Courseiva

CCNA System Architecture Questions

72 questions · System Architecture topic · All types, answers revealed

1
MCQeasy

Which command shows the amount of free and used memory in the system, including swap?

A.top
B.free -h
C.df -h
D.vmstat
AnswerB

`free -h` reads `/proc/meminfo` and reports total, used and available RAM alongside swap usage, with the `-h` flag converting values into human-readable units. This directly satisfies the stem's requirement to display both free and used memory plus swap, unlike `df`, which reports filesystem space instead.

Why this answer

The `free -h` command displays the total, used, and free physical memory (RAM) and swap space in a human-readable format (e.g., GiB, MiB). The `-h` flag ensures output is scaled to appropriate units, making it the direct and correct tool for checking both memory and swap usage.

Exam trap

The trap here is that candidates may confuse `free` with `df` (disk free) or assume `top` provides a simpler memory summary, but only `free` directly and concisely shows both RAM and swap totals in a single, easy-to-read output.

How to eliminate wrong answers

Option A is wrong because `top` shows real-time process activity and memory usage but does not provide a concise summary of total free and used memory including swap; it focuses on per-process and dynamic system load. Option C is wrong because `df -h` reports disk filesystem usage (e.g., partitions and mount points), not memory or swap. Option D is wrong because `vmstat` reports virtual memory statistics, including swap activity, but its output is more granular and less immediately readable for a simple summary of free and used memory; it requires interpretation of columns like `swpd`, `free`, `buff`, and `cache`.

2
MCQeasy

A small office server running Ubuntu 20.04 experiences a gradual time drift. The system clock loses about 2 minutes per week. The hardware clock (RTC) is maintained by the motherboard battery and appears accurate when checked manually. The sysadmin wants to ensure the system clock stays synchronized automatically. Which single action should be taken? Options: A) Run 'timedatectl set-ntp true' to enable systemd-timesyncd, B) Add 'hwclock --hctosys' to /etc/rc.local, C) Install and configure the ntp package with a pool server, D) Use 'cron' to run ntpdate every minute.

A.Run 'timedatectl set-ntp true' to enable systemd-timesyncd
B.Add 'hwclock --hctosys' to /etc/rc.local
C.Install and configure the ntp package with a pool server
D.Use 'cron' to run ntpdate every minute
AnswerA

On Ubuntu 20.04, systemd-timesyncd is the default NTP client. Running 'timedatectl set-ntp true' activates it, which automatically synchronizes the system clock with NTP servers, correcting the gradual drift without needing additional packages or manual cron jobs. This is the simplest and most appropriate single action for automatic time sync on a modern systemd-based distribution.

Why this answer

On Ubuntu 20.04, systemd-timesyncd is the default NTP client. Running 'timedatectl set-ntp true' (option A) activates it, which automatically synchronizes the system clock with NTP servers, correcting the gradual drift without needing additional packages or manual cron jobs. This is the simplest and most appropriate single action for automatic time sync on a modern systemd-based distribution.

Exam trap

The trap here is that candidates may assume the full ntp package is always required for time synchronization, overlooking that systemd-timesyncd is the default and sufficient for basic NTP sync on modern Ubuntu systems.

How to eliminate wrong answers

Option A is wrong because installing and configuring the full ntp package is overkill for a small office server; systemd-timesyncd is already present and sufficient for basic NTP synchronization. Option B is wrong because adding 'hwclock --hctosys' to /etc/rc.local only sets the system clock from the hardware clock at boot, which does not correct ongoing time drift during operation. Option C is wrong because using cron to run ntpdate every minute is inefficient, can cause abrupt time jumps, and ntpdate is deprecated in favor of more gradual synchronization methods like systemd-timesyncd or ntpd.

3
MCQmedium

A Linux workstation appears to hang early in the boot process after the initramfs is loaded. The administrator wants to add kernel boot parameters temporarily from the GRUB 2 menu without making a permanent change. Which action should the administrator take?

A.At the GRUB menu, press e to edit the selected entry, append the parameters to the linux line, and press Ctrl+X or F10 to boot.
B.At the GRUB menu, press c to open the command line and run the normal command.
C.Boot normally, then use sysctl -w to apply the parameters and reboot.
D.Edit /etc/default/grub, add the parameters to GRUB_CMDLINE_LINUX, and reboot.
AnswerA

Pressing e at the GRUB 2 menu opens an editable view of the chosen entry, where the kernel command line on the linux line can be modified in memory. Booting with Ctrl+X or F10 uses those edits for that single boot only and does not persist them to disk, exactly matching the request for a temporary kernel parameter change to diagnose the hang.

Why this answer

GRUB 2 allows one-time modification of a boot entry from the menu. Pressing e opens the entry for editing, where the kernel command line can be appended, then Ctrl+X or F10 boots with those in-memory changes. Nothing is written to configuration files, so the modification applies only to that boot, which is ideal for testing parameters during troubleshooting.

Exam trap

The trap here is confusing the persistent configuration files and the GRUB command shell with the menu edit feature, when only editing the selected entry applies a temporary kernel parameter for a single boot.

4
MCQeasy

Which hardware component uses a unique address to identify itself on the network at the data link layer?

A.IP address
C.Hostname
D.Port number
AnswerB

The MAC address is a 48-bit identifier burned into the network interface card, used at the data link layer to distinguish frames between hosts on the same segment. It uniquely satisfies the stem's requirement for a hardware component addressing at layer 2.

Why this answer

The MAC address (Media Access Control) is a unique 48-bit identifier burned into the network interface controller (NIC) by the manufacturer. It operates at Layer 2 (data link layer) of the OSI model, enabling devices on the same local network segment to communicate directly using protocols like Ethernet or Wi-Fi.

Exam trap

The trap here is that candidates often confuse the MAC address with the IP address because both are used for network identification, but the question specifically asks for the data link layer, where only the MAC address (not the IP address) operates.

How to eliminate wrong answers

Option A is wrong because an IP address operates at Layer 3 (network layer) and is used for logical addressing and routing across networks, not for hardware identification at the data link layer. Option C is wrong because a hostname is a human-readable alias resolved to an IP address via DNS or local hosts files, and it has no role in data link layer addressing. Option D is wrong because a port number is a Layer 4 (transport layer) identifier used by TCP or UDP to distinguish application services on a host, not for hardware-level network identification.

5
MCQmedium

On a systemd-based system, which file is NOT used for system initialization?

A./etc/fstab
B./etc/systemd/system/default.target
C./etc/inittab
D./lib/systemd/system/sysinit.target
AnswerC

/etc/inittab belongs to the SysV init and Upstart era, where it defined runlevels and spawned getty processes. On a systemd-based system, initialisation is handled by units and targets, so inittab is ignored entirely. This satisfies the stem's constraint of identifying the file not used for system initialisation.

Why this answer

/etc/inittab is the configuration file used by the traditional SysV init system to define runlevels and control terminal getty processes. On a systemd-based system, systemd does not read /etc/inittab; instead, it uses unit files and targets to manage system initialization, making this file unused for that purpose.

Exam trap

The trap here is that candidates familiar with SysV init assume /etc/inittab is still relevant on modern Linux systems, but LPIC-1 tests the distinction between legacy and systemd initialization files.

How to eliminate wrong answers

Option A is wrong because /etc/fstab is still used by systemd (via systemd-fstab-generator) to mount filesystems during boot, so it is involved in system initialization. Option B is wrong because /etc/systemd/system/default.target is a symlink that defines the default boot target (e.g., multi-user.target or graphical.target) and is actively used by systemd to determine the initial system state. Option D is wrong because /lib/systemd/system/sysinit.target is a special target unit that systemd uses to synchronize early boot services and is a core part of the initialization process.

6
Multi-Selectmedium

A Linux server uses a systemd-based init and has several custom services. The administrator wants to inspect the runtime state and configuration of a unit named backup.service without starting or stopping it. Which TWO commands provide information about this unit? (Choose two.)

Select 2 answers
A.systemctl enable backup.service
B.systemctl restart backup.service
C.systemctl status backup.service
D.systemctl start backup.service
E.systemctl cat backup.service
AnswersC, E

systemctl status backup.service shows the unit's current active state, recent log lines, and key properties such as loaded and enabled status. It is a read-only inspection command that does not start or stop the service, so it directly satisfies the requirement to examine the unit's runtime state and configuration.

Why this answer

Inspecting a systemd unit without altering it calls for read-only commands. systemctl status shows the unit's active state, recent journal entries, and loaded properties, while systemctl cat prints the unit file and any drop-ins that define its effective configuration. Commands such as start, restart, and enable change state or configuration and therefore do not meet the requirement.

Exam trap

The trap here is treating systemctl enable as an inspection command, when it only creates boot-time symlinks and shows nothing about the unit's current runtime state.

7
MCQhard

After a system upgrade, the server fails to boot with the error: 'ERROR: Failed to mount the real root device.' The root filesystem is on an LVM logical volume. Which recovery step is most appropriate?

A.Boot from a live CD, chroot, and run 'update-initramfs -u -k all' to regenerate the initramfs with lvm2 support
B.Run 'lvchange -ay' to activate all LVs
C.Reinstall GRUB to the MBR
D.Use 'fsck' on the root LV
AnswerA

The upgrade rebuilt the initramfs without the lvm2 hook, so the kernel cannot activate the volume group before mounting root. Booting a live CD and running update-initramfs -u -k all regenerates it with lvm2 support, restoring the ability to assemble the logical volume at boot.

Why this answer

The error 'Failed to mount the real root device' after a system upgrade indicates the initramfs lacks the necessary LVM modules (e.g., lvm2) to activate and mount the root logical volume. Regenerating the initramfs with 'update-initramfs -u -k all' rebuilds it to include LVM support, ensuring the kernel can locate and mount the root filesystem during boot.

Exam trap

The trap here is that candidates confuse a missing initramfs module issue with a logical volume activation problem (Option B), but 'lvchange -ay' is only effective after the initramfs has loaded LVM support; without it, the kernel cannot even see the LVs to activate them.

How to eliminate wrong answers

Option B is wrong because 'lvchange -ay' activates all logical volumes, but this command must be run from a rescue environment (e.g., live CD) and does not address the missing LVM support in the initramfs; the kernel still cannot mount the root LV without proper modules. Option C is wrong because reinstalling GRUB to the MBR only fixes bootloader issues (e.g., missing or corrupted stage files), not the kernel's inability to mount the root filesystem due to missing LVM drivers. Option D is wrong because 'fsck' checks and repairs filesystem integrity, but the error occurs before the filesystem is even mounted; the root cause is the initramfs lacking LVM support, not filesystem corruption.

8
MCQeasy

A system administrator is troubleshooting a Linux server that fails to boot. The server has a software RAID 1 configuration using mdadm, with the root filesystem located on /dev/md0. During boot, the system halts with the following error: 'VFS: Unable to mount root fs on unknown-block(0,0)'. The admin verifies that the BIOS recognizes all disks and that the RAID array was properly assembled prior to the last shutdown. The system was working after a recent kernel update, but now fails. Which of the following actions is the most likely solution?

A.Use a live CD to run fsck on /dev/md0.
B.Rebuild the initramfs to include the mdadm module and the RAID metadata.
C.Check the /etc/fstab file for incorrect root device.
D.Reinstall the bootloader on the MBR.
AnswerB

A kernel update can produce an initramfs lacking the mdadm module, so the kernel cannot assemble /dev/md0 and reports unknown-block(0,0). Rebuilding initramfs with mdadm and RAID metadata satisfies the requirement to mount the root filesystem at boot.

Why this answer

After a kernel update, the new kernel may lack the necessary mdadm module or RAID metadata support in the initramfs. The error 'unknown-block(0,0)' indicates the kernel cannot find the root device because the initramfs does not contain the required RAID drivers or assembly instructions. Rebuilding the initramfs with the correct mdadm configuration ensures the kernel can assemble and mount /dev/md0 during boot.

Exam trap

The trap here is that candidates often confuse a root filesystem mount failure with filesystem corruption (fsck) or bootloader issues, but the specific 'unknown-block(0,0)' error points to a missing kernel module or initramfs problem after a kernel update.

How to eliminate wrong answers

Option A is wrong because fsck repairs filesystem corruption, but the error 'unknown-block(0,0)' indicates the kernel cannot locate the block device at all, not that the filesystem is damaged. Option C is wrong because /etc/fstab is read after the root filesystem is mounted; if the root device cannot be found, the system never reaches the point of parsing fstab. Option D is wrong because reinstalling the bootloader on the MBR addresses bootloader issues (e.g., GRUB stage 1), but the error occurs after the kernel is loaded and fails to mount root, indicating a missing driver or module in the initramfs.

9
MCQmedium

A technician must determine whether a Linux server's CPU supports hardware-assisted virtualization so the host can run KVM guests. The technician needs to inspect the processor flags exposed by the running kernel. Which command should be used?

A.lsmod
B.uname -a
C.lscpu
D.cat /proc/cpuinfo
AnswerD

The /proc/cpuinfo virtual file is generated by the kernel and reports per-processor details, including the flags line that enumerates capabilities such as vmx on Intel or svm on AMD. Searching that output for the virtualization flag gives definitive evidence that the CPU and kernel expose hardware-assisted virtualization, which is exactly the check the technician needs before enabling KVM guests.

Why this answer

CPU capability flags are exposed by the kernel through the virtual /proc filesystem. Reading /proc/cpuinfo shows the flags line for each logical processor, and the presence of the vendor-specific virtualization flag confirms the hardware supports KVM acceleration. Tools that report loaded modules or kernel build strings describe software state rather than the underlying processor features being investigated.

Exam trap

The trap here is assuming that a loaded kvm module or a friendly CPU summary tool proves the processor has virtualization extensions, when only the kernel-exposed CPU flags definitively confirm it.

10
MCQeasy

A system administrator notices that after updating the kernel, the system fails to boot. The administrator wants to boot the previous kernel. Which GRUB menu option should be selected?

A.Memory test
B.Advanced options for Ubuntu
C.Recovery mode
D.Boot from first hard disk
AnswerB

Selecting "Advanced options for Ubuntu" exposes the GRUB submenu listing every installed kernel version, including the previous one alongside its recovery mode entry. This satisfies the stem's constraint of booting the prior kernel after the update broke boot, since the default top-level entry points only at the newest kernel.

Why this answer

The 'Advanced options for Ubuntu' GRUB menu entry provides access to a submenu listing all installed kernel versions, allowing the administrator to select and boot the previous kernel. This is the standard method to revert to a known-good kernel after a failed update, as GRUB dynamically generates entries for each kernel found in /boot.

Exam trap

The trap here is that candidates may confuse 'Recovery mode' with a kernel version selector, but Recovery mode is a single-kernel boot option for troubleshooting, not a menu for choosing among multiple kernels.

How to eliminate wrong answers

Option A is wrong because 'Memory test' runs a diagnostic memory check (e.g., Memtest86+) and does not allow selecting a different kernel version. Option C is wrong because 'Recovery mode' boots a specific kernel with minimal services and a root shell, but it does not offer a choice of kernel versions; it is used for system repair, not kernel selection. Option D is wrong because 'Boot from first hard disk' bypasses the GRUB menu entirely and boots the default boot loader on the first disk, which would likely load the same problematic kernel.

11
MCQmedium

A Linux server has two hot-swappable SATA drives that are part of a software RAID 1 array. The administrator needs to replace one drive while the system is running, but first wants to verify the current status of the array to ensure it is not degraded. Which command will display the detailed status of the mdadm array?

A.cat /proc/mdstat
B.mdadm --detail /dev/md0
C.smartctl -a /dev/sda
D.fdisk -l /dev/sda
AnswerB

The mdadm --detail command displays comprehensive information about the specified array, including RAID level, array size, state (active/clean, degraded, etc.), UUID, and the status of each component device. This is exactly what the administrator needs to verify the array is not degraded and to confirm which drive can be safely replaced. It is the standard tool for detailed RAID inspection on Linux.

Why this answer

To verify the status of a software RAID array before replacing a drive, the administrator needs detailed information about the array's health and component devices. The mdadm --detail command provides this comprehensive view, including RAID level, state, and per-device status. This ensures the array is not already degraded and that the correct drive can be identified for replacement.

Other commands either show only summary information or focus on physical drives rather than the RAID logical device.

Exam trap

The trap here is assuming that /proc/mdstat provides all necessary details, but it only gives a summary and lacks the detailed component status needed for safe hot-swapping.

12
MCQhard

A server configured with UEFI firmware and GPT partitioning fails to boot after a GRUB package update. The administrator suspects the bootloader is not correctly installed. Which command should be used to reinstall GRUB to the EFI system partition?

A.grub2-install /dev/sda1
B.grub-mkconfig -o /boot/grub/grub.cfg
C.grub-install /dev/sda
D.grub-install --target=x86_64-efi --efi-directory=/boot/efi
AnswerD

On UEFI systems with GPT, GRUB's EFI binary must be written to the EFI System Partition. The --target=x86_64-efi flag selects the EFI platform and --efi-directory=/boot/efi specifies the ESP mount point, satisfying the stem's UEFI firmware and GPT partitioning constraint.

Why this answer

On a UEFI-based system with GPT partitioning, GRUB must be installed as an EFI application to the EFI System Partition (ESP). The `--target=x86_64-efi` flag specifies the EFI firmware target, and `--efi-directory=/boot/efi` points to the mount point of the ESP, ensuring the bootloader files (e.g., `grubx64.efi`) are placed in the correct EFI directory (e.g., `/boot/efi/EFI/GRUB/`).

Exam trap

The trap here is that candidates confuse `grub-install /dev/sda` (which works for BIOS/MBR systems) with the UEFI-specific command, or they mistakenly think regenerating the config file with `grub-mkconfig` reinstalls the bootloader.

How to eliminate wrong answers

Option A is wrong because `grub2-install /dev/sda1` targets a partition (e.g., `/dev/sda1`) rather than the disk device; GRUB installation for BIOS or EFI requires the whole disk (e.g., `/dev/sda`) or specific EFI parameters, and using a partition number is invalid. Option B is wrong because `grub-mkconfig -o /boot/grub/grub.cfg` only regenerates the GRUB configuration file from templates and does not install the bootloader to the disk or ESP; it cannot fix a missing or corrupted bootloader installation. Option C is wrong because `grub-install /dev/sda` without the `--target` and `--efi-directory` flags defaults to installing for BIOS/legacy boot (i386-pc), which writes to the Master Boot Record (MBR) and is incompatible with UEFI firmware that expects an EFI executable on the ESP.

13
MCQmedium

A Linux system administrator is tasked with setting up a new server that will host multiple virtual machines using KVM. The server has 64 GB of RAM and two physical CPUs, each with 8 cores (16 threads). The administrator needs to allocate resources efficiently. The VMs will have varying workloads. The administrator wants to ensure that the host system has enough resources for itself and that VMs can use all available CPU cores. Which approach should the administrator take to configure CPU allocation for the host and VMs?

A.Use QEMU emulation instead of KVM to reduce CPU overhead.
B.Pin all physical CPU cores to the VMs using virsh vcpupin, and leave no cores for the host.
C.Use CPU pinning to reserve two physical cores for the host and distribute the remaining cores among VMs using host-passthrough mode.
D.Overcommit CPU resources by assigning 32 vCPUs to each VM, relying on the hypervisor to schedule.
AnswerC

CPU pinning dedicates two physical cores to the host, guaranteeing its resources, while host-passthrough exposes remaining cores so VMs access all available CPU features. This matches the stem's dual constraints: host reservation plus full core availability.

Why this answer

It reserves two physical cores for the host system to ensure its stability and performance, while distributing the remaining cores among VMs using CPU pinning and host-passthrough mode. This approach allows VMs to access the full CPU feature set and all available cores efficiently, balancing host overhead with VM resource needs in a KVM environment.

Exam trap

The trap here is that candidates may assume overcommitting CPU resources is always safe (Option D) or that QEMU emulation is a performance improvement (Option A), when in fact KVM's hardware acceleration and proper pinning are critical for efficient virtualization.

How to eliminate wrong answers

Option A is wrong because QEMU emulation adds significant CPU overhead compared to KVM's hardware-assisted virtualization, which would degrade performance rather than reduce it. Option B is wrong because pinning all physical cores to VMs leaves no CPU resources for the host, causing the host to starve and potentially crash or become unresponsive. Option D is wrong because overcommitting CPU resources by assigning 32 vCPUs per VM (exceeding the total 32 threads) can lead to severe contention and performance degradation, as the hypervisor cannot efficiently schedule such an extreme overcommitment without proper resource limits.

14
MCQhard

A Linux server uses a custom udev rule to assign a persistent name to a USB-to-serial adapter. After a kernel update, the adapter is no longer recognized by its custom name, and the administrator finds that the rule file is still present. Which command should be used to reload the udev rules and trigger them for existing devices without rebooting?

A.udevadm info --query=all --name=/dev/ttyUSB0
B.systemctl restart systemd-udevd
C.udevadm monitor --kernel --property
D.udevadm control --reload-rules && udevadm trigger
AnswerD

udevadm control --reload-rules reloads the rules from /etc/udev/rules.d and /lib/udev/rules.d into the running udev daemon. udevadm trigger then replays kernel uevents for existing devices, causing the new rules to be applied. This combination applies rule changes immediately without a reboot, which is essential after modifying udev rules.

Why this answer

To apply modified udev rules to devices that are already connected, the rules must be reloaded into the udev daemon and then existing devices must be re-triggered. The command udevadm control --reload-rules performs the reload, and udevadm trigger replays events for all devices. Together they activate the new rule without requiring a reboot or physical reconnection.

Exam trap

The trap here is assuming that restarting the udev daemon or monitoring events is enough, overlooking that existing devices need an explicit trigger to be re-evaluated.

15
MCQhard

Refer to the exhibit. The system has multiple SAS drives attached to this controller, but one of them is not detected during boot. Which command is most likely to provide information about the device detection order?

A.cat /proc/scsi/scsi
B.lsblk
C.dmesg | grep -i scsi
D.lsscsi
AnswerC

The kernel ring buffer records SCSI and SAS device discovery, including host, target and LUN assignment order, as the controller probes each disk. Filtering dmesg for SCSI lines reveals which drives were detected and in what sequence, exposing the missing device.

Why this answer

The `dmesg` command displays kernel ring buffer messages, which include hardware detection and initialization logs during boot. By piping to `grep -i scsi`, you filter for SCSI-related messages, revealing the order in which devices were discovered and any errors for undetected drives. This is the most direct way to see why a specific SAS drive failed to appear.

Exam trap

The trap here is that candidates often pick `lsscsi` or `cat /proc/scsi/scsi` because they show SCSI devices, but they fail to realize those commands only show the final state, not the boot-time detection order or failure messages that `dmesg` provides.

How to eliminate wrong answers

Option A is wrong because `cat /proc/scsi/scsi` shows a static list of currently detected SCSI devices, not the boot-time detection order or failure details. Option B is wrong because `lsblk` lists block devices that are already recognized by the kernel, providing no information about the detection sequence or why a drive was missed. Option D is wrong because `lsscsi` displays a snapshot of SCSI devices currently visible to the system, similar to `/proc/scsi/scsi`, and does not reveal the boot-time probe order or errors.

16
Multi-Selectmedium

Which TWO of the following are valid methods to view kernel messages on a systemd-based system?

Select 2 answers
A.lsmod
B.journalctl -k
C.cat /var/log/syslog
D.grub-mkconfig
E.dmesg
AnswersB, E

journalctl -k filters the systemd journal to kernel-originated messages only, reading the persistent or volatile journal maintained by systemd-journald. On a systemd-based system this satisfies the requirement to view kernel messages without relying on the legacy ring buffer alone.

Why this answer

Option B (journalctl -k) is correct because on systemd-based systems the journal stores kernel messages, and the -k (or --dmesg) flag filters the journal to show only kernel-ring-buffer entries, making it a native systemd method to view kernel messages. Option E (dmesg) is correct because it directly reads and prints the kernel ring buffer, which contains kernel boot and runtime messages, and it remains valid on systemd systems. Option A (lsmod) is not correct because it only lists currently loaded kernel modules and does not display kernel log messages.

Option C (cat /var/log/syslog) is not correct as a systemd-specific kernel-message method because syslog files are produced by a syslog daemon (and may not even exist on all systemd systems), not by systemd's journal, so it is not a reliable systemd-based way to view kernel messages. Option D (grub-mkconfig) is not correct because it generates GRUB bootloader configuration and has nothing to do with viewing kernel messages.

Exam trap

The trap here is that candidates may think `dmesg` is the only valid method for kernel messages, overlooking that `journalctl -k` is equally valid on systemd-based systems, or they may confuse `lsmod` with kernel message viewing due to its association with kernel information.

17
Multi-Selectmedium

Which TWO commands can be used to set the default boot target (runlevel) in systemd?

Select 2 answers
A.ln -sf /lib/systemd/system/multi-user.target /etc/systemd/system/default.target
B.systemctl isolate multi-user.target
C.systemctl default multi-user.target
D.systemctl enable multi-user.target
E.systemctl set-default multi-user.target
AnswersA, E

Symlinking the desired target unit to /etc/systemd/system/default.target changes the default boot target, satisfying the requirement to set it persistently. systemd resolves this symlink at boot, so multi-user.target replaces the previous default. This mirrors what systemctl set-default performs, making it a valid command for the scenario.

Why this answer

Option E, `systemctl set-default multi-user.target`, is correct because it is the official systemd command that creates or replaces the `/etc/systemd/system/default.target` symlink to point at the desired target, thereby setting the default boot target persistently. Option A, `ln -sf /lib/systemd/system/multi-user.target /etc/systemd/system/default.target`, is also correct because it manually performs the same underlying operation that `set-default` does: replacing the `default.target` symlink so systemd boots into multi-user.target on next boot. Option B, `systemctl isolate multi-user.target`, only switches the running system to that target immediately without changing the persistent default.

Option C, `systemctl default multi-user.target`, is not a valid systemd command syntax for setting a default target. Option D, `systemctl enable multi-user.target`, only enables the unit for activation (creating wants symlinks) and does not change the default boot target.

Exam trap

The trap here is that candidates confuse `systemctl isolate` (which changes the current runlevel immediately) with `systemctl set-default` (which sets the persistent default), or they mistakenly think `systemctl enable` sets the default target when it only enables a unit for automatic startup.

18
MCQeasy

A system administrator runs the command `fdisk -l` and sees the following line: Disk /dev/sda: 1000 GB, 1000204886016 bytes, 1953525168 sectors Based on this output, which statement is true?

A.The disk has write protection enabled
B.The disk has 5 partitions
C.The disk is 1 TB
D.The disk uses GPT partitioning
AnswerC

The kernel reports the disk as 1000204886016 bytes, which is approximately one trillion bytes. Disk manufacturers quote decimal units, so this capacity is marketed and recognised as 1 TB, not 1 TiB, which would be roughly 1.1 trillion bytes.

Why this answer

The output from `fdisk -l` shows the total disk size as 1000 GB, which is 1 TB. Thus, option C is correct. The output does not provide information about write protection, partition count, or partition table type.

Exam trap

The trap here is that candidates might assume the disk has a specific partition table type (like GPT) or partition count based on common defaults, but the output only provides disk size and geometry, not partition details, leading to overinterpretation of the data.

How to eliminate wrong answers

Option A is wrong because write protection is typically indicated by a read-only flag or specific error messages (e.g., 'Read-only file system'), not by the disk size or partition table type shown in the exhibit. Option B is wrong because the exhibit does not list any partitions; it only shows the disk size, so claiming 5 partitions is unsupported by the evidence. Option D is wrong because GPT partitioning is identified by a protective MBR or a 'gpt' label in partition table output, and the exhibit does not provide any partition table information to confirm GPT usage.

19
MCQeasy

A junior admin is tasked with configuring network bonding on a Debian server with two Ethernet interfaces, eth0 and eth1. The goal is to provide link redundancy using active-backup mode. The admin edits /etc/network/interfaces and adds configuration for bond0 with slaves eth0 eth1, then runs 'ifup bond0'. However, the bond interface fails to come up and the error message indicates that the 'bond' kernel module is not loaded. The admin checks with 'lsmod | grep bonding' and finds no output. Which additional step is required to successfully bring up the bond interface? Options: A) Run 'modprobe bonding' before ifup, B) Use ifenslave directly after ifup, C) Reboot the system to load the module, D) Add 'auto bond0' in /etc/network/interfaces.

A.Run 'modprobe bonding' before ifup
B.Use ifenslave directly after ifup
C.Reboot the system to load the module
D.Add 'auto bond0' in /etc/network/interfaces
AnswerA

The bonding driver is built as a loadable module, and ifup does not auto-load it, so the bond0 interface cannot be created. Running modprobe bonding loads the module into the kernel before ifup, satisfying the missing-module constraint reported by lsmod.

Why this answer

The 'bond' kernel module must be loaded before the bonding interface can be created. Running 'modprobe bonding' loads the module into the kernel, making the bonding functionality available. Without this step, 'ifup bond0' fails because the kernel does not recognize the bonding driver.

Exam trap

The trap here is that candidates may think adding 'auto bond0' or rebooting will solve the module loading issue, but the kernel module must be explicitly loaded before the bonding interface can be created.

How to eliminate wrong answers

Option B is wrong because adding 'auto bond0' only configures the interface to start automatically at boot, but does not load the kernel module; the module must be loaded first. Option C is wrong because 'ifenslave' is a tool to attach slaves to an already existing bond interface, but the bond interface itself cannot be created without the bonding module. Option D is wrong because rebooting is unnecessary and inefficient; the module can be loaded dynamically with 'modprobe' without a reboot.

20
MCQhard

A minimal Linux system boots using a legacy BIOS with GRUB 2 installed in the MBR of /dev/sda. The administrator wants to install a new boot loader configuration that writes the boot code to the MBR and also places core.img in the gap between the MBR and the first partition. Which command accomplishes this?

A.grub-mkconfig -o /boot/grub/grub.cfg
B.grub-install /dev/sda1
C.update-grub
D.grub-install /dev/sda
AnswerD

On a BIOS/MBR system, running grub-install with the disk device as the target embeds the boot image in the MBR and writes core.img into the post-MBR gap, then installs modules under /boot/grub. This matches the administrator's requirement to update both the MBR boot code and the embedded core image for a legacy BIOS boot path.

Why this answer

Installing GRUB 2 for legacy BIOS boot requires writing code to the disk's master boot record and embedding the core image in the space before the first partition. Passing the whole disk device to the installer achieves both. Configuration generators such as grub-mkconfig or its wrapper only rebuild the menu file and never modify the MBR, and targeting a partition instead of the disk writes to the wrong location.

Exam trap

The trap here is treating menu-regeneration commands like update-grub as if they install the boot loader, when only the installer targeting the whole disk writes MBR boot code and embeds core.img.

21
MCQhard

After connecting a USB device, the system does not create a device node in /dev. Which command can be used to trigger udev to re-evaluate the device?

A.modprobe
B.udevadm control --reload
C.udevadm settle
D.udevadm trigger
AnswerD

udevadm trigger requests that udev re-run its rules for existing devices, replaying kernel uevents so device nodes in /dev are recreated. This directly addresses a missing node after USB connection, unlike udevadm info, which only queries.

Why this answer

The correct command is `udevadm trigger`. This command causes udev to re-evaluate all devices by simulating kernel uevents, which forces udev to process rules and create device nodes in /dev for devices that were missed or not properly initialized.

Exam trap

The trap here is confusing `udevadm trigger` with `udevadm control --reload`; candidates often think reloading rules alone will fix missing device nodes, but without re-triggering uevents, udev does not re-evaluate already-connected devices.

How to eliminate wrong answers

Option A is wrong because `modprobe` is used to load or unload kernel modules, not to trigger udev rule processing or device node creation. Option B is wrong because `udevadm control --reload` reloads the udev rules and configuration files but does not re-trigger uevents for existing devices. Option C is wrong because `udevadm settle` waits for the udev event queue to finish processing; it does not initiate new uevents or force device node creation.

22
Multi-Selecthard

Which THREE of the following are valid sources to configure GRUB?

Select 3 answers
A./boot/grub/menu.lst
B./etc/grub.conf
C./boot/grub/grub.cfg
D./etc/default/grub
E./etc/grub.d/
AnswersC, D, E

/boot/grub/grub.cfg is the generated GRUB 2 configuration file, read directly by GRUB at boot. It satisfies the stem's requirement for a valid configuration source, though it is produced by grub-mkconfig from /etc/default/grub and /etc/grub.d scripts, so manual edits are overwritten on regeneration.

Why this answer

Option C, /boot/grub/grub.cfg, is correct because it is the primary GRUB 2 configuration file that grub-mkconfig generates and that GRUB reads at boot time to build the menu. Option D, /etc/default/grub, is correct because it holds user-editable variables such as GRUB_TIMEOUT and GRUB_CMDLINE_LINUX that grub-mkconfig sources when regenerating grub.cfg. Option E, /etc/grub.d/, is correct because it contains the executable scripts (e.g., 00_header, 10_linux, 30_os-prober) whose output is assembled by grub-mkconfig into grub.cfg.

Option A, /boot/grub/menu.lst, is not a valid GRUB 2 source since menu.lst belongs to the legacy GRUB 1 configuration scheme. Option B, /etc/grub.conf, is likewise a legacy GRUB 1 file (often a symlink to menu.lst on older Red Hat systems) and is not used by GRUB 2.

Exam trap

The trap here is that candidates confuse GRUB Legacy files (`menu.lst` or `grub.conf`) with GRUB 2 files, or think `/etc/grub.conf` is a standard GRUB 2 configuration file, when in fact GRUB 2 uses `/etc/default/grub` and `/etc/grub.d/` as sources, with the generated output in `/boot/grub/grub.cfg`.

23
MCQmedium

A Linux workstation fails to boot and drops to a GRUB prompt. The administrator needs to inspect the available disks and partitions from within the GRUB environment before attempting recovery. Which command lists block devices and partitions recognized by GRUB?

A.ls
B.fdisk -l
C.parted -l
D.lsblk
AnswerA

In the GRUB shell, ls lists devices and partitions that GRUB recognizes, such as (hd0) and (hd0,gpt1). It is the GRUB-native way to inspect available disks and partitions before setting root and loading the kernel, making it the correct tool for this recovery step.

Why this answer

The GRUB shell provides its own command set, and ls enumerates devices and partitions that GRUB can see, such as (hd0,gpt1). Userspace tools like lsblk, fdisk, and parted are not available in that environment. Using ls lets the administrator identify the correct root device before loading the kernel or reinstalling the bootloader.

Exam trap

The trap here is assuming familiar Linux disk utilities work inside the GRUB shell, when GRUB only supports its own built-in commands such as ls.

24
MCQeasy

A technician needs to identify the hardware installed on a Linux workstation. The technician runs a command that prints a hierarchical tree of PCI devices showing vendor and device IDs, along with the kernel driver in use. Which command was most likely executed?

A.dmidecode -t memory
B.lsblk -f
C.lsusb -t
D.lspci -k
AnswerD

lspci -k lists PCI devices and, for each, shows the kernel driver and kernel modules in use. This matches the requirement for a hierarchical view of PCI devices with vendor and device IDs and driver information. It reads from /sys and /proc/bus/pci, making it the standard tool for PCI hardware inspection.

Why this answer

The lspci utility enumerates PCI devices, and its -k option adds the kernel driver and modules handling each device. That combination directly satisfies the need to see a PCI device tree with vendor/device IDs and driver information. Storage, USB, and DMI tools cover other hardware classes and do not provide the required PCI driver mapping.

Exam trap

The trap here is confusing tools that enumerate different buses or hardware classes, such as lsusb or lsblk, with the PCI-specific lspci command and its driver-listing option.

25
MCQmedium

A Linux system has two network interfaces: eth0 and eth1. The administrator wants to bond them for increased throughput. Which kernel module is required for bonding?

A.aggregation
B.bonding
C.team
D.bond
AnswerB

The bonding kernel module provides the driver that aggregates eth0 and eth1 into a single logical interface, enabling the throughput increase the administrator wants. Loading it is the prerequisite before any bond configuration can be applied.

Why this answer

The bonding driver in Linux allows multiple network interfaces to be aggregated into a single logical interface for increased throughput or redundancy. The correct kernel module is named 'bonding' (loaded via modprobe bonding or compiled into the kernel), which implements the IEEE 802.3ad Link Aggregation standard and other bonding modes. Option B is correct because 'bonding' is the exact module name used in the Linux kernel.

Exam trap

The trap here is that candidates confuse the interface name (bond0) with the kernel module name (bonding), or think 'team' is a synonym for bonding, when in fact they are separate technologies with different kernel modules.

How to eliminate wrong answers

Option A is wrong because 'aggregation' is a generic term for combining links, not a specific Linux kernel module; the actual module is 'bonding'. Option C is wrong because 'team' refers to the libteam project, which is a separate user-space-based teaming solution that uses the 'team' kernel module, not the standard bonding driver. Option D is wrong because 'bond' is a common abbreviation but not the exact kernel module name; the module is loaded as 'bonding' (e.g., modprobe bonding), and the resulting interface is named bond0, bond1, etc.

26
MCQmedium

An administrator wants to add a kernel parameter 'quiet splash' to the default boot entry. Which file should be edited?

A./etc/default/grub
B./etc/grub.d/00_header
C./etc/grub.conf
D./boot/grub/grub.cfg
AnswerA

Editing `/etc/default/grub` sets the `GRUB_CMDLINE_LINUX_DEFAULT` variable, which supplies kernel parameters to the default boot entry. This satisfies the requirement to add `quiet splash` persistently. After editing, run `update-grub` to regenerate `/boot/grub/grub.cfg`, since GRUB reads the generated configuration at boot, not this file directly.

Why this answer

The correct file to edit is /etc/default/grub because it is the main configuration file for GRUB 2 where kernel boot parameters like 'quiet splash' are defined in the GRUB_CMDLINE_LINUX_DEFAULT variable. After editing this file, the administrator must run update-grub (or grub-mkconfig) to regenerate the actual boot configuration file /boot/grub/grub.cfg.

Exam trap

The trap here is that candidates often confuse the auto-generated /boot/grub/grub.cfg (option D) with the source configuration file, or mistakenly think the legacy /etc/grub.conf (option C) is still used in GRUB 2 environments.

How to eliminate wrong answers

Option B is wrong because /etc/grub.d/00_header is a script that generates part of the GRUB 2 configuration, not a file where kernel parameters are directly set; editing it would be overwritten on updates and is not the intended method. Option C is wrong because /etc/grub.conf is a legacy file used by GRUB Legacy (version 0.97) and is not the standard location for GRUB 2 on modern Linux distributions. Option D is wrong because /boot/grub/grub.cfg is the auto-generated boot configuration file; editing it directly is discouraged as changes are overwritten by update-grub and it is not the source of truth for kernel parameters.

27
Multi-Selectmedium

A system administrator is troubleshooting a server that takes a long time to boot. The administrator wants to identify which systemd units are slowing down the boot process. Which TWO of the following commands can be used to analyze boot performance? (Choose two.)

Select 2 answers
A.systemd-analyze critical-chain
B.systemctl list-units --state=failed
C.journalctl -b -p err
D.systemd-analyze blame
E.dmesg | grep -i 'time'
AnswersA, D

systemd-analyze critical-chain displays a tree of units that are on the critical path to reaching the default target, highlighting dependencies that delay boot. It shows the time spent waiting for each unit in the chain, helping pinpoint bottlenecks in the boot sequence.

Why this answer

The systemd-analyze suite provides dedicated subcommands for boot performance. blame ranks units by initialization time, and critical-chain shows the dependency tree that determines total boot time. These tools directly measure and display timing data, unlike log inspection or unit state listing, which focus on errors or failures rather than duration.

Exam trap

The trap here is confusing error diagnosis tools with performance analysis tools, assuming that checking logs or failed units will reveal slow boot causes.

28
MCQmedium

The system administrator wants to add a new swap partition on /dev/sdb2. After creating the partition, which command should be used to initialize it as swap?

A.mkfs.ext4 /dev/sdb2
B.fsck /dev/sdb2
C.mkswap /dev/sdb2
D.swapon /dev/sdb2
AnswerC

mkswap writes the swap signature and UUID onto /dev/sdb2, initialising the partition so the kernel can use it as swap space. This satisfies the requirement to prepare the newly created partition before swapon activates it or an /etc/fstab entry mounts it.

Why this answer

The `mkswap` command is specifically designed to initialize a partition or file as a swap area by writing a swap signature (UUID and swap superblock) to the device. After creating the partition, you must run `mkswap /dev/sdb2` to set it up for use as swap before activating it with `swapon`.

Exam trap

The trap here is that candidates often confuse `swapon` (which activates swap) with `mkswap` (which initializes it), mistakenly thinking `swapon` can both prepare and enable the swap area.

How to eliminate wrong answers

Option A is wrong because `mkfs.ext4` creates an ext4 filesystem, which is a standard data filesystem, not a swap area; using it would overwrite the partition with filesystem metadata, making it unusable as swap. Option B is wrong because `fsck` checks and repairs an existing filesystem, but it cannot initialize a partition as swap and would fail on a partition without a recognized filesystem. Option D is wrong because `swapon` activates an already-initialized swap area; it cannot initialize a partition that has not been set up with `mkswap` first.

29
Multi-Selecthard

A technician is diagnosing a server that fails to reach the expected multi-user target. The technician wants to gather evidence about kernel ring buffer messages and the systemd journal for the current boot. Which TWO commands provide this diagnostic information? (Choose two.)

Select 2 answers
A.journalctl -b
B.dmesg
C.systemctl status
D.uptime
E.last reboot
AnswersA, B

journalctl -b displays journal entries recorded since the current boot, aggregating kernel and service messages with timestamps and unit context. This lets the technician trace which units failed or timed out before the multi-user target, making it the primary tool for systemd boot diagnostics alongside the kernel ring buffer.

Why this answer

Kernel and service boot messages live in two complementary places on a systemd host. The kernel ring buffer, read with dmesg, holds low-level hardware and driver messages from early boot. The journal, queried with journalctl -b for the current boot, aggregates kernel and unit messages with timestamps and context.

Together they give the technician the evidence needed to find why the multi-user target was not reached.

Exam trap

The trap here is reaching for status or accounting commands like uptime, last reboot, or a bare status call, when actual boot diagnostics require reading the kernel ring buffer and the current-boot journal.

30
Multi-Selecthard

A Linux administrator is troubleshooting a server that intermittently fails to detect a newly installed network card. The administrator suspects the kernel is not loading the correct driver automatically. Which TWO commands should be used to identify the PCI device and then load the appropriate kernel module manually? (Choose two.)

Select 2 answers
A.lspci -nn
B.rmmod
C.ifconfig -a
D.lsusb -v
E.modprobe
AnswersA, E

lspci -nn lists PCI devices with numeric vendor and device IDs, which are essential for identifying an unrecognized network card. The numeric IDs can be matched against driver aliases or the pci.ids database to determine the correct module. This is the first step before loading a driver manually.

Why this answer

To resolve an undetected PCI network card, the administrator must first identify the device with lspci -nn to obtain numeric vendor and device IDs, then load the matching driver with modprobe. This sequence confirms the hardware presence and activates the correct kernel module, after which the interface should appear. USB inspection, interface listing, and module removal do not address a missing PCI driver.

Exam trap

The trap here is reaching for interface-level tools like ifconfig or unrelated buses like USB when the root problem is a PCI device whose kernel driver has not been loaded.

31
MCQmedium

A technician is troubleshooting a system that fails to boot with the error 'Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. What is the most likely cause?

A.The init binary is missing or corrupted.
B.The root filesystem is corrupted and needs fsck.
C.The kernel lacks the necessary driver for the storage controller.
D.The boot loader is not installed correctly.
AnswerC

The panic occurs because the kernel cannot access the root filesystem, typically when the storage controller driver is built as a module absent from the initramfs. Without that driver, the kernel sees no block device, producing unknown-block(0,0).

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates that the kernel cannot locate or access the root filesystem. This typically occurs because the kernel lacks the necessary driver (module) for the storage controller (e.g., SATA, SCSI, NVMe) that the root device is connected to, so it cannot read the partition table or mount the root filesystem.

Exam trap

The trap here is that candidates often confuse a root filesystem corruption error with a missing storage driver error, because both can prevent booting, but the specific 'unknown-block(0,0)' message uniquely points to the kernel's inability to identify the block device, not a filesystem issue.

How to eliminate wrong answers

Option A is wrong because a missing or corrupted init binary would cause a different error, such as 'Kernel panic - not syncing: No init found' or 'Failed to execute /sbin/init', not a VFS mount failure on unknown-block(0,0). Option B is wrong because a corrupted root filesystem would typically produce filesystem-specific errors (e.g., 'EXT4-fs error') or a kernel panic with a different message, not the unknown-block(0,0) error which indicates the device itself is unrecognized. Option D is wrong because an incorrectly installed boot loader would prevent the kernel from being loaded at all (e.g., 'Missing operating system' or 'GRUB error'), not cause the kernel to fail mounting the root filesystem after it has already started executing.

32
MCQeasy

An administrator needs to inspect the hardware inventory of a server, including details about the motherboard, BIOS, and memory banks, in a structured way. Which command provides this information by reading from the DMI/SMBIOS data?

A.dmidecode
B.lsusb
C.lspci
D.lshw
AnswerA

dmidecode reads the SMBIOS/DMI table presented by the firmware and decodes it into readable sections describing the BIOS, system, baseboard, chassis, processors, and memory devices. Because the administrator wants structured motherboard, firmware, and memory-bank details, this is the correct tool; it requires root privileges to access the raw table and report the full inventory.

Why this answer

The DMI/SMBIOS table is firmware-provided data describing the physical platform. dmidecode decodes that table directly, yielding sections for BIOS, system, baseboard, and memory devices including individual slots. Commands that enumerate buses such as PCI or USB describe attached devices instead, and general-purpose inventory tools aggregate data rather than decoding the firmware table itself.

Exam trap

The trap here is confusing bus-enumeration commands like lspci or lsusb with firmware-table decoders, when only the DMI/SMBIOS reader exposes motherboard, BIOS, and memory-bank details.

33
MCQeasy

Which directory contains information about hardware devices in a hierarchical structure, such as PCI devices and USB devices?

A./sys
B./dev
C./etc
D./proc
AnswerA

/sys is the sysfs pseudo-filesystem, exposing kernel objects as directories and attributes, including PCI and USB device hierarchies. Unlike /dev, which holds device nodes, or /proc, which reports processes and kernel parameters, sysfs is specifically structured for enumerating hardware topology.

Why this answer

The /sys directory (sysfs) is a virtual filesystem that exports information about hardware devices, drivers, and kernel objects in a hierarchical structure. It organizes devices by their bus type (e.g., PCI, USB) and provides detailed attributes such as vendor IDs, device IDs, and power management states, making it the correct location for querying hardware topology.

Exam trap

The trap here is that candidates confuse /proc (which also contains some hardware info like /proc/cpuinfo) with /sys, but /proc lacks the structured, hierarchical device topology that sysfs provides for buses like PCI and USB.

How to eliminate wrong answers

Option B (/dev) is wrong because it contains device special files (e.g., /dev/sda, /dev/ttyUSB0) for accessing hardware via block or character I/O, not a hierarchical representation of device relationships. Option C (/etc) is wrong because it stores system configuration files (e.g., /etc/fstab, /etc/ssh/sshd_config), not dynamic hardware information. Option D (/proc) is wrong because it primarily exposes process and kernel runtime data (e.g., /proc/cpuinfo, /proc/meminfo) in a flat or process-centric structure, not a hierarchical device tree.

34
MCQeasy

The administrator wants the sshd service to start automatically at boot. Which command should be used?

A.systemctl start sshd.service
B.systemctl daemon-reload
C.systemctl set-default multi-user.target
D.systemctl enable sshd.service
AnswerD

systemctl enable creates the symlink in the multi-user.target.wants directory, so systemd starts sshd automatically during boot. This satisfies the requirement for automatic startup, whereas systemctl start only launches the service for the current session and does not persist across reboots.

Why this answer

The `systemctl enable sshd.service` command creates the necessary symlinks in the systemd unit configuration directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) so that the sshd service is automatically started when the system boots into its default target. This is the correct way to enable a service to start at boot in a systemd-based Linux distribution.

Exam trap

The trap here is confusing `systemctl start` (immediate, one-time activation) with `systemctl enable` (persistent boot-time activation), leading candidates to choose option A when the question asks for automatic startup at boot.

How to eliminate wrong answers

Option A is wrong because `systemctl start sshd.service` only starts the service immediately in the current session; it does not configure it to start automatically at boot. Option B is wrong because `systemctl daemon-reload` reloads the systemd manager configuration after unit files have been changed, but it does not enable or disable any service for boot-time startup. Option C is wrong because `systemctl set-default multi-user.target` changes the default systemd target (runlevel) that the system boots into, but it does not enable a specific service like sshd to start at boot.

35
MCQmedium

Which command can be used to check whether a specific kernel module is currently loaded?

A.modinfo <module>
B.lsmod | grep <module>
C.depmod -a
D.insmod <module>
AnswerB

lsmod reads /proc/modules and lists every currently loaded module with size and usage count. Piping to grep filters that output for the named module, directly answering whether it is loaded — unlike modprobe, which loads modules rather than reporting state.

Why this answer

`lsmod` lists all currently loaded kernel modules by reading the `/proc/modules` file, and piping its output through `grep` filters for the specific module name. This directly shows whether the module is loaded in the running kernel, which is the exact requirement of the question.

Exam trap

The trap here is that candidates confuse `modinfo` (which shows module information from disk) with `lsmod` (which shows runtime load status), leading them to incorrectly select option A.

How to eliminate wrong answers

Option A is wrong because `modinfo` displays metadata about a kernel module (such as description, author, and parameters) from the module file itself, but it does not check whether the module is currently loaded into the kernel. Option C is wrong because `depmod -a` generates dependency files (modules.dep) for all modules in the kernel tree, but it does not report on the current load status of any module. Option D is wrong because `insmod` is used to insert (load) a module into the kernel, not to check if it is already loaded; attempting to load an already-loaded module will typically fail with an error like 'File exists'.

36
Multi-Selectmedium

Which TWO commands can display the UUID of block devices?

Select 2 answers
A.blkid
B.lsblk -f
C.df -T
D.fdisk -l
E.parted /dev/sda print
AnswersA, B

blkid scans block devices and prints their attributes, including the filesystem UUID and TYPE, straight from the superblock. It reports UUIDs for all detected devices by default, satisfying the requirement to display block device UUIDs.

Why this answer

Option A, blkid, is correct because it directly queries block-device metadata and prints each device's UUID (along with TYPE and LABEL) by reading the filesystem superblock, e.g. /dev/sda1: UUID="..." TYPE="ext4". Option B, lsblk -f, is correct because the -f (--fs) flag adds filesystem information columns including UUID, FSTYPE, LABEL, and mountpoint for each block device in a tree view. Option C, df -T, only reports filesystem type, size, and usage per mountpoint, not UUIDs.

Option D, fdisk -l, lists partition tables, sizes, and types but does not display filesystem UUIDs. Option E, parted /dev/sda print, shows the partition table, geometry, and partition types, but not filesystem UUIDs.

Exam trap

The trap here is that candidates confuse commands that display partition table information (like `fdisk` and `parted`) with commands that display filesystem metadata (like `blkid` and `lsblk -f`), leading them to select options that show partition layout but not UUIDs.

37
MCQeasy

Which command displays information about currently loaded kernel modules?

A.insmod
B.modinfo
C.lsmod
D.modprobe -l
AnswerC

`lsmod` reads `/proc/modules` and lists every kernel module currently loaded, showing name, size and usage count. It directly satisfies the stem's requirement for loaded-module information, unlike `modinfo`, which describes a module file's metadata, or `insmod`, which inserts one.

Why this answer

The `lsmod` command reads the `/proc/modules` file to display a list of all currently loaded kernel modules, showing their name, size, usage count, and dependent modules. This is the standard tool for querying the current module state in the Linux kernel.

Exam trap

The trap here is that candidates confuse `lsmod` (list loaded modules) with `modinfo` (show module metadata) or `modprobe -l` (list available modules), because all three commands relate to kernel modules but serve distinct purposes.

How to eliminate wrong answers

Option A is wrong because `insmod` is used to insert a kernel module into the running kernel, not to display information about loaded modules. Option B is wrong because `modinfo` displays metadata (such as description, author, and parameters) from a module file, not a list of currently loaded modules. Option D is wrong because `modprobe -l` is a deprecated option that listed available module files in the module tree, not currently loaded modules; modern `modprobe` does not support `-l` and it was never used to show loaded modules.

38
MCQeasy

Which directory contains the kernel modules for the currently running kernel?

A./boot
B./etc/modprobe.d
C./usr/src
D./lib/modules/$(uname -r)
AnswerD

Kernel modules are stored under /lib/modules, with a subdirectory named after the running kernel's release version. Using $(uname -r) resolves that exact version dynamically, satisfying the stem's constraint that the path must reference the currently running kernel.

Why this answer

The kernel modules for the currently running kernel are stored in /lib/modules/$(uname -r). The uname -r command returns the exact kernel release version, and the corresponding directory contains all loadable kernel modules (.ko files) compiled for that specific kernel. This is the standard location used by the kernel and tools like modprobe and insmod to locate and load modules.

Exam trap

The trap here is that candidates confuse the location of kernel modules with the kernel image itself (/boot) or with configuration files (/etc/modprobe.d), failing to recognize that modules are version-specific and stored under /lib/modules.

How to eliminate wrong answers

Option A is wrong because /boot contains the kernel image (vmlinuz), initramfs, and bootloader configuration files, not the kernel modules. Option B is wrong because /etc/modprobe.d contains configuration files for modprobe (e.g., aliases, blacklists, options), not the actual module binaries. Option C is wrong because /usr/src typically contains kernel source code or headers, not compiled modules; modules are built from source but stored separately in /lib/modules.

39
MCQeasy

A technician needs to output only the kernel release number. Which command should be used?

A.cat /proc/version
B.uname -r
C.dmesg | head -1
D.lsmod
AnswerB

`uname -r` prints just the kernel release string, such as 6.8.0-45-generic, satisfying the requirement to output only the kernel release number. Other `uname` flags return different fields: `-a` shows everything, `-s` the kernel name, and `-v` the build version, so none isolates the release.

Why this answer

The `uname -r` command specifically prints the kernel release number (e.g., '5.10.0-28-amd64') by querying the `utsname` system call. This is the standard, portable way to retrieve only the kernel release string without additional system information.

Exam trap

The trap here is that candidates confuse `/proc/version` (which shows the full version string) with a command that outputs only the release number, or they assume `dmesg` output is consistent across all systems.

How to eliminate wrong answers

Option A is wrong because `cat /proc/version` outputs the full version string including the kernel release, compiler version, and build timestamp, not just the release number. Option C is wrong because `dmesg | head -1` shows the first line of the kernel ring buffer, which typically includes the kernel version and build info but is not guaranteed to be just the release number and may vary by system or boot. Option D is wrong because `lsmod` lists loaded kernel modules, not the kernel release number.

40
MCQmedium

A server with a udev rule fails to consistently assign a persistent network interface name. What is the most likely cause?

A.The rule uses an incorrect operator.
B.The BIOS device name is configured incorrectly.
C.The kernel module for the NIC is not loaded.
D.The network interface's MAC address is not unique or changes.
AnswerD

udev derives persistent names from stable attributes such as MAC address. If the MAC is duplicated, randomised or changes between boots, the rule matches different devices or none, producing inconsistent naming. Non-unique or volatile MAC addresses are the usual root cause.

Why this answer

Persistent network interface names in Linux rely on udev rules that match attributes like MAC address. If the MAC address is not unique (e.g., due to a virtual machine or cloned NIC) or changes (e.g., after hardware replacement or driver update), the rule will fail to consistently identify the interface, causing the name assignment to be unpredictable.

Exam trap

The trap here is that candidates assume udev rules always work if the syntax is correct, overlooking that dynamic or non-unique MAC addresses undermine the stability of the matching attribute.

How to eliminate wrong answers

Option A is wrong because an incorrect operator (e.g., using '==' instead of '!=') would cause a syntax error or mis-match, but the question describes inconsistent assignment, not a complete failure; the rule still runs but the matching attribute is unreliable. Option B is wrong because BIOS device names (like 'eno1') are a naming scheme, not a cause of udev rule failure; incorrect BIOS configuration might affect the name format but does not prevent consistent assignment if the rule uses a stable attribute. Option C is wrong because if the kernel module for the NIC were not loaded, the interface would not appear at all, leading to a persistent failure rather than inconsistent naming.

41
MCQhard

A Linux server has a USB serial adapter that is sometimes detected as /dev/ttyUSB0 and sometimes as /dev/ttyUSB1 after reboot. An administrator wants to create a udev rule that always assigns the name /dev/ttyUSB-radio to this specific adapter based on its serial number. Which udev rule syntax should be used?

A.KERNEL=="ttyUSB*", ATTR{idVendor}=="0403", SYMLINK="ttyUSB-radio"
B.SUBSYSTEM=="tty", ATTRS{serial}=="A50285BI", SYMLINK+="ttyUSB-radio"
C.SUBSYSTEM=="usb", ATTR{serial}=="A50285BI", NAME="ttyUSB-radio"
D.ACTION=="add", SUBSYSTEM=="tty", RUN+="/bin/ln -s /dev/%k /dev/ttyUSB-radio"
AnswerB

This rule matches the tty subsystem and the device's serial attribute, then creates a persistent symbolic link named ttyUSB-radio. Using SYMLINK+ adds a link without removing existing ones, and ATTRS matches attributes of the device or its parents, which is appropriate for USB serial adapters whose serial number appears on the USB device.

Why this answer

A reliable udev rule for a USB serial adapter must match the tty subsystem and a unique attribute such as the adapter's serial number, then create a persistent symlink. ATTRS{serial} searches the device and its parent devices, which is where USB serial numbers are exposed. SYMLINK+ adds the link without disturbing other symlinks, ensuring the adapter is always reachable at /dev/ttyUSB-radio.

Exam trap

The trap here is matching on a non-unique attribute like vendor ID or using a USB subsystem rule, which either affects multiple devices or fails to name the tty node correctly.

42
MCQmedium

A Linux administrator needs to determine which kernel modules are currently loaded on a running system. The administrator also wants to see the module dependencies and the use count for each module. Which command should be used?

A.lsmod
B.depmod
C.modprobe -l
D.modinfo
AnswerA

lsmod reads /proc/modules and prints the currently loaded modules along with their size, use count, and dependencies. This directly matches the requirement to see loaded modules with dependencies and use counts. It is the standard tool for verifying whether a module such as a filesystem or network driver is active.

Why this answer

lsmod queries the kernel's loaded module list by reading /proc/modules and presents each module with its memory size, use count, and dependencies. That output lets an administrator confirm whether a needed driver is active and whether it is in use. Tools like modinfo and depmod operate on module files and metadata, not on the runtime state of loaded modules.

Exam trap

The trap here is confusing commands that inspect module files and metadata, such as modinfo or depmod, with the command that reports modules currently loaded in the running kernel.

43
MCQhard

Refer to the exhibit. A Linux system fails to boot with a kernel panic. The dmesg output shows the disk is detected and partitions are recognized. Which of the following is the most likely cause of the kernel panic?

A.The root filesystem cannot be mounted because the root= kernel parameter points to a non-existent or incorrect device.
B.The kernel module for the SATA controller is missing from the initramfs.
C.The SATA controller is not supported by the kernel.
D.The disk has bad sectors causing read errors during boot.
AnswerA

Kernel panic after disk and partition detection indicates the kernel cannot mount the root filesystem. An incorrect root= parameter points to a non-existent device, so the kernel halts with a panic once it fails to locate the root filesystem.

Why this answer

A is correct because the kernel panic occurs after the disk and partitions are detected, indicating the kernel can see the hardware but cannot mount the root filesystem. The most common cause is an incorrect or missing `root=` kernel parameter in the bootloader configuration (e.g., GRUB), which specifies the root device (e.g., `/dev/sda1` or `UUID=...`). If this parameter points to a non-existent or wrong partition, the kernel cannot pivot to the root filesystem, leading to a panic.

Exam trap

The trap here is that candidates see the disk is detected and assume hardware is fine, then incorrectly blame the SATA controller or initramfs, missing the subtle point that the kernel panic occurs specifically because the root filesystem cannot be mounted due to a misconfigured `root=` parameter.

How to eliminate wrong answers

Option B is wrong because if the SATA controller module were missing from the initramfs, the disk would not be detected at all, but the dmesg output shows the disk is detected and partitions are recognized. Option C is wrong because the SATA controller is clearly supported by the kernel, as the disk is detected and partitions are recognized, contradicting a lack of support. Option D is wrong because bad sectors causing read errors would typically produce I/O errors or filesystem corruption messages, not a kernel panic at the stage where the root filesystem cannot be mounted; the panic occurs before any filesystem read attempts.

44
MCQeasy

A Linux system fails to boot after installing a new kernel. Which step should be taken first to recover the system?

A.Edit GRUB configuration at boot to select the old kernel
B.Reinstall the original kernel using a live CD
C.Boot into single-user mode to fix the kernel
D.Use the rescue mode from installation media
AnswerA

Selecting the previous kernel from the GRUB menu at boot bypasses the faulty new kernel, restoring a bootable system immediately. This is the fastest recovery step, since the old kernel and its modules remain intact on disk, allowing later diagnosis of the new kernel.

Why this answer

When a new kernel fails to boot, the quickest recovery method is to select the previous working kernel from the GRUB boot menu. GRUB typically retains the old kernel entry in its menu (e.g., 'Advanced options for Ubuntu' or a similar submenu), allowing you to boot the system without any external media or reinstallation. This approach avoids the overhead of using a live CD or rescue mode and directly restores functionality.

Exam trap

The trap here is that candidates often assume a failed kernel boot requires external recovery media (live CD or rescue mode) or single-user mode, forgetting that GRUB’s boot menu already provides direct access to the old kernel without any additional tools.

How to eliminate wrong answers

Option B is wrong because reinstalling the original kernel using a live CD is unnecessary and time-consuming; the old kernel is already present on the disk and accessible via GRUB. Option C is wrong because single-user mode still requires a bootable kernel; if the new kernel fails to load, you cannot reach single-user mode without first selecting a working kernel. Option D is wrong because rescue mode from installation media is a valid recovery method but is a more drastic step that should only be used if the GRUB menu itself is corrupted or the old kernel entry is missing.

45
MCQeasy

What is stored in the first sector of a hard disk (Master Boot Record)?

A.The Master Boot Record (boot loader and partition table)
B.The partition table only
C.The Linux kernel
D.The root filesystem
AnswerA

The first sector of a hard disk holds the Master Boot Record, comprising 446 bytes of boot loader code, a 64-byte partition table describing up to four primary partitions, and a 2-byte boot signature. This layout matches the question's description of the MBR contents.

Why this answer

The Master Boot Record (MBR) occupies the first sector (sector 0, 512 bytes) of a hard disk and contains both the boot loader code (first 446 bytes) and the partition table (next 64 bytes), plus a 2-byte signature (0x55AA). This structure is essential for BIOS-based booting, as the BIOS loads the MBR into memory and executes the boot loader, which then uses the partition table to locate the active partition and load the operating system.

Exam trap

The trap here is that candidates often confuse the MBR with the entire boot process, mistakenly thinking the kernel or root filesystem is directly stored in the first sector, when in reality the MBR only contains minimal boot code and partition metadata.

How to eliminate wrong answers

Option B is wrong because the partition table alone is only part of the MBR; the MBR also includes the boot loader code and the signature, so the partition table is not stored in isolation. Option C is wrong because the Linux kernel is never stored in the MBR; it resides on a filesystem (e.g., /boot) and is loaded later by a boot loader like GRUB. Option D is wrong because the root filesystem is a mounted filesystem (e.g., ext4) containing system directories and files, not a 512-byte sector; it is stored on a partition, not in the MBR.

46
MCQhard

A system takes a long time to boot due to a service that fails to start. Which systemd command can be used to identify the service causing the delay?

A.journalctl -u service
B.systemctl status
C.systemd-analyze critical-chain
D.systemd-analyze blame
AnswerD

`systemd-analyze blame` lists each unit's initialisation time in descending order, directly exposing the service whose startup delay dominates the boot. It satisfies the stem's requirement to identify the specific failing service, since the slowest unit appears at the top of the output.

Why this answer

The `systemd-analyze blame` command prints a list of all running units, sorted by the time they took to initialize, making it the direct tool to identify which service is causing a boot delay. Unlike other options, it specifically measures and displays the initialization time of each unit, allowing you to pinpoint the slowest service.

Exam trap

The trap here is that candidates confuse `systemd-analyze critical-chain` (which shows the longest dependency chain) with `systemd-analyze blame` (which shows the actual time each unit took to start), leading them to choose C when D is the correct tool for identifying the specific slow service.

How to eliminate wrong answers

Option A is wrong because `journalctl -u service` shows the log entries for a specific service, but it does not provide a summary of boot-time durations or identify which service is slow; it requires you already know the service name. Option B is wrong because `systemctl status` shows the current status and recent logs of a service, but it does not display boot-time analysis or comparative initialization times. Option C is wrong because `systemd-analyze critical-chain` prints the critical chain of units that took the longest to boot, but it focuses on the chain of dependencies rather than listing all services sorted by their individual initialization time, so it may not directly show the single slowest service if it is not on the critical path.

47
MCQeasy

Which command displays information about the CPU, including model name, cache size, and flags?

A.uname -a
B.lscpu
C.cat /proc/cpuinfo
D.dmidecode
AnswerB

lscpu reads /proc/cpuinfo and sysfs to report CPU architecture, model name, per-core cache sizes and instruction flags in one view, satisfying the stem's requirement to display all three. Alternatives such as lspci list PCI devices, not processor details.

Why this answer

The `lscpu` command is the correct choice because it is specifically designed to display CPU architecture information, including model name, cache sizes, and flags (such as SSE, AES, etc.), by reading data from sysfs and /proc/cpuinfo in a human-readable format. It provides a concise summary without requiring root privileges, making it the most appropriate tool for this task.

Exam trap

The trap here is that candidates often choose `cat /proc/cpuinfo` because it contains all the raw data, but the exam expects the command that is specifically designed to present CPU information in a readable summary, which is `lscpu`.

How to eliminate wrong answers

Option A is wrong because `uname -a` displays system kernel information (e.g., kernel name, hostname, kernel release, architecture), but it does not show CPU model name, cache size, or flags. Option C is wrong because while `cat /proc/cpuinfo` does contain all the requested CPU details, it outputs raw, verbose data that is not formatted for quick reading; the question asks for a command that 'displays information' in a practical sense, and `lscpu` is the standard utility for this purpose. Option D is wrong because `dmidecode` reads DMI/SMBIOS tables to provide hardware information (e.g., BIOS, motherboard, memory), but it requires root privileges and does not directly output CPU flags or cache details in a straightforward manner.

48
MCQhard

A company runs a critical database server on Linux. The server has a hardware RAID controller with two logical volumes: one for the operating system (LV1) and one for the database data (LV2). The server uses LVM on top of the RAID volumes. Recently, the database performance has degraded. The administrator suspects that the file system on LV2 is heavily fragmented. The server uses the ext4 filesystem. The administrator wants to check the fragmentation level and, if necessary, defragment the filesystem without unmounting it or causing downtime. What should the administrator do to minimize fragmentation impact while maintaining availability?

A.Create a new filesystem on LV2, copy data back, and symlink the old mount point to the new one.
B.Use tune2fs to set the reserved block percentage to 0 and increase the inode size.
C.Schedule a maintenance window, unmount LV2, run e2fsck -fn, then run e2fsck -D to defragment.
D.Use the e4defrag command with the -v option on the mount point to check and defragment files online.
AnswerD

The e4defrag utility operates on mounted ext4 filesystems, satisfying the no-downtime constraint. Its -v flag reports each file's fragmentation score before and after defragmentation, letting the administrator assess LV2 and defragment online. Note that e4defrag works per-file and cannot defragment directories or free space, unlike offline fsck-based approaches.

Why this answer

e4defrag is a userspace tool that provides online defragmentation for ext4 filesystems. It can check fragmentation levels and defragment files without unmounting the filesystem, thus avoiding downtime. This allows the administrator to minimize fragmentation impact while maintaining availability.

Exam trap

The trap here is that candidates may assume ext4 has no online defragmentation support at all, but e4defrag provides a limited online capability, or they may confuse e4defrag with e2fsck, which requires unmounting.

How to eliminate wrong answers

Option A is wrong because creating a new filesystem and copying data back requires unmounting LV2 or at least remounting it, causing downtime, and symlinking does not solve fragmentation on the original filesystem. Option B is wrong because tune2fs adjusts filesystem parameters like reserved blocks and inode size, but it does not perform defragmentation or check fragmentation levels. Option C is wrong because while e2fsck -D can defragment directories, it requires the filesystem to be unmounted, causing downtime, and the -fn option is for a read-only check, not defragmentation.

49
Multi-Selectmedium

Which TWO of the following are required for a system to boot using UEFI?

Select 2 answers
A.The bootloader installed in the ESP
B.An EFI System Partition (ESP) formatted with FAT32
C.The bootloader installed in the Master Boot Record (MBR)
D.A BIOS boot partition
E.A kernel with EFI stub support
AnswersA, B

UEFI firmware reads bootloaders exclusively from the EFI System Partition, a FAT32 partition holding `.efi` executables. Without a bootloader placed there, the firmware finds no boot target, so installation into the ESP is mandatory for UEFI boot.

Why this answer

Option B is correct because UEFI firmware requires an EFI System Partition (ESP) formatted with FAT32 (or FAT16 on removable media) to store and load EFI boot applications. Option A is correct because the bootloader must be installed as an EFI application within the ESP (e.g., \EFI\BOOT\BOOTX64.EFI or a vendor path) for the firmware to locate and execute it. Option C is incorrect because the MBR boot code is a legacy BIOS mechanism, not used by UEFI.

Option D is incorrect because a BIOS boot partition is a GPT partition used by GRUB in BIOS/GPT setups, not by UEFI. Option E is incorrect because EFI stub support is optional; UEFI can boot via a separate bootloader such as GRUB or systemd-boot without a kernel EFI stub.

Exam trap

The trap here is that candidates often confuse UEFI requirements with legacy BIOS requirements, mistakenly thinking the MBR or a BIOS boot partition is needed, or assuming EFI stub support is mandatory when it is only an optional feature for direct kernel booting.

50
Multi-Selectmedium

Which TWO statements about GRUB 2 are correct?

Select 2 answers
A.After modifying /etc/default/grub, the command update-grub must be run to regenerate grub.cfg.
B.The GRUB configuration file read at boot is /boot/grub/grub.cfg.
C.GRUB 2 uses a configuration file named menu.lst.
D.The GRUB prompt can be accessed by pressing the 'e' key during boot.
E.The /etc/default/grub file is directly read by GRUB during boot.
AnswersA, B

Editing /etc/default/grub only changes the input variables; GRUB 2 reads the generated grub.cfg at boot, so update-grub (a wrapper for grub-mkconfig) must regenerate that file for the changes to take effect. This satisfies the stem's requirement that the statement accurately describe GRUB 2 behaviour.

Why this answer

Option A is correct because /etc/default/grub is a user-editable configuration file containing variables like GRUB_TIMEOUT and GRUB_CMDLINE_LINUX, and changes to it only take effect after running update-grub (a wrapper for grub-mkconfig) to regenerate the actual boot configuration. Option B is correct because GRUB 2 reads /boot/grub/grub.cfg at boot time, which is the generated file containing menu entries and boot directives. Option C is incorrect because menu.lst belongs to GRUB Legacy, not GRUB 2.

Option D is incorrect because pressing 'e' at the GRUB menu opens an editor for the selected entry, not a GRUB command prompt; the 'c' key accesses the command-line prompt. Option E is incorrect because /etc/default/grub is not read directly by GRUB at boot; it is only consumed by grub-mkconfig/update-grub to produce grub.cfg.

Exam trap

The trap here is that candidates often confuse the GRUB 2 configuration workflow with GRUB Legacy, mistakenly thinking menu.lst is still used, or that pressing 'e' opens the GRUB prompt instead of the entry editor.

51
MCQeasy

Which systemd target corresponds to the traditional runlevel 3?

A.multi-user.target
B.graphical.target
C.emergency.target
D.rescue.target
AnswerA

multi-user.target is systemd's equivalent of traditional runlevel 3, providing a non-graphical multi-user environment with networking and text-mode login. It satisfies the stem's requirement by mapping the SysV runlevel 3 concept onto the corresponding systemd target unit.

Why this answer

In systemd, the 'multi-user.target' corresponds to the traditional SysV runlevel 3, which provides a multi-user, non-graphical environment with networking enabled. This target is the default for headless servers and is equivalent to the old /etc/inittab runlevel 3.

Exam trap

The trap here is that candidates often confuse 'rescue.target' with runlevel 3, when in fact rescue.target is the systemd equivalent of single-user mode (runlevel 1), while multi-user.target is the correct match for runlevel 3.

How to eliminate wrong answers

Option B (graphical.target) is wrong because it corresponds to runlevel 5, which adds a display manager (e.g., GDM, LightDM) on top of multi-user.target, not runlevel 3. Option C (emergency.target) is wrong because it is the most minimal target, starting only a single root shell on the console without networking or multi-user support, analogous to runlevel 1 or S. Option D (rescue.target) is wrong because it corresponds to runlevel 1 (single-user mode), pulling in basic system services but not a full multi-user environment.

52
MCQmedium

A system administrator wants to disable the graphical target and boot to the text mode multi-user.target permanently. Which command should they run?

A.systemctl enable multi-user.target
B.systemctl isolate multi-user.target
C.systemctl set-default multi-user.target
D.systemctl default multi-user.target
AnswerC

systemctl set-default writes the multi-user.target symlink into /etc/systemd/system/default.target, changing the persistent default boot target. This satisfies the requirement for a permanent switch away from graphical.target, unlike isolate or rescue, which affect only the running session.

Why this answer

`systemctl set-default multi-user.target` permanently changes the default systemd target to multi-user.target, ensuring the system boots into text mode (runlevel 3 equivalent) on every subsequent boot. This persists across reboots, unlike temporary switches.

Exam trap

The trap here is confusing runtime isolation (`isolate`) with persistent default setting (`set-default`), leading candidates to choose option B for a permanent change when it only affects the current session.

How to eliminate wrong answers

Option A is wrong because `systemctl enable multi-user.target` enables the target as a unit but does not set it as the default boot target; it only ensures the target is started if something requires it, not that the system boots into it. Option B is wrong because `systemctl isolate multi-user.target` immediately switches the current running target to multi-user.target but does not persist across reboots; it is a runtime change only. Option D is wrong because `systemctl default multi-user.target` is not a valid systemctl command; the correct syntax for resetting to the compiled-in default is `systemctl default` without arguments, and it does not accept a target name.

53
MCQmedium

A Linux system fails to boot with the error: 'Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. What is the most likely cause?

A.Missing root filesystem
B.Corrupt kernel image
C.Damaged bootloader
D.Missing or incorrect initrd
AnswerD

The kernel has mounted neither root nor initramfs, so it cannot load the storage driver needed to reach the root filesystem. A missing or mismatched initrd leaves the kernel without those modules, producing exactly this unknown-block(0,0) panic at boot.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates the kernel cannot locate or access the root filesystem during boot. The most common cause is a missing or incorrect initrd (initial RAM disk) that contains the necessary drivers (e.g., for SCSI, SATA, or filesystem modules) to mount the root partition. Without a proper initrd, the kernel lacks the modules to access the storage device, resulting in this panic.

Exam trap

The LPIC-1 exam often tests the distinction between a missing root filesystem and a missing initrd, trapping candidates who assume the error means the root partition itself is absent, when in fact the kernel cannot access it due to missing drivers in the initrd.

How to eliminate wrong answers

Option A is wrong because a missing root filesystem would typically produce a different error, such as 'No such device' or 'fsck' failures, not a kernel panic referencing 'unknown-block(0,0)', which specifically points to the kernel's inability to find the block device. Option B is wrong because a corrupt kernel image usually causes a panic earlier in the boot process (e.g., 'Kernel panic: Attempted to kill init!' or a crash during decompression), not a VFS mount failure with a block device number. Option C is wrong because a damaged bootloader (e.g., GRUB) would prevent the kernel from being loaded at all, resulting in a blank screen or 'No bootable device' error, not a kernel panic after the kernel has started executing.

54
MCQhard

A system has a software RAID1 array (/dev/md0) with two disks: /dev/sda and /dev/sdb. Disk /dev/sda fails. Which command sequence will replace the failed disk with a new /dev/sdc without stopping the array?

A.mdadm --stop /dev/md0; replace disk; mdadm --assemble /dev/md0 /dev/sdb /dev/sdc
B.mdadm --manage /dev/md0 --fail /dev/sda --remove /dev/sda && mdadm --manage /dev/md0 --add /dev/sdc
C.Shutdown system, physically replace disk, reboot
D.dd if=/dev/sdb of=/dev/sdc bs=64K
AnswerB

mdadm --manage marks the failed member faulty with --fail, then detaches it using --remove, freeing the slot. Adding /dev/sdc with --add triggers the RAID1 rebuild while /dev/md0 stays assembled and serving, satisfying the no-downtime constraint.

Why this answer

Mdadm's --manage mode allows hot-replacement of a failed disk in a RAID1 array without stopping it. The --fail flag marks /dev/sda as faulty, --remove detaches it, and --add incorporates the new /dev/sdc, triggering an automatic rebuild of the mirror.

Exam trap

The trap here is that candidates assume a failed disk requires array shutdown or physical replacement before software reconfiguration, but mdadm's --manage subcommand allows all steps (fail, remove, add) while the array remains active.

How to eliminate wrong answers

Option A is wrong because stopping the array with --stop is unnecessary and disruptive; RAID1 supports online replacement, and reassembling requires all members, risking data loss if the array is degraded. Option C is wrong because shutting down the system is not required; hot-swap capable hardware and mdadm's online management allow disk replacement without downtime. Option D is wrong because dd directly copies /dev/sdb to /dev/sdc, which overwrites the new disk's partition table and metadata, and does not integrate the disk into the RAID array; mdadm --add must be used to incorporate the new disk.

55
MCQmedium

A system administrator needs to ensure that the httpd service starts automatically when the system enters the multi-user.target. Which command should be used?

A.systemctl add-wants multi-user.target httpd.service
B.systemctl enable httpd
C.systemctl start httpd
D.systemctl set-default multi-user.target
AnswerB

`systemctl enable httpd` creates the symlinks under `/etc/systemd/system/multi-user.target.wants/` that pull the unit into the target's dependency graph at boot, satisfying the requirement that httpd start automatically with multi-user.target. It does not start the service now, but persistence across reboots is exactly what the stem demands.

Why this answer

The `systemctl enable httpd` command creates the necessary symlinks in the systemd unit configuration to ensure the httpd service starts automatically when the system enters the multi-user.target. This is the correct method to enable a service to start at boot in a systemd-based Linux system.

Exam trap

The trap here is confusing `systemctl start` (which only runs the service now) with `systemctl enable` (which configures it to start at boot), leading candidates to pick option C.

How to eliminate wrong answers

Option A is wrong because `systemctl add-wants` is not a valid systemd command; the correct command to add a dependency is `systemctl add-wants` (with a hyphen) but it is rarely used directly, and it does not enable the service for automatic start at boot. Option C is wrong because `systemctl start httpd` only starts the service immediately in the current session, but does not configure it to start automatically on subsequent boots. Option D is wrong because `systemctl set-default multi-user.target` sets the default target for the system (e.g., booting into multi-user mode), but does not enable any specific service to start automatically.

56
Multi-Selecteasy

Which TWO of the following are valid methods to change the default runlevel on a SysV init-based system?

Select 2 answers
A.Use the 'runlevel' command to set the default runlevel.
B.Edit /etc/inittab to set the initdefault line.
C.Pass the desired runlevel as a kernel parameter at boot time.
D.Use 'systemctl set-default' to set the default runlevel.
E.Use the 'telinit' command to change the default runlevel.
AnswersB, C

SysV init reads /etc/inittab at startup, and the initdefault line specifies which runlevel init enters by default. Editing that entry directly changes the persistent default runlevel, satisfying the requirement for a valid configuration method on a SysV init-based system.

Why this answer

Option B is correct because on a SysV init-based system the default runlevel is defined in /etc/inittab by the initdefault entry (e.g., id:3:initdefault:), which init reads at startup to determine which runlevel to enter. Option C is correct because passing a runlevel as a kernel boot parameter (e.g., appending '3' or 'single' to the kernel command line) overrides the initdefault setting for that boot, causing init to start in the specified runlevel. Option A is incorrect because the 'runlevel' command only reports the previous and current runlevels; it does not set them.

Option D is incorrect because 'systemctl set-default' is a systemd command for setting the default target, not applicable to SysV init systems. Option E is incorrect because 'telinit' changes the runlevel of the currently running system immediately, but does not persistently alter the default runlevel configured in /etc/inittab.

Exam trap

The trap here is that candidates confuse the 'runlevel' command (which only displays) with a command that can set the default, or they mistakenly apply systemd commands like 'systemctl set-default' to SysV init systems.

57
Matchingmedium

Match each ACL term to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Permissions for a specific user

Permissions for a specific group

Maximum permissions for named users and groups

Permissions for everyone else

Inherited ACL for new files/directories

Why these pairings

The correct matches: Access ACL applies to files and directories; Default ACL applies to new objects; Mask limits permissions for named users/groups. Common confusions include applying ACLs only to directories or misinterpreting mask as owner permissions.

58
MCQmedium

To add a kernel parameter temporarily to the kernel command line at boot, what key should be pressed in the GRUB menu?

A.e
B.b
C.r
D.c
AnswerA

Pressing e in the GRUB menu opens the selected entry for editing, exposing the kernel command line where a parameter can be appended for that boot only. This temporary edit is discarded on reboot, unlike changes written to configuration files.

Why this answer

Pressing 'e' in the GRUB menu enters the edit mode for the selected boot entry, allowing you to temporarily modify kernel parameters on the command line (e.g., adding 'single' for single-user mode or 'nomodeset' for graphics issues). These changes apply only to the current boot and are not saved to the GRUB configuration file.

Exam trap

The trap here is that candidates confuse the 'e' (edit) key with 'c' (command line) or 'b' (boot), assuming they can add parameters via the GRUB shell or by simply booting, but only 'e' provides direct access to modify the kernel command line for a single boot.

How to eliminate wrong answers

Option B is wrong because pressing 'b' in GRUB Legacy boots the selected entry immediately without any editing capability; it does not allow adding kernel parameters. Option C is wrong because pressing 'r' is not a standard GRUB key; it has no function in the GRUB menu for editing kernel parameters. Option D is wrong because pressing 'c' opens the GRUB command-line interface (a shell-like environment), not an editor for the kernel command line of a specific boot entry.

59
MCQmedium

A system administrator needs to see the boot messages recorded by systemd-journald from the current boot. Which command is most appropriate?

A.journalctl -b
B.dmesg
C.tail -n 50 /var/log/syslog
D.cat /var/log/messages
AnswerA

`journalctl -b` reads the journal for the current boot, satisfying the requirement to view systemd-journald boot messages. The `-b` flag filters entries by boot ID, excluding earlier boots, whereas plain `journalctl` would return the entire persistent journal.

Why this answer

The `journalctl -b` command is the most appropriate because it specifically queries the systemd journal for messages from the current boot. Systemd-journald is the default logging daemon on modern Linux distributions, and `journalctl -b` filters the binary journal to show only entries with a boot ID matching the current boot, which includes kernel messages, service logs, and boot-time events.

Exam trap

The trap here is that candidates often confuse `dmesg` (which shows kernel messages) with the full boot log, or assume traditional syslog files like `/var/log/messages` are still the primary source on systemd-based systems, leading them to overlook the journal-specific `journalctl -b` command.

How to eliminate wrong answers

Option B is wrong because `dmesg` shows only kernel ring buffer messages, not the full set of boot messages recorded by systemd-journald (e.g., service startup logs). Option C is wrong because `tail -n 50 /var/log/syslog` reads a traditional text log file that may not exist on systems using journald, and it shows only the last 50 lines of general system logs, not specifically boot messages from the current boot. Option D is wrong because `/var/log/messages` is a legacy log file used by syslog, not by systemd-journald; on modern systems, this file may be absent or incomplete, and it does not provide a boot-specific filter.

60
MCQhard

A system administrator needs to ensure that a custom kernel module named 'mydriver.ko' is loaded automatically at boot on a system that uses systemd. The module is located in /lib/modules/$(uname -r)/extra/. Which approach is most appropriate?

A.Add the line 'mydriver' to /etc/modules.
B.Insert the module into the initramfs using 'mkinitrd' and rely on it being loaded during early boot.
C.Run 'modprobe mydriver' and add it to /etc/rc.local.
D.Create a file /etc/modules-load.d/mydriver.conf containing the line 'mydriver'.
AnswerD

The systemd-modules-load.service reads configuration files from /etc/modules-load.d/ and loads the listed modules at boot. Placing the module name in a .conf file there ensures it is loaded automatically. This is the systemd-native method for specifying modules to load at startup.

Why this answer

On systemd-based systems, the systemd-modules-load service is responsible for loading modules at boot based on configuration files in /etc/modules-load.d/, /run/modules-load.d/, and /usr/lib/modules-load.d/. Creating a .conf file with the module name in /etc/modules-load.d/ is the correct, supported method. Other approaches may work incidentally but are not the intended mechanism.

Exam trap

The trap here is assuming that any file named /etc/modules will be honored by systemd, when the correct directory is /etc/modules-load.d/.

61
MCQmedium

A system administrator notices that a server with a freshly installed Linux system fails to boot with the error 'No bootable device found'. The server has a single SATA hard disk connected to the motherboard's SATA controller. Which of the following is the most likely cause of this issue?

A.The root filesystem is formatted with an unsupported filesystem type.
B.The kernel module for the SATA controller is not included in the initramfs.
C.The GRUB bootloader configuration file is missing or corrupted.
D.The BIOS boot order is set to a device that does not contain a bootable operating system.
AnswerD

A freshly installed disk with no bootloader leaves the firmware with nothing to hand off to. If the BIOS boot order still prioritises another device, such as the network or optical drive, the system reports 'No bootable device found' rather than reading the SATA disk.

Why this answer

The error 'No bootable device found' occurs during the BIOS/UEFI POST phase, before any bootloader is loaded. This indicates that the system firmware cannot find a valid boot sector on any device in its boot order. Since the server has a single SATA hard disk, the most likely cause is that the BIOS boot order is set to a different device (e.g., a network boot or removable media) that does not contain a bootable operating system, or the hard disk itself is not listed first in the boot priority.

Exam trap

The trap here is that candidates often confuse a pre-boot firmware error with a bootloader or kernel issue, leading them to incorrectly select options related to GRUB configuration or initramfs modules, when the actual problem is a simple BIOS boot order misconfiguration.

How to eliminate wrong answers

Option A is wrong because an unsupported root filesystem type would cause a kernel panic or mount failure during the boot process, not a 'No bootable device found' error, which occurs before the kernel is loaded. Option B is wrong because a missing SATA controller kernel module in the initramfs would result in a kernel panic or inability to mount the root filesystem after the bootloader loads, not a pre-boot firmware error. Option C is wrong because a missing or corrupted GRUB configuration file would cause GRUB to drop to a rescue shell or display a GRUB-specific error, not a 'No bootable device found' message, which is issued by the BIOS/UEFI before any bootloader is executed.

62
Multi-Selecthard

Which THREE of the following are characteristics of UEFI firmware compared to legacy BIOS? (Select exactly 3.)

Select 3 answers
A.Supports booting from disks larger than 2 TB.
B.Provides a graphical user interface during firmware setup.
C.Supports Secure Boot to prevent unauthorized operating systems from loading.
D.Uses the Master Boot Record partition table.
E.Requires a boot loader stored in the Master Boot Record.
AnswersA, B, C

UEFI uses GPT which supports large disks.

Why this answer

UEFI firmware uses the GUID Partition Table (GPT) instead of MBR, which supports 64-bit logical block addressing (LBA). This allows addressing disks larger than 2 TB, as the MBR scheme is limited to 32-bit LBA and a maximum addressable size of approximately 2.2 TB. Therefore, option A is correct.

Exam trap

The trap here is that candidates often confuse UEFI's support for GPT with MBR, incorrectly assuming UEFI still uses MBR for partition tables or boot loaders, leading them to select D or E as correct.

63
MCQeasy

During the boot process, the system stops at a GRUB prompt. Which command should be typed to continue booting?

A.quit
B.start
C.exit
D.boot
AnswerD

At the GRUB prompt, the boot command instructs GRUB to load the configured kernel and initrd and transfer control to the kernel, continuing the boot process. Other commands such as ls or set merely inspect configuration and do not initiate loading, so boot is required to proceed.

Why this answer

The 'boot' command at the GRUB prompt instructs the bootloader to load the selected kernel and initramfs, then transfer control to the kernel to continue the boot process. This is the standard way to proceed from the GRUB command-line interface when the system halts at a GRUB prompt.

Exam trap

A common misconception is that typing 'exit' or 'quit' will resume the boot process, but in GRUB, only 'boot' triggers the actual kernel execution.

How to eliminate wrong answers

Option A is wrong because 'quit' is not a valid GRUB command; it would be ignored or cause an error. Option B is wrong because 'start' is not a GRUB command; GRUB uses 'boot' to initiate the boot process. Option C is wrong because 'exit' is not a valid GRUB command; in GRUB, you use 'boot' to continue booting, not 'exit'.

64
Multi-Selecteasy

Which TWO commands can be used to display the amount of free and used memory on a Linux system? (Select exactly 2.)

Select 2 answers
A.vmstat
B.du
C.cat /proc/meminfo
D.free
E.top
AnswersC, D

Directly reads kernel memory information.

Why this answer

`/proc/meminfo` is a virtual file maintained by the kernel that provides detailed, real-time memory statistics, including total, free, available, and used memory. Reading this file with `cat` directly displays the current memory usage without any additional processing.

Exam trap

The trap here is that candidates may confuse `du` (disk usage) with memory reporting, or assume `vmstat` or `top` are primary tools for a simple free/used memory display, when `free` and `/proc/meminfo` are the direct and standard answers.

65
Multi-Selectmedium

Which TWO of the following are valid methods to reduce boot time on a Linux system? (Select exactly 2.)

Select 2 answers
A.Disable unnecessary systemd services.
B.Use an initramfs with minimal drivers.
C.Replace a hard disk drive with a solid-state drive.
D.Increase the kernel log level to debug.
E.Use ext2 instead of ext4 as the root filesystem.
AnswersA, C

Reduces the number of processes started sequentially.

Why this answer

Disabling unnecessary systemd services reduces the number of processes that must be started during boot, directly decreasing the time spent in the target phase of systemd's parallel service activation. Each disabled service eliminates its own dependency resolution, unit loading, and execution overhead, which is especially impactful on systems with many enabled services.

Exam trap

The trap here is that candidates often confuse 'reducing boot time' with 'reducing kernel size' or 'removing features,' but the two most effective methods are eliminating unnecessary startup processes (services) and upgrading the storage hardware to reduce I/O wait, not tweaking filesystem types or kernel logging verbosity.

66
MCQhard

A system boots in UEFI mode, and the administrator wants to add a new kernel entry to the EFI boot manager. Which tool should be used?

A.efibootmgr
B.grub2-install
C.lilo
D.mknbi
AnswerA

`efibootmgr` manipulates the UEFI firmware boot manager variables directly from Linux, creating and ordering boot entries stored in NVRAM. Since the system boots in UEFI mode, this satisfies the requirement to add a kernel entry to the EFI boot manager, unlike BIOS-era tools such as `grub-install` alone.

Why this answer

In UEFI mode, the system's boot manager is stored in NVRAM, and `efibootmgr` is the standard Linux tool for creating, deleting, and modifying boot entries in the UEFI Boot Manager. It directly manipulates the UEFI Boot Manager variables (e.g., BootOrder, Boot####) via the efivars kernel interface, allowing the administrator to add a new kernel entry without relying on a bootloader like GRUB.

Exam trap

The trap here is that candidates often confuse `grub2-install` (which installs a bootloader) with `efibootmgr` (which manages UEFI boot entries), mistakenly thinking that installing GRUB is the only way to add a kernel entry in UEFI mode.

How to eliminate wrong answers

Option B is wrong because `grub2-install` installs the GRUB2 bootloader to a disk or partition (e.g., the EFI System Partition) and updates the UEFI boot entry for GRUB itself, but it does not add arbitrary kernel entries to the UEFI boot manager; it is a bootloader installation tool, not a boot manager entry editor. Option C is wrong because `lilo` is a legacy bootloader for BIOS/MBR systems and does not support UEFI boot manager manipulation; it is obsolete for UEFI environments. Option D is wrong because `mknbi` is a tool for creating network boot images (e.g., for PXE or Etherboot), not for managing UEFI NVRAM boot entries.

67
MCQmedium

A system administrator suspects a failing power supply because the server randomly reboots. Which command can be used to check hardware health and event logs?

A.ipmitool sensor list
B.sensors -u
C.lspci -v
D.dmidecode -t baseboard
AnswerA

ipmitool sensor list queries the BMC over the IPMI interface, reporting voltages, temperatures, fan speeds and power supply status independently of the operating system. This satisfies the hardware-health requirement, since random reboots caused by a failing PSU appear in BMC sensor and event logs.

Why this answer

The `ipmitool sensor list` command queries the Baseboard Management Controller (BMC) via the IPMI protocol to retrieve real-time sensor readings (e.g., voltages, temperatures, fan speeds) and system event logs (SEL). This is the correct tool for diagnosing hardware-level issues like a failing power supply, as it provides direct access to the server's hardware health monitoring subsystem, independent of the operating system.

Exam trap

The trap here is that candidates confuse `sensors -u` (a user-space tool for reading motherboard sensors via kernel drivers) with IPMI-based hardware monitoring, not realizing that `sensors` cannot access the BMC or event logs, and thus cannot diagnose random reboots caused by power supply issues.

How to eliminate wrong answers

Option B is wrong because `sensors -u` reads from kernel-based sensor drivers (e.g., lm-sensors) and only reports current sensor values in a raw format; it does not access the BMC or event logs, and it cannot detect power supply failures that cause random reboots if the OS is already unstable. Option C is wrong because `lspci -v` lists PCI devices and their configuration details, but it does not monitor hardware health, sensor data, or event logs; it is purely for enumerating the PCI bus. Option D is wrong because `dmidecode -t baseboard` decodes DMI/SMBIOS tables to show motherboard information (e.g., manufacturer, serial number), but it provides no dynamic sensor readings or event log history; it is static hardware inventory data, not a health monitoring tool.

68
Multi-Selecteasy

Which TWO of the following are valid methods to list currently loaded kernel modules?

Select 2 answers
A.dmesg | grep module
B.lsmod
C.modprobe -l
D.cat /proc/modules
E.modinfo
AnswersB, D

lsmod reads /proc/modules and prints currently loaded kernel modules in a formatted table with size and usage counts. It satisfies the requirement to list loaded modules without loading or unloading anything, unlike modprobe or insmod.

Why this answer

Option B (lsmod) is correct because lsmod reads /proc/modules and prints the currently loaded kernel modules along with their size and usage count, making it the standard tool for this task. Option D (cat /proc/modules) is also correct because /proc/modules is the kernel-provided virtual file that lists all loaded modules, so displaying it directly shows the same information lsmod parses. Option A (dmesg | grep module) only filters kernel ring-buffer log messages and does not enumerate loaded modules.

Option C (modprobe -l) lists available module files on disk rather than loaded modules, and the -l option is deprecated/removed in modern kmod. Option E (modinfo) displays metadata about a specific module file or name, not a list of currently loaded modules.

Exam trap

The trap here is that candidates confuse commands that list available modules (like modprobe -l or find /lib/modules) with commands that list currently loaded modules, or they assume dmesg is a valid module listing tool because it shows kernel messages related to module loading.

69
MCQhard

A server has two disk drives: /dev/sda (SSD) and /dev/sdb (HDD). The administrator wants to place frequently accessed files on the SSD for performance. Which approach best achieves this using Linux filesystem features?

A.Create separate LVM logical volumes on each disk and mount them at different mount points.
B.Configure RAID 0 across both disks to combine speed.
C.Use symbolic links to redirect file access to the SSD.
D.Use a union mount to overlay the SSD on top of the HDD.
AnswerA

LVM lets you carve separate logical volumes from each physical disk and mount them at distinct paths, so frequently accessed data lives on the SSD while bulk data stays on the HDD. This satisfies the performance placement requirement without exotic tiering software.

Why this answer

LVM allows the administrator to create separate logical volumes on each physical disk (/dev/sda and /dev/sdb) and mount them at distinct mount points. By placing frequently accessed files on the SSD logical volume and less critical data on the HDD logical volume, the administrator can directly control which files benefit from the SSD's faster performance without mixing data or requiring complex overlays.

Exam trap

The trap here is that candidates may confuse RAID 0's speed benefits with the goal of isolating hot data, failing to recognize that RAID 0 mixes all data across both disks, preventing the administrator from selectively placing frequently accessed files on the faster SSD.

How to eliminate wrong answers

Option B is wrong because RAID 0 stripes data across both disks, combining their storage capacity and speed but also mixing frequently and infrequently accessed data on both the SSD and HDD, which negates the goal of isolating hot data on the faster SSD. Option C is wrong because symbolic links redirect file access at the filesystem level but do not provide a mechanism to automatically or efficiently place frequently accessed files on the SSD; they require manual management and do not leverage any filesystem feature for performance tiering. Option D is wrong because a union mount overlays one filesystem on top of another, but it does not intelligently direct frequently accessed files to the SSD; it simply merges directories, and writes typically go to the top layer, which could be the HDD, defeating the purpose.

70
MCQmedium

A data center server with two NICs (eth0 and eth1) is configured for network bonding in mode 1 (active-backup). The admin notices that after a cable pull on eth0, the bond interface fails over to eth1 as expected. However, when the cable is reconnected to eth0, the bond remains on eth1 indefinitely. The admin checks /proc/net/bonding/bond0 and sees that eth0 is marked as 'up' but not as 'active'. Which parameter is most likely missing from the bond configuration? Options: A) 'miimon=100' to enable link monitoring, B) 'downdelay=0', C) 'updelay=0', D) 'primary=eth0' to prefer eth0 as the active slave.

A.updelay=0
B.downdelay=0
C.miimon=100
D.primary=eth0
AnswerD

Active-backup mode does not automatically fail back; without the primary=eth0 parameter, the bond keeps using whichever slave is currently active. Setting primary=eth0 makes the bond prefer eth0 as the active slave once its link returns, restoring the original path.

Why this answer

The bond is in active-backup mode (mode 1) and eth0 is marked as 'up' but not 'active' after reconnection. Without the 'primary=eth0' parameter, the bond does not automatically switch back to the preferred slave (eth0) once it becomes available; it only fails over to eth1 when eth0 goes down. Setting 'primary=eth0' ensures that eth0 is always preferred as the active slave when it is in 'up' state, triggering a failback.

Exam trap

The trap here is that candidates assume 'miimon' alone handles both failover and failback, but in active-backup mode, failback to a preferred slave requires the explicit 'primary' parameter.

How to eliminate wrong answers

Option A is wrong because 'miimon=100' enables link monitoring via MII, which is already functioning (the bond detected the cable pull and failed over), so it is not the missing parameter. Option B is wrong because 'downdelay=0' (default) controls the delay before deactivating a slave after link loss; the issue is about failback, not failover timing. Option C is wrong because 'updelay=0' (default) controls the delay before considering a link as up after reconnection; the bond already sees eth0 as 'up', so the problem is not a delay but the lack of a preference to switch back.

71
MCQmedium

A system administrator wants to ensure a service named 'app.service' starts automatically on boot in a systemd-based system. Which command should be used?

A.systemctl start app.service
B.systemctl enable app.service
C.chkconfig app.service on
D.update-rc.d app.service enable
AnswerB

systemctl enable creates the symlink from the multi-user.target (or other install target) wants directory to the unit file, so systemd pulls app.service in at boot. Starting it now is separate; enable satisfies the automatic-start-on-boot requirement.

Why this answer

The correct command is 'systemctl enable app.service' because in systemd-based systems, 'enable' creates the necessary symlinks in the filesystem (typically under /etc/systemd/system/multi-user.target.wants/) to ensure the service starts automatically at boot. In contrast, 'systemctl start' only activates the service immediately without affecting its boot-time behavior.

Exam trap

The trap here is that candidates confuse 'start' (immediate activation) with 'enable' (boot-time activation), or mistakenly apply legacy SysV commands like 'chkconfig' or 'update-rc.d' to a systemd environment, which is a common pitfall in LPIC-1 exams.

How to eliminate wrong answers

Option A is wrong because 'systemctl start app.service' only starts the service immediately in the current session, but does not configure it to start automatically on boot. Option C is wrong because 'chkconfig' is a legacy tool for SysV init systems (e.g., RHEL/CentOS 6 and earlier), not for systemd-based systems; it would not work or would be deprecated. Option D is wrong because 'update-rc.d' is a Debian/Ubuntu-specific command for managing SysV init scripts, not for systemd services; it would not properly enable a systemd unit.

72
MCQmedium

A system administrator notices that the system boots to the graphical interface but wants to change it to boot to a non-graphical multi-user target. Which command will make this change persistent?

A.systemctl set-default multi-user.target
B.systemctl isolate multi-user.target
C.systemctl enable multi-user.target
D.systemctl start multi-user.target
AnswerA

systemctl set-default multi-user.target rewrites the default.target symlink in /etc/systemd/system, so the non-graphical multi-user target persists across reboots. The isolation and get-default subcommands only affect the running session or read state, so they cannot satisfy the persistence requirement.

Why this answer

`systemctl set-default multi-user.target` changes the default systemd target to `multi-user.target`, which boots to a non-graphical multi-user environment. This change is persistent across reboots, as it updates the symlink `/etc/systemd/system/default.target` to point to `multi-user.target`.

Exam trap

The trap here is that candidates confuse `isolate` (which changes the current target but is not persistent) with `set-default` (which makes the change permanent), leading them to incorrectly select Option B.

How to eliminate wrong answers

Option B is wrong because `systemctl isolate multi-user.target` immediately switches the current running target to `multi-user.target`, but this change is not persistent; it only affects the current session and does not modify the default target for future boots. Option C is wrong because `systemctl enable multi-user.target` is not a valid systemd command for setting the default target; `enable` is used to enable services or units at boot, not to set the default target. Option D is wrong because `systemctl start multi-user.target` starts the target immediately but does not make it the default for subsequent boots; it only activates the target in the current session.

Ready to test yourself?

Try a timed practice session using only System Architecture questions.