CompTIA Linux+ (XK0-006) flashcards
188 free flashcards. Tap a card to flip it.
systemd Restart Policies
Flip cardThe `Restart=` directive in a `systemd` service unit's `[Service]` section defines when `systemd` should automatically restart the service's main process.
- Common values: `no`, `on-success`, `on-failure`, `always`.
- `on-failure` restarts on non-zero exit code or signal.
- Prevents service downtime from crashes.
Memory trick: RESTART a service ON-FAILURE to keep it alive.
systemd Timer Unit Relationship
Flip cardA `systemd` timer unit (`.timer`) is used to schedule the execution of a corresponding `systemd` service unit (`.service`). The service unit is typically configured as `Type=oneshot` and is only activated by the timer.
- `.timer` unit activates a `.service` unit.
- Timer units must be enabled and started.
- Service units often appear `inactive (dead)` when not actively running, if timer-triggered.
Memory trick: TIMERS control SERVICES, check the TIMER first!
FHS /var Directory
Flip card/var holds variable data that changes during system operation, such as logs, spool files, and caches.
- /var/log stores system and application logs
- /var/spool holds print and mail queues
- /var/cache stores application cache data
Memory trick: VAR = 'Various Altering Records' — data that keeps changing lives here
ACL (Access Control List)
Flip cardACLs provide a more granular way to manage file system permissions than traditional Unix permissions, allowing specific permissions for individual users or groups.
- Managed with `setfacl` (set) and `getfacl` (get) commands.
- Can explicitly grant or deny permissions beyond owner/group/other.
- Often used in conjunction with traditional permissions.
Memory trick: ACLs are like VIP lists for file access.
Default Route Configuration
Flip cardA default route (gateway) tells the kernel where to forward packets destined for networks not directly connected to the host; without it, only local-subnet communication works.
- ip route add default via <gateway-ip>
- View routes with ip route show or route -n
- Persistent config depends on NetworkManager/netplan or /etc/sysconfig/network-scripts
Memory trick: 'No gateway = stuck in your neighborhood; default route is the highway on-ramp.'
mount --bind
Flip cardCreates a mirror mount of an existing directory tree at another location, useful for exposing host directories (like /dev, /proc) into a chroot environment.
- Bind mount shares the same underlying data, not a copy
- Commonly used for /dev, /proc, /sys before chroot repair
- Symlinks don't work reliably across chroot boundaries
- Unmount bind mounts before exiting the rescue chroot
Memory trick: Bind = borrow the live /dev, don't build a new one
Bash `while IFS= read -r` Loop
Flip cardThe `while IFS= read -r line; do ... done < file` construct is the idiomatic and most robust way in Bash to read a file line by line, preserving whitespace and preventing backslash interpretation.
- `IFS=` prevents word splitting (important for lines with spaces).
- `-r` prevents backslash escapes from being interpreted.
- Redirecting input with `< file` avoids subshell issues of pipes.
Memory trick: IFS and Read, for lines you need, perfectly freed.
Zombie (Defunct) Processes
Flip cardA zombie is a terminated process whose exit status has not yet been collected by its parent via wait(), leaving a process table entry until reaped.
- Shown as state Z in top/ps
- Cannot be killed directly since it's already dead
- Remedy: fix or restart the parent process so it reaps children
Memory trick: A zombie is dead but its paperwork isn't filed until the parent signs off.
/etc/login.defs
Flip cardThe `/etc/login.defs` file contains system-wide default settings for user account creation and management on Linux, including password policies, UID/GID ranges, and default umask.
- Influences `useradd` and other user management utilities.
- Settings are applied when a user account is *created*.
- Common parameters include `PASS_MAX_DAYS`, `UID_MIN`, `GID_MIN`, and `UMASK`.
Memory trick: Login definitions dictate user beginnings.
SCP (Secure Copy)
Flip cardA command-line utility for securely copying files and directories between hosts on a network. It uses SSH for data transfer and provides the same authentication and security as SSH.
- Uses SSH for encryption and authentication.
- Supports copying files between two remote hosts as well as local-to-remote and remote-to-local.
- Syntax: scp [options] [[user@]host1:]file1 [[user@]host2:]file2
Memory trick: Securely Copying Files Protects Data.
fstab noauto Option
Flip cardnoauto is an /etc/fstab mount option that prevents a filesystem entry from being mounted automatically at boot or by 'mount -a', while still allowing manual mounting.
- Used for removable or occasional-use filesystems
- Entry still defines device, mount point, and fs type
- Combine with nofail for optional devices that may be missing
Memory trick: 'noauto = the door stays shut till you knock (mount) yourself.'
Linux File Ownership & Permissions
Flip cardLinux file permissions are controlled by owner, group, and others, with read (r), write (w), and execute (x) rights. Ownership (user and group) dictates which set of permissions applies to a given user or process.
- Each file/directory has an owner user and an owner group.
- Permissions are `rwx` for owner, group, and others.
- `chown` changes ownership, `chmod` changes permissions.
Memory trick: Owner, Group, Others: The Linux Permission Trio.
/proc/interrupts for Interrupt Load
Flip cardThe `/proc/interrupts` pseudofile provides detailed information about interrupt requests (IRQs) handled by the Linux kernel. It lists the number of interrupts received by each CPU core for various devices, making it invaluable for diagnosing high `sy`/`si` CPU usage caused by excessive hardware or software interrupt handling, especially from network interfaces.
- Shows interrupt counts per CPU and device.
- Distinguishes hardware (IRQ) and software interrupts.
- Crucial for identifying interrupt-related bottlenecks (e.g., busy NICs).
Memory trick: PROC INTERRUPTS reveals the source of the CPU's jitters.
vgextend
Flip cardLVM command that adds one or more physical volumes to an existing volume group, increasing its total available storage pool.
- Requires the PV to already be initialized with pvcreate
- Must run before lvextend can use the new space
- Reverse operation is vgreduce to remove a PV from a VG
Memory trick: vgextend feeds the pool before lvextend can drink from it.
ksoftirqd / Software Interrupts (si)
Flip card`ksoftirqd` is a kernel thread responsible for handling deferred software interrupts (softirqs), which are lower-priority interrupt processing tasks. High `si` CPU usage indicates significant time spent on these tasks.
- Softirqs are used to defer interrupt processing that doesn't need to be handled immediately within the hard interrupt context.
- Commonly associated with high network I/O, as network packet processing is frequently deferred to softirqs.
- Each CPU core typically has its own `ksoftirqd` process (e.g., `ksoftirqd/0`, `ksoftirqd/1`).
Memory trick: Soft interrupts are like 'S'oftware 'I'nterrupts for 'S'treaming 'I'nformation, especially network traffic.
LVM + Filesystem Resize
Flip cardExtending an LVM logical volume with lvextend does not automatically grow the filesystem; you must also resize the filesystem using the correct tool for its type.
- ext2/3/4: use resize2fs
- XFS: use xfs_growfs (can only grow, never shrink)
- Combine both steps with lvextend -r to resize automatically
Memory trick: Bigger box (LV) still needs bigger shelves (filesystem) — match the tool to the filesystem type
vmstat Swap Columns (si/so)
Flip cardsi (swap-in) and so (swap-out) in vmstat report the rate, in KB/s, that memory pages move between RAM and swap space; sustained high values indicate memory pressure and thrashing.
- si = swap-in (KB/s), so = swap-out (KB/s)
- High wa (I/O wait) combined with high si/so confirms swap thrashing
- Fix: add RAM, reduce memory usage, or tune swappiness (vm.swappiness)
Memory trick: Elephant-sized memory demand forces pages to swap in and out — si/so are the footprints.
UUID-Based Mounting
Flip cardUsing the unique UUID of a filesystem in /etc/fstab ensures a device mounts consistently regardless of its detected device name.
- Retrieve UUID with 'blkid' or 'lsblk -f'
- Prevents mount failures from device renumbering
- Format in fstab: UUID=xxxx-xxxx /mountpoint ext4 defaults 0 2
Memory trick: UUID = a device's 'fingerprint' that never changes, unlike its nickname
Python `json.loads()`
Flip cardThe `json.loads()` function in Python's `json` module is used to deserialize (load) a JSON formatted string into a Python object, typically a dictionary or list.
- Input must be a valid JSON string.
- Converts JSON data types to corresponding Python data types.
- The 's' in `loads` stands for 'string'.
Memory trick: Loads from string, dumps to string, that's the JSON swing!
OOM Killer Activation
Flip cardThe Linux kernel's Out-Of-Memory (OOM) killer is a mechanism that activates when the system runs out of physical RAM and swap space. It terminates processes (often large memory consumers) to free up memory and prevent a system crash. Its activation is explicitly logged with 'Out of memory' messages.
- Kernel kills processes due to lack of memory.
- Occurs when RAM and swap are exhausted.
- Logged as 'Out of memory' in kernel messages.
Memory trick: OOM Killer means Out Of Memory, a system's sad story.
Python `with` Statement
Flip cardThe `with` statement in Python is used to wrap the execution of a block with methods defined by a context manager. It ensures that 'clean-up' code is executed, even if exceptions occur.
- Guarantees resource release (e.g., file closure, lock release).
- Works with objects that implement the context manager protocol (`__enter__` and `__exit__`).
- Commonly used for file I/O, database connections, and threading locks.
Memory trick: With every resource, ensure a clean exit.
pam_limits.so and limits.conf
Flip cardThe `pam_limits.so` PAM module uses the `/etc/security/limits.conf` file to enforce resource limits for users, such as CPU time, memory, or maximum concurrent login sessions.
- Controls system resource usage for users.
- Configured via `/etc/security/limits.conf`.
- Part of Pluggable Authentication Modules (PAM).
Memory trick: PAM sets LIMITS on your resources.
LVM Build Order
Flip cardLVM is built in three layers: physical volumes (PVs) created from disks/partitions with pvcreate, grouped into a volume group with vgcreate, from which logical volumes are carved with lvcreate.
- pvcreate initializes raw disks/partitions as PVs
- vgcreate pools PVs into a VG
- lvcreate allocates a sized LV from VG free space
Memory trick: 'Please Very Loudly: Pvcreate, Vgcreate, Lvcreate.'
free -h available column
Flip cardThe 'available' column in free output estimates usable memory for new applications, factoring in reclaimable cache/buffers.
- Linux uses free RAM for disk caching (buff/cache)
- 'free' alone underestimates usable memory
- 'available' is the correct metric to judge memory pressure
Memory trick: Available = Actually-usable memory (cache can be dropped)
LUKS Encryption Workflow
Flip cardLUKS encrypts a block device; the standard process formats the raw device, opens it to a mapped name, then filesystem operations occur on /dev/mapper/<name>.
- luksFormat writes LUKS header to raw partition
- luksOpen creates /dev/mapper/<name> decrypted device
- Filesystem is created on the mapper device, not raw partition
- luksClose closes the mapped device when done
Memory trick: Format, Open, then Format the Filesystem
ss Socket Statistics
Flip cardss is a modern replacement for netstat used to display socket information; combining flags like -tuln filters to numeric, listening TCP/UDP sockets.
- -t = TCP sockets
- -u = UDP sockets
- -l = listening only
- -n = numeric (no DNS resolution)
Memory trick: T-U-L-N: 'Totally Useful Listing, Numeric' for finding open ports
ss Command
Flip cardA modern replacement for netstat used to display socket statistics, including listening ports and associated processes.
- -t shows TCP sockets, -u shows UDP sockets
- -l filters for listening sockets only
- -p shows the owning process, -n avoids DNS resolution delays
Memory trick: ss = 'socket snapshot' revealing who's listening on the server
FHS /etc Directory
Flip cardThe /etc directory stores host-specific static configuration files used by the system and installed applications.
- Contains /etc/passwd, /etc/fstab, /etc/hosts
- No binaries should be stored here
- Configuration is host-specific, not shared across machines
Memory trick: 'etc = Every Configuration Textfile Center.'
efibootmgr
Flip cardA Linux utility that interacts with the EFI firmware to manage boot entries. It allows users to add, delete, change, and list boot entries, as well as modify the boot order.
- Requires root privileges to run.
- Operates directly on the EFI NVRAM.
- Commonly used options include -v (verbose), -o (set boot order), -a (activate entry), -b (bootnum).
Memory trick: EFI Boot Manager, very verbose for UEFI.
SGID (Set Group ID) on files
Flip cardThe SGID permission bit, when set on an executable file, causes the process to run with the effective group ID of the file's group owner, rather than the primary group ID of the user executing it.
- Represented by `s` in the group execute position (`rws` or `r-s`).
- Octal value is `2` in the special permissions digit.
- Useful for shared applications or scripts requiring specific group access.
Memory trick: Special bits grant super powers to files.
dig for Specific DNS Server Query
Flip cardThe `dig` (domain information groper) command is a flexible tool for querying DNS name servers, allowing users to specify a particular DNS server to test resolution for a given domain.
- Syntax: `dig @<DNS_SERVER_IP> <DOMAIN> [QUERY_TYPE]`.
- Provides detailed DNS response, including authoritative server, query time, and answer section.
- Useful for diagnosing problems with specific DNS servers or verifying DNS records.
Memory trick: To 'Dig' into a specific DNS server, use '@' and the domain.
journalctl for systemd targets
Flip cardThe `journalctl` utility can be used with the `-u` option to view log messages generated by or related to a specific `systemd` unit, including target units like `network-online.target`.
- Filters logs by unit name.
- Useful for diagnosing target activation issues.
- Provides historical and real-time log data.
Memory trick: JOURNALctl logs all TARGET actions.
apt-get install -f
Flip cardCommand used to fix broken package dependencies, commonly needed after installing a .deb file manually with dpkg -i.
- -f stands for 'fix-broken'
- Downloads and installs missing dependency packages
- Often paired with dpkg --configure -a for full recovery
Memory trick: apt -f = 'fix' the puzzle pieces dpkg left missing.
mdadm RAID Recovery
Flip cardWhen a RAID array becomes degraded due to a failed disk, mdadm --add integrates a replacement device and triggers resynchronization to restore redundancy.
- mdadm --detail shows array state (clean, degraded, etc.)
- --add re-adds a replacement/spare disk to an existing array
- --create only be used for building a new array, not repairing one
Memory trick: --add = 'adopting' a new disk into the existing RAID family after a loss
CI/CD Pipeline Orchestration
Flip cardCI/CD Pipeline Orchestration is the process of defining, managing, and executing the sequence of automated stages (build, test, deploy, etc.) in a CI/CD workflow, ensuring proper flow, conditional execution, and error handling.
- Involves tools like Jenkins, GitLab CI, GitHub Actions, Azure DevOps.
- Defines conditional transitions between stages.
- Manages parallel execution and dependencies.
- Includes notification mechanisms for pipeline status.
Memory trick: Orchestration conducts the pipeline's grand production.
traceroute for Path Analysis
Flip card`traceroute` (or `tracepath`) is a network diagnostic tool used to display the route (path) and measure transit delays of packets across an IP network. It identifies each hop (router) along the path and can help pinpoint where connectivity issues, such as packet loss or high latency, occur.
- Maps the network path to a destination.
- Shows latency to each 'hop' (router).
- Essential for diagnosing intermediate network issues.
Memory trick: TRACEROUTE shows the trail of packet's travail.
Python `re` Module
Flip cardThe `re` module in Python provides support for regular expressions (regex). It allows developers to define complex search patterns to match, find, and manipulate strings based on those patterns.
- Used for pattern matching and string manipulation.
- Common functions: `re.search()`, `re.findall()`, `re.match()`, `re.sub()`.
- Patterns are defined using a specific regex syntax.
Memory trick: Regex needs 're', don't forget it, you see!
fdisk partition type change
Flip cardWithin fdisk's interactive menu, 't' sets or changes the hex system ID of a partition, such as 8e for Linux LVM.
- 'n' creates a new partition
- 't' changes partition type code (e.g., 8e=Linux LVM)
- 'w' writes changes and exits
- 'l' lists all type codes
Memory trick: Type comes before Write: set the Tag then Write it
ss -tlnp for listening ports
Flip cardThe `ss -tlnp` command lists all TCP (t) sockets in listening (l) state, showing their numerical (n) port numbers and the process (p) that opened them. It's crucial for verifying if a service is actually binding to its intended port.
- Shows TCP sockets only.
- Lists ports in a listening state.
- Displays the process ID and name associated with the listening port.
- Useful for diagnosing 'Connection Refused' errors when a service should be listening.
Memory trick: No socket, no service, no connection.
CPU 'si' (software interrupts)
Flip cardThe 'si' (software interrupts) metric in `top` indicates the percentage of CPU time spent handling software interrupts. High 'si' often points to intensive kernel-level processing, most commonly related to network packet handling.
- Represents time spent in softirq handlers.
- Commonly elevated during heavy network traffic (NIC processing).
- Can also be affected by storage I/O, but less directly than 'wa'.
Memory trick: SIgnaling Network Interrupts.
DNS Resolver Configuration (/etc/resolv.conf)
Flip cardThe `/etc/resolv.conf` file specifies the IP addresses of DNS (Domain Name System) servers that a Linux system should use to resolve hostnames to IP addresses. Incorrect or unreachable entries prevent successful name resolution.
- Lists `nameserver` entries for DNS server IPs.
- Crucial for external (and sometimes internal) hostname resolution.
- Often managed by network managers (e.g., NetworkManager, systemd-resolved).
Memory trick: Resolve to check the nameservers.
GRUB root parameter
Flip cardThe `root=` parameter in the GRUB configuration (`/boot/grub/grub.cfg`) specifies the device (e.g., `/dev/sdb1` or UUID) where the kernel should find and mount the root filesystem. An incorrect value leads to boot failures.
- Crucial for the kernel to locate the root filesystem.
- Typically found in the `linux` or `linuxefi` line of a boot entry.
- Can use device names (e.g., `/dev/sdb1`) or UUIDs.
Memory trick: GRUB's config roots the kernel.
top command
Flip cardThe `top` command provides a dynamic real-time view of a running Linux system, showing process activity, CPU usage, memory usage, and other system statistics.
- Displays processes sorted by CPU usage by default.
- Interactive; allows sorting by different columns (e.g., memory, PID).
- Includes system-wide statistics like load average and uptime.
Memory trick: Topping the charts with CPU and memory usage.
ip route show
Flip cardThe `ip route show` command displays the kernel routing table, which dictates how network packets are forwarded to their destinations, including the default route for traffic outside the local subnet.
- Shows all configured network routes.
- Essential for verifying the default gateway configuration.
- Used to troubleshoot network connectivity issues beyond the local subnet.
Memory trick: Routing means showing the way, like a map.
PAM common-auth
Flip cardThe /etc/pam.d/common-auth file is a common PAM configuration file used to define authentication policies that apply to multiple services on a Linux system.
- Often included by other service-specific PAM files (e.g., login, sshd).
- Used for defining authentication-related modules like pam_unix.so or pam_faillock.so.
- Modifying it provides a centralized way to enforce system-wide authentication policies.
Memory trick: PAM's Common Auth is like a central library for all login rules.
Removing User Accounts with Home Directory
Flip cardThe `userdel -r` command removes a user account and their associated home directory and mail spool.
- `userdel` removes the user entry from system files.
- `-r` (or `--remove-home`) removes the home directory.
- Also removes the mail spool and other related files.
Memory trick: 'Userdel' for 'Delete', '-r' for 'Remove everything'.
Umask Calculation for Files
Flip cardThe `umask` (user file-creation mode mask) determines the default permissions for newly created files and directories.
- For files, base permissions are usually `666` (rw-rw-rw-).
- For directories, base permissions are usually `777` (rwxrwxrwx).
- The `umask` bits are 'subtracted' from the base permissions (more accurately, the inverse of the umask is ANDed with the base permissions).
Memory trick: UMASK: Subtract from 666 (files) or 777 (dirs), then check the math!
Following systemd Unit Logs
Flip cardUse `journalctl -u <unit> -f` to view `systemd` unit logs in real-time, displaying new entries as they are generated.
- The `-f` (follow) option continuously outputs new log entries.
- Essential for troubleshooting services that fail to start or have intermittent issues.
- Filters logs specifically for a `systemd` unit.
Memory trick: Journal's 'U' for 'Unit', 'F' for 'Follow'.
Adding Cron Jobs from Standard Input
Flip cardYou can add cron jobs to a user's crontab directly from standard input using the `crontab -` command, often piped from `echo`.
- `crontab -` reads from stdin.
- Useful for scripting cron job additions.
- Requires correct cron syntax (minute hour day_of_month month day_of_week command).
Memory trick: Cron's 'E' for 'Edit', 'L' for 'List', '-' for 'Input'.
AIDE --check
Flip cardThe 'aide --check' command is used to perform an integrity check of the file system by comparing the current state of files against the previously generated AIDE database.
- It reports any changes (modification, addition, deletion) since the last database update.
- Requires a pre-existing AIDE database (created with 'aide --init').
- Often run as part of a scheduled task (e.g., cron job) for regular monitoring.
Memory trick: AIDE's Init starts, Check verifies, Update accepts changes.
Dockerfile ENTRYPOINT
Flip cardConfigures a container that will run as an executable. Arguments provided to `docker run` will be appended after the `ENTRYPOINT`.
- Defines the main command to execute when a container starts.
- Best used in `exec` form (JSON array).
- Often combined with `CMD` to provide default arguments.
Memory trick: ENTRYPOINT is the main door, CMD is the welcome mat.
Docker Bind Mounts
Flip cardDocker bind mounts allow you to share a file or directory from the host machine directly into a container, providing persistent storage and host-side access.
- Uses `-v host_path:container_path` or `--mount type=bind,source=host_path,target=container_path`.
- Data persists on the host even if the container is removed.
- Host path must exist, or Docker will create a file if not a directory.
Memory trick: VOLUME Mounts: Host to Container - H:C!
Non-Login Shells
Flip cardUsing `/bin/false` or `/sbin/nologin` as a user's shell prevents interactive login sessions by immediately exiting upon login.
- User can authenticate but gets no shell.
- Common for service accounts or disabled user accounts.
- Different from locking an account (e.g., `passwd -l`).
Memory trick: Shell's a 'door', `false` means 'no entry'.
SGID on Directories for Group Inheritance
Flip cardThe Set Group ID (SGID) bit on a directory forces all new files and subdirectories created within it to inherit the parent directory's group ownership.
- Set with `chmod g+s` or `chmod 2xxx`.
- Applies group ownership inheritance, not permissions.
- Useful for shared directories among team members.
Memory trick: Group 'S'hares and 'G'ets 'ID'ea from parent.
Group Deletion Prerequisites
Flip cardTo successfully delete a group using `groupdel`, no user should have that group assigned as their primary group.
- Users' primary group is stored in `/etc/passwd` (GID field).
- Use `usermod -g` to change a user's primary group.
- Use `groupdel` to remove a group.
Memory trick: PRIMARY users must LEAVE before the GROUP can be gone!
systemd Target Unit Dependencies
Flip card`systemd` targets are used to group units and define synchronization points during boot or system state changes. Dependencies control their activation order.
- `After=` and `Before=` define ordering, not strict dependencies.
- `Wants=` defines a weak dependency: unit will be started, but target won't fail if it doesn't.
- `Requires=` defines a strong dependency: unit will be started, and target will fail if it doesn't.
Memory trick: ORDER (After/Before) your WANTS and REQUIRES for a perfect target!
systemctl enable --now
Flip cardA `systemctl` command combination that both enables a `systemd` unit to start automatically at boot and starts it immediately in the current session.
- Combines `enable` and `start` actions.
- Useful for quickly activating services/timers permanently.
- Avoids separate commands for immediate activation and boot persistence.
Memory trick: ENABLE NOW for instant boot-up power!
chage command
Flip cardUsed to change user password expiry information and account aging policies in Linux.
- Modifies entries in `/etc/shadow` related to password aging.
- `-M` sets maximum days between password changes.
- `-W` sets warning days before password expiration.
Memory trick: Change (`chage`) your AGE (`-M` for Max, `-W` for Warning) before it's too late!
/etc/group 'x' field
Flip cardIn `/etc/group`, an 'x' in the password field indicates that the group has an encrypted password, which is stored in the `/etc/gshadow` file for security.
- Analogous to 'x' in `/etc/passwd`.
- Group passwords are rare on most Linux systems.
- Managed by `gpasswd` command.
Memory trick: Group 'X': e'X'tra secure password in gshadow.
nftables Chain Policy
Flip cardIn nftables, a chain policy defines the default action for packets that traverse a chain and do not match any specific rules within that chain. Common policies are 'accept' (allow) and 'drop' (discard silently).
- Set when defining or updating a chain (e.g., 'policy drop;').
- Crucial for security, as it dictates default behavior.
- 'drop' discards packets silently, 'reject' sends an error message back.
Memory trick: Tables hold Chains, Chains hold Rules, all with a Family.