CompTIA Linux+ (XK0-006) flashcards
188 free flashcards. Tap a card to flip it.
LUKS Multi-User Key Management
Flip cardLUKS supports multiple key slots, allowing several independent passphrases (or keyfiles) to unlock the same encrypted volume; cryptsetup luksAddKey adds a new one without disturbing existing keys.
- LUKS1 supports 8 key slots; LUKS2 supports up to 32
- luksAddKey requires an existing valid passphrase to authorize the add
- luksRemoveKey deletes a specific passphrase/key slot
- luksDump shows slot usage and status
Memory trick: 'AddKey' = adding a spare house key to the same lock, not replacing the original.
apt list --upgradable
Flip cardAn APT command that shows which installed packages have newer versions available in configured repositories.
- Run 'apt update' first to refresh package indexes
- Does not install or modify packages
- Complementary to 'apt upgrade' which performs the update
Memory trick: List before you leap — check upgradable before upgrading
systemd Target Dependencies
Flip card`systemd` targets use `Requires=` and `After=` directives to define strong dependencies and ordering, ensuring a target is activated only after its prerequisites are met and active.
- `Requires=`: strong dependency, unit fails if required unit fails.
- `After=`: ordering, unit starts after specified units have started.
- `Wants=`: weak dependency, unit still tries to start if wanted unit fails.
Memory trick: REQUIRE and AFTER for strict dependency order.
GPG Symmetric Encryption
Flip cardGPG's -c (--symmetric) option encrypts a file using a single shared passphrase and a symmetric cipher (default AES256), suitable when no recipient key exchange is needed.
- gpg -c file encrypts using a passphrase (symmetric)
- gpg -d file.gpg decrypts using the same passphrase
- Differs from --encrypt --recipient, which uses asymmetric public/private keys
- Default cipher is AES256 unless --cipher-algo specifies otherwise
Memory trick: '-c' for 'code word' — one shared secret unlocks it for everyone who knows it.
RAID 10 (RAID 1+0)
Flip cardA nested RAID level that combines striping (RAID 0) and mirroring (RAID 1). It creates mirrored pairs of disks, and then stripes data across these mirrors. It requires a minimum of four disks and provides both performance and redundancy.
- Minimum 4 disks, must be an even number.
- Usable capacity is 50% of total raw capacity.
- Offers good performance (from striping) and excellent redundancy (from mirroring).
- Can sustain multiple disk failures, as long as they are not in the same mirrored pair.
Memory trick: RAID 10: Mirror then Stripe, Half the Space, Double the Speed.
Service Failure via journalctl
Flip cardjournalctl -u <service> -xe shows detailed logs including the exact error causing a systemd service failure, such as permission issues, missing files, or configuration errors.
- systemctl status shows high-level state (active/failed) and Result reason
- journalctl -u <service> -xe shows extended log entries with context
- Common causes: wrong file ownership/permissions, missing dependencies, bad config syntax
Memory trick: status tells you IT failed, journalctl tells you WHY
Online ext4 Logical Volume Extension
Flip cardTo grow a mounted ext4 filesystem on LVM without downtime, extend the logical volume with lvextend, then resize the filesystem with resize2fs.
- lvextend -L +10G adds 10GB to the logical volume
- resize2fs grows ext4 to fill the extended LV, and can run online
- XFS filesystems use xfs_growfs instead of resize2fs
Memory trick: lvextend then resize2fs = 'stretch the box, then stretch the contents inside'
systemd-analyze blame
Flip cardA diagnostic command that lists systemd units sorted by how long each took to start during boot.
- Helps identify slow-starting services
- Complements 'systemd-analyze' (total boot time)
- Also see 'systemd-analyze critical-chain' for dependency chains
Memory trick: Blame the slowpoke units for a slow boot.
SELinux Context Restoration
Flip cardrestorecon resets the SELinux security context of files/directories to the default defined by policy, commonly needed after copying or moving files.
- mv preserves original context; cp usually gets a new context
- restorecon -Rv is recursive and verbose
- chcon changes context manually but is not persistent across restorecon runs
- semanage fcontext defines persistent custom rules
Memory trick: Moved files carry old labels—restorecon relabels them to fit their new home.
Removing Sensitive Files from Git History
Flip cardRemoving sensitive files from Git history, especially before pushing, is crucial for security. For recent, unpushed commits, amending the commit is the simplest method. For older or pushed commits, more drastic measures like `git filter-branch` or `BFG Repo-Cleaner` are needed.
- `git rm --cached <file>` removes file from index but keeps local copy.
- `git commit --amend` rewrites the most recent commit.
- Avoid `filter-branch` unless absolutely necessary due to complexity.
Memory trick: Amend to correct, Filter to rewrite.
RPM Package Verification
Flip cardRPM verification checks the integrity of installed package files against their original metadata, detecting modifications.
- Uses 'rpm -V' or 'rpm --verify'.
- Compares file attributes like size, checksums, permissions.
- Outputs codes indicating discrepancies (e.g., S for size, M for MD5 sum).
Memory trick: RPM: Install, Update, Query, Verify.
iptables MASQUERADE (NAT)
Flip cardMASQUERADE is a NAT target used in the POSTROUTING chain to dynamically translate the source IP of outbound packets to the address of the exiting interface, commonly used for internet-sharing gateways with dynamic IPs.
- Applied in the nat table's POSTROUTING chain
- Ideal for interfaces with dynamic/DHCP-assigned IPs
- SNAT is the static-IP equivalent target
Memory trick: MASQUERADE hides internal IPs behind the gateway's public face, applied on the way OUT (POSTROUTING).
ethtool for Duplex Settings
Flip card`ethtool` is a utility used to query or control network interface card (NIC) settings, including critical parameters like speed and duplex mode, which are vital for network troubleshooting.
- Provides detailed hardware-level information about a NIC.
- Can show current speed (e.g., 1000Mb/s), duplex (Full/Half), and autonegotiation status.
- Useful for diagnosing duplex mismatch, which can severely degrade network performance.
Memory trick: Use the 'eth'tool to see 'eth'ernet settings like duplex and speed.
SELinux Modes
Flip cardSELinux operates in one of three modes controlling how policy violations are handled at runtime.
- Enforcing: blocks and logs violations
- Permissive: logs only, does not block
- Disabled: SELinux is off entirely
- setenforce changes mode temporarily; /etc/selinux/config changes it permanently
Memory trick: E-P-D: Enforce, Permit(log), Disable — like a bouncer who blocks, warns, or leaves.
fstab nofail Option
Flip cardThe nofail mount option in /etc/fstab tells systemd not to block booting if that particular filesystem entry fails to mount, useful for optional or removable devices.
- Prevents emergency mode when a device is legitimately absent
- Often paired with 'noauto' for devices mounted manually or on demand
- Contrast: default fstab behavior treats a failed mount as critical, halting boot
Memory trick: 'nofail' says: don't fail the whole boot just because one drive didn't show up.
Secure Credential Management (Python)
Flip cardSecure credential management involves methods to protect sensitive information like API keys, passwords, and tokens from being exposed in source code, version control, or insecure files. Environment variables are a common and effective method.
- Environment variables separate credentials from code.
- `os.getenv()` in Python retrieves environment variable values.
- Avoid hardcoding sensitive data directly in scripts.
Memory trick: Environment Variables Guard All Secrets.
grub2-install
Flip cardCommand that writes the GRUB2 bootloader code to a disk's boot sector (MBR) or EFI partition, required whenever a new disk lacks a bootloader.
- Different from grub2-mkconfig, which only writes the config file
- Must target the whole disk device (e.g., /dev/sda), not a partition, for BIOS systems
- Often run inside a chroot after disk restoration or recovery
Memory trick: Install puts GRUB's boots on the disk; mkconfig just writes its itinerary.
pam_pwquality Password Complexity
Flip cardpam_pwquality is a PAM module that enforces password strength rules (length, character classes) configured in /etc/security/pwquality.conf, typically invoked from /etc/pam.d/system-auth or password-auth.
- minlen sets minimum password length
- dcredit/ucredit/lcredit/ocredit control required character classes
- Configured file: /etc/security/pwquality.conf
- Invoked via 'password requisite pam_pwquality.so' in PAM stack
Memory trick: 'pwquality' = the password's quality inspector, checks length before approval.
RAID Rebuild with mdadm
Flip cardWhen a RAID member fails, mdadm --manage --add hot-adds a replacement disk, and the array automatically rebuilds redundancy using parity or mirror data from surviving members.
- Check status: mdadm --detail /dev/mdX or cat /proc/mdstat
- Add replacement: mdadm --manage /dev/mdX --add /dev/sdXN
- Monitor rebuild progress via /proc/mdstat percentage
Memory trick: Add the new puzzle piece back in — mdadm rebuilds the picture from parity.
Ansible Package & Service Management
Flip cardAnsible manages packages using the `package` module (or specific ones like `apt`, `yum`) and services using the `service` (or `systemd`) module. These are often combined in playbooks to ensure applications are both installed and running correctly.
- `package: name=pkg_name state=present` installs a package.
- `service: name=svc_name state=started` starts a service.
- `service: name=svc_name enabled=yes` ensures service starts on boot.
- Often require `become: yes` for root privileges.
Memory trick: Packages install, services then enthrall.
SGID on Directories
Flip cardWhen the Set Group ID (SGID) bit is set on a directory, any new files or subdirectories created within that directory will inherit the group ownership of the parent directory.
- Applied to directories only.
- Ensures group inheritance for new files/subdirectories.
- Set using `chmod g+s` or `chmod 2770` (example).
Memory trick: SGID on a Directory guarantees Group Inheritance.
SSH Private Key Permissions
Flip cardSSH requires private key files to be readable only by their owner (mode 600) to prevent unauthorized users from stealing key material.
- Private key files must be chmod 600
- ~/.ssh directory itself should be chmod 700
- Public keys (.pub) can safely be world-readable (644)
Memory trick: Private keys are secrets — lock them to 600, owner-only.
systemctl daemon-reload
Flip cardThe `systemctl daemon-reload` command instructs the `systemd` manager to reload all unit files from disk, incorporating any changes made since the last reload.
- Essential after modifying any `.service`, `.timer`, `.target`, etc., unit files.
- Does not stop or start any services.
- Updates `systemd`'s internal representation of unit configurations.
Memory trick: Daemon reload makes systemd see new code.
SELinux Booleans
Flip cardBooleans are runtime on/off switches that let administrators enable or disable specific SELinux policy behaviors without writing custom policy.
- getsebool -a lists all booleans
- setsebool -P makes a change persistent
- Booleans avoid the need for custom SELinux policy modules
Memory trick: Booleans are 'policy light switches' you flip with setsebool.
sudo Credential Caching (timestamp_timeout)
Flip cardsudo caches successful authentication for a configurable period (default 5 minutes) so repeated sudo commands don't require re-entering the password; controlled by timestamp_timeout in /etc/sudoers.
- Default timestamp_timeout is 5 minutes
- Value of 0 disables caching entirely
- sudo -k invalidates the cached timestamp immediately
- Negative value caches indefinitely until reboot
Memory trick: 'timestamp_timeout' = the sudo hourglass counting down before re-asking for your password.
Missing Default Route
Flip cardWithout a default route, a host can only communicate with directly connected subnets; all other traffic has no path and is discarded by the kernel.
- Check with ip route show or route -n
- Add temporarily with ip route add default via <gw> dev <iface>
- Persist via NetworkManager, netplan, or /etc/sysconfig/network-scripts depending on distro
Memory trick: No default route = no way out of town.
Ansible Service Management
Flip cardAnsible's `service` and `systemd` modules are used to manage the state (started, stopped, restarted) and boot-time enablement (enabled, disabled) of system services on target hosts. They ensure idempotent operations.
- `service` module is generic, `systemd` is specific to systemd-based systems.
- `state: started` ensures the service is running.
- `enabled: yes` ensures the service starts automatically at boot.
Memory trick: Service state and enabled, Ansible's command is nailed.
systemctl enable
Flip cardThe `systemctl enable` command is used to configure a `systemd` service to start automatically upon system boot.
- Creates symbolic links to allow `systemd` to start the service.
- Does not start the service immediately, only configures auto-start.
- Opposite of `systemctl disable`.
Memory trick: Enable the engine to always start the journey.
AppArmor Complain Mode
Flip cardA per-profile AppArmor mode that logs policy violations without enforcing restrictions, useful for testing new profiles before enforcement.
- aa-complain <profile> sets complain mode
- aa-enforce <profile> sets enforce mode
- Violations appear in /var/log/audit/audit.log or syslog
- aa-status shows which profiles are in each mode
Memory trick: 'Complain' = complain loudly (log) but don't fight (enforce).
Kernel Module Blacklisting
Flip cardA method to prevent a kernel module from auto-loading by adding a 'blacklist <module>' directive in /etc/modprobe.d/.
- Files typically named blacklist.conf or custom .conf
- May require initramfs regeneration if module loads early boot
- Does not remove the module, only prevents auto-load
Memory trick: Blacklist = bouncer at the door, keeps unwanted module out permanently
nmcli ipv4.dns
Flip cardNetworkManager command to persistently set a DNS server on a connection profile, avoiding it being overwritten by NetworkManager-managed /etc/resolv.conf.
- Manual /etc/resolv.conf edits get overwritten by NetworkManager
- 'nmcli con mod <conn> ipv4.dns <ip>' sets DNS persistently
- Requires 'nmcli con up <conn>' to apply the change
Memory trick: NetworkManager rewrites resolv.conf every boot — tell nmcli instead.
Bash `set -e` (errexit)
Flip cardA Bash shell option that causes the script to exit immediately if a command exits with a non-zero status, indicating failure.
- Also known as `set -o errexit`.
- Prevents script execution with potentially corrupted data after an error.
- Can be temporarily disabled with `set +e`.
- Important for robust scripting and CI/CD pipelines.
Memory trick: Set 'e' for Exit on Error, like a strict teacher stopping a bad performance.
Ansible `template` Module
Flip cardAn Ansible module that generates files from Jinja2 templates, enabling dynamic content based on Ansible variables, facts, and loops.
- Uses Jinja2 templating engine.
- Source template file is specified by `src` parameter.
- Destination file on the target host is specified by `dest` parameter.
- Idempotent: only updates the file if the rendered content changes.
Memory trick: Ansible has a 'template' for every file, a 'copy' for static, and 'lineinfile' for tweaks.
systemd Service Troubleshooting
Flip cardTroubleshooting systemd services involves checking their status, examining logs for execution errors, and verifying environment and dependencies.
- `systemctl status <unit>` provides a high-level overview.
- `journalctl -xeu <unit>` is critical for detailed log output from the service.
- Common issues include incorrect paths, missing dependencies, permission problems, or environment variables.
Memory trick: When a service fails, 'J'ournal into it to 'J'ust get the 'J'ist.
parted -a optimal
Flip cardparted alignment flag that creates partitions aligned to the device's optimal I/O size, improving performance on SSDs.
- Alignment options: none, cylinder, minimal, optimal
- Misalignment can cause read-modify-write penalties on SSDs
- align-check verifies alignment of existing partitions
Memory trick: Optimal alignment keeps SSD blocks lined up like soldiers.
LUKS Header Backup
Flip cardThe LUKS header stores encryption metadata and keyslots; backing it up with cryptsetup luksHeaderBackup protects against data loss if the header becomes corrupted or overwritten.
- Command: cryptsetup luksHeaderBackup <device> --header-backup-file <file>
- Restore with cryptsetup luksHeaderRestore
- Header backups should be stored securely since they can expose keyslot data to attack if a valid passphrase is later guessed
Memory trick: Header backup = saving the vault's combination dial separately from the vault.
firewalld Interface-to-Zone Binding
Flip cardfirewalld maps network interfaces to zones; runtime changes are temporary unless made with --permanent or written to NetworkManager connection profiles.
- firewall-cmd --get-active-zones shows current bindings
- --permanent requires --reload to take runtime effect
- --change-interface replaces any existing zone assignment for that interface
- Default zone applies to unassigned interfaces
Memory trick: No --permanent, no persistence — it vanishes like a runtime ghost.
DNF Repository Configuration
Flip cardDNF reads repository definitions from .repo files in /etc/yum.repos.d/, each specifying baseurl, gpgcheck, and enabled settings.
- File extension is .repo
- Equivalent APT location is /etc/apt/sources.list(.d/)
- GPG key verification is controlled by gpgcheck=1 and gpgkey= directives
Memory trick: yum.repos.d = 'the yellow pages' DNF checks to find its software stores
GPG Revocation Certificate
Flip cardA revocation certificate is a pre-generated file that lets a key owner publicly invalidate their GPG key pair if it is lost or compromised, created with gpg --gen-revoke.
- Should be generated right after key creation, not after compromise
- Stored offline/securely, separate from the private key
- Once imported and published, marks the key as revoked to others
Memory trick: Revocation cert = the emergency 'kill switch' made in advance.
RAID 5 Capacity Calculation
Flip cardRAID 5 stripes data with distributed parity equal to one disk's capacity, so usable space equals (number of disks - 1) multiplied by the size of one disk.
- Formula: usable = (n-1) × disk size
- RAID 5 tolerates failure of exactly one disk
- Requires a minimum of three disks
Memory trick: 'RAID 5 always gives back one disk to the parity gods.'
iostat -x
Flip cardCommand from the sysstat package that reports extended I/O statistics per block device, useful for diagnosing storage bottlenecks.
- %util shows how busy a device is
- await is average time for I/O requests to complete
- Requires the sysstat package to be installed
Memory trick: iostat -x = X-ray vision into disk device health.
nftables Rule Syntax
Flip cardnftables organizes rules into tables (address families) containing chains (hook points) containing rules; the base command to add a rule is 'nft add rule <family> <table> <chain> <expression>'.
- Families: ip, ip6, inet, arp, bridge, netdev
- Tables are created with 'nft add table'
- Chains need base chain type/hook/priority when created with 'nft add chain'
- Rules are added with 'nft add rule' or inserted at top with 'nft insert rule'
Memory trick: Table holds Chain holds Rule — like a filing cabinet, drawer, and folder.
Bash Conditional Test `-d`
Flip cardThe Bash `-d` test operator is used within conditional expressions (e.g., `[ ]` or `[[ ]]`) to determine if a given path refers to an existing directory.
- `-d path` returns true if `path` exists and is a directory.
- Often used with `!` for negation, e.g., `! -d path` (not a directory).
- Part of file test operators for scripting.
Memory trick: Directory's door: is it there, or is it not?
AIDE File Integrity Checking
Flip cardAIDE (Advanced Intrusion Detection Environment) creates a cryptographic baseline of file attributes and later compares the filesystem against it to detect unauthorized changes.
- aide --init builds initial database as aide.db.new.gz
- Database must be moved/renamed to aide.db.gz to activate it
- aide --check compares against active database
- Configuration lives in /etc/aide/aide.conf
Memory trick: Init sets the photo, Check compares the room to the photo.
GRUB Rescue Prompt Recovery
Flip cardThe minimal grub rescue> environment only supports basic commands like ls, set, and insmod; loading the 'normal' module restores full GRUB menu functionality.
- grub rescue> is a minimal fallback shell
- set root= points to the partition holding grub files
- insmod normal loads full GRUB functionality
- 'normal' command then invokes the full menu
Memory trick: Set the root, then go Normal to escape rescue mode
firewalld Rich Rules
Flip cardRich rules provide fine-grained firewalld syntax to combine sources, services, ports, and actions (accept/reject/drop) beyond what basic zone commands allow.
- Syntax: rule family=... source address=... service name=... accept
- Rich rules take priority over zone-wide service settings
- Must reload firewalld or use --permanent then --reload to apply
Memory trick: Rich rules are the 'fine print' firewalld uses for precise targeting.
SSH Key Generation
Flip cardssh-keygen creates public/private key pairs for SSH authentication; the -t flag selects the algorithm such as rsa, ecdsa, or ed25519.
- Default output: ~/.ssh/id_<type> and id_<type>.pub
- Ed25519 offers strong security with a compact 256-bit key
- ssh-copy-id deploys the public key to a remote authorized_keys file
- Private keys should have permissions 600
Memory trick: 'Keygen' generates, 'copy-id' delivers, 'add' remembers.
pam_faillock Account Lockout
Flip cardpam_faillock is a PAM module that locks user accounts after a configurable number of consecutive failed login attempts for a configurable duration, mitigating brute-force attacks.
- deny=N sets the failed-attempt threshold
- unlock_time=SECONDS sets automatic lockout duration (0 = permanent until admin unlock)
- Configured in /etc/security/faillock.conf or inline in PAM files
- faillock --user <name> shows and can reset a locked account
Memory trick: Five strikes, fifteen-minute penalty box — deny=5, unlock_time=900.
iostat %util
Flip cardThe '%util' column in `iostat` output indicates the percentage of time the device was busy processing I/O requests. High values (near 100%) suggest an I/O bottleneck.
- Measures disk device utilization.
- Values near 100% signify a potential I/O bottleneck.
- Part of `iostat -x` output.
Memory trick: IOSTAT's UTIL column reveals the disk's true toil.
LVM Logical Volume Extension
Flip cardTo grow a filesystem on LVM, first extend the logical volume with lvextend, then resize the filesystem itself with a tool like resize2fs (ext) or xfs_growfs (XFS).
- lvextend -L +<size> adds space to an LV
- resize2fs grows ext2/3/4 filesystems online
- xfs_growfs is used instead for XFS filesystems
Memory trick: 'Extend the pipe (lvextend), then stretch the balloon inside it (resize2fs).'
Inode Exhaustion
Flip cardEvery file consumes one inode; a filesystem can run out of inodes (many small files) even when disk block space remains available.
- Check with df -i
- IUse% 100% means no inodes remain
- Common cause: millions of tiny files (e.g., session caches, mail spools)
Memory trick: Blocks hold data, inodes hold file entries — run out of either and writes fail.
Dockerfile CMD Instruction
Flip cardThe `CMD` instruction in a Dockerfile provides the default command or parameters that are executed when a container is launched from the image. It can be easily overridden by specifying a command in the `docker run` command.
- Defines default command for container execution.
- Only one `CMD` per Dockerfile (last one wins).
- Can be overridden by `docker run <image> <command>`.
Memory trick: CMD gives the default COMMAND for the container.
Infrastructure as Code (IaC)
Flip cardInfrastructure as Code (IaC) is the practice of managing and provisioning computing infrastructure (e.g., networks, virtual machines, load balancers) using machine-readable definition files, rather than physical hardware configuration or interactive configuration tools. It applies software engineering best practices to infrastructure.
- Infrastructure definitions are codified in files (e.g., YAML, JSON).
- Enables version control, consistency, and repeatability.
- Reduces manual errors and configuration drift.
- Facilitates automation and collaboration.
Memory trick: Versioned Code Ensures Repeatable Infrastructure.
traceroute
Flip cardThe `traceroute` command displays the route and measures packet transit delays across an IP network. It identifies all intermediate routers (hops) between the source and destination.
- Uses UDP packets (or ICMP, depending on implementation/options) with increasing TTL values.
- Each hop responds with an ICMP 'Time Exceeded' message or the destination with 'Port Unreachable'.
- Shows IP addresses and often hostnames of intermediate routers, along with round-trip times.
Memory trick: To 'trace' the 'route', use `traceroute`.
Network Interface Error Statistics
Flip cardCommands like `ifconfig` or `ip -s link show` provide detailed statistics for network interfaces, including counts for errors, dropped packets, overruns, and collisions. These metrics are vital for diagnosing physical layer network problems, faulty hardware (NIC), or driver issues.
- Shows transmit/receive packet counts.
- Includes error, dropped, overrun, collision counts.
- Helps identify physical layer or NIC driver issues.
Memory trick: IP LINK SHOWs the interface's inner woes.
GPG Asymmetric Encryption
Flip cardGPG can encrypt data for a specific recipient using their imported public key; only the corresponding private key can decrypt the resulting ciphertext.
- gpg --encrypt --recipient <keyid/email> file
- Recipient's public key must be imported and trusted first
- Output is file.gpg by default
- Use --decrypt with the private key to read the file back
Memory trick: Public key locks the mailbox; only the private key opens it.
IOPS Bottleneck vs. Throughput Bottleneck
Flip cardAn IOPS bottleneck occurs when the storage system cannot handle the high number of small, random I/O operations, even if individual operations are fast. A throughput bottleneck occurs when the storage system cannot sustain the transfer rate of large, sequential data blocks.
- IOPS bottleneck: High `wa`, high IOPS, low service time. Common for databases, static web servers.
- Throughput bottleneck: High `wa`, lower IOPS, high service time. Common for large file transfers, video streaming.
- Diagnosed by combining `top`'s `wa` with `iostat`'s r/s, w/s, and await metrics.
Memory trick: IOPS vs. Throughput: If many small 'I'tems are 'O'verwhelming, it's an 'I'OPS problem.
IOPS vs. Throughput Bottleneck
Flip cardA disk can be bottlenecked by either low data throughput (low MB/s) or low I/O operations per second (IOPS). `%util` in `iostat` might be low if throughput is low, but high `r/s` or `w/s` with high `await` can still cause high CPU I/O wait ('wa' in `top`) due to many small, latent operations.
- IOPS (I/O Operations Per Second) measures frequency of I/O.
- Throughput measures data volume (MB/s).
- High IOPS with small files can cause high 'wa' even with low `%util` if `await` is high.
Memory trick: IOPS can hide, while UTIL lies, but WAITING still makes the CPU cry.
/proc/net/dev
Flip card`/proc/net/dev` is a virtual file in the `/proc` filesystem that provides real-time statistics for all network interfaces on a Linux system, including received and transmitted data.
- Contains metrics like bytes, packets, errors, dropped packets for each interface.
- Does not require specific tools; can be viewed with `cat`.
- Useful for quickly assessing network traffic and basic interface health.
Memory trick: For network `dev`ice stats, check `/proc/net/dev`.
modprobe vs insmod
Flip cardmodprobe loads a kernel module plus its dependencies using the modules.dep map, while insmod inserts a single module file with no dependency handling.
- modprobe reads /lib/modules/$(uname -r)/modules.dep
- insmod requires the full path to a .ko file
- depmod regenerates the dependency database
Memory trick: 'modprobe brings friends; insmod comes alone.'