EX200 Configure local storage Practice Question
A filesystem reports 0% free space in df -h, but when checking the directory size with du -sh, it shows much less usage. What is the most likely cause?
⚠ Common exam trap
Red Hat often tests the misconception that `df` and `du` should always match, leading candidates to suspect corruption or hardware failure, when the real cause is the classic 'deleted but open file' scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deleted files still held open by processes
When a file is deleted while a process still holds an open file descriptor to it, the file's data blocks remain allocated on disk and are not freed until the process closes the descriptor. The `df` command reports disk usage based on the filesystem's block allocation, which still counts those blocks as used, while `du` calculates usage by walking the directory tree and cannot see the deleted file's data, leading to the discrepancy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Filesystem is corrupted
Why it's wrong here
If the filesystem metadata, such as the superblock or inode tables, were corrupt, you would normally see I/O errors, mounting failures, or fsck reporting inconsistencies, not df showing 0 free space when space is actually available. Corruption can theoretically cause incorrect block accounting, but that would appear as dirty bitmap warnings during a filesystem check, not a clean 0 free space reading. The far more common cause of this discrepancy is unlinked files that are still held open by processes.
- ✗
The disk has bad sectors
Why it's wrong here
Bad sectors are physical defects on the drive that cause read/write errors on specific blocks; they typically result in I/O errors when accessing those blocks, and the filesystem may remap or mark them. They do not cause the filesystem to report 0 free space when there is actually free space, because that would require the allocation metadata to be incorrectly updated, which is a logical issue, not a physical media problem. Bad sector reports would also show up in SMART data or dmesg messages, whereas df reads live on-disk block usage statistics.
- ✓
Deleted files still held open by processes
Why this is correct
When a file is deleted (unlinked) but a process still holds an open file descriptor to it, the inode and its data blocks remain allocated on disk. The filesystem does not reclaim those blocks until the last open handle is closed, yet the directory entry is removed immediately, so df still shows the space as consumed while `ls` no longer lists the file. This commonly occurs with log files or temporary files that are unlinked while still being written; running `lsof +L1` will reveal such deleted-but-open files and their associated processes.
- ✗
Filesystem is mounted with noexe
Why it's wrong here
The noexec mount option only controls whether binary executables can be run from that filesystem; it has no effect on filesystem capacity accounting or free space reporting. You can still create, delete, and store files on a noexec filesystem, and df will report true free space based on block usage. Consequently, a noexec mount cannot explain a reported 0 free space when there is actually available space, as it does not alter how the filesystem allocates or deallocates blocks.
Go deeper
Related to this question
About these practice questions
This EX200 question is part of Courseiva's 427-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.