LPIC-1 Linux Installation and Package Management Practice Question
You are a junior administrator for a company that uses a standard disk image for all Linux servers. The image is based on CentOS 7. You need to ensure that new servers automatically install all available security updates during the first boot. You plan to run a command in a startup script. Which command should you use?
⚠ Common exam trap
Watch out — candidates often confuse the command for listing updates (`check-update`) with the command for installing them, or mistakenly apply a Debian-based command (`apt-get`) to a Red Hat-based system like CentOS 7.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
yum update -y
`yum update -y` installs all available updates, including security updates, without prompting for confirmation. On CentOS 7, this command updates all packages to their latest versions, which encompasses security patches. Running this in a startup script ensures that security updates are applied automatically on first boot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
yum check-update
Why it's wrong here
check-update only queries repositories and lists pending packages; it installs nothing, so first-boot servers would remain unpatched. It is tempting because it is the standard CentOS 7 way to discover which security updates exist, and would be the right choice when auditing or scripting a report rather than applying patches.
- ✗
yum install yum-cron
Why it's wrong here
yum install yum-cron only installs the package; it neither enables the service nor configures it to apply security updates, so first-boot patching never occurs. It tempts because yum-cron is the correct tool once enabled and configured via /etc/yum/yum-cron.conf.
- ✓
yum update -y
Why this is correct
yum update -y resolves and installs all available package updates, including security errata, without interactive prompts, so running it from a first-boot startup script satisfies the requirement for unattended patching on the CentOS 7 image.
- ✗
apt-get upgrade -y
Why it's wrong here
apt-get is Debian and Ubuntu's package manager, not CentOS 7's; the image ships RPM packages and yum metadata, so apt-get upgrade -y cannot resolve dependencies or install anything. It is tempting because it is the canonical unattended-upgrade command on Debian-family systems, where it would correctly apply all pending updates.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.