CompTIA Linux+ (XK0-006) flashcards
188 free flashcards. Tap a card to flip it.
EFI System Partition (ESP)
Flip cardA small FAT32-formatted partition required by UEFI firmware to store bootloader files needed to start the OS.
- Typically mounted at /boot/efi
- Must be FAT32 formatted
- Stores .efi bootloader executables like grubx64.efi
Memory trick: ESP = 'Entry Step Point' UEFI reads first
Python `subprocess.run()`
Flip cardThe `subprocess.run()` function is the recommended high-level API for running external commands in Python. It waits for the command to complete and returns a `CompletedProcess` object.
- Introduced in Python 3.5; replaces `call`, `check_call`, `check_output` for most use cases.
- `capture_output=True` captures stdout and stderr.
- `text=True` (or `encoding`) decodes output to string; otherwise, it's bytes.
- Returns `CompletedProcess` object with `stdout`, `stderr`, and `returncode` attributes.
Memory trick: Run the command, capture the text, then you're all set!
journalctl for Service Failures
Flip card`journalctl -u <service_name>` is used to view logs specifically for a given systemd service unit. It's essential for diagnosing why a service failed to start, stop, or is behaving unexpectedly.
- Filters logs by systemd unit name.
- Shows stdout/stderr of the service.
- Crucial for identifying root causes of service issues.
Memory trick: Journalctl's Unit logs unveil the service's ultimate sorrow.
Docker Bind Mount
Flip cardA Docker bind mount allows a directory or file on the host machine to be mounted directly into a container, providing persistent storage that is managed by the host's filesystem.
- Uses `-v host_path:container_path` or `--mount type=bind,source=host_path,target=container_path`.
- Data persists even if the container is removed.
- Host path must exist for the bind mount to work correctly.
Memory trick: Docker needs mounts to make data last.
Docker Volumes
Flip cardDocker volumes are the recommended way to persist data in Docker. They are fully managed by Docker and stored in a part of the host filesystem (`/var/lib/docker/volumes/`) that is dedicated to Docker.
- Managed by Docker.
- Data persists beyond container lifecycle.
- More portable and secure than bind mounts for general use.
Memory trick: VOLUMES are for persistent Docker data.
firewalld Persistence
Flip cardfirewalld rules must be added with --permanent to survive reloads/reboots; firewall-cmd --reload then applies permanent rules to the active runtime configuration.
- Runtime rules are temporary, lost on reload/reboot
- --permanent writes to /etc/firewalld/zones/
- --reload merges permanent config into runtime
- firewall-cmd --list-all shows active rules for a zone
Memory trick: No --permanent, no future—rules vanish like sandcastles without the permanent seal.
rpm -V Verification Codes
Flip cardrpm -V compares installed files against the RPM database, printing a code string where each position flags a specific attribute mismatch (size, mode, checksum, etc.); a dot means no change.
- S = size differs
- M = mode (permissions) differs
- 5 = MD5/digest checksum differs (content changed)
- U/G = user/group ownership differs
Memory trick: '5' looks like a fingerprint scanner — it's checking the file's digital fingerprint (checksum).
/usr/local
Flip cardFHS directory for software compiled and installed locally by the administrator, kept separate from distro-managed packages.
- Contains its own bin, lib, share subdirectories
- Not touched by dnf/apt package upgrades
- Different from /opt, which is for vendor bundles
Memory trick: 'usr/local' = the admin's private workshop, untouched by the package manager.
OOM Killer (Out-Of-Memory Killer)
Flip cardThe OOM Killer is a Linux kernel mechanism that identifies and terminates processes when the system runs out of physical memory, aiming to prevent a complete system crash or unresponsiveness.
- Triggered when the kernel cannot allocate more memory.
- Chooses processes based on factors like memory usage, CPU time, and oom_score.
- Logs messages like 'Out of memory: Kill process...' to the system journal/logs.
Memory trick: When 'O'ut 'O'f 'M'emory, the 'OOM' Killer executes.
systemd Unit File Paths
Flip cardSystemd unit files (like services, targets, mounts) are stored in specific directories. Systemd searches these paths in a defined order to find and load unit configurations.
- Primary locations: /etc/systemd/system (for local admin overrides), /run/systemd/system (runtime generated), /usr/lib/systemd/system (for installed packages).
- Unit files must have the correct extension (e.g., .service, .target, .mount).
- After placing a new unit file, 'systemctl daemon-reload' is required for systemd to recognize it.
Memory trick: SystemD needs its files in the right place to start.
firewalld Rich Rules for Source Filtering
Flip cardfirewalld rich rules provide granular control to allow or deny traffic based on source IP, service, port, and other criteria.
- Syntax: 'rule family="ipv4|ipv6" source address="IP/CIDR" service name="svc" accept|reject|drop'.
- Used for complex policies not covered by direct service/port additions.
- Must be applied with '--permanent' for persistence and then '--reload'.
Memory trick: Firewall: Zones, Services, Ports, then Rich for complex.
Bash 'for...in' loop
Flip cardA Bash construct used to iterate over a list of items, executing a block of commands for each item in the list.
- Syntax: `for VAR in LIST; do COMMANDS; done`
- LIST is typically a space-separated string or an array.
- Commonly used for processing files, arguments, or elements of a string.
Memory trick: For every item in the list, do the task.
SSH Root Login Restriction
Flip cardPermitRootLogin controls whether the root account can authenticate directly via SSH; setting it to 'no' enforces least-privilege administration.
- Located in /etc/ssh/sshd_config
- Restart sshd after changes: systemctl restart sshd
- Values: yes, no, prohibit-password, forced-commands-only
- Best practice pairs this with sudo for privileged tasks
Memory trick: Root stays home—PermitRootLogin no locks the front door to root.
GitPython `clone_from`
Flip cardThe `git.Repo.clone_from()` method in the GitPython library is used to programmatically clone an existing remote Git repository into a new local directory.
- Takes the remote repository URL and the local path as arguments.
- Equivalent to running `git clone <remote_url> <local_path>` from the command line.
- Returns a `Repo` object representing the newly cloned repository.
Memory trick: To start a new repo, clone_from the remote to go!
GitPython Library
Flip cardA Python library that provides a high-level API for interacting with Git repositories programmatically, abstracting away the command-line Git interface.
- Allows cloning, committing, branching, tagging, and more.
- Manages repositories as `Repo` objects.
- Simplifies automation of Git workflows within Python scripts.
Memory trick: Python's Git is like a well-tended 'Python' tree, with 'GitPython' as its strongest branch.
UUID Mismatch Boot Failure
Flip cardAn incorrect or stale UUID in /etc/fstab causes systemd to fail mounting that filesystem, halting the boot process into emergency mode.
- blkid lists device UUIDs and filesystem types
- Fix fstab entry, then run systemctl daemon-reload and mount -a
- Emergency shell message references 'Dependency failed for Local File Systems'
Memory trick: Blkid before you fstab it, or the boot will grab it (emergency shell).
groupadd command
Flip cardThe `groupadd` command is used to create a new group account on a Linux system, allowing specification of a GID.
- Creates new group accounts.
- Requires root privileges.
- Option: `-g` (GID).
Memory trick: GROUPADDs a new group with a GID.
CI/CD Conditional Deployment
Flip cardThe practice of executing specific deployment steps or stages in a CI/CD pipeline only when certain conditions are met, such as the source branch or build status.
- Ensures deployments only occur from designated branches (e.g., 'main', 'release').
- Prevents accidental deployments from feature branches.
- Implemented using conditional logic (`if`, `when`) within pipeline configuration files.
Memory trick: Deploy only when conditions are right, like a rocket launching from the correct pad.
dig for DNS Isolation
Flip cardUsing dig @<server> to directly query different DNS servers helps isolate whether a resolution failure is due to the client's configured resolver or the domain/authoritative server itself.
- dig @8.8.8.8 <name> bypasses local resolv.conf and queries directly
- SERVFAIL from one server but NOERROR from another isolates the faulty server
- Check /etc/resolv.conf to see which DNS server the client normally uses
Memory trick: Two dig results, two suspects — compare them to find the guilty resolver
noexec,nosuid,nodev
Flip cardA common fstab hardening option set that disables binary execution, setuid/setgid privilege escalation, and device file access on a mount point.
- Frequently applied to /tmp and other writable partitions
- noexec blocks running programs from that filesystem
- nosuid ignores setuid/setgid bits; nodev ignores device special files
Memory trick: Lock /tmp down: no run, no super-power, no devices.
modinfo
Flip cardA command-line utility used to display information about a specific Linux kernel module. It retrieves details from the module file itself, typically located in /lib/modules/<kernel-version>/.
- Shows module filename, author, description, license, and version.
- Crucially lists module parameters and their descriptions.
- Also displays dependencies (modules required by the queried module).
Memory trick: Module Info Details Every Parameter and Dependency.
SSH AllowUsers Directive
Flip cardThe AllowUsers directive in sshd_config restricts SSH access to specified users and can include host patterns for IP-based filtering.
- Can specify user@host patterns.
- Host can be an IP address, hostname, or CIDR range.
- If specified, users not listed are denied SSH access.
Memory trick: SSH access: Who, Where, How.
iptables Default Chain Policy
Flip cardThe -P flag sets the default action (ACCEPT or DROP) applied to packets that don't match any rule in a built-in chain (INPUT, OUTPUT, FORWARD).
- iptables -P INPUT DROP sets default policy to DROP
- Only built-in chains (INPUT/OUTPUT/FORWARD) support -P
- -A appends a rule; it does not change the chain policy
- -F flushes all rules but leaves the policy unchanged
Memory trick: '-P' = the Policy gatekeeper standing at the end of the chain.
ethtool -S
Flip cardThe `ethtool -S` command is used to query or control network driver and hardware settings, specifically displaying detailed statistics for a specified network interface.
- Requires root privileges to modify settings, but not to view statistics.
- Provides granular counters for receive/transmit errors, dropped packets, collisions, etc.
- Useful for diagnosing physical layer or driver issues on a network interface.
Memory trick: Errors are 'S'erious, so use 'S'tatistics from 'eth'tool.
CI/CD for Microservices
Flip cardCI/CD for microservices emphasizes independent, automated pipelines for each service. This allows for rapid, isolated development, testing, and deployment, aligning with the modular nature of microservices architecture.
- Each microservice should have its own CI/CD pipeline.
- Pipelines should be loosely coupled to allow independent execution.
- Automation is key to achieve speed and consistency.
Memory trick: Independent pipelines for microservices mean modular success.
initramfs
Flip cardA temporary root filesystem loaded into RAM by the bootloader, containing drivers/tools needed to mount the actual root filesystem during boot.
- Built with tools like dracut or mkinitramfs
- Commonly needed for LVM, RAID, or encrypted root setups
- Handed off to the real root via 'switch_root'
Memory trick: initramfs = the 'temporary tent' pitched in RAM before the real house (root fs) is ready
GRUB2 Configuration Regeneration
Flip card/etc/default/grub holds user-editable settings that must be compiled into /boot/grub2/grub.cfg using grub2-mkconfig (or update-grub on Debian systems) before changes take effect.
- /etc/default/grub is the template file
- grub2-mkconfig -o writes the final grub.cfg
- Debian-based systems use update-grub as a wrapper
Memory trick: 'Default is just a draft, mkconfig makes it craft.'
Swap File Activation
Flip cardSequence to create and enable a swap file: allocate space, secure permissions, format as swap, then activate with swapon.
- fallocate/dd allocates file size
- chmod 600 restricts access for security
- mkswap formats the file as swap space
- swapon activates it; add to /etc/fstab for persistence
Memory trick: Allocate, lock, format, then switch ON the swap
dnf history undo
Flip carddnf history undo <id|last> reverses a specific past transaction, reinstalling removed packages and removing/downgrading updated ones to restore the prior state.
- dnf history list shows past transaction IDs
- 'last' refers to the most recent transaction
- dnf history rollback <id> reverts to a specific point, undoing multiple transactions
Memory trick: 'History undo = the package time machine's rewind button.'
Systemd ExecStart 'No such file'
Flip cardWhen a systemd service fails to start with the error `No such file or directory` for its `ExecStart` command, it means the specified executable path is invalid. The binary might be missing, misspelled, or located elsewhere than declared in the service unit file.
- Indicates executable not found.
- Check `ExecStart` path in service file.
- Verify actual file existence and path.
Memory trick: ExecStart's path must be perfectly paved.
nmcli Connection Apply
Flip cardAfter modifying a NetworkManager connection profile with 'nmcli con mod', the profile must be reactivated with 'nmcli con up' to apply changes.
- nmcli con mod edits the stored profile
- Changes are not live until reactivated
- nmcli con up <name> reactivates the connection
- nmcli con show displays but doesn't change settings
Memory trick: Modify then bring it Up to make it live
GRUB Rescue Prompt
Flip cardThe grub rescue> prompt with 'unknown filesystem' indicates GRUB cannot locate its boot partition, usually from UUID changes, disk reordering, or corrupted grub.cfg.
- Occurs before OS/kernel loads
- Fix by locating boot partition (ls, set root=) and reinstalling GRUB
- grub-install and update-grub/grub2-mkconfig regenerate configuration
Memory trick: GRUB rescue = lost map before the journey even starts
ip route show (Default Route)
Flip cardThe `ip route show` command displays the Linux kernel's routing table. It's used to verify if a default route (specified as `default via <gateway_ip> dev <interface>`) exists, which is essential for communication with hosts outside the local subnet.
- Shows the kernel's routing table.
- Identifies the default gateway for external traffic.
- Crucial for diagnosing external network connectivity issues.
Memory trick: IP ROUTE SHOWs the road out of town.
ksoftirqd CPU Usage
Flip cardHigh CPU utilization by `ksoftirqd` processes indicates that the Linux kernel is spending significant time processing 'soft interrupts'. This often points to high network activity (packet processing) or other device-related interrupt overhead, potentially bottlenecking the system.
- Handles deferred kernel interrupt processing.
- High usage often linked to network I/O or device drivers.
- Suggests a bottleneck at the interrupt handling layer.
Memory trick: KSOFTIRQD's buzz means the network's got a big fuss.
dig for DNS Resolution Testing
Flip cardThe `dig` command is a powerful tool for querying DNS name servers. Using `dig @<dns_server_ip> <hostname>` allows direct testing of a specific DNS server's ability to resolve a hostname, which is critical for diagnosing DNS-related network connectivity issues.
- Queries DNS name servers directly.
- Allows specifying a particular DNS server.
- Provides detailed DNS response information.
Memory trick: DIG it up, the DNS truth you'll find.
AppArmor Profile Modes
Flip cardAppArmor profiles can run in complain mode (log violations only) or enforce mode (actively block violations), switched using aa-complain and aa-enforce.
- aa-complain = log-only testing mode
- aa-enforce = active blocking mode
- aa-status shows current mode of all loaded profiles
Memory trick: Complain first, Enforce later — test before you gate.
journalctl Filtering
Flip cardjournalctl supports flags to filter by boot session (-b) and priority level (-p) to narrow down relevant log entries.
- -b [N] filters by boot number
- -p priority filters by severity (emerg..debug)
- -k shows only kernel ring buffer messages
- -f follows the log in real time
Memory trick: Boot + Priority = pinpoint the problem period and severity
Regex for IPv4 Address
Flip cardA regular expression for an IPv4 address typically matches four sets of one to three digits, separated by dots, ensuring word boundaries to prevent partial matches. It's important to use the correct `grep` flags for extended regex and only matching output.
- `[0-9]{1,3}` matches 1-3 digits.
- `\.` matches a literal dot.
- `\b` matches a word boundary.
- `grep -o` outputs only the matched parts.
Memory trick: Octets, dots, and boundaries, for IPs, grep's all-around.
firewalld Port Management
Flip cardfirewalld manages firewall rules using zones and services; --add-port opens a specific port, and --permanent plus --reload makes the change persistent and active.
- firewall-cmd --add-port=<port>/<proto> --permanent
- firewall-cmd --reload applies persistent changes
- firewall-cmd --list-all shows current zone configuration
Memory trick: Listening isn't enough — the firewall gatekeeper must also say yes.
PAM Management Groups
Flip cardPAM organizes rules into four management groups—auth, account, password, and session—each handling a distinct phase of the authentication and authorization process.
- auth: verifies identity/credentials
- account: checks account validity (expiration, time-of-day)
- password: manages credential updates
- session: handles setup/cleanup tasks around login
Memory trick: AAPS: Auth checks WHO you are, Account checks if you're ALLOWED, Password updates secrets, Session wraps the visit.
Git Clone Specific Branch
Flip cardTo clone a Git repository and immediately switch to a branch other than the default, use the `git clone -b <branch_name> <repository_url>` command. This streamlines the process by performing both actions in one step.
- `git clone` copies a repository.
- The `-b` or `--branch` flag specifies the initial branch to check out.
- If `-b` is not used, the default branch (e.g., `main` or `master`) is checked out.
Memory trick: Clone a branch directly, like picking a specific fruit from the tree.
Load Average Interpretation
Flip cardLoad average shows the average number of processes runnable or waiting for CPU over 1, 5, and 15-minute windows; comparing it to core count reveals CPU saturation.
- Format: 1-min, 5-min, 15-min averages
- Compare value to number of CPU cores
- Rising trend (1-min higher than 15-min) = recent spike
Memory trick: 1-5-15: like watching a fever rise over time
initramfs dmesg for Boot Issues
Flip cardWhen a Linux system boots to an `(initramfs)` prompt, it often indicates a failure to locate or mount the root filesystem. Reviewing `dmesg` output from within the `initramfs` environment, especially for disk controller or filesystem-related errors, is a critical diagnostic step.
- Provides kernel boot messages.
- Crucial for diagnosing hardware detection failures.
- Helps identify missing storage drivers or corrupted filesystems.
Memory trick: DMESG reveals the kernel's disk dilemmas.
DROP vs REJECT (Firewall Actions)
Flip cardDROP silently discards packets with no response, while REJECT actively replies to the sender (e.g., TCP RST or ICMP unreachable), informing them the connection was refused rather than lost.
- DROP causes client-side timeouts, useful for stealthy blocking
- REJECT provides immediate negative feedback to the sender
- REJECT can leak information about firewall presence/rules
- Both are terminal actions ending rule processing for a packet
Memory trick: REJECT sends a 'no thanks' letter back; DROP just ignores the knock at the door.
/opt directory
Flip cardFHS location for optional/add-on third-party software packages, each typically in its own subdirectory.
- Each package gets /opt/<package_name>
- /var/opt holds variable data for those packages
- Differs from /usr/local, which is for locally built software
Memory trick: OPTional extras live in /opt
systemd Targets
Flip cardTargets are systemd's replacement for SysV runlevels, grouping units into a desired system state such as text-mode or graphical.
- multi-user.target ≈ old runlevel 3
- graphical.target ≈ old runlevel 5
- systemctl set-default <target> persists the choice via symlink
Memory trick: 'Multi-user is the plain office desk; graphical is the office with a TV.'
ss -tlnp
Flip cardThe `ss -tlnp` command lists all listening TCP sockets (`-t`, `-l`) in numerical format (`-n`) and shows the process (`-p`) associated with each socket. It's vital for network troubleshooting to confirm services are listening on expected ports.
- Displays listening TCP sockets.
- Shows associated process IDs and names.
- Useful for verifying network service availability.
Memory trick: SS tells if the Server is Standing and Speaking.
sudoers NOPASSWD Restriction
Flip cardThe NOPASSWD tag in /etc/sudoers (edited via visudo) can be scoped to specific commands so a user can run only that command without a password, preserving password requirements elsewhere.
- Always edit sudoers with visudo for syntax checking
- Format: user host=(runas) NOPASSWD: /path/to/command
- %groupname syntax applies rules to a group
- Scoping NOPASSWD to full paths prevents privilege escalation via PATH manipulation
Memory trick: Scope the key to one lock—NOPASSWD on one command, not the whole house.
firewall-cmd --add-port
Flip cardThe `firewall-cmd --add-port` command is used to open a specific TCP or UDP port through the `firewalld` firewall, optionally specifying a zone and making the change permanent.
- Syntax: `firewall-cmd --zone=<zone> --add-port=<port>/<protocol> --permanent`.
- Requires `--reload` to apply permanent changes immediately.
- Used when a service doesn't have a predefined `firewalld` service or for custom ports.
Memory trick: To add a 'P'ort, you need to 'P'ermanently 'P'ut it in the 'P'ublic zone and then 'R'eload.
fsck on Mounted Filesystem
Flip cardfsck should not be run on a mounted, in-use filesystem; doing so risks corruption because the kernel may write to the disk during the check.
- Root filesystem: boot to rescue/single-user mode first
- fsck displays a warning if run on a mounted filesystem
- Non-root filesystems can simply be unmounted with umount before checking
Memory trick: Never repair a car engine while it's still running
Bash Conditional Tests
Flip cardBash conditional tests are used within `if` statements or `[[ ]]` constructs to evaluate expressions and determine script flow. They check file attributes, string comparisons, or arithmetic operations.
- `-d file` checks if file exists and is a directory.
- `-w file` checks if file exists and is writable.
- `&&` performs a logical AND operation between conditions.
Memory trick: Directory Writable And Go!
useradd command
Flip cardThe `useradd` command is used to create a new user account on a Linux system, allowing specification of UID, GID, home directory, and shell.
- Creates new user accounts.
- Requires root privileges.
- Options: `-u` (UID), `-g` (primary GID), `-d` (home directory), `-s` (shell).
Memory trick: USERADDs all the details for a new user.
GPT Partition Table Creation
Flip cardGUID Partition Table (GPT) supports disks larger than 2TB and up to 128 partitions by default; created using tools like parted or gdisk.
- parted /dev/sdX mklabel gpt creates the table
- GPT stores partition info redundantly for reliability
- MBR is limited to 2TB and 4 primary partitions
Memory trick: GPT = 'Giant Partition Table' for giant disks over 2TB
/etc/shadow file
Flip cardThe `/etc/shadow` file is a critical system file that stores secure user account information, including encrypted passwords, last password change date, and password expiration policies.
- Contains encrypted passwords.
- Stores password aging information.
- Only readable by the root user.
Memory trick: SHADOW hides the password details.
Python Directory Creation (`os.makedirs`)
Flip cardThe `os.makedirs()` function in Python creates directories recursively. The `exist_ok=True` parameter, introduced in Python 3.2, prevents an `OSError` from being raised if the target directory already exists, making it an idempotent way to ensure a directory's presence.
- `os.makedirs()` creates all necessary parent directories.
- `exist_ok=True` avoids errors if the directory already exists.
- `os.mkdir()` only creates a single directory and errors if it exists.
Memory trick: MakeDirs with OK, no error, good to go!
dracut Emergency Shell / Missing Driver
Flip card'Gave up waiting for root device' in the initramfs stage usually means the initramfs lacks the storage driver needed to detect the root disk after a hardware/controller change.
- Fix with: dracut --force --add-drivers <module> /boot/initramfs-<version>.img
- Common after P2V/V2V migrations changing disk controller type
- Must chroot into the system from rescue media first
Memory trick: No driver, no disk — dracut needs the right key for the new lock
sudo -l
Flip cardThe sudo -l command lists the sudo privileges (allowed commands, hosts, and options) granted to the current user according to the sudoers configuration.
- Shows rules from /etc/sudoers and /etc/sudoers.d/
- Useful for verifying least-privilege configurations
- Can be run as 'sudo -l -U username' by root to check another user's rights
Memory trick: sudo -l is your personal permission slip listing.
rpm -q Query
Flip cardrpm -q <package> reports the installed version-release of a package directly from the local RPM database, with no network access needed.
- -q queries installed packages locally
- -qa lists all installed packages
- -qi shows detailed package info
- dnf commands often query remote repo metadata instead
Memory trick: rpm -q = Quick local Query, no internet needed
Ansible `user` Module
Flip cardAn Ansible module (`ansible.builtin.user`) used for managing user accounts on remote hosts in an idempotent manner.
- Ensures users exist or are removed (`state=present`/`absent`).
- Can set user properties like `shell`, `groups`, `uid`, `home`, `password`.
- Idempotent: running it multiple times yields the same result without errors.
Memory trick: Ansible modules manage resources perfectly, just like a chef uses specific tools for each ingredient.
Git Hooks
Flip cardGit hooks are scripts that Git executes automatically before or after events such as commit, push, and receive. They can be used to automate tasks, enforce policies, and integrate with continuous integration systems.
- Scripts located in the `.git/hooks` directory.
- Examples include `pre-commit`, `post-commit`, `pre-push`, `post-receive`.
- Can be used for linting, testing, formatting, and deployment tasks.
Memory trick: Hooks control the flow, ensuring rules are met.