix, distinguishing it from `$1$` (MD5), `$5$` (SHA-256) and `$2$` (bcrypt).

Why this answer

The prefix '$6$' in the /etc/shadow file indicates that the password hash was generated using the SHA-512 (Secure Hash Algorithm 512-bit) algorithm. This is defined in the crypt(3) function's modular crypt format, where $1$ is MD5, $5$ is SHA-256, and $6$ is SHA-512. SHA-512 is the strongest of the commonly used hash algorithms in Linux password hashing, providing a 512-bit digest.

Exam trap

The trap here is that candidates often confuse the prefix '$6$' with SHA-256 (which uses '$5$') or mistakenly associate '$6$' with Blowfish due to similar numbering, but the correct mapping is $1$=MD5, $5$=SHA-256, $6$=SHA-512.

How to eliminate wrong answers

Option B (SHA-256) is wrong because SHA-256 uses the prefix '$5$', not '$6$'. Option C (MD5) is wrong because MD5 uses the prefix '$1$', and it is considered cryptographically broken for password storage. Option D (Blowfish) is wrong because Blowfish-based bcrypt uses the prefix '$2a$', '$2b$', or '$2y$', not '$6$'.

54
MCQmedium

A junior administrator needs to add a new user account named 'tester' to a Linux server. The account must have a home directory created at /home/tester, and the default shell should be set to /bin/bash. The administrator runs 'useradd tester' but later finds that no home directory was created and the shell is /bin/sh. Which command should have been used to meet both requirements?

A.usermod -m -s /bin/bash tester
B.useradd -d /home/tester -s /bin/bash tester
C.adduser tester --home /home/tester --shell /bin/bash
D.useradd -m -s /bin/bash tester
AnswerD

The -m option instructs useradd to create the user's home directory if it does not exist, and -s /bin/bash sets the login shell to bash. This directly fulfills both requirements in a single command. Without -m, no home directory is created; without -s, the system default shell (often /bin/sh) is used. This is the correct and efficient solution.

Why this answer

The correct command is useradd -m -s /bin/bash tester. The -m flag ensures the home directory is created, and -s specifies the login shell. Other options either fail to create the home directory, use non-standard syntax, or attempt to modify a non-existent user.

This single command meets both stated requirements.

Exam trap

The trap here is assuming that useradd automatically creates a home directory; by default, it does not unless the -m option is given or the CREATE_HOME variable is set in /etc/login.defs.

55
MCQeasy

Which command adds a new group named 'developers' to the system?

A.addgroup developers
B.groupadd developers
C.newgroup developers
D.groupadd -r developers
AnswerB

groupadd creates a new group entry in /etc/group with the specified name, so 'groupadd developers' adds the developers group. It does not assign users or set passwords, which require separate commands such as usermod or gpasswd.

Why this answer

The correct command to add a new group on a Linux system is `groupadd developers`. This command creates a new group entry in the system's group database (typically /etc/group). The `groupadd` utility is the standard tool for this task in Linux, and it is part of the shadow-utils package.

Exam trap

The trap here is that candidates may confuse `groupadd` with distribution-specific wrappers like `addgroup` (Debian/Ubuntu) or think that `newgroup` is a valid command, or they may overlook the significance of the `-r` flag which creates a system group instead of a regular group.

How to eliminate wrong answers

Option A is wrong because `addgroup` is not a standard Linux command; it is a Debian/Ubuntu-specific wrapper that may not exist on all distributions, and the standard command is `groupadd`. Option C is wrong because `newgroup` is not a valid Linux command; the correct command is `groupadd`. Option D is wrong because `groupadd -r developers` creates a system group (with a GID in the system range, typically below 1000), not a regular group named 'developers' as required by the question.

56
MCQmedium

An administrator needs to extend a logical volume by 10GB. The volume group has available physical extents. Which command should be used?

A.lvcreate -L 10G /dev/vg/lv
B.vgextend /dev/vg/lv -L +10G
C.lvextend -L +10G /dev/vg/lv
D.lvresize -L 10G /dev/vg/lv
AnswerC

`lvextend -L +10G /dev/vg/lv` grows the logical volume by exactly 10GB using free physical extents already present in the volume group, satisfying the stem's constraint that no additional physical volumes are required. The `+` prefix adds to the current size rather than setting an absolute value, and `-L` specifies size in gigabytes.

Why this answer

The `lvextend` command with the `-L +10G` flag increases the size of the existing logical volume `/dev/vg/lv` by exactly 10 GB, using available physical extents from the volume group. This is the standard LVM command for extending a logical volume without recreating it.

Exam trap

The trap here is that candidates confuse `lvcreate` with `lvextend` or forget the `+` sign in `lvresize`, leading them to choose an option that either creates a new volume or sets an absolute size instead of incrementing it.

How to eliminate wrong answers

Option A is wrong because `lvcreate` creates a new logical volume, not extends an existing one; using it would attempt to create a separate 10 GB LV, not modify the target LV. Option B is wrong because `vgextend` is used to add a physical volume to a volume group, not to extend a logical volume; the syntax and purpose are entirely mismatched. Option D is wrong because `lvresize -L 10G` sets the absolute size of the logical volume to exactly 10 GB, which would shrink it if it were larger than 10 GB, rather than adding 10 GB; the `+` sign is required for an extension operation.

Ready to test yourself?

Try a timed practice session using only Admin Tasks questions.