CertSafari

    Free CompTIA Linux+ Sample Questions

    35 free sample questions from our bank of 358+, covering every exam domain, with answers and detailed explanations. Updated October 2026.

    Domain 1: System Management

    Subdomain 1.1: Explain basic Linux concepts.

    1.A team must install Linux on 30 bare-metal servers that have no optical drives and no USB media available. They plan to use PXE boot. Which TWO services must be reachable on the network?(Select 2)

    1. A.An NTP server that signs boot manifests, because PXE firmware refuses to download an image without a verified clock
    2. B.A DHCP server that supplies the client address plus the next-server and boot filename options for the network bootloader
    3. C.A DNS server holding SRV records that the NIC firmware queries instead of DHCP to find the installation repository
    4. D.A TFTP server that serves the bootloader, such as pxelinux or grubx64.efi, along with the kernel and initrd files
    5. E.An LDAP directory that stores each MAC address and returns the matching kickstart file before the NIC firmware starts
    Show answer & explanation

    Correct answers: B, D — A DHCP server that supplies the client address plus the next-server and boot filename options for the network bootloader; A TFTP server that serves the bootloader, such as pxelinux or grubx64.efi, along with the kernel and initrd files

    • A. NIC firmware has no notion of signed manifests or a time source. Time synchronization is not part of the PXE exchange.
    • B. The firmware broadcasts a DHCP request and learns its address together with the TFTP server and boot filename. Without these options the client cannot find a bootloader.
    • C. PXE firmware discovers its boot server through DHCP options, not DNS SRV records. A repository location is only used later by the installer.
    • D. After DHCP, the firmware downloads the network bootloader over TFTP, which then fetches the kernel and initrd. TFTP is the transport used for these early files.
    • E. The firmware cannot query a directory service before it has an IP stack and a bootloader. A kickstart file may be fetched later by the installer, but LDAP is not required for PXE.

    Subdomain 1.2: Summarize Linux device management concepts and tools.

    2.A technician must load a driver module that depends on two other modules. The dependencies are listed in modules.dep, and the technician wants them resolved and loaded automatically in the right order. Which command should be used?

    1. A.insmod
    2. B.modprobe
    3. C.depmod
    4. D.modinfo
    Show answer & explanation

    Correct answer: B — modprobe

    • A. insmod loads only the single .ko file it is given and does not resolve dependencies, so it fails with unknown symbol errors when prerequisites are not already loaded.
    • B. modprobe reads modules.dep, loads the prerequisite modules first, and then the requested module, which is exactly the automatic dependency handling the technician wants.
    • C. depmod generates the modules.dep and alias files that modprobe consults, but it does not load any module itself.
    • D. modinfo only prints metadata such as the description, parameters, and dependencies of a module and never loads anything into the kernel.

    Subdomain 1.2: Summarize Linux device management concepts and tools.

    3.On a RHEL 9 host, a new storage controller driver, mpt3sas, must be built into the initramfs for the running kernel so the root volume is found at boot. Which command rebuilds the image?

    1. A.dracut --force --add-drivers "mpt3sas" /boot/initramfs-$(uname -r).img $(uname -r)
    2. B.mkinitrd -f --with=mpt3sas /boot/initrd-$(uname -r).img $(uname -r) to rebuild the image
    3. C.depmod -a mpt3sas, then grub2-mkconfig -o /boot/grub2/grub.cfg to update the menu
    4. D.insmod mpt3sas.ko /boot/initramfs-$(uname -r).img to inject the module into the boot image
    Show answer & explanation

    Correct answer: A — dracut --force --add-drivers "mpt3sas" /boot/initramfs-$(uname -r).img $(uname -r)

    • A. dracut is the initramfs generator on current RHEL releases, and --add-drivers adds the named module to the image generated for the given kernel version.
    • B. mkinitrd is the legacy tool that modern dracut-based releases no longer ship as a real generator, so this form is not the way to rebuild the image on RHEL 9.
    • C. depmod only rebuilds module index files and grub2-mkconfig only regenerates the boot menu, so neither places a driver inside the initramfs.
    • D. insmod loads a module into the running kernel and cannot modify an initramfs file, which is a compressed archive built by a separate tool.

    Subdomain 1.3: Given a scenario, manage storage in a Linux system.

    4.A team stores backups on a second disk at `/backup` and a separate NFS share at `/mnt/archive`. When the NFS server was down for maintenance, a rebooted application server hung in emergency mode. Which change to the `/etc/fstab` entries prevents this?

    1. A.Add the `noauto` option to the entries so a failing mount is retried in the background at every login
    2. B.Set the sixth field to `2` so the entries are checked by `fsck` after the root filesystem completes
    3. C.Add the `ro` option to the entries so the system skips writing to shares that are currently unavailable
    4. D.Add the `nofail` option to the entries so a missing or unreachable mount does not stop the boot
    Show answer & explanation

    Correct answer: D — Add the `nofail` option to the entries so a missing or unreachable mount does not stop the boot

    • A. `noauto` prevents mounting at boot altogether and has no retry behaviour; the shares would simply never mount automatically.
    • B. The sixth field sets the `fsck` pass order, and NFS shares are never checked by `fsck`, so it has no effect on boot failures.
    • C. `ro` makes a mount read-only after it succeeds. It does not change what happens when the device or server is unreachable.
    • D. Correct. `nofail` tells systemd that a failed or missing mount is not fatal, so boot continues instead of dropping to emergency mode.

    Subdomain 1.4: Given a scenario, manage network services and configurations on a Linux server.

    5.Before a database replication cutover, an administrator must measure achievable TCP throughput between two Linux servers on the same VLAN. Which procedure provides that measurement?

    1. A.Run `ping -f <server-ip>` from both hosts at once and read the packets-per-second figure as the available link bandwidth
    2. B.Run `nmap -sT <server-ip>` from the sending host, which reports the achievable TCP throughput on each open port it finds
    3. C.Start `iperf3 -s` on the receiving server and run `iperf3 -c <server-ip>` from the sender to report TCP throughput
    4. D.Run `ethtool -s eth0 speed 1000` on both hosts, which transmits test traffic and prints the measured throughput in Mbit/s
    Show answer & explanation

    Correct answer: C — Start `iperf3 -s` on the receiving server and run `iperf3 -c <server-ip>` from the sender to report TCP throughput

    • A. A flood ping measures ICMP echo rate with tiny packets, which does not represent TCP bandwidth, and it reports round-trip statistics rather than throughput.
    • B. `nmap -sT` performs TCP connect scans to find open ports and does not push bulk data, so it reports no throughput figures.
    • C. `iperf3` uses a server and client pair that exchange bulk TCP traffic, and the client prints the measured bandwidth per interval and in total.
    • D. `ethtool -s` changes link settings such as speed and duplex and does not generate test traffic or print measurements.

    Subdomain 1.5: Given a scenario, manage a Linux system using common shell operations.

    6.A user connects over SSH and finds that aliases defined in `~/.bashrc` are missing, while the same aliases work in a terminal opened from the desktop. The user's `~/.bash_profile` exists and contains only an `export EDITOR=vim` line. What is the most likely fix?

    1. A.Delete `~/.bashrc` and put the aliases in `/etc/hostname`, which every login shell reads for personal settings
    2. B.Rename `~/.bash_profile` to `~/.profile`, because only that file is read by interactive login shells over SSH
    3. C.Move the aliases into `~/.bash_history`, which is evaluated by every shell each time a session opens
    4. D.Add a line to `~/.bash_profile` that sources `~/.bashrc`, since login shells read the profile, not the rc file
    Show answer & explanation

    Correct answer: D — Add a line to `~/.bash_profile` that sources `~/.bashrc`, since login shells read the profile, not the rc file

    • A. `/etc/hostname` holds the system name and is never read as shell configuration. Deleting `.bashrc` would also lose the working aliases.
    • B. Renaming the file would not help, and bash reads `~/.profile` only when `~/.bash_profile` and `~/.bash_login` are absent. The aliases still would not load.
    • C. `~/.bash_history` stores previously typed commands and is not executed at startup. Placing aliases there has no effect.
    • D. An SSH session starts a login shell, which reads `~/.bash_profile` and not `~/.bashrc`. Sourcing the rc file from the profile loads the aliases in both cases.

    Subdomain 1.6: Given a scenario, perform backup and restore operations for a Linux server.

    7.An administrator created `/backup/full.tar.gz` with `tar -czf /backup/full.tar.gz /etc`. A user deleted /etc/fstab, and only that one file must be restored into /tmp/restore without unpacking the rest. Which command does this?

    1. A.`tar -xzf /backup/full.tar.gz -C /tmp/restore /etc/fstab`
    2. B.`tar -tzf /backup/full.tar.gz -C /tmp/restore etc/fstab`
    3. C.`tar -xjf /backup/full.tar.gz -C /tmp/restore etc/fstab`
    4. D.`tar -xzf /backup/full.tar.gz -C /tmp/restore etc/fstab`
    Show answer & explanation

    Correct answer: D — `tar -xzf /backup/full.tar.gz -C /tmp/restore etc/fstab`

    • A. GNU tar strips the leading slash when creating the archive, so the member is stored as etc/fstab. A pattern with a leading slash does not match it.
    • B. The -t flag only lists matching members and extracts nothing, so /tmp/restore stays empty.
    • C. The -j flag treats the archive as bzip2-compressed, but it was gzip-compressed. tar would report that the data is not in bzip2 format.
    • D. The -x and -z flags extract a gzip archive, -C changes into the target directory, and the member name etc/fstab matches the stored relative path. Only that file is written.

    Subdomain 1.7: Summarize virtualization on Linux systems.

    8.A VM's 20 GB qcow2 disk is full and must grow to 40 GB. Which TWO actions are needed so the guest can actually use the added space?(Select 2)

    1. A.Enlarge the virtual disk with qemu-img resize while the VM is off, or with virsh blockresize while it is running
    2. B.Grow the partition and filesystem inside the guest afterwards, for example with growpart and resize2fs or xfs_growfs
    3. C.Create a snapshot with virsh snapshot-create-as so the overlay file adds free blocks that the guest reports immediately
    4. D.Run qemu-img convert with -O raw, which automatically expands every partition and filesystem within the guest image
    5. E.Restart libvirtd so the daemon rescans the image header and rewrites the guest partition table to the new size
    6. F.Edit the memory element in the libvirt domain XML so the hypervisor backs the root filesystem with extra RAM space
    Show answer & explanation

    Correct answers: A, B — Enlarge the virtual disk with qemu-img resize while the VM is off, or with virsh blockresize while it is running; Grow the partition and filesystem inside the guest afterwards, for example with growpart and resize2fs or xfs_growfs

    • A. Correct. The image's virtual size must be increased first on the host; this is what makes the larger block device visible to the guest.
    • B. Correct. Enlarging the image does not change the guest's partition table or filesystem, so both must be extended from inside the guest.
    • C. Incorrect. A snapshot overlay records changes for rollback; it does not enlarge the disk presented to the guest.
    • D. Incorrect. convert rewrites the image in another format and never touches the partition layout or the filesystem.
    • E. Incorrect. libvirtd never edits the guest partition table, and restarting it does not change the virtual size of the image.
    • F. Incorrect. The memory element sets guest RAM, which is unrelated to persistent disk capacity.

    Domain 2: Services and User Management

    Subdomain 2.1: Given a scenario, manage files and directories on a Linux system.

    9.An admin must copy `/etc/app` to `/backup/app` so that ownership, permissions, timestamps, and any symbolic links inside the tree are preserved exactly as they are. Which command achieves this?

    1. A.Run `cp -u /etc/app /backup/` to copy only the files that are newer than the matching files at the destination
    2. B.Run `cp -a /etc/app /backup/` to copy recursively in archive mode, keeping attributes and links unchanged
    3. C.Run `cp -L /etc/app /backup/` so each symbolic link is followed and its target copied into the backup
    4. D.Run `cp -r /etc/app /backup/`, which preserves ownership and timestamps by default while it recurses into the tree
    Show answer & explanation

    Correct answer: B — Run `cp -a /etc/app /backup/` to copy recursively in archive mode, keeping attributes and links unchanged

    • A. `-u` only skips files that are up to date; it does not recurse or preserve attributes, and a directory needs `-R` as well.
    • B. `-a` is equivalent to `-dR --preserve=all`, so it recurses and preserves mode, ownership, timestamps, and symbolic links as links.
    • C. `-L` dereferences symlinks, which replaces links with copies of their targets, and without `-R` it will not copy a directory either.
    • D. `cp -r` recurses, but new files get the invoking user's ownership and current timestamps, and symlinks may be followed.

    Subdomain 2.2: Given a scenario, perform local account management in a Linux environment.

    10.A new developer, priya, must be created with UID 2500, the existing group `devs` as her primary group, `/bin/bash` as her shell, and a home directory created automatically. Which command accomplishes this?

    1. A.`useradd -m -u 2500 -g devs -s /bin/bash priya`
    2. B.`useradd -M -u 2500 -G devs -s /bin/bash priya`
    3. C.`useradd -m -u 2500 -g 2500 -s /bin/bash priya`
    4. D.`useradd -m -U 2500 -g devs -s /bin/bash priya`
    Show answer & explanation

    Correct answer: A — `useradd -m -u 2500 -g devs -s /bin/bash priya`

    • A. The -m flag creates the home directory, -u sets the UID, -g sets the existing group as the primary group, and -s sets the login shell. Every requirement is met.
    • B. The uppercase -M flag suppresses home directory creation, and -G only adds devs as a supplementary group, so the primary group would not be devs.
    • C. This creates the home directory, but -g 2500 assigns the primary group by numeric GID 2500, which is not necessarily the devs group.
    • D. The uppercase -U flag takes no argument; it creates a user group named after the user. The stray 2500 would be parsed as the username and the command would fail.

    Subdomain 2.3: Given a scenario, manage processes and jobs in a Linux environment.

    11.A nightly database export running as user `dbadmin` with PID 4821 is starving a web application of CPU during business hours. You must lower its priority without stopping it. Which command accomplishes this?

    1. A.Run `nice -n 10 -p 4821` to attach a new niceness to the running export process using its existing PID number
    2. B.Run `renice -n -10 -p 4821` to lower the nice value so the scheduler gives the export fewer CPU cycles than other tasks
    3. C.Run `kill -SIGSTOP 4821` followed by `bg` so the export continues running at a reduced share of the available CPU time
    4. D.Run `renice -n 10 -p 4821` to raise the nice value so the export yields CPU time to higher-priority interactive tasks
    Show answer & explanation

    Correct answer: D — Run `renice -n 10 -p 4821` to raise the nice value so the export yields CPU time to higher-priority interactive tasks

    • A. Incorrect. `nice` only sets niceness when launching a new command; it has no `-p` option for modifying a process that is already running.
    • B. Incorrect. A negative nice value raises priority rather than lowering it, so the export would receive more CPU, and only root may assign negative values.
    • C. Incorrect. SIGSTOP halts the process completely rather than reducing its share, and `bg` only resumes jobs of the current shell, not arbitrary PIDs.
    • D. Correct. `renice` changes the niceness of an already running process, and a higher nice value means a lower scheduling priority, so the export yields CPU to the web application.

    Subdomain 2.4: Given a scenario, configure and manage software in a Linux environment.

    12.A server has both OpenJDK 11 and OpenJDK 17 installed from packages. `java -version` reports 11, but a new application requires 17 for all users on this host. Which action switches the system-wide default while keeping the package manager's alternatives links intact?

    1. A.Run `ln -sf /opt/jdk-17/bin/java /usr/bin/java`, replacing the executable path directly until the next package update.
    2. B.Run `hash -r` in the shell so the cached command location is cleared and the newer installed Java binary is picked up.
    3. C.Add `export PATH=/usr/lib/jvm/jdk-17/bin:$PATH` to a single user's ~/.bashrc so that account runs the newer binary first.
    4. D.Run `update-alternatives --config java` as root and pick the entry for OpenJDK 17 from the numbered selection menu.
    Show answer & explanation

    Correct answer: D — Run `update-alternatives --config java` as root and pick the entry for OpenJDK 17 from the numbered selection menu.

    • A. Overwriting /usr/bin/java bypasses /etc/alternatives, so a later package update can silently restore the old link, and it leaves the alternatives database out of sync.
    • B. `hash -r` only clears the shell's cached command paths; it does not change which binary the alternatives symlink chain points to, so version 11 would still be used.
    • C. A PATH change in one user's ~/.bashrc affects only that account's shells, not services or other users, so it fails the system-wide requirement.
    • D. Correct. `update-alternatives --config` updates the /etc/alternatives symlink for the `java` group, which is what /usr/bin/java resolves to, making 17 the default for every user.

    Subdomain 2.4: Given a scenario, configure and manage software in a Linux environment.

    13.After editing /etc/nginx/conf.d/app.conf to add a `proxy_pass` directive, an administrator must apply the change on a busy production host without dropping established client connections. Which sequence is correct?

    1. A.Run `systemctl restart nginx` right away, because a full restart of the service is the only way to read modified configuration files.
    2. B.Run `nginx -s quit` followed by `nginx`, which stops the master process immediately and starts a new one with the updated files.
    3. C.Run `nginx -t` to validate the syntax, then `systemctl reload nginx` so workers are replaced gracefully with the new configuration.
    4. D.Run `kill -9` on the master process, because systemd then respawns the service and loads the new configuration on its own.
    Show answer & explanation

    Correct answer: C — Run `nginx -t` to validate the syntax, then `systemctl reload nginx` so workers are replaced gracefully with the new configuration.

    • A. A restart stops the master and every worker, which severs in-flight connections, and it is not the only way to apply configuration since nginx can reload gracefully.
    • B. `nginx -s quit` shuts down gracefully, but starting a new instance afterwards leaves a gap with no listener; it is also unnecessary because a reload does the swap in place.
    • C. Correct. `nginx -t` catches syntax errors before they can break the service, and a reload signals the master to start new workers with the new configuration while old workers finish existing requests.
    • D. SIGKILL terminates the master with no cleanup, dropping connections, and may leave stale PID or socket state; it is never a supported way to apply configuration.

    Subdomain 2.5: Given a scenario, manage Linux using systemd.

    14.A host that uses `systemd-resolved` cannot reach internal names. The administrator needs to see which DNS servers are assigned to each network link and test a lookup through the local resolver. Which TWO commands help?(Select 2)

    1. A.`sysctl net.ipv4.ip_forward`
    2. B.`hostnamectl status`
    3. C.`timedatectl timesync-status`
    4. D.`resolvectl query intranet.example.com`
    5. E.`resolvectl status`
    Show answer & explanation

    Correct answers: D, E — `resolvectl query intranet.example.com`; `resolvectl status`

    • A. Incorrect. This sysctl key reports whether IPv4 forwarding is enabled; it is unrelated to name resolution.
    • B. Incorrect. `hostnamectl status` shows the hostname, machine ID, operating system and kernel, with no DNS server information.
    • C. Incorrect. `timedatectl timesync-status` shows details of NTP synchronization for the system clock, not DNS configuration.
    • D. Correct. `resolvectl query` resolves a name through `systemd-resolved` and reports which link and server answered, which tests the resolver path directly.
    • E. Correct. `resolvectl status` prints the DNS servers, search domains and DNSSEC settings for the global configuration and for each link.

    Subdomain 2.6: Given a scenario, manage applications in a container on a Linux server.

    15.When a container uses the ___ network type, it shares the network namespace of the Linux host, so the application binds directly to host interfaces and port publishing with `-p` is not needed.

    1. A.host
    2. B.bridge
    3. C.macvlan
    Show answer & explanation

    Correct answer: A — host

    • A. Correct: host networking removes network isolation, so the container uses the host's interfaces and ports directly. Port mappings are unnecessary and are ignored.
    • B. Incorrect: bridge networking gives the container its own namespace and private subnet behind NAT. Ports must be published to reach it from outside.
    • C. Incorrect: macvlan gives the container its own MAC and IP address on the parent interface, in a separate namespace. It does not share the host's network stack.

    Domain 3: Security

    Subdomain 3.1: Summarize authorization, authentication, and accounting methods.

    16.After an intrusion, an administrator needs the sshd messages from the previous boot on a system where journald already has Storage=persistent set. Which command shows them?

    1. A.Run journalctl -u sshd.service -b -1 to list only the sshd unit's entries recorded during the previous boot
    2. B.Run journalctl -k -b 0 to read the kernel ring buffer messages that were recorded since the current boot began
    3. C.Run journalctl -u sshd.service -f to follow the unit's journal output live as new entries arrive in real time
    4. D.Run journalctl -p err -b to list every error-level message from all units that were logged since the system booted
    Show answer & explanation

    Correct answer: A — Run journalctl -u sshd.service -b -1 to list only the sshd unit's entries recorded during the previous boot

    • A. -u limits output to one unit and -b -1 selects the boot before the current one, which works because the journal is stored persistently. Together they return the sshd messages from the previous boot.
    • B. -k restricts output to kernel messages and -b 0 is the current boot. This neither selects sshd nor reaches the previous boot.
    • C. -f follows new entries live, much like tail -f. It shows sshd's current activity and does not go back to a prior boot.
    • D. -p err filters by priority across all units, and -b with no offset means the current boot. It would miss non-error sshd messages and the earlier boot.

    Subdomain 3.1: Summarize authorization, authentication, and accounting methods.

    17.To search the audit log for every event that carries the key identity, an administrator runs ______.

    1. A.ausearch -k identity
    2. B.auditctl -k identity
    3. C.aureport --failed
    Show answer & explanation

    Correct answer: A — ausearch -k identity

    • A. ausearch -k identity queries the audit log for events tagged with that key, which is how keys set in audit.rules are used to retrieve events later.
    • B. auditctl manages rules and status of the kernel audit system, so it does not search stored log events. It would not return the tagged records.
    • C. aureport --failed produces a summary report of failed events and does not filter by key. It would not list the identity-tagged events.

    Subdomain 3.2: Given a scenario, configure and implement firewalls on a Linux system.

    18.A custom application listens on TCP 8443 and must be reachable through the active `public` zone immediately and after every reboot. Which TWO command sequences achieve this?(Select 2)

    1. A.Run `firewall-cmd --zone=public --add-port=8443/tcp --permanent`, then run `firewall-cmd --reload` to load the stored configuration into runtime
    2. B.Run `firewall-cmd --zone=public --add-port=8443/tcp`, then run `firewall-cmd --runtime-to-permanent` to save the active runtime state to disk
    3. C.Run `firewall-cmd --zone=public --add-port=8443 --permanent`, then run `firewall-cmd --reload` so the numeric port opens for every protocol
    4. D.Run only `firewall-cmd --zone=public --add-port=8443/tcp --permanent` and expect the port to be reachable at once, with no reload needed
    5. E.Run `firewall-cmd --permanent --zone=public --add-service=8443`, then reload, so firewalld treats the number as a built-in service name
    Show answer & explanation

    Correct answers: A, B — Run `firewall-cmd --zone=public --add-port=8443/tcp --permanent`, then run `firewall-cmd --reload` to load the stored configuration into runtime; Run `firewall-cmd --zone=public --add-port=8443/tcp`, then run `firewall-cmd --runtime-to-permanent` to save the active runtime state to disk

    • A. Correct. The `--permanent` flag writes the port to the stored zone, and the reload then applies the stored configuration to the running firewall. The port is open now and after reboot.
    • B. Correct. Adding the port to runtime opens it immediately, and `--runtime-to-permanent` writes the current runtime state to the permanent configuration so it persists.
    • C. Incorrect. firewalld requires a protocol suffix such as `/tcp` when adding a port. A bare number is rejected as an invalid port specification.
    • D. Incorrect. A `--permanent` change does not touch the running firewall. Without a reload, the port stays closed until the next reload or reboot.
    • E. Incorrect. `--add-service` expects a defined service name such as `https`, and 8443 is not one. The command fails with an invalid service error.

    Subdomain 3.3: Given a scenario, apply operating system (OS) hardening techniques on a Linux system.

    19.Apache on an SELinux enforcing server cannot connect to a remote database, and the audit log shows AVC denials for the httpd_t domain. Which two actions fix this properly while keeping SELinux enforcing?(Select 2)

    1. A.Run setsebool -P httpd_can_network_connect_db on so the allowance survives a reboot.
    2. B.Run setenforce 0 so SELinux logs the denials as warnings and stops blocking the connection.
    3. C.Run sealert -a /var/log/audit/audit.log to read the analysis that points to the boolean to change.
    4. D.Run chcon -t httpd_sys_content_t on the database client library so httpd may open outbound sockets.
    5. E.Run semanage fcontext to map the database port to the httpd_sys_content_t label across reboots.
    Show answer & explanation

    Correct answers: A, C — Run setsebool -P httpd_can_network_connect_db on so the allowance survives a reboot.; Run sealert -a /var/log/audit/audit.log to read the analysis that points to the boolean to change.

    • A. Correct. setsebool -P changes the boolean persistently, permitting httpd to connect to database ports while the system stays in enforcing mode.
    • B. Incorrect. setenforce 0 moves the whole system to permissive mode, which stops enforcement for every domain and does not survive a reboot.
    • C. Correct. sealert parses the audit log and suggests remedies, usually naming the boolean that matches the denied access.
    • D. Incorrect. File labels such as httpd_sys_content_t govern file access, not outbound network connections, so relabeling a library cannot allow the socket.
    • E. Incorrect. semanage fcontext maps file paths to labels; it cannot label a network port, which would need semanage port, and content type is not the fix.

    Subdomain 3.4: Explain account hardening techniques and best practices.

    20.A junior analyst needs a login shell that lets them run only the tools symlinked in `/home/analyst/bin`. The shell must block `cd`, changes to `PATH`, and any command name containing a slash. Which configuration meets this?

    1. A.Set the login shell to `/sbin/nologin` and expose the symlink directory to the analyst through a `ForceCommand` entry in `sshd_config`
    2. B.Set the login shell to `/bin/bash` and mount the home directory with the `noexec` option so unapproved commands cannot be launched there
    3. C.Set the login shell to `/bin/sh` and add the analyst to a group named `restricted` in `/etc/group` to switch on the shell limits
    4. D.Set the login shell to `/bin/rbash` and define `PATH` as the symlink directory in a root-owned profile file the analyst cannot edit
    Show answer & explanation

    Correct answer: D — Set the login shell to `/bin/rbash` and define `PATH` as the symlink directory in a root-owned profile file the analyst cannot edit

    • A. `/sbin/nologin` refuses the login altogether, so the analyst would never reach a prompt. `ForceCommand` runs a single fixed command for SSH sessions and does not give a restricted interactive shell.
    • B. `noexec` only stops binaries stored on that mount from being executed. It does not block `cd`, PATH changes, or slash-containing command names, and the approved symlinks point to programs on other filesystems anyway.
    • C. A group called `restricted` has no special meaning to the shell. Group membership alone cannot switch on restrictions, and the plain `sh` shell would allow every command the analyst types.
    • D. `/bin/rbash` is bash in restricted mode, which forbids `cd`, assigning `PATH`, and commands containing slashes. Pointing `PATH` at the symlink directory from a file the user cannot modify leaves only the approved tools runnable.

    Subdomain 3.5: Explain cryptographic concepts and technologies in a Linux environment.

    21.A technician must protect the data on a laptop's secondary partition, `/dev/sdb1`, so that the contents are unreadable if the drive is stolen. The partition must be unlocked with a passphrase before use. Which approach implements this?

    1. A.Run `mkfs.ext4 /dev/sdb1` and set `chattr +e` on the mount point so every file written to the partition is encrypted on disk.
    2. B.Run `gpg --symmetric /dev/sdb1` and mount the resulting `.gpg` file as a loop device so the filesystem decrypts transparently at boot.
    3. C.Run `cryptsetup luksFormat --type luks2 /dev/sdb1`, unlock it with `cryptsetup open`, then create the filesystem on the mapped device.
    4. D.Run `openssl enc -aes-256-cbc -in /dev/sdb1 -out /dev/sdb1` so the raw partition is overwritten in place with the ciphertext output.
    Show answer & explanation

    Correct answer: C — Run `cryptsetup luksFormat --type luks2 /dev/sdb1`, unlock it with `cryptsetup open`, then create the filesystem on the mapped device.

    • A. Incorrect. The `chattr +e` flag only marks extents on ext4 and does not encrypt anything. Native ext4 encryption would need fscrypt, and the drive's raw contents would remain readable.
    • B. Incorrect. GPG encrypts individual files or streams and cannot expose a block device as a transparently decrypted filesystem; it provides no loop-device mount integration.
    • C. Correct. LUKS2 through `cryptsetup` encrypts the whole block device, and the filesystem is created on the decrypted mapper device, so everything stored on the partition is ciphertext without the passphrase.
    • D. Incorrect. Reading and writing the same device with `openssl enc` corrupts the data while it is being processed, and the result is a raw encrypted blob with no mountable filesystem or key management.

    Subdomain 3.6: Explain the importance of compliance and audit procedures.

    22.A vulnerability scanner reports ten findings for a web server. Two are CVEs scored CVSS 9.8 on an internet-facing service, and eight are CVEs scored 3.1 on an internal-only service. The team can patch only a few items this week. How should they prioritize?

    1. A.Patch the eight low-scored items first, since each is quick to fix and removing more CVE entries lowers total risk the most
    2. B.Patch the items in alphabetical order of package name so that every finding is handled consistently across all servers
    3. C.Patch the two critical items first, because a CVSS score near 10 on an exposed service signals easy, high-impact exploitation
    4. D.Ignore every finding until a CVE entry appears in a vendor advisory, since scanner output alone cannot rank remediation work this week
    Show answer & explanation

    Correct answer: C — Patch the two critical items first, because a CVSS score near 10 on an exposed service signals easy, high-impact exploitation

    • A. Counting findings does not measure risk. Eight low-severity CVEs on an internal-only service together carry far less exposure than two critical issues reachable from the internet.
    • B. Alphabetical ordering has no relation to severity or exposure. Remediation order should come from CVSS scores combined with how reachable the vulnerable service is.
    • C. CVSS rates how severe a CVE is, and a 9.8 on an internet-facing service combines high impact with high exposure. Patching those two first reduces the most risk with limited time.
    • D. Every scanner finding that references a CVE already maps to a published entry with a CVSS score. Waiting for extra advisories delays remediation and leaves critical exposure open.

    Domain 4: Automation, Orchestration, and Scripting

    Subdomain 4.1: Summarize the use cases and techniques of automation and orchestration in a Linux environment.

    23.A team wants the state of its Kubernetes cluster to always match declarative manifests in a Git repository, with manual cluster edits detected and reverted automatically. Which approach implements this?

    1. A.A nightly cron job on an administrator's laptop that runs `kubectl apply` against every cluster from a local checkout
    2. B.A pipeline that connects over SSH to the nodes once per release and copies edited YAML files into the kubelet directory
    3. C.A shared wiki of runbooks where operators record each cluster change after they make it with `kubectl edit`
    4. D.A GitOps controller such as Argo CD or Flux that continuously reconciles live objects against the repository
    Show answer & explanation

    Correct answer: D — A GitOps controller such as Argo CD or Flux that continuously reconciles live objects against the repository

    • A. Incorrect: a scheduled push from one laptop is not continuous reconciliation, and drift between runs stays in place.
    • B. Incorrect: a one-time push per release does not watch the cluster, so manual changes remain until the next release.
    • C. Incorrect: documentation after the fact leaves Git out of the control loop and permits exactly the drift GitOps removes.
    • D. Correct: GitOps treats Git as the source of truth, and an in-cluster controller pulls manifests and corrects deviation automatically.

    Subdomain 4.2: Given a scenario, perform automated tasks using shell scripting.

    24.A script is saved as `report.sh` and made executable. The author wants the kernel to launch it with whichever `bash` appears first in the user's `PATH`. Which first line of the file achieves this?

    1. A.#/usr/bin/env bash
    2. B.$!/usr/bin/env bash
    3. C.!#/usr/bin/env bash
    4. D.#!/usr/bin/env bash
    Show answer & explanation

    Correct answer: D — #!/usr/bin/env bash

    • A. Without the exclamation mark the line is only a comment, so the kernel does not recognise an interpreter and the current shell runs the file.
    • B. The sequence $! expands to the PID of the last background job and has no meaning as the first two bytes of an executable script.
    • C. Reversing the characters to !# is not a recognised magic number, so the kernel will not treat the line as an interpreter directive.
    • D. The #! interpreter directive followed by env lets the kernel use env to search PATH for bash, which is a portable way to select the interpreter.

    Subdomain 4.3: Summarize Python basics used for Linux system administration.

    25.In Python, the Boolean value of an empty string, as returned by `bool("")`, is ___ , so an `if` test on it skips its block.

    1. A.`True`
    2. B.`False`
    3. C.`None`
    Show answer & explanation

    Correct answer: B — `False`

    • A. Incorrect. Only non-empty strings are truthy, and an empty string has no characters.
    • B. Correct. Empty strings, empty lists and dictionaries, `0` and `None` all evaluate as false in a Boolean context.
    • C. Incorrect. `bool()` always returns either `True` or `False`, never `None`.

    Subdomain 4.4: Given a scenario, implement version control using Git.

    26.A developer has three unpushed commits on `feature/api`, while `main` has gained several new commits. The team wants a linear history without a merge commit. Which TWO steps are part of doing this correctly?(Select 2)

    1. A.Run `git rebase main` while `feature/api` is checked out to replay the local commits on top of the current tip of `main`.
    2. B.Run `git merge main` on `feature/api`, which rewrites the three local commits so the history becomes linear.
    3. C.After resolving a conflict, stage the files with `git add` and run `git rebase --continue` to proceed to the next commit.
    4. D.Rebase the shared `origin/feature-api` branch after teammates pulled it, and publish it with a plain `git push`.
    5. E.Run `git rebase --abort` after fixing each conflict so Git accepts the resolved files and continues replaying commits.
    Show answer & explanation

    Correct answers: A, C — Run `git rebase main` while `feature/api` is checked out to replay the local commits on top of the current tip of `main`.; After resolving a conflict, stage the files with `git add` and run `git rebase --continue` to proceed to the next commit.

    • A. Correct. Rebasing rewrites the local commits so they start from the latest `main`, which yields a linear history without a merge commit.
    • B. Incorrect. A merge never rewrites existing commits. It adds a merge commit that joins the two histories, so the result is not linear.
    • C. Correct. During a rebase each conflicting commit stops the replay, and staging the resolution followed by `--continue` lets Git finish that commit and move on.
    • D. Incorrect. Rebasing published commits changes their hashes and diverges from teammates' copies, and a plain push is rejected as non-fast-forward.
    • E. Incorrect. `git rebase --abort` cancels the whole rebase and restores the branch to its original state, discarding the conflict resolution already done.

    Subdomain 4.5: Summarize best practices and responsible uses of artificial intelligence (AI).

    27.Company policy permits AI use only through an approved internal gateway. A developer finds that a public AI tool is faster for documenting a script that contains internal hostnames. What should the developer do?

    1. A.Use the public tool after replacing the company name with a placeholder, since hostnames alone are never treated as sensitive information.
    2. B.Use the approved internal gateway for the task, and ask the security team to review the request if the gateway lacks a needed feature.
    3. C.Use the public tool from a personal laptop outside the VPN, which keeps the work separate from corporate systems and policy scope.
    4. D.Use the public tool for a first draft only, then copy the finished documentation into the internal wiki without telling anyone.
    Show answer & explanation

    Correct answer: B — Use the approved internal gateway for the task, and ask the security team to review the request if the gateway lacks a needed feature.

    • A. Internal hostnames reveal network layout, and renaming the company does not remove them. Hostnames can be sensitive, and the policy still requires the approved gateway.
    • B. Following corporate policy means using the approved gateway, and escalating missing capabilities to the security team keeps the work compliant while addressing the usability gap.
    • C. Corporate policy applies to company data regardless of which device processes it. Using a personal laptop only hides the violation and moves the data further from organizational control.
    • D. A draft produced by an unapproved tool still involves sending internal data to it. Concealing this from others makes the policy breach worse.

    Subdomain 4.5: Summarize best practices and responsible uses of artificial intelligence (AI).

    28.An AI assistant rewrites a nightly log-processing script so that a slow shell loop becomes a single `awk` pipeline. The rewritten version runs much faster in one test. What should the team do before adopting it?

    1. A.Adopt it after the single faster run, since shorter runtime proves the rewritten version produces identical output for all inputs.
    2. B.Ask the assistant to certify that behavior is unchanged, and accept its written assurance in place of any regression testing.
    3. C.Compare output with the original on representative data, benchmark both versions, and review it like any other code change.
    4. D.Install it only on the scheduler host and leave the version-controlled original unchanged, so the two cannot be compared later.
    Show answer & explanation

    Correct answer: C — Compare output with the original on representative data, benchmark both versions, and review it like any other code change.

    • A. Speed says nothing about correctness. A faster rewrite can drop edge cases such as unusual delimiters or empty fields while still completing quickly.
    • B. A model's assurance is not verification. Behavior changes must be demonstrated by tests, not by the generating tool's own statement.
    • C. Comparing outputs on representative data confirms the optimization preserves behavior, benchmarking confirms the gain, and code review applies normal quality assurance to AI-generated changes.
    • D. Keeping the change out of version control removes traceability and review. It prevents the comparison that responsible use of AI-driven optimization requires.

    Domain 5: Troubleshooting

    Subdomain 5.1: Summarize monitoring concepts and configurations in a Linux system.

    29.An administrator configures SNMP polling between monitoring servers and devices across an untrusted network. Which TWO settings improve the security of this setup?(Select 2)

    1. A.Grant read-write access to the monitoring user so the server can reset counters on the devices whenever this is needed
    2. B.Use SNMPv3 with the authPriv security level so that requests are authenticated and the payload is encrypted in transit
    3. C.Keep the default `public` community string with SNMPv2c because that community is only ever used for read access
    4. D.Expose the complete MIB tree to every account so that troubleshooting never requires a later change in access settings
    5. E.Restrict each SNMP agent to accept requests only from the monitoring server IP address using access control or firewall rules
    Show answer & explanation

    Correct answers: B, E — Use SNMPv3 with the authPriv security level so that requests are authenticated and the payload is encrypted in transit; Restrict each SNMP agent to accept requests only from the monitoring server IP address using access control or firewall rules

    • A. Incorrect. Write access lets an attacker or mistake change device configuration; monitoring only needs read access.
    • B. Correct. SNMPv3 authPriv adds per-user authentication and encryption, unlike community strings which travel in clear text.
    • C. Incorrect. The default `public` string is widely known, and SNMPv2c sends it unencrypted, so anyone on the path can read it.
    • D. Incorrect. Exposing every object to all accounts widens the information an attacker can collect; views should be limited to what monitoring needs.
    • E. Correct. Limiting accepted sources shrinks the exposure, so only the monitoring server can query the agent.

    Subdomain 5.2: Given a scenario, analyze and troubleshoot hardware, storage, and Linux OS issues.

    30.A rack server shows no fan activity or LEDs when the power button is pressed, and its BMC network port is also dead, while other servers on the same PDU run normally. What should be checked first?

    1. A.Reseat the power cords and test each power supply, since a failed PSU or loose cord leaves the whole chassis, BMC included, unpowered.
    2. B.Boot from rescue media and run `grub2-mkconfig`, since a corrupted GRUB configuration prevents the server from drawing power at all.
    3. C.Review `journalctl -b -1` for the previous boot's errors, since the logs will show why the hardware refused to turn on at startup.
    4. D.Run `fsck -f` on the root volume from the previous session, since filesystem corruption stops the power button from signalling the board.
    Show answer & explanation

    Correct answer: A — Reseat the power cords and test each power supply, since a failed PSU or loose cord leaves the whole chassis, BMC included, unpowered.

    • A. With no fans, LEDs, or BMC standby power, the fault is in the power path. Cords and PSUs are the cheapest first checks.
    • B. GRUB runs only after firmware has started the CPU. It cannot stop a chassis from receiving power.
    • C. Logs are written by a running OS and cannot be read from a machine without power. They also would not explain a dead BMC.
    • D. Filesystem state is irrelevant before the hardware powers on. fsck needs a running system.

    Subdomain 5.5: Given a scenario, analyze and troubleshoot performance issues.

    31.A host has a load average far above its core count while CPU idle stays high. Which TWO checks would best identify what the blocked processes are waiting for?(Select 2)

    1. A.Run `ps -eo state,pid,wchan:20,cmd` and filter `D` state to see where tasks are blocked in the kernel
    2. B.Run `iostat -x 1` to look for devices with high `await` or `%util` that may be stalling those tasks
    3. C.Run `chronyc tracking` to measure clock offset, since time drift directly increases the scheduler run queue
    4. D.Run `ulimit -a` to display the maximum number of processes, which is the value the load average reports
    5. E.Run `sysctl -a | grep hostname` to confirm the node name, since it determines the I/O scheduler selection
    Show answer & explanation

    Correct answers: A, B — Run `ps -eo state,pid,wchan:20,cmd` and filter `D` state to see where tasks are blocked in the kernel; Run `iostat -x 1` to look for devices with high `await` or `%util` that may be stalling those tasks

    • A. Correct. Listing `D`-state tasks with their wait channel shows exactly where in the kernel they are blocked, such as a filesystem or NFS call.
    • B. Correct. High `await` or `%util` on a device confirms that storage latency is stalling the blocked tasks.
    • C. Incorrect. Clock offset reported by chrony does not change how many tasks are runnable or blocked.
    • D. Incorrect. `ulimit -a` shows resource limits for the shell and is not a measurement of load average.
    • E. Incorrect. The hostname has no relation to I/O scheduler selection or to why processes are blocked.

    Subdomain 5.3: Given a scenario, analyze and troubleshoot networking issues on a Linux system.

    32.After a tunnel to a branch office was added, `ping 10.20.0.5` succeeds and SSH logins work, but `scp` of large files stalls. A packet capture shows full-size packets leaving eth0 with no replies. Which action best confirms the cause?

    1. A.Run `ethtool -s eth0 speed 1000 duplex full autoneg off` to force the link settings, then repeat the large file transfer
    2. B.Run `resolvectl flush-caches` so stale name entries are discarded, then repeat the large file transfer to the remote host
    3. C.Run `ping -M do -s 1472 10.20.0.5` and lower the size step by step until replies return, revealing the usable path MTU
    4. D.Run `ip neigh flush all` so the ARP table is rebuilt from scratch, then retry the scp transfer to the branch office
    Show answer & explanation

    Correct answer: C — Run `ping -M do -s 1472 10.20.0.5` and lower the size step by step until replies return, revealing the usable path MTU

    • A. Incorrect. Forcing speed and duplex addresses link negotiation faults, which would also hurt small packets and SSH. The symptom of only large packets failing points to size limits instead.
    • B. Incorrect. Flushing resolver caches only affects name lookups, and the connection already works by address. Name resolution has no effect on packets of a particular size being dropped.
    • C. Correct. Setting the don't-fragment flag with a large payload shows where packets stop passing, which exposes an MTU mismatch caused by tunnel overhead. Small pings and SSH work because their packets fit.
    • D. Incorrect. Neighbor entries only map next-hop addresses to MAC addresses, and small packets already reach the same next hop. A stale ARP entry would not break only large transfers.

    Subdomain 5.3: Given a scenario, analyze and troubleshoot networking issues on a Linux system.

    33.An admin ran `firewall-cmd --add-service=https` on a web server and HTTPS worked immediately. After `firewall-cmd --reload` later that day, clients can no longer connect on port 443. What explains this?

    1. A.The https service definition is removed when firewalld reloads, so the port has to be opened with a manual `iptables -A` rule
    2. B.The rule was added only to the runtime configuration, so it must be repeated with `--permanent` and reloaded to survive
    3. C.The zone's target switched to ACCEPT on reload, which makes the kernel reset all inbound TLS handshakes from clients
    4. D.NetworkManager moved the interface into the trusted zone on reload, which blocks services that were added to the public zone
    Show answer & explanation

    Correct answer: B — The rule was added only to the runtime configuration, so it must be repeated with `--permanent` and reloaded to survive

    • A. Incorrect. Service definitions ship with firewalld and persist across reloads. Mixing in raw iptables rules is neither required nor how the permanent state is kept.
    • B. Correct. Without `--permanent`, firewalld changes apply only to the running state. A reload rebuilds rules from the saved configuration, which does not contain the service.
    • C. Incorrect. An ACCEPT target would permit traffic rather than block it. Zone targets are also unchanged by a reload and do not break TLS handshakes.
    • D. Incorrect. The trusted zone accepts all traffic, so moving to it would open ports instead of closing them. The zone assignment is not what changed.

    Subdomain 5.4: Given a scenario, analyze and troubleshoot security issues on a Linux system.

    34.From a RHEL client, `curl https://intranet.example.com` fails with 'unable to get local issuer certificate'. The server certificate is unexpired, the hostname matches, and it was issued by the company's internal CA. Which TWO actions should be taken?(Select 2)

    1. A.Copy the internal root CA certificate to /etc/pki/ca-trust/source/anchors/ and run `update-ca-trust` for system-wide trust
    2. B.Run `update-crypto-policies --set LEGACY` so the client accepts certificates issued by authorities that it does not know about
    3. C.Set `SSLVerifyClient require` in the web server configuration so that the client presents a certificate during the handshake
    4. D.Check the chain with `openssl s_client -connect intranet.example.com:443 -showcerts` and have the server send its intermediate
    5. E.Regenerate the server key with `openssl genrsa 4096` so the issuer chain is rebuilt automatically on the next restart
    Show answer & explanation

    Correct answers: A, D — Copy the internal root CA certificate to /etc/pki/ca-trust/source/anchors/ and run `update-ca-trust` for system-wide trust; Check the chain with `openssl s_client -connect intranet.example.com:443 -showcerts` and have the server send its intermediate

    • A. Correct. Placing the private root CA in the anchors directory and running `update-ca-trust` makes it trusted system-wide for TLS clients.
    • B. Incorrect. Crypto policies restrict algorithms and protocols and never add trusted issuers.
    • C. Incorrect. That enables client certificate authentication, which does not supply the missing issuer the client needs for chain validation.
    • D. Correct. A server that omits the intermediate CA forces clients to find the issuer on their own, which produces this error.
    • E. Incorrect. A new key does not change the issuer chain, and a certificate must be re-issued by the CA to match any new key.

    Subdomain 5.4: Given a scenario, analyze and troubleshoot security issues on a Linux system.

    35.An admin ran `chcon -R -t httpd_sys_content_t /srv/web`, but the label reverted after a full relabel. To make the label persist, the admin must first record a rule with ____ and then apply it using `restorecon`.

    1. A.semanage fcontext -a -t
    2. B.chcon --reference
    3. C.setsebool -P
    Show answer & explanation

    Correct answer: A — semanage fcontext -a -t

    • A. Correct. `semanage fcontext` stores a file context rule in the policy, which `restorecon` uses to apply the label persistently.
    • B. Incorrect. `chcon` changes a label directly on disk and does not record anything, so a relabel discards it.
    • C. Incorrect. `setsebool` toggles policy booleans and does not define file labels.

    Want the full experience?

    These are just samples. Practice the full CompTIA Linux+ question bank in quiz mode — free, no signup, with domain practice and exam simulation.