1. A system administrator wants to define a custom `systemd` target named `my-custom.target` that depends on `network-online.target` and `multi-user.target`. This custom target should be reached only after both of its dependencies are active. Which `systemd` unit file configuration snippet correctly defines these dependencies?
D. [Unit]
Description=My Custom Target
Requires=network-online.target multi-user.target
After=network-online.target multi-user.target
To ensure a target is reached *only after* its dependencies are active, both `Requires=` and `After=` directives are typically used. `Requires=` means the target cannot be started unless the listed units are started, and `After=` ensures correct ordering, meaning `my-custom.target` will start only after `network-online.target` and `multi-user.target` have started.
2. A user needs to quickly encrypt a single file, notes.txt, for personal storage on a USB drive using a shared passphrase rather than public-key cryptography, so that anyone who knows the passphrase can later decrypt it. Which command should the user run?
The -c (or --symmetric) flag tells GPG to use symmetric encryption, prompting for a passphrase and using a cipher such as AES256 to encrypt the file into notes.txt.gpg; anyone with the passphrase can decrypt it with gpg -d. Asymmetric encryption (--recipient) instead requires the recipient's public/private key pair.
3. A technician is preparing a new Linux server for a database application that requires high-performance, redundant storage. They have four new 1TB physical disks (/dev/sdb, /dev/sdc, /dev/sdd, /dev/sde) and plan to use RAID 10. What is the maximum usable storage capacity for this RAID 10 array?
System Management
A.2 TB
B.4 TB
C.1 TB
D.3 TB
Show answerAnswer
A. 2 TB
RAID 10 (or RAID 1+0) requires an even number of disks, typically at least four. It stripes data across mirrored pairs. With four 1TB disks, you get two 1TB mirrored pairs. The usable capacity is the sum of the capacities of the mirrored pairs, so 1TB + 1TB = 2TB.
4. A technician checks a failed service:
`systemctl status app.service` shows: `Active: failed (Result: exit-code)`
Running `journalctl -u app.service -xe` reveals: `Permission denied` when the application attempts to open `/var/lib/app/data.db`. The file is owned by root:root with mode 600, but the service runs as user `appuser`. What should the technician do to resolve this?
Troubleshooting
A.Change the file ownership with `chown appuser:appuser /var/lib/app/data.db`
B.Run `systemctl daemon-reload` to reload the unit file and clear the error
C.Edit /etc/passwd to change appuser's UID to 0
D.Restart the service repeatedly until it starts successfully
Show answerAnswer
A. Change the file ownership with `chown appuser:appuser /var/lib/app/data.db`
The journalctl log clearly shows a permission denied error caused by ownership mismatch: the file is owned by root with restrictive mode 600, but the service process runs as appuser, which has no access. Changing ownership to appuser (or appropriate group) resolves the access issue without weakening security by making the file world-readable or granting root privileges.
5. A technician runs 'lsblk' on a server and notices a logical volume /dev/vg_data/lv_apps is mounted at /opt/apps but the underlying volume group vg_data has 20GB of free (unallocated) extents. Management wants the mounted filesystem grown by 10GB without unmounting it, and the filesystem is ext4. Which sequence of commands correctly accomplishes this?
System Management
A.lvcreate -L 10G -n lv_apps2 vg_data && mount /dev/vg_data/lv_apps2 /opt/apps
C. lvextend -L +10G /dev/vg_data/lv_apps && resize2fs /dev/vg_data/lv_apps
Since free space already exists in the volume group, the correct approach is to extend the logical volume with 'lvextend -L +10G' and then grow the ext4 filesystem online with 'resize2fs' so it uses the new space, all without unmounting.
6. A server administrator notices that a physical server takes significantly longer to boot than expected. The administrator wants to see a breakdown of how much time each systemd unit took to initialize during the last boot. Which command should be used?
System Management
A.systemctl list-units --failed
B.journalctl -b
C.systemd-analyze blame
D.dmesg | grep boot
Show answerAnswer
C. systemd-analyze blame
'systemd-analyze blame' lists all running units ordered by the time each one took to initialize, making it the correct tool to identify boot-time bottlenecks. The other commands show logs or failed units but do not provide per-unit timing.
7. A technician moved a website's files from /tmp/newsite to /var/www/html using the mv command. Standard Linux permissions are correct, but Apache still cannot serve the pages due to SELinux denials in the audit log. Which command should the technician run to fix the file security contexts to match the default policy for that directory?
Security
A.chmod -R 755 /var/www/html
B.restorecon -Rv /var/www/html
C.chown -R apache:apache /var/www/html
D.setsebool -P httpd_enable_homedirs on
Show answerAnswer
B. restorecon -Rv /var/www/html
Because mv preserves the source directory's SELinux context, files moved from /tmp retain the wrong context (typically tmp_t) instead of the httpd_sys_content_t expected in /var/www/html. restorecon -Rv resets the context recursively based on the system's default file context policy.
8. A junior administrator is learning Git and has accidentally committed a file containing sensitive information (e.g., a password) to the local repository. They have not yet pushed this commit to a remote server. Which of the following Git commands should be used to remove the sensitive file from the commit history before pushing to the remote repository?
B. `git rm <sensitive_file> && git commit --amend --no-edit`
If the sensitive file was introduced in the most recent commit and has not been pushed, `git rm <sensitive_file>` followed by `git commit --amend --no-edit` will remove the file from the HEAD commit and rewrite that commit without creating a new history entry. This is the simplest and most appropriate solution for an unpushed, recent commit.
9. A server with two network interfaces needs to act as a NAT gateway so that internal clients on eth1 can reach the internet through eth0. Which iptables command correctly enables this masquerading behavior?
Security
A.iptables -A INPUT -i eth0 -j MASQUERADE
B.iptables -t nat -A PREROUTING -i eth0 -j MASQUERADE
C.iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
D.iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
Show answerAnswer
C. iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
MASQUERADE is a NAT target applied to the POSTROUTING chain that dynamically rewrites the source address of outgoing packets to the address of the outbound interface (eth0), allowing internal hosts to share a single public IP for internet access.
10. A Linux server is experiencing extremely slow network performance, but CPU utilization and disk I/O appear normal. The administrator suspects an issue with the network interface's duplex settings, potentially causing a duplex mismatch. Which command would allow the administrator to check the current speed and duplex settings of the `eth0` network interface?
Troubleshooting
A.`ethtool eth0`
B.`cat /sys/class/net/eth0/speed`
C.`ifconfig eth0`
D.`ip link show eth0`
Show answerAnswer
A. `ethtool eth0`
`ethtool` is the dedicated command-line utility for querying and controlling network device driver and hardware settings, including speed, duplex, autonegotiation, and other advanced parameters essential for diagnosing physical layer network issues.
11. A security administrator is troubleshooting a web application that is being blocked by SELinux even though standard file permissions are correct. The administrator wants to temporarily switch SELinux into a mode that logs violations without blocking them, without rebooting the server. Which command accomplishes this?
Security
A.sestatus --disable
B.getenforce permissive
C.setenforce 0
D.semanage permissive -a httpd_t
Show answerAnswer
C. setenforce 0
The setenforce command changes the current runtime SELinux mode without a reboot; setenforce 0 sets Permissive mode (log only), while setenforce 1 sets Enforcing mode. The change is not persistent across reboots (that requires editing /etc/selinux/config).
12. A server fails to boot normally and drops into a systemd emergency shell. The journal shows: "[TIME] Timed out waiting for device /dev/sdb1." Investigation reveals /dev/sdb1 is an external USB drive that is not always connected, but it has a standard entry in /etc/fstab. Which fstab mount option should be added to that entry to prevent this boot failure when the device is absent?
Troubleshooting
A.defaults
B.nofail
C.ro
D.noauto
Show answerAnswer
B. nofail
The nofail option tells systemd to continue booting even if the device fails to mount, rather than treating it as critical and blocking the boot process. noauto would prevent automatic mounting entirely (even when the device is present), which changes intended behavior rather than fixing the boot-blocking issue.
13. A developer is working on a Python script that needs to interact with a REST API. The script uses the `requests` library to make HTTP GET requests and processes the JSON response. During development, the developer wants to store the API key securely and avoid hardcoding it in the script. Which of the following is the MOST secure and flexible way to manage the API key in a Python script?
Automation, Orchestration and Scripting
A.Store the API key directly in a string variable within the Python script.
B.Write the API key to a plain text file (`api_key.txt`) and read it from the script.
C.Prompt the user to enter the API key every time the script runs using `input()`.
D.Store the API key in an environment variable and access it using `os.getenv()`.
Show answerAnswer
D. Store the API key in an environment variable and access it using `os.getenv()`.
Storing the API key in an environment variable is the most secure and flexible option among those given. It keeps the key out of the codebase, preventing accidental commits to version control, and allows for easy rotation and different keys for different environments without modifying the script.
14. A technician replaced a failed disk in a BIOS-based server and restored the operating system data to the new disk, /dev/sda. The system fails to boot because no bootloader is installed on the new disk. After booting into a rescue environment and chrooting into the restored system, which command should the technician run to install GRUB onto the disk's boot sector?
System Management
A.update-grub
B.dracut -f
C.grub2-install /dev/sda
D.grub2-mkconfig -o /boot/grub2/grub.cfg
Show answerAnswer
C. grub2-install /dev/sda
'grub2-install /dev/sda' writes the GRUB boot code to the disk's MBR/boot sector, which is required after replacing a disk that has no bootloader installed. 'grub2-mkconfig' and 'update-grub' only regenerate the grub.cfg configuration file, and 'dracut' rebuilds the initramfs image, neither of which installs the actual bootloader.
15. A compliance policy requires that all new local user passwords be at least 14 characters long, enforced through PAM at password creation time. Which file and setting should the administrator configure to meet this requirement?
Security
A./etc/login.defs with 'PASS_MIN_LEN 14'
B./etc/sudoers with 'Defaults passwd_min_length=14'
C./etc/pam.d/system-auth with 'password requisite pam_faillock.so'
D./etc/security/pwquality.conf with 'minlen = 14'
Show answerAnswer
D. /etc/security/pwquality.conf with 'minlen = 14'
pam_pwquality, configured via /etc/security/pwquality.conf, is the module invoked during password change/creation on modern distributions to enforce complexity rules such as minlen. login.defs' PASS_MIN_LEN is a legacy setting largely unused by PAM-based password quality checks, pam_faillock handles lockouts (not length), and sudoers has no such directive.
16. An administrator runs `mdadm --detail /dev/md0` on a RAID 5 array and sees:
State : clean, degraded
Active Devices : 2
Working Devices : 2
Failed Devices : 1
...
2 8 33 - removed
A new replacement disk has been partitioned as /dev/sdc1. Which command correctly adds this disk back into the array to begin rebuilding?
mdadm --manage --add hot-adds a spare disk to an existing degraded array, triggering an automatic rebuild/resync using parity data from the remaining active devices. --create would destroy the existing array metadata, --assemble is for reconstructing an array from its member devices after a reboot, and --grow changes the number of active devices in size/configuration rather than replacing a failed member.
17. A system administrator needs to check the validity and integrity of installed RPM packages on a critical server. Which command should be used to verify all files belonging to a specific package, such as 'httpd', against its stored metadata and checksums?
Security
A.rpm -q httpd
B.rpm -i httpd
C.rpm -U httpd
D.rpm -V httpd
Show answerAnswer
D. rpm -V httpd
The 'rpm -V' command (or 'rpm --verify') is used to verify the integrity of files belonging to an installed RPM package. It checks file sizes, MD5 sums, permissions, types, owners, and groups against the RPM database.
18. A system administrator is using Ansible to ensure that a specific package, `nginx`, is installed on all web servers. They also need to ensure that the `nginx` service is running and enabled to start automatically on boot. Which Ansible task correctly achieves both of these requirements?
Automation, Orchestration and Scripting
A.- name: Ensure Nginx is installed, running, and enabled
ansible.builtin.systemd: name=nginx state=started enabled=yes
B.- name: Ensure Nginx is installed, running, and enabled
ansible.builtin.package: name=nginx state=present
ansible.builtin.service: name=nginx state=started enabled=yes
C.- name: Ensure Nginx is installed, running, and enabled
ansible.builtin.yum: name=nginx state=present
ansible.builtin.service: name=nginx state=started enabled=yes
B. - name: Ensure Nginx is installed, running, and enabled
ansible.builtin.package: name=nginx state=present
ansible.builtin.service: name=nginx state=started enabled=yes
To ensure a package is installed and a service is running/enabled, Ansible typically uses two separate modules: `package` (or distributions specific modules like `apt`, `yum`) for package management, and `service` (or `systemd`) for service management. Option C correctly combines the `package` module for installation and the `service` module for starting and enabling `nginx`.
19. A system administrator needs to implement a policy where all new files created by any user in the `/shared/data` directory automatically inherit the group ownership of the directory itself, rather than the user's primary group. Which command achieves this?
Services and User Management
A.chmod g+s /shared/data
B.setfacl -m d:g:sharedgroup:rwx /shared/data
C.chown root:sharedgroup /shared/data
D.chmod +t /shared/data
Show answerAnswer
A. chmod g+s /shared/data
Setting the Set Group ID (SGID) bit on a directory (`chmod g+s`) causes new files and subdirectories created within it to inherit the group ownership of the parent directory, rather than the primary group of the user who created them. This is exactly what the scenario describes.
20. An administrator runs 'ssh user@server' and receives the error: 'WARNING: UNPROTECTED PRIVATE KEY FILE!' referencing ~/.ssh/id_rsa. What is the correct fix?
Security
A.chown root:root ~/.ssh/id_rsa
B.chmod 644 ~/.ssh/id_rsa
C.chmod 600 ~/.ssh/id_rsa
D.chmod 777 ~/.ssh/id_rsa
Show answerAnswer
C. chmod 600 ~/.ssh/id_rsa
SSH refuses to use a private key that is readable or writable by group or others, as this represents a security risk. Setting permissions to 600 (read/write for owner only) resolves the warning and allows the key to be used.
21. A system administrator has just modified the unit file for a `systemd` service named `myservice.service` (e.g., `/etc/systemd/system/myservice.service`). After saving the changes, the administrator attempts to `systemctl start myservice.service`, but the changes do not seem to take effect. What is the most likely reason for this, and which command should be executed to resolve it?
Services and User Management
A.The service is masked; use `sudo systemctl unmask myservice.service`.
B.The unit file has syntax errors; check `journalctl -xe`.
C.The service is already running; use `systemctl restart myservice.service`.
D.`systemd` needs to reload its configuration; use `sudo systemctl daemon-reload`.
Show answerAnswer
D. `systemd` needs to reload its configuration; use `sudo systemctl daemon-reload`.
After modifying a `systemd` unit file, `systemd` needs to re-read its configuration files from disk. This is done with the `systemctl daemon-reload` command.
22. An administrator noticed that after entering a password once for a sudo command, subsequent sudo commands in the same terminal session do not prompt for a password again for several minutes. Which sudoers directive controls the length of this credential caching window?
Security
A.Defaults timestamp_timeout=15
B.Defaults env_reset
C.Defaults !authenticate
D.Defaults passwd_tries=3
Show answerAnswer
A. Defaults timestamp_timeout=15
timestamp_timeout defines, in minutes, how long sudo caches successful authentication before requiring the password again; setting it to 15 caches credentials for 15 minutes. passwd_tries limits failed attempts, env_reset controls environment sanitization, and !authenticate disables password prompts entirely.
23. A server can successfully ping other hosts on its local subnet but cannot reach any external IP addresses. Running `ip route show` returns no default route entry. Which command adds a default gateway of 192.168.1.1 through interface eth0?
Troubleshooting
A.ip route add default via 192.168.1.1 dev eth0
B.ip link set eth0 up
C.ip neigh add 192.168.1.1 dev eth0
D.ip addr add 192.168.1.1/24 dev eth0
Show answerAnswer
A. ip route add default via 192.168.1.1 dev eth0
The `ip route add default via <gateway> dev <interface>` command inserts a default route so that traffic destined for networks outside the local subnet is forwarded to the specified gateway. Without this entry, the kernel has no route for external destinations and packets are dropped.
24. A system administrator is using Ansible to manage a fleet of Linux servers. They need to ensure a specific service, `httpd`, is running and enabled at boot time on all web servers. Which of the following Ansible playbook snippets correctly achieves this goal?
Automation, Orchestration and Scripting
A.```yaml
- name: Ensure httpd is running and enabled
shell: systemctl start httpd && systemctl enable httpd
```
B.```yaml
- name: Ensure httpd is running and enabled
systemd:
name: httpd
state: started
enabled: yes
```
C.```yaml
- name: Ensure httpd is running and enabled
package:
name: httpd
state: present
```
D.```yaml
- name: Ensure httpd is running and enabled
service:
name: httpd
state: started
enabled: no
```
Show answerAnswer
B. ```yaml
- name: Ensure httpd is running and enabled
systemd:
name: httpd
state: started
enabled: yes
```
The `systemd` module (or the more generic `service` module which often defaults to systemd for modern Linux) is the correct and idempotent way to manage services in Ansible. `state: started` ensures it's running, and `enabled: yes` ensures it starts at boot.
25. A system administrator is configuring a new Linux server and needs to ensure that the `firewalld` service is started automatically every time the system boots up. Which `systemctl` command should the administrator use to achieve this?
Services and User Management
A.sudo systemctl start firewalld
B.sudo systemctl activate firewalld
C.sudo systemctl boot firewalld
D.sudo systemctl enable firewalld
Show answerAnswer
D. sudo systemctl enable firewalld
The `systemctl enable` command is used to create the necessary symbolic links to ensure a service starts automatically at boot.
`systemd` targets use `Requires=` and `After=` directives to define strong dependencies and ordering, ensuring a target is activated only after its prerequisites are met and active.
`Requires=`: strong dependency, unit fails if required unit fails.
`After=`: ordering, unit starts after specified units have started.
`Wants=`: weak dependency, unit still tries to start if wanted unit fails.
GPG's -c (--symmetric) option encrypts a file using a single shared passphrase and a symmetric cipher (default AES256), suitable when no recipient key exchange is needed.
gpg -c file encrypts using a passphrase (symmetric)
gpg -d file.gpg decrypts using the same passphrase
Differs from --encrypt --recipient, which uses asymmetric public/private keys
A nested RAID level that combines striping (RAID 0) and mirroring (RAID 1). It creates mirrored pairs of disks, and then stripes data across these mirrors. It requires a minimum of four disks and provides both performance and redundancy.
Minimum 4 disks, must be an even number.
Usable capacity is 50% of total raw capacity.
Offers good performance (from striping) and excellent redundancy (from mirroring).
journalctl -u <service> -xe shows detailed logs including the exact error causing a systemd service failure, such as permission issues, missing files, or configuration errors.
systemctl status shows high-level state (active/failed) and Result reason
journalctl -u <service> -xe shows extended log entries with context
Common causes: wrong file ownership/permissions, missing dependencies, bad config syntax
Removing sensitive files from Git history, especially before pushing, is crucial for security. For recent, unpushed commits, amending the commit is the simplest method. For older or pushed commits, more drastic measures like `git filter-branch` or `BFG Repo-Cleaner` are needed.
`git rm --cached <file>` removes file from index but keeps local copy.
`git commit --amend` rewrites the most recent commit.
Avoid `filter-branch` unless absolutely necessary due to complexity.
MASQUERADE is a NAT target used in the POSTROUTING chain to dynamically translate the source IP of outbound packets to the address of the exiting interface, commonly used for internet-sharing gateways with dynamic IPs.
Applied in the nat table's POSTROUTING chain
Ideal for interfaces with dynamic/DHCP-assigned IPs
`ethtool` is a utility used to query or control network interface card (NIC) settings, including critical parameters like speed and duplex mode, which are vital for network troubleshooting.
Provides detailed hardware-level information about a NIC.
Can show current speed (e.g., 1000Mb/s), duplex (Full/Half), and autonegotiation status.
Useful for diagnosing duplex mismatch, which can severely degrade network performance.
The nofail mount option in /etc/fstab tells systemd not to block booting if that particular filesystem entry fails to mount, useful for optional or removable devices.
Prevents emergency mode when a device is legitimately absent
Often paired with 'noauto' for devices mounted manually or on demand
Contrast: default fstab behavior treats a failed mount as critical, halting boot
Secure credential management involves methods to protect sensitive information like API keys, passwords, and tokens from being exposed in source code, version control, or insecure files. Environment variables are a common and effective method.
Environment variables separate credentials from code.
`os.getenv()` in Python retrieves environment variable values.
Avoid hardcoding sensitive data directly in scripts.
pam_pwquality is a PAM module that enforces password strength rules (length, character classes) configured in /etc/security/pwquality.conf, typically invoked from /etc/pam.d/system-auth or password-auth.
minlen sets minimum password length
dcredit/ucredit/lcredit/ocredit control required character classes
When a RAID member fails, mdadm --manage --add hot-adds a replacement disk, and the array automatically rebuilds redundancy using parity or mirror data from surviving members.
Check status: mdadm --detail /dev/mdX or cat /proc/mdstat
Ansible manages packages using the `package` module (or specific ones like `apt`, `yum`) and services using the `service` (or `systemd`) module. These are often combined in playbooks to ensure applications are both installed and running correctly.
`package: name=pkg_name state=present` installs a package.
`service: name=svc_name state=started` starts a service.
`service: name=svc_name enabled=yes` ensures service starts on boot.
When the Set Group ID (SGID) bit is set on a directory, any new files or subdirectories created within that directory will inherit the group ownership of the parent directory.
Applied to directories only.
Ensures group inheritance for new files/subdirectories.
The `systemctl daemon-reload` command instructs the `systemd` manager to reload all unit files from disk, incorporating any changes made since the last reload.
Essential after modifying any `.service`, `.timer`, `.target`, etc., unit files.
Does not stop or start any services.
Updates `systemd`'s internal representation of unit configurations.
sudo caches successful authentication for a configurable period (default 5 minutes) so repeated sudo commands don't require re-entering the password; controlled by timestamp_timeout in /etc/sudoers.
Default timestamp_timeout is 5 minutes
Value of 0 disables caching entirely
sudo -k invalidates the cached timestamp immediately
Ansible's `service` and `systemd` modules are used to manage the state (started, stopped, restarted) and boot-time enablement (enabled, disabled) of system services on target hosts. They ensure idempotent operations.
`service` module is generic, `systemd` is specific to systemd-based systems.
`state: started` ensures the service is running.
`enabled: yes` ensures the service starts automatically at boot.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.