KubeRusted
Spinning up your cluster…

LFCS exam prep — Linux Foundation Certified System Administrator

Free LFCS (Linux Foundation Certified System Administrator) practice: the 5 official domains, exam-style questions, a timed practice exam and more.

Play the LFCS map → · Official LFCS exam page

Operations Deployment (25%)

Kernel parameters, processes and services, scheduled jobs, packages, recovery, VMs, containers, SELinux

Networking (25%)

IPv4/IPv6, time sync, troubleshooting, OpenSSH, packet filtering and NAT, routes, bridges and bonds

Storage (20%)

LVM, filesystems, remote filesystems, swap, automount, storage performance

Essential Commands (20%)

Git, services, performance, constraints, disk space, SSL certificates

Users and Groups (10%)

Users and groups, environment profiles, resource limits, ACLs, LDAP

Practice questions

Which command shows why a systemd service failed, with recent log lines?

Answer: systemctl status <unit>. journalctl -u <unit> shows the full log.

Which command shows logs for the nginx unit since the last boot?

Answer: journalctl -u nginx -b. -b limits to the current boot; -f follows.

Which target is used to boot into a multi-user system without a GUI?

Answer: multi-user.target. systemctl set-default multi-user.target makes it the default.

How do you make a kernel module load at boot?

Answer: Add its name to a file in /etc/modules-load.d/. modprobe loads it immediately; the file persists it.

Which command lists the timers managed by systemd?

Answer: systemctl list-timers. systemd timers are an alternative to cron.

Which command schedules a one-off job for 23:00 today?

Answer: at 23:00. atq lists pending jobs; atrm removes them.

Which dnf command shows which package provides /usr/bin/dig?

Answer: dnf provides /usr/bin/dig. On Debian/Ubuntu: dpkg -S for installed files, or apt-file search.

How do you verify the files of an installed RPM package against the package database?

Answer: rpm -V <package>. Changed sizes, checksums or permissions are reported.

Which command shows SELinux denials from the audit log in readable form?

Answer: ausearch -m AVC -ts recent (or sealert). Denials are logged as AVC messages.

Which command permanently allows httpd to make network connections in SELinux?

Answer: setsebool -P httpd_can_network_connect on. -P makes the boolean persistent across reboots.

How do you make a rootless Podman container start at boot with systemd?

Answer: A Quadlet .container unit (in ~/.config/containers/systemd/) plus lingering enabled for the user. loginctl enable-linger lets user services run without a login.

Which virsh command makes a VM start automatically when the host boots?

Answer: virsh autostart <vm>. virsh autostart --disable reverts it.

Which command shows IP addresses on all interfaces?

Answer: ip addr show (ip a). ip link shows interface state; ip route shows routes.

How do you set a static IPv4 address with nmcli and apply it?

Answer: nmcli con mod <con> ipv4.addresses 10.0.0.5/24 ipv4.gateway 10.0.0.1 ipv4.method manual; nmcli con up <con>. ip addr changes are lost on reboot; the connection profile persists them.

Which command sets the system hostname persistently?

Answer: hostnamectl set-hostname <name>. hostname alone changes it until reboot.

Where is local hostname resolution (before DNS) configured?

Answer: /etc/hosts (order set in /etc/nsswitch.conf). resolv.conf configures DNS servers.

Which command checks that chrony is synchronized?

Answer: chronyc tracking (and chronyc sources -v). timedatectl also shows "System clock synchronized".

Which command opens TCP port 8443 permanently in the public zone with firewalld?

Answer: firewall-cmd --permanent --zone=public --add-port=8443/tcp && firewall-cmd --reload. Without --permanent the change is lost on reload.

Which firewalld option enables NAT (masquerading) in a zone?

Answer: --add-masquerade. Combine with IP forwarding for routing.

How do you create a network bond with nmcli?

Answer: nmcli con add type bond con-name bond0 ifname bond0 mode active-backup, then add ports with type ethernet master bond0. Bridges are created similarly with type bridge.

Which command traces the network path to a host?

Answer: traceroute (or tracepath / mtr). dig +trace follows DNS delegation, not network hops.

Which command tests DNS resolution for example.com against a specific server?

Answer: dig @1.1.1.1 example.com. dig shows the full answer section.

Which sshd_config setting disables password logins?

Answer: PasswordAuthentication no. Keep key-based login working before disabling passwords.

How do you copy your public key to a server for key-based SSH login?

Answer: ssh-copy-id user@host. It appends the key to ~/.ssh/authorized_keys on the server.

Which command lists block devices with their mount points?

Answer: lsblk. lsblk -f also shows filesystems and UUIDs.

Which command creates a GPT partition table and partitions non-interactively?

Answer: parted (e.g. parted /dev/sdb mklabel gpt mkpart …). fdisk and gdisk are interactive alternatives.

After adding a new disk /dev/sdc to volume group vg0, which commands come first?

Answer: pvcreate /dev/sdc, then vgextend vg0 /dev/sdc. The disk must become a physical volume before joining the VG.

How do you grow an XFS filesystem after extending its logical volume?

Answer: xfs_growfs <mountpoint>. lvextend -r does both steps; XFS cannot be shrunk.

Which filesystem cannot be shrunk?

Answer: XFS. ext4 can be shrunk offline with resize2fs.

Which /etc/fstab option prevents boot failure if an NFS server is down?

Answer: nofail (often with _netdev). _netdev waits for the network; nofail tolerates the mount failing.

Which command mounts an NFS export from server:/srv/share at /mnt/share?

Answer: mount -t nfs server:/srv/share /mnt/share. Persist it with an fstab line or autofs.

Which command shows active swap areas?

Answer: swapon --show. It lists each swap device or file with its size, usage and priority; free -h shows totals.

Which command shows per-process disk I/O?

Answer: iotop. iostat shows per-device statistics.

Which git command shows what changed in the working tree compared to the last commit?

Answer: git diff. git diff --staged shows staged changes.

How do you create and switch to a new branch called fix?

Answer: git switch -c fix (or git checkout -b fix). git branch fix only creates it.

Which command finds files larger than 100 MB under /var?

Answer: find /var -type f -size +100M. Combine with -exec ls -lh {} + to show sizes.

Which command shows a filesystem is out of inodes?

Answer: df -i. Many tiny files can exhaust inodes while space remains.

Which command shows the load average and uptime?

Answer: uptime. Load is meaningful relative to the number of CPUs.

Which openssl command shows a remote server’s certificate?

Answer: openssl s_client -connect host:443 -servername host. Pipe into openssl x509 -noout -dates to see validity.

Which openssl command creates a private key and a CSR?

Answer: openssl req -new -newkey rsa:2048 -nodes -keyout key.pem -out req.csr. Add -x509 -days N to self-sign instead of creating a CSR.

How do you limit a service’s memory with systemd?

Answer: MemoryMax= in the unit (e.g. via systemctl edit). systemd uses cgroups; LimitNOFILE= limits open files.

Which command creates a systemd override file for a unit?

Answer: systemctl edit <unit>. Overrides go in /etc/systemd/system/<unit>.d/override.conf.

Which command shows memory and swap usage in human-readable form?

Answer: free -h. available is the best estimate of memory for new processes.

Which command forces a user to change their password at next login?

Answer: chage -d 0 <user> (or passwd -e <user>). usermod -L and passwd -l lock the account instead.

Which command locks a user account?

Answer: usermod -L <user> (or passwd -l). Locking prefixes the password hash with ! so password logins fail; -U unlocks it.

Which file defines defaults for new users such as UID ranges and password ageing?

Answer: /etc/login.defs. useradd -D shows other useradd defaults.

How do you let group admins run commands as root via sudo safely?

Answer: Add a rule like "%admins ALL=(ALL) ALL" in a file under /etc/sudoers.d/ using visudo. visudo -f /etc/sudoers.d/admins validates the syntax.

Enable IPv4 forwarding now and after every reboot. Which steps?

Answer: Put net.ipv4.ip_forward = 1 in /etc/sysctl.d/, then run sysctl --system. Writing /proc changes it until reboot; files in /etc/sysctl.d/ are applied at boot.

A cron job should run at 02:30 every Monday. Which line?

Answer: 30 2 * * 1 /usr/local/bin/backup.sh. Fields: minute hour day-of-month month day-of-week; Monday is 1.

Apache cannot read files in /web because of SELinux. Correct fix?

Answer: semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?" then restorecon -Rv /web. Define the context in policy and apply it; chcon changes are lost on relabel and disabling SELinux is not a fix.

Which command shows which process is listening on TCP port 443?

Answer: ss -tlnp | grep :443. ss lists sockets; -l listening, -n numeric, -p process.

Disable root login over SSH. What do you do?

Answer: Set PermitRootLogin no in sshd_config, validate with sshd -t, reload sshd. The server config controls logins; testing first avoids locking yourself out.

Forward incoming TCP 8080 to local port 80 permanently with firewalld. Which?

Answer: firewall-cmd --permanent --add-forward-port=port=8080:proto=tcp:toport=80, then --reload. Port forwarding is a firewall (NAT) rule; --permanent plus reload makes it persistent and active.

Grow logical volume /dev/vg0/data by 5 GiB along with its filesystem, online. Which command?

Answer: lvextend -r -L +5G /dev/vg0/data. -r resizes the filesystem after extending the LV (xfs_growfs or resize2fs under the hood).

You added a line to /etc/fstab. What should you do before rebooting?

Answer: Run mount -a (and check findmnt) to catch mistakes. A broken fstab entry can leave the system in emergency mode; mount -a tests it safely.

Add a 2 GiB swap file. Which sequence?

Answer: fallocate (or dd) the file, chmod 600, mkswap, swapon, and add it to fstab. A swap file needs the swap signature (mkswap), activation (swapon) and an fstab line to persist.

/var is 100% full but du finds little. What is a likely cause?

Answer: A deleted file still held open by a process — check lsof +L1 and restart it. Space is only freed when the last open handle closes.

A custom service should restart automatically if it crashes. Which unit setting?

Answer: Restart=on-failure in the [Service] section. Restart= controls automatic restarts; WantedBy decides at which target it starts on boot.

Add user alice to the group devs without removing her other groups.

Answer: usermod -aG devs alice. Without -a, -G replaces the supplementary group list.

Give user bob read/write on /data without changing its owner or group. How?

Answer: setfacl -m u:bob:rw /data. ACLs grant extra per-user permissions on top of the standard owner/group/other bits.