Courseiva

Red Hat Certified System Administrator EX200 (EX200) — Questions 1–75

427 questions total · 6pages · All types, answers revealed

Page 1 of 6

Page 2
1
Multi-Selectmedium

Which THREE of the following commands can be used to display information about file systems?

Select 3 answers
A.df
B.blkid
C.lsblk
D.fdisk
E.du
AnswersA, B, C

df displays information about mounted filesystems, including total size, used space, available space, and the mount point, by reading filesystem statistics via statfs(2). This makes it the standard command for checking how full a mounted filesystem is. Unlike du, it does not walk the directory tree; it queries the filesystem itself.

Why this answer

The `df` command displays information about mounted file systems, including total size, used space, available space, and mount points. It reads the /proc/mounts file to show file system usage statistics, making it a primary tool for file system information.

Exam trap

Red Hat often tests the distinction between disk partitioning tools (fdisk) and file system information commands, so candidates mistakenly select fdisk because it lists partitions, but it does not display file system details like type or usage.

2
MCQeasy

What is the default filesystem type in Red Hat Enterprise Linux 8?

A.btrfs
B.ZFS
C.ext4
D.XFS
AnswerD

XFS is the correct default filesystem in RHEL 8. Since RHEL 7, XFS has been the default choice, and it continues in RHEL 8 due to its scalability for large storage systems, metadata journaling, and support for online, non-destructive growth. Anaconda, the RHEL installer, preselects XFS for the root filesystem on new installations unless an administrator explicitly changes it.

Why this answer

In Red Hat Enterprise Linux 8, the default filesystem type is XFS. XFS is a high-performance 64-bit journaling filesystem that supports large files and filesystems, and it has been the default since RHEL 7. The Anaconda installer selects XFS by default for the root filesystem during a standard installation.

Exam trap

The trap here is that candidates may confuse the default filesystem in RHEL 8 with ext4, which was the default in RHEL 6 and earlier, or mistakenly think btrfs is the default due to its prominence in other distributions like openSUSE.

How to eliminate wrong answers

Option A is wrong because btrfs is not the default filesystem in RHEL 8; it is available as a technology preview but is not the default choice. Option B is wrong because ZFS is not included in RHEL 8 due to licensing incompatibilities (CDDL vs GPL) and is not a supported filesystem. Option C is wrong because ext4, while supported and commonly used in older RHEL versions, is not the default in RHEL 8; XFS replaced ext4 as the default starting in RHEL 7.

3
MCQeasy

Based on the exhibit, which command should be used to start the container named 'mycontainer'?

A.podman attach mycontainer
B.podman restart mycontainer
C.podman run mycontainer
D.podman start mycontainer
AnswerD

podman start is correct because it changes an existing, stopped container from the Exited state to the Running state without creating a new container or pulling an image. It resumes the container's configured entrypoint, command, and environment, making it the exact tool needed for the situation shown in the exhibit.

Why this answer

The correct command to start an existing but stopped container is 'podman start mycontainer'. 'podman start' resumes a container that has been created (via 'podman create') or previously stopped, without creating a new instance. Option D is correct because it directly addresses the requirement to start the container named 'mycontainer' that already exists.

Exam trap

The trap here is that candidates confuse 'podman run' (which creates and starts a new container) with 'podman start' (which starts an existing stopped container), leading them to choose option C when the container already exists.

How to eliminate wrong answers

Option A is wrong because 'podman attach' connects your terminal to a running container's standard input/output/error streams; it does not start a container. Option B is wrong because 'podman restart' stops and then starts a container that is already running or stopped, but the question asks specifically to 'start' the container, not to restart it; restart implies a stop followed by a start, which is unnecessary and potentially disruptive for a stopped container. Option C is wrong because 'podman run' creates and starts a new container from an image, but the container 'mycontainer' already exists (as implied by the exhibit), so 'run' would attempt to create a duplicate or fail if the name conflicts.

4
MCQeasy

A system administrator needs to allow members of the 'developers' group to run any command as root without being prompted for a password. Which sudoers configuration line should be added?

A.%developers ALL=(root) PASSWD: ALL
B.%developers ALL=(ALL) NOPASSWD: ALL
C.developers ALL=(ALL) NOPASSWD: ALL
D.%developers ALL=(ALL) ALL
AnswerB

This line grants the developers group passwordless sudo for every command as any user on any host. The leading % marks it as a group entry, ALL=(ALL) permits running commands as any target user, and NOPASSWD: ALL overrides the default password prompt. This is the exact configuration needed to satisfy the requirement of allowing group members to run commands without supplying a password.

Why this answer

The line `%developers ALL=(ALL) NOPASSWD: ALL` grants all members of the 'developers' group (indicated by the `%` prefix) permission to run any command as any user (including root) via sudo without being prompted for a password. The `NOPASSWD` tag is the key directive that bypasses password authentication, which directly matches the requirement to run commands as root without a password.

Exam trap

Red Hat often tests the distinction between user and group entries in sudoers, where omitting the `%` prefix causes candidates to mistakenly apply the rule to a user instead of a group, leading to a non-functional configuration.

How to eliminate wrong answers

Option A is wrong because it uses `PASSWD: ALL` instead of `NOPASSWD: ALL`, which would still require the user to enter a password when running sudo commands, contrary to the requirement. Option C is wrong because it omits the `%` prefix before 'developers', which means the rule applies to a user named 'developers' rather than the group, so members of the group would not be affected. Option D is wrong because it lacks the `NOPASSWD` tag entirely, meaning sudo would prompt for a password by default, and it also uses `ALL` for the user specification without the `%` prefix, making it apply to a user named 'developers' instead of the group.

5
Multi-Selectmedium

Which TWO commands can change the primary group of an existing user?

Select 2 answers
A.usermod -aG
B.gpasswd -a
C.vigr
D.groupmems -a
E.useradd -G
AnswersA, B

`usermod -aG` adds the user to a supplementary group, not the primary group.

Why this answer

None of the listed commands change the primary group of an existing user. The correct commands are `usermod -g` to change the primary group directly, or `groupmod -g` after ensuring the user is the only member of the group.

Exam trap

The trap is assuming that `usermod -aG` or `gpasswd -a` can change the primary group when they actually manage supplementary group membership only.

6
MCQmedium

A system administrator needs to ensure that a web server running Apache httpd starts automatically after a system reboot. Which command should the administrator use to enable the httpd service?

A.systemctl daemon-reload
B.systemctl start httpd
C.systemctl reenable httpd
D.systemctl enable httpd
AnswerD

systemctl enable httpd creates the systemd symlinks that pull the httpd unit into the boot target, so the service starts automatically at reboot. It satisfies the persistence requirement without starting the service immediately, unlike systemctl start.

Why this answer

`systemctl enable httpd` creates the necessary symlinks in the systemd unit configuration directories (e.g., `/etc/systemd/system/multi-user.target.wants/`) to ensure the httpd service starts automatically at boot. This is the standard method for enabling a service in a Red Hat Enterprise Linux 8/9 environment using systemd.

Exam trap

The trap here is that candidates confuse `systemctl start` (immediate runtime start) with `systemctl enable` (persistent boot-time activation), or they invent a non-existent command like `systemctl reenable` instead of using the correct `systemctl enable`.

How to eliminate wrong answers

Option A is wrong because `systemctl daemon-reload` reloads the systemd manager configuration, scanning for new or changed unit files, but does not enable any service for automatic startup. Option B is wrong because `systemctl start httpd` immediately starts the service in the current session but does not configure it to persist across reboots. Option C is wrong because `systemctl reenable httpd` is not a valid systemd command; the correct command to re-enable a service is `systemctl enable httpd` (which is idempotent) or `systemctl disable httpd` followed by `systemctl enable httpd`.

7
MCQeasy

In /etc/fstab, which values in the dump and pass fields enable automatic file system checking at boot?

A.dump=1, pass=0
B.dump=0, pass=0
C.dump=0, pass=1
D.dump=1, pass=1
AnswerC

This is the correct setting. A dump value of 0 is the standard choice on modern Linux systems, as dump(8) is obsolete and almost never used. The pass value of 1 tells fsck(8) to check this filesystem at boot, and 1 is specifically used for the root filesystem; other filesystems use pass=2 to run after the root check completes.

Why this answer

The `pass` field in `/etc/fstab` controls the order of file system checks at boot. A value of 1 means the root file system is checked first, and a value of 2 or higher means other file systems are checked after root. The `dump` field is for backup utility (dump) and is not related to boot-time checking; it must be 0 to disable dump.

Thus, `dump=0, pass=1` enables automatic file system checking (fsck) at boot for the root file system.

Exam trap

Red Hat often tests the misconception that `dump=1` is required for boot-time file system checks, but the `dump` field is unrelated to fsck; the trap is confusing the `dump` field with the `pass` field's role in enabling automatic checks.

How to eliminate wrong answers

Option A is wrong because `dump=1` enables dump backups (not boot-time checking), and `pass=0` disables fsck entirely, so no automatic checking occurs. Option B is wrong because `dump=0` and `pass=0` both disable dump and fsck, meaning no file system check at boot. Option D is wrong because `dump=1` enables dump (unnecessary for boot checking) and `pass=1` enables fsck, but the combination is not required; the correct minimal setting for enabling fsck is `dump=0, pass=1`.

8
MCQhard

An administrator attempts to mount an XFS filesystem from /dev/sdc1 to /mnt/archive but receives the error: 'mount: /mnt/archive: wrong fs type, bad option, bad superblock on /dev/sdc1, missing codepage or helper program, or other error.' The output of 'dumpe2fs /dev/sdc1' shows 'dumpe2fs: Bad magic number in super-block while trying to open /dev/sdc1'. What is the most likely problem?

A.The mount point /mnt/archive does not exist
B.The filesystem on /dev/sdc1 is XFS, not ext4
C.The XFS kernel module is not loaded
D.The partition /dev/sdc1 does not exist
AnswerB

dumpe2fs is designed for ext2, ext3, and ext4 filesystems; it looks for the ext family superblock magic (0xEF53) at offset 1024 on the device. XFS uses its own superblock format with the ASCII magic "XFSB" at a different offset. When dumpe2fs reads /dev/sdc1, it does not find the ext magic and prints "bad magic number in super-block," which simply means the device does not contain an ext filesystem, not that it is corrupt. The device likely holds a valid XFS filesystem, so running mount -t xfs /dev/sdc1 /mnt/archive will succeed. This is the correct diagnosis because the tool was incompatible with the actual filesystem type.

Why this answer

The error message 'wrong fs type' combined with 'dumpe2fs: Bad magic number in super-block' indicates that the filesystem on /dev/sdc1 is not an ext2/3/4 filesystem. dumpe2fs is designed to read ext2/3/4 superblocks, and the 'bad magic number' error means it cannot find a valid ext superblock. Since the administrator is trying to mount an XFS filesystem, the correct tool to examine it is xfs_db or xfs_info, not dumpe2fs. Therefore, the most likely problem is that the filesystem is XFS, not ext4.

Exam trap

The trap here is that candidates see 'bad superblock' and immediately think of ext4 superblock corruption or backup superblock recovery, when in fact the error is simply due to using an ext4-specific tool (dumpe2fs) on a non-ext4 filesystem.

How to eliminate wrong answers

Option A is wrong because if the mount point /mnt/archive did not exist, the error would be 'mount point does not exist' rather than 'wrong fs type' or 'bad superblock'. Option C is wrong because if the XFS kernel module were not loaded, the error would typically be 'mount: unknown filesystem type 'xfs'' or a similar message, not a 'bad superblock' error from dumpe2fs. Option D is wrong because if /dev/sdc1 did not exist, the error would be 'mount: special device /dev/sdc1 does not exist' or 'no such device', not a superblock-related error.

9
MCQhard

You are managing a Red Hat Enterprise Linux 9 server that hosts a critical database application. The database stores its data on an XFS filesystem mounted on /data, backed by a logical volume in a volume group named vg_db. Recently, the database team reported that write operations are failing with 'Disk quota exceeded' errors, but the filesystem still shows 40% free space. You check the filesystem quota configuration and find that no user or group quotas are set on /data. The database runs as user 'dbadmin' with group 'dba'. Which of the following is the most likely cause of the 'Disk quota exceeded' error?

A.The logical volume is thin provisioned and the data pool is full.
B.An XFS project quota is configured on the /data directory, limiting the space used by the database files.
C.SELinux is blocking the database writes due to a denial.
D.The filesystem has run out of inodes.
AnswerB

XFS project quotas are designed to limit usage of a directory subtree by assigning a project ID (e.g., project 42) to /data and setting a hard block limit. All files in /data, including the database files, inherit that project ID, and when the aggregate usage reaches the limit, further writes return the 'Disk quota exceeded' (EDQUOT) error. This is exactly the behavior described in the question, making it the correct explanation.

Why this answer

XFS project quotas can limit the total space used by a directory tree, regardless of the user or group that owns the files. Even though no user or group quotas are set, a project quota on /data restricts the database files, causing 'Disk quota exceeded' errors despite 40% free space on the filesystem.

Exam trap

The trap here is that candidates assume 'Disk quota exceeded' always implies user or group quotas are configured, overlooking XFS project quotas which operate on directory trees and are invisible to standard 'quota' or 'repquota' commands without the '-p' flag.

How to eliminate wrong answers

Option A is wrong because a thin-provisioned logical volume with a full data pool would cause 'No space left on device' errors, not 'Disk quota exceeded', and the filesystem would show 0% free space, not 40%. Option C is wrong because SELinux denials produce 'Permission denied' or AVC denial messages, not 'Disk quota exceeded' errors. Option D is wrong because running out of inodes would cause 'No space left on device' errors when creating files, and the filesystem would still show free space, but the error message would be different and the 'df -i' command would show 100% inode usage.

10
MCQmedium

A partition /dev/sdc1 is formatted as ext4. The administrator needs to check the file system for errors without making any repairs. Which command should be used?

A.xfs_repair -n /dev/sdc1
B.fsck -n /dev/sdc1
C.fsck -y /dev/sdc1
D.e2fsck -p /dev/sdc1
AnswerB

fsck is the generic filesystem check front-end that probes the filesystem type on /dev/sdc1 and invokes the appropriate underlying tool, such as e2fsck for ext4. The -n option forces it to answer 'no' to every repair prompt, making the run strictly read-only and non-destructive. This lets the administrator see errors without changing anything, exactly what a dry-run check needs.

Why this answer

The `fsck -n` command checks the file system for errors without making any repairs, as the `-n` flag forces a non-interactive, read-only check. Since /dev/sdc1 is formatted as ext4, `fsck` automatically calls the appropriate ext4-specific tool (e2fsck) with the no-repair option. This matches the requirement to only check for errors without fixing them.

Exam trap

Red Hat often tests the distinction between checking and repairing file systems, and the trap here is that candidates may confuse `-n` (no repair) with `-y` (auto-repair) or assume `xfs_repair -n` works on ext4, not recognizing that file system-specific tools must match the file system type.

How to eliminate wrong answers

Option A is wrong because `xfs_repair -n` is used for XFS file systems, not ext4; /dev/sdc1 is formatted as ext4, so this command is incompatible and would fail. Option C is wrong because `fsck -y` automatically answers 'yes' to all repair prompts, which would make repairs, contradicting the requirement to check without making repairs. Option D is wrong because `e2fsck -p` runs in 'preen' mode, which automatically repairs minor file system issues without prompting, thus performing repairs rather than just checking.

11
MCQmedium

An administrator needs to create a user account that will be used by an application service. The account should not have a valid shell or home directory. Which command correctly creates such an account?

A.useradd -r -M -s /bin/false appuser
B.useradd -r -s /sbin/nologin -M appuser
C.useradd -r -s /sbin/nologin appuser
D.useradd -s /bin/false -M appuser
AnswerB

This is the canonical command for creating a service account: -r assigns a UID from the system range, -s /sbin/nologin sets the PAM-aware shell that immediately rejects interactive logins, and -M suppresses creation of a home directory. Together these flags produce a minimal, non-interactive account that follows Red Hat's recommended security baseline for daemon users. No home directory means less attack surface and no risk of user-owned files in /home.

Why this answer

It uses the `-r` flag to create a system account (no aging information), `-s /sbin/nologin` to set the shell to a program that politely refuses login, and `-M` to explicitly skip creating a home directory. This combination ensures the account has no valid shell and no home directory, meeting the requirement for an application service account.

Exam trap

Candidates often forget the `-M` flag when the requirement explicitly states no home directory. Additionally, they may incorrectly use `/bin/false` instead of `/sbin/nologin` for a service account on Red Hat systems.

How to eliminate wrong answers

Option A is wrong because `/bin/false` is a valid shell that simply exits with a non-zero status, but it is not the standard Red Hat Enterprise Linux shell for denying login; `/sbin/nologin` is the preferred choice as it prints a message and logs the attempt. Option C is wrong because it omits the `-M` flag, so a home directory will be created by default (unless overridden by `/etc/default/useradd`), which violates the requirement of no home directory. Option D is wrong because it lacks the `-r` flag, so the account will be created as a regular user with password aging and other normal user attributes, and it uses `/bin/false` instead of the standard `/sbin/nologin`.

12
Multi-Selecthard

A system administrator needs to ensure that data written to a container's `/var/lib/mysql` directory persists after the container is removed. Which TWO methods accomplish this requirement?

Select 2 answers
A.Use the `--read-only` flag.
B.Use the `--tmpfs` flag.
C.Create a named volume with `podman volume create` and mount it.
D.Mount a host directory using `-v /host/data:/var/lib/mysql`.
E.Use the `--rm` flag when running the container.
AnswersC, D

Running podman volume create creates a named volume that is managed by Podman and stored on the host under /var/lib/containers/storage/volumes (or a configured driver). Mounting it with -v volname:/var/lib/mysql makes MySQL data persist independently of the container's lifecycle; the volume remains after container removal and can be reused by a new container. Named volumes also allow easy backup, inspection, and sharing, and they are the recommended way to store persistent data with containers.

Why this answer

A named volume created with `podman volume create` is managed by Podman and persists independently of the container lifecycle. When mounted to `/var/lib/mysql`, data written to that directory is stored in the volume and remains available even after the container is removed. This is the recommended method for persistent data in production environments.

Exam trap

The trap here is that candidates often confuse `--tmpfs` with persistent storage, not realizing that tmpfs is volatile and exists only in RAM, or they mistakenly think `--rm` helps with persistence when it actually ensures automatic cleanup of the container's writable layer.

13
MCQmedium

Refer to the exhibit. A user named 'carol' has been added to the system with the command useradd -G wheel carol. Which line in /etc/group will confirm that carol is now a member of the wheel group?

A.wheel:x:10:carol,root,alice,bob
B.wheel:x:10:root,alice,bob,carol
C.wheel:x:10:root,alice,bob,carol,
D.wheel:x:10:root,alice,bob carol
AnswerB

Correct. The `useradd -G wheel carol` command adds 'carol' to the supplementary group 'wheel' by appending her username to the end of the comma-separated member list in `/etc/group`. The line `wheel:x:10:root,alice,bob,carol` shows 'carol' after the existing members, with no trailing comma, which is the correct format.

Why this answer

The `useradd -G wheel carol` command adds 'carol' to the supplementary group 'wheel', and the `/etc/group` file lists supplementary members as a comma-separated list with no trailing comma. The line `wheel:x:10:root,alice,bob,carol` shows 'carol' appended after the existing members, which matches the expected format.

Exam trap

In Red Hat Enterprise Linux, the /etc/group file format requires member lists to be comma-separated with no trailing comma, and the useradd -G command appends users to the end of the supplementary group member list.

How to eliminate wrong answers

Option A is wrong because it lists 'carol' before 'root', but the `useradd -G` command appends the new user to the end of the existing group member list, not at the beginning. Option C is wrong because it includes a trailing comma after 'carol', which is invalid in `/etc/group` — the file format does not allow a trailing comma. Option D is wrong because it uses a space instead of a comma to separate 'bob' and 'carol', but the `/etc/group` file requires commas as delimiters between usernames.

14
Matchingmedium

Match each cron syntax field to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

0-59

0-23

1-31

1-12 or Jan-Dec

Why these pairings

The five fields in a cron syntax are (in order): minute (0-59), hour (0-23), day of month (1-31), month (1-12), and day of week (0-7). Common confusions include swapping the minute and hour ranges.

15
MCQmedium

What does the 's' in the owner execute position indicate?

A.Mandatory access control
B.SetGID
C.Sticky bit
D.No special permission
E.SetUID
AnswerE

SetUID (set user ID) is the correct interpretation: a lowercase 's' in the owner execute position means the executable runs with the effective UID of the file's owner rather than the invoking user. For example, `/usr/bin/passwd` has the setuid bit because it is owned by root and must modify `/etc/shadow`. This is a classic and security-sensitive special permission.

Why this answer

In Linux file permissions, the 's' in the owner execute position (e.g., `-rwsr-xr-x`) indicates the SetUID (Set User ID) special permission. When set on an executable file, it allows the process to run with the effective user ID of the file's owner (typically root), rather than the user who launched it. This is why option E is correct.

Exam trap

Red Hat often tests the distinction between SetUID (owner execute 's') and SetGID (group execute 's'), and candidates confuse which position corresponds to which special permission.

How to eliminate wrong answers

Option A is wrong because Mandatory Access Control (MAC) is a security model enforced by systems like SELinux or AppArmor, not represented by the 's' in the owner execute position. Option B is wrong because SetGID (Set Group ID) is indicated by an 's' in the group execute position, not the owner execute position. Option C is wrong because the sticky bit is indicated by a 't' in the 'others' execute position, not the owner execute position.

Option D is wrong because 'No special permission' would show a simple 'x' in the owner execute position, not an 's'.

16
MCQeasy

Which command can be used to display a list of all currently mounted filesystems on a Linux system?

A.fdisk -l
B.lsblk -m
C.cat /proc/filesystems
D.df -a
E.mount
AnswerE

Running mount with no arguments displays the kernel's current mount table, typically sourced from /proc/mounts, in a format showing the device, mount point, filesystem type, and mount options (e.g., /dev/sda1 on / type xfs (rw,relatime)). This output is precisely a list of all currently mounted filesystems, including real devices, pseudo-filesystems like sysfs, and bind mounts. As the standard command for mounting and unmounting filesystems, its bare invocation serves as the canonical way to view the complete active mount configuration.

Why this answer

The `mount` command with no arguments displays a list of all currently mounted filesystems, showing the device, mount point, filesystem type, and mount options. This is the standard and most direct way to view active mounts on a Linux system.

Exam trap

The trap here is that candidates confuse commands that list block devices or filesystem types with the command that shows actual mounted filesystems, leading them to pick `lsblk` or `cat /proc/filesystems` instead of `mount`.

How to eliminate wrong answers

Option A is wrong because `fdisk -l` lists partition tables on block devices, not currently mounted filesystems. Option B is wrong because `lsblk -m` lists block devices with their permissions and owners, but does not show mount status or filesystem type details. Option C is wrong because `cat /proc/filesystems` shows which filesystem types are supported by the kernel, not which are currently mounted.

Option D is wrong because `df -a` reports disk space usage for mounted filesystems, but it does not display all mount details such as mount options or device paths for pseudo-filesystems.

17
MCQmedium

A system administrator needs to extend a logical volume 'lv_data' in volume group 'vg_data' by adding a new 50GB disk. Which sequence of commands should be used (assuming the filesystem is XFS)?

A.pvcreate, vgextend, lvextend, resize2fs
B.vgextend, lvcreate, pvcreate, xfs_growfs
C.vgextend, pvcreate, lvextend, xfs_growfs
D.pvcreate, vgextend, lvextend, xfs_growfs
E.pvcreate, lvextend, vgextend, fsck
AnswerD

This is the correct sequence for extending an XFS logical volume: pvcreate initializes the new disk or partition as a physical volume; vgextend adds that PV to the existing volume group, making new extents available; lvextend extends the logical volume into the free extents; and finally xfs_growfs expands the XFS filesystem to fill the larger LV. Because XFS can be grown online and does not support shrinking, xfs_growfs is the proper tool rather than resize2fs. This order ensures every prerequisite is satisfied before the next operation.

Why this answer

The proper sequence to extend an XFS logical volume is: first, initialize the new disk as a physical volume with `pvcreate`; second, add it to the volume group with `vgextend`; third, extend the logical volume with `lvextend`; and finally, grow the XFS filesystem with `xfs_growfs`. XFS does not support shrinking and requires `xfs_growfs` (not `resize2fs`) for online growth.

Exam trap

The trap here is that candidates confuse `resize2fs` (for ext4) with `xfs_growfs` (for XFS), or incorrectly order the commands by adding the disk to the volume group before initializing it as a physical volume.

How to eliminate wrong answers

Option A is wrong because `resize2fs` is used for ext2/3/4 filesystems, not XFS; XFS uses `xfs_growfs`. Option B is wrong because `lvcreate` creates a new logical volume, not extends an existing one, and `pvcreate` must precede `vgextend`. Option C is wrong because `pvcreate` must be run before `vgextend` to initialize the disk as a physical volume.

Option E is wrong because `lvextend` cannot be done before adding the physical volume to the volume group (`vgextend`), and `fsck` is a filesystem check, not a resize tool.

18
MCQmedium

A system administrator runs the following command: # vgextend mydata-vg /dev/sdc. After successfully extending the volume group, what is the next step to make the additional space available in the logical volume mydata-lv?

A.xfs_growfs /data
B.lvextend -l +100%FREE /dev/mydata-vg/mydata-lv
C.resize2fs /dev/mydata-vg/mydata-lv
D.lvextend -L +10G /dev/mydata-vg/mydata-lv
AnswerB

lvextend -l +100%FREE /dev/mydata-vg/mydata-lv is correct because it extends the logical volume by all free extents present in the volume group, ensuring the LV consumes every unused physical extent. The -l option uses logical extent counts rather than a fixed size, and +100%FREE is a relative allocation that dynamically calculates the total free space in the VG. By using all free extents, this command maximizes the LV size without requiring you to know the exact amount of free capacity, which is ideal after a vgextend operation.

Why this answer

After extending the volume group with vgextend, you must extend the logical volume to use the new free space. The command lvextend -l +100%FREE /dev/mydata-vg/mydata-lv allocates all remaining free extents in the volume group to the logical volume, making the additional space available for the filesystem.

Exam trap

The trap here is that candidates often confuse the order of operations and try to grow the filesystem directly (option A or C) without first extending the logical volume, or they use a specific size (option D) instead of the '100%FREE' syntax to consume all new space.

How to eliminate wrong answers

Option A is wrong because xfs_growfs /data is used to grow an XFS filesystem, but the logical volume itself has not been extended yet; you must first run lvextend to allocate the space to the LV. Option C is wrong because resize2fs is for ext2/ext3/ext4 filesystems, not XFS, and again the LV must be extended first. Option D is wrong because lvextend -L +10G adds a specific amount of space (10 GiB) rather than using all available free space in the volume group, which may not match the full extent of the newly added physical volume.

19
MCQeasy

An administrator writes a script that uses the 'set -e' option at the top. What is the primary effect of this option?

A.It treats unset variables as an error
B.It prints each command before execution
C.It enables debug mode with verbose output
D.It exits the script immediately if a command fails
AnswerD

This is the exact purpose of `set -e`, also known as `errexit`. When enabled, the shell immediately exits if any simple command, pipeline, or compound command (outside of contexts like `if`, `while`, `until`, `!`, or `&&`/`||` left operands) returns a non-zero status. This halts the script at the first error rather than continuing with unchecked failures.

Why this answer

The 'set -e' option instructs the shell to exit immediately if any command or pipeline returns a non-zero exit status (i.e., fails). This is commonly used in scripts to prevent execution from continuing after an error, which could lead to unpredictable behavior or data corruption. It does not affect variable handling, command printing, or debug verbosity.

Exam trap

The trap here is that candidates often confuse 'set -e' with 'set -u' (unset variable errors) or with debugging options like 'set -x' or 'set -v', because all are shell options that begin with 'set -' but have very different effects.

How to eliminate wrong answers

Option A is wrong because treating unset variables as an error is the behavior of 'set -u', not 'set -e'. Option B is wrong because printing each command before execution is the effect of 'set -x' (or 'set -o xtrace'), not 'set -e'. Option C is wrong because enabling debug mode with verbose output is achieved by 'set -v' (or 'set -o verbose'), which prints shell input lines as they are read, not by 'set -e'.

20
MCQmedium

A file has been assigned an incorrect SELinux context, preventing a service from accessing it. Which command restores the default SELinux context for that file?

A.restorecon
B.chcon
C.fixfiles
D.setfiles
AnswerA

restorecon resets a file's SELinux context to the policy-defined default by consulting the file_contexts rules, typically with `restorecon -v /path/to/file`. It is the correct tool when a file's context has become incorrect because it determines the intended context from the policy rather than relying on a manually specified value, and it only changes files whose current context does not match the default.

Why this answer

The `restorecon` command is used to restore the default SELinux security context for a file or directory based on the system's policy store (the file_contexts database). When a file has an incorrect context that prevents a service from accessing it, `restorecon` resets the context to the correct default, allowing the service to access the resource as intended.

Exam trap

The trap here is that candidates often confuse `chcon` (which changes context manually) with `restorecon` (which restores the default from policy), leading them to pick `chcon` because they think they need to 'change' the context rather than 'restore' it to the correct default.

How to eliminate wrong answers

Option B (chcon) is wrong because `chcon` changes the SELinux context manually to a user-specified value, but it does not restore the default context from the policy database; it can introduce further misconfiguration if the wrong context is specified. Option C (fixfiles) is wrong because `fixfiles` is a script that corrects file contexts on entire filesystems or directories (e.g., after a policy update), not for a single file, and it is overkill for a targeted restoration. Option D (setfiles) is wrong because `setfiles` is a low-level tool used to initialize or verify file contexts on a filesystem, typically during system installation or policy reloads, and is not intended for routine single-file context restoration.

21
Multi-Selecteasy

A system administrator writes a shell script to monitor disk usage and send an alert if any partition exceeds 80%. Which TWO of the following are best practices for implementing this script?

Select 2 answers
A.Use `cat /proc/partitions` to retrieve partition sizes.
B.Include error handling to check for missing commands and exit gracefully.
C.Send alerts only via syslog (logger command).
D.Use `df -h` and parse the output to check usage percentages.
E.Use `du -h /` and parse the output.
AnswersB, D

A script run via cron or an administrator's shell inherits a minimal PATH and can fail silently if critical commands like df or awk are missing or are non-executable. Including error handling, such as verifying prerequisites with command -v and checking the exit status of df, prevents the script from issuing false alerts or exiting with unrelated error codes. A graceful exit that logs a clear diagnostic message to stderr or syslog makes the failure self-evident and allows administrators to correct the environment rather than debug mysterious output.

Why this answer

Robust shell scripts should always include error handling to verify that required commands (e.g., `df`, `awk`, `grep`) are available before proceeding. This prevents the script from failing silently or producing misleading output, and allows it to exit gracefully with a meaningful error message, which is a key best practice for production scripts.

Exam trap

Red Hat often tests the distinction between `df` (filesystem-level usage) and `du` (directory-level usage), and candidates mistakenly choose `du` because they think it shows disk usage, but it does not report capacity or percentage used.

22
MCQhard

Refer to the exhibit. A web server must also accept HTTPS traffic on port 8443. Which command should the administrator run to permanently open this port?

A.firewall-cmd --add-service=8443/tcp --permanent
B.firewall-cmd --add-port=8443/tcp
C.firewall-cmd --add-port=8443/tcp --permanent && firewall-cmd --reload
D.firewall-cmd --add-port=8443/tcp --zone=public
AnswerC

This correctly adds TCP port 8443 to the persistent configuration of the default zone and then reloads firewalld to make the permanent rule active without restarting services. The --permanent flag writes the rule to the zone's permanent config (e.g., /etc/firewalld/zones/public.xml), and --reload re-applies that config cleanly. This is the proper way to expose a non-standard HTTPS port.

Why this answer

It uses `--add-port=8443/tcp` to open a non-standard port (8443) for HTTPS traffic, applies the `--permanent` flag to persist the rule across reboots, and then runs `--reload` to activate the change immediately without restarting the firewall service. Without `--reload`, the permanent rule would not take effect until the next firewall reload or system restart.

Exam trap

The trap here is that candidates often forget the `--permanent` flag or the `--reload` step, assuming that adding a port with `--add-port` alone is sufficient to make it persistent, or they mistakenly use `--add-service` with a port number instead of a service name.

How to eliminate wrong answers

Option A is wrong because `--add-service` expects a predefined service name (e.g., 'https'), not a port/protocol string like '8443/tcp'; it would fail or create an invalid rule. Option B is wrong because it omits `--permanent`, so the rule is only added to the runtime configuration and will be lost after a reboot or firewall reload. Option D is wrong because it lacks `--permanent` and does not include `--reload`, meaning the rule is temporary and not activated in the current runtime; additionally, specifying `--zone=public` is unnecessary here as the default zone is already public.

23
Drag & Dropmedium

Order the steps to configure firewall rules to allow HTTP and HTTPS traffic using firewalld.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Firewalld rules are added with --permanent flag and then reloaded to take effect.

24
Multi-Selecthard

A container is running but cannot be accessed from the network. Which TWO commands could help diagnose the issue? (Select exactly two.)

Select 2 answers
A.podman logs
B.podman port
C.podman inspect
D.podman exec
E.podman top
AnswersB, C

The podman port command prints the host port bindings for a running container, e.g., 8080/tcp -> 0.0.0.0:32768, by reading the port-mapping rules that podman created. If the container was started without -p or -P, this command produces no output, which is an immediate indicator that no host port was published and external access is impossible. It is the direct, minimal diagnostic for checking whether a container's ports are exposed to the network.

Why this answer

`podman port` lists the port mappings for a container, showing which host ports are mapped to container ports. If a container is running but unreachable from the network, this command reveals whether the expected port mapping exists and is correctly configured. Without a proper mapping, external traffic cannot reach the container's service.

Exam trap

Red Hat often tests the distinction between commands that inspect container metadata (`podman inspect`) versus commands that interact with running processes (`podman exec`, `podman top`), leading candidates to choose the latter for network issues.

25
MCQhard

An administrator needs to grant user 'dev' the ability to execute /usr/local/bin/deploy.sh as root without a password, but no other commands. Which sudoers entry accomplishes this?

A.dev ALL=(root) PASSWD: /usr/local/bin/deploy.sh
B.dev ALL=(root) NOPASSWD: /usr/local/bin/deploy.sh
C.dev ALL=(ALL) NOPASSWD: /usr/local/bin/deploy.sh
D.%dev ALL=(root) NOPASSWD: /usr/local/bin/deploy.sh
AnswerB

This rule correctly grants dev the ability to run /usr/local/bin/deploy.sh with root privileges without entering a password. The NOPASSWD tag overrides the default password requirement, and the fully qualified command path restricts execution to exactly that binary, preventing PATH-based substitution. The (root) runas specification ensures the command runs only as root, matching the requirement precisely.

Why this answer

The sudoers entry 'dev ALL=(root) NOPASSWD: /usr/local/bin/deploy.sh' grants user dev permission to run only that command as root without a password prompt. The NOPASSWD tag removes the password requirement, and specifying the single command restricts the privilege to exactly that binary.

Exam trap

EX200 often tests whether candidates confuse the PASSWD/NOPASSWD tags, the (root) vs (ALL) runas specification, and the '%' group prefix, any of which changes the meaning of the sudoers rule.

How to eliminate wrong answers

Option A is wrong because PASSWD: requires the user to enter their password, contradicting the no-password requirement. Option C is wrong because (ALL) allows running the command as any user, not just root, which is broader than needed. Option D is wrong because the '%' prefix denotes a group named dev, not the user dev, so it would not apply to the user account.

26
MCQeasy

A system administrator wants to run a container that uses the rootless mode available in Podman. Which requirement must be met for rootless containers to work correctly?

A.The container must be run with the '--privileged' flag.
B.The user must have entries in /etc/subuid and /etc/subgid for user namespace mapping.
C.The system must have cgroups v2 enabled.
D.The user must have root privileges to run the container.
AnswerB

For rootless containers, every UID and GID used inside the container must be mapped to an unprivileged range on the host, and those ranges are defined in /etc/subuid and /etc/subgid. The container engine such as Podman calls newuidmap and newgidmap to apply the subordinate ID mapping, and without at least one range assigned to the user, the kernel cannot establish the user namespace and the container fails to launch. A typical entry allocates a starting UID and a count, for example 1000:100000:65536, to give the container up to 65,536 IDs to work with.

Why this answer

Rootless Podman containers require user namespace mapping to assign subordinate UIDs and GIDs from the host to the container. Without entries in /etc/subuid and /etc/subgid for the user, Podman cannot allocate the necessary ID ranges, and the container will fail to run in rootless mode.

Exam trap

Red Hat often tests the misconception that rootless containers require root privileges or special flags like '--privileged', when in fact they rely on user namespace mapping configured in /etc/subuid and /etc/subgid.

How to eliminate wrong answers

Option A is wrong because the '--privileged' flag grants elevated capabilities and disables user namespace isolation, which is the opposite of what rootless mode requires. Option C is wrong because cgroups v2 is not a strict requirement for rootless containers; Podman can use cgroups v1 with rootless mode, though v2 is recommended for better resource management. Option D is wrong because rootless mode explicitly allows non-root users to run containers, so requiring root privileges contradicts the purpose of rootless containers.

27
MCQmedium

An administrator needs to combine two physical network interfaces into a single logical interface for redundancy. Which RHEL tool is recommended to configure this in RHEL 8/9?

A.teamd
B.ip link
C.brctl
D.nmcli
AnswerD

nmcli is the NetworkManager command-line utility and is the recommended way to configure a bond or team on RHEL systems. For example, you can run nmcli connection add type bond to create the bond master, then add slave interfaces, and NetworkManager will persist the configuration and manage the underlying teamd or bonding driver automatically.

Why this answer

In RHEL 8/9, NetworkManager is the default networking service, and `nmcli` is its command-line tool. For bonding (combining two physical interfaces into a single logical interface for redundancy or increased throughput), the recommended approach is to use `nmcli` to create a bond connection, which uses the Linux kernel bonding driver. The `teamd` service was deprecated in RHEL 8 and removed in RHEL 9, making `nmcli` the correct and supported method.

Exam trap

The trap here is that candidates familiar with older RHEL versions (RHEL 7 or earlier) may remember `teamd` as the recommended tool for teaming, but RHEL 8/9 deprecated and removed it, making `nmcli` the correct answer for bonding.

How to eliminate wrong answers

Option A is wrong because `teamd` (libteam) was deprecated in RHEL 8 and removed in RHEL 9; it is no longer a supported tool for interface aggregation. Option B is wrong because `ip link` is a low-level tool for managing network interfaces individually (e.g., creating VLANs or bridges) but cannot create a persistent bond configuration that integrates with NetworkManager; it lacks the abstraction and persistence needed for a production bond setup. Option C is wrong because `brctl` is used to manage Ethernet bridges (for bridging/switching, not bonding/aggregation); it creates a bridge that forwards traffic based on MAC addresses, not a redundant logical interface that combines bandwidth or provides failover.

28
Multi-Selecthard

Which THREE of the following mount options are commonly used to enhance security on a filesystem?

Select 3 answers
A.nosuid
B.nodev
C.suid
D.defaults
E.noexec
AnswersA, B, E

Mounting a filesystem with nosuid disables the setuid and setgid bits on all executable files within it, so a binary cannot temporarily assume the UID or GID of its file owner. This is critical for partitions like /tmp that are writable by unprivileged users, because a setuid root binary created there could otherwise be exploited for privilege escalation. Administrators commonly include nosuid when mounting removable media or network shares to prevent untrusted binaries from attaining local higher privileges.

Why this answer

The `nosuid` option prevents the set-user-identifier (setuid) and set-group-identifier (setgid) bits from taking effect on the filesystem. This blocks unprivileged users from executing binaries with elevated privileges, a common vector for privilege escalation attacks.

Exam trap

The trap here is that candidates often confuse `defaults` with a secure baseline, not realizing it includes `suid`, `dev`, and `exec` — the very options that security hardening aims to disable.

29
MCQhard

A system fails to mount an XFS filesystem at boot. The /etc/fstab entry is: UUID=abc123 /mnt xfs defaults 0 0. Running mount -a shows: 'mount: wrong fs type, bad option, bad superblock on /dev/sdb1'. Which is the most likely cause?

A.The UUID specified in fstab does not match the actual UUID of /dev/sdb1.
B.The mount point /mnt does not exist.
C.The kernel does not have XFS support enabled.
D.The filesystem on /dev/sdb1 is not XFS but ext4.
AnswerD

If /dev/sdb1 actually contains an ext4 filesystem, the mount command would report "wrong fs type, bad option, bad superblock" only when the fstab entry specifies `xfs` and the filesystem type is inconsistent. However, a UUID mismatch prevents the mount from even locating the device — the error occurs during device resolution, before the kernel reads the superblock — so the failure described in the question would happen regardless of whether the filesystem type were ext4 or XFS. Moreover, an ext4 filesystem mounted with the correct UUID would succeed, so merely having ext4 on the device does not inherently cause a boot-time mount failure.

Why this answer

The error 'wrong fs type, bad option, bad superblock' occurs when the device exists but the filesystem type does not match or the superblock is unreadable. Since the error explicitly mentions /dev/sdb1, the UUID must have resolved to that device. Therefore, a UUID mismatch would produce a different error like 'can't find UUID=abc123' or 'no such device'.

The most likely cause is that /dev/sdb1 is not formatted as XFS (e.g., it is ext4). A missing mount point gives 'No such file or directory', and kernel XFS support issues typically produce 'unknown filesystem type'.

Exam trap

A UUID mismatch results in 'mount: can't find UUID=...' or 'no such device', not a 'wrong fs type' error. The error 'wrong fs type, bad option, bad superblock' points to an actual device that cannot be mounted with the specified filesystem type, so candidates should suspect a filesystem type mismatch.

How to eliminate wrong answers

Option B is wrong because if the mount point /mnt did not exist, the error would be 'mount point does not exist' or 'No such file or directory', not a filesystem type error. Option C is wrong because if the kernel lacked XFS support, the error would be 'mount: unknown filesystem type 'xfs'' or similar, not a 'wrong fs type' message that implies the filesystem is recognized but mismatched. Option D is wrong because if the filesystem were ext4, the error would still be 'wrong fs type' only if the fstab explicitly specified 'xfs' and the kernel tried to mount it as XFS; however, the error message 'bad superblock' is more specific to a superblock mismatch, and the UUID mismatch is a more direct and common cause than a filesystem type mismatch, which would also produce a different error (e.g., 'mount: /dev/sdb1 is not a valid XFS filesystem').

30
Multi-Selecteasy

Which TWO of the following commands can be used to create an XFS filesystem on a block device?

Select 2 answers
A.mkfs.ext4 /dev/sdb1
B.mkfs.xfs /dev/sdb1
C.xfs_admin /dev/sdb1
D.mke2fs /dev/sdb1
E.mkfs -t xfs /dev/sdb1
AnswersB, E

mkfs.xfs is the XFS-specific formatting utility provided by the xfsprogs package. Running it against /dev/sdb1 initializes the partition with an XFS superblock, allocation-group headers, and the associated metadata structures. It is the canonical, unambiguous command for creating an XFS filesystem, which makes it a correct answer.

Why this answer

The `mkfs.xfs` command (option B) directly creates an XFS filesystem on a block device. The `mkfs -t xfs` command (option E) is the generic front-end that calls the same XFS-specific tool, making both valid. These are the standard methods for formatting a partition with the XFS filesystem in Red Hat Enterprise Linux.

Exam trap

The trap here is that candidates confuse filesystem creation commands with management commands (like `xfs_admin`) or assume `mke2fs` is a generic tool that can create any filesystem type, when it is strictly for ext2/3/4 families.

31
MCQmedium

A team wants to run a container as a non-root user inside the container for security. Which instruction should be included in the Containerfile?

A.USER
B.PODMAN_USER
C.ENV USER
D.RUN useradd
AnswerA

The USER instruction is the standard Containerfile directive that sets the active user for subsequent instructions, including the final CMD/ENTRYPOINT runtime process. By specifying a non-root user or numeric UID (e.g., USER 1000), the container runs with least privilege. This is the only option here that directly changes the identity of the running container process.

Why this answer

The USER instruction in a Containerfile (Dockerfile) sets the user name or UID to use when running the container and for any subsequent RUN, CMD, or ENTRYPOINT instructions. By default, containers run as root (UID 0), which poses a security risk. Using USER to switch to a non-root user (e.g., USER 1001) ensures the container process runs with reduced privileges, aligning with the principle of least privilege.

Exam trap

The trap here is that candidates often confuse creating a user (RUN useradd) with actually running as that user, forgetting that the USER instruction is required to switch the runtime context, or they invent non-existent instructions like PODMAN_USER.

How to eliminate wrong answers

Option B (PODMAN_USER) is wrong because there is no such instruction in Containerfile/Dockerfile syntax; Podman uses the same standard instructions as Docker. Option C (ENV USER) is wrong because ENV sets environment variables (e.g., ENV USER=myuser) but does not change the runtime user identity; the container still runs as root unless a USER instruction is used. Option D (RUN useradd) is wrong because while useradd creates a user account inside the image, it does not switch the active user for subsequent instructions or the container's entrypoint; you must still use USER to actually run as that user.

32
MCQhard

A script has a syntax error. Which command will help identify the line number of the error without executing the script?

A.which bash
B.bash -n script.sh
C.set -x
D.bash -v script.sh
AnswerB

The `bash -n script.sh` command invokes Bash's noexec mode, which causes the shell to read and parse the entire script but not execute any of its commands. The parser reports any syntax errors with the offending line number and returns a non-zero exit status, making this the standard method for syntax-checking a Bash script. Note that this check only validates grammar, not logical or runtime errors.

Why this answer

The `bash -n` (noexec) option performs syntax checking on a script without executing any commands. If a syntax error exists, Bash reports the error along with the line number, making it the correct tool for identifying syntax errors in a script without running it.

Exam trap

The Red Hat RHCSA exam often tests the distinction between syntax checking (`-n`) and execution tracing (`-x` or `-v`), so candidates mistakenly choose `set -x` thinking it will catch errors without execution, but it actually runs the script and only shows debug output.

How to eliminate wrong answers

Option A is wrong because `which bash` only displays the path to the Bash executable, not perform any syntax checking. Option C is wrong because `set -x` enables execution tracing (debug mode) that prints commands as they execute, but it does not prevent execution and does not report syntax errors without running the script. Option D is wrong because `bash -v` prints script lines as they are read, but it still executes the script and will not stop at a syntax error to report the line number without execution.

33
MCQmedium

A system administrator is managing a Red Hat Enterprise Linux 9 web server running Apache httpd. The server hosts a custom application that stores its files in /var/www/custom. The administrator has set ownership to apache:apache and file permissions to 755. However, when users access the web application, they receive a 'Forbidden' error. The httpd service is running, and SELinux is in enforcing mode. The administrator checks the SELinux context of the /var/www/custom directory and sees 'unconfined_u:object_r:default_t:s0'. What should the administrator do to resolve the issue without disabling SELinux?

A.Use semanage fcontext to set the SELinux type to httpd_sys_content_t and run restorecon
B.Set SELinux to permissive mode
C.Use chcon to set the SELinux type to httpd_sys_content_t
D.Add the apache user to the group that owns the directory
AnswerA

The correct procedure is to use `semanage fcontext` to add a persistent rule to the SELinux policy database that maps the target directory and its contents to the `httpd_sys_content_t` type, then run `restorecon` to apply that context to the filesystem. Because the rule is stored in the file context database, it survives system reboots and filesystem relabels initiated by `restorecon -R` or `fixfiles`. This is the standard, supported method for serving static web content from non-default directories such as `/var/www/html` or custom paths, and it ensures the type enforcement allows `httpd_t` to read the files.

Why this answer

The directory /var/www/custom has the SELinux type default_t, which the httpd_t domain is not permitted to read. Apache runs confined by SELinux, so even with correct Unix ownership and permissions, the kernel blocks access and returns 'Forbidden'. The correct fix is to persistently label the directory with httpd_sys_content_t using semanage fcontext, then apply it with restorecon.

This preserves SELinux enforcement while granting httpd the access it needs.

Exam trap

The trap is confusing DAC (Unix permissions/ownership) with MAC (SELinux type enforcement) — candidates see 755 and apache:apache and assume permissions are fine, missing that SELinux is the actual blocker.

How to eliminate wrong answers

Option B is wrong because setting SELinux to permissive mode disables enforcement — it masks the symptom rather than fixing the labeling and violates the requirement to keep SELinux enforcing. Option C is wrong because chcon changes the context only for the current files and is not persistent; a future restorecon or relabel will revert it, and it doesn't update the policy database. Option D is wrong because Unix group membership is irrelevant when SELinux type enforcement is the blocking control — the denial is at the SELinux layer, not the DAC layer.

34
MCQeasy

A user needs to find all files with the '.conf' extension under /etc. Which command should be used?

A.grep -r "*.conf" /etc
B.locate /etc/*.conf
C.ls /etc/*.conf
D.find /etc -name "*.conf"
AnswerD

find /etc -name "*.conf" is the correct choice because find recursively descends into all subdirectories of /etc, applying the -name test to every file and directory it encounters. The -name test compares the filename (basename) against the glob pattern "*.conf" using standard glob matching, and the double quotes ensure the shell passes the pattern to find rather than expanding it to existing filenames. This command outputs the full path of every file under /etc whose name ends in .conf, making it the proper tool for this name-based recursive search.

Why this answer

The `find` command is designed to search for files and directories based on criteria such as name, type, or size. Using `find /etc -name "*.conf"` recursively searches the entire `/etc` directory tree for files ending in `.conf`, which is the standard and most reliable method for this task.

Exam trap

The trap here is that candidates confuse `grep` (for content search) with `find` (for file search), or assume `ls` with a glob is sufficient, overlooking the need for recursion across subdirectories.

How to eliminate wrong answers

Option A is wrong because `grep -r` searches for text patterns inside file contents, not for filenames; it would attempt to match the literal string "*.conf" within files, not find files with that extension. Option B is wrong because `locate` relies on a pre-built database (updated by `updatedb`) and may not reflect recent changes or include all files under `/etc` by default; also, the pattern `/etc/*.conf` is a shell glob, not a valid `locate` argument. Option C is wrong because `ls /etc/*.conf` only lists files matching the glob in the immediate `/etc` directory, not in subdirectories, and will fail or produce errors if no matches are found or if there are too many matches.

35
MCQhard

A RHEL 9 system has a second disk /dev/sdb that needs to be partitioned with a single partition using all space, formatted with XFS, and mounted persistently at /data. The administrator uses fdisk to create the partition /dev/sdb1. Which filesystem creation command should be used?

A.mkfs.xfs /dev/sdb1
B.mke2fs /dev/sdb1
C.mkfs -t ext4 /dev/sdb1
D.mkfs.ext4 /dev/sdb1
AnswerA

mkfs.xfs is the correct command because it explicitly initializes an XFS filesystem on the target partition. XFS is the default filesystem in RHEL 9 for root and many standard partitions, and this invocation creates the required on-disk structure, including the superblock, allocation groups, and B+tree metadata. After running this command, the partition can be mounted and used as an XFS volume.

Why this answer

The correct command is mkfs.xfs /dev/sdb1 because the question specifies that the partition must be formatted with XFS. The mkfs.xfs command is the dedicated tool for creating an XFS filesystem on a block device. It directly invokes the mkfs.xfs utility, which writes the XFS superblock and metadata structures to the partition.

Exam trap

The trap here is that candidates often confuse mkfs.xfs with generic mkfs commands or ext-family tools, assuming any mkfs variant will work, but the exam specifically tests knowledge of the correct filesystem-specific command for XFS.

How to eliminate wrong answers

Option B is wrong because mke2fs is a legacy command for creating ext2/ext3/ext4 filesystems, not XFS. Option C is wrong because mkfs -t ext4 creates an ext4 filesystem, not XFS. Option D is wrong because mkfs.ext4 is a convenience wrapper for creating ext4 filesystems, not XFS.

36
Multi-Selecteasy

Which THREE of the following are valid utilities for creating partitions on a disk in Red Hat Enterprise Linux?

Select 3 answers
A.mkfs
B.mount
C.fdisk
D.gdisk
E.parted
AnswersC, D, E

fdisk is the traditional interactive text-based utility for creating, modifying, and deleting partitions on MBR (DOS) partition tables, and modern versions also support GPT with a compatible interface. It writes partition entries that define start and end sectors, partition type, and boot flag, but it cannot directly create a filesystem without a separate mkfs step. fdisk is well-suited for manual partition planning and small disks.

Why this answer

C is correct because `fdisk` is a traditional command-line utility for creating, deleting, and managing MBR (Master Boot Record) partition tables on disks in Red Hat Enterprise Linux. It supports interactive and scripted partitioning, making it a valid tool for local storage configuration.

Exam trap

The trap here is that candidates often confuse filesystem creation (`mkfs`) or mounting (`mount`) with actual partition creation, leading them to select those invalid options instead of the correct partitioning utilities.

37
MCQeasy

Which command displays the current system time, timezone, and whether NTP synchronization is active?

A.ntpq -p
B.date
C.timedatectl
D.cal
AnswerC

timedatectl is the correct command because it gives a consolidated, systemd-based view of the time and timezone configuration. Running it with no arguments prints local time, universal time (UTC), RTC time, the currently configured timezone (e.g., 'Europe/Amsterdam'), and whether NTP synchronization is active or enabled. It also supports subcommands like set-timezone to change the configuration, making it the standard utility for this purpose on modern Linux distributions. Thus it directly and unambiguously displays both the current system time and the timezone, plus related status information.

Why this answer

The `timedatectl` command (option C) is the correct tool in Red Hat Enterprise Linux (RHEL) for querying and configuring system time, timezone, and NTP synchronization status. It displays the current local time, timezone, and whether NTP is active or enabled in a single, clear output, making it the standard utility for these tasks in systemd-based systems.

Exam trap

The trap here is that candidates often choose `ntpq -p` (option A) because they associate it with NTP, but they overlook that it does not show the system time or timezone, which the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because `ntpq -p` only shows the list of NTP peers and their synchronization status (e.g., delay, offset, jitter), but it does not display the current system time or timezone. Option B is wrong because `date` outputs the current date and time but does not show the timezone name or NTP synchronization status. Option D is wrong because `cal` simply displays a calendar for a given month or year and has no relation to time, timezone, or NTP.

38
Multi-Selecteasy

Which TWO commands can list all groups a user belongs to? (Choose exactly 2)

Select 2 answers
A.id -nG
B.cat /etc/group | grep user
C.usermod -g user
D.getent group user
E.groups
AnswersA, E

The `id -nG` command prints all group IDs for the named user (or the current user if no user is given) and then converts those numeric IDs to names via the `-n` flag. Because `id` queries the system's user and group databases through NSS, it includes the primary group from `/etc/passwd` and every supplementary group from `/etc/group` (or LDAP/SSSD), making it a complete and script-friendly listing.

Why this answer

Option A, `id -nG`, is correct because it prints the names of all groups the specified user is a member of, including both the primary group and supplementary groups, using the `-n` flag to show names instead of numeric GIDs and `-G` to list all group memberships. Option E, `groups`, is correct because it displays the groups a user belongs to, defaulting to the current user or accepting a username argument, and it reads from the same system group database to show all memberships. Option B, `cat /etc/group | grep user`, is not reliable because it only matches the literal string 'user' in the group file and may miss memberships or match unintended entries, and it does not handle network-based group sources.

Option C, `usermod -g user`, is incorrect because it modifies a user's primary group rather than listing group memberships. Option D, `getent group user`, is incorrect because it queries the group database for a group named 'user' and lists that group's members, not all groups a user belongs to.

Exam trap

The trap here is that candidates often think `cat /etc/group | grep user` or `getent group user` will list all groups for a user, but these commands only search for a group named 'user' or lines containing the string, not the user's actual group memberships, which is a common misconception tested on the EX200 exam.

39
MCQhard

Refer to the exhibit. A user tries to execute a script located in /data/script.sh but gets 'Permission denied'. The script has execute permissions. What is the most likely cause?

A.The filesystem is mounted with noexec
B.The filesystem is full
C.SELinux is blocking execution
D.The script is in a directory with noexec
AnswerA

A `noexec` mount option on the filesystem is the direct cause: the kernel refuses to execute any file (binary or script) from that mount, even if the file has executable permissions set. This is enforced at the VFS layer, so attempting to run the script with `./script.sh` will return `Permission denied` or `Operation not permitted`, matching the reported symptom. The option is set in `/etc/fstab` (or via `mount -o noexec`), and it overrides normal execute-bit checks.

Why this answer

The most likely cause is that the filesystem where /data resides is mounted with the 'noexec' option. This mount option prevents the execution of any binary or script directly from that filesystem, regardless of the file's individual execute permissions. The 'noexec' flag is commonly set on partitions like /tmp or /var for security reasons, and it overrides the file's permission bits.

Exam trap

Red Hat often tests the distinction between file-level permissions and filesystem-level mount options, where candidates mistakenly think execute permissions alone guarantee execution, ignoring that mount options like 'noexec' can override them.

How to eliminate wrong answers

Option B is wrong because a full filesystem would produce a 'No space left on device' error, not 'Permission denied'. Option C is wrong because SELinux blocking execution typically produces an 'Operation not permitted' or AVC denial message, not a generic 'Permission denied', and the question states the script has execute permissions. Option D is wrong because directories themselves do not have a 'noexec' attribute; the 'noexec' option is a mount-level filesystem flag, not a directory-level attribute.

40
MCQmedium

Refer to the exhibit. An administrator runs xfs_growfs on /dev/sdc1. What is the most likely reason the command succeeded without prior partition resizing?

A.The partition was automatically resized by xfs_growfs
B.The underlying block device (partition or logical volume) was extended before the command
C.The filesystem was already using the full partition size and the command had no effect
D.The filesystem was mounted with the 'grow' option allowing online growth
AnswerB

xfs_growfs works by expanding the filesystem's data allocation structures to consume the additional space that must already exist on the backing device. Before running the command, the administrator must have extended the partition or logical volume using lvextend or a partition editor. When invoked on a mounted XFS filesystem with no arguments, it grows the filesystem to the maximum size permitted by the underlying block device.

Why this answer

xfs_growfs can only expand an XFS filesystem to fill the available space on the underlying block device. If the command succeeded without prior partition resizing, it means the block device (e.g., a partition or logical volume) was already extended beforehand. The filesystem then uses the new space when xfs_growfs is run.

Exam trap

A common misconception is that xfs_growfs can resize the partition itself, but it only expands the filesystem to match an already extended block device (e.g., LVM volume or disk partition).

How to eliminate wrong answers

Option A is wrong because xfs_growfs does not resize partitions; it only grows the filesystem within the existing block device. Option C is wrong because if the filesystem already used the full partition, xfs_growfs would report that no change was needed, but the question states the command 'succeeded' (implying growth occurred). Option D is wrong because there is no 'grow' mount option in XFS; online growth is handled by xfs_growfs itself, not a mount flag.

41
MCQmedium

An administrator writes a script to check disk usage and send an alert if usage exceeds 80%. The script uses 'df -h /' and parses the output. To maintain portability and avoid common pitfalls, which approach is recommended?

A.Use 'df -h / | tail -1 | sed 's/.* //' | tr -d '%'
B.Use 'df -h / | tail -1 | cut -d' ' -f5'
C.Use 'df / | awk 'NR==2 {print $5}' | tr -d '%'
D.Use 'df -h / | grep -oP '\d+%'
AnswerC

This option uses `df /` without `-h`, which produces a stable, machine-parseable output. The `awk` command extracts the fifth field (the percentage used) and `tr` removes the percent sign. This is portable across different Unix/Linux systems.

Why this answer

It uses `df /` (without `-h`) to produce a stable, machine-parseable output where the fifth field (`$5`) is always the percentage used, and `awk` reliably extracts it. The `tr -d '%'` removes the percent sign for numeric comparison. This approach avoids the portability issues of parsing human-readable output from `df -h`, which can vary in column spacing and ordering across different Unix/Linux systems.

Exam trap

The trap on the RHCSA exam is that candidates assume `-h` is always better for readability, but the exam tests understanding that human-readable output is unreliable for scripting due to inconsistent column formatting across different Unix/Linux distributions.

How to eliminate wrong answers

Option A is wrong because `sed 's/.* //'` greedily removes everything up to the last space, which fails if the mount point contains spaces or if the output format varies (e.g., long device names). Option B is wrong because `cut -d' ' -f5` splits on single spaces, but `df -h` output often uses multiple spaces or tabs as delimiters, causing `cut` to misinterpret columns. Option D is wrong because `grep -oP` uses Perl-compatible regex, which is not available in all environments (e.g., older systems or minimal installations), and the pattern `\d+%` may match unexpected text like '1%' in a filesystem name.

42
MCQhard

During boot, a server fails to mount an NFS filesystem listed in /etc/fstab. Which troubleshooting step should be taken first to isolate the issue?

A.Check the status of remote-fs.target with 'systemctl status remote-fs.target'
B.Check the status of nfs-client.target with 'systemctl status nfs-client.target'
C.Try to manually mount the NFS share with 'mount /mnt/nfs'
D.View kernel messages with 'dmesg | grep -i nfs'
AnswerA

Checking 'systemctl status remote-fs.target' is the correct first step because systemd uses this target to synchronize the activation of all remote filesystem mounts, including NFS, during the boot sequence. If the target is in a 'failed' or 'degraded' state, the status output will directly show which mount unit failed and why, allowing you to then inspect that specific unit's logs or configuration rather than guessing. This target is explicitly ordered after network-online.target and pulls in the mount units, so its state is the authoritative indicator of whether boot-time NFS mounting was attempted and completed.

Why this answer

When an NFS filesystem fails to mount during boot, the first step is to check whether the remote-fs.target unit is active. This target is responsible for triggering the mounting of all remote filesystems (including NFS) after the network is available. If remote-fs.target is not active or has failed, the NFS mount will not be attempted, and troubleshooting should start here before investigating the NFS share itself.

Exam trap

Red Hat often tests the misconception that NFS client services (nfs-client.target) are responsible for mounting NFS filesystems, when in fact the mounting is orchestrated by remote-fs.target, and troubleshooting should start there.

How to eliminate wrong answers

Option B is wrong because nfs-client.target is a target that only ensures NFS client services (like rpcbind and nfs-idmapd) are started, but it does not directly control the mounting of filesystems listed in /etc/fstab; the actual mount is governed by remote-fs.target. Option C is wrong because attempting to manually mount the share with 'mount /mnt/nfs' assumes the issue is with the share or network, but if the boot failure is due to a missing or misconfigured remote-fs.target, the manual mount might succeed and mislead the troubleshooting; the correct first step is to check the target status. Option D is wrong because viewing kernel messages with 'dmesg | grep -i nfs' can provide useful details after the target status is verified, but it is not the first step; the boot failure may be caused by a target dependency issue that dmesg would not directly reveal.

43
MCQmedium

An administrator needs to measure the execution time of the command 'backup.sh'. Which command prefix should be used?

A.time
B.date
C.watch
D.timeout
AnswerA

The `time` utility, whether the Bash reserved word or the external `/usr/bin/time` binary, is specifically designed to measure how long a command takes to complete. It reports real (wall-clock), user, and system CPU time consumed by the command, typically written to stderr. For example, `time ls -lR /etc` prints a timing summary after the command finishes, making it the correct tool for measuring execution duration.

Why this answer

The 'time' command is the correct prefix to measure the execution time of a command in Linux. When placed before 'backup.sh', it runs the script and then outputs the real, user, and system time consumed, providing the precise measurement the administrator needs.

Exam trap

The trap here is that candidates may confuse 'time' with 'timeout' because both involve time, but 'timeout' controls execution duration while 'time' measures it.

How to eliminate wrong answers

Option B is wrong because 'date' displays or sets the system date and time, not the execution duration of a command. Option C is wrong because 'watch' repeatedly runs a command at a specified interval (default 2 seconds) to monitor its output, not to measure its execution time. Option D is wrong because 'timeout' runs a command with a time limit and kills it if it exceeds that limit, which is for controlling runtime, not measuring it.

44
MCQmedium

Refer to the exhibit. An administrator wants to create an LVM logical volume using /dev/sdb3. What is the first step to complete this task?

A.Format the partition with mkfs.ext4 /dev/sdb3
B.Create a physical volume with pvcreate /dev/sdb3
C.Create a logical volume with lvcreate -L 10G -n lv01 vg01
D.Create a volume group with vgcreate vg01 /dev/sdb3
AnswerC

The exhibit confirms that the physical volume /dev/sdb3 and the volume group vg01 already exist, so the only remaining prerequisite is to create the logical volume itself. The command lvcreate -L 10G -n lv01 vg01 allocates a 10 GiB logical volume named lv01 from the free extents in vg01, which is exactly the correct next step. Afterward, a filesystem can be created on /dev/vg01/lv01.

Why this answer

Based on the exhibit, /dev/sdb3 is already initialized as a physical volume and belongs to a volume group. Therefore, the first step to create a logical volume is to use lvcreate directly, as the PV and VG are already in place. Option B is incorrect because pvcreate is not needed when the partition is already a PV.

Exam trap

The trap is that candidates may assume they must always run pvcreate first, but the exhibit shows the PV already exists. Always verify the current state of the disk before deciding the next step.

How to eliminate wrong answers

Option A is wrong because formatting the partition with mkfs.ext4 creates a filesystem directly on the block device, which bypasses LVM entirely and prevents its use as a physical volume. Option C is wrong because lvcreate requires an existing volume group (vg01) that already contains physical volumes; attempting this step first would fail as vg01 does not exist. Option D is wrong because vgcreate requires at least one initialized physical volume as an argument; /dev/sdb3 must first be a PV via pvcreate before it can be added to a volume group.

45
MCQmedium

A system administrator needs to find all regular files larger than 10MB in /var/log. Which find command should they use?

A.find /var/log -type f -size -10M
B.find /var/log -type d -size +10M
C.find /var/log -type f -size 10M
D.find /var/log -type f -size +10M
AnswerD

The plus sign in `-size +10M` is the "greater than" operator, so this command finds all regular files over 10 MiB in /var/log. The `-type f` option filters for regular files only, excluding directories, symlinks, and special files. This is the correct way to identify large files with find.

Why this answer

It uses `-type f` to select only regular files and `-size +10M` to match files larger than 10 megabytes. The `+` prefix in the `-size` test means 'greater than', which is the correct syntax for finding files exceeding a given size.

Exam trap

Red Hat often tests the `+` and `-` prefix syntax for `-size`, and the trap here is that candidates confuse `-size +10M` with `-size 10M` or `-size -10M`, or they mistakenly use `-type d` instead of `-type f` when the question specifies regular files.

How to eliminate wrong answers

Option A is wrong because `-size -10M` uses the `-` prefix, which means 'less than 10MB', not 'greater than'. Option B is wrong because `-type d` selects directories, not regular files, and the question specifically asks for regular files. Option C is wrong because `-size 10M` without a `+` or `-` prefix matches files exactly 10MB in size, not files larger than 10MB.

46
MCQhard

An administrator is migrating user accounts to a new system. They want to preserve the user's primary group name and GID. Which commands should be used in sequence?

A.useradd -u <UID> -g <group> <user>
B.useradd -g <group> <user>
C.groupadd --gid <GID> <group> && useradd -g <group> <user>
D.groupadd -g <GID> <group> then useradd -g <group> <user>
AnswerC

This is the correct sequence because groupadd --gid explicitly creates the group with the requested GID, and the && operator ensures the subsequent useradd runs only if groupadd succeeds. The useradd -g then sets that newly-created group as the user's primary group. This atomic two-step chain guarantees both objects exist with the intended numeric GID.

Why this answer

To preserve the primary group name and GID during migration, you must first create the group with the desired GID using `groupadd --gid <GID> <group>`, then create the user with that group using `useradd -g <group> <user>`. Option A fails because the group does not exist; Option B fails for the same reason if the group is new; Option D is not a valid shell command sequence because 'then' is not a command.

47
Multi-Selecteasy

Which TWO commands are needed to set up a swap partition on /dev/sdd1 for immediate use?

Select 2 answers
A.swapon /dev/sdd1
B.parted /dev/sdd mkswap
C.mkswap /dev/sdd1
D.swapon -a
E.mkfs.swap /dev/sdd1
AnswersA, C

The swapon command activates an existing swap device. After a partition has been prepared with mkswap, it is not automatically enabled; running swapon /dev/sdd1 makes the kernel immediately use that partition as paging space. Without this step, the swap space remains available only as a prepared but inactive signature on disk.

Why this answer

The `swapon /dev/sdd1` command activates the swap partition immediately, making it available for the kernel to use as virtual memory. Option C is correct because `mkswap /dev/sdd1` writes the swap signature (UUID and swap superblock) to the partition, which is a prerequisite for any swap device to be recognized by the kernel. Together, these two commands first prepare the partition as a swap area and then enable it for immediate use.

Exam trap

Red Hat often tests the distinction between preparing a swap device (`mkswap`) and activating it (`swapon`), and the trap here is that candidates might think `swapon -a` or a single command like `mkfs.swap` is sufficient, when in fact both steps are required and the correct command names are specific.

48
MCQeasy

A user reports that they cannot start a service. Which command would an administrator use to view the service's journal logs since last boot?

A.journalctl -b
B.journalctl -u service -b
C.journalctl service
D.dmesg | grep service
AnswerB

Running `journalctl -u service -b` combines the `--unit` filter with the `--boot` option, instructing systemd's journal to display only log records belonging to the specified service unit within the current boot cycle. This is the precise diagnostic command because it isolates the service's own output, errors, and exit status messages. It also automatically appends `.service` to the name if omitted, making it the recommended method for checking why a service failed to start.

Why this answer

`journalctl -u service -b` combines the `-u` flag to filter logs for a specific systemd unit (the service) with the `-b` flag to show only logs from the current boot. This is the precise command an administrator would use to view a service's journal logs since the last system start, directly addressing the user's inability to start the service.

Exam trap

The trap here is that candidates often forget the `-u` flag is mandatory to filter for a specific service unit, mistakenly thinking `journalctl service` is valid, or they confuse `journalctl -b` (all logs since boot) with the more targeted command needed for service-specific troubleshooting.

How to eliminate wrong answers

Option A is wrong because `journalctl -b` shows all journal logs since the last boot, but without the `-u` flag it does not filter for a specific service, making it impractical for troubleshooting a single service. Option C is wrong because `journalctl service` is invalid syntax; `journalctl` requires the `-u` flag to specify a unit name, otherwise it treats 'service' as a non-existent option or argument. Option D is wrong because `dmesg | grep service` displays kernel ring buffer messages, which are primarily hardware and driver-related, not the detailed service logs from systemd-journald, and it does not filter by boot session.

49
MCQhard

A system administrator is managing a Red Hat Enterprise Linux 9 server that uses LVM for storage. The volume group 'vgdata' contains two 500 GB physical volumes (sdb and sdc) with a logical volume 'lvdata' of 800 GB formatted with XFS and mounted at /data. The administrator adds a new 200 GB disk /dev/sdd and intends to use all of its capacity to extend lvdata. The following commands are executed in order: pvcreate /dev/sdd, vgextend vgdata /dev/sdd, lvextend -l +100%FREE /dev/vgdata/lvdata. The lvextend command completes successfully, but running 'df -h /data' still shows 800 GB. What is the most likely reason?

A.The volume group 'vgdata' is not active, so the new space is ignored.
B.The logical volume was extended using a snapshot instead of the original.
C.The filesystem has not been grown after extending the logical volume.
D.The physical volume was not created correctly and the space is not available.
AnswerC

Extending a logical volume with lvextend only increases the size of the block device; the filesystem on top of it remains unchanged until explicitly resized. For XFS filesystems, the resize must be performed with xfs_growfs, which can only grow the filesystem online to fill the additional space in the LV. Since the administrator has presumably not run xfs_growfs (or did not mount the filesystem with a tool that auto-grows it), the new space is allocated but not yet available to files, which exactly matches the symptom.

Why this answer

After extending the logical volume with `lvextend`, the underlying block device has more space, but the filesystem still sees the original size. For XFS, you must run `xfs_growfs /data` (or `xfs_growfs /dev/vgdata/lvdata`) to expand the filesystem to use the newly allocated extents. Without this step, `df -h` continues to report the old filesystem size.

Exam trap

The trap here is that candidates assume `lvextend` automatically resizes the filesystem, but Red Hat exams specifically test that you must run a separate filesystem-specific command (e.g., `xfs_growfs` or `resize2fs`) after extending the logical volume.

How to eliminate wrong answers

Option A is wrong because the volume group must be active for `lvextend` to succeed; the command completed successfully, confirming vgdata is active. Option B is wrong because snapshots are separate logical volumes; extending the original LV does not involve snapshots, and no snapshot was created in the scenario. Option D is wrong because `pvcreate /dev/sdd` and `vgextend vgdata /dev/sdd` both succeeded, and the `lvextend` command used `+100%FREE`, which would have failed if the PV were not available.

50
Multi-Selecthard

Which THREE commands can be used to monitor real-time process status and update the display every 2 seconds? (Choose three.)

Select 3 answers
A.htop
B.top -d 2
C.ps aux
D.watch -n 2 ps aux
E.at 2
AnswersA, B, D

htop is an ncurses-based interactive process viewer that updates its display continuously by default, refreshing CPU, memory, and per-process statistics roughly once per second while it remains in the foreground. It redraws the screen in place, so you see live changes without rerunning a command, and it also lets you sort, filter, and signal processes interactively. Because it keeps running and updating until you quit, it is a genuine real-time process monitor.

Why this answer

Option A, htop, is correct because it is an interactive real-time process viewer that continuously refreshes its display (by default every second, and its refresh interval is configurable), so it can monitor process status in real time. Option B, top -d 2, is correct because top is the classic real-time process monitor and the -d 2 flag explicitly sets the screen update delay to 2 seconds. Option D, watch -n 2 ps aux, is correct because watch repeatedly executes the given command at a fixed interval, and -n 2 makes it rerun ps aux every 2 seconds, producing a refreshed process listing.

Option C, ps aux, is not correct because ps is a one-shot snapshot command that prints process information once and exits, with no continuous refresh. Option E, at 2, is not correct because at is a job-scheduling utility for running commands at a specified future time, not a real-time process monitoring tool.

Exam trap

Red Hat often tests the distinction between snapshot commands (like `ps aux`) and real-time monitoring tools (like `top`, `htop`, or `watch`), trapping candidates who think `ps aux` can update continuously without an external wrapper like `watch`.

51
Multi-Selecteasy

A system administrator needs to ensure a service called 'myapp' starts automatically at boot and also start it immediately without affecting the current boot configuration. Which TWO commands should be used?

Select 2 answers
A.systemctl daemon-reload myapp
B.systemctl start myapp
C.systemctl restart myapp
D.systemctl activate myapp
E.systemctl enable myapp
AnswersB, E

`systemctl start myapp` immediately activates the unit by loading it into memory, satisfying its dependencies, and launching the main process defined in `ExecStart`. This changes the unit's *active* state but not its *enabled* state, so myapp will not automatically start after a reboot unless it is also enabled.

Why this answer

The 'systemctl enable myapp' command creates the necessary symlinks so that the service starts automatically at boot, while 'systemctl start myapp' launches the service immediately in the current session without altering the boot configuration. Together, they satisfy both requirements without affecting the existing boot setup.

Exam trap

The trap here is that candidates confuse 'enable' with 'start' or think 'restart' or 'daemon-reload' can achieve both goals, but only the combination of 'enable' (for boot persistence) and 'start' (for immediate activation) meets the exact requirements.

52
MCQmedium

A system administrator needs to change the primary group of an existing user to a group that already exists. Which command should be used?

A.groupmod -g existinggroup username
B.usermod -g existinggroup username
C.usermod -p existinggroup username
D.usermod -G existinggroup username
AnswerB

This is correct because `usermod -g` directly modifies the user's primary group by changing the GID field in the `/etc/passwd` entry. The specified group must already exist on the system, otherwise `usermod` will return an error and make no changes. After this command, newly created files and directories will inherit this group as their owning group by default, until the user changes it.

Why this answer

The `usermod -g` command changes the primary group of an existing user to a specified group that already exists on the system. The `-g` option sets the initial login group (GID) for the user, which must be a valid group name or GID from `/etc/group`.

Exam trap

The trap here is confusing the `-g` (primary group) and `-G` (supplementary groups) options of `usermod`, leading candidates to pick option D when they need to change the primary group.

How to eliminate wrong answers

Option A is wrong because `groupmod -g` changes the GID of an existing group, not the primary group of a user. Option C is wrong because `usermod -p` is used to set or change the user's password (encrypted), not their group membership. Option D is wrong because `usermod -G` sets the supplementary (secondary) group list for the user, not the primary group.

53
MCQmedium

A junior system administrator configures rsyslog on a RHEL 9 server to forward logs to a remote centralized log server. They add the line *.* @192.168.1.100:514 to /etc/rsyslog.conf and restart rsyslog with systemctl restart rsyslog. Local logging works fine, but the remote server does not receive any logs. The administrator checks the local firewall and confirms that UDP port 514 is open outbound. They also verify network connectivity using nc. What is the most likely cause?

A.The systemd unit for rsyslog is masked, preventing it from running.
B.The remote rsyslog server is not listening on UDP port 514.
C.The SELinux boolean rsyslog_remote is disabled, blocking outbound syslog.
D.The configuration should use @@ for TCP instead of @ for UDP.
AnswerC

On RHEL 9, SELinux ships with the rsyslog_remote boolean disabled by default, which prevents rsyslogd from making outbound TCP/UDP connections to a central log server. Even with a correct rsyslog action line (e.g., *.* @192.0.2.10:514), SELinux will silently drop the packet and log an AVC denial in /var/log/audit/audit.log. Enabling the boolean with `setsebool -P rsyslog_remote 1` allows rsyslog to send syslog messages over the network, making this the correct fix when the service restarts normally but no logs arrive at the remote server.

Why this answer

On RHEL 9, SELinux enforces a targeted policy that blocks rsyslog from making outbound network connections by default. The boolean `rsyslog_remote` controls this behavior; when disabled, SELinux denies the outbound syslog traffic even though the local firewall allows it. The administrator must enable this boolean with `setsebool -P rsyslog_remote on` to allow rsyslog to forward logs via UDP or TCP.

Exam trap

The trap here is that candidates focus on network-level troubleshooting (firewall, connectivity) and overlook SELinux, which is a mandatory access control layer that can block outbound connections even when the firewall is open.

How to eliminate wrong answers

Option A is wrong because if the systemd unit for rsyslog were masked, the `systemctl restart rsyslog` command would fail with an error, and local logging would not work. Option B is wrong because the administrator verified network connectivity with `nc`, which would fail if the remote server were not listening on UDP 514, and the question states local logging works fine, implying the remote server is reachable. Option D is wrong because the `@` directive correctly specifies UDP transport; using `@@` would switch to TCP, which is not required and would not fix the SELinux block.

54
MCQmedium

Refer to the exhibit. Why did the sshd service fail?

A.The service binary is missing.
B.The service start was requested too many times in quick succession.
C.The configuration file /etc/ssh/sshd_config has a syntax error.
D.The system ran out of memory.
AnswerB

The log literally contains the message 'start request repeated too quickly', which is systemd's rate-limiting protection for units that crash immediately after starting. When a service fails more than StartLimitBurst times within StartLimitIntervalSec, systemd refuses to attempt further starts until the interval elapses or the unit is reset. The sshd service has hit this start limit, so the failure is correctly explained by too many rapid restart attempts, not by a faulty binary, bad config, or memory exhaustion.

Why this answer

B is correct because systemd's `StartLimitIntervalSec` and `StartLimitBurst` settings (default: 10 seconds and 5 starts) prevent rapid service restarts. When `sshd` fails repeatedly within the interval, systemd marks it as failed with the status 'start-limit-hit' to avoid resource exhaustion from restart loops.

Exam trap

The trap here is that candidates assume the failure is due to a configuration error or missing binary, but the 'start-limit-hit' status is a systemd mechanism that explicitly indicates too many restart attempts, not a problem with the service itself.

How to eliminate wrong answers

Option A is wrong because if the service binary were missing, `systemctl status sshd` would show 'Exec format error' or 'No such file or directory', not a start-limit-hit failure. Option C is wrong because a syntax error in `/etc/ssh/sshd_config` would cause `sshd` to exit with a specific error message in the journal (e.g., 'Bad configuration option'), not a start-limit-hit from systemd. Option D is wrong because out-of-memory conditions produce OOM-killer logs or 'Cannot allocate memory' errors in the journal, not the start-limit-hit status shown in the exhibit.

55
MCQeasy

A new intern created a script to display the current user's home directory: #!/bin/bash echo "Home directory: $home" The script outputs 'Home directory: ' with nothing after the colon. What is the most likely cause?

A.The HOME variable is not set in the environment.
B.There is a typo: it should be $HOME, not $home.
C.The script is run with 'sh' instead of 'bash'.
D.The root user has no home directory.
AnswerB

The command uses $home, which is a different variable name from $HOME because bash is case-sensitive. Environment variables like HOME are uppercase by convention, and the lowercase $home is not defined in any standard shell session, so it expands to an empty string. Assigning or exporting a lowercase home would require the script author to have previously set it, and echo "$home" would then output that value rather than the actual home directory. The only correct fix is to change the script to use $HOME (or ${HOME}).

Why this answer

Bash variable names are case-sensitive, so $home is a distinct variable from the standard $HOME environment variable. Since 'home' was never assigned, it expands to an empty string, producing the observed output. The correct reference is $HOME.

Exam trap

EX200 often tests whether candidates overlook shell case-sensitivity and instead blame environment configuration or shell choice, when the real cause is a simple variable-name typo.

How to eliminate wrong answers

Option A is wrong because HOME is virtually always set in an interactive login environment; the issue is the variable name case, not its absence. Option C is wrong because both sh and bash treat variable names as case-sensitive, so running under sh would produce the same empty result. Option D is wrong because even root has a home directory (typically /root) and HOME is set for root; the script would still fail due to the lowercase variable name.

56
Multi-Selecteasy

Which TWO commands can be used to view the contents of a compressed file named 'data.log.gz' without decompressing it permanently? (Choose exactly two.)

Select 2 answers
A.gunzip data.log.gz
B.zcat data.log.gz
C.zless data.log.gz
D.gzip -d data.log.gz
E.bzcat data.log.gz
AnswersB, C

zcat data.log.gz reads the gzip-compressed file, decompresses it, and writes the result to standard output, leaving data.log.gz completely unchanged. Its non-destructive, streaming behavior makes it ideal for piping into tools like head or grep, or for redirecting to another file. Note that zcat is functionally equivalent to gunzip -c.

Why this answer

B is correct because `zcat` reads the contents of a gzip-compressed file and outputs them to standard output without permanently decompressing the file. It is functionally equivalent to `gunzip -c` and is the standard tool for viewing compressed text files in place.

Exam trap

Red Hat often tests the distinction between commands that permanently decompress (gunzip, gzip -d) versus those that only view the contents (zcat, zless, zmore), and candidates frequently confuse `bzcat` as a valid alternative for .gz files.

57
Drag & Dropmedium

Order the steps to configure SELinux to allow Apache to read files in a custom directory /webcontent.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

SELinux configuration involves setting proper file context for Apache to access custom directories.

58
MCQeasy

An administrator needs to add a 2GB swap partition to an existing disk (/dev/sdc) that already has one partition. The administrator creates a second primary partition using fdisk and sets the type to Linux swap (82). Which command completes the setup to enable swap?

A.swapon /dev/sdc2
B.mkfs.swap /dev/sdc2 && swapon /dev/sdc2
C.mkswap /dev/sdc2 && swapon /dev/sdc2
D.mkswap /dev/sdc && swapon /dev/sdc
AnswerC

mkswap /dev/sdc2 writes the swap signature and metadata to the /dev/sdc2 partition, preparing it for use as swap space. Then swapon /dev/sdc2 activates it immediately, making the kernel use it for paging. This two-step sequence is the correct procedure, and you can verify that it worked with swapon --show or by checking the output of free.

Why this answer

After creating the partition with fdisk and setting the type to 82 (Linux swap), the partition must be formatted as a swap area using `mkswap` before it can be activated. The `swapon` command then enables the swap space. Option C correctly chains `mkswap /dev/sdc2` to initialize the swap signature and `swapon /dev/sdc2` to activate it.

Exam trap

Red Hat often tests the distinction between formatting a filesystem (`mkfs`) and initializing swap (`mkswap`), leading candidates to mistakenly use `mkfs.swap` or skip the initialization step entirely.

How to eliminate wrong answers

Option A is wrong because `swapon` alone cannot activate a partition that has not been initialized as a swap area; it requires a valid swap signature written by `mkswap`. Option B is wrong because `mkfs.swap` is not a valid command; the correct command is `mkswap`. Option D is wrong because it targets the whole disk `/dev/sdc` instead of the specific partition `/dev/sdc2`, and the disk itself cannot be used as swap without a partition table and proper initialization.

59
MCQhard

An administrator wants to create a symbolic link named 'link_to_hosts' in /tmp that points to /etc/hosts. Which command is correct?

A.ln -s /tmp/link_to_hosts /etc/hosts
B.ln -s /etc/hosts /tmp/link_to_hosts
C.ln -s /etc/hosts link_to_hosts
D.ln -s /tmp/link_to_hosts /etc/hosts
AnswerB

This command correctly uses the syntax ln -s <target> <link_name>, with /etc/hosts as the target and /tmp/link_to_hosts as the new symlink. The link is created with absolute path /tmp/link_to_hosts, and accessing it will resolve to /etc/hosts. Because /tmp/link_to_hosts does not already exist, no files are overwritten, making this the correct way to create the requested link.

Why this answer

The `ln -s` command creates a symbolic link. The correct syntax is `ln -s TARGET LINK_NAME`. Option B correctly specifies the existing target file `/etc/hosts` first, followed by the new link path `/tmp/link_to_hosts`, which creates the symbolic link in `/tmp` pointing to `/etc/hosts`.

Exam trap

Red Hat often tests the argument order of `ln -s`, where candidates mistakenly place the link name before the target, confusing it with the `cp` or `mv` command syntax where the destination comes last.

How to eliminate wrong answers

Option A is wrong because it reverses the arguments, attempting to create a link named `/etc/hosts` pointing to `/tmp/link_to_hosts`, which would fail if `/etc/hosts` already exists or create an incorrect link. Option C is wrong because it omits the full path for the link name, creating `link_to_hosts` in the current working directory instead of `/tmp` as required. Option D is wrong because it is identical to Option A, with the same reversed argument order, leading to the same incorrect behavior.

60
MCQmedium

An administrator wants to extend an XFS filesystem that resides on an LVM logical volume. The volume group has free physical extents. Which is the correct sequence?

A.lvextend, then xfs_growfs
B.lvextend, then resize2fs
C.xfs_growfs, then lvextend
D.resize2fs, then lvextend
AnswerA

Extending the logical volume first is required because XFS can only be grown, and the filesystem growth depends on the block device's new capacity. After lvextend allocates the additional storage to the LV, the mounted XFS filesystem is still the old size; running xfs_growfs on the mount point resizes it online to consume the newly available space. This is the only correct sequence for an XFS filesystem on LVM.

Why this answer

To extend an XFS filesystem on an LVM logical volume, you must first extend the logical volume with `lvextend` to allocate additional physical extents from the volume group, then grow the XFS filesystem to use the new space with `xfs_growfs`. XFS does not support online shrinking and requires the filesystem to be mounted for `xfs_growfs` to work. This sequence ensures the block device has sufficient capacity before the filesystem is expanded.

Exam trap

The trap here is that candidates confuse the filesystem type and apply `resize2fs` (for ext4) to XFS, or incorrectly assume the filesystem can be grown before the logical volume is extended.

How to eliminate wrong answers

Option B is wrong because `resize2fs` is used for ext2/ext3/ext4 filesystems, not XFS; using it on an XFS filesystem would fail. Option C is wrong because `xfs_growfs` cannot expand the filesystem if the underlying logical volume has not been extended first; the filesystem cannot grow beyond the block device size. Option D is wrong because `resize2fs` is not applicable to XFS, and attempting to resize the filesystem before extending the logical volume would also fail due to insufficient block device space.

61
Multi-Selecthard

Which TWO of the following are correct statements about exit codes in shell scripts?

Select 2 answers
A.An exit code of 1 means success
B.A non-zero exit code usually indicates a failure
C.An exit code of -1 indicates a system error
D.If no 'exit' is used, the script exits with code 0
E.Using 'exit 1' in a script sets the exit code to 1
AnswersB, E

The shell and many programs follow the convention that exit status 0 means successful completion, while any non-zero value signals an error, warning, or unusual termination. This convention is pervasive across UNIX-like systems and is relied upon by scripts, continuous integration pipelines, and command-line tools to make control-flow decisions. While specific programs may assign different meanings to specific non-zero codes, the general rule remains that non-zero means the command did not complete as intended.

Why this answer

In shell scripting, exit codes are integers from 0 to 255. An exit code of 0 conventionally indicates success, while any non-zero value (1–255) indicates a failure or error condition. Option B is correct because a non-zero exit code usually signals that the command or script did not complete successfully.

Exam trap

A common pitfall is confusing the default exit code: many candidates assume the script always exits with 0 unless 'exit 1' is used, but actually the default exit code is the exit status of the last command run in the script.

62
MCQeasy

Refer to the exhibit. Why does the 'bin' user have /sbin/nologin as its shell?

A.The user's home directory is missing.
B.The user is a system account that should not log in interactively.
C.The user is locked.
D.The shell is not installed.
AnswerB

The bin user is a system account (UID typically below 1000) created for running services and binaries rather than for human interactive use. Its login shell is deliberately set to /sbin/nologin in /etc/passwd, which causes any login attempt to print a message and exit immediately. This is a standard security precaution: system accounts should never provide an interactive shell, but they may still be used for non-interactive tasks like cron jobs or service startup. The exhibit shows nologin precisely because this account is not meant for shell access.

Why this answer

The /sbin/nologin shell is explicitly assigned to system accounts like 'bin' to prevent interactive logins. This shell prints a message and exits, ensuring that the account can only be used for non-interactive system processes, such as owning files or running daemons, without providing a login session.

Exam trap

Red Hat often tests the distinction between a locked account (password disabled) and a non-interactive shell (shell set to /sbin/nologin), leading candidates to confuse the two mechanisms for restricting access.

How to eliminate wrong answers

Option A is wrong because a missing home directory does not cause the shell to be set to /sbin/nologin; the shell field in /etc/passwd is independent of the home directory. Option C is wrong because a locked account (e.g., with 'passwd -l') places an exclamation mark in the password hash field in /etc/shadow, not by changing the shell to /sbin/nologin. Option D is wrong because /sbin/nologin is a valid executable that is part of the util-linux package; if it were missing, the system would fall back to /bin/sh or display an error, but the shell field would not be set to a non-existent path by default.

63
MCQhard

A Red Hat Enterprise Linux 9 system has a logical volume 'lv_data' in the volume group 'vg_data' that needs to be resized from 10G to 15G. The underlying physical volumes have enough free space. Which sequence of commands correctly resizes the logical volume and the ext4 filesystem?

A.lvextend -L 15G /dev/vg_data/lv_data; resize2fs /dev/vg_data/lv_data
B.resize2fs /dev/vg_data/lv_data; lvextend -L 15G /dev/vg_data/lv_data
C.lvextend -L 15G /dev/vg_data/lv_data; xfs_growfs /dev/vg_data/lv_data
D.lvreduce -L 15G /dev/vg_data/lv_data; resize2fs /dev/vg_data/lv_data
AnswerA

lvextend -L 15G /dev/vg_data/lv_data; resize2fs /dev/vg_data/lv_data — This is the correct order. lvextend first expands the logical volume by adding physical extents from the volume group, making a larger block device available to the filesystem. Only after that can resize2fs safely grow the ext4 filesystem into the newly available space; attempting filesystem growth first would have no extra capacity to claim.

Why this answer

To resize an ext4 filesystem on a logical volume, you must first extend the logical volume with `lvextend -L 15G /dev/vg_data/lv_data` to allocate the additional 5G from the volume group, then use `resize2fs /dev/vg_data/lv_data` to grow the filesystem to fill the enlarged block device. This order ensures the underlying block device has sufficient capacity before the filesystem resize operation.

Exam trap

The trap here is that candidates often confuse the filesystem-specific resize commands, mistakenly using `xfs_growfs` for ext4 (option C) or reversing the order of operations (option B), failing to recognize that LVM resizing must precede filesystem resizing.

How to eliminate wrong answers

Option B is wrong because `resize2fs` is run before `lvextend`, which would fail as the filesystem cannot be resized beyond the current logical volume size of 10G. Option C is wrong because `xfs_growfs` is used for XFS filesystems, not ext4; using it on an ext4 filesystem would either fail or produce incorrect results. Option D is wrong because `lvreduce` shrinks the logical volume, which is the opposite of the required operation (resizing from 10G to 15G), and would reduce capacity instead of increasing it.

64
MCQmedium

A production server runs RHEL 8 with a software RAID 5 array (/dev/md0) composed of three disks: /dev/sda, /dev/sdb, /dev/sdc. The array is used to store database files. The server experiences a disk failure on /dev/sdc. The admin replaces /dev/sdc with an identical disk and wants to rebuild the array. He runs: mdadm /dev/md0 --add /dev/sdc. The command completes without error, but the array shows a degraded state after several hours. What should the admin do next?

A.Run mdadm --detail /dev/md0 to check the status and rebuild progress.
B.Rebuild will happen automatically; just wait longer.
C.Recreate the array using mdadm --create with the same parameters.
D.Format /dev/sdc with a filesystem before adding to the array.
AnswerA

Running `mdadm --detail /dev/md0` is the correct first step because it reports the array state (`clean`, `degraded`, or `recovering`) and shows per-device status, including whether `/dev/sdc` is present as an active or spare device. It also displays a rebuild progress percentage and estimated time when a reshape or reconstruction is in progress, allowing you to confirm that recovery is actually underway and to spot device errors or mismatches. Without this command, you cannot distinguish a healthy rebuild from one that has stalled or failed.

Why this answer

After adding a replacement disk to a RAID 5 array, the rebuild process begins automatically but may take hours depending on disk size and I/O load. Running `mdadm --detail /dev/md0` allows the admin to check the current state, rebuild progress (e.g., percentage complete), and any errors that might have stalled the rebuild. This is the first diagnostic step to determine if the rebuild is still ongoing, has failed, or is degraded for another reason.

Exam trap

The trap here is that candidates assume the rebuild is always automatic and instantaneous, or they panic and choose destructive options like recreating the array, instead of first verifying the rebuild status with a simple diagnostic command.

How to eliminate wrong answers

Option B is wrong because while the rebuild does start automatically, it can stall or fail due to issues like bad sectors on the new disk, I/O errors, or a mismatch in superblock information; simply waiting longer without checking progress may waste time if the rebuild has stopped. Option C is wrong because recreating the array with `mdadm --create` would destroy all existing data on the array, which is unnecessary and catastrophic for a production database server; the correct approach is to add the disk to the existing array. Option D is wrong because adding a filesystem to /dev/sdc before adding it to the array would corrupt the RAID metadata and prevent the disk from being recognized as a spare; mdadm expects a raw block device without a filesystem.

65
MCQmedium

A junior administrator is asked to create a new group named 'qa' with an explicit GID of 4500 on a Red Hat Enterprise Linux 8 server. After running the appropriate command, they verify the result with getent group qa and see 'qa:x:4500:'. Which command did the junior administrator most likely run?

A.usermod -g 4500 qa
B.groupmod -g 4500 qa
C.groupadd -g 4500 qa
D.newgrp -g 4500 qa
AnswerC

This is correct because groupadd with the -g option creates a new group and assigns the specified GID value of 4500 to it. The output from getent group qa confirms the group exists with GID 4500 and no members, which is exactly what groupadd -g produces. No other command in the list creates a group entry in /etc/group with a custom GID.

Why this answer

Creating a group with a specific GID requires the groupadd command with the -g option. The -g flag sets the numeric GID, and the final argument is the group name. The getent output shows the group exists with the requested GID and no supplementary members, which matches exactly what groupadd -g 4500 qa produces.

None of the other commands create a new group entry.

Exam trap

The trap here is confusing group management commands: assuming usermod or groupmod creates groups, when only groupadd can add a new group entry.

66
MCQmedium

An administrator needs to compress a directory 'data' into an archive named backup.tar.gz using gzip compression. Which command should they use?

A.gzip -r data > backup.tar.gz
B.tar -cjf backup.tar.gz data
C.tar -xzf backup.tar.gz data
D.tar -czf backup.tar.gz data
AnswerD

tar -czf backup.tar.gz data is correct because -c tells tar to create a new archive, -z pipes the tar stream through gzip for compression, and -f specifies the output file name. The operand data is the directory tar recursively reads into the archive, producing exactly the requested gzip-compressed tarball.

Why this answer

The `tar -czf` command creates a compressed archive: `-c` creates a new archive, `-z` filters the archive through gzip compression, `-f` specifies the archive filename `backup.tar.gz`, and `data` is the directory to archive. This produces a tarball compressed with gzip, matching the requirement exactly.

Exam trap

The trap here is confusing the compression flags: Red Hat often tests whether candidates know that `-z` is for gzip, `-j` for bzip2, and `-J` for xz, and that `-c` creates while `-x` extracts.

How to eliminate wrong answers

Option A is wrong because `gzip -r` compresses individual files recursively but does not create a single archive; redirecting output with `>` produces a corrupted file, not a valid tar.gz. Option B is wrong because `-j` specifies bzip2 compression, not gzip; this would create `backup.tar.bz2`, not `backup.tar.gz`. Option C is wrong because `-x` extracts an archive instead of creating one; this would attempt to extract from `backup.tar.gz` into the `data` directory, which is the opposite of the required action.

67
Multi-Selectmedium

Which THREE of the following are valid methods to schedule a recurring task in Red Hat Enterprise Linux 8? (Choose exactly three.)

Select 3 answers
A.Using the 'batch' command
B.Creating a systemd timer unit
C.Using the 'at' command
D.Configuring /etc/anacrontab
E.Adding an entry in /etc/crontab
AnswersB, D, E

`systemd.timer` units are unit files with a `.timer` suffix that activate corresponding `.service` units on a schedule defined in `[Timer]` sections with directives like `OnCalendar=`, `OnBootSec=`, or `OnUnitActiveSec=`. Timers support calendar events, monotonic timers, persistent timers (`Persistent=true`), and can run missed jobs after boot, making them the modern replacement for cron on systems using systemd. They provide fine-grained control, logging integration with `journald`, and dependency management, so creating a timer unit is a fully valid scheduling method.

Why this answer

Systemd timer units are the modern, recommended method for scheduling recurring tasks in RHEL 8. They replace traditional cron-based scheduling by leveraging systemd's service and timer units, providing features like monotonic timers, calendar events, and integration with systemd's logging and dependency management.

Exam trap

Red Hat often tests the distinction between one-time scheduling tools (at, batch) and recurring scheduling tools (cron, anacron, systemd timers), leading candidates to mistakenly select 'at' or 'batch' for recurring tasks.

68
MCQhard

An administrator is building a container image with a Containerfile. They want to ensure that a specific RUN command always executes without using the build cache. Which build option should they use?

A.--layers=false
B.--squash
C.--force-rm
D.--no-cache
AnswerD

`--no-cache` is the correct answer because it tells Podman to ignore every cached layer and execute each instruction from the `Containerfile` as if this were the first build. It forces all dependent stages, such as `RUN` steps, to re-run and pull any changed content from network repositories, giving a pristine result. This is useful for reproducible builds where you need to verify that a fresh base image and package set produce the image.

Why this answer

The `--no-cache` build option instructs Podman or Docker to rebuild every layer from scratch, ignoring any cached intermediate layers. This ensures that the specific RUN command always executes fresh, which is essential when the command's outcome depends on dynamic external data or must not reuse stale cached results.

Exam trap

Red Hat often tests the distinction between cache-related flags and cleanup-related flags, so candidates may confuse `--no-cache` with `--force-rm` or mistakenly think `--squash` disables caching.

How to eliminate wrong answers

Option A is wrong because `--layers=false` is not a valid build option in Podman or Docker; the correct flag to disable layer caching is `--no-cache`. Option B is wrong because `--squash` merges all filesystem layers into a single layer after the build completes, but it does not prevent the use of the build cache during the build process. Option C is wrong because `--force-rm` forces removal of intermediate containers after a successful build, but it does not affect whether cached layers are used for RUN commands.

69
MCQmedium

A system administrator runs the command 'ls -l' and sees that a file has permissions '-rwxr-xr-x'. The administrator wants to remove execute permission for the group and others while keeping it for the owner. Which chmod command should be used?

A.chmod u-x file
B.chmod 755 file
C.chmod go-x file
D.chmod a+x file
AnswerC

chmod go-x file is correct because the symbolic mode 'go-x' targets the group (g) and other (o) permission classes with a minus operation, stripping only their execute bits. The owner's existing execute permission is unaffected, which precisely matches the requirement to remove execute access from group and others while preserving the owner's access.

Why this answer

The command 'chmod go-x file' removes execute permission for group (g) and others (o) while leaving the owner's permissions unchanged. The current permissions '-rwxr-xr-x' indicate owner has rwx, group has r-x, and others have r-x, so removing execute from group and others yields '-rwxr--r--'.

Exam trap

The trap here is that candidates often confuse the symbolic notation (u, g, o, a) and may incorrectly choose 'chmod u-x' thinking it affects group/others, or they misapply numeric modes like 755 which set permissions absolutely rather than modifying them incrementally.

How to eliminate wrong answers

Option A is wrong because 'chmod u-x file' removes execute permission from the owner, not from group and others, which would change the file to '-rw-r-xr-x'. Option B is wrong because 'chmod 755 file' sets permissions to rwxr-xr-x (owner rwx, group r-x, others r-x), which is the current state and does not remove execute from group and others. Option D is wrong because 'chmod a+x file' adds execute permission for all (owner, group, others), which is the opposite of what is needed.

70
MCQhard

A Red Hat Enterprise Linux server has been configured with a custom repository for offline updates. The administrator runs 'yum repolist' and the custom repository is not listed. Which command should be used to verify that the repository configuration file is valid and located in the correct directory?

A.yum repoinfo
B.cat /etc/yum.repos.d/custom.repo
C.yum check-repo
D.yum-config-manager --dump
AnswerB

Running cat /etc/yum.repos.d/custom.repo will print the exact bytes of the file to stdout, confirming both that the file exists in the proper /etc/yum.repos.d directory and what its repository configuration lines contain. If the file is missing, cat returns a nonzero exit status with a 'No such file or directory' error, so it provides an unambiguous, immediate pass/fail verification for this specific path.

Why this answer

The most direct way to verify that a repository configuration file is valid and located in the correct directory is to check its presence and syntax using 'cat /etc/yum.repos.d/custom.repo'. The repository configuration files must reside in /etc/yum.repos.d/ and have a .repo extension; if the file is missing or malformed, 'yum repolist' will not list the repository. This command simply reads the file, allowing the administrator to confirm its location and inspect its contents for errors.

Exam trap

The trap here is that candidates may assume a specialized yum subcommand exists for repository validation (like 'yum repoinfo' or 'yum check-repo'), when in fact the simplest and most reliable method is to directly inspect the configuration file with 'cat' or 'vim'.

How to eliminate wrong answers

Option A is wrong because 'yum repoinfo' is not a valid yum command; the correct command is 'yum repoinfo <repoid>' to display details about a repository that is already recognized, not to verify the configuration file's existence or validity. Option C is wrong because 'yum check-repo' is not a valid yum command; yum does not have a built-in 'check-repo' subcommand for validating repository configuration files. Option D is wrong because 'yum-config-manager --dump' is used to display the current yum configuration settings, not to verify the location or validity of a specific repository configuration file; it requires the repository to already be recognized.

71
MCQhard

A container running a database service needs to persist data across restarts. The administrator decides to use a named volume. Which command creates a named volume and mounts it correctly?

A.podman run -v /var/lib/mysql:/var/lib/mysql mydb
B.podman volume create dbdata && podman run -v dbdata:/var/lib/mysql mydb
C.podman run --mount type=bind,src=dbdata,dst=/var/lib/mysql mydb
D.podman run --mount type=tmpfs,dst=/var/lib/mysql mydb
AnswerB

This is the correct approach because podman volume create dbdata allocates a dedicated, managed volume in Podman's storage area, and the -v dbdata:/var/lib/mysql flag uses the non-absolute source to identify it as a named volume rather than a host path. Podman handles all lifecycle operations, permissions are configured correctly for the container's user, and the volume persists across container restarts and even after the container is removed. You can inspect it with podman volume inspect and reuse it with other containers, making it the right choice for durable database data.

Why this answer

It first creates a named volume with `podman volume create dbdata`, then mounts that named volume to the container's `/var/lib/mysql` directory using the `-v` flag. Named volumes are managed by Podman and persist data independently of the container lifecycle, ensuring data survives container restarts or removal.

Exam trap

The trap here is that candidates confuse bind mounts with named volumes, assuming `-v` always creates a named volume when the source is not an absolute path, but Podman treats a non-absolute source as a host-relative path or volume name depending on context, and the exam tests the explicit use of `podman volume create` for named volumes.

How to eliminate wrong answers

Option A is wrong because `-v /var/lib/mysql:/var/lib/mysql` creates a bind mount from a host directory, not a named volume; this requires the host path to exist and does not leverage Podman's volume management. Option C is wrong because `--mount type=bind,src=dbdata,dst=/var/lib/mysql` specifies a bind mount, not a named volume; `src=dbdata` is interpreted as a host directory path, not a volume name. Option D is wrong because `--mount type=tmpfs` creates a temporary filesystem in memory, which does not persist data across container restarts or host reboots.

72
MCQmedium

A database server experiences high disk I/O wait times. The administrator runs 'iostat -x 1' and sees that the avgqu-sz for /dev/sda is 25 and await is 200 ms. The disk is a single 7200 RPM SATA drive. Which action is most likely to improve performance?

A.Increase the read-ahead buffer using blockdev --setra
B.Change the I/O scheduler from CFQ to noop
C.Run 'fsck -f' on the filesystem to check for fragmentation
D.Replace the drive with an SSD or add additional drives in RAID 10
AnswerD

Replacing a mechanical drive with an SSD or deploying RAID 10 directly attacks the root cause of high disk i/o wait: excessive per-request latency and insufficient IOPS. SSDs eliminate rotational seek times and provide thousands of IOPS, while RAID 10 combines striping for parallel reads and writes with mirroring for redundancy, allowing multiple spindles to serve requests concurrently. This decreases both service time and queue depth, thereby reducing the await metric and iowait experienced by the database server.

Why this answer

The high avgqu-sz (25) and await (200 ms) indicate the single 7200 RPM SATA drive is saturated, as its maximum IOPS is typically around 75-100 random I/O operations per second. Replacing it with an SSD (which can handle thousands of IOPS) or adding drives in RAID 10 (which increases IOPS through parallelism) directly addresses the hardware bottleneck. No software tuning can overcome the physical limitations of a single spinning disk under heavy I/O load.

Exam trap

The trap here is that candidates assume software tuning (scheduler, read-ahead) can fix a hardware saturation issue, but Red Hat exams emphasize that when a single spinning disk is the bottleneck, only a hardware upgrade or RAID configuration will improve performance.

How to eliminate wrong answers

Option A is wrong because increasing the read-ahead buffer (--setra) only helps sequential I/O patterns, not the random I/O causing high wait times, and can actually waste memory and increase latency for random workloads. Option B is wrong because changing the I/O scheduler from CFQ to noop reduces CPU overhead but does not increase the disk's maximum IOPS; the disk is already saturated, so the scheduler choice has negligible impact on throughput. Option C is wrong because fsck checks filesystem metadata integrity, not fragmentation; even if the filesystem were fragmented, defragmentation would provide minimal benefit on a modern filesystem like ext4 and cannot resolve a hardware throughput bottleneck.

73
MCQeasy

A system administrator receives alerts that the /var/log partition is 100% full. The partition is on /dev/mapper/vg_log-lv_var_log, formatted with XFS, and is mounted at /var/log. The volume group vg_log has 10GB of free space available. The administrator runs the command `lvextend -L +10G /dev/mapper/vg_log-lv_var_log` successfully, but then `df -h` still shows 100% full. What is the next step the administrator should take to use the newly added space?

A.Run resize2fs /dev/mapper/vg_log-lv_var_log
B.Run xfs_growfs /var/log
C.Reboot the system to remount the filesystem
D.Run fsck /dev/mapper/vg_log-lv_var_log
AnswerB

xfs_growfs is the proper command to expand an XFS filesystem online, and it can be run while the filesystem is mounted. Passing the mount point /var/log instructs the tool to grow the filesystem to consume all available space in the underlying logical volume after an lvextend operation. This command performs the growth without requiring a reboot or unmounting, making it the correct and immediate solution for a full /var/log partition.

Why this answer

After extending the logical volume with `lvextend`, the underlying block device has more space, but the XFS filesystem does not automatically recognize it. The correct next step is to run `xfs_growfs /var/log` to expand the filesystem to fill the newly available space. Unlike ext4, XFS cannot be resized while mounted with `resize2fs`; it requires the XFS-specific `xfs_growfs` command, which can operate on a mounted filesystem.

Exam trap

The trap here is that candidates familiar with ext4 may instinctively choose `resize2fs`, not realizing that XFS requires its own grow command (`xfs_growfs`) and that the filesystem must be explicitly resized after the logical volume extension.

How to eliminate wrong answers

Option A is wrong because `resize2fs` is used for ext2/ext3/ext4 filesystems, not XFS; using it on an XFS filesystem would fail. Option C is wrong because rebooting is unnecessary and would not cause the filesystem to automatically grow; the filesystem must be explicitly resized with `xfs_growfs`. Option D is wrong because `fsck` checks and repairs filesystem metadata, but the filesystem is healthy and simply needs to be grown; running `fsck` would not add the new space.

74
Multi-Selecteasy

Which THREE file descriptors are always available for every Unix process?

Select 3 answers
A.4: socket
B.3: log file
C.2: stderr
D.1: stdout
E.0: stdin
AnswersC, D, E

stderr, file descriptor 2, is one of the three standard streams that the kernel guarantees to be open for every process from the moment it starts. It is specifically designated for error and diagnostic output, and is intentionally unbuffered or line-buffered so messages appear immediately, even if stdout is redirected or fully buffered. This descriptor is inherited from the parent process and can be redirected via shell operators like 2>.

Why this answer

File descriptor 2 (stderr) is one of the three standard file descriptors that every Unix process inherits from its parent process. These descriptors are opened automatically by the kernel when a process starts, providing default channels for input (stdin, fd 0), output (stdout, fd 1), and error output (stderr, fd 2).

Exam trap

Red Hat often tests the misconception that file descriptors beyond 0, 1, and 2 are standard or always available, leading candidates to select options like '3: log file' or '4: socket' as if they were universally present.

75
MCQhard

A Red Hat Enterprise Linux 8 server is used as a file server. It has a 1 TB disk /dev/sdc formatted as XFS and mounted at /srv/files. The /etc/fstab entry uses the device name /dev/sdc. After a hardware replacement, the new disk is detected as /dev/sdd, and the server fails to boot because /srv/files cannot be mounted. The administrator used 'blkid' and found the new disk's filesystem UUID is 'abc-123'. What is the best course of action to ensure reliable mounting after future reboots?

A.Add the 'nofail' option to the /etc/fstab entry and reboot
B.Change the /etc/fstab entry to use UUID=abc-123 and run mount -a
C.Create a symbolic link /dev/sdc pointing to /dev/sdd
D.Use PARTUUID instead of UUID in /etc/fstab
AnswerB

Switching the /etc/fstab entry to use the filesystem's UUID (e.g., UUID=abc-123) makes the mount independent of the kernel's device node naming order, because the UUID is burned into the filesystem superblock and remains constant regardless of which /dev/sdX node the disk acquires. After editing the file, running 'mount -a' mounts all entries listed in /etc/fstab that are not already mounted, applying the new configuration immediately without needing a reboot. This is the standard, reliable way to handle devices whose /dev names are not stable.

Why this answer

Using the filesystem UUID in /etc/fstab provides a persistent identifier that remains constant regardless of the device name assigned by the kernel. After the hardware replacement, the disk is detected as /dev/sdd, but its UUID ('abc-123') is unchanged. Changing the fstab entry to UUID=abc-123 ensures the system can reliably mount the filesystem on every boot, as the UUID is tied to the filesystem itself, not the kernel's device enumeration order.

Exam trap

The trap here is that candidates may think using the device name is sufficient because it worked before, or they may overcomplicate the fix with symlinks or PARTUUID, failing to recognize that the filesystem UUID is the simplest and most robust persistent identifier for mounting filesystems in Red Hat Enterprise Linux 8.

How to eliminate wrong answers

Option A is wrong because adding 'nofail' would allow the system to boot even if the mount fails, but it does not fix the root cause—the fstab entry still references the wrong device name (/dev/sdc), so the filesystem would not be mounted at all. Option C is wrong because creating a symbolic link /dev/sdc pointing to /dev/sdd is not persistent across reboots; device names can change again, and udev rules would be needed for a permanent symlink, which is more complex and not the standard best practice. Option D is wrong because PARTUUID identifies the partition table entry, not the filesystem; if the disk is replaced with a different partition layout, the PARTUUID may change, whereas the filesystem UUID remains stable as long as the filesystem is intact.

Page 1 of 6

Page 2

All pages