Courseiva

EX200 Deploy, configure, and maintain systems Practice Question

A cron job runs a script every hour and leaves many log files. The administrator wants to clean up log files older than 7 days in /var/log/myapp/. Which command should be added to a weekly cron job?

⚠ Common exam trap

It's easy for candidates to confuse `-atime`, `-ctime`, and `-mtime`, or think `-exec rm {} \;` is equivalent to `-delete`, when in fact `-delete` is the preferred, safer, and more efficient method for bulk file removal in cron jobs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

find /var/log/myapp -type f -mtime +7 -delete

`-mtime +7` matches files whose modification time is older than 7 days, and `-delete` safely removes them. This is the most efficient and standard approach for cleaning up old log files in a cron job, as it avoids spawning a separate process for each file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    find /var/log/myapp -type f -atime +7 -delete

    Why it's wrong here

    The -atime primary matches files whose access time (atime) is older than the specified number of days. Log files are typically written by a cron job and are almost never read afterward, so a log can be old and unread without its atime changing; conversely, a single read (e.g., by an operator or monitoring tool) can update atime, making a recent file appear old. This makes atime unreliable for deciding whether a log is stale, so this command will not target the intended files. Use -mtime to match when the log content was last modified.

  • ✗

    find /var/log/myapp -type f -mtime +7 -exec rm {} \;

    Why it's wrong here

    Using -exec rm {} \; is functionally correct but much less efficient than -delete. For every matched file, find spawns a separate /bin/rm process, which costs time and system resources—especially problematic when a log directory has thousands of files. Additionally, -delete is implemented directly inside find without invoking an external program, reducing overhead and avoiding potential issues with command-line length or process limits. While -exec does pass filenames safely as arguments, it is an unnecessarily heavy way to remove a large batch of files.

  • ✗

    find /var/log/myapp -type f -ctime +7 -delete

    Why it's wrong here

    The -ctime primary matches the inode change time, which records when the file's metadata (permissions, owner, link count, or rename status) last changed, and it is also updated whenever the file content is modified. For cleanup purposes, -mtime is the precise indicator of when the log data was written, whereas ctime can be misleadingly recent if, for example, a log was chowned or had its permissions tweaked after the last write. Even if the content is old, a metadata change would make -ctime +7 exclude that file, causing old logs to be kept. Therefore, -mtime is the correct time stamp for log retention.

  • ✓

    find /var/log/myapp -type f -mtime +7 -delete

    Why this is correct

    This command correctly targets log files whose data was last modified more than 7 days ago, because -mtime +7 matches any file with a modification time older than 168 hours (7 × 24 hours). The -type f restriction ensures only regular files are removed, not directories or special files, and -delete is a safe, built-in action that unlinks each matched file without spawning an external process. When used in a cron job, this is an efficient and reliable one-line log cleanup method. It correctly balances retaining recent logs (≤7 days old) while purging stale entries.

About these practice questions

This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.