Courseiva

CCNA Devices Filesystems Questions

69 questions · Devices Filesystems topic · All types, answers revealed

1
MCQhard

Refer to the exhibit. A user tries to execute a script on a mounted filesystem but gets a permission denied error. The script has execute permissions. What is the most likely cause?

A.The script is not executable for the user.
B.The user does not have read permission on the script.
C.The filesystem is mounted with the 'noexec' option.
D.The filesystem is full.
AnswerC

The `noexec` mount option instructs the kernel to refuse execution of any binary or script residing on that filesystem, regardless of the file's own execute permission bits. Since the script already has execute permissions, the mount-level restriction is the only remaining cause of the permission denied error.

Why this answer

The 'noexec' mount option prevents execution of any binary or script on the filesystem, regardless of file permissions. Even if the script has execute permissions set, the kernel will refuse to execute it when the filesystem is mounted with 'noexec'. This is a common security measure on filesystems like /tmp or /home to prevent unauthorized code execution.

Exam trap

The trap here is that candidates often assume 'permission denied' always means incorrect file permissions, but the LPIC-1 exam tests the understanding that mount options like 'noexec' can override file-level permissions and cause execution failures.

How to eliminate wrong answers

Option A is wrong because the question explicitly states that the script has execute permissions, so the script is executable for the user. Option B is wrong because read permission is not required to execute a script; execute permission alone is sufficient for execution (though the interpreter needs read access to the script file). Option D is wrong because a full filesystem would cause write failures, not a 'permission denied' error when trying to execute a script.

2
MCQhard

Refer to the exhibit. An admin attempts to execute a shell script located in /tmp but gets 'Permission denied'. Which mount option is most likely causing this?

A.relatime
B.noexec
C.nodev
D.nosuid
AnswerB

The `noexec` mount option prevents execution of any binaries or scripts on that filesystem, directly causing the "Permission denied" error when running the script from /tmp. Since /tmp is frequently mounted with `noexec` for security hardening, this constraint matches the symptom precisely, whereas other options would produce different errors.

Why this answer

The 'noexec' mount option prevents execution of any binary or script directly from the filesystem, regardless of file permissions. Since the script is in /tmp and the admin gets 'Permission denied' despite correct execute bits, the /tmp partition is likely mounted with noexec, which is a common security hardening practice.

Exam trap

The trap here is that candidates assume 'Permission denied' always means missing execute bits (chmod +x), when in fact the noexec mount option silently blocks execution even with correct permissions.

How to eliminate wrong answers

Option A (relatime) is wrong because it only controls how access timestamps are updated on the filesystem, not execution permissions. Option C (nodev) is wrong because it prevents block or character special devices from being interpreted, not script execution. Option D (nosuid) is wrong because it ignores setuid/setgid bits on executables, but does not block execution itself.

3
Multi-Selectmedium

Which THREE of the following commands can be used to display information about block devices?

Select 3 answers
A.lsblk
B.free
C.fdisk -l
D.blkid
E.ip link
AnswersA, C, D

`lsblk` reads the sysfs and udev databases to list all block devices, showing their names, major and minor numbers, sizes, types and mountpoints in a tree hierarchy. This directly satisfies the stem's requirement to display block device information, unlike commands that report only filesystem usage or partition tables.

Why this answer

lsblk (A) is correct because it reads /sys/block and udev data to list all block devices in a tree, showing names, sizes, types, mountpoints, and major:minor numbers. fdisk -l (C) is correct because it enumerates the partition tables of all detected block devices, printing disk geometry, sector sizes, and partition layouts. blkid (D) is correct because it queries block-device attributes such as UUID, LABEL, and filesystem TYPE from the blkid cache and device superblocks. free (B) is not a block-device tool; it reports RAM and swap usage from /proc/meminfo. ip link (E) is a networking command that lists and manages network interfaces at layer 2, not block devices.

Exam trap

The trap here is that candidates may confuse `free` (memory) or `ip link` (network) with block device commands, or forget that `fdisk -l` and `blkid` also display block device information, not just `lsblk`.

4
MCQmedium

An administrator is preparing a new USB drive for use as a portable ext4 data disk. After writing the partition table, the administrator wants to confirm the partition layout and the filesystem type currently on the device before formatting. Which command displays both the partition table and the detected filesystem types for /dev/sdd?

A.lsblk -f /dev/sdd
B.partprobe /dev/sdd
C.fdisk -l /dev/sdd
D.blkid /dev/sdd
AnswerA

lsblk reads from sysfs and udev to present block device topology. The -f option adds filesystem information including type, label, UUID, and mount point for each partition. Combined with the device argument, it shows the partition layout and detected filesystem types in one view, satisfying both requirements.

Why this answer

Verifying a device before formatting requires both the partition layout and any existing filesystem signatures. lsblk with the -f option merges block device topology from sysfs with filesystem metadata detected by libblkid, showing each partition's type, label, UUID, and mount point in a single tree view, which covers both needs at once.

Exam trap

The trap here is assuming fdisk -l reports filesystem types, when it only reports partition table entries and partition type codes.

5
MCQeasy

Refer to the exhibit. An administrator notices that /proc is mounted with 'noexec'. What is the impact of this mount option?

A.Device files are not interpreted.
B.Setuid programs do not work.
C.No binaries can be executed directly from /proc.
D.The filesystem cannot be written to.
AnswerC

The noexec mount option blocks direct execution of any binary stored on that filesystem, so running an executable file located under /proc fails with a permission error. This satisfies the stem's constraint: /proc is mounted noexec, therefore no binaries can be executed directly from it.

Why this answer

The 'noexec' mount option prevents the direct execution of any binary files located on the mounted filesystem. Since /proc is a virtual filesystem that contains runtime system information and process data, mounting it with 'noexec' means that no binaries can be executed directly from /proc. This is a security measure to prevent malicious code from being run from procfs, as /proc should never contain executable programs in normal operation.

Exam trap

The trap here is that candidates often confuse 'noexec' with 'nosuid' or 'nodev', thinking it affects setuid binaries or device files, when in fact 'noexec' strictly controls whether binary executables can be run directly from the filesystem.

How to eliminate wrong answers

Option A is wrong because device files are not interpreted by the 'noexec' option; device file handling is governed by the 'nodev' mount option, which prevents the interpretation of device files. Option B is wrong because setuid programs are affected by the 'nosuid' mount option, not 'noexec'; 'noexec' only prevents direct execution of binaries, while setuid behavior is controlled separately. Option D is wrong because the ability to write to a filesystem is controlled by the 'ro' (read-only) or 'rw' (read-write) mount options, not by 'noexec', which only affects execution permissions.

6
MCQeasy

Which directory in the Filesystem Hierarchy Standard (FHS) contains essential user command binaries that are needed in single-user mode?

A./tmp
B./sbin
C./bin
D./boot
AnswerC

/bin holds essential user command binaries required for single-user mode and system repair, such as ls, cp and sh. The FHS designates it specifically for commands needed before other filesystems are mounted, matching the stem's single-user-mode constraint.

Why this answer

The /bin directory contains essential user command binaries (e.g., ls, cp, mv) that are required for system booting and repair in single-user mode. According to the FHS, /bin is intended for commands needed by both the system administrator and users when no other filesystems are mounted, making it critical for single-user mode operations.

Exam trap

The trap here is that candidates confuse /sbin with /bin, assuming that system administration binaries are the essential ones for single-user mode, when in fact /bin provides the user-level commands needed for basic system interaction and recovery.

How to eliminate wrong answers

Option A is wrong because /tmp is a temporary directory for files that may be deleted on reboot, not for essential command binaries. Option B is wrong because /sbin contains system administration binaries (e.g., fdisk, init) intended for the root user, not essential user commands needed in single-user mode. Option D is wrong because /boot contains static boot loader files (e.g., kernel images, initramfs) and not user command binaries.

7
MCQhard

You are a system administrator at a hosting company. A customer reports that their website hosted on a shared LAMP server is returning error 500. The server runs Ubuntu 22.04 with Apache, MySQL, and PHP. You log in and find that the /var partition (on /dev/sda3, ext4) is almost full. You identify that the MySQL database directory /var/lib/mysql contains several large binary logs that are no longer needed. You delete the binary logs using 'rm -f /var/lib/mysql/mysql-bin.*'. However, the available space does not increase. You also notice that an inode leak is suspected. You check inode usage with 'df -i' and see that the partition has plenty of free inodes. You then check with 'lsof | grep deleted' and see several entries for mysqld holding deleted files. What is the correct procedure to free the space?

A.Restart the MySQL service with 'systemctl restart mysql'.
B.Use 'dpkg --purge mysql-server' to completely remove MySQL, then reinstall it.
C.Run 'e2fsck -f /dev/sda3' to reclaim inodes and fix filesystem inconsistencies.
D.Move the binary logs to a different partition using 'mv /var/lib/mysql/mysql-bin.* /tmp/' and then delete them.
AnswerA

mysqld still holds open descriptors to the unlinked binary logs, so the ext4 blocks remain allocated despite the rm. Restarting MySQL closes those handles, releasing the space; free inodes confirm the issue is held descriptors, not inode exhaustion.

Why this answer

When a file is deleted while a process (like mysqld) still holds an open file descriptor to it, the file's inode remains allocated and the disk space is not freed until the process releases the descriptor. Restarting the MySQL service (systemctl restart mysql) causes mysqld to close all open file descriptors, allowing the kernel to release the deleted binary logs' inodes and reclaim the disk space.

Exam trap

The trap here is that candidates assume deleting a file immediately frees disk space, overlooking that processes with open file descriptors prevent the kernel from releasing the inode and data blocks until the descriptor is closed.

How to eliminate wrong answers

Option B is wrong because completely purging and reinstalling MySQL is an unnecessarily destructive and time-consuming procedure; the issue is simply that the MySQL process holds open file descriptors to the deleted logs, not a problem with the MySQL installation itself. Option C is wrong because e2fsck checks and repairs filesystem metadata, but it does not force processes to release open file descriptors; the inodes are already marked as deleted but are still held open by mysqld, so e2fsck cannot reclaim them. Option D is wrong because moving the files to /tmp/ and then deleting them would still leave the MySQL process holding open file descriptors to the moved (and then deleted) files, resulting in the same space-not-freed problem; the core issue is the open file descriptor, not the file's location.

8
MCQmedium

A user complains that a filesystem is reporting 'Disk quota exceeded' even though the user has not stored any new files recently. What could be the cause?

A.Symlinks are counted against the quota
B.Hard links are consuming additional inodes
C.The user has exceeded the inode quota
D.File ownership is misconfigured
AnswerC

Disk quotas limit both blocks and inodes separately. A user can stay under the block quota yet exceed the inode quota by creating many small files or directories, so writes fail with 'Disk quota exceeded' despite no significant new data being stored.

Why this answer

Linux filesystems enforce two types of quotas: block quotas (for disk space) and inode quotas (for the number of files and directories). If the user has not stored new files recently but still receives a 'Disk quota exceeded' error, it is likely that they have exceeded their inode quota, meaning they have created too many files or directories (each consuming an inode), even if those files are small or empty. The error message is generic and can refer to either quota type, so the inode limit is the probable cause when no recent data writes have occurred.

Exam trap

The trap here is that candidates assume 'Disk quota exceeded' always refers to disk space (blocks), but LPIC-1 tests the distinction between block quotas and inode quotas, and that the same error message applies to both.

How to eliminate wrong answers

Option A is wrong because symlinks (symbolic links) are not counted against the quota of the user who owns the symlink; they are separate files that point to another file and do not consume the target's quota. Option B is wrong because hard links do not consume additional inodes; they are additional directory entries pointing to the same inode, so the inode count remains unchanged for the user. Option D is wrong because misconfigured file ownership would cause permission errors (e.g., 'Permission denied'), not a 'Disk quota exceeded' error, which is specifically a quota enforcement mechanism.

9
MCQhard

A system is running out of disk space on /var. The administrator finds that /var/log/syslog is 4GB. Which of the following is the best course of action to prevent future issues while keeping recent logs?

A.Use 'truncate -s 0 /var/log/syslog' to empty the file.
B.Configure logrotate to rotate and compress logs daily.
C.Configure syslog to stop logging.
D.Delete /var/log/syslog and create an empty file.
AnswerB

logrotate rotates /var/log/syslog on a daily schedule, compressing archived copies and enforcing retention limits, so recent logs remain readable while total size stays bounded. This directly satisfies the stem's constraint of preventing recurrence while preserving recent log data.

Why this answer

Logrotate is the standard Linux utility for managing log file growth. By configuring it to rotate and compress logs daily, the administrator can automatically archive old logs (e.g., /var/log/syslog.1.gz) and keep only recent entries in the active file, preventing disk space exhaustion without losing historical data.

Exam trap

The trap here is that candidates confuse immediate space recovery (truncation/deletion) with sustainable log management, overlooking that logrotate provides automated, policy-driven rotation and compression to prevent recurrence.

How to eliminate wrong answers

Option A is wrong because truncating the file to zero bytes only frees space immediately but does not prevent the file from growing again; it also discards all existing logs, which may violate compliance or troubleshooting needs. Option C is wrong because stopping syslog entirely would halt all system logging, losing critical diagnostic information and potentially violating security auditing requirements. Option D is wrong because deleting and recreating the file is functionally similar to truncation—it frees space now but offers no automated rotation or compression, so the problem will recur.

10
Multi-Selecthard

A Linux administrator needs to create a new ext4 filesystem on a logical volume /dev/vg0/lv_data and mount it persistently at /data. Which TWO of the following steps are required to accomplish this? (Choose two.)

Select 2 answers
A.Run pvcreate /dev/vg0/lv_data
B.Add an entry for /dev/vg0/lv_data in /etc/fstab
C.Run mkfs.ext4 /dev/vg0/lv_data
D.Run mount -a to mount all filesystems
E.Run vgcreate vg0 /dev/vg0/lv_data
AnswersB, C

To mount the filesystem persistently at /data, an entry must be added to /etc/fstab. This ensures the filesystem is mounted automatically at boot or with mount -a. The entry typically includes the device, mount point, filesystem type, and options. Without this, the mount would not persist across reboots.

Why this answer

To create and persistently mount a new ext4 filesystem on an existing logical volume, the administrator must first create the filesystem with mkfs.ext4, then add an entry to /etc/fstab to ensure it mounts at boot. Other commands like pvcreate, vgcreate, and mount -a are either incorrect or not strictly required for this task.

Exam trap

The trap here is confusing LVM creation steps with filesystem creation and persistent mounting, or thinking that mount -a is mandatory.

11
MCQmedium

A system administrator notices that the /tmp directory is filling up quickly, causing applications to fail. The administrator wants to ensure that files in /tmp are automatically cleaned after a certain period. Which of the following is the best approach without installing additional software?

A.Add a cron job that runs 'rm -rf /tmp/*' every hour.
B.Install tmpwatch and configure it to clean files older than 1 day.
C.Set the sticky bit on /tmp to automatically delete old files.
D.Configure the systemd-tmpfiles service with a configuration file to clean /tmp regularly.
AnswerD

Configuring systemd-tmpfiles uses the distribution's built-in age-based cleanup: a drop-in under /etc/tmpfiles.d/ with a `d /tmp 1777 root root 10d` line makes systemd-tmpfiles-clean.timer purge entries older than the specified age. This satisfies the no-additional-software constraint, since systemd already ships with the system.

Why this answer

Systemd-based Linux distributions include the systemd-tmpfiles service, which can be configured via files in /etc/tmpfiles.d/ to automatically clean temporary files based on age, size, or other criteria. This approach uses built-in systemd functionality without requiring additional software, and it is the recommended method for managing /tmp cleanup on modern systems.

Exam trap

The trap here is that candidates may confuse the sticky bit (which only prevents deletion by other users) with automatic cleanup, or assume that a brute-force cron job is acceptable, while the correct answer leverages a built-in systemd service that is already present on most modern Linux distributions.

How to eliminate wrong answers

Option A is wrong because using 'rm -rf /tmp/*' in a cron job is dangerous and unreliable: it will delete all files regardless of age, may fail on hidden files or subdirectories with special characters, and can cause race conditions or data loss for running applications. Option B is wrong because tmpwatch is not installed by default on most modern distributions and the question explicitly states 'without installing additional software'. Option C is wrong because the sticky bit (chmod +t) only prevents users from deleting files they do not own; it does not automatically delete old files.

12
MCQmedium

A Linux administrator needs to create an ext4 filesystem on the second partition of the third SCSI disk, /dev/sdc2. After running mkfs.ext4 /dev/sdc2, the command completes successfully. Which additional step is required before the filesystem can be mounted and used?

A.Create a mount point and mount the filesystem.
B.Run e2fsck /dev/sdc2 to initialize the journal.
C.Add an entry to /etc/fstab to make the filesystem usable immediately.
D.Run partprobe /dev/sdc to update the kernel partition table.
AnswerA

After mkfs.ext4 successfully creates the filesystem, it must be mounted to a directory (mount point) to be accessible. The administrator should create a directory such as /mnt/data and then run mount /dev/sdc2 /mnt/data. Without mounting, the filesystem is not part of the directory tree and cannot be used.

Why this answer

Creating a filesystem with mkfs.ext4 only writes the filesystem metadata and structures onto the partition. To access the filesystem, it must be mounted to a directory in the existing directory tree. The administrator must create a mount point and use the mount command.

Without mounting, the filesystem remains inaccessible to users and applications.

Exam trap

The trap here is assuming that creating a filesystem automatically makes it available, or that editing /etc/fstab mounts it immediately.

13
MCQmedium

Refer to the exhibit. The system administrator notices the /var/log partition is nearly full. The syslog file is 2GB. Which command will safely reduce the size of this log file without stopping the logging daemon?

A.cp /dev/null /var/log/syslog
B.rm /var/log/syslog && touch /var/log/syslog
C.> /var/log/syslog
D.mv /var/log/syslog /var/log/syslog.old
AnswerC

The shell redirection operator truncates the file to zero bytes in place, preserving the inode and open file descriptor, so syslogd continues writing without restart. That satisfies the stem's requirement to reduce the 2 GB file safely without stopping the logging daemon.

Why this answer

Using the shell redirection operator `> /var/log/syslog` truncates the file to zero length without deleting or closing its file descriptor. The syslog daemon (rsyslogd or syslogd) continues writing to the same inode, so no service interruption occurs. This is the safest method to free disk space while maintaining continuous logging.

Exam trap

The trap here is that candidates confuse truncating a file with deleting or moving it, not realizing that the logging daemon holds an open file descriptor tied to the inode, so only in-place truncation preserves continuous logging without a restart.

How to eliminate wrong answers

Option A is wrong because `cp /dev/null /var/log/syslog` replaces the file with a new inode, which causes the logging daemon to lose its file handle and stop writing until restarted or signaled. Option B is wrong because `rm` followed by `touch` also creates a new inode, breaking the daemon's open file descriptor and requiring a restart or SIGHUP to resume logging. Option D is wrong because `mv` renames the file, but the daemon still holds the old inode; the renamed file remains open and continues to grow, so disk space is not freed until the daemon is restarted or the old file is deleted.

14
MCQmedium

Which directory under the root filesystem is defined by FHS as containing variable data that may change in size, such as logs and spools?

A./opt
B./var
C./run
D./tmp
AnswerB

/var holds variable data such as logs, spools and mail queues, which grow unpredictably at runtime. FHS reserves it precisely for files whose size changes during normal operation, unlike /usr for static, shareable content. This satisfies the stem's requirement for variable data that may change in size.

Why this answer

The Filesystem Hierarchy Standard (FHS) defines /var as the directory for variable data that changes in size during normal system operation, including log files (e.g., /var/log), spool directories (e.g., /var/spool/mail), and temporary files that persist across reboots. This is distinct from /tmp, which is cleared on reboot, and /run, which holds runtime variable data that is volatile and cleared at boot.

Exam trap

The trap here is that candidates confuse /var with /run or /tmp because both hold variable data, but the FHS specifically assigns persistent variable data (logs, spools) to /var, while /run is for volatile runtime state and /tmp for temporary files that may be cleared on reboot.

How to eliminate wrong answers

Option A is wrong because /opt is reserved for the installation of add-on application software packages, not for variable data like logs or spools. Option C is wrong because /run contains runtime variable data (e.g., PID files, sockets) that is cleared at system boot, whereas /var retains data across reboots. Option D is wrong because /tmp is for temporary files that may be deleted on reboot and is not intended for persistent variable data like logs or spools.

15
MCQeasy

A technician is preparing a USB stick that must be readable by both Linux and Windows systems without installing extra drivers. Which filesystem should be created on the stick?

A.ext4
B.XFS
C.Btrfs
D.exFAT
AnswerD

exFAT is supported natively by Windows and by modern Linux kernels through the exfat driver, and it has no 4 GB per-file limit like FAT32. It stores no Unix permissions, which is acceptable for a portable data stick. This makes it the practical choice when a device must move between Linux and Windows without installing additional software on either side.

Why this answer

A USB stick shared between Linux and Windows needs a filesystem both operating systems understand out of the box. exFAT satisfies this: Windows supports it natively, current Linux kernels include an exFAT driver, and unlike FAT32 it does not impose a 4 GB file size ceiling. The Linux-native filesystems ext4, XFS, and Btrfs all require extra software on Windows, so they fail the cross-platform condition.

Exam trap

The trap here is reaching for a feature-rich Linux filesystem like ext4 or Btrfs when portability to Windows, not advanced features, is the actual requirement.

16
MCQmedium

An administrator runs `mount /dev/sdc1 /mnt/data` and receives the error "mount: /mnt/data: unknown filesystem type 'ntfs'." The partition contains an NTFS volume that must be mounted read-write on a Linux server. Which action resolves the issue?

A.Mount with the -o loop option to force filesystem detection
B.Install the ntfs-3g package and mount with -t ntfs-3g
C.Run mkfs.ntfs on /dev/sdc1 to initialize NTFS support
D.Add the ntfs module to /etc/modules and reboot
AnswerB

The error indicates the kernel has no in-kernel driver registered for the ntfs type. The ntfs-3g package provides a FUSE-based userspace driver that supports reliable read-write access, and mounting explicitly with -t ntfs-3g selects it. This directly supplies the missing filesystem support and satisfies the read-write requirement without altering the volume.

Why this answer

The unknown filesystem type message means no driver is registered for NTFS. Modern Linux systems rely on the userspace ntfs-3g driver from the package of the same name for dependable read-write access; installing it and mounting with -t ntfs-3g supplies that support. Reformatting destroys data, loading a limited legacy module does not grant write access, and loop mounting is irrelevant to a real partition.

Exam trap

The trap here is assuming the legacy in-kernel ntfs module is sufficient, when it offers at best limited read support and not the reliable read-write access the scenario demands.

17
MCQhard

A server has an LVM logical volume mounted at /data. The administrator needs to add a new physical disk to the volume group and then extend both the logical volume and the filesystem online, without unmounting. Which sequence of commands achieves this?

A.vgextend data_vg /dev/sdc1; pvcreate /dev/sdc1; lvextend -L +50G /data; resize2fs /data
B.pvcreate /dev/sdc1; vgextend data_vg /dev/sdc1; lvresize -L +50G /data; mount -o remount /data
C.pvcreate /dev/sdc1; vgextend data_vg /dev/sdc1; lvextend -r -L +50G /data
D.pvcreate /dev/sdc1; vgcreate data_vg /dev/sdc1; lvextend -r -L +50G /data
AnswerC

pvcreate initializes the new partition as a physical volume, vgextend adds it to the existing volume group, and lvextend -r -L +50G /data grows the logical volume while the -r flag invokes the appropriate resize tool (resize2fs or xfs_growfs) to expand the filesystem online. This is the correct end-to-end sequence.

Why this answer

Extending LVM storage online requires initializing the new device with pvcreate, adding it to the existing group with vgextend, and growing the logical volume with lvextend while using -r so the filesystem is expanded in the same step. Reversing the first two commands, creating a new volume group, or omitting the filesystem resize all leave the task incomplete or failing outright.

Exam trap

The trap here is assuming that growing a logical volume automatically grows the filesystem it contains, when the two layers must be resized explicitly or via the -r flag.

18
MCQhard

A technician is troubleshooting a server whose /var partition is reported as full by applications, but df -h shows the filesystem at only 40 percent usage. The technician suspects deleted files are still held open by running processes. Which command best identifies the process holding a deleted file open on that filesystem?

A.lsof +L1
B.fuser -m /var
C.df -i /var
D.du -sh /var
AnswerA

The +L1 option to lsof lists files with a link count less than one, which is exactly the state of a file that has been unlinked but is still referenced by an open file descriptor. This reveals the process name and PID holding the space, directly addressing the suspected cause.

Why this answer

When a file is unlinked while a process still holds it open, the blocks remain allocated but the name disappears from the directory tree, so df shows usage that du cannot account for. lsof with the +L1 filter enumerates files whose link count has dropped below one, exposing the process responsible and allowing the administrator to restart it and reclaim space.

Exam trap

The trap here is trusting du output to match df, when unlinked-but-open files are invisible to du yet still consume blocks counted by df.

19
Multi-Selecthard

Which TWO of the following are true about the /proc filesystem?

Select 2 answers
A.It is formatted with the ext4 filesystem.
B.It is a network filesystem.
C.It is a pseudo-filesystem that contains runtime system information.
D.It is used to store persistent configuration data.
E.It is typically mounted at boot time.
AnswersC, E

/proc is a virtual, kernel-generated filesystem exposing runtime data such as CPU details, memory usage and process state. Nothing on it occupies disk blocks, satisfying the stem's pseudo-filesystem criterion and distinguishing it from persistent on-disk filesystems.

Why this answer

Option C is correct because /proc is a pseudo-filesystem (a virtual, kernel-generated filesystem) that exposes runtime system and process information such as /proc/cpuinfo, /proc/meminfo, and per-process directories like /proc/PID, rather than storing real data blocks on disk. Option E is correct because /proc is typically mounted automatically at boot time, commonly via an entry like 'proc /proc proc defaults 0 0' in /etc/fstab or by systemd, since many tools and the kernel expect it to be present early in the boot process. Option A is incorrect because /proc is not formatted with ext4 or any on-disk filesystem; it has no persistent backing store.

Option B is incorrect because /proc is not a network filesystem like NFS or CIFS; it is a kernel-internal virtual filesystem. Option D is incorrect because /proc does not store persistent configuration data—it reflects transient kernel and process state, and changes are lost on reboot.

Exam trap

The trap here is that candidates often confuse /proc with a real filesystem stored on disk, leading them to select Option A, or they mistake its runtime nature for persistent storage (Option D), when in fact /proc is a volatile kernel interface that is mounted automatically at boot (Option E).

20
MCQeasy

A system administrator needs to check if a filesystem has any errors without actually performing a repair. Which command should be used?

A.fsck -y /dev/sdb1
B.fsck -N /dev/sdb1
C.fsck -n /dev/sdb1
D.e2fsck -p /dev/sdb1
AnswerC

The `-n` flag makes fsck answer "no" to every prompt, so it opens the filesystem read-only and reports errors without writing repairs — satisfying the no-repair constraint. Unlike `-y`, which auto-fixes, `-n` guarantees the check is non-destructive, though it may skip some checks needing write access.

Why this answer

The `-n` option with `fsck` performs a read-only check, displaying any filesystem errors without making any modifications or repairs. This is the correct choice for a non-destructive check that only reports issues.

Exam trap

The trap here is confusing `-N` (which only shows what would be checked without actually scanning) with `-n` (which performs a read-only scan), leading candidates to mistakenly choose the dry-run option instead of the actual read-only check.

How to eliminate wrong answers

Option A is wrong because `fsck -y` automatically answers 'yes' to all repair prompts, which would attempt to fix errors, not just check for them. Option B is wrong because `fsck -N` only shows what would be done (a dry-run) without actually checking the filesystem for errors. Option D is wrong because `e2fsck -p` automatically repairs filesystem issues without prompting, which performs repairs rather than just checking.

21
MCQeasy

A junior administrator needs to create a new ext4 filesystem on the partition /dev/sdb2. The partition already exists but has never been formatted. Which command should the administrator run to create the filesystem?

A.fsck.ext4 /dev/sdb2
B.mount -t ext4 /dev/sdb2 /mnt
C.mkfs.ext4 /dev/sdb2
D.fdisk /dev/sdb2
AnswerC

mkfs.ext4 is the dedicated front-end for creating an ext4 filesystem on a block device; it invokes mke2fs with ext4 defaults, writes the superblock, inode tables, and journal, and is safe to run on a raw partition. Since /dev/sdb2 is unformatted, this is the direct and correct tool.

Why this answer

Creating a filesystem requires a mkfs-family tool, and the ext4-specific front end is mkfs.ext4. Because the partition exists but is blank, no partitioning step is needed and no mount or repair step applies. The command writes the on-disk structures that make /dev/sdb2 mountable as ext4.

Exam trap

The trap here is confusing partition creation tools like fdisk with filesystem creation tools like mkfs.ext4, when the partition already exists and only needs formatting.

22
MCQmedium

A Linux administrator runs df -h and sees that the /var filesystem is 100% full. The administrator deletes several large log files, but df still shows 100% usage. Which command should the administrator use to identify processes that are holding deleted files open?

A.fdisk -l /dev/sda
B.lsof +L1
C.fsck /dev/sda1
D.du -sh /var
AnswerB

lsof +L1 lists open files that have a link count less than 1, which indicates deleted files still held open by processes. This helps identify which processes are keeping the space allocated. Once identified, the administrator can restart or kill those processes to release the space. This directly solves the problem of df showing full despite deletion.

Why this answer

When a file is deleted but still open by a process, the directory entry is removed, but the inode and data blocks remain allocated until the process closes the file. df reflects the actual blocks allocated, while du only sees directory entries. lsof +L1 lists open files with link count less than 1, identifying deleted files still in use. Restarting the holding process releases the space.

Exam trap

The trap here is assuming that deleting a file immediately frees disk space, when open file descriptors can keep the space allocated.

23
MCQmedium

Refer to the exhibit. A user tries to write to /mnt/usb/myfile.txt as a non-root user and receives a permission denied error. What is the most likely reason?

A.The filesystem is mounted read-only
B.The vfat filesystem does not support Unix permissions, and the mount options (fmask/dmask) restrict write access to root only
C.The filesystem is mounted with the 'noexec' option, preventing write
D.The file's permissions are 644, so the user does not have write access
AnswerB

Correct. The vfat filesystem does not store Unix permissions; the fmask and dmask options control the permissions shown. With fmask=0022, files get 755 permissions, but the owner is root (default unless uid/gid options are used). So only root can write.

Why this answer

The vfat filesystem does not store Unix-style permissions; instead, it relies on mount options like fmask and dmask to set the effective permissions for all files and directories. If these masks are set to restrict write access to root only (e.g., fmask=0133), non-root users will receive a 'permission denied' error even if the filesystem is mounted read-write. This is a common cause of write failures on USB drives formatted with FAT/VFAT.

Exam trap

The trap here is that candidates assume the 'permission denied' error must be due to file permissions (option D) or a read-only mount (option A), but they overlook that vfat does not store Unix permissions and that mount masks are the actual controlling mechanism.

How to eliminate wrong answers

Option A is wrong because the error would occur regardless of user identity if the filesystem were truly read-only; the question specifies the user is non-root, and a read-only mount would block root as well, which is not the scenario. Option C is wrong because the 'noexec' mount option prevents execution of binaries, not write operations; it has no effect on writing to files. Option D is wrong because on a vfat filesystem, the file's permissions (e.g., 644) are not stored on disk; they are synthesized at mount time via fmask/dmask, so the actual permissions seen by the user depend on those mount options, not on a stored mode.

24
MCQeasy

An administrator needs to identify the device file for the first SATA SSD in a server. Which device file should they use?

A./dev/hda
B./dev/sdb
C./dev/nvme0n1
D./dev/sda
AnswerD

Linux assigns SATA and SCSI disks sequentially as /dev/sda, /dev/sdb and so on, so the first SATA SSD enumerates as /dev/sda. The /dev/sdX naming reflects the detected drive order, satisfying the request for the first device.

Why this answer

The first SATA SSD in a Linux system is typically assigned the device file /dev/sda. SATA drives use the SCSI subsystem via the libata driver, which names them /dev/sdX, with 'a' representing the first detected drive. This is the standard naming convention for SATA SSDs in modern Linux kernels.

Exam trap

The trap here is that candidates often confuse SATA with PATA (IDE) and choose /dev/hda, or mistakenly think SATA SSDs use NVMe naming like /dev/nvme0n1, not realizing that SATA drives are mapped to the SCSI subsystem as /dev/sdX.

How to eliminate wrong answers

Option A is wrong because /dev/hda is used for PATA (IDE) drives, not SATA SSDs; SATA drives are handled by the SCSI subsystem and named /dev/sdX. Option B is wrong because /dev/sdb would be the second SATA drive (or second SCSI device), not the first. Option C is wrong because /dev/nvme0n1 is used for NVMe SSDs, which connect via PCIe and use a different naming scheme (nvme0n1 for the first namespace of the first NVMe controller), not for SATA SSDs.

25
MCQmedium

A technician needs to inspect the filesystem type, UUID, and filesystem label of the partition /dev/sdb1 without mounting it. Which command provides all of this information in a single invocation?

A.blkid /dev/sdb1
B.lsblk -f /dev/sdb1
C.tune2fs -l /dev/sdb1
D.fdisk -l /dev/sdb1
AnswerA

blkid queries the libblkid cache and reads superblock metadata to print the UUID, TYPE (filesystem), and LABEL for the specified block device. It works on unmounted partitions, requires no mount, and is the standard tool for retrieving persistent identifiers used in /etc/fstab. This directly satisfies the need to see filesystem type, UUID, and label together.

Why this answer

blkid reads on-disk superblock metadata and reports UUID, TYPE, and LABEL for a block device without requiring a mount. That single invocation answers all three questions the technician has. fdisk shows partition-table data, lsblk -f is less reliable when given a single partition argument, and tune2fs works only on ext-family filesystems, so each of those alternatives leaves part of the requirement unmet.

Exam trap

The trap here is assuming that any tool that lists disks will also surface the filesystem UUID and label, when only tools that read superblock metadata do so.

26
MCQmedium

A server has a partition /dev/sda2 that is almost full. The admin suspects a large file has been deleted but is still held open by a process. Which command can identify such a file?

A.du -sh /
B.find / -size +100M
C.lsof | grep deleted
D.df -h
AnswerC

lsof lists open file descriptors; filtering for deleted shows files unlinked from the directory but still held open, so the space is not reclaimed until the process closes or restarts. This identifies the culprit consuming the partition.

Why this answer

The `lsof` command lists open files and their associated processes. When a file is deleted but still held open by a process, `lsof` shows the filename with a '(deleted)' marker in its output. Piping through `grep deleted` filters for exactly those entries, allowing the admin to identify the file and the process keeping it alive, which is the precise scenario described.

Exam trap

The trap here is that candidates often choose `df -h` or `du` because they show disk usage, but they fail to realize that deleted-but-open files are invisible to those tools, while `lsof` directly reveals the hidden space consumption.

How to eliminate wrong answers

Option A is wrong because `du -sh /` calculates disk usage of the entire root filesystem but does not show which files are deleted and still open; it only reports current space consumption. Option B is wrong because `find / -size +100M` locates files larger than 100 MB on disk, but it cannot detect files that have been unlinked (deleted) from the directory tree, as those files no longer have a directory entry to find. Option D is wrong because `df -h` shows overall filesystem disk usage and free space, but it provides no information about individual files or processes holding deleted files open.

27
MCQhard

A Linux system has a software RAID1 array /dev/md0 consisting of /dev/sda1 and /dev/sdb1. After replacing a failed disk, the administrator runs 'mdadm --manage /dev/md0 --add /dev/sdc1', but the array remains degraded. Which command should be used to check the status of the array?

A.mdadm --examine /dev/sdc1
B.mdadm --version
C.mdadm --detail /dev/md0
D.mdadm --query /dev/md0
AnswerC

`mdadm --detail /dev/md0` reports the array's current state, including which member devices are active, failed or spare, and the overall RAID1 redundancy level. This directly satisfies the stem's requirement to check why the array remains degraded after adding /dev/sdc1, showing whether the new device was actually incorporated.

Why this answer

The `mdadm --detail /dev/md0` command displays the current state of the RAID array, including its status (e.g., degraded, active), the number of active and failed devices, and the sync/resync progress. Since the array remains degraded after adding a new disk, this command will show whether the new disk has been properly integrated or if there is an underlying issue, such as a missing or failed component.

Exam trap

The trap here is that candidates often confuse `--examine` (which inspects a disk's superblock) with `--detail` (which shows the array's overall state), leading them to choose Option A when they need to check the array's degraded status rather than a single disk's metadata.

How to eliminate wrong answers

Option A is wrong because `mdadm --examine /dev/sdc1` reads the superblock on a specific disk to show its metadata and RAID membership, but it does not report the overall array status or whether the array is still degraded. Option B is wrong because `mdadm --version` only prints the version of the mdadm utility and provides no information about the array's state. Option D is wrong because `mdadm --query /dev/md0` gives a brief summary (e.g., 'is not an md array' or a one-line status) but lacks the detailed device-by-device status and resync progress needed to diagnose why the array remains degraded.

28
MCQeasy

The /proc filesystem is described as a virtual filesystem. Which statement best describes its purpose?

A.It contains configuration files for system services.
B.It provides an interface to kernel data structures and processes.
C.It holds binary executables for system administration.
D.It stores temporary files that survive reboots.
AnswerB

/proc is generated in memory by the kernel, not stored on disk, so it has no persistent backing blocks. It exposes kernel data structures and per-process information through files, satisfying the virtual filesystem definition in the stem.

Why this answer

The /proc filesystem is a virtual filesystem that does not contain actual files on disk but instead provides a runtime interface to kernel data structures, including process information, system memory, CPU details, and hardware configuration. This allows users and system tools (like ps, top, and free) to read kernel state in real time without needing direct kernel memory access.

Exam trap

The trap here is that candidates confuse /proc with a real filesystem for storing configuration or executables, when in fact it is a virtual interface to kernel data structures that contains no persistent files.

How to eliminate wrong answers

Option A is wrong because configuration files for system services are stored in /etc, not in /proc, which is a virtual filesystem with no persistent configuration data. Option C is wrong because binary executables for system administration reside in directories like /bin, /sbin, /usr/bin, or /usr/sbin, while /proc contains no executable binaries. Option D is wrong because temporary files that survive reboots are typically stored in /var/tmp, whereas /proc is a volatile, kernel-generated filesystem that is recreated fresh on every boot and does not persist any data.

29
Multi-Selectmedium

An administrator must configure persistent mounts for two filesystems on a database server. One is an ext4 volume that should be mounted at boot without failing the whole boot process if it is unavailable. The other is a swap partition that must be activated at boot. Which TWO entries belong in /etc/fstab to meet these requirements? (Choose two.)

Select 2 answers
A.UUID=5678-efgh /data ext4 defaults,nofail 0 2
B.UUID=90ab-cdef none swap sw 0 0
C.UUID=1234-abcd /data ext4 defaults,noauto 0 2
D.UUID=90ab-cdef /swap swap defaults 0 2
E.UUID=5678-efgh /data ext4 defaults 1 1
AnswersA, B

This entry mounts the ext4 volume at boot using its UUID, and the nofail option tells systemd not to treat a mount failure as fatal, so the boot continues if the device is missing. The dump and fsck fields are valid for an ext4 data filesystem, satisfying the first requirement.

Why this answer

Persistent mounts are declared in /etc/fstab using the device, mount point, filesystem type, options, dump, and fsck pass fields. The ext4 volume needs nofail so an unavailable device does not halt boot, while swap uses the mount point none, type swap, and option sw. The two entries matching those patterns are correct.

Exam trap

The trap here is using noauto when nofail is required, since both affect boot behavior but only one keeps the mount automatic while tolerating a missing device.

30
Multi-Selecteasy

Which TWO options in /etc/fstab affect whether a filesystem is mounted at boot? (Choose two.)

Select 2 answers
A.user
B.defaults
C.auto
D.ro
E.noauto
AnswersC, E

The auto option marks the filesystem for mounting by mount -a, which the boot process invokes, so the entry is mounted at startup. Omitting it defaults to auto, but specifying it explicitly confirms boot mounting.

Why this answer

Option C (auto) is correct because it explicitly marks the filesystem as mountable by the mount -a command, which is what the boot process runs to mount all entries in /etc/fstab, so an entry with auto will be mounted at boot. Option E (noauto) is correct because it does the opposite: it tells mount -a to skip that entry, meaning the filesystem will not be mounted automatically at boot and must be mounted manually. The other options do not control boot-time mounting: A (user) permits non-root users to mount the filesystem, B (defaults) is a shorthand for rw,suid,dev,exec,auto,nouser,async (it includes auto but is a general option bundle, not the specific boot-mount toggle), and D (ro) only sets the filesystem read-only, which is unrelated to whether it is mounted at boot.

Exam trap

The trap here is that candidates often confuse 'auto' with 'defaults' or think 'ro' affects boot mounting, when in fact only 'auto' and 'noauto' directly control automatic mounting at boot.

31
MCQeasy

A system administrator wants to ensure that the filesystem on /dev/sdb1 is checked for errors every 30 mounts. Which command accomplishes this?

A.fsck -c 30 /dev/sdb1
B.e2fsck -c 30 /dev/sdb1
C.tune2fs -c 30 /dev/sdb1
D.mount -o errors=remount-ro
AnswerC

`tune2fs -c 30 /dev/sdb1` sets the maximum mount count to 30 on the ext2/3/4 filesystem, satisfying the requirement to trigger `e2fsck` after every 30 mounts. The `-c` flag directly controls this counter, whereas `-i` would set a time-based interval instead.

Why this answer

The `tune2fs` command is used to adjust tunable filesystem parameters on ext2/ext3/ext4 filesystems. The `-c` option sets the maximum mount count between filesystem checks; `tune2fs -c 30 /dev/sdb1` configures the filesystem to trigger an `fsck` check every 30 mounts. This is the correct tool for modifying this persistent setting.

Exam trap

The trap here is confusing the `-c` option of `tune2fs` (set mount count) with the `-c` option of `e2fsck` (bad-block check), leading candidates to mistakenly choose `e2fsck -c 30`.

How to eliminate wrong answers

Option A is wrong because `fsck` is a frontend that runs filesystem checks, not a tool to set mount-count parameters; `fsck -c 30` would attempt to check the filesystem and the `-c` option is not valid for setting mount intervals. Option B is wrong because `e2fsck` is the ext2/ext3/ext4 filesystem checker, and its `-c` option performs a bad-block scan, not a mount-count configuration. Option D is wrong because `mount -o errors=remount-ro` is a mount option that remounts the filesystem as read-only on error, but it does not schedule periodic checks based on mount count.

32
Multi-Selecteasy

Which TWO of the following commands can be used to create a new filesystem on a partition?

Select 2 answers
A.fdisk
B.mkfs.ext4
C.parted
D.fsck
E.mkfs
AnswersB, E

mkfs.ext4 is a filesystem-specific front end that builds an ext4 filesystem directly on a block device, writing superblocks, inode tables and journal structures. It satisfies the stem's requirement to create a new filesystem on a partition.

Why this answer

Option B, mkfs.ext4, is correct because it is a front-end to the mkfs family that specifically writes an ext4 filesystem onto a block device or partition, e.g. mkfs.ext4 /dev/sdb1. Option E, mkfs, is correct because it is the generic filesystem-creation utility that, when invoked with a type such as mkfs -t xfs /dev/sdb1, builds a new filesystem on the target partition. The unmarked options do not belong: fdisk (A) and parted (C) are partitioning tools that create/modify partition tables and partitions, not filesystems, and fsck (D) is a consistency-checking and repair utility for existing filesystems, not a creator.

Exam trap

The trap here is that candidates confuse partition management tools (fdisk, parted) with filesystem creation tools (mkfs), or mistakenly think fsck can create a filesystem because it interacts with filesystem metadata.

33
MCQmedium

A junior administrator accidentally deleted a large log file that is still being written to by a running process. The file no longer appears in directory listings, but `df -h` shows the filesystem is still nearly full. Which command will reclaim the space without interrupting the running process?

A.Run sync to flush dirty pages and free the deleted file's blocks
B.lsof | grep deleted, then kill the process holding the file
C.truncate -s 0 /proc/<PID>/fd/<FD> using the file descriptor path
D.Run fsck on the filesystem to release orphaned inodes
AnswerC

When a file is unlinked but still open, its data blocks remain allocated until the last file descriptor closes. Truncating through the /proc/<PID>/fd/ path empties the file content while the process keeps its descriptor open, immediately freeing the blocks. The running process continues writing from its current offset, and the filesystem space is reclaimed without any service interruption.

Why this answer

An unlinked file that remains open keeps its inode and data blocks allocated until the last descriptor closes. Truncating the file through its /proc/<PID>/fd/ descriptor zeroes the content and frees the blocks while the process continues running, satisfying the requirement of no interruption. Diagnostics like lsof help locate the descriptor, but the reclamation itself must act on the open file.

Exam trap

The trap here is assuming that a deleted file immediately frees its disk space, when an open file descriptor keeps the blocks allocated until the process closes it or the file is truncated.

34
MCQmedium

Refer to the exhibit. An administrator attempts to remount /mnt as read-only but receives the error shown. What is the most likely cause?

A.The /mnt directory is not a mount point
B.The /mnt directory is not empty
C.The /mnt directory does not exist
D.The filesystem is already mounted read-only
AnswerA

Remounting requires an existing mount point; if /mnt is merely an ordinary directory in the root filesystem, the kernel has no mount entry to modify and rejects the remount with an error. This matches the stem's constraint that the remount command fails.

Why this answer

The error 'mount: /mnt is not a mount point' indicates that the administrator attempted to use the `remount` option on a directory that is not currently a mount point. The `mount -o remount` command only works on directories where a filesystem is already mounted; it modifies the mount options of an existing mount, not a regular directory. Since /mnt is not a mount point, the kernel rejects the operation with this specific error.

Exam trap

The trap here is that candidates confuse the `remount` option (which modifies an existing mount) with the `mount` command (which creates a new mount), leading them to think the error is about directory emptiness or existence rather than the mount point status.

How to eliminate wrong answers

Option B is wrong because a non-empty directory can still be a mount point; the error message specifically says 'not a mount point', not 'not empty'. Option C is wrong because if /mnt did not exist, the error would be 'mount: /mnt: No such file or directory', not 'not a mount point'. Option D is wrong because if the filesystem were already mounted read-only, the `remount` command would succeed (it would just be a no-op) or produce a different error like 'mount: /mnt: cannot remount ...' but not 'not a mount point'.

35
MCQhard

According to FHS, which directory should NOT be mounted on a networked filesystem (e.g., NFS) because it contains host-specific configuration files?

A./home
B./var
C./etc
D./opt
AnswerC

/etc holds host-specific configuration such as fstab, passwd and network settings. Sharing it over NFS would let one machine's configuration override another's, so FHS expects /etc to remain local to each host rather than mounted remotely.

Why this answer

The Filesystem Hierarchy Standard (FHS) specifies that /etc contains host-specific configuration files that must be local to each machine. Mounting /etc over a network filesystem like NFS would cause all clients to share the same configuration, breaking system identity, network settings, and security policies. This violates the FHS requirement that /etc be a local filesystem.

Exam trap

The trap here is that candidates may think /var or /home are the correct answers because they contain user data or logs, but the FHS specifically singles out /etc as the directory that must remain local due to its host-specific configuration files.

How to eliminate wrong answers

Option A is wrong because /home is designed to be shared across networked systems via NFS, allowing user home directories to be accessed from any client. Option B is wrong because /var contains variable data such as logs and spools that can be shared or local, but it is not specifically prohibited from NFS mounting by the FHS. Option D is wrong because /opt is for add-on software packages and can be shared over NFS if the software is identical across hosts, though it is not host-specific like /etc.

36
MCQhard

An ext4 filesystem is experiencing performance degradation due to very frequent small writes. Which tune2fs option can help by reserving a percentage of blocks for the root user to prevent fragmentation?

A.-i 0
B.-g root
C.-c 0
D.-m 0
AnswerB

The -g option sets the group that can use the reserved blocks. Specifying 'root' ensures that the reserved blocks are available to the root group, which can help prevent fragmentation by keeping free space contiguous for root's small writes.

Why this answer

The -g option in tune2fs sets the group that can use the reserved blocks. By specifying 'root', it assigns the reserved blocks to the root group, ensuring that the root user can access this reserved space. This helps prevent fragmentation by keeping free blocks available for root's small writes, rather than allowing the filesystem to become completely full.

Options A and C are unrelated to block reservation. Option D sets the reserved block percentage to 0, which does not reserve any blocks and can actually increase fragmentation.

Exam trap

The trap is that candidates often think -m 0 helps by removing reserved blocks, but the question specifically asks for an option that reserves a percentage. The correct answer is -g root, which works in conjunction with the default or set reserved blocks to ensure they are available for root.

How to eliminate wrong answers

Option A is wrong because `-i 0` disables the filesystem check interval (i.e., maximum time between checks), which does not affect block reservation or fragmentation from small writes. Option B is wrong because `-g root` is not a valid tune2fs option; the `-g` option is used to specify a group for reserved blocks, but it requires a group ID or name, and 'root' is not a valid group specification in this context. Option C is wrong because `-c 0` sets the maximum mount count between filesystem checks to 0, disabling checks based on mount count, which has no impact on block reservation or fragmentation.

37
MCQmedium

An administrator needs to mount an ISO image located at /tmp/install.iso to the directory /mnt/iso. Which command will accomplish this?

A.mount --bind /tmp/install.iso /mnt/iso
B.mount -o remount,loop /tmp/install.iso /mnt/iso
C.mount -o loop /tmp/install.iso /mnt/iso
D.mount -t iso9660 /tmp/install.iso /mnt/iso
AnswerC

The -o loop option tells mount to use a loop device, which allows a file to be mounted as a block device. This is the standard way to mount an ISO image. The command mounts the ISO to the specified directory, making its contents accessible.

Why this answer

Mounting an ISO image requires the loop option to associate the file with a loop device, which the kernel then treats as a block device. The mount command with -o loop is the correct syntax. Other options either omit loop, use bind incorrectly, or attempt to remount a non-mounted filesystem.

Exam trap

The trap here is forgetting that regular files require the loop option to be mounted as filesystems.

38
MCQhard

Refer to the exhibit. The 'mount -a' command fails for the NFS mount. What is the most likely cause?

A.The local mount point /mnt/nfs does not exist.
B.The filesystem type 'nfs' is not supported by the kernel.
C.The NFS server is not exporting the directory or is unreachable.
D.The 'defaults' option is missing for the NFS entry.
AnswerC

The mount fails because the client cannot reach the server or the export is absent; 'mount -a' relies on the server's export list and network reachability. Neither /etc/fstab syntax nor local mount options cause this, so an unexported or unreachable NFS server is the likely cause.

Why this answer

The 'mount -a' command reads /etc/fstab and attempts to mount all entries. For an NFS mount, the most common failure is that the NFS server is not exporting the specified directory or is unreachable, which causes the mount to fail with an error like 'mount.nfs: access denied by server while mounting' or 'mount.nfs: No route to host'. This is the correct answer because network-based filesystem mounts depend on server availability and export configuration.

Exam trap

LPI exams frequently test the distinction between local mount point existence and network service availability, tricking candidates into thinking a missing mount point is the cause when the real issue is server-side or network connectivity.

How to eliminate wrong answers

Option A is wrong because if the local mount point /mnt/nfs did not exist, the mount command would fail with a 'mount point does not exist' error, but the question states the failure is specifically for the NFS mount, implying other mounts succeed, and a missing mount point would affect any mount, not just NFS. Option B is wrong because if the kernel did not support the 'nfs' filesystem type, the mount would fail for all NFS mounts, but the question implies a specific NFS entry fails, and modern kernels typically include NFS support as a module or built-in; a missing kernel module would produce a 'mount: unknown filesystem type' error, which is not the most likely cause in a typical scenario. Option D is wrong because the 'defaults' option is not required for NFS mounts; it is a shorthand for a set of default mount options (like rw, suid, dev, exec, auto, nouser, async) but omitting it does not cause the mount to fail—the mount will still proceed with explicit options or defaults from the kernel.

39
MCQhard

A company is setting up a database server that requires high reliability and support for snapshots. The storage will be on a single large disk. Which filesystem is best suited for this requirement?

A.ext4
B.NTFS
C.XFS
D.btrfs
AnswerD

btrfs provides copy-on-write snapshots and checksummed data with RAID support on a single disk, directly meeting the stated reliability and snapshot requirements. ext4 lacks native snapshots, and XFS snapshot support is limited, so btrfs is the best fit.

Why this answer

Btrfs (B-tree filesystem) is best suited for this requirement because it natively supports snapshots, checksumming, and copy-on-write (CoW) for high reliability, all on a single disk. Unlike other Linux filesystems, btrfs provides built-in snapshot and rollback capabilities without requiring an external volume manager, making it ideal for database servers needing consistent point-in-time backups.

Exam trap

The trap here is that candidates often choose XFS for its high performance with large files, but they overlook that XFS lacks native snapshot support, while btrfs is specifically designed for advanced features like snapshots and self-healing on a single disk.

How to eliminate wrong answers

Option A is wrong because ext4 lacks native snapshot support; it relies on external tools like LVM for snapshots, which adds complexity and does not provide filesystem-level checksumming for data integrity. Option B is wrong because NTFS is a Windows filesystem not natively supported on Linux without FUSE or kernel modules, and it is not designed for the Linux environment or LPIC-1 scope. Option C is wrong because XFS does not support snapshots natively; it requires LVM or other volume managers for snapshot functionality, and while it offers high performance for large files, it lacks the integrated snapshot and rollback features of btrfs.

40
Multi-Selecteasy

Which TWO commands can be used to create an ext4 filesystem on a partition?

Select 2 answers
A.mkfs.btrfs /dev/sdb1
B.mkfs.ext4 /dev/sdb1
C.mke2fs -t ext4 /dev/sdb1
D.mkfs.msdos /dev/sdb1
E.mkfs.xfs /dev/sdb1
AnswersB, C

mkfs.ext4 is the ext4-specific front end that invokes mke2fs with the correct type, creating the filesystem directly on the named partition. It satisfies the requirement to build an ext4 filesystem on /dev/sdb1 without extra flags.

Why this answer

Option B, mkfs.ext4 /dev/sdb1, is correct because mkfs.ext4 is the dedicated front-end utility for creating an ext4 filesystem on the specified block device, invoking the ext4 filesystem code directly. Option C, mke2fs -t ext4 /dev/sdb1, is also correct because mke2fs is the underlying ext-family filesystem creation tool, and the -t ext4 flag explicitly selects the ext4 filesystem type, producing the same ext4 result. The unmarked options do not belong: mkfs.btrfs creates a Btrfs filesystem, mkfs.msdos creates a FAT filesystem, and mkfs.xfs creates an XFS filesystem, none of which are ext4.

Exam trap

The trap here is that candidates may think only `mkfs.ext4` is valid, overlooking that `mke2fs -t ext4` is an equivalent command, or they may confuse filesystem-specific mkfs wrappers (like `mkfs.btrfs` or `mkfs.xfs`) as being able to create ext4 filesystems.

41
MCQhard

Refer to the exhibit. The root filesystem is nearly full. The administrator needs to increase its size. Which steps should be performed?

A.Use parted to resize the root partition and then mount it
B.Use fdisk to increase the size of /dev/sda1 and then run resize2fs
C.Use lvextend to extend the logical volume and then resize2fs to resize the filesystem
D.Create a new filesystem on /dev/sda2 and mount it to /
AnswerC

lvextend grows the logical volume using free space in its volume group, then resize2fs expands the ext4 filesystem online to occupy that new space. Both steps are required because enlarging the LV alone leaves the filesystem unchanged.

Why this answer

The root filesystem is on an LVM logical volume, as indicated by the exhibit (e.g., /dev/mapper/rootvg-rootlv). To increase its size, you must first extend the logical volume using lvextend, then resize the filesystem with resize2fs. This two-step process ensures the underlying block device and the filesystem are both enlarged to utilize the newly available space.

Exam trap

The trap here is that candidates assume the root filesystem is on a traditional partition and attempt to resize it with fdisk or parted, failing to recognize that LVM requires a different workflow with lvextend and resize2fs.

How to eliminate wrong answers

Option A is wrong because parted resizes partitions, not LVM logical volumes; the root filesystem resides on a logical volume, not a physical partition, so resizing the partition would not affect the LV. Option B is wrong because fdisk operates on physical partitions (e.g., /dev/sda1), but the root filesystem is on an LVM logical volume; increasing /dev/sda1 would not extend the LV, and resize2fs alone cannot expand the LV. Option D is wrong because creating a new filesystem on /dev/sda2 and mounting it to / would replace the existing root filesystem, destroying all data and requiring a complete reinstall or data migration, which is not a valid method to increase the size of the current root filesystem.

42
MCQeasy

A user reports that a USB flash drive plugged into a Linux workstation is not automatically mounted. The administrator runs 'lsblk' and sees the device as /dev/sdb1 with no mountpoint. Which command should the administrator use to manually mount the filesystem on /dev/sdb1 to the /mnt/usb directory?

A.mount -t auto /dev/sdb1 /mnt/usb
B.mount /mnt/usb /dev/sdb1
C.mount /dev/sdb1 /mnt/usb
D.mount -o loop /dev/sdb1 /mnt/usb
AnswerC

The mount command with the device and mount point as arguments will mount the filesystem. The system will auto-detect the filesystem type if not specified. This is the correct syntax to manually mount a device to a directory.

Why this answer

The correct command is 'mount /dev/sdb1 /mnt/usb'. This uses the standard syntax of device followed by mount point. The system will auto-detect the filesystem type.

Other options either reverse the arguments, add unnecessary options, or use loop mounting which is not applicable.

Exam trap

The trap here is confusing the order of arguments or adding unnecessary options like -t auto or -o loop, which are not required for a simple manual mount.

43
MCQmedium

Refer to the exhibit. On boot, which filesystem will be checked first by fsck?

A.The swap partition
B.The root filesystem (/)
C.The CD-ROM device
D.The /boot filesystem
AnswerB

The root filesystem is mounted first during boot, so fsck checks it before any other filesystem. Its pass number in /etc/fstab is typically 1, while other local filesystems use 2, ensuring / is verified ahead of them.

Why this answer

The root filesystem (/) is checked first by fsck because it is mounted read-only during the initial boot phase, and fsck must verify its integrity before the system can proceed to mount other filesystems. The order of filesystem checks is determined by the fs_passno field in /etc/fstab, where the root filesystem typically has a passno of 1, ensuring it is checked before any filesystem with a higher passno value.

Exam trap

The trap here is that candidates often assume the /boot filesystem is checked first because it contains the kernel and bootloader, but the root filesystem is always checked first due to its fs_passno=1 setting in /etc/fstab.

How to eliminate wrong answers

Option A is wrong because swap partitions have a passno of 0 in /etc/fstab, which means they are never checked by fsck; swap is not a mounted filesystem and does not require integrity verification. Option C is wrong because CD-ROM devices are typically not listed in /etc/fstab with a passno greater than 0, and even if they were, they are not mounted at boot time by default; fsck only checks filesystems that are mounted or have a non-zero passno. Option D is wrong because the /boot filesystem, if separate, usually has a passno of 2, meaning it is checked after the root filesystem (passno 1) has been verified.

44
MCQeasy

After modifying /etc/fstab, an administrator wants to test if the new mount points can be mounted without rebooting. Which command should be used?

A.systemctl daemon-reload
B.mount -a
C.mount -o remount
D.mount -t ext4
AnswerB

`mount -a` reads /etc/fstab and mounts every entry not already mounted, directly satisfying the requirement to validate the modified configuration without rebooting. It parses each filesystem line, so syntax errors or unreachable devices surface immediately, letting the administrator confirm the new mount points work before a restart.

Why this answer

The `mount -a` command reads /etc/fstab and mounts all filesystems listed there that are not already mounted, making it the correct way to test new entries without rebooting. This command respects the mount options and order defined in fstab, allowing the administrator to verify that the new mount points work correctly.

Exam trap

The trap here is that candidates confuse `systemctl daemon-reload` with a command that applies fstab changes, when in fact it only reloads systemd unit files and has no effect on mount operations defined in /etc/fstab.

How to eliminate wrong answers

Option A is wrong because `systemctl daemon-reload` is used to reload systemd unit files, not to mount filesystems; it does not process /etc/fstab mount entries. Option C is wrong because `mount -o remount` requires a specific device or mount point argument and only remounts an already mounted filesystem, it cannot mount new entries from /etc/fstab. Option D is wrong because `mount -t ext4` specifies the filesystem type but requires explicit device and mount point arguments, it does not read /etc/fstab to mount new entries.

45
Multi-Selecteasy

Which TWO commands can be used to display the UUID of a filesystem? (Choose two.)

Select 2 answers
A.df -h
B.mount
C.lsblk -f
D.cat /etc/fstab
E.blkid
AnswersC, E

`lsblk -f` lists block devices with their filesystem type, label, mountpoint and UUID, reading the superblock metadata directly. It satisfies the stem's requirement to display a filesystem UUID without needing the device mounted, unlike `blkid` alternatives that may require root or a populated cache.

Why this answer

Option C, lsblk -f, is correct because the -f (--fs) flag makes lsblk print filesystem information for each block device, including the filesystem type, label, mountpoint, and the UUID column, so it directly displays the UUID of a filesystem. Option E, blkid, is correct because blkid probes block devices and prints their attributes, including UUID and TYPE, by default showing the UUID for each device with a filesystem. Option A, df -h, only reports filesystem disk usage in human-readable sizes and does not show UUIDs.

Option B, mount, lists mounted filesystems and their mount options but does not display filesystem UUIDs. Option D, cat /etc/fstab, shows configured mount entries, which may contain UUID= identifiers if the admin wrote them that way, but it does not query or display the actual UUID of a filesystem.

Exam trap

The trap here is that candidates may confuse `mount` (which shows current mounts) with `blkid` or `lsblk` for UUID display, or think `/etc/fstab` is a command rather than a configuration file.

46
MCQmedium

An admin runs 'lsblk' and sees that /dev/nvme0n1p1 is listed with size 512M and mounted at /boot/efi. What is the most likely filesystem type?

A.ext4
B.swap
C.xfs
D.vfat
AnswerD

The EFI System Partition must use a FAT variant so UEFI firmware can read it without Linux drivers; vfat is the standard choice. The 512M size and /boot/efi mount point confirm this role, whereas ext4, xfs and swap cannot serve as the ESP.

Why this answer

The /boot/efi partition is the EFI System Partition (ESP), which is required for UEFI boot. The ESP must be formatted with a FAT-based filesystem (typically vfat/FAT32) because the UEFI firmware is designed to read FAT partitions to load boot loaders. The size of 512M is also typical for an ESP.

Exam trap

The trap here is that candidates often assume /boot/efi uses a Linux filesystem like ext4 because it is a Linux mount point, but the UEFI specification mandates FAT for the ESP, making vfat the only correct choice.

How to eliminate wrong answers

Option A is wrong because ext4 is a Linux-native filesystem not supported by UEFI firmware for the ESP; the ESP must use FAT. Option B is wrong because swap is used for virtual memory, not for storing boot files or EFI executables. Option C is wrong because xfs is a high-performance filesystem for large data volumes, but it is not recognized by UEFI firmware for the ESP.

47
MCQmedium

After running 'df -h', the administrator sees that /dev/sda1 is 100% used. 'du -sh /mountpoint' shows only 50% used. What is the most likely cause?

A.The disk has bad blocks
B.A large file was deleted but a process still holds it open
C.There is a hard link that du does not count
D.The filesystem is corrupted and needs fsck
AnswerB

Deleting a file removes its directory entry but the inode and data blocks persist while a process keeps the file descriptor open. df counts allocated blocks, so usage stays at 100% until that process closes or restarts.

Why this answer

When a file is deleted but a process still holds an open file descriptor to it, the kernel does not release the disk space until the process closes the file. The 'df' command reports space usage based on the filesystem's superblock, which still counts the deleted file's blocks. 'du' calculates space by traversing the directory tree and summing file sizes, so it does not see the unlinked file. This discrepancy explains why 'df' shows 100% usage while 'du' shows only 50%.

Exam trap

The trap here is that candidates assume 'du' and 'df' should always match, overlooking the fact that 'du' cannot account for space used by unlinked files still held open by processes.

How to eliminate wrong answers

Option A is wrong because bad blocks would cause read/write errors and potential data loss, but they would not create a discrepancy between df and du; bad blocks are marked as unusable and do not inflate used space. Option C is wrong because hard links are counted correctly by both df and du; du counts each hard link's contribution to the directory tree, and df accounts for the inode's allocated blocks only once. Option D is wrong because filesystem corruption typically causes inconsistencies in metadata that fsck can repair, but it would not produce a clean df vs du mismatch; corruption often leads to errors or missing files, not a hidden file consuming space.

48
Drag & Dropmedium

Arrange the steps to create a LVM logical volume and mount it.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for creating an LVM logical volume and mounting it is: first create physical volumes (PVs) using pvcreate, then create a volume group (VG) with vgcreate, then create a logical volume (LV) with lvcreate, and finally format the LV with a filesystem (e.g., mkfs) and mount it. This ensures that each step builds on the previous one.

49
MCQeasy

Refer to the exhibit. How many physical disks are present in the system?

A.3
B.2
C.4
D.1
AnswerB

Two physical disks appear because the exhibit lists two distinct block devices (for example /dev/sda and /dev/sdb), each with its own geometry and partition table. Logical volumes, partitions or RAID members shown beneath those devices are not counted separately, so the total remains two.

Why this answer

The output shows two SCSI disks: /dev/sda and /dev/sdb. Each device file represents a physical disk, so there are exactly two physical disks present. The partitions (sda1, sda2, sdb1) are subdivisions of those disks and do not count as separate physical disks.

Exam trap

The trap here is that candidates often count partition entries (e.g., sda1, sda2, sdb1) as separate physical disks, leading them to overcount the actual number of drives.

How to eliminate wrong answers

Option A is wrong because it likely counts partitions (sda1, sda2, sdb1) as separate disks, but partitions are logical divisions, not physical disks. Option C is wrong because it may misinterpret the number of device files or include non-disk devices (e.g., /dev/sr0 for optical drive) as physical disks. Option D is wrong because it ignores the second disk /dev/sdb, possibly assuming all partitions belong to a single disk.

50
Multi-Selectmedium

Which TWO of the following are valid methods to specify a partition in /etc/fstab?

Select 3 answers
A.PARTUUID
B.UUID
C.LABEL
D.DEVPATH
E.ID
AnswersA, B, C

PARTUUID is a partition table UUID, less commonly used in /etc/fstab.

Why this answer

Options A (PARTUUID), B (UUID), and C (LABEL) are all valid device specifiers in the first field of /etc/fstab. UUID= and LABEL= reference the filesystem UUID and filesystem label, while PARTUUID= references the partition-table UUID (GUID) of the partition. For example, 'UUID=1234-ABCD / ext4 defaults 0 1', 'LABEL=root / ext4 defaults 0 1', and 'PARTUUID=12345678-01 / ext4 defaults 0 1' are all valid and resolved at mount time.

Options D (DEVPATH) and E (ID) are not valid fstab device specifiers; they are udev properties and are not recognized fstab tags.

Exam trap

The trap here is that candidates may confuse PARTUUID (a partition table identifier) with UUID (a filesystem identifier), or assume any udev property like DEVPATH or ID is valid in fstab, when only UUID, LABEL, PARTUUID, and device paths are supported.

51
Multi-Selecthard

Which THREE of the following directories are part of the FHS and must be present on a standard Linux system? (Choose three.)

Select 3 answers
A./var
B./etc
C./lost+found
D./bin
E./home
AnswersA, B, D

/var holds variable data such as logs, spools and caches, and the FHS lists it among the directories that must exist on a standard system. Its presence is required even when separate partitions are not used.

Why this answer

The Filesystem Hierarchy Standard (FHS) defines /var (option A) as the directory for variable data such as logs, spool files, and caches, and it is a required top-level directory on a standard Linux system. Option B, /etc, is also mandated by the FHS to hold host-specific system configuration files, making it essential for a functioning system. Option D, /bin, is required by the FHS to contain essential user command binaries needed for single-user mode and system boot.

Option C, /lost+found, is not an FHS-mandated directory; it is created by the e2fsck utility on ext2/ext3/ext4 filesystems to hold recovered files and is filesystem-specific rather than a standard FHS requirement. Option E, /home, while commonly present for user home directories, is not strictly required by the FHS and may be absent or mounted from a remote server in some configurations.

Exam trap

The trap here is that /lost+found appears essential because it is commonly seen on ext filesystems, but it is not part of the FHS mandatory list, and /home is often assumed required due to its ubiquity, yet the FHS does not mandate it for a standard Linux system.

52
MCQeasy

A Linux administrator is preparing a new server and needs to create an ext4 filesystem on the /dev/sdb1 partition. Which command should be used?

A.mkfs -t ext4 /dev/sdb1
B.fsck.ext4 /dev/sdb1
C.tune2fs -t ext4 /dev/sdb1
D.mke2fs -j /dev/sdb1
AnswerA

The mkfs command with the -t option specifies the filesystem type. mkfs -t ext4 /dev/sdb1 creates an ext4 filesystem on the partition. This is a standard and correct way to format a partition with a specific filesystem type. The command invokes the appropriate mkfs.ext4 helper.

Why this answer

The mkfs command is the standard utility for creating filesystems. Using mkfs -t ext4 /dev/sdb1 explicitly specifies the ext4 filesystem type. This invokes the mkfs.ext4 program, which writes the ext4 superblock, inode tables, and journal to the partition.

Other commands like fsck and tune2fs are for checking or modifying existing filesystems, not for creation.

Exam trap

The trap here is confusing filesystem creation tools with filesystem checking or tuning tools, or using mke2fs -j which creates ext3.

53
MCQeasy

A user reports that they cannot create new files in their home directory even though the filesystem shows free space. Running df -h shows the filesystem at 100 percent inode usage. Which action most directly resolves the immediate problem?

A.Run resize2fs to expand the filesystem onto additional space.
B.Remount the filesystem with the noatime option to stop inode updates.
C.Delete unneeded files that consume many inodes, such as old session files or cached mail, to free inode entries.
D.Increase the inode count by running tune2fs -i 0 on the mounted filesystem.
AnswerC

A filesystem can run out of inodes while still having free data blocks, and on ext4 the inode count is fixed at mkfs time. Removing large numbers of small files frees inode entries, allowing new files to be created. This addresses the actual exhaustion reported by df -i and restores the ability to create files.

Why this answer

When df -h reports 100 percent inode usage, the filesystem has no free inode entries even though data blocks may remain. Deleting many small files, such as session or cache files, releases inodes and restores file creation. Expanding the filesystem, remounting with noatime, or adjusting the check interval do not increase available inodes and therefore do not fix the immediate issue.

Exam trap

The trap here is reading only the percentage in df -h and assuming block exhaustion, when the same command's inode column reveals the real constraint.

54
MCQeasy

Refer to the exhibit. The system administrator sees that /var/log is 93% full and the syslog file is nearly 2 GB. What is the most appropriate immediate action to free up disk space without losing any critical log data?

A.Run 'logrotate -f /etc/logrotate.conf' to force log rotation.
B.Increase the size of the /var/log partition using lvextend.
C.Delete /var/log/syslog and restart the syslog daemon.
D.Move /var/log/syslog to /tmp and create a symbolic link.
AnswerA

Forcing logrotate rotates the oversized syslog immediately, compressing or archiving it rather than deleting it, so disk space is reclaimed while the log content is preserved. This satisfies the stem's requirement not to lose critical log data.

Why this answer

'logrotate -f' forces an immediate rotation of all log files as defined in /etc/logrotate.conf, which compresses or archives the current syslog file (e.g., syslog becomes syslog.1) and creates a fresh empty log file. This frees disk space without deleting any data, as the rotated logs remain on disk until the configured retention policy removes them. It is the standard, safe immediate action for a nearly full /var/log partition.

Exam trap

LPI often tests the misconception that deleting or moving log files is acceptable, when in fact the correct immediate action is to use logrotate -f to safely rotate logs without data loss.

How to eliminate wrong answers

Option B is wrong because increasing the partition size with lvextend does not free up existing disk space; it only adds more capacity, which does not address the immediate 93% full condition and may not be possible without available free space in the volume group. Option C is wrong because deleting /var/log/syslog and restarting the syslog daemon permanently loses all current log data, which violates the requirement to not lose any critical log data. Option D is wrong because moving the syslog file to /tmp and creating a symbolic link does not free up space on /var/log (the file still occupies space elsewhere), and /tmp is often a tmpfs filesystem that may lose data on reboot, risking log loss.

55
Multi-Selectmedium

An administrator needs to gather detailed information about the partition table and filesystem geometry of /dev/sda before migrating data. Which TWO commands will display the partition layout of the disk? (Choose two.)

Select 2 answers
A.fdisk -l /dev/sda
B.lsblk -f /dev/sda
C.blkid /dev/sda
D.df -h /dev/sda
E.parted /dev/sda print
AnswersA, E

fdisk -l lists the partition table of the specified disk, showing partition numbers, start and end sectors, sizes, and type codes for both MBR and GPT layouts. It reads the on-disk partition table directly, so it reports the actual partition boundaries the administrator needs for migration planning. This is a standard, reliable way to inspect disk partitioning without modifying anything.

Why this answer

Both fdisk -l and parted print read and display the on-disk partition table, enumerating partitions with their start and end positions and the table type. The other tools focus on filesystem identity or capacity rather than partitioning: blkid and lsblk -f describe what filesystems exist, and df reports mount usage. For migration planning that requires partition geometry, the partition-table readers are the correct choices.

Exam trap

The trap here is treating lsblk or blkid as partition-layout tools, when they actually report filesystem and device attributes rather than the partition table itself.

56
MCQmedium

An administrator needs to mount an ISO image file /tmp/image.iso to the directory /mnt/iso. Which command should be used?

A.mount -o loop /tmp/image.iso /mnt/iso
B.mount -o ro /tmp/image.iso /mnt/iso
C.mount -t iso /tmp/image.iso /mnt/iso
D.mount /tmp/image.iso /mnt/iso
AnswerA

The loop option attaches the ISO as a loopback block device, allowing the kernel to read its ISO9660 filesystem and mount it at /mnt/iso. Without -o loop, mount would treat the file as a raw block device and fail.

Why this answer

The `-o loop` option tells the mount command to use a loop device, which is required to mount a file (like an ISO image) as if it were a block device. Without the loop option, mount expects a block device path, not a regular file.

Exam trap

The trap here is that candidates often forget the `-o loop` option and assume mount can directly handle a file path, or they confuse the read-only option (`-o ro`) with the loop option, thinking read-only is sufficient for ISO images.

How to eliminate wrong answers

Option B is wrong because `-o ro` only mounts the filesystem as read-only, but it does not enable loop device support, so mount will fail with an error like 'mount: /tmp/image.iso is not a block device'. Option C is wrong because `-t iso` is not a valid filesystem type; the correct type for ISO images is `iso9660` (or `udf`), and even with the correct type, the loop option is still required. Option D is wrong because without any options, mount expects a block device as the first argument, not a regular file, and will reject the ISO file.

57
Multi-Selectmedium

Which TWO statements about udev rules are correct? (Choose two.)

Select 2 answers
A.Custom udev rules should be placed in /etc/udev/rules.d/.
B.Udev rules are only applied at boot time.
C.Udev rules can be used to schedule periodic tasks via cron.
D.Rules can match on attributes such as vendor ID and product ID.
E.The 'udevadm verify' command tests rule syntax.
AnswersA, D

Placing custom rules in /etc/udev/rules.d/ satisfies the requirement for persistent, administrator-defined device naming that survives package upgrades. Files here are parsed before /usr/lib/udev/rules.d/, so local rules take precedence, and the directory is reserved for local administration rather than vendor-supplied defaults.

Why this answer

Option A is correct because locally administered custom udev rules belong in /etc/udev/rules.d/, which takes precedence over the distribution-supplied rules in /usr/lib/udev/rules.d/ and is the supported location for administrator-defined rules. Option D is correct because udev rules match devices using keys such as ATTRS{idVendor} and ATTRS{idProduct} (or ENV{ID_VENDOR_ID}/ENV{ID_MODEL_ID} from the hardware database), allowing rules to target specific USB vendor and product IDs. Option B is wrong because udev processes events dynamically whenever devices are added or removed at runtime, not only at boot.

Option C is wrong because udev is a device manager for the kernel device model and has no scheduling capability; periodic tasks are handled by cron or systemd timers. Option E is wrong because there is no 'udevadm verify' subcommand; syntax checking is done with 'udevadm test' or 'udevadm test-builtin', while 'udevadm control --reload' reloads rules.

Exam trap

The trap here is that candidates may confuse 'udevadm verify' with a real command, but the LPIC-1 exam tests knowledge of the actual udevadm subcommands, and 'verify' is not one of them.

58
MCQeasy

Which of the following commands displays the amount of free disk space on all mounted filesystems in a human-readable format?

A.df -i
B.df -h
C.du -sh
D.df -T
AnswerB

The -h flag makes df print sizes in powers of 1024 with human-readable suffixes (K, M, G), satisfying the human-readable requirement. Without it, df reports raw 1K blocks across all mounted filesystems, which is harder to interpret.

Why this answer

The `df -h` command displays disk space usage for all mounted filesystems with sizes in human-readable units (e.g., KB, MB, GB). The `-h` flag converts raw block counts into powers of 1024 with appropriate suffixes, making the output easy to interpret at a glance.

Exam trap

The trap here is that candidates often confuse `df -h` (free disk space) with `du -sh` (used space for a directory) or `df -i` (inode usage), because all three involve storage-related metrics but serve fundamentally different purposes.

How to eliminate wrong answers

Option A is wrong because `df -i` shows inode usage, not disk space; it reports the number of used and free inodes on each filesystem, which is a separate resource from data blocks. Option C is wrong because `du -sh` estimates the total disk space used by a specific directory or file (defaulting to the current directory), not free space across all mounted filesystems. Option D is wrong because `df -T` displays the filesystem type (e.g., ext4, xfs) in addition to disk usage, but does not enable human-readable formatting; it still outputs sizes in 1K blocks unless combined with `-h`.

59
MCQmedium

An administrator plans to back up the /home filesystem using dump. Which option to dump is required to perform a full backup?

A.-f /dev/st0
B.-u
C.-0
D.-1
AnswerC

Dump level 0 copies every inode and block regardless of prior dumps, producing a complete backup. Higher levels (1-9) are incremental, capturing only changes since the last lower-level dump, so -0 is required for the full backup the administrator plans.

Why this answer

The dump utility uses dump levels (0-9) to control backup depth. A level 0 dump performs a full backup of the specified filesystem, copying all files regardless of modification time. This is the required option for a complete backup of /home.

Exam trap

The trap here is that candidates confuse the -0 option with a generic flag or think -1 is the full backup because it is the lowest non-zero number, but dump levels start at 0 for full backups.

How to eliminate wrong answers

Option A is wrong because -f /dev/st0 specifies the output device (tape drive), not the backup level; it is optional and not required for a full backup. Option B is wrong because -u updates the /etc/dumpdates file with the backup timestamp, but does not control whether the backup is full or incremental. Option D is wrong because -1 specifies an incremental backup level 1, which only backs up files changed since the last lower-level dump (e.g., level 0), not a full backup.

60
MCQeasy

A technician is repairing a system and needs to mount the root filesystem from a different disk to /mnt/sysroot. The partition is /dev/sda2 with an ext4 filesystem. Which command should be used?

A.mount -o loop /dev/sda2 /mnt/sysroot
B.mount -a
C.mount -t ext4 /dev/sda2 /mnt
D.mount /dev/sda2 /mnt/sysroot
AnswerD

Mounting requires the device node and target directory only; ext4 is auto-detected, so no -t flag is needed. This command attaches /dev/sda2 at /mnt/sysroot, satisfying the requirement to mount the root filesystem from a different disk.

Why this answer

The `mount` command with the device and mount point as arguments automatically detects the filesystem type (e.g., ext4) and mounts the partition at the specified directory. This is the standard way to mount a root filesystem from a different disk for repair purposes.

Exam trap

The trap here is that candidates may confuse the `-o loop` option with mounting a partition, or assume that `-t ext4` is always required, when in fact `mount` auto-detects the filesystem type for common formats like ext4.

How to eliminate wrong answers

Option A is wrong because the `-o loop` option is used for mounting a file as a loop device (e.g., an ISO image), not a block device like `/dev/sda2`. Option B is wrong because `mount -a` mounts all filesystems listed in `/etc/fstab`, not a specific partition to a custom mount point. Option C is wrong because it specifies the mount point as `/mnt` instead of `/mnt/sysroot`, which does not match the required target directory.

61
MCQmedium

A server has a dedicated disk /dev/sdc that will store application logs. The administrator wants the filesystem to be checked automatically only after 30 mounts or 60 days, whichever comes first, and wants to reduce the reserved block percentage to 1 percent. Which single command accomplishes both changes on the existing ext4 filesystem?

A.dumpe2fs -c 30 -i 60d -m 1 /dev/sdc
B.e2fsck -c 30 -i 60d -m 1 /dev/sdc
C.tune2fs -c 30 -i 60d -m 1 /dev/sdc
D.mkfs.ext4 -c 30 -i 60d -m 1 /dev/sdc
AnswerC

tune2fs modifies ext2/ext3/ext4 superblock parameters on an existing filesystem. The -c option sets the mount count threshold, -i sets the interval between checks, and -m sets the reserved block percentage. All three requested changes are applied in one operation, making this the correct command.

Why this answer

Adjusting existing ext filesystem behavior is the job of tune2fs, which writes superblock fields such as maximum mount count, check interval, and reserved block percentage. Formatting tools would destroy data, and checking or reporting tools cannot alter policy. The single command combining -c, -i, and -m meets both requirements.

Exam trap

The trap here is reaching for mkfs.ext4 or e2fsck when the filesystem already exists and only superblock policy values need to change.

62
MCQmedium

A system administrator wants to install custom scripts that should be available to all users. The scripts are not part of any package and should be placed under the Filesystem Hierarchy Standard (FHS). Which directory is most appropriate?

A./var
B./opt
C./usr/local/bin
D./home
AnswerC

/usr/local/bin is reserved by the FHS for locally compiled or custom executables outside the package manager, exactly matching scripts that belong to no package. Placing them here keeps them on the default PATH for all users, satisfying the requirement that the scripts be globally available without distribution interference.

Why this answer

/usr/local/bin because the Filesystem Hierarchy Standard (FHS) designates /usr/local as the location for locally installed software not managed by the system's package manager. Placing custom scripts in /usr/local/bin ensures they are in the default PATH for all users, while keeping them separate from system binaries in /usr/bin and /bin.

Exam trap

The trap here is that candidates often confuse /opt with /usr/local, but /opt is designed for self-contained third-party application packages (each in its own subdirectory), not for individual scripts that need to be directly in the PATH.

How to eliminate wrong answers

Option A is wrong because /var is intended for variable data files such as logs, spools, and temporary files, not for executable scripts. Option B is wrong because /opt is reserved for add-on application software packages, typically installed in their own subdirectory tree, not for individual scripts meant to be directly executable from the PATH. Option D is wrong because /home contains user home directories and is not part of the default system PATH; scripts placed there would not be accessible to all users without explicit path configuration.

63
MCQmedium

Refer to the exhibit. An administrator wants to mount /dev/sda4 persistently by its UUID. Which line should be added to /etc/fstab?

A.UUID=abc-123 /mnt/data ext4 defaults 0 2
B.UUID=abc-123 /mnt/data ext4 noauto 0 2
C.LABEL=data /mnt/data ext4 defaults 0 2
D./dev/sda4 /mnt/data ext4 defaults 0 2
AnswerA

The UUID= form identifies the filesystem independently of device name ordering, which /dev/sda4 cannot guarantee across reboots. Field six set to 2 schedules fsck after root, and ext4 with defaults matches the filesystem, giving a persistent, correctly ordered mount.

Why this answer

It uses the UUID= syntax to identify the filesystem by its universally unique identifier, which is the persistent method requested. The mount point is /mnt/data, the filesystem type is ext4, the mount options are defaults, and the dump and fsck order values (0 and 2) are appropriate for a non-root filesystem. This line ensures the device is mounted automatically at boot regardless of device name changes.

Exam trap

The trap here is that candidates often choose the device path option (D) out of habit, forgetting that device names are not persistent, or they confuse the 'noauto' option (B) as a valid way to mount persistently, when in fact it prevents automatic mounting.

How to eliminate wrong answers

Option B is wrong because it uses the 'noauto' mount option, which prevents the filesystem from being mounted automatically at boot, contradicting the requirement for persistent mounting. Option C is wrong because it uses LABEL=data instead of UUID=abc-123; while LABEL can be used for persistent mounting, the question explicitly specifies mounting by UUID. Option D is wrong because it uses the device path /dev/sda4, which is not persistent and can change across reboots (e.g., if disks are added or removed), failing the requirement to mount by UUID.

64
MCQmedium

An administrator needs to create a new ext4 filesystem on /dev/sdb1 and wants to reserve 2% of the blocks for the root user. Which command should be used?

A.mkfs.ext4 -m 2 /dev/sdb1
B.tune2fs -m 2 /dev/sdb1
C.mke2fs -r 2 /dev/sdb1
D.mkfs.ext4 -R 2 /dev/sdb1
AnswerA

The `-m` flag on `mkfs.ext4` sets the percentage of filesystem blocks reserved for root, so `-m 2` reserves exactly 2%, satisfying the stem's constraint. It creates the ext4 filesystem on /dev/sdb1 in one step, unlike `tune2fs -m`, which only adjusts reservation on an existing filesystem.

Why this answer

The `-m` flag in `mkfs.ext4` specifies the percentage of filesystem blocks reserved for the root user (superuser). By default, ext4 reserves 5% of blocks; using `-m 2` reduces this to 2%, as required. This command creates a new ext4 filesystem on `/dev/sdb1` with the specified reserved block percentage.

Exam trap

The trap here is that candidates confuse `-m` (reserved block percentage) with `-r` (revision level) or assume `tune2fs` can be used to create a filesystem, when in fact `tune2fs` only modifies existing filesystems.

How to eliminate wrong answers

Option B is wrong because `tune2fs` modifies parameters on an existing ext2/3/4 filesystem, but the question asks to create a new filesystem; `tune2fs` cannot create a filesystem. Option C is wrong because `mke2fs -r 2` sets the filesystem revision level (e.g., revision 1 or 2), not the reserved block percentage; the correct flag for reserved blocks is `-m`. Option D is wrong because `mkfs.ext4 -R 2` is invalid; `-R` is not a recognized option in `mkfs.ext4` (the correct flag is `-m`), and this would likely produce an error or be ignored.

65
MCQeasy

Refer to the exhibit. How much unpartitioned space is available on /dev/sda?

A.256G
B.5.5G
C.6G
D.150G
AnswerB

Unpartitioned space is the gap between the end of the last partition and the disk's total capacity. Reading the partition table, the final partition ends at 5.5G short of the full device size, so that remainder is unallocated.

Why this answer

The output of `fdisk -l /dev/sda` shows partitions sda1 (0.5G), sda2 (100G), and sda3 (150G), summing to 250.5G. The total disk size is 256G, so the unpartitioned space is 256G - 250.5G = 5.5G. Candidates often misread the partition sizes or add them incorrectly, leading to wrong answers.

Exam trap

The trap is that candidates may misread the partition sizes from the exhibit or incorrectly sum them. The exhibit shows sda1=0.5G, sda2=100G, sda3=150G, totaling 250.5G, leaving 5.5G unpartitioned. Picking 6G comes from assuming all partitions are round numbers or misremembering the total.

How to eliminate wrong answers

Option A is wrong because 256G is the total disk size, not the unpartitioned space; it ignores that partitions already occupy 250 GB. Option C is wrong because 6G is the raw difference between total size and partition sum (256 - 250 = 6), but it fails to account for the extended partition's metadata overhead (e.g., extended boot record), which reduces usable unpartitioned space to about 5.5 GB. Option D is wrong because 150G is the size of a single partition (sda3), not the unpartitioned space; it likely confuses a partition's size with free space.

66
MCQeasy

A system administrator needs to locate the largest directories under /var to free up disk space. Which command is most appropriate?

A.df -h /var
B.find /var -size +100M
C.ls -lS /var
D.du -sk /var/* | sort -rn
AnswerD

du -sk reports each /var subdirectory's size in kilobytes without descending into individual files, and sort -rn orders them largest first. This directly identifies the biggest space consumers, satisfying the requirement to find the largest directories.

Why this answer

`du -sk /var/* | sort -rn` calculates the disk usage in kilobytes for each top-level item under /var, then sorts them numerically in reverse order, showing the largest directories first. This directly addresses the need to locate the largest directories to free up space, as `du` reports actual disk usage (including subdirectories) rather than file sizes.

Exam trap

The trap here is that candidates often confuse `df` (filesystem-level usage) with `du` (directory-level usage), or mistakenly think `ls -lS` can show directory sizes, when in fact `ls` only shows the size of the directory entry itself (typically 4 KB), not its contents.

How to eliminate wrong answers

Option A is wrong because `df -h /var` shows the total disk usage and free space on the filesystem mounted at /var, not the sizes of individual directories or files within it. Option B is wrong because `find /var -size +100M` finds files larger than 100 MB, not directories, and does not aggregate sizes of directory contents. Option C is wrong because `ls -lS /var` lists the immediate contents of /var sorted by file size, but it does not recurse into subdirectories and cannot show the total size of directories, which is needed to identify large directories.

67
Drag & Dropmedium

Order the steps to create and apply a file system permission using ACLs.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

ACLs require the filesystem to be mounted with the acl option, then setfacl applies rules, and getfacl verifies them.

68
MCQhard

A system administrator is troubleshooting a server where the /var partition is full, causing services to fail. The administrator deletes old log files in /var/log, but the available space does not increase. Which step should be taken next?

A.Run 'sync; echo 3 > /proc/sys/vm/drop_caches' to clear cache.
B.Remount the /var partition with the 'noatime' option.
C.Use 'lsof /var/log' to find processes holding deleted file handles, then restart those processes.
D.Run 'df -i' to check inode usage.
AnswerC

Deleting log files unlinks directory entries, but processes still holding open file descriptors keep the inodes allocated, so space is not reclaimed. lsof /var/log identifies those processes; restarting them releases the handles and frees the blocks.

Why this answer

When a file is deleted while a process still holds an open file descriptor to it, the file's data blocks are not freed until that process releases the handle. The `lsof /var/log` command identifies such processes, and restarting them forces the kernel to release the deleted inodes, thereby reclaiming the disk space. This is why option C is the correct next step.

Exam trap

The trap here is that candidates assume deleting files immediately frees space, but they overlook that processes can keep deleted files open, and they confuse memory caches (cleared by drop_caches) with disk space.

How to eliminate wrong answers

Option A is wrong because writing to `/proc/sys/vm/drop_caches` clears kernel page cache, dentries, and inode caches, which frees memory but does not affect disk space; the /var partition remains full. Option B is wrong because remounting with `noatime` prevents future access time updates, which can reduce write overhead but does not recover already consumed disk space. Option D is wrong because `df -i` checks inode usage (the number of files/directories), not block usage; the problem is the partition is full due to block exhaustion, not inode exhaustion.

69
MCQmedium

An administrator notices that a large file on an ext4 filesystem is taking up more disk space than expected based on its size. Which command would show the actual disk usage (block allocation) of the file?

A.ls -l
B.df -h
C.du -h
D.stat
AnswerC

du reports allocated blocks, including indirect blocks and filesystem overhead, so it reveals the real space consumed. ls -l shows only apparent file length, which explains why the file appears larger on disk than its logical size suggests.

Why this answer

(du -h) is correct because du (disk usage) reports the actual disk space consumed by a file, including allocated blocks, which can be larger than the file's logical size due to block size overhead, fragmentation, or sparse file handling. On ext4, the default block size is 4096 bytes, so a 1-byte file occupies 4096 bytes on disk, and du reflects this allocation.

Exam trap

The trap here is that candidates confuse logical file size (shown by ls -l) with actual disk block allocation, assuming they are identical, and overlook that du accounts for filesystem overhead like block size rounding and sparse file handling.

How to eliminate wrong answers

Option A (ls -l) is wrong because it shows the logical file size (st_size), not the actual disk blocks allocated; it does not account for block size overhead or sparse file holes. Option B (df -h) is wrong because it reports filesystem-wide free and used space, not per-file disk usage. Option D (stat) is wrong because while it displays the file's size and blocks allocated (in 512-byte units), it does not directly show human-readable disk usage like du does; stat is more for inode metadata, not a quick usage summary.

Ready to test yourself?

Try a timed practice session using only Devices Filesystems questions.