Courseiva

EX200 Create and configure file systems Practice Question

An IT department runs a web server that stores user uploads on an ext4 filesystem on /dev/sdb1 mounted at /uploads. Recently, the partition has run out of space. The administrator checks with df -h and sees 100% usage. However, du -sh /uploads shows only 2GB used. The administrator suspects deleted files still held open by processes. Which command should be used to identify and resolve the issue?

⚠ Common exam trap

Red Hat often tests the misconception that `rm` or filesystem repair tools can recover space from deleted-but-open files, when in fact only closing the file descriptor (by killing the process) releases the blocks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

lsof +L1 /uploads to find deleted open files, then kill processes

The discrepancy between `df -h` showing 100% usage and `du -sh /uploads` showing only 2GB indicates that deleted files are still held open by running processes. The `lsof +L1 /uploads` command lists files with a link count of zero (deleted but still open), and killing the associated processes releases the disk space. This is a classic scenario on ext4 filesystems where file descriptors prevent space reclamation until the process closes the file.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    rm -rf /uploads/* to clean all files

    Why it's wrong here

    Running `rm -rf /uploads/*` would delete every regular file currently present in that directory, including legitimate user uploads, causing permanent data loss. More importantly, it cannot remove or reclaim space for files that were already deleted (unlinked) but are still held open by a process, because those files no longer appear in the directory tree. This command only targets existing directory entries, so it does not address the open-deleted-file problem that is consuming disk space.

  • ✗

    fsck /dev/sdb1 to repair filesystem

    Why it's wrong here

    `fsck` checks and repairs filesystem metadata such as inodes, block bitmaps, and directory entries; it does not alter the allocation state of files that are open but unlinked. Those inodes remain marked as allocated because the kernel still references them via the open file description, so a consistency check will not free their blocks. Running fsck on a live, mounted filesystem is also unsafe and would require downtime, and even after a successful check the disk would still be full.

  • ✗

    resize2fs /dev/sdb1 to shrink filesystem

    Why it's wrong here

    Shrinking the filesystem with `resize2fs` first requires free space to move data blocks into the new, smaller footprint, but this filesystem is at 100% capacity, so the shrink operation cannot even begin. Additionally, for ext-family filesystems, the partition must be unmounted (or only read-only) before an offline shrink, which is impossible on a busy production web server. Most fundamentally, resizing does not release the space held by open deleted inodes; it merely changes the filesystem boundaries, so the underlying disk-space leak remains.

  • ✓

    lsof +L1 /uploads to find deleted open files, then kill processes

    Why this is correct

    `lsof +L1 /uploads` enumerates open files whose link count is zero — exactly the deleted-but-still-in-use files that are consuming space. Once identified, you can either close the file gracefully (e.g., by restarting the application) or terminate the offending process, causing the kernel to drop the last reference and free the inode's blocks. This is the targeted, surgical remedy: it doesn't touch valid uploads and it directly releases the missing space. After the process is killed, the directory will show no trace of the file, but df will report the reclaimed capacity.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.