LPIC-1 Devices, Filesystems and FHS Practice Question
Which directory under the root filesystem is defined by FHS as containing variable data that may change in size, such as logs and spools?
⚠ Common exam trap
Test-takers frequently confuse /var with /run or /tmp because both hold variable data, but the FHS specifically assigns persistent variable data (logs, spools) to /var, while /run is for volatile runtime state and /tmp for temporary files that may be cleared on reboot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
/var
The Filesystem Hierarchy Standard (FHS) defines /var as the directory for variable data that changes in size during normal system operation, including log files (e.g., /var/log), spool directories (e.g., /var/spool/mail), and temporary files that persist across reboots. This is distinct from /tmp, which is cleared on reboot, and /run, which holds runtime variable data that is volatile and cleared at boot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
/opt
Why it's wrong here
/opt holds add-on application software packages, not variable data such as logs and spools. The FHS reserves /var for variable data that grows at runtime. /opt would be the correct location when installing a third-party application bundle with its own static program files and directory tree.
- ✓
/var
Why this is correct
/var holds variable data such as logs, spools and mail queues, which grow unpredictably at runtime. FHS reserves it precisely for files whose size changes during normal operation, unlike /usr for static, shareable content. This satisfies the stem's requirement for variable data that may change in size.
- ✗
/run
Why it's wrong here
/run holds volatile runtime state such as PID files and sockets, cleared on reboot, rather than persistent variable data like logs and spools. The FHS assigns that role to /var. /run is correct when you need a tmpfs location for transient process state created during system startup.
- ✗
/tmp
Why it's wrong here
/tmp stores temporary files that applications may delete at any time and that are typically cleared on reboot, not the persistent variable data FHS assigns to /var. /tmp is correct when programs need scratch space for short-lived intermediate files during execution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.