Courseiva

Red Hat Certified System Administrator EX200 (EX200) — Questions 226–300

427 questions total · 6pages · All types, answers revealed

Page 3

Page 4 of 6

Page 5
226
MCQhard

You are a system administrator for a small company. The development team has created a shell script named 'deploy.sh' that automates deployment of a web application. The script is located at /home/devops/deploy.sh. The team reports that when they run the script with './deploy.sh' from the /home/devops directory, it fails with a 'Permission denied' error. However, running 'bash deploy.sh' works fine. Additionally, the script's first line is '#!/bin/bash' and the file permissions are '-rw-rw-r--'. The team wants to be able to run the script directly without typing 'bash'. Which of the following actions should you take to resolve the issue?

A.Change the shebang line to '#!/bin/sh' because bash is not the default shell.
B.Move the script to /usr/local/bin so it can be found in the PATH.
C.Add the execute permission to the script using 'chmod +x /home/devops/deploy.sh'.
D.Change the owner of the script to root using 'chown root:root /home/devops/deploy.sh'.
AnswerC

The correct action is to grant execute permission explicitly. The chmod +x command adds the execute bit (x) to the file's mode for the user, group, and others, which is required for the kernel to allow execve to run the script directly. Without this bit, the shell returns 'Permission denied' even though the user can read and write the file. Since the devops user already owns the file and has read/write permissions, adding the execute bit is the minimal, sufficient fix to make the script runnable.

Why this answer

The 'Permission denied' error when running './deploy.sh' indicates that the script lacks execute permission. The current permissions '-rw-rw-r--' show read/write for owner and group, and read-only for others, but no execute bit. Adding execute permission with 'chmod +x' allows the script to be run directly via its shebang line.

Exam trap

Red Hat often tests the distinction between execute permission and interpreter availability; candidates may mistakenly think the shebang or PATH is the issue when the real problem is the missing execute bit.

How to eliminate wrong answers

Option A is wrong because the shebang '#!/bin/bash' is correct; bash is the default shell on Red Hat Enterprise Linux, and changing to '#!/bin/sh' would not resolve the missing execute permission. Option B is wrong because moving the script to /usr/local/bin does not grant execute permission; the script would still fail with 'Permission denied' when run directly. Option D is wrong because changing ownership to root does not add execute permission; the script would still lack the execute bit and fail with 'Permission denied'.

227
MCQmedium

An administrator extends a logical volume by 5GB. The filesystem is XFS. Which command must be run to make the additional space available?

A.xfs_growfs /mount
B.mount -o remount /mount
C.resize2fs /dev/vg/lv_root
D.lvresize -L +5G /dev/vg/lv_root
AnswerA

xfs_growfs /mount is correct because it is the only command that actually expands the XFS filesystem to fill the newly available space in the underlying logical volume. It operates online on a mounted filesystem, takes the mount point as an argument, and grows the filesystem to consume all unallocated space in the LV without requiring an unmount or reboot.

Why this answer

After extending a logical volume with lvresize, the XFS filesystem does not automatically recognize the new space. The xfs_growfs command must be run on the mounted filesystem to expand it to fill the enlarged logical volume. This command can target the mount point directly and works online without unmounting.

Exam trap

The trap here is that candidates confuse the logical volume resize (lvresize) with the filesystem resize, assuming the filesystem automatically expands when the LV grows, or they mistakenly apply ext4 tools like resize2fs to an XFS filesystem.

How to eliminate wrong answers

Option B is wrong because 'mount -o remount /mount' only reapplies mount options and does not resize any filesystem; it is irrelevant for making additional space available after an LV extension. Option C is wrong because 'resize2fs' is the tool for ext2/ext3/ext4 filesystems, not XFS; using it on an XFS filesystem would fail or cause corruption. Option D is wrong because 'lvresize -L +5G /dev/vg/lv_root' is the command that extends the logical volume itself, but the question asks what must be run after that step to make the space available to the filesystem; the LV resize is already assumed to have been done.

228
Multi-Selectmedium

Which TWO commands can be used to add a user to a secondary group without removing existing supplementary group memberships? (Choose exactly 2)

Select 2 answers
A.usermod -aG group user
B.usermod -AG group user
C.adduser user group
D.gpasswd -a user group
E.groupadd -a user group
AnswersA, D

The `-a` flag in `usermod -aG group user` is the critical component: it stands for 'append', meaning the specified user is added to the supplementary group listed after `-G` without removing the user from any existing supplementary groups. Omitting `-a` would replace the user's entire supplementary group membership list with just the one group, which can unexpectedly strip access to other groups. This command directly edits /etc/group and /etc/passwd to update group membership.

Why this answer

`usermod -aG` appends the user to the specified supplementary group(s) without affecting any existing supplementary group memberships. The `-a` flag (append) must be used with `-G` to avoid overwriting the current list of supplementary groups. This is the standard method in Red Hat Enterprise Linux for adding a user to an additional group while preserving all other group memberships.

Exam trap

The trap here is that candidates often confuse `usermod -G` (which replaces all supplementary groups) with `usermod -aG` (which appends), and may also mistakenly think `groupadd` or `adduser` can modify group memberships, when in fact only `usermod -aG` and `gpasswd -a` are the correct tools for this task.

229
Multi-Selectmedium

Which three statements about firewalld zones are correct? (Choose three.)

Select 3 answers
A.The default zone can be changed using firewall-cmd.
B.A network interface can be assigned to multiple zones simultaneously.
C.The 'public' zone is more restrictive than the 'trusted' zone.
D.Rich rules can specify source and destination addresses.
E.Zones can have a default target of only 'DROP' or 'ACCEPT'.
AnswersA, C, D

The default zone can be changed with `firewall-cmd --set-default-zone=<zone>`. This command updates the default zone in the firewalld configuration, so the change persists across reboots. The default zone applies only to interfaces or source addresses that have not been explicitly bound to another zone.

Why this answer

The default zone in firewalld can be changed using the 'firewall-cmd --set-default-zone=<zone>' command. This command updates the runtime and permanent configuration, ensuring that all new network interfaces are automatically assigned to the specified zone unless explicitly overridden.

Exam trap

The trap here is that candidates often assume a network interface can belong to multiple zones simultaneously (like in some other firewall systems), but firewalld enforces a strict one-interface-per-zone binding, and they may also forget that zones support 'REJECT' and 'default' targets, not just 'DROP' and 'ACCEPT'.

230
Multi-Selecthard

Which TWO methods can be used to permanently set the system's hostname to 'server01.example.com'?

Select 2 answers
A.hostnamectl set-hostname server01.example.com
B.echo '127.0.1.1 server01.example.com' >> /etc/hosts
C.echo 'server01.example.com' > /etc/hostname
D.hostname server01.example.com
E.echo 'HOSTNAME=server01.example.com' >> /etc/sysconfig/network
AnswersA, C

hostnamectl set-hostname server01.example.com writes the given name to /etc/hostname as the static hostname and also signals systemd-hostnamed to apply it immediately to the running kernel, so the change takes effect right away and remains after reboot. It is the systemd-native command and the official tool on RHEL systems; unlike writing /etc/hostname directly, it also updates the transient hostname by default and can set other metadata such as the pretty hostname. This is the recommended and most robust method.

Why this answer

`hostnamectl set-hostname server01.example.com` is the systemd-based command that permanently sets the hostname by writing to `/etc/hostname` and applying the change immediately via the `hostnamed` service. This is the recommended method on RHEL 8/9 systems, as it updates both the transient and static hostnames, ensuring persistence across reboots.

Exam trap

The trap here is that candidates confuse setting the hostname with hostname resolution, picking option B (editing `/etc/hosts`) because they think it permanently sets the hostname, when it only affects local DNS-like lookups and does not change the system's actual hostname.

231
MCQhard

Refer to the exhibit. A system administrator wants to add an additional mount option 'noexec' to the /boot filesystem permanently. Which step is necessary before remounting?

A.Run mount -o remount,noexec /boot without editing /etc/fstab
B.Edit /etc/fstab to add 'noexec' to the /boot entry, then run mount -o remount /boot
C.Run umount /boot, edit /etc/fstab to add 'noexec', then mount /boot
D.Edit /etc/fstab to add 'noexec' to the /boot entry, then run mount -a
AnswerB

Editing /etc/fstab to add noexec to the /boot entry updates the persistent source of truth for that filesystem's options. Running mount -o remount /boot then asks the kernel to reapply the mount flags from fstab without requiring an unmount, so the new noexec setting takes effect while the system stays running. This is the correct way to change mount options permanently and immediately.

Why this answer

To make the 'noexec' mount option persistent for /boot, you must first edit /etc/fstab to add the option to the /boot entry. Then, running 'mount -o remount /boot' will remount the filesystem with the new options from fstab without needing to unmount it. This ensures the change survives reboots and is applied correctly.

Exam trap

A common trap on the RHCSA exam is confusing a temporary remount (which applies options only until the next reboot) with a permanent change via /etc/fstab. Candidates often choose option A thinking a simple remount is sufficient for permanence, but only editing /etc/fstab makes the mount option persistent across reboots.

How to eliminate wrong answers

Option A is wrong because running 'mount -o remount,noexec /boot' without editing /etc/fstab applies the option only for the current session; the change is lost after a reboot. Option C is wrong because you cannot unmount /boot while the system is running (it is a critical filesystem containing the kernel and bootloader), and the procedure unnecessarily unmounts when a remount suffices. Option D is wrong because 'mount -a' mounts all filesystems listed in /etc/fstab that are not already mounted; it does not remount an already-mounted filesystem, so the new 'noexec' option would not be applied to /boot until a reboot.

232
MCQhard

Refer to the exhibit. A CGI script located at /var/www/cgi-bin/test.cgi fails to execute. What is the most likely cause?

A.The script is in the wrong directory.
B.The SELinux context should be httpd_sys_script_exec_t.
C.The script is not marked as executable.
D.The file permissions are incorrect.
AnswerB

SELinux prevents httpd from executing scripts unless the file has the httpd_sys_script_exec_t type, which allows a transition into the httpd_sys_script_t domain when the script runs. If the script retains a generic context such as httpd_sys_content_t or user_home_t, httpd is blocked even when permissions and location are correct, producing a 500 error. Running `restorecon -R /var/www/cgi-bin` or `chcon -t httpd_sys_script_exec_t /var/www/cgi-bin/script.cgi` is the correct fix, not changing permissions.

Why this answer

SELinux contexts control which processes can access files and directories. The CGI script at /var/www/cgi-bin/test.cgi requires the httpd_sys_script_exec_t context to allow the Apache HTTP server (httpd) to execute it. Without this context, SELinux will deny execution even if file permissions and ownership are correct.

Exam trap

The pitfall in this question is that examinees often focus on file permissions or script location, overlooking that SELinux contexts (specifically httpd_sys_script_exec_t) are required for CGI execution in Red Hat systems.

How to eliminate wrong answers

Option A is wrong because /var/www/cgi-bin/ is the default directory for CGI scripts on Red Hat-based systems, so the script is in the correct location. Option C is wrong because the question does not indicate that the script lacks execute permissions; SELinux can block execution even when the file is marked executable. Option D is wrong because file permissions (e.g., 755) may be correct, but SELinux enforces its own policy that overrides standard permissions.

233
MCQeasy

A container named 'web1' was created and ran briefly before exiting with status 0. The administrator needs to restart it and attach to the running container's console. Which command should be used?

A.podman run --name web1 -it registry.access.redhat.com/ubi8/httpd-24
B.podman start web1
C.podman restart web1 && podman attach web1
D.podman start web1 && podman attach web1
AnswerD

This combination first uses podman start web1 to take the existing stopped container and transition it to the running state, preserving its filesystem and configuration. Then podman attach web1 connects your terminal to the container's primary process' STDIN and STDOUT, giving you the same interactive console session that existed when it was originally run. This is the correct lifecycle sequence for resuming an existing interactive container without recreating it.

Why this answer

`podman start web1` restarts the existing container that exited with status 0, and `podman attach web1` connects the current terminal to the container's main process console. The `&&` ensures the attach runs only after the container is successfully started, allowing the administrator to interact with the running container's console.

Exam trap

The primary trap is that candidates may think `podman restart` is required to resume an exited container, but `podman start` is the correct command. Additionally, candidates often forget to attach to the console after starting, leading them to choose option B. Note: `podman restart` does work on stopped containers, but it stops and starts the container unnecessarily; `podman start` is the appropriate command for resuming a container that exited with status 0.

How to eliminate wrong answers

Option A is wrong because `podman run` creates and runs a new container with the name 'web1', which will fail since a container named 'web1' already exists, and it does not restart the existing container. Option B is wrong because `podman start web1` only starts the container but does not attach to its console, so the administrator cannot interact with the running container. Option C is wrong because `podman restart web1` stops and then starts the container, which is unnecessary for a container that exited with status 0 and can be started directly; additionally, the `&&` syntax is valid but the restart is redundant and may cause a brief interruption.

234
Matchingmedium

Match each log file to its typical content.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

General system log (most non-critical messages)

Authentication and security events

Audit records from auditd

Cron job execution logs

Why these pairings

These log files are commonly monitored by sysadmins. Correct matches: /var/log/messages for general messages, /var/log/secure for authentication, /var/log/maillog for mail, /var/log/cron for cron jobs. Common confusions involve swapping secure and maillog.

235
Multi-Selectmedium

A system administrator needs to ensure that the user 'jdoe' can read files in the shared directory /project/data which is owned by group 'project'. The user 'jdoe' is currently not a member of the 'project' group. Which TWO steps should the administrator take to add 'jdoe' to the 'project' group? (Choose two.)

Select 2 answers
A.gpasswd -a jdoe project
B.groupmod -A jdoe project
C.vigr to add jdoe to project group
D.useradd -G project jdoe
E.usermod -aG project jdoe
AnswersA, E

gpasswd -a jdoe project is correct because it directly appends the existing user jdoe to the supplementary group 'project' by modifying the /etc/group file. The -a (add) flag explicitly instructs gpasswd to add the user to the group, making it a dedicated group-administration command. This is a safe, standard method that does not affect the user's primary group or any other group memberships.

Why this answer

`gpasswd -a jdoe project` adds the user 'jdoe' to the 'project' group by appending the user to the group's member list in /etc/group. This command is specifically designed for group membership management and does not require the user to be logged out; the change takes effect on the next login.

Exam trap

In Red Hat RHCSA exams, a common trap is confusing `usermod -G` (which overwrites all supplementary groups) with `usermod -aG` (which appends). Also, candidates may mistakenly think `useradd` modifies an existing user, but it is only for new users. The correct commands to add a user to an existing group are `usermod -aG` or `gpasswd -a`.

236
MCQhard

A system fails to boot and drops into an emergency shell. The administrator suspects a misconfigured /etc/fstab. Which command should be used to determine which filesystem is causing the boot issue?

A.systemctl status local-fs.target
B.journalctl -xb -p err
C.fsck -A
D.mount -a
AnswerB

Running journalctl -xb -p err reads the persistent journal from the current boot (-b), applies extended explanatory hints (-x) that describe what each message means, and filters to error priority and above (-p err). This will surface kernel driver errors, systemd mount failures, and device not found messages that directly explain why local-fs.target failed. Because the emergency shell runs early in the boot process, the journal still contains the relevant log entries, making this the most reliable diagnostic command.

Why this answer

When a system fails to boot due to a misconfigured /etc/fstab, the emergency shell is entered. The `journalctl -xb -p err` command displays the systemd journal from the current boot (`-b`) with extended information (`-x`) and filters for error-level messages (`-p err`). This will show the exact mount failure and the offending filesystem entry, making it the correct diagnostic tool.

Exam trap

The trap here is that candidates often choose `mount -a` (option D) thinking it will show the error, but it only attempts the mount again without providing the specific fstab line or error context, whereas `journalctl -xb -p err` reveals the exact failure from the boot process.

How to eliminate wrong answers

Option A is wrong because `systemctl status local-fs.target` shows the status of the local-fs target unit, but it does not provide detailed error messages about which specific filesystem failed to mount; it only indicates whether the target is active or failed. Option C is wrong because `fsck -A` checks all filesystems listed in /etc/fstab for consistency, but it does not report which filesystem caused the boot failure—it may run checks on healthy filesystems and does not parse mount errors. Option D is wrong because `mount -a` attempts to mount all filesystems in /etc/fstab, but if the system is already in an emergency shell, this command may fail again without providing clear diagnostic output about the specific misconfiguration.

237
MCQeasy

A system administrator needs to create an XFS filesystem on /dev/sdb1 with the label 'data'. Which command should be used?

A.mkfs.ext4 -L data /dev/sdb1
B.mkfs.xfs -l data /dev/sdb1
C.xfs_admin -L data /dev/sdb1
D.mkfs.xfs -L data /dev/sdb1
AnswerD

This command creates a new XFS filesystem on /dev/sdb1 and assigns the volume label 'data' in a single step using the uppercase -L option. The -L flag is the correct way to set a label during XFS creation, unlike the lowercase -l which configures the log. This exactly matches the requirement to create an XFS filesystem with the specified label, so it is the correct answer.

Why this answer

The `mkfs.xfs` command creates an XFS filesystem, and the `-L` flag assigns a label to the filesystem during creation. The command `mkfs.xfs -L data /dev/sdb1` correctly creates an XFS filesystem on the specified partition with the label 'data'.

Exam trap

The trap here is confusing the lowercase `-l` (used for log parameters in mkfs.xfs) with the uppercase `-L` (used for labels), or thinking that `xfs_admin` can create a filesystem when it only modifies existing ones.

How to eliminate wrong answers

Option A is wrong because `mkfs.ext4` creates an ext4 filesystem, not XFS, and the `-L` flag is used for labels on ext4, but the question specifically requires an XFS filesystem. Option B is wrong because `mkfs.xfs -l data /dev/sdb1` uses a lowercase `-l`, which in mkfs.xfs is used to specify the log section parameters (e.g., log size or device), not the filesystem label; the correct flag for a label is uppercase `-L`. Option C is wrong because `xfs_admin` is used to change parameters of an existing XFS filesystem (like the label or UUID), not to create a new one; it cannot be used to create a filesystem.

238
MCQeasy

A system administrator needs to add a new 10GB disk to an existing volume group 'vgdata' to extend logical volumes. Which of the following is the correct sequence of commands?

A.pvcreate /dev/sdb, vgextend vgdata /dev/sdb, lvextend
B.vgextend vgdata /dev/sdb, pvcreate /dev/sdb, lvextend
C.pvcreate /dev/sdb, lvextend, vgextend vgdata /dev/sdb
D.lvextend, vgextend vgdata /dev/sdb, pvcreate /dev/sdb
AnswerA

pvcreate initializes /dev/sdb with LVM metadata, making it a physical volume that LVM can recognize. vgextend then adds that PV to the existing volume group vgdata, increasing its total allocatable space. Only after the VG has free physical extents can lvextend allocate from them to grow a logical volume, followed by a filesystem resize if needed. This dependency chain makes the order mandatory.

Why this answer

The proper sequence to add a new disk to an existing volume group is: first create a physical volume with `pvcreate /dev/sdb`, then extend the volume group with `vgextend vgdata /dev/sdb`, and finally extend the logical volume with `lvextend`. This order ensures the disk is initialized as a PV before it can be added to the VG, and the VG must have the new PV before the LV can be extended.

Exam trap

The trap here is that candidates may think `vgextend` can automatically initialize the disk, or that the order of commands does not matter, but LVM strictly requires `pvcreate` before `vgextend` and `vgextend` before `lvextend`.

How to eliminate wrong answers

Option B is wrong because `vgextend` is attempted before `pvcreate`, but a disk must be initialized as a physical volume before it can be added to a volume group. Option C is wrong because `lvextend` is performed before `vgextend`, but the volume group does not yet contain the new physical volume, so the extension would fail. Option D is wrong because both `lvextend` and `vgextend` are attempted before `pvcreate`, violating the dependency that the disk must first be a PV, then added to the VG, then used to extend the LV.

239
MCQhard

An administrator wants to enable user disk quotas on an XFS filesystem mounted at /home. Which steps are required?

A.Add 'usrquota' to /etc/fstab, remount, then run quotacheck and edquota
B.Quotas are not supported on XFS filesystems
C.Use mount -o uquota /home, then setquota -u user1 500M 1G /home
D.Add 'uquota' to /etc/fstab, remount, then run xfs_quota -x -c 'limit -u bsoft=500m bhard=1g user1' /home
AnswerD

This is the correct procedure for enabling user quotas on XFS. Adding uquota to the mount options in /etc/fstab ensures the option persists across reboots, and remounting applies it to the live filesystem. The xfs_quota command in expert mode (-x) with the -c option runs a quota command non-interactively; 'limit -u' sets the user's block soft and hard limits, with suffixes like 'm' and 'g' for megabytes and gigabytes. This is the standard, supported method for XFS quota enforcement.

Why this answer

XFS uses its own quota management tools, not the traditional `quotacheck`/`edquota` tools used by ext4. The correct procedure is to add the `uquota` mount option to `/etc/fstab`, remount the filesystem, and then use `xfs_quota` to set limits. The `xfs_quota` command with the `-x` (expert) flag and `-c` (command) flag allows setting user quotas directly, and the path `/home` specifies the filesystem.

Exam trap

The trap here is that candidates familiar with ext4 quotas assume the same `quotacheck`/`edquota` workflow applies to XFS, but Red Hat EX200 expects knowledge of XFS-specific tools like `xfs_quota` and the `uquota` mount option.

How to eliminate wrong answers

Option A is wrong because `quotacheck` and `edquota` are tools for ext2/ext3/ext4 filesystems, not XFS; XFS manages quotas internally and does not require a separate `quotacheck` step. Option B is wrong because XFS fully supports user and group quotas via the `uquota`/`gquota` mount options and the `xfs_quota` utility. Option C is wrong because `mount -o uquota /home` only enables quota accounting but does not set any limits; additionally, `setquota` is an ext4 command and is not used with XFS.

240
MCQeasy

Refer to the exhibit. When the system boots, which filesystem will be mounted after the root filesystem?

A.None
B.Swap
C.Both /boot and swap
D./boot
AnswerD

According to the exhibit, /etc/fstab has the root filesystem (/) as its first entry and /boot as the second. Once the kernel mounts root, systemd processes the fstab entries in order, mounting /boot next. /boot is a dedicated filesystem that holds the kernel and initramfs, so it must be available for the boot process to continue.

Why this answer

According to the default boot process in RHEL 8/9, the initramfs mounts the root filesystem first, then the systemd-based init process mounts the /boot filesystem (if it is a separate partition) as specified in the /etc/fstab file. The root filesystem is mounted by the kernel or initramfs, and subsequent filesystems like /boot are mounted by systemd based on fstab entries.

Exam trap

The trap here is that candidates often confuse swap with a filesystem, but swap is a raw block device for memory paging and is not mounted; it is activated via swapon, so it does not count as a mounted filesystem in this context.

How to eliminate wrong answers

Option A is wrong because the system does mount additional filesystems after root, such as /boot, as defined in /etc/fstab. Option B is wrong because swap is not a filesystem in the traditional sense; it is a swap area that is activated by swapon, not mounted as a filesystem, and it is typically activated after filesystem mounts. Option C is wrong because while /boot is mounted, swap is not mounted as a filesystem; it is activated separately, and the question specifically asks about filesystem mounting.

241
MCQeasy

A new employee named asmith needs a user account with a home directory and a specific UID of 1500. Which command accomplishes this?

A.useradd -m -u 1500 asmith
B.adduser -uid 1500 asmith
C.useradd -h /home/asmith -u 1500 asmith
D.useradd -d /home/asmith -U 1500 asmith
AnswerA

The `-m` flag tells `useradd` to create the user's home directory (`/home/asmith`) immediately, and `-u 1500` explicitly assigns UID 1500. This is the correct way to create a new account for asmith with both a usable home directory and a known UID for ownership purposes.

Why this answer

`useradd -m -u 1500 asmith` creates the user asmith with a home directory (via `-m`) and assigns a specific UID of 1500 (via `-u`). The `-m` flag ensures the home directory is created if it does not exist, which is required by the question.

Exam trap

The trap here is confusing `-u` (UID) with `-U` (create user group) and mistaking `-h` for home directory instead of the correct `-d` flag.

How to eliminate wrong answers

Option B is wrong because `adduser` is a Perl script (not a standard command on RHEL/CentOS) and `-uid` is not a valid flag; the correct flag for UID with `adduser` would be `--uid`, but the question expects the standard `useradd` command. Option C is wrong because `-h` is not a valid flag for `useradd`; the flag to specify a home directory is `-d`, and `-h` is used for help. Option D is wrong because `-U` creates a user group with the same name as the user (not a UID), and the UID should be specified with `-u` (lowercase), not `-U`.

242
MCQmedium

A user complains that the 'ls' command no longer outputs colors. The administrator suspects a change in environment variables. Which command would help diagnose the issue?

A.set
B.declare
C.env
D.alias
AnswerC

The `env` command, when run without arguments, prints the complete environment that will be passed to child processes, making it the most direct way to verify whether `LS_COLORS` is defined and what its value is. Because `ls` relies on the `LS_COLORS` environment variable to know which color codes to use (assuming color output is enabled), `env` immediately exposes whether that variable is missing, empty, or malformed. It also allows filtering, e.g., `env | grep LS_COLORS`, for a concise check.

Why this answer

The `env` command displays all current environment variables, which directly affect the behavior of commands like `ls`. The `ls` command uses the `LS_COLORS` environment variable to determine color output; if this variable is missing or altered, colors will not appear. Running `env` allows the administrator to inspect the current environment and identify if `LS_COLORS` has been changed or unset.

Exam trap

The trap here is that candidates often confuse `env` with `set` or `declare`, thinking all three show the same information, but `env` specifically shows only exported environment variables, which is exactly what affects child processes like `ls`.

How to eliminate wrong answers

Option A is wrong because `set` displays shell variables (including local variables) and shell functions, not just environment variables; it may show environment variables but is not the standard tool for diagnosing environment-specific issues like `LS_COLORS`. Option B is wrong because `declare` is used to declare and display shell variables and attributes in Bash, but it is not the primary command for listing environment variables; it also shows local variables and functions, which can clutter the output. Option D is wrong because `alias` displays or defines command aliases, which are not environment variables; while an alias could override `ls` (e.g., `alias ls='ls --color=auto'`), the question specifically points to a change in environment variables, not aliases.

243
MCQmedium

An IT department runs a web server that stores user uploads on an ext4 filesystem on /dev/sdb1 mounted at /uploads. Recently, the partition has run out of space. The administrator checks with df -h and sees 100% usage. However, du -sh /uploads shows only 2GB used. The administrator suspects deleted files still held open by processes. Which command should be used to identify and resolve the issue?

A.rm -rf /uploads/* to clean all files
B.fsck /dev/sdb1 to repair filesystem
C.resize2fs /dev/sdb1 to shrink filesystem
D.lsof +L1 /uploads to find deleted open files, then kill processes
AnswerD

`lsof +L1 /uploads` enumerates open files whose link count is zero — exactly the deleted-but-still-in-use files that are consuming space. Once identified, you can either close the file gracefully (e.g., by restarting the application) or terminate the offending process, causing the kernel to drop the last reference and free the inode's blocks. This is the targeted, surgical remedy: it doesn't touch valid uploads and it directly releases the missing space. After the process is killed, the directory will show no trace of the file, but df will report the reclaimed capacity.

Why this answer

The discrepancy between `df -h` showing 100% usage and `du -sh /uploads` showing only 2GB indicates that deleted files are still held open by running processes. The `lsof +L1 /uploads` command lists files with a link count of zero (deleted but still open), and killing the associated processes releases the disk space. This is a classic scenario on ext4 filesystems where file descriptors prevent space reclamation until the process closes the file.

Exam trap

Red Hat often tests the misconception that `rm` or filesystem repair tools can recover space from deleted-but-open files, when in fact only closing the file descriptor (by killing the process) releases the blocks.

How to eliminate wrong answers

Option A is wrong because `rm -rf /uploads/*` would attempt to remove files that are already deleted (unlinked) and thus cannot free the space held by open file descriptors; it may also delete active uploads. Option B is wrong because `fsck` checks and repairs filesystem metadata, but the filesystem is not corrupted—the issue is with in-use file handles, not structural damage. Option C is wrong because `resize2fs` resizes the filesystem, but shrinking it would not recover space from deleted-but-open files and could cause data loss if the filesystem is full.

244
MCQhard

The /data filesystem is at 99% capacity. The LVM setup shows that the volume group has 50GB free space, but the logical volume is only 100GB. What is the correct sequence of commands to increase the filesystem to use all available space in the volume group?

A.lvextend -L 50G /dev/mapper/vg01-data && xfs_growfs /dev/mapper/vg01-data
B.lvextend -L +50G /dev/mapper/vg01-data && xfs_growfs /data
C.lvextend -L +50G /dev/mapper/vg01-data && resize2fs /dev/mapper/vg01-data
D.xfs_growfs /dev/mapper/vg01-data && lvextend -L +50G /dev/mapper/vg01-data
AnswerB

This is correct because `lvextend -L +50G` explicitly adds 50G of space to the existing logical volume, expanding the LV to accommodate more data. After the LV is enlarged, `xfs_growfs /data` is executed against the mount point, which is the proper way to grow an XFS filesystem online. `xfs_growfs` automatically expands the filesystem to fill the entire LV, so no size argument is required, and the order is correct because the filesystem can only be grown after the underlying block device has been extended.

Why this answer

The volume group has 50GB free space, so you need to extend the logical volume by +50GB (not to 50GB) using `lvextend -L +50G`, and then grow the XFS filesystem with `xfs_growfs /data` (the mount point, not the block device). The `+` sign indicates an addition to the current size, while omitting it would set an absolute size.

Exam trap

The trap here is that candidates confuse the `-L` syntax (absolute vs. relative size) and mistakenly use `resize2fs` for XFS, or reverse the order of commands.

How to eliminate wrong answers

Option A is wrong because `lvextend -L 50G` sets the logical volume to exactly 50GB, which would shrink it from 100GB to 50GB, losing data and not using the free space; also `xfs_growfs` should target the mount point, not the block device. Option C is wrong because `resize2fs` is for ext2/3/4 filesystems, not XFS; XFS requires `xfs_growfs`. Option D is wrong because the order is reversed: you must extend the logical volume first with `lvextend` before growing the filesystem with `xfs_growfs`.

245
Multi-Selectmedium

Which two are required to create a logical volume? (Choose two.)

Select 2 answers
A.Physical volume
B.Mount point
C.Filesystem
D.Partition
E.Volume group
AnswersA, E

A physical volume (PV) is a disk or partition that has been initialized with LVM metadata using pvcreate. This raw storage device provides the fundamental capacity that LVM pools into a volume group. Without at least one PV, there is no physical storage for LVM to manage, and creating a logical volume directly from a raw disk is impossible—the disk must first be a PV.

Why this answer

A physical volume (PV) is required because it is the underlying storage device (e.g., a disk or partition) that LVM uses as a building block. Without a PV, there is no raw storage to allocate to a volume group. The volume group (VG) is then created from one or more PVs, and logical volumes (LVs) are carved from the VG.

Both are mandatory steps in the LVM workflow.

Exam trap

The trap here is that candidates confuse the steps of creating a logical volume with the steps of making it usable (mount point and filesystem), leading them to select options B or C as required prerequisites.

246
MCQeasy

Which command checks if a specific systemd service is currently running?

A.systemctl is-active
B.systemctl status
C.systemctl list-units
D.systemctl show
AnswerA

systemctl is-active directly queries the systemd manager over the D-Bus interface for the unit's current runtime state and prints a single word such as 'active', 'inactive', 'activating', or 'failed'. Its exit code is also set to 0 only when the service is active, making it the ideal tool for shell conditionals and monitoring scripts because it requires no output parsing or filtering.

Why this answer

The `systemctl is-active` command is specifically designed to check whether a systemd service is currently in the 'active' (running) state. It returns an exit code of 0 if the service is active, and a non-zero exit code otherwise, making it ideal for scripting and direct status checks.

Exam trap

Candidates often confuse `systemctl status` with `systemctl is-active`. While `systemctl status` displays detailed information including whether the service is running, it does not return a simple exit code for scripting. The question specifically asks for a command that *checks* if a service is currently running, which `systemctl is-active` does via its exit code, making it the correct choice for automation and direct status queries in Red Hat Enterprise Linux.

How to eliminate wrong answers

Option B is wrong because `systemctl status` displays detailed information about a service, including its current state, but it is not the command specifically designed to return a simple active/inactive exit code for scripting; it outputs human-readable text. Option C is wrong because `systemctl list-units` lists all loaded units and their states, but it does not target a specific service and requires parsing output to determine if a single service is running. Option D is wrong because `systemctl show` displays all properties of a unit in key-value format, which is useful for detailed configuration inspection but not for a direct running/not-running check.

247
MCQmedium

Refer to the exhibit. An administrator needs to create a new 5GB filesystem for /var/log. Which step is required?

A.Create a new partition on /dev/sdc and format with xfs
B.Shrink /home to free space in vg00 and create a new LV
C.Add /dev/sdc as a physical volume, extend vg00, create a logical volume, and format
D.Create a new volume group using /dev/sdb
AnswerC

The exhibit shows VG vg00 has no free physical extents, so you cannot create a new logical volume in that volume group without first adding capacity. Adding /dev/sdc as a physical volume via pvcreate or vgextend expands the VG's available space, after which a new logical volume can be created with lvcreate and then formatted with a filesystem such as xfs using mkfs.xfs. This is the standard approach when a dedicated disk is available and the goal is to allocate a new filesystem from an existing volume group.

Why this answer

To create a new filesystem for /var/log using available space on /dev/sdc, the disk must first be added as a physical volume (pvcreate), then added to the existing volume group vg00 (vgextend). After extending the VG, a new logical volume can be created (lvcreate) and formatted with a filesystem (e.g., mkfs.xfs). This approach leverages LVM's flexibility to allocate space from multiple physical volumes without requiring a separate volume group or partition manipulation.

Exam trap

For RHCSA, the key trap is that candidates often forget to add the new disk as a physical volume (pvcreate) before extending the volume group. They may try to directly create a logical volume on the raw disk or add it to the VG without the pvcreate step.

How to eliminate wrong answers

Option A is wrong because creating a new partition on /dev/sdc and formatting it with xfs would create a standalone filesystem not managed by LVM, which contradicts the requirement to use the existing volume group vg00 and does not integrate with the existing logical volume management. Option B is wrong because shrinking /home to free space in vg00 is unnecessary and risky; the question specifies a new 5GB filesystem for /var/log, and the available disk /dev/sdc should be added to vg00 rather than resizing existing LVs, which could cause data loss or complexity. Option D is wrong because creating a new volume group using /dev/sdb is irrelevant; the exhibit shows /dev/sdc as the available disk, and the goal is to extend the existing vg00, not create a separate VG.

248
MCQeasy

Refer to the exhibit. An administrator is unable to write to /tmp because the filesystem is full. What is the most likely cause?

A.The /tmp is a separate filesystem
B.There is a filesystem quota enabled
C.The /boot partition is too small
D.The root filesystem is nearly full at 90% usage
AnswerD

The root filesystem / is at 90% capacity with only 5.2GB free, and since /tmp is not a separate mount, it is part of this same root volume. When the root filesystem is nearly full, write attempts to /tmp can fail due to insufficient free space, especially if the file to be written is large or the filesystem has reserved blocks for root. The df output directly indicates a high usage level that commonly triggers 'no space left on device' errors for temporary file creation.

Why this answer

The exhibit shows that the root filesystem (/) is at 90% usage, while /tmp is not a separate filesystem but a directory under the root. Since /tmp resides on the root filesystem, when the root filesystem is nearly full, there is no space left for writing to /tmp, causing the write failure.

Exam trap

Red Hat often tests the misconception that /tmp is always a separate filesystem, leading candidates to overlook the root filesystem's usage as the cause of write failures.

How to eliminate wrong answers

Option A is wrong because if /tmp were a separate filesystem, it would have its own usage percentage shown in the df output; the exhibit does not list /tmp as a separate mount point, so it is part of the root filesystem. Option B is wrong because there is no indication of a filesystem quota being enabled; quotas are typically shown with commands like `repquota` or `quota`, and the df output does not reflect quota limits. Option C is wrong because the /boot partition being too small would not affect the ability to write to /tmp, as /boot is a separate filesystem used for boot files and does not share space with /tmp.

249
Multi-Selecteasy

Which TWO are correct ways to check the SELinux context of a file named 'test.txt'? (Choose exactly two.)

Select 2 answers
A.ls -Z test.txt
B.ls -l test.txt
C.sestatus
D.getenforce
E.stat test.txt
AnswersA, E

ls -Z is correct because the -Z flag, when used with ls, appends a column showing the SELinux security context (user:role:type:level) of the specified path. This output is read directly from the file's inode and provides the per-file label that SELinux uses for access control. It is the standard command for quickly checking a file's context in a directory listing.

Why this answer

`ls -Z` displays the SELinux security context of files, including user, role, type, and sensitivity level. The `-Z` option is specifically designed to show SELinux context information for files and processes.

Exam trap

Red Hat often tests the distinction between commands that show SELinux status (`sestatus`, `getenforce`) versus commands that show file-level SELinux context (`ls -Z`, `stat`), trapping candidates who confuse system-wide status with per-file attributes.

250
MCQmedium

An administrator needs to terminate a hung process with PID 3456 that does not respond to 'kill -15 3456'. Which signal should be used next?

A.kill -9 3456
B.kill -15 3456
C.kill -19 3456
D.kill -1 3456
AnswerA

SIGKILL (signal 9) is the only signal that the Linux kernel delivers directly, bypassing any user-space signal handler in process 3456. Because neither the process nor its threads can catch, block, or ignore SIGKILL, the kernel immediately terminates the process and reaps its resources, making it the correct last resort for a hung process that has failed to respond to SIGTERM.

Why this answer

Kill -9 (SIGKILL) is the signal of last resort for a process that does not respond to SIGTERM (kill -15). SIGKILL cannot be caught, blocked, or ignored by the process; it forces immediate termination by the kernel. Since the process is hung and unresponsive to SIGTERM, SIGKILL is the appropriate next step.

Exam trap

Red Hat often tests the distinction between signals that can be caught/ignored (SIGTERM, SIGHUP) and those that cannot (SIGKILL, SIGSTOP), and candidates may mistakenly choose SIGSTOP (kill -19) thinking it will terminate the process, when it actually only suspends it.

How to eliminate wrong answers

Option B is wrong because kill -15 (SIGTERM) was already attempted and the process did not respond; repeating the same signal will not change the outcome. Option C is wrong because kill -19 (SIGSTOP) suspends a process rather than terminating it, which would leave the hung process in a stopped state, not resolve the issue. Option D is wrong because kill -1 (SIGHUP) typically causes a process to reread its configuration or terminate gracefully, but it is not a guaranteed termination signal and may be ignored or handled by the process, similar to SIGTERM.

251
MCQmedium

An administrator notices that the /tmp directory is filling up quickly. They want to find all files in /tmp that are larger than 100 MB and owned by user 'ftp', then delete them. The administrator runs: find /tmp -type f -size 100M -user ftp -exec rm {} \;. However, this command deletes only files that are exactly 100 MB, not larger. Which find expression should be used instead?

A.find /tmp -type f -size 100M -user ftp -exec rm {} \;
B.find /tmp -type f -size +100M -user ftp -exec rm {} \;
C.find /tmp -type f -size +100M ! -size 100M -user ftp -exec rm {} \;
D.find /tmp -type f -size +100M -size -100M -user ftp -exec rm {} \;
AnswerB

The + in -size +100M correctly selects every regular file in /tmp owned by the ftp user whose size is greater than 100 MiB, because the plus sign means 'greater than' in find's size test. Combined with -type f to ensure only regular files are considered and -user ftp to restrict ownership, the -exec rm {} \; safely removes each matching file, replacing {} with the pathname. This is the simplest and most precise way to express the administrator's intention.

Why this answer

The `find` command uses `+` before a size value to match files larger than that size, not exactly equal. The original command omitted the `+`, so it matched only files exactly 100 MB. Adding `+100M` correctly selects files larger than 100 MB.

Exam trap

Red Hat often tests the subtle difference between exact size matching and size range matching using the `+` and `-` prefixes, trapping candidates who assume `-size 100M` means 'greater than or equal to' instead of 'exactly equal to'.

How to eliminate wrong answers

Option A is wrong because `-size 100M` matches files exactly 100 MB, not larger, so it fails to delete files exceeding that size. Option C is wrong because `-size +100M ! -size 100M` is redundant and incorrect; `-size +100M` already excludes files exactly 100 MB, and the negation adds no benefit while potentially causing confusion. Option D is wrong because `-size +100M -size -100M` is contradictory and matches no files, as a file cannot be both larger than 100 MB and smaller than 100 MB simultaneously.

252
Multi-Selecthard

Which THREE actions are required to enable a non-root user to run containers using Podman on Red Hat Enterprise Linux 8?

Select 3 answers
A.Ensure the user has a running systemd user instance (loginctl enable-linger).
B.Configure subordinate UID and GID ranges for the user in /etc/subuid and /etc/subgid.
C.Add the user to the 'docker' group to access the Docker socket.
D.Enable user namespaces in the kernel if not already enabled.
E.Grant the user sudo privileges to run podman commands.
AnswersA, B, D

Rootless Podman relies on a per-user systemd instance to manage the lifecycle of container processes and services. `loginctl enable-linger` ensures that this user instance starts automatically at boot and persists after the user logs out, which is essential for containers running in the background. Without linger, containers may be terminated when the user session ends.

Why this answer

`loginctl enable-linger` ensures that the user's systemd user instance starts at boot and remains running after the user logs out. This is required for Podman to manage containers using systemd user services, such as auto-starting containers with `podman generate systemd`.

Exam trap

The trap here is that candidates may think adding a user to the 'docker' group is required for Podman, but Podman uses a different architecture (no daemon, no socket) and relies on user namespaces and subordinate ID ranges for rootless operation.

253
MCQhard

A company runs a critical web application in a container on a Red Hat Enterprise Linux 9 server. The container is started via a systemd service called 'webapp.service'. The service unit file was generated using 'podman generate systemd --new --name webapp'. Recently, after a kernel update and reboot, the service fails to start the container. The administrator runs 'systemctl status webapp.service' and sees 'Active: failed (Result: exit-code)' and 'Process: 1234 ExecStart=/usr/bin/podman run ... (code=exited, status=125)'. The administrator also checks 'journalctl -u webapp.service' and sees: 'Error: unable to start container: container create failed: OCI runtime error: container_linux.go:380: starting container process caused: exec: "/usr/bin/app.sh": stat /usr/bin/app.sh: no such file or directory'. The container image was built locally using a Containerfile that includes 'COPY app.sh /usr/bin/app.sh'. The administrator verifies the image is present locally. What should the administrator do to resolve this issue?

A.Disable SELinux with setenforce 0 and restart the service.
B.Remove the systemd service and regenerate it with 'podman generate systemd --new --name webapp'.
C.Manually create the /usr/bin/app.sh file inside the container using podman exec.
D.Rebuild the container image using 'podman build -t webapp .' to ensure the app.sh file is included, then restart the service.
AnswerD

Rebuilding with podman build -t webapp . rereads the Dockerfile/Containerfile in the current directory and recreates the image; if that file contains a COPY app.sh /usr/bin/app.sh step, the new image will contain the missing script. Because the systemd unit references the webapp image tag, when the service restarts it will pull the updated local image with the same tag and use it to run a fresh container. This addresses the root cause, and restarting the service verifies the container starts cleanly.

Why this answer

The error indicates that the container image is missing the `/usr/bin/app.sh` file, even though the `COPY` instruction was in the Containerfile. The most likely cause is that the image was built before the `app.sh` script was added to the build context, or the build was incomplete. Rebuilding the image with `podman build -t webapp .` ensures the file is properly included in the image layers, resolving the OCI runtime error.

Exam trap

The trap here is that candidates may confuse a missing file inside the container image with a host-level issue (SELinux, service unit, or runtime environment) and overlook the need to rebuild the image with the correct build context.

How to eliminate wrong answers

Option A is wrong because the error is a missing file inside the container, not a SELinux denial; disabling SELinux would not fix the missing binary and introduces a security risk. Option B is wrong because the systemd service unit is correctly generated and the issue is with the container image content, not the service definition; regenerating the unit would not add the missing file. Option C is wrong because `podman exec` requires a running container, but the container fails to start, so you cannot exec into it; even if you could, manual creation would be overwritten on restart and is not a proper fix.

254
MCQeasy

An administrator needs to ensure that the httpd service starts automatically after a system reboot and is set to start immediately without rebooting. Which command should be used?

A.systemctl set-default httpd
B.systemctl add httpd
C.systemctl enable --now httpd
D.systemctl start --enable httpd
AnswerC

systemctl enable --now httpd performs two actions atomically: it enables the httpd service to start automatically at boot by creating the appropriate .wants symlinks, and immediately starts it in the current session. This is the administrator-friendly equivalent of running systemctl enable httpd followed by systemctl start httpd. It is the correct command to satisfy the requirement of ensuring the service is running now and persists across reboots.

Why this answer

`systemctl enable --now httpd` both creates the necessary symlinks to start the httpd service automatically at boot (enable) and starts the service immediately (--now) without requiring a reboot. This combines two operations into one command, satisfying both requirements in the question.

Exam trap

The trap here is that candidates may confuse `systemctl enable` (for boot persistence) with `systemctl start` (for immediate execution), or misremember the `--now` flag as `--enable`, leading them to pick a syntactically invalid option like D or a non-existent subcommand like B.

How to eliminate wrong answers

Option A is wrong because `systemctl set-default` sets the default target (e.g., multi-user.target), not a service; it has no effect on httpd. Option B is wrong because `systemctl add` is not a valid systemctl subcommand; the correct command for enabling a service is `systemctl enable`. Option D is wrong because `systemctl start --enable httpd` uses an invalid option order; the correct syntax is `systemctl enable --now httpd`, and `--enable` is not a valid flag for `systemctl start`.

255
MCQhard

During a security audit, an administrator needs to list all TCP ports on which the system is listening, showing only the port numbers and the associated process names. Which command best achieves this?

A.netstat -tulpn
B.nmap -sT localhost
C.sudo ss -tlnp
D.lsof -i TCP:1-65535
AnswerC

sudo ss -tlnp is the correct modern command because ss is part of iproute2 and is the standard socket inspection utility in RHEL. The flags -t limit output to TCP, -l show only listening sockets, -n display numeric ports, and -p attach the PID and process name to each entry; sudo is required because process ownership information is only visible to root for sockets belonging to other users. This command directly reads kernel socket tables via /proc and gives a clean, complete list of all TCP listeners.

Why this answer

`sudo ss -tlnp` lists TCP listening sockets with numeric port numbers and process names. The `-t` flag filters for TCP, `-l` shows only listening sockets, `-n` displays numeric addresses/ports (avoiding DNS resolution), and `-p` reveals the process name. This command requires root privileges to see process information, hence `sudo`.

Exam trap

The trap here is that candidates often default to `netstat -tulpn` (Option A) because it is familiar, but Red Hat EX200 emphasizes `ss` as the modern replacement, and the question specifically asks for only TCP ports and process names, making `-u` (UDP) and the lack of `-l` (listening only) in the default `netstat` command incorrect.

How to eliminate wrong answers

Option A is wrong because `netstat -tulpn` lists both TCP and UDP sockets (due to `-u`), which is not requested, and it shows all sockets (including non-listening) unless combined with `-l`; also, `netstat` is deprecated in many distributions in favor of `ss`. Option B is wrong because `nmap -sT localhost` performs a TCP connect scan against the local host, which is an active scanning technique that may alter system state and does not simply list listening ports; it also requires root for certain scan types and does not show process names. Option D is wrong because `lsof -i TCP:1-65535` lists all open TCP file descriptors across the entire port range, which includes both listening and established connections, and it does not filter to only listening sockets without additional flags like `-sTCP:LISTEN`.

256
Multi-Selecthard

Which three commands can be used to display overall memory usage information?

Select 3 answers
A.free
B.uptime
C.top
D.ps aux
E.vmstat
AnswersA, C, E

`free` is a dedicated memory-reporting utility that reads from `/proc/meminfo` and displays a concise summary of total, used, free, shared, buff/cache, and available physical memory, along with swap usage. Modern versions emphasize the `available` field, which estimates how much memory can be allocated without swapping, unlike the more misleading `free` column. This makes `free` a straightforward and accurate command for quickly checking overall memory utilization.

Why this answer

The 'free' command displays the total, used, and available physical and swap memory on the system. It reads /proc/meminfo and presents a concise summary of memory usage, making it a primary tool for checking overall memory consumption.

Exam trap

Red Hat often tests the distinction between commands that show per-process memory (like ps aux) versus those that show system-wide memory totals (like free, top, vmstat), leading candidates to incorrectly select ps aux as a memory usage command.

257
MCQeasy

A system administrator is setting up storage for a new application server. The application requires two separate filesystems: one for the database (needs to be at least 10GiB) and one for logs (needs at least 5GiB). The server has a single 20GiB disk /dev/sda. The administrator plans to use LVM and a single volume group 'vg_app'. They create physical volume on /dev/sda, create the volume group, and then create two logical volumes: 'lv_db' of 10GiB and 'lv_logs' of 5GiB. They format lv_db as ext4 and lv_logs as xfs, and mount them at /db and /logs respectively. After rebooting, the system fails to mount /logs. What is the most likely cause?

A.The logical volume 'lv_logs' overlaps with 'lv_db'.
B.The /logs entry is missing from /etc/fstab.
C.The physical volume /dev/sda is not recognized by LVM after reboot.
D.The volume group 'vg_app' is not automatically activated.
AnswerB

The /etc/fstab file is the persistent mount table that systemd reads at boot via fstab-generator to create mount units. Without an entry for /dev/vg_app/lv_logs (or its UUID) pointing to /logs, the filesystem will not be mounted automatically after a reboot. The storage device exists and is formatted, but the mount point is empty because no fstab line tells the system to mount it. This is the classic cause of a filesystem that is reachable manually but unavailable after the server restarts.

Why this answer

The most likely cause is that the /logs entry is missing from /etc/fstab. After reboot, the system relies on /etc/fstab to mount filesystems automatically. Since the administrator created and mounted the filesystem manually, but did not add an entry for /logs in /etc/fstab, the mount fails on reboot.

The database mount may succeed if it was added, but the logs mount fails due to the missing fstab entry.

Exam trap

Red Hat often tests the misconception that LVM volumes are automatically mounted after creation, when in fact only the logical volumes are activated; the filesystem mount must be explicitly configured in /etc/fstab.

How to eliminate wrong answers

Option A is wrong because logical volumes in the same volume group do not overlap; LVM allocates distinct extents to each LV, so 'lv_db' and 'lv_logs' occupy separate non-overlapping regions on the physical volume. Option C is wrong because the physical volume /dev/sda is automatically recognized by LVM after reboot if the PV was created and the volume group was active; LVM stores metadata on the disk itself, so it persists across reboots. Option D is wrong because volume groups are automatically activated by default via the lvm2 systemd service or init script, unless explicitly deactivated or filtered in lvm.conf; a single VG on a single disk will activate normally.

258
Multi-Selecteasy

Which TWO statements about the /etc/shadow file are true? (Select exactly two.)

Select 2 answers
A.Contains hashed passwords for local users.
B.Contains the user's UID.
C.Is used to store encrypted group passwords.
D.Is readable by all users.
E.Contains password aging information such as minimum and maximum days.
AnswersA, E

This file is the central repository for each local user's password hash, stored as a salted string using an algorithm identifier such as $6$ for SHA-512 or $y$ for yescrypt. Because /etc/passwd must be world-readable for tools like ls -l to map UIDs, the encrypted password field there was moved out to this protected file. The presence of a password hash here is what makes local login authentication possible; an x field in /etc/passwd simply indicates the hash is in /etc/shadow.

Why this answer

The /etc/shadow file stores hashed user passwords using algorithms like SHA-512 or yescrypt, as defined by the pam_unix module. It also contains password aging fields (e.g., minimum days, maximum days, warning period) that enforce password expiration policies. These two functions make options A and E correct.

Exam trap

A common pitfall on Red Hat exams is confusing /etc/passwd (which contains UIDs and is world-readable) with /etc/shadow (which contains hashed passwords and is root-only). Many candidates incorrectly think /etc/shadow contains UIDs or is readable by all users.

259
Drag & Dropmedium

Arrange the steps to configure a logical volume snapshot named 'snap_lv_data' of logical volume 'lv_data'.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for configuring a logical volume snapshot is to first create the snapshot with lvcreate -s, mount it to access its contents, perform necessary operations (such as backups), unmount the snapshot, and finally remove it to clean up. Common mistakes include mounting or operating on the snapshot before it exists, or removing it prematurely.

260
MCQeasy

An administrator is configuring an NFS mount in /etc/fstab to mount from server:/export to /mnt/data. The mount must use the 'hard' and 'nosuid' options. Which line is correct?

A.server:/export /mnt/data nfs defaults,noexec,nodev 0 0
B.server:/export /mnt/data nfs nosuid,hard,defaults 0 0
C.server:/export /mnt/data ext4 defaults 0 0
D.server:/export /mnt/data nfs suid,soft 0 0
E.server:/export /mnt/data nfs nosuid,hard 0 0
AnswerE

Correct: for an NFS mount in /etc/fstab, the nfs filesystem type is used and the options nosuid,hard provide the required security and reliability. nosuid disables setuid bit processing on the remote filesystem, and hard ensures client processes hang and retry if the server goes down, avoiding premature I/O errors. This entry is the only one that satisfies both requirements without conflicting options.

Why this answer

It specifies the NFS filesystem type and includes both required mount options: 'nosuid' (disallows set-user-identifier/set-group-identifier bits) and 'hard' (retries NFS requests indefinitely until the server responds). The syntax follows the correct /etc/fstab format: <server>:/<export> <mountpoint> <fstype> <options> <dump> <pass>.

Exam trap

Red Hat often tests the misconception that 'defaults' can be combined with other options without conflict, but in reality 'defaults' includes 'suid', which directly contradicts the required 'nosuid' option.

How to eliminate wrong answers

Option A is wrong because it uses 'noexec' and 'nodev' instead of the required 'nosuid' and 'hard' options, and it omits 'hard' entirely. Option B is wrong because it includes 'defaults' after 'nosuid,hard', which is redundant and may cause unexpected behavior (defaults includes 'suid', conflicting with 'nosuid'). Option C is wrong because it specifies 'ext4' as the filesystem type, which is incorrect for an NFS mount.

Option D is wrong because it uses 'suid' (the opposite of the required 'nosuid') and 'soft' (which can cause silent data corruption on NFS timeouts) instead of 'hard'.

261
Multi-Selectmedium

Which TWO statements about systemd journal and rsyslog are correct?

Select 2 answers
A.rsyslog reads log messages directly from the journal files in /var/log/journal.
B.The command 'journalctl --list-boots' lists only the current boot's journal entries.
C.The command 'journalctl -u sshd.service' outputs the same as 'tail -f /var/log/messages' for SSH logs.
D.The journal stores logs in a structured binary format, allowing filtering by fields like _UID or _SYSTEMD_UNIT.
E.The journal can forward log messages to rsyslog by setting ForwardToSyslog=yes in /etc/systemd/journald.conf.
AnswersD, E

The systemd journal is stored as a compact, indexed binary database, not as text. Each entry includes a rich set of structured metadata fields, such as _UID, _SYSTEMD_UNIT, _PID, and _COMM, which can be used for powerful filtering with journalctl, e.g., journalctl _UID=1000. This design enables more precise querying than plain-text log files.

Why this answer

The systemd journal stores log data in a structured binary format (using the journald protocol), which allows filtering by specific fields such as _UID, _SYSTEMD_UNIT, or _COMM. This enables precise queries via journalctl, unlike plain-text log files.

Exam trap

The trap here is that candidates confuse the journal's structured binary format with plain-text log files, or assume rsyslog reads journal files directly, when in fact forwarding is configured via journald.conf.

262
MCQhard

Refer to the exhibit. The filesystem /var/www/html is mounted, but after a reboot, the directory is empty. What is the most likely cause?

A.The filesystem type is incorrectly specified as ext4 in fstab
B.The mount point /var/www/html does not exist after reboot
C.The device path /dev/vg_data/lv_web is not persistent across reboots
D.The logical volume is not activated at boot because the volume group is not set to auto-activate
AnswerD

The logical volume /dev/vg_data/lv_web is not activated at boot because the volume group vg_data is not set to auto-activate. In RHEL, LVM auto-activation is controlled by the volume_list setting in /etc/lvm/lvm.conf or by the LVM systemd units; if vg_data is excluded, the /dev/mapper/vg_data-lv_web device node is not created at boot, so /etc/fstab's mount attempt fails with a 'special device does not exist' error. Running vgchange -ay vg_data or enabling auto-activation would make the mount succeed. This precisely matches the symptom in the exhibit, so this is the correct answer.

Why this answer

If the volume group containing the logical volume is not set to auto-activate, the logical volume will not be available after reboot, causing the mount to fail silently or the filesystem to appear empty. The `auto_activation_volume_list` in `/etc/lvm/lvm.conf` controls which volume groups are activated automatically at boot; if the VG is excluded, the LV never becomes visible to the system.

Exam trap

Red Hat often tests the misconception that a missing mount point or incorrect fstab entry is the cause, when the real issue is LVM volume group auto-activation being disabled or misconfigured.

How to eliminate wrong answers

Option A is wrong because an incorrect filesystem type in fstab would cause a mount failure with an error message, not an empty directory after a successful mount. Option B is wrong because the mount point `/var/www/html` is a directory that persists across reboots unless explicitly deleted; if it did not exist, the mount would fail with a 'mount point does not exist' error. Option C is wrong because the device path `/dev/vg_data/lv_web` is a persistent LVM logical volume path that remains valid across reboots as long as the volume group is activated; the issue is not path persistence but volume group activation.

263
Multi-Selecteasy

Which TWO commands can be used to view the kernel ring buffer?

Select 2 answers
A.journalctl -f
B.dmesg
C.cat /var/log/messages
D.systemctl status
E.journalctl -k
AnswersB, E

dmesg is the canonical command for viewing the kernel ring buffer, a fixed-size circular buffer in kernel memory where the kernel stores its own messages, such as driver initialization, hardware detection, and early boot errors. It reads from the buffer directly via the syslog(2) system call or /dev/kmsg, providing a concise snapshot of kernel-level events. This is the primary, in-memory source for kernel logs, not a file or a systemd-specific interface.

Why this answer

The kernel ring buffer stores kernel-related messages, such as hardware driver and boot messages. The `dmesg` command is specifically designed to print or control this buffer, making it a direct and correct tool for viewing kernel ring buffer messages.

Exam trap

The trap here is that candidates may confuse general log viewing commands (like `journalctl -f` or `cat /var/log/messages`) with the specific tools designed to read the kernel ring buffer, or forget that `journalctl -k` is the systemd-native way to access kernel messages.

264
MCQhard

A complex script uses 'trap' to handle signals. The admin writes 'trap '' SIGINT' to ignore Ctrl+C, but later in the script they want to re-enable the default behavior. Which command restores the default behavior for SIGINT?

A.trap - SIGINT
B.trap : SIGINT
C.trap 2
D.trap SIGINT
AnswerA

trap - SIGINT resets SIGINT to its default disposition, undoing the earlier ignore. The hyphen tells the shell to restore default handling rather than run a command, which is exactly the re-enable behaviour the script needs after ignoring Ctrl+C.

Why this answer

`trap - SIGINT` resets the signal handler for SIGINT to its default behavior. The `trap '' SIGINT` command sets an empty action, which ignores the signal; using `trap - signal` removes that custom handler and restores the default action (typically terminating the process).

Exam trap

The RHCSA exam often tests the subtle distinction between `trap '' signal` (ignore) and `trap - signal` (restore default), where candidates mistakenly think `trap signal` or `trap : signal` resets the handler.

How to eliminate wrong answers

Option B is wrong because `trap : SIGINT` sets the action to the null command `:`, which is a no-op that still ignores the signal (similar to `trap '' SIGINT`), not restoring the default. Option C is wrong because `trap 2` is invalid syntax; signal numbers must be preceded by a dash or used with a signal name, and this would attempt to set a command '2' for the signal, causing an error or unintended behavior. Option D is wrong because `trap SIGINT` without a command or dash is ambiguous and typically results in an error or sets the trap to an empty string, depending on the shell, but does not restore the default handler.

265
MCQeasy

A junior admin receives a ticket: 'The /var partition is filling up quickly. The server has an extra 100GB disk /dev/sdb. The /var filesystem is on logical volume lv_var in volume group vg_system. Currently, vg_system has no free extents. The admin's plan: create a new physical volume on /dev/sdb, extend vg_system, extend lv_var, and resize the filesystem. He runs: pvcreate /dev/sdb; vgextend vg_system /dev/sdb; lvextend -L+100G /dev/vg_system/lv_var; resize2fs /dev/vg_system/lv_var. The system reports error: 'resize2fs: Invalid argument while trying to open /dev/vg_system/lv_var'. What is the most likely mistake?

A.He should have used lvresize instead of lvextend.
B.He forgot to run partprobe after pvcreate.
C.The lvextend command failed because vg_system has no free extents.
D.He used resize2fs instead of xfs_growfs because /var is typically XFS.
AnswerD

On RHEL 8 and RHEL 9, the default filesystem for /var (and other directories) is XFS, not ext4. After extending the logical volume, the filesystem must be grown to use the new space, and the proper command for that is xfs_growfs, not resize2fs—resize2fs only works on ext2/ext3/ext4 filesystems and will fail or do nothing against XFS. Therefore, the admin's use of resize2fs is exactly the mistake that would leave /var appearing full even though the LV was successfully expanded.

Why this answer

The error 'resize2fs: Invalid argument while trying to open /dev/vg_system/lv_var' indicates that the filesystem on lv_var is not ext2/3/4 but likely XFS. RHEL 8/9 defaults to XFS for /var, and XFS requires xfs_growfs (which operates on a mount point, not a block device) instead of resize2fs. Using resize2fs on an XFS filesystem produces this exact error.

Exam trap

The trap here is that candidates assume all Linux filesystems use resize2fs, but EX200 tests the RHEL default of XFS, which requires xfs_growfs and a mount point argument, not a block device.

How to eliminate wrong answers

Option A is wrong because lvextend and lvresize are functionally equivalent for extending a logical volume; lvextend is a subset of lvresize and does not cause the error. Option B is wrong because partprobe is unnecessary after pvcreate on a whole disk (no partition table); pvcreate directly writes LVM metadata to /dev/sdb, and the kernel recognizes it without partprobe. Option C is wrong because the lvextend command would have failed with a 'no free extents' error before reaching resize2fs; the admin successfully extended lv_var (as shown by the error occurring at resize2fs), meaning vgextend provided free extents.

266
MCQeasy

A system administrator is troubleshooting a RHEL 9 server that fails to boot and drops into emergency mode. The system console shows an error about mounting /dev/sdb1 on /data. The administrator enters emergency mode, checks /etc/fstab, and sees the line: /dev/sdb1 /data ext4 defaults 0 0. The /data directory exists but /dev/sdb1 is a partition on an external USB drive that was removed. The administrator needs the system to boot normally without the USB drive and plans to fix the mount configuration later. Which course of action should the administrator take?

A.Remove the line from /etc/fstab and run systemctl daemon-reload, then reboot.
B.Add the nofail option to the fstab line, then reboot.
C.Delete the /data directory and reboot.
D.Use a text editor to insert '#' at the beginning of the /dev/sdb1 line in /etc/fstab, then reboot.
AnswerD

Inserting a '#' at the start of the /dev/sdb1 line comments out the entire fstab entry, causing systemd-fstab-generator to skip generating a mount unit for that device. With the entry now inactive, no mount attempt is made at boot, and the system avoids the failure while retaining the rest of the fstab configuration for maintenance or later re-enablement.

Why this answer

Commenting out the /dev/sdb1 line in /etc/fstab with '#' prevents systemd from attempting to mount the missing device during boot, allowing the system to boot normally into multi-user.target. This is a safe, reversible change that does not delete the mount point or alter the filesystem, and it preserves the original configuration for later restoration.

Exam trap

The trap here is that candidates may think removing the line or adding nofail is the correct fix, but they overlook that the system is already in emergency mode and the immediate goal is to boot normally with minimal changes, making a simple comment-out the safest and most reversible action.

How to eliminate wrong answers

Option A is wrong because removing the line from /etc/fstab and running systemctl daemon-reload does not take effect until the next reboot; however, the immediate boot failure is caused by systemd's mount unit for /data failing, and removing the line alone does not address the current emergency mode state—though it would work after reboot, it is less reversible and not the minimal fix. Option B is wrong because adding the nofail option to the fstab line requires editing the file and rebooting, but the system is already in emergency mode; while nofail would prevent future boot failures, it does not resolve the immediate need to boot without the USB drive, and it permanently changes the mount behavior rather than temporarily disabling the entry. Option C is wrong because deleting the /data directory does not fix the mount failure; systemd still attempts to mount /dev/sdb1 on /data, and the missing device will cause the same error, plus deleting the directory may cause data loss if it contains important files.

267
Multi-Selectmedium

Which TWO commands can be used to view the contents of a compressed file named 'archive.tar.gz' without extracting it?

Select 2 answers
A.gzip -d archive.tar.gz
B.tar -tzf archive.tar.gz
C.gunzip -c archive.tar.gz
D.tar -xf archive.tar.gz
E.zcat archive.tar.gz | tar -t
AnswersB, E

tar -tzf archive.tar.gz is the canonical one-step listing command: -t selects list mode, -z tells tar to transparently decompress the gzip layer, and -f specifies the archive filename. It reads the gzip-compressed tar stream, walks each tar header entry, and prints metadata such as filenames, permissions, sizes, and timestamps without extracting any files. This is the standard, safe way to inspect a .tar.gz archive's contents.

Why this answer

`tar -tzf archive.tar.gz` lists the contents of a gzip-compressed tar archive without extracting it. The `-t` option tells tar to list the table of contents, `-z` filters the archive through gzip decompression, and `-f` specifies the archive file. This command reads the archive metadata directly without writing any files to disk.

Exam trap

The trap here is that candidates confuse decompression commands (like `gunzip -c`) with listing commands, or they assume `tar -xf` can list contents because of the `-x` (extract) flag, but `-x` always writes files unless combined with `-t` which overrides it to list mode.

268
MCQeasy

A technician needs to configure a static IPv4 address on a RHEL 9 network interface 'enp1s0' using NetworkManager. Which command should be used to set the IP address?

A.nmcli connection modify enp1s0 ipv4.addresses 192.168.1.100/24
B.nmtui edit enp1s0 --ipv4 192.168.1.100/24
C.ip addr add 192.168.1.100/24 dev enp1s0
D.ifconfig enp1s0 192.168.1.100 netmask 255.255.255.0
AnswerA

`nmcli connection modify` writes the static address into the NetworkManager connection profile for `enp1s0`, satisfying the requirement to configure it through NetworkManager rather than editing ifcfg files or using `ip addr`. The `ipv4.addresses` property accepts the address with prefix length, and the change persists across reboots once the connection is reactivated.

Why this answer

`nmcli connection modify enp1s0 ipv4.addresses 192.168.1.100/24` is the proper NetworkManager command to set a static IPv4 address on a RHEL 9 interface. This command modifies the connection profile for 'enp1s0' by setting the `ipv4.addresses` property to the specified address and prefix length, which is the standard method for persistent static IP configuration via NetworkManager.

Exam trap

The trap here is that candidates often confuse temporary runtime commands (like `ip addr add` or deprecated `ifconfig`) with persistent configuration tools required by NetworkManager, or they misuse `nmtui` syntax expecting inline arguments instead of its interactive interface.

How to eliminate wrong answers

Option B is wrong because `nmtui edit enp1s0 --ipv4 192.168.1.100/24` is not a valid syntax; `nmtui` is an interactive text user interface and does not accept command-line arguments like `--ipv4` — it must be run interactively or with subcommands like `nmtui edit` without inline IP assignment. Option C is wrong because `ip addr add 192.168.1.100/24 dev enp1s0` only adds the IP address temporarily to the kernel's network stack; it does not persist across reboots and does not use NetworkManager, so it is not the correct tool for a persistent static configuration. Option D is wrong because `ifconfig` is deprecated in RHEL 9 and does not integrate with NetworkManager; it also only sets the address temporarily and lacks persistent configuration capabilities.

269
MCQhard

A company has a RHEL 9 server that hosts a critical application. The server has two network interfaces: enp1s0 (192.168.1.100/24) and enp2s0 (10.0.0.100/24). The default gateway is 192.168.1.1. The application listens on a TCP port 8080 and should be accessible from both networks. Recently, the administrator noticed that clients on the 10.0.0.0/24 network can ping the server's 10.0.0.100 address but cannot connect to port 8080. Clients on 192.168.1.0/24 can connect fine. The firewall is configured with the default zone (public) and the service 'http' is allowed, but port 8080 is not specifically allowed. The administrator checks 'firewall-cmd --list-all' and sees that only services 'ssh' and 'http' are listed. The application is running and listening on 0.0.0.0:8080. What is the most likely cause and the correct course of action?

A.Disable SELinux to allow the application to accept connections.
B.Add a firewall rule to open TCP port 8080 in the public zone using 'firewall-cmd --add-port=8080/tcp --permanent' and reload.
C.Change the application to listen only on the 10.0.0.100 interface.
D.Add a static route for the 10.0.0.0/24 network via the 10.0.0.1 gateway.
AnswerB

This is the correct fix because firewalld's public zone is rejecting incoming TCP connections to port 8080, even though the application is bound to all interfaces. The command 'firewall-cmd --add-port=8080/tcp --permanent' adds the rule to the persistent configuration, and then executing 'firewall-cmd --reload' loads it into the active runtime. This allows external clients on 10.0.0.0/24 to reach the service while preserving all other existing zone rules.

Why this answer

The firewall is blocking incoming connections to port 8080 because only services 'ssh' (port 22) and 'http' (port 80) are allowed in the public zone. Since the application listens on 0.0.0.0:8080, it is reachable from both networks at the IP level, but the firewall drops packets destined for port 8080. Adding a permanent rule to open TCP port 8080 and reloading the firewall configuration resolves the issue.

Exam trap

The trap here is that candidates assume the application is unreachable due to a routing or SELinux issue, overlooking the fact that the firewall's default zone only allows explicitly listed services and ports, and that 'http' does not cover port 8080.

How to eliminate wrong answers

Option A is wrong because SELinux does not block network ports by default; it enforces mandatory access control on processes, and disabling it is unnecessary and insecure—the problem is firewall-related, not SELinux. Option C is wrong because the application already listens on 0.0.0.0 (all interfaces), and restricting it to 10.0.0.100 would break connectivity for clients on the 192.168.1.0/24 network. Option D is wrong because clients on 10.0.0.0/24 can already ping the server's 10.0.0.100 address, indicating routing is functional; the issue is a firewall rule, not a missing static route.

270
MCQhard

An administrator wants to encrypt a new partition /dev/sdc1 using LUKS. Which command sequence is correct?

A.mkfs.ext4 /dev/sdc1; cryptsetup luksFormat /dev/sdc1; cryptsetup open /dev/sdc1 secret; mount /dev/mapper/secret /mnt
B.cryptsetup open /dev/sdc1 secret; mkfs.ext4 /dev/mapper/secret; cryptsetup luksFormat /dev/mapper/secret; mount /dev/mapper/secret /mnt
C.cryptsetup luksFormat /dev/sdc1; mkfs.ext4 /dev/sdc1; cryptsetup open /dev/sdc1 secret; mount /dev/mapper/secret /mnt
D.cryptsetup open /dev/sdc1 secret; cryptsetup luksFormat /dev/mapper/secret; mkfs.ext4 /dev/mapper/secret; mount /dev/mapper/secret /mnt
E.cryptsetup luksFormat /dev/sdc1; cryptsetup open /dev/sdc1 secret; mkfs.ext4 /dev/mapper/secret; mount /dev/mapper/secret /mnt
AnswerE

This is the correct sequence. First, cryptsetup luksFormat /dev/sdc1 writes the LUKS header and initial encryption metadata to the raw partition, binding it to a passphrase. Next, cryptsetup open /dev/sdc1 secret authenticates the passphrase and creates /dev/mapper/secret as a decrypted block device that transparently encrypts all writes and decrypts all reads. Then mkfs.ext4 on /dev/mapper/secret creates a normal ext4 filesystem inside the encrypted container, so every filesystem block is stored on /dev/sdc1 in ciphertext; finally, mount /dev/mapper/secret /mnt attaches that decrypted filesystem. The order is essential: format the raw device first, map it, and only then create the filesystem on the mapped device.

Why this answer

The proper sequence for encrypting a new partition with LUKS is: first initialize the LUKS header on the block device with `cryptsetup luksFormat`, then open the encrypted device to create a mapping under `/dev/mapper/`, then create a filesystem on the mapped device (not the raw block device), and finally mount the mapped device. This ensures the filesystem is built on top of the encrypted layer, not on the unencrypted partition.

Exam trap

Red Hat often tests the misconception that you can create a filesystem directly on the raw partition after `luksFormat` (Option C) or that you should open the device before formatting it with LUKS (Option B), leading candidates to confuse the order of operations for LUKS encryption.

How to eliminate wrong answers

Option A is wrong because it creates a filesystem on the raw `/dev/sdc1` before LUKS encryption, which would leave the filesystem unencrypted and the subsequent `luksFormat` would overwrite it. Option B is wrong because it attempts to open a LUKS device that hasn't been formatted yet (`cryptsetup open` before `luksFormat`), and then tries to `luksFormat` the mapper device instead of the raw block device. Option C is wrong because it creates a filesystem directly on `/dev/sdc1` after `luksFormat`, which would destroy the LUKS header and leave data unencrypted.

Option D is wrong because it opens a non-existent LUKS container (no `luksFormat` first) and then tries to `luksFormat` the mapper device, which is not the correct target for initialization.

271
MCQeasy

An administrator needs to enable swap on a newly created partition /dev/sdc1. Which two commands should be executed in order?

A.mkswap /dev/sdc1; mount /dev/sdc1
B.swapon /dev/sdc1; mkswap /dev/sdc1
C.swapon /dev/sdc1; mount /dev/sdc1
D.mkfs.swap /dev/sdc1; swapon /dev/sdc1
E.mkswap /dev/sdc1; swapon /dev/sdc1
AnswerE

This is the correct two-step sequence: first mkswap /dev/sdc1 writes the swap signature (version 2 header with UUID and page count) onto the partition, making it a valid swap area. Then swapon /dev/sdc1 reads that signature, validates it, and registers the device with the kernel's swap subsystem, adding it to the active swap list visible under /proc/swaps. This immediately enables kernel memory paging to the device without requiring a mount point. The order is mandatory because swapon will reject a device that does not already contain a valid swap header.

Why this answer

Enabling swap on a new partition requires first formatting it as swap space with `mkswap`, then activating it with `swapon`. The `mkswap` command writes a swap signature to the partition, and `swapon` enables the kernel to use it as swap. Without `mkswap`, the partition lacks the proper swap filesystem structure and cannot be used for swapping.

Exam trap

The trap here is that candidates confuse the order of operations or mistakenly think `mount` can be used for swap, or that `mkfs.swap` is a valid command, when in fact swap requires `mkswap` followed by `swapon` and never uses `mount`.

How to eliminate wrong answers

Option A is wrong because `mount` cannot mount a swap partition; swap is not a regular filesystem and must be activated with `swapon`, not mounted. Option B is wrong because `swapon` is executed before `mkswap`, which fails since the partition has no swap signature yet; the order must be reversed. Option C is wrong because `swapon` on an unformatted partition fails, and `mount` is invalid for swap.

Option D is wrong because `mkfs.swap` is not a valid command; the correct command to create a swap filesystem is `mkswap`.

272
Multi-Selecteasy

Which TWO commands can mount an ISO file /tmp/rhel.iso to /mnt/iso?

Select 2 answers
A.mount -o loop /tmp/rhel.iso /mnt/iso
B.isomount /tmp/rhel.iso /mnt/iso
C.mount -t iso9660 -o loop /tmp/rhel.iso /mnt/iso
D.losetup /tmp/rhel.iso && mount /dev/loop0 /mnt/iso
E.mount /tmp/rhel.iso /mnt/iso
AnswersA, C

The -o loop option is what makes this command correct. Without an explicit filesystem type, mount probes the file and detects the ISO 9660 filesystem automatically. The kernel associates the regular file /tmp/rhel.iso with an available loop device (e.g., /dev/loop0), then mounts that device at /mnt/iso. This is the standard, minimal way to mount an ISO file.

Why this answer

Option A is correct because `mount -o loop /tmp/rhel.iso /mnt/iso` uses the loop option to associate the ISO file with a loop device and mount it; on modern Linux, mount auto-detects the ISO9660 filesystem, so no explicit type is required. Option C is also correct because `mount -t iso9660 -o loop /tmp/rhel.iso /mnt/iso` explicitly specifies the ISO9660 filesystem type while still using the loop option, which is the traditional and fully explicit way to mount an ISO image. Option B is wrong because `isomount` is not a standard Linux command.

Option D is wrong as written because `losetup /tmp/rhel.iso` without `-f` does not reliably create/attach a loop device and the chained mount assumes /dev/loop0, which may not be the device assigned. Option E is wrong because `mount /tmp/rhel.iso /mnt/iso` lacks the loop option and will fail to mount a regular file as a block device.

Exam trap

The trap here is that candidates may think `mount` can directly handle a file without the loop option (Option E), or they may confuse `losetup` syntax (Option D) with the correct procedure, leading to errors in a real exam scenario.

273
Drag & Dropmedium

Order the steps to create a new LVM logical volume of 5 GiB named 'lv_data' in volume group 'vg_data'.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for creating an LVM logical volume is: first create physical volumes (PVs) with pvcreate, then the volume group (VG) with vgcreate, then the logical volume (LV) with lvcreate, then a filesystem on the LV with mkfs, and finally mount it. Any deviation from this order will fail because each step depends on the previous ones.

274
MCQmedium

A developer runs the script shown in the exhibit and always sees 'Success' printed, even when the previous command fails. What is the most likely cause?

A.The [[ ]] syntax always evaluates to true
B.The $? variable is only set after external commands, not builtins
C.The $? variable captures the exit status of the [[ command, not the intended command
D.The $? variable always returns 0 in a conditional
AnswerC

In the given script, if an intended command is followed by a [[ ... ]] test, $? will reflect the exit status of the [[ ]] evaluation, not the earlier command. For example, if the script does [[ -f file ]] after running an application, $? becomes 1 when file does not exist, even if the application succeeded. Because $? is overwritten by each subsequent command, any intervening conditional destroys the original exit value.

Why this answer

The `[[ ]]` conditional construct is a shell keyword that itself produces an exit status. When `$?` is checked immediately after `[[ ]]`, it captures the exit status of the `[[ ]]` evaluation (which is 0 if the condition is true, 1 if false), not the exit status of the command that was run before the `[[ ]]`. Since the developer always sees 'Success' printed, the `[[ ]]` condition must be evaluating to true (exit status 0), causing `$?` to be 0 and the script to always take the success path, regardless of the actual previous command's result.

Exam trap

The trap here is that candidates mistakenly think `$?` always reflects the original command's exit status, not realizing that `[[ ]]` is itself a command that resets `$?` to its own exit status, causing the check to always succeed if the `[[ ]]` expression is syntactically valid.

How to eliminate wrong answers

Option A is wrong because `[[ ]]` does not always evaluate to true; it evaluates to true (exit status 0) or false (exit status 1) based on the expression inside it. Option B is wrong because `$?` is set after every command, including shell builtins like `[[ ]]`, `[ ]`, and `echo`; it is not limited to external commands. Option D is wrong because `$?` does not always return 0 in a conditional; it returns the exit status of the most recently executed command, which can be non-zero if that command failed.

275
MCQhard

An ext4 filesystem on a logical volume has been extended with lvextend, but df -h still shows the old size. Which command must be run to make the filesystem aware of the new size?

A.lvextend -r
B.fsadm resize
C.resize2fs
D.xfs_growfs
AnswerC

resize2fs is the correct command because the logical volume has already been grown and only the ext4 filesystem's metadata still reflects the old smaller size. Running resize2fs /dev/yourvg/yourlv without a size argument makes the filesystem expand to use all available space in the enlarged logical volume. It can be used online for mounted ext4 filesystems, making it the direct and standard method to complete the extension.

Why this answer

The `resize2fs` command is the correct tool to resize an ext4 filesystem after the underlying logical volume has been extended with `lvextend`. While `lvextend` expands the block device, the filesystem itself is not automatically aware of the new space; `resize2fs` adjusts the filesystem metadata to utilize the additional capacity.

Exam trap

The trap here is that candidates may confuse the filesystem-specific commands (resize2fs for ext4 vs. xfs_growfs for XFS) or assume that extending the logical volume automatically resizes the filesystem, which is only true if the `-r` flag is used with `lvextend`.

How to eliminate wrong answers

Option A is wrong because `lvextend -r` is a valid shortcut that combines extending the logical volume and resizing the filesystem, but the question asks which command must be run after `lvextend` has already been executed without the `-r` flag. Option B is wrong because `fsadm resize` is a utility for resizing filesystems on LVM volumes, but it is not the standard command for ext4; `resize2fs` is the direct and preferred tool. Option D is wrong because `xfs_growfs` is used to grow XFS filesystems, not ext4 filesystems.

276
MCQeasy

A RHEL 8 system has an ext4 filesystem on /dev/sdb1 mounted at /backup. The admin runs out of space and wants to extend the filesystem. He adds a new disk /dev/sdc, creates a partition /dev/sdc1 (all space), adds it to LVM by creating a PV and extending the VG that contains the LV for /backup. He then extends the logical volume with lvextend -L+20G /dev/vg_backup/lv_backup. The command succeeds, but the filesystem still shows the old size. What did he forget to do?

A.Reboot the system to recognize the new space.
B.Resize the filesystem using resize2fs.
C.Run lvchange -ay to activate the logical volume.
D.Unmount the filesystem before extending the LV.
AnswerB

Running resize2fs on the logical volume is the mandatory second step because lvextend only expands the block device, not the filesystem. The ext4 superblock's block count is still set to the old capacity, and the resize2fs utility updates the on-disk metadata and grows the filesystem to consume the newly available blocks. Because the filesystem is already mounted, the online resize can be done with no downtime, using the device path such as /dev/vg/lv.

Why this answer

When extending an LVM logical volume, the `lvextend` command only expands the logical volume's block device, not the filesystem residing on it. After extending the LV, the admin must run `resize2fs` (for ext4) to resize the filesystem to match the new LV size. Without this step, the kernel still sees the old filesystem metadata, so `df -h` reports the original size.

Exam trap

The trap here is that candidates assume `lvextend` automatically resizes the filesystem, but it only extends the logical volume; a separate filesystem resize command is required for non-LVM-aware filesystems like ext4.

How to eliminate wrong answers

Option A is wrong because rebooting is unnecessary; the kernel recognizes the new LV size immediately after `lvextend`, but the filesystem itself must be resized with `resize2fs`. Option C is wrong because `lvchange -ay` activates the LV, but the LV is already active (the `lvextend` succeeded), so this command is irrelevant. Option D is wrong because ext4 filesystems can be resized online (mounted) with `resize2fs`; unmounting is not required for extending, only for shrinking.

277
Multi-Selecthard

Which THREE options are valid when creating a new partition with the 'parted' command? (Choose three.)

Select 3 answers
A.Setting the partition's UUID
B.Setting the partition's bootable flag
C.Setting the partition's name (GPT only)
D.Mounting the partition to a directory
E.Setting the partition type (e.g., ext4)
AnswersB, C, E

Setting the partition's bootable flag is a valid operation when creating a partition with parted, as the 'set' command can toggle flags such as 'boot' on MBR partitions. This flag marks the partition as active, which is required for legacy BIOS booting to find the boot loader. It is purely a partition table attribute and does not affect the filesystem, so it can be done during or after partition creation without any formatting implications.

Why this answer

The 'parted' command can set the bootable flag on a partition using the 'set' command (e.g., 'set 1 boot on'). This flag is used by legacy BIOS bootloaders to identify the active partition, and it is a standard operation in MBR and GPT partition tables.

Exam trap

The trap here is that candidates confuse setting the partition type label (e.g., 'ext4') in parted with actually formatting the partition, or they assume parted can mount or assign UUIDs, which are filesystem-level tasks outside parted's scope.

278
MCQeasy

A junior admin needs to ensure that the 'apache' user (UID 48) cannot log in via SSH or console. Which command achieves this?

A.usermod -s /sbin/nologin apache
B.passwd -l apache
C.chage -l apache
D.usermod -e 1 apache
AnswerA

Setting the login shell to /sbin/nologin blocks interactive SSH and console sessions for apache while leaving the account valid for service processes. This satisfies the requirement to deny login without deleting the UID 48 account.

Why this answer

Setting the user's login shell to `/sbin/nologin` prevents the user from obtaining an interactive shell via SSH or console login. When the user attempts to log in, the system executes `/sbin/nologin`, which prints a polite message and exits immediately, effectively denying shell access while leaving other services (e.g., Apache) functional.

Exam trap

The trap here is that candidates often confuse password locking (`passwd -l`) with shell restriction, not realizing that SSH key authentication or console login via `su` bypasses password locks, while changing the shell to `/sbin/nologin` blocks all interactive login methods.

How to eliminate wrong answers

Option B is wrong because `passwd -l apache` locks the user's password, preventing password-based authentication, but it does not prevent SSH key-based authentication or console login via other methods (e.g., su, sudo). Option C is wrong because `chage -l apache` lists the user's password aging information; it does not modify any setting that would block login. Option D is wrong because `usermod -e 1 apache` sets the account expiration date to January 1, 1970 (epoch), which disables the account entirely, but this is an overly aggressive approach that also prevents the Apache service from running as that user, whereas the requirement is only to prevent interactive login.

279
MCQmedium

A technician is configuring a new Red Hat Enterprise Linux 9 server with multiple disks. They need to create a RAID 1 array using /dev/sda and /dev/sdb for the /boot partition. Which tool can create the RAID array and enable booting from it?

A.Use mdadm to create a RAID1 device and install GRUB on both disks
B.Use parted to create a RAID array directly by specifying the RAID level
C.Use fdisk to create a RAID partition and then format with ext4
D.Use LVM to create a mirrored logical volume for /boot
AnswerA

mdadm is the standard RHEL tool for building software RAID, and RAID1 gives /boot redundancy without requiring GRUB to understand LVM. After creating /dev/md0 from a partition on each disk, run grub2-install on both /dev/sda and /dev/sdb so the BIOS can load GRUB from either disk if one fails. This is the only supported way to get a redundant boot path on a traditional BIOS system.

Why this answer

Mdadm is the standard Linux tool for creating software RAID arrays, including RAID 1 (mirroring). For the /boot partition, which must be readable by the bootloader, GRUB must be installed on both disks in the RAID 1 array to ensure bootability if one disk fails. mdadm creates the RAID device, and GRUB can then be installed on each disk's MBR or GPT partition.

Exam trap

The trap here is that candidates may think LVM mirroring is acceptable for /boot, but Red Hat exams emphasize that /boot must not use LVM or complex RAID levels; only RAID 1 with mdadm and GRUB on both disks is supported for bootability.

How to eliminate wrong answers

Option B is wrong because parted is a partition editor and cannot create RAID arrays; it can only create partitions, not configure RAID levels. Option C is wrong because fdisk can create RAID partitions (by setting the partition type to fd for Linux RAID), but it cannot create the RAID array itself; formatting with ext4 alone does not provide mirroring. Option D is wrong because LVM mirrored logical volumes are not recommended for /boot; the bootloader (GRUB) cannot read LVM metadata reliably, and /boot must reside on a non-LVM, non-RAID (or simple RAID 1) partition for boot compatibility.

280
Multi-Selecthard

Which THREE are valid methods to configure network bonding in RHEL 9? (Choose exactly three.)

Select 3 answers
A.Using a configuration file in /etc/NetworkManager/system-connections/.
B.Using nmcli to create a bond connection.
C.Using nmtui interactive interface.
D.Using the teamd service.
E.Editing /etc/sysconfig/network-scripts/ifcfg-bond0 directly.
AnswersA, B, C

This is valid because NetworkManager persists every connection profile as a keyfile in /etc/NetworkManager/system-connections/. You can manually create a file like bond0.nmconnection with a [bond] section, specify the interface-name and bond mode, then run `nmcli connection reload` and `nmcli connection up bond0`. NetworkManager reads these files natively on RHEL 8/9.

Why this answer

In RHEL 9, NetworkManager stores connection profiles in `/etc/NetworkManager/system-connections/`. You can manually create a bond configuration file in this directory with the proper key-value pairs (e.g., `type=bond`, `bond.options=mode=1,miimon=100`), and NetworkManager will read it on restart or reload. This is a valid method for configuring network bonding.

Exam trap

The trap here is that candidates familiar with RHEL 7 or 8 may still expect `ifcfg-*` files or `teamd` to be valid, but RHEL 9 has fully removed both, making only NetworkManager-based methods (files, nmcli, nmtui) correct.

281
Multi-Selecthard

Which THREE of the following are common steps to configure a system to automatically mount an NFS share at boot?

Select 3 answers
A.Run 'mount -a' after boot
B.Ensure nfs-utils is installed
C.Use autofs
D.Configure /etc/exports
E.Add an entry to /etc/fstab
AnswersB, C, E

The nfs-utils package must be present on the client because it supplies mount.nfs, a helper binary that the kernel's NFS client calls to perform the mount operation, along with tools like showmount. On Red Hat Enterprise Linux, if nfs-utils is not installed, any attempt to mount an NFS share fails with 'mount: unknown filesystem type nfs'. Thus, ensuring nfs-utils is installed is a fundamental prerequisite for an NFS client.

Why this answer

B is correct because the NFS client functionality in Red Hat Enterprise Linux is provided by the nfs-utils package. Without this package installed, the system lacks the necessary tools (such as mount.nfs and rpcbind) to mount NFS shares, making it impossible to configure automatic mounting at boot.

Exam trap

Red Hat often tests the misconception that /etc/exports is a client-side configuration file, when in fact it is strictly a server-side file used to define exported directories, not client-side automount settings.

282
MCQeasy

A developer is running Podman as a non-root user on a Red Hat Enterprise Linux 8 system. The developer successfully runs a container, but notices that after logging out of the SSH session, the container stops. The developer wants the container to continue running even after disconnecting from the SSH session. The container is a simple web server that listens on port 8080. The developer has already enabled lingering for the user account using 'loginctl enable-linger'. However, the container still stops upon logout. What additional step should the developer take to ensure the container persists after logout?

A.Add the --restart=always flag to the podman run command
B.Use podman run --detach to run the container in the background
C.Use podman run -d to run the container in detached mode
D.Create a systemd user service by running 'podman generate systemd --new --name mywebcontainer' and then enable and start the service with 'systemctl --user enable --now container-mywebcontainer.service'
AnswerD

For a rootless Podman container to persist after logout, the correct approach is to make it a systemd user service: podman generate systemd --new --name mywebcontainer creates a unit that will recreate and start the container each time the service is started, and systemctl --user enable --now container-mywebcontainer.service both enables the unit and starts it immediately. This places the container under the user's systemd manager rather than under the login session's process tree. To survive logout entirely, the user must also have lingering enabled (loginctl enable-linger <user>) so that the systemd user instance persists after the last session closes. This is the only option that actually ties the container to systemd and provides session-independent lifecycle management.

Why this answer

Even with lingering enabled, a container started directly via `podman run` is tied to the user's login session and will be terminated when the session ends. To make the container persist independently of the SSH session, it must be managed as a systemd user service. The `podman generate systemd --new` command creates a systemd unit file that can be enabled with `systemctl --user`, ensuring the container starts automatically and continues running after logout.

Exam trap

The trap here is that candidates confuse `--detach` or `-d` with making a container persistent, when in fact those flags only detach the container from the terminal, not from the user's login session; the container still stops when the session ends unless it is managed by systemd.

How to eliminate wrong answers

Option A is wrong because `--restart=always` is a Docker flag, not a Podman flag; Podman uses `--restart` with policies like `always` or `on-failure`, but even if used, it only restarts the container if it exits, not if the user session ends. Option B is wrong because `--detach` (or `-d`) runs the container in the background but still ties it to the user's login session; when the SSH session ends, the container is killed because it is a child of the shell session. Option C is wrong for the same reason as Option B: `-d` is synonymous with `--detach` and does not decouple the container from the user's login session; it only detaches the container from the terminal, not from the session lifecycle.

283
MCQhard

A system has a logical volume that is thinly provisioned. The thin pool has a size of 100GB and the thin volume has a virtual size of 500GB. The administrator notices that the thin pool has only 5GB of data written so far. Which command will display the current data usage of the thin volume?

A.df -h /dev/mapper/vg01-thinvol
B.lsblk /dev/mapper/vg01-thinvol
C.lvdisplay /dev/vg01/thinvol
D.lvs -o lv_name,data_percent
AnswerD

The lvs command with the -o lv_name,data_percent option is the direct LVM reporting mechanism for thin provisioning usage. It reads LVM metadata and displays, for each specified logical volume, its name and the percentage of the underlying thin pool's data area that the volume's stored data has consumed. This is the standard way to monitor how much of the shared thin pool each thin volume is actually using, and unlike df, it reflects device-mapper level allocation, not filesystem-level usage.

Why this answer

The `lvs -o lv_name,data_percent` command specifically displays the percentage of the thin pool that has been consumed by the thinly provisioned logical volume. For thin volumes, the `data_percent` field reports the actual data usage relative to the thin pool's capacity, which is exactly what the administrator needs to see the current 5GB usage against the 100GB pool.

Exam trap

The trap here is that candidates confuse filesystem-level usage (shown by `df`) with thin pool-level data usage, leading them to pick `df -h` which incorrectly reports the virtual size instead of the actual consumed space.

How to eliminate wrong answers

Option A is wrong because `df -h` shows filesystem usage from the perspective of the mounted filesystem, not the thin pool's data usage; it would report the virtual size (500GB) as the total capacity, not the actual 5GB of data written. Option B is wrong because `lsblk` displays block device attributes like size, type, and mount point, but it does not provide thin pool-specific metrics such as data percentage or actual consumption. Option C is wrong because `lvdisplay` shows general logical volume properties (e.g., size, status) but does not include the `data_percent` field; that field is only available via `lvs` with specific output columns.

284
MCQeasy

An administrator wants to gracefully terminate a process with PID 12345. Which command should be used?

A.kill -STOP 12345
B.kill -9 12345
C.kill -KILL 12345
D.kill -TERM 12345
AnswerD

Using -TERM sends SIGTERM, the default signal from kill, which politely asks the process to exit. Because SIGTERM can be caught and handled, a well-behaved process can flush buffers, close files, release resources, and perform other cleanup before its standard action (termination) completes. That makes it the canonical signal for graceful termination in an administrative context.

Why this answer

`kill -TERM` (or `kill -15`) sends the SIGTERM signal, which requests a process to terminate gracefully. This allows the process to perform cleanup tasks (e.g., closing files, releasing resources) before exiting, making it the standard way to stop a process politely.

Exam trap

Red Hat often tests the distinction between signals that allow graceful termination (SIGTERM) versus those that force immediate termination (SIGKILL), and candidates frequently confuse `kill -9` as the 'standard' way to stop a process, missing the 'graceful' requirement in the question.

How to eliminate wrong answers

Option A is wrong because `kill -STOP` sends SIGSTOP, which pauses (suspends) the process rather than terminating it; the process remains in a stopped state and can be resumed with SIGCONT. Option B is wrong because `kill -9` sends SIGKILL, which forcefully terminates the process without allowing any cleanup, which is not graceful. Option C is wrong because `kill -KILL` is equivalent to `kill -9` (SIGKILL), which also forcefully kills the process and does not permit graceful shutdown.

285
Multi-Selectmedium

Which command can be used to create a logical volume using all available free space in a volume group?

Select 1 answer
A.lvcreate --size 20G vgdata lvdata
B.lvcreate -l 100%FREE -n lvdata vgdata
C.lvcreate -L 20G -n lvdata vgdata
D.lvcreate -l 100%VG -n lvdata vgdata
E.lvcreate -L 100%FREE -n lvdata vgdata
AnswersB

The -l flag accepts percentage-based allocation, and 100%FREE specifically targets only the unallocated physical extents in the volume group, so the resulting LV consumes all remaining free space. In contrast to a fixed-size command, this scales automatically as the VG's free space changes. It is the canonical way to create an LV spanning the full free capacity without requiring the administrator to calculate extent counts.

Why this answer

The `-l 100%FREE` flag allocates all unallocated physical extents in the volume group, which is the precise way to use all available free space. Option D (`-l 100%VG`) is incorrect because it attempts to allocate 100% of the volume group's extents, including those already used by other logical volumes, causing the command to fail if any extents are already allocated. Therefore, only option B is correct.

Exam trap

Red Hat often tests the distinction between `-l` (extents/percentage) and `-L` (fixed size) flags, and candidates mistakenly use `-L 100%FREE` thinking it works like the `-l` percentage syntax.

286
MCQhard

A system administrator tries to mount a filesystem but receives the error: 'mount: /dev/sdb1 is already mounted or /data busy'. The filesystem is not listed in the mount output. What is the most likely cause?

A.The kernel does not have the filesystem driver loaded
B.The mount point /data is in use by a process
C.The device is already mounted on another mount point
D.The filesystem is corrupted
AnswerB

The kernel refuses to mount over a directory that is currently being used as a process's current working directory or that has open file descriptors referencing it. Mounting would hide the existing directory contents, creating a security and consistency risk, so the kernel returns a 'mount point is busy' (EBUSY) error. This matches the administrator's symptom, making it the correct explanation.

Why this answer

The error message 'mount: /dev/sdb1 is already mounted or /data busy' indicates that the mount point /data is currently in use by a process, preventing the mount operation. Even though the filesystem is not listed in the mount output, a process may have an open file descriptor or be using /data as its current working directory, which keeps the directory busy. The 'lsof' or 'fuser' commands can be used to identify the offending process.

Exam trap

Red Hat often tests the distinction between 'device busy' (device already mounted elsewhere) and 'mount point busy' (directory in use), leading candidates to incorrectly assume the device is already mounted when the error actually points to the mount point being active.

How to eliminate wrong answers

Option A is wrong because if the kernel lacked the filesystem driver, the error would be something like 'mount: unknown filesystem type' or 'mount: /dev/sdb1: can't read superblock', not a 'busy' message. Option C is wrong because if the device were already mounted on another mount point, it would appear in the mount output (e.g., via 'mount' or 'findmnt'), and the error would typically say 'device is busy' or 'already mounted', but the specific mention of '/data busy' points to the mount point, not the device. Option D is wrong because a corrupted filesystem would produce errors like 'mount: /dev/sdb1: can't read superblock' or 'mount: wrong fs type, bad option, bad superblock', not a 'busy' condition.

287
Multi-Selecthard

Which TWO commands are valid for resizing an XFS file system? (Choose exactly two.)

Select 2 answers
A.xfs_admin -L /mnt
B.xfs_growfs /mnt
C.resize2fs /dev/sda1
D.xfs_growfs -D 10g /mnt
E.xfs_repair /dev/sda1
AnswersB, D

xfs_growfs is the standard tool for resizing an XFS filesystem, and running it with a mount point grows the filesystem to occupy all available space in the underlying device or logical volume. This command works online—meaning the filesystem can remain mounted and in use during the operation—which is a key advantage in production environments. Therefore, xfs_growfs /mnt is a valid and correct answer for resizing an XFS filesystem.

Why this answer

`xfs_growfs` is the dedicated command for resizing (growing) an XFS file system while it is mounted. It expands the file system to fill the available space in the underlying device or logical volume, making it the primary tool for XFS resizing operations.

Exam trap

Red Hat often tests the distinction between file system-specific tools, so the trap here is that candidates confuse `resize2fs` (for ext4) with `xfs_growfs` (for XFS), or mistakenly think `xfs_admin` can resize the file system when it only manages labels and UUIDs.

288
MCQeasy

A company needs to create a user account for a temporary contractor who will work for exactly 90 days. The account must be automatically disabled after 90 days. Which command should the administrator use?

A.useradd -f 90 contractor
B.useradd -e $(date -d '+90 days' +%Y-%m-%d) contractor
C.useradd -e 90 contractor
D.useradd -f 90 -e 0 contractor
AnswerB

Correct. The -e option specifies an account expiration date in YYYY-MM-DD format. Using $(date -d '+90 days' +%Y-%m-%d) dynamically calculates the date 90 days from today, ensuring the account is disabled after exactly 90 days.

Why this answer

The `-e` (expiration date) option sets the date on which the user account will be disabled. Using `$(date -d '+90 days' +%Y-%m-%d)` dynamically calculates the exact date 90 days from today in YYYY-MM-DD format, which meets the requirement for automatic disable after exactly 90 days.

Exam trap

The trap here is confusing the `-e` (account expiration date) option with a number of days, when it actually requires a specific date in YYYY-MM-DD format, and confusing `-f` (inactive days after password expiry) with account expiration.

How to eliminate wrong answers

Option A is wrong because the `-f` option sets the number of days after a password expires until the account is permanently disabled (inactive), not the account expiration date itself; it does not disable the account after 90 days from creation. Option C is wrong because the `-e` option expects a date in YYYY-MM-DD format, not a number of days; passing `90` will be interpreted as an invalid date and the account will not be set to expire. Option D is wrong because `-f 90` sets the inactivity period to 90 days after password expiry, and `-e 0` sets the account expiration date to January 1, 1970 (epoch), which disables the account immediately, not after 90 days.

289
MCQmedium

A Red Hat Enterprise Linux 9 server has an LVM volume group 'vg01' that contains two physical volumes: /dev/sda2 and /dev/sdb1. After a reboot, the system fails to activate the volume group. The administrator runs 'pvdisplay' and sees one physical volume as 'unknown device'. What is the most likely cause?

A.The physical volume is corrupted and needs to be restored from backup
B.The LVM filter in /etc/lvm/lvm.conf is excluding /dev/sdb1
C.The filesystem on the logical volume has become corrupted, preventing LVM metadata access
D.The UUID of the physical volume has changed due to a disk replacement
AnswerB

The LVM filter in /etc/lvm/lvm.conf controls which block devices LVM scans when looking for physical volumes. A negative entry such as filter = ['r|/dev/sdb1|'] tells LVM to reject that device entirely, so its PV metadata is never read and the VG sees the missing PV as an 'unknown device.' Removing the rejection or using a positive filter that accepts /dev/sdb1 and running pvscan/vgscan restores visibility.

Why this answer

The LVM filter in /etc/lvm/lvm.conf controls which devices LVM scans during activation. If the filter excludes /dev/sdb1, LVM will not recognize that physical volume, causing the volume group to fail activation. The 'unknown device' status indicates LVM cannot access the device metadata, not that the device is missing or corrupted.

Exam trap

The trap here is that candidates often assume 'unknown device' means hardware failure or corruption, when in reality it is usually a configuration issue like an incorrect LVM filter or missing device-mapper entries.

How to eliminate wrong answers

Option A is wrong because a corrupted physical volume would typically show I/O errors or fail to read metadata, not appear as 'unknown device' — LVM would still detect the device but report corruption. Option C is wrong because filesystem corruption on the logical volume does not prevent LVM from accessing the physical volume metadata; LVM activation occurs at the block level, independent of the filesystem. Option D is wrong because a UUID change due to disk replacement would cause LVM to see a new device with a different UUID, not mark the existing device as 'unknown' — the 'unknown device' label means LVM cannot read the device at all, not that the UUID mismatches.

290
MCQeasy

A junior administrator is tasked with setting up SELinux contexts on a Red Hat Enterprise Linux 9 server to allow Apache HTTPD to read and write to a custom directory /var/www/customcontent. The directory already exists and contains several files. The administrator has confirmed that the httpd service is running and SELinux is in enforcing mode. After changing the context to httpd_sys_content_t using chcon, the web server can read files but cannot write to the directory. The administrator needs to fix this without disabling SELinux or changing the mode to permissive. Which of the following is the correct next step?

A.Set the SELinux boolean httpd_enable_homedirs to on using setsebool.
B.Run restorecon -R -v /var/www/customcontent after setting the default context with semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/customcontent(/.*)?'
C.Change the context to httpd_sys_content_t using chcon -R -t httpd_sys_content_t /var/www/customcontent
D.Run semanage fcontext -a -t httpd_sys_rw_content_t '/var/www/customcontent(/.*)?' without running restorecon.
AnswerB

The correct approach uses semanage fcontext to add a persistent default rule that maps /var/www/customcontent and its contents to the httpd_sys_rw_content_t type. Running restorecon -R -v then applies that rule immediately, relabeling existing files to match the policy. The -R flag ensures recursive relabeling and -v shows which files are being relabeled. This combination establishes the writable SELinux type persistently, so future files created in that directory inherit the correct context.

Why this answer

The directory already has the httpd_sys_content_t type, which allows reading but not writing. To enable write access, the correct type is httpd_sys_rw_content_t. Option B correctly uses semanage fcontext to set the default context to this type and then runs restorecon to apply it persistently, ensuring Apache can both read and write.

Exam trap

The trap here is that candidates may think setting the context with chcon or semanage alone is sufficient, but they overlook the need to run restorecon to apply the new default context to existing files, or they confuse httpd_sys_content_t (read-only) with httpd_sys_rw_content_t (read-write).

How to eliminate wrong answers

Option A is wrong because the httpd_enable_homedirs boolean controls access to user home directories, not to /var/www/customcontent, and does not grant write permissions to custom content directories. Option C is wrong because it sets the context to httpd_sys_content_t, which is read-only; the administrator already confirmed this type allows reading but not writing, so repeating the same action does not fix the write issue. Option D is wrong because running semanage fcontext without restorecon only sets the default context in the policy but does not apply it to the existing files and directories; the files retain their current context, so write access is not granted.

291
Multi-Selecthard

Which TWO of the following are required steps when migrating a logical volume from one physical volume to another in the same volume group?

Select 2 answers
A.Delete and recreate the logical volume on the new physical volume
B.Add the new physical volume to the volume group with vgextend if not already present
C.Remove the source physical volume from the volume group with vgreduce after migration
D.Use pvmove to relocate the physical extents from the source to the target PV
E.Extend the logical volume to include the new physical volume
AnswersC, D

After pvmove has successfully relocated all allocated physical extents off the source PV, that PV becomes empty and can be removed from the volume group with vgreduce. This step is essential to shrink the VG's member list and to permanently detach the old physical volume without affecting logical volumes that now reside elsewhere. Without vgreduce, the empty PV would remain part of the VG, preventing its physical removal from the system.

Why this answer

After using pvmove to relocate all physical extents from the source physical volume to the target, you must remove the source PV from the volume group using vgreduce to clean up the volume group metadata and free the device for other use. This step ensures the volume group no longer references the now-empty source PV.

Exam trap

Red Hat often tests the misconception that you must extend the logical volume (Option E) or delete/recreate it (Option A) to move data between PVs, when in fact pvmove handles the migration transparently without LV modification.

292
MCQhard

After being added to a new supplementary group with usermod -aG, a user logs out and back in but still cannot access files owned by that group. Which command should the user run to verify current effective group membership?

A.newgrp -c 'groups'
B.id
C.groups $(whoami)
D.usermod -g
AnswerB

The `id` command with no arguments reads the kernel's credential data for the current process via getgroups(), displaying the real UID, effective UID, all supplementary GIDs, and, where available, SELinux context. Because it reports actual process credentials rather than performing a database lookup, it is the definitive way to verify which groups your current shell truly belongs to after a group change.

Why this answer

The `id` command displays the real and effective user/group IDs and all supplementary groups for the current process, making it the correct way to confirm whether the new group is actually active in the current shell. `groups $(whoami)` is incorrect because it uses the username argument, which reads the group membership from the user database (e.g., getgrouplist) and does not necessarily reflect the groups in the current process. This can misleadingly show the new group even if the current shell has not inherited it. `newgrp -c 'groups'` is not standard and is meant for changing the real group ID, not for displaying groups. `usermod -g` modifies group settings and requires superuser privileges, so it does not verify membership.

Exam trap

After `usermod -aG`, the new group is only active in new login sessions. To verify if the current shell actually has the group, use `id` (no arguments). Do not use `groups $(whoami)`, because that checks the user's group list from /etc/group and may show the new group even if the current process does not have it.

How to eliminate wrong answers

Option A is wrong because `newgrp -c 'groups'` is not a valid syntax; `newgrp` is used to start a new shell with a different primary group, not to list groups, and the `-c` option is not supported in that way. Option C is wrong because `groups $(whoami)` runs the `groups` command for the username returned by `whoami`, which may reflect the user's group membership from the user database but does not necessarily show the effective groups of the current shell session if the session was started before the group change. Option D is wrong because `usermod -g` is used to change a user's primary group, not to verify current group membership; it requires root privileges and modifies the user database, not the running session.

293
MCQeasy

To allow a user to run a specific program with root privileges without providing the root password, which configuration file should be modified?

A./etc/passwd
B./etc/security/limits.conf
C./etc/sudoers
D./etc/sysconfig/sshd
AnswerC

The /etc/sudoers file is the central configuration for the sudo utility, which permits designated users to execute commands as root or another user. Rules use a syntax like "user host=(runas) commands" and can be tailored to allow a specific binary without granting a general root shell. This file must always be edited with the visudo command to prevent syntax errors that could break sudo, and it supports including drop-in files from /etc/sudoers.d.

Why this answer

The /etc/sudoers file is the correct configuration file to modify because it controls the sudo command, which allows specified users to execute programs with root privileges. By adding an entry such as `username ALL=(ALL) NOPASSWD: /path/to/program`, the user can run that specific program without being prompted for a password. This is the standard mechanism in Red Hat Enterprise Linux for granting passwordless privilege escalation.

Exam trap

Candidates often mistakenly think that modifying /etc/passwd or /etc/security/limits.conf can grant root privileges, but only /etc/sudoers controls passwordless sudo access for specific programs.

How to eliminate wrong answers

Option A is wrong because /etc/passwd stores user account information (UID, GID, home directory, shell) and does not control privilege escalation or passwordless execution. Option B is wrong because /etc/security/limits.conf sets resource limits (e.g., file size, number of processes) for users and does not manage sudo or root access. Option D is wrong because /etc/sysconfig/sshd contains configuration for the SSH daemon (e.g., port, protocol versions) and has no role in granting root privileges to run programs.

294
MCQhard

The administrator attempts to run 'xfs_growfs /dev/vg00/lvol1' but receives an error. What is the most likely cause?

A.The file system is not XFS
B.Unmet dependencies
C.The volume group is full
D.The logical volume is not mounted
AnswerD

xfs_growfs requires the target XFS filesystem to be mounted because it performs an online growth operation, reading the current geometry via the mounted filesystem and updating the superblock without unmounting. The lvs attributes for lvol1 lack the 'o' flag (open), which indicates that the logical volume is not currently open/mounted. Since xfs_growfs is invoked on a device that is not mounted, it cannot determine the filesystem's mountpoint and returns an error indicating the filesystem is not mounted. Mounting the LV first and then re-running xfs_growfs with the mountpoint or device would resolve the issue.

Why this answer

The `xfs_growfs` command requires the XFS filesystem to be mounted in order to resize it. If the logical volume `/dev/vg00/lvol1` is not mounted, the kernel cannot access the filesystem's superblock and allocation group information, causing the command to fail with an error such as 'XFS filesystem not mounted' or 'No such file or directory'.

Exam trap

The trap here is that candidates often assume `xfs_growfs` works like `resize2fs` for ext4, which can resize unmounted filesystems, but XFS requires the filesystem to be mounted for online growth, and the error message may be misinterpreted as a missing package or wrong filesystem type.

How to eliminate wrong answers

Option A is wrong because the command `xfs_growfs` is specifically designed for XFS filesystems; if the filesystem were not XFS, the error would typically be 'wrong fs type' or the command would not be found, but the question states the command runs and receives an error, implying the filesystem is XFS. Option B is wrong because `xfs_growfs` is a standalone utility from the `xfsprogs` package and does not have runtime dependencies that would cause a failure during execution; unmet dependencies would prevent installation, not command execution. Option C is wrong because a full volume group would prevent extending the logical volume, but `xfs_growfs` only resizes the filesystem to match the already-extended logical volume; the error occurs before any resize attempt, and the volume group's free space is irrelevant if the logical volume itself is not mounted.

295
MCQeasy

Which command creates a 2GB logical volume named 'lvdata' in the volume group 'vgdata'?

A.lvcreate -L 2G -n lvdata vgdata
B.lvcreate -n vgdata -L 2G lvdata
C.lvcreate -n lvdata -s 2G vgdata
D.lvcreate -l 2G -n lvdata vgdata
AnswerA

This is the correct invocation. The -L 2G option explicitly sets the logical volume's size to 2 gigabytes, -n lvdata assigns the logical volume name, and vgdata is the volume group from which the space is allocated. The syntax matches lvcreate(8): lvcreate [options] volume_group.

Why this answer

The `lvcreate` command with `-L 2G` specifies the size in gigabytes, `-n lvdata` sets the logical volume name, and `vgdata` is the volume group in which the logical volume is created. This syntax follows the standard LVM2 command structure for creating a logical volume of a specified size within an existing volume group.

Exam trap

The trap here is confusing the `-L` (size in units) and `-l` (number of extents) flags, leading candidates to incorrectly use `-l` with a size suffix, which is syntactically invalid in LVM2.

How to eliminate wrong answers

Option B is wrong because the arguments are reversed: `-n vgdata` incorrectly assigns the volume group name as the logical volume name, and `lvdata` is placed as the volume group argument, which would cause a syntax error or create a logical volume in the wrong context. Option C is wrong because `-s 2G` is used for creating a snapshot (`-s` flag) or specifying a size in a different context, not for creating a standard logical volume with a size of 2GB; the correct flag for size is `-L`. Option D is wrong because `-l 2G` uses the lowercase `-l` flag, which expects extents (number of logical extents), not a size in gigabytes; using `-l` with a unit like `G` is invalid and would result in an error.

296
MCQeasy

Which single command shows the UUID of a filesystem on /dev/sdb1?

A.df -h
B.mount
C.blkid /dev/sdb1
D.fdisk -l
AnswerC

blkid is the util-linux utility that directly reads the superblock of a block device to display its UUID, filesystem type, and label. Running blkid /dev/sdb1 causes it to inspect that specific partition and print the filesystem UUID, making it the only command here that accomplishes the task. This works whether or not /dev/sdb1 is mounted, because blkid queries the raw device metadata.

Why this answer

The `blkid /dev/sdb1` command queries the libblkid library to read the filesystem metadata directly from the block device, displaying attributes including the UUID (Universally Unique Identifier) stored in the superblock. This is the standard, single-purpose command to retrieve the UUID of a specific partition.

Exam trap

The trap here is that candidates often confuse partition table tools like `fdisk` with filesystem metadata tools, or assume `mount` shows UUIDs by default, when in fact only `blkid` (or `lsblk -f`) directly queries the filesystem superblock for the UUID.

How to eliminate wrong answers

Option A is wrong because `df -h` shows human-readable disk space usage for mounted filesystems, not UUIDs. Option B is wrong because `mount` (without options) lists currently mounted filesystems and their mount points, but does not display UUIDs unless combined with `-l` or `-U` flags, and even then it is not the direct command for UUID retrieval. Option D is wrong because `fdisk -l` lists partition tables (sizes, types, start/end sectors) but does not show filesystem UUIDs, which are stored in the filesystem superblock, not the partition table.

297
MCQhard

After adding the last line to /etc/fstab, the system fails to boot with an error. What is the most likely cause?

A.The UUID for /boot is invalid
B.The mount point /mydata does not exist
C.The device /dev/sdb1 is not formatted
D.The filesystem type ext4 is incorrect for /dev/sdb1
AnswerB

The scenario explicitly states that /mydata does not exist, and systemd requires the mount point directory to be present before mounting any filesystem defined in /etc/fstab. For each fstab entry, systemd generates a mount unit that will fail if the target directory is absent, reporting an error like "mount: mount point /mydata does not exist." Because this directory is missing, the mount unit for /mydata fails, causing the boot to enter emergency mode. The solution is to create the directory with mkdir -p /mydata and then run mount -a to verify.

Why this answer

When a mount point directory specified in /etc/fstab does not exist, the systemd mount unit will fail during boot because the mount operation cannot find the target directory. This is a common misconfiguration: the fstab entry references /mydata, but the directory has not been created with mkdir. The boot process halts with an error indicating the mount point is missing, not that the device or filesystem is invalid.

Exam trap

The trap here is that candidates often focus on device or filesystem issues (UUID, formatting, type) and overlook the simple prerequisite that the mount point directory must exist, which is a fundamental step tested in the EX200.

How to eliminate wrong answers

Option A is wrong because an invalid UUID for /boot would cause a different error (e.g., 'UUID=... does not exist') and would prevent the root filesystem from mounting, not specifically a missing mount point error. Option C is wrong because an unformatted device would produce a 'wrong fs type, bad option, bad superblock' error, not a 'mount point does not exist' error. Option D is wrong because an incorrect filesystem type (e.g., ext4 on an XFS partition) would also yield a 'wrong fs type' error, not a missing directory error.

298
Multi-Selecteasy

Which TWO options to podman run can be used to persist data outside the container? (Select exactly two.)

Select 2 answers
A.--mount
B.--read-only
C.--tmpfs
D.-v
E.--squash
AnswersA, D

--mount is a structured key=value flag, e.g., --mount type=bind,source=/data,target=/var/lib/data or type=volume,source=myvol,target=/var/lib/data. Unlike -v, it explicitly exposes the mount type and cleanly separates source and destination syntax. Because the mount points to a named volume or a host directory outside the container's writable layer, data is written to external storage and survives container deletion or re-creation.

Why this answer

The `--mount` option (A) and `-v` (D) are both used to mount host directories or volumes into a container, allowing data to persist outside the container's writable layer. `--mount` provides a more explicit syntax for specifying mount type, source, and destination, while `-v` is a shorter alias for `--volume` that also binds host paths or named volumes. Both ensure data survives container removal.

Exam trap

Red Hat often tests the distinction between ephemeral storage options like `--tmpfs` and persistent storage options like `--mount`/`-v`, and candidates mistakenly select `--tmpfs` thinking it persists data because it is writable, but it is memory-backed and lost on container stop.

299
Multi-Selecteasy

Which two statements about SELinux modes are correct? (Choose two.)

Select 2 answers
A.Permissive mode denies actions but does not log.
B.Permissive mode logs violations but does not deny actions.
C.Enforcing mode only logs violations but does not deny.
D.Enforcing mode logs violations and denies actions.
E.Disabled mode completely disables SELinux without requiring a reboot.
AnswersB, D

In permissive mode, SELinux policy is not enforced, so processes can perform operations that would normally be prohibited; those violations are recorded as AVC denial messages in the audit log. This behavior is intentional: it allows administrators to observe how SELinux would react without breaking functionality. Therefore, the statement correctly identifies both actions of permissive mode: logging and not denying.

Why this answer

SELinux permissive mode allows all actions but logs any violations that would have been denied in enforcing mode. Option D is correct because enforcing mode both logs violations and denies actions that violate the SELinux policy, providing full security enforcement.

Exam trap

The trap here is that candidates often confuse permissive mode with logging-only behavior, forgetting that permissive mode does not deny actions, while enforcing mode both logs and denies, and that disabling SELinux requires a reboot, not just a runtime change.

300
MCQmedium

You are the system administrator for a small company. A developer, Alice, needs to restart the web server (httpd.service) on server 'web1.example.com' without being prompted for a password. She should also be able to run any command as root on that server, but only from the server itself (not remotely). Currently, Alice can SSH into the server using her SSH key, but when she runs 'sudo systemctl restart httpd', she is prompted for her password. You have verified that Alice is in the 'wheel' group. The sudoers file currently has the line '%wheel ALL=(ALL) ALL'. You want to modify sudoers to satisfy the requirement with minimal privilege. Which action should you take?

A.Add 'alice web1.example.com=(root) NOPASSWD: ALL' to /etc/sudoers.d/alice.
B.Add 'alice web1.example.com=(root) NOPASSWD: /usr/bin/systemctl restart httpd' to /etc/sudoers.d/alice.
C.Add 'alice web1.example.com=(root) /usr/bin/systemctl restart httpd' to /etc/sudoers.d/alice.
D.Change '%wheel ALL=(ALL) ALL' to '%wheel ALL=(ALL) NOPASSWD: ALL' in /etc/sudoers.
AnswerB

This entry precisely scopes alice's sudo privilege to the exact systemctl invocation required to restart httpd, with NOPASSWD so the service can be restarted without interactive password entry. The command path /usr/bin/systemctl is verified as a literal command; arguments are permitted as given. This meets the stated requirement of minimal access while allowing the action.

Why this answer

It grants Alice passwordless sudo access specifically to the command `/usr/bin/systemctl restart httpd` on the host `web1.example.com` as root, meeting the requirement with minimal privilege. The `NOPASSWD:` tag is essential to bypass the password prompt, and the host restriction ensures the rule applies only when Alice is on that server.

Exam trap

The trap here is that candidates often forget the `NOPASSWD:` tag when the requirement explicitly says 'without being prompted for a password', leading them to choose Option C, which grants the command but still requires authentication.

How to eliminate wrong answers

Option A is wrong because it grants Alice passwordless sudo access to ALL commands as root on web1.example.com, which exceeds the minimal privilege requirement (she only needs to restart httpd). Option C is wrong because it lacks the `NOPASSWD:` tag, so Alice would still be prompted for a password when running the command. Option D is wrong because it modifies the wheel group rule to allow all wheel members passwordless sudo for all commands, which is excessive and violates the principle of least privilege.

Page 3

Page 4 of 6

Page 5

All pages