sysctl — Read and set kernel parameters — persist them in /etc/sysctl.d/. `sysctl -w net.ipv4.ip_forward=1` changes it now; a file in /etc/sysctl.d/ plus `sysctl --system` makes it survive reboots. Docs
systemctl — Start, stop, enable and inspect systemd services. `systemctl enable --now nginx`, `systemctl status`, `systemctl daemon-reload` after editing unit files. Docs
cron — Recurring jobs: crontab -e with minute hour day-of-month month day-of-week. `30 2 * * 1 /usr/local/bin/backup.sh` = 02:30 every Monday. systemd timers and `at` (one-off) are the alternatives. Docs
dnf / apt — Install, update, verify packages and manage repositories. `dnf install`, `dnf provides`, `rpm -V` to verify; `apt install`, `apt-cache policy`, repos in /etc/apt/sources.list.d/. Docs
ps & kill — Find processes and send them signals (TERM, KILL, HUP). `ps aux --sort=-%mem | head`, `pgrep -a nginx`, `kill -15 <pid>`; `nice`/`renice` adjust priority. Docs
SELinux — Mandatory access control: contexts, booleans, enforcing/permissive. `getenforce`, `ls -Z`, `semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?"` + `restorecon -Rv /web`, `setsebool -P`. Denials land in the audit log. Docs
podman / docker — Run and manage containers: run, ps, logs, port mappings, restart policies. `podman run -d --name web -p 8080:80 nginx`; a Quadlet `.container` unit in /etc/containers/systemd/ keeps it running after reboot (`podman generate systemd` is deprecated). Docs
IPv4/IPv6, time sync, troubleshooting, OpenSSH, packet filtering and NAT, routes, bridges and bonds
nmcli — NetworkManager CLI: IPv4/IPv6 addresses, gateways, DNS, bonds and bridges. `nmcli con mod eth0 ipv4.addresses 10.0.0.5/24 ipv4.method manual` then `nmcli con up eth0`. Netplan does this on Ubuntu. Docs
ip route — Show and add routes; persist them in the connection profile. `ip route add 192.168.50.0/24 via 10.0.0.1`; persistent via `nmcli con mod … +ipv4.routes`. Docs
ss — Which sockets are listening, and which process owns them. `ss -tulpn` — the first step when a service "isn’t reachable". Pair with ping, dig, traceroute and curl. Docs
sshd_config — OpenSSH server settings: PermitRootLogin, PasswordAuthentication, Port. Edit /etc/ssh/sshd_config (or a drop-in), test with `sshd -t`, reload sshd. Client defaults live in ~/.ssh/config. Docs
firewalld / nftables — Packet filtering, port forwarding and NAT (masquerade). `firewall-cmd --add-service=http --permanent && firewall-cmd --reload`, `--add-forward-port`, `--add-masquerade`; ufw on Ubuntu. Docs
chrony — Synchronize system time with NTP servers. Servers/pools in /etc/chrony.conf; `chronyc sources -v` and `timedatectl` to verify. Docs
Reverse proxy — nginx proxy_pass / upstream blocks for proxying and load balancing. An upstream with several servers balances round-robin by default; HAProxy is the other common choice. Docs
LVM — pvcreate → vgcreate → lvcreate, and lvextend -r to grow online. Physical volumes form a volume group; logical volumes are carved from it and can be resized. `lvextend -r` grows the filesystem too. Docs
mkfs & fsck — Create (mkfs.xfs, mkfs.ext4) and check/repair filesystems. Repair unmounted: `fsck` for ext4, `xfs_repair` for XFS. `blkid` shows UUIDs for fstab. Docs
/etc/fstab — Mounts at boot: device (UUID), mount point, type, options, dump, pass. Test with `mount -a` before rebooting — a bad line can drop the system into emergency mode. Docs
NFS — Remote filesystems: /etc/exports on the server, mount -t nfs on clients. `exportfs -ra` after editing exports. NBD (network block devices) and SMB/CIFS are the other remote options. Docs
autofs — Mounts filesystems on demand when a path is accessed. Master map /etc/auto.master points at maps like /etc/auto.nfs; systemd automount units are an alternative. Docs
iostat — Per-device I/O utilization, throughput and wait times. `iostat -xz 1` — high %util and await point at a saturated disk; `iotop` shows which process. Docs
Essential Commands (20%)
Git, services, performance, constraints, disk space, SSL certificates
git — clone, add, commit, push, branch, merge, log. Basic Git operations appear on the exam: clone a repo, commit a change with a message, push it, inspect history. Docs
systemd unit files — Create a service: [Unit], [Service] ExecStart, Restart=, [Install] WantedBy=. Drop it in /etc/systemd/system/, `systemctl daemon-reload`, `enable --now`; `journalctl -u name` for its logs. `systemctl edit` creates overrides. Docs
top — Live CPU, memory, load and per-process usage. Load average vs CPU count, %wa for I/O wait. `vmstat`, `free -h` and `uptime` complement it. Docs
df & du — Free space per filesystem, and what is using it. `df -h` (and `df -i` for inodes), `du -sh /var/* | sort -h`. Deleted-but-open files still hold space: `lsof +L1`. Docs
Users and groups, environment profiles, resource limits, ACLs, LDAP
useradd — Create users; usermod -aG adds them to groups. `useradd -m -s /bin/bash -G wheel alice`, `passwd alice`, `groupadd devs`, `usermod -aG devs alice` (without -a, other groups are removed). Docs
/etc/profile.d — System-wide login environment; ~/.bashrc and ~/.bash_profile per user. Drop a script in /etc/profile.d/ to set variables for every login shell; /etc/skel seeds new home directories. Docs
limits.conf — Per-user resource limits (nproc, nofile…) via pam_limits. e.g. `alice hard nproc 100` in /etc/security/limits.conf or limits.d/; `ulimit -a` shows the current limits. Docs
setfacl — Access control lists: grant extra users/groups permissions on files. `setfacl -m u:bob:rwx /data`, default ACLs with -d for new files, `getfacl` to inspect. Docs
SSSD (LDAP) — Use LDAP users and groups for login, alongside local accounts. Configured in /etc/sssd/sssd.conf (or via authselect / realm); `getent passwd <user>` confirms the lookup works. Docs
Practice questions
Which command shows why a systemd service failed, with recent log lines?
Answer: systemctl status <unit>. journalctl -u <unit> shows the full log.
Which command shows logs for the nginx unit since the last boot?
Answer: journalctl -u nginx -b. -b limits to the current boot; -f follows.
Which target is used to boot into a multi-user system without a GUI?
Answer: multi-user.target. systemctl set-default multi-user.target makes it the default.
How do you make a kernel module load at boot?
Answer: Add its name to a file in /etc/modules-load.d/. modprobe loads it immediately; the file persists it.
Which command lists the timers managed by systemd?
Answer: systemctl list-timers. systemd timers are an alternative to cron.
Which command schedules a one-off job for 23:00 today?
Answer: at 23:00. atq lists pending jobs; atrm removes them.
Which dnf command shows which package provides /usr/bin/dig?
Answer: dnf provides /usr/bin/dig. On Debian/Ubuntu: dpkg -S for installed files, or apt-file search.
How do you verify the files of an installed RPM package against the package database?
Answer: rpm -V <package>. Changed sizes, checksums or permissions are reported.
Which command shows SELinux denials from the audit log in readable form?
Answer: ausearch -m AVC -ts recent (or sealert). Denials are logged as AVC messages.
Which command permanently allows httpd to make network connections in SELinux?
Answer: setsebool -P httpd_can_network_connect on. -P makes the boolean persistent across reboots.
How do you make a rootless Podman container start at boot with systemd?
Answer: A Quadlet .container unit (in ~/.config/containers/systemd/) plus lingering enabled for the user. loginctl enable-linger lets user services run without a login.
Which virsh command makes a VM start automatically when the host boots?
Answer: virsh autostart <vm>. virsh autostart --disable reverts it.
Which command shows IP addresses on all interfaces?
Answer: ip addr show (ip a). ip link shows interface state; ip route shows routes.
How do you set a static IPv4 address with nmcli and apply it?
Answer: nmcli con mod <con> ipv4.addresses 10.0.0.5/24 ipv4.gateway 10.0.0.1 ipv4.method manual; nmcli con up <con>. ip addr changes are lost on reboot; the connection profile persists them.
Which command sets the system hostname persistently?
Answer: hostnamectl set-hostname <name>. hostname alone changes it until reboot.
Where is local hostname resolution (before DNS) configured?
Answer: /etc/hosts (order set in /etc/nsswitch.conf). resolv.conf configures DNS servers.
Which command opens TCP port 8443 permanently in the public zone with firewalld?
Answer: firewall-cmd --permanent --zone=public --add-port=8443/tcp && firewall-cmd --reload. Without --permanent the change is lost on reload.
Which firewalld option enables NAT (masquerading) in a zone?
Answer: --add-masquerade. Combine with IP forwarding for routing.
How do you create a network bond with nmcli?
Answer: nmcli con add type bond con-name bond0 ifname bond0 mode active-backup, then add ports with type ethernet master bond0. Bridges are created similarly with type bridge.
Which command traces the network path to a host?
Answer: traceroute (or tracepath / mtr). dig +trace follows DNS delegation, not network hops.
Which command tests DNS resolution for example.com against a specific server?
Answer: dig @1.1.1.1 example.com. dig shows the full answer section.
Which sshd_config setting disables password logins?
Answer: PasswordAuthentication no. Keep key-based login working before disabling passwords.
How do you copy your public key to a server for key-based SSH login?
Answer: ssh-copy-id user@host. It appends the key to ~/.ssh/authorized_keys on the server.
Which command lists block devices with their mount points?
Answer: lsblk. lsblk -f also shows filesystems and UUIDs.
Which command creates a GPT partition table and partitions non-interactively?
Answer: parted (e.g. parted /dev/sdb mklabel gpt mkpart …). fdisk and gdisk are interactive alternatives.
After adding a new disk /dev/sdc to volume group vg0, which commands come first?
Answer: pvcreate /dev/sdc, then vgextend vg0 /dev/sdc. The disk must become a physical volume before joining the VG.
How do you grow an XFS filesystem after extending its logical volume?
Answer: xfs_growfs <mountpoint>. lvextend -r does both steps; XFS cannot be shrunk.
Which filesystem cannot be shrunk?
Answer: XFS. ext4 can be shrunk offline with resize2fs.
Which /etc/fstab option prevents boot failure if an NFS server is down?
Answer: nofail (often with _netdev). _netdev waits for the network; nofail tolerates the mount failing.
Which command mounts an NFS export from server:/srv/share at /mnt/share?
Answer: mount -t nfs server:/srv/share /mnt/share. Persist it with an fstab line or autofs.
Which command shows active swap areas?
Answer: swapon --show. It lists each swap device or file with its size, usage and priority; free -h shows totals.
How do you create and switch to a new branch called fix?
Answer: git switch -c fix (or git checkout -b fix). git branch fix only creates it.
Which command finds files larger than 100 MB under /var?
Answer: find /var -type f -size +100M. Combine with -exec ls -lh {} + to show sizes.
Which command shows a filesystem is out of inodes?
Answer: df -i. Many tiny files can exhaust inodes while space remains.
Which command shows the load average and uptime?
Answer: uptime. Load is meaningful relative to the number of CPUs.
Which openssl command shows a remote server’s certificate?
Answer: openssl s_client -connect host:443 -servername host. Pipe into openssl x509 -noout -dates to see validity.
Which openssl command creates a private key and a CSR?
Answer: openssl req -new -newkey rsa:2048 -nodes -keyout key.pem -out req.csr. Add -x509 -days N to self-sign instead of creating a CSR.
How do you limit a service’s memory with systemd?
Answer: MemoryMax= in the unit (e.g. via systemctl edit). systemd uses cgroups; LimitNOFILE= limits open files.
Which command creates a systemd override file for a unit?
Answer: systemctl edit <unit>. Overrides go in /etc/systemd/system/<unit>.d/override.conf.
Which command shows memory and swap usage in human-readable form?
Answer: free -h. available is the best estimate of memory for new processes.
Which command forces a user to change their password at next login?
Answer: chage -d 0 <user> (or passwd -e <user>). usermod -L and passwd -l lock the account instead.
Which command locks a user account?
Answer: usermod -L <user> (or passwd -l). Locking prefixes the password hash with ! so password logins fail; -U unlocks it.
Which file defines defaults for new users such as UID ranges and password ageing?
Answer: /etc/login.defs. useradd -D shows other useradd defaults.
How do you let group admins run commands as root via sudo safely?
Answer: Add a rule like "%admins ALL=(ALL) ALL" in a file under /etc/sudoers.d/ using visudo. visudo -f /etc/sudoers.d/admins validates the syntax.
Enable IPv4 forwarding now and after every reboot. Which steps?
Answer: Put net.ipv4.ip_forward = 1 in /etc/sysctl.d/, then run sysctl --system. Writing /proc changes it until reboot; files in /etc/sysctl.d/ are applied at boot.
A cron job should run at 02:30 every Monday. Which line?
Apache cannot read files in /web because of SELinux. Correct fix?
Answer: semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?" then restorecon -Rv /web. Define the context in policy and apply it; chcon changes are lost on relabel and disabling SELinux is not a fix.
Which command shows which process is listening on TCP port 443?
Answer: ss -tlnp | grep :443. ss lists sockets; -l listening, -n numeric, -p process.
Disable root login over SSH. What do you do?
Answer: Set PermitRootLogin no in sshd_config, validate with sshd -t, reload sshd. The server config controls logins; testing first avoids locking yourself out.
Forward incoming TCP 8080 to local port 80 permanently with firewalld. Which?
Answer: firewall-cmd --permanent --add-forward-port=port=8080:proto=tcp:toport=80, then --reload. Port forwarding is a firewall (NAT) rule; --permanent plus reload makes it persistent and active.
Grow logical volume /dev/vg0/data by 5 GiB along with its filesystem, online. Which command?
Answer: lvextend -r -L +5G /dev/vg0/data. -r resizes the filesystem after extending the LV (xfs_growfs or resize2fs under the hood).
You added a line to /etc/fstab. What should you do before rebooting?
Answer: Run mount -a (and check findmnt) to catch mistakes. A broken fstab entry can leave the system in emergency mode; mount -a tests it safely.
Add a 2 GiB swap file. Which sequence?
Answer: fallocate (or dd) the file, chmod 600, mkswap, swapon, and add it to fstab. A swap file needs the swap signature (mkswap), activation (swapon) and an fstab line to persist.
/var is 100% full but du finds little. What is a likely cause?
Answer: A deleted file still held open by a process — check lsof +L1 and restart it. Space is only freed when the last open handle closes.
A custom service should restart automatically if it crashes. Which unit setting?
Answer: Restart=on-failure in the [Service] section. Restart= controls automatic restarts; WantedBy decides at which target it starts on boot.
Add user alice to the group devs without removing her other groups.
Answer: usermod -aG devs alice. Without -a, -G replaces the supplementary group list.
Give user bob read/write on /data without changing its owner or group. How?
Answer: setfacl -m u:bob:rw /data. ACLs grant extra per-user permissions on top of the standard owner/group/other bits.