TT Lab
Get started
Learn Learning paths Courses

LFCS — Linux Foundation System Administrator

LFCS Mock Exam A

Continue in TT Lab

Goal

You solve 18 tasks in 120 minutes under the same conditions as the real LFCS exam. The passing line is 67% and scoring is partial credit, so if you pass 13 of the 18 tasks, you pass.

The real exam environment

How to solve this practice exam

  1. Do not look at the hints; solve everything through first. After you have skimmed all 18, open the hints only for the ones you got stuck on then.
  2. Do not do web searches. Solve with man and --help only. This is the most important practice for this exam. In the real exam room there is no search box.
  3. If you cannot remember a command name, look for it with man -k <키워드> or apropos <키워드> (the placeholder is a keyword). For example, you write man -k acl, man -k quota, and man -k "file system". If you do not practice this now, you will be doing it for the first time in the exam room.
  4. If you need the section number, write it like man 5 fstab. Configuration files are in section 5 and administrator commands are in section 8.

How this environment differs from the real exam

The lab Pod has almost no kernel privileges and systemd does not run as PID 1. So mount, systemctl, and iptables do not work here. We framed the knowledge of the same domains in a form you can verify in this environment. In the real exam all three of these work, so think of the fstab entries and unit files you make here as leading on, in the exam room, to mount -a and systemctl enable --now.

Steps

  1. In /root/exam/find/src/, create five files, data-01.txt through data-05.txt. Each of data-01–data-03 must be at least 200000 bytes, and each of data-04–data-05 must be at least 1 byte and under 4096 bytes. In the same directory, create a hard link data-01.hard pointing to data-01.txt. Then write only the names of the regular files directly under src whose size exceeds 100 KiB to /root/exam/find/big.txt, and only the names of those whose hard link count is 2 or more to /root/exam/find/links.txt. In both files, write only the names, one per line, in LC_ALL=C sort order.
  2. From /etc/services, pick the entries whose protocol is tcp and whose port number is between 1024 and 2000 inclusive, and write them to /root/exam/text/tcp-high.txt. On each line, write <포트> <서비스 이름> (port, then service name) separated by a single space, and for the service name use the first field of that line. Sort by port number in ascending order and keep only one of identical lines.
  3. In /root/exam/arch/src/, create five files, log-01.txt through log-05.txt, each at least 20000 bytes, and one file with the extension .tmp. In /root/exam/arch/, create a tar archive of the src directory compressed with gzip, /root/exam/arch/backup.tar.gz, but exclude the .tmp file. Write the list of entries contained in that archive, in LC_ALL=C sort order, to /root/exam/arch/members.txt.
  4. Create a group ops with GID 4200 and a group audit with GID 4201. Create a user deploy with UID 4300 with primary group ops, supplementary group audit, login shell /bin/bash, and home /home/deploy, actually create the home directory, and set its permissions to 750 and its ownership to deploy:ops. Set the password policy of deploy to a minimum change interval of 7 days, a maximum usage period of 60 days, and 14 days of expiry warning, and specify the account expiry date as 2027-06-30.
  5. Create a user intern with UID 4301. Set the login shell to /usr/sbin/nologin, actually create the home, and put it in ops as a supplementary group. Set a password for intern once, and then lock that account. Finally, change the defaults in /etc/login.defs to PASS_MAX_DAYS 90, PASS_MIN_DAYS 7, PASS_WARN_AGE 14, and UMASK 027.
  6. Create the directories /srv/data and /srv/scratch and add two entries to /etc/fstab. The first has the device UUID=2f9c1a70-0007-4e00-9a00-000000000007, mount point /srv/data, type ext4, options defaults,nofail, dump 0, and pass 2. The second has the device tmpfs, mount point /srv/scratch, type tmpfs, options rw,nosuid,nodev,noexec,size=256m, dump 0, and pass 0. You cannot run mount in this Pod, so stop at writing the entries.
  7. Create /root/exam/storage/data.img with exactly 134217728 bytes and make an ext4 filesystem on that file. The volume label is EXAMDATA and the reserved block percentage is 1%. Write the UUID of the created filesystem on one line to /root/exam/storage/data.uuid.
  8. Create /root/exam/storage/sparse.img as a sparse file with an apparent size of 536870912 bytes (its actual usage must be nearly 0). Create /root/exam/storage/dense.img as a file with 4 MiB actually allocated. Then write the three lines below to /root/exam/storage/usage.txt. The values are integers in KiB. sparse_apparent_kib=<sparse.img 의 겉보기 크기> (the apparent size of sparse.img) sparse_actual_kib=<sparse.img 이 실제로 차지하는 크기> (the size sparse.img actually occupies) dense_actual_kib=<dense.img 이 실제로 차지하는 크기> (the size dense.img actually occupies)
  9. Create the shared directory /srv/team, and set its ownership to root:ops and its permissions to 2770. With ACLs give deploy rwx and intern r-x, and set a default ACL so that files newly created under this directory have rwx for the owning group and no permissions for other users. The owner entry of the default ACL is rwx.
  10. In /etc/hosts, register 10.60.0.11 as web1.lab.internal with the short name web1, and 10.60.0.12 as db1.lab.internal with the short name db1. Then make files come before dns in the hosts: line of /etc/nsswitch.conf. All four names must resolve with getent hosts.
  11. Create /etc/ssh/sshd_config.d/90-exam.conf and write the following seven items in this file: PermitRootLogin no, PasswordAuthentication no, MaxAuthTries 3, ClientAliveInterval 300, ClientAliveCountMax 2, AllowTcpForwarding no, X11Forwarding no. The configuration must be syntactically correct and the final values sshd interprets must be exactly these. You do not need to restart the daemon.
  12. Start, in the background, a process that accepts connections on TCP port 9101 of 127.0.0.1 and keep it alive until the exam ends. Then find the process holding that socket and write the three lines below to /root/exam/net/listener.txt: port=9101, pid=<그 프로세스의 PID>, comm=<그 프로세스의 이름> (pid= followed by that process's PID, and comm= followed by that process's name).
  13. Query this Pod's current network state and write it to /root/exam/net/facts.txt in four lines: iface=<기본 경로가 나가는 인터페이스 이름>, ipv4=<그 인터페이스의 IPv4 주소를 프리픽스까지 포함해>, mtu=<그 인터페이스의 MTU>, gateway=<기본 경로의 게이트웨이 주소> (respectively: the name of the interface the default route goes out through, that interface's IPv4 address including the prefix, that interface's MTU, and the default route's gateway address).
  14. Create /usr/local/bin/labhub-batch.sh, give it execute permission, and write the unit file /etc/systemd/system/labhub-batch.service. [Unit] must have a Description, and both Wants and After must be network-online.target. In [Service], Type is oneshot, ExecStart is /usr/local/bin/labhub-batch.sh, and WorkingDirectory is /srv/data. In [Install], WantedBy is multi-user.target. In this Pod systemd does not run as PID 1, so systemctl enable does not work, so create by hand the symbolic link that command would make, /etc/systemd/system/multi-user.target.wants/labhub-batch.service.
  15. Create /usr/local/bin/labhub-report.sh and /usr/local/bin/labhub-weekly.sh and set both to permissions 755. Create /etc/cron.d/labhub-report and register it to run /usr/local/bin/labhub-report.sh every 15 minutes as root, with that file's permissions 644 and ownership root:root. And in root's crontab, register a line that runs /usr/local/bin/labhub-weekly.sh every Sunday at 02:30.
  16. Create /var/log/labhub-app.log and write /etc/logrotate.d/labhub-app so that this log is rotated daily and up to 14 are kept. Turn on compress, delaycompress, missingok, and notifempty, and make the new file after rotation be created with create 0640 root adm.
  17. Create /usr/local/bin/exam-worker.sh and give it permissions 755. The first line must start with a shebang, and the content can be anything that keeps running without exiting. Run it in the background with a nice value of 15, and write that process's PID on one line to /run/exam-worker.pid. The process must be alive until grading time.
  18. Install the packages figlet and pv (this environment has no internet and the /opt/localrepo offline repository is already registered). Write the names and versions of the two installed packages to /root/exam/ops/pkg.txt, one per line, in the format <패키지 이름> <버전> (package name, then version). Finally, lock only pv so that it is excluded from automatic upgrades.

Notes

Picking files that match size and link conditions with find

The unit of -size +100k is KiB, and -links +1 selects those with a hard link count of 2 or more. To print only names, use %f of -printf, and fix the sorting with LC_ALL=C sort. A hard link is ln and a symbolic link is ln -s.

Filtering entries from /etc/services by condition

The second field of each line has the form 포트/프로토콜 (port/protocol). Split on the slash with split() in awk and then compare the numbers. Sorting by port ascending and removing duplicates is done with a single sort -n -u.

Making a tar archive excluding a particular extension

In tar, c is create, z is gzip, and f is the file name. Exclude with --exclude, and wrap the pattern in quotes so that the shell does not expand it first. Extract the contained list again with tar -tzf.

Creating groups and users, and the password expiry policy

Combine groupadd -g and the -u -g -G -s -m -d of useradd. Set the password policy with chage, and the account expiry date is chage -E. Look at man 8 useradd and man 1 chage. You may need to set the home directory's permissions and ownership separately after useradd has created it.

A login-blocked account and the default password policy

If you give the shell as /usr/sbin/nologin, login is blocked. Locking is usermod -L or passwd -l, but if you lock an account that has no password at all, only the lock marker remains and there is no hash. Put in the password first with chpasswd and then lock. The defaults are in /etc/login.defs.

Writing two fstab entries

man 5 fstab gives the meaning of all six fields. The order is device, mount point, type, options, dump, pass. You must create the mount point directories beforehand. To check only the syntax, use findmnt --verify --tab-file /etc/fstab.

Making ext4 on a file and reading the superblock

Making an empty file of an exact size is truncate -s. mkfs.ext4 can also make a filesystem on a file that is not a block device, but it requires -F. The label is -L and the reserved block percentage is -m. Reading the values after making it is tune2fs -l or dumpe2fs -h.

Sparse files and reporting the actual occupied size

truncate only punches holes to make a sparse file, and fallocate actually takes blocks. The apparent size is du --apparent-size, the actual occupancy is plain du, and the KiB unit is -k. Comparing %s and %b of stat also shows the difference.

A setgid shared directory and a default ACL

The leading 2 of chmod 2770 is setgid. An ACL is setfacl -m, and the default ACL to pass on to files that will be created is -d -m. Check the entries currently set with getfacl. The examples section of man 1 setfacl is especially short and useful.

Static name resolution and resolution order

If you write one address and several names on one line, the ones written after become aliases. To check, use getent hosts <이름> (the placeholder is the name). The resolution order is decided by the hosts: line of /etc/nsswitch.conf, and it is explained in man 5 nsswitch.conf.

SSH server configuration and checking the final values

The main configuration includes sshd_config.d/*.conf at the very top, and sshd uses the value read first if the same keyword appears several times. To check the syntax use sshd -t, and to check the final interpreted values use sshd -T. man 5 sshd_config has all the keywords.

Finding the process that opens a port

To see the listening TCP sockets together with the processes that own them, use ss -ltnp. To filter by port, write it like ss -ltnp 'sport = :9101'. The process name is also in /proc/<PID>/comm. Start it so that it does not die when you close the shell.

Reading and writing down the current interface and route

The default route is seen with ip route show default and the address with ip -o -4 addr show dev <이름> (the placeholder is the interface name). With -o it comes out on one line, which makes it easy to pull out fields. The MTU is also in ip link, and you may read /sys/class/net/<이름>/mtu directly as well.

Writing a systemd unit file and the enable link

A unit file is in ini format made of three sections, [Unit], [Service], and [Install]. To check the syntax, use systemd-analyze verify <경로> (the placeholder is the path). All that systemctl enable actually does is create a symbolic link in the .wants directory of the target that WantedBy in [Install] points to. Look at man 5 systemd.service.

A cron.d entry and root's crontab

A line in /etc/cron.d has one more user field, so it has six fields. A user's crontab does not have that field. Every 15 minutes is */15, and Sunday is 0 in the day-of-week position. To check the registration, use crontab -l -u root. Look at man 5 crontab.

Writing a log rotation configuration

A configuration block has the form 경로 { 지시어들 } (path, then directives in braces). To see only what the parser read without actually rotating, use logrotate -d <설정파일> (the placeholder is the configuration file). A misspelled directive shows up in that output as error:. man 8 logrotate has all the directives.

A lowered-priority background job and a PID file

Start it with lowered priority using nice -n 15 <명령> (the placeholder is the command). To keep it alive even if you close the shell, start it with nohup ... &. The PID of the process you just started is in the shell variable $!. To check the current nice value, use ps -o pid,ni,comm -p <PID>. The shebang on the first line of the script is written like #!/bin/bash.

Package installation and upgrade lock

This environment has no internet and /opt/localrepo is registered as a repository, so apt-get install works as is. To pull out only the versions of the installed packages, use the format string of dpkg-query -W -f. Excluding from upgrades is apt-mark hold, and to check use apt-mark showhold.