LFCS — Linux Foundation System Administrator
LFCS Mock Exam A
Goal
You solve 18 tasks in 120 minutes under the same conditions as the real LFCS exam. The passing line is 67% and scoring is partial credit, so if you pass 13 of the 18 tasks, you pass.
The real exam environment
- There is no browser and no internet. All you can see is the
manpages,--help, andinfoin the terminal, and the distribution documentation under/usr/share/doc/. - You must not block ports 8080, 4505, and 4506 tcp, and if you kill the
certerminalprocess, the exam session ends on the spot. - The passing line is 67% and scoring is partial credit. Spending all your time clinging to one task is the most common reason for failing. If you get stuck, skip it and come back later.
How to solve this practice exam
- Do not look at the hints; solve everything through first. After you have skimmed all 18, open the hints only for the ones you got stuck on then.
- Do not do web searches. Solve with
manand--helponly. This is the most important practice for this exam. In the real exam room there is no search box. - If you cannot remember a command name, look for it with
man -k <키워드>orapropos <키워드>(the placeholder is a keyword). For example, you writeman -k acl,man -k quota, andman -k "file system". If you do not practice this now, you will be doing it for the first time in the exam room. - If you need the section number, write it like
man 5 fstab. Configuration files are in section 5 and administrator commands are in section 8.
How this environment differs from the real exam
The lab Pod has almost no kernel privileges and systemd does not run as PID 1. So
mount, systemctl, and iptables do not work here. We framed the knowledge of the same domains
in a form you can verify in this environment. In the real exam all three of these work,
so think of the fstab entries and unit files you make here as leading on, in the exam room, to
mount -a and systemctl enable --now.
Steps
- In
/root/exam/find/src/, create five files,data-01.txtthroughdata-05.txt. Each ofdata-01–data-03must be at least 200000 bytes, and each ofdata-04–data-05must be at least 1 byte and under 4096 bytes. In the same directory, create a hard linkdata-01.hardpointing todata-01.txt. Then write only the names of the regular files directly undersrcwhose size exceeds 100 KiB to/root/exam/find/big.txt, and only the names of those whose hard link count is 2 or more to/root/exam/find/links.txt. In both files, write only the names, one per line, inLC_ALL=C sortorder. - From
/etc/services, pick the entries whose protocol istcpand whose port number is between 1024 and 2000 inclusive, and write them to/root/exam/text/tcp-high.txt. On each line, write<포트> <서비스 이름>(port, then service name) separated by a single space, and for the service name use the first field of that line. Sort by port number in ascending order and keep only one of identical lines. - In
/root/exam/arch/src/, create five files,log-01.txtthroughlog-05.txt, each at least 20000 bytes, and one file with the extension.tmp. In/root/exam/arch/, create a tar archive of thesrcdirectory compressed with gzip,/root/exam/arch/backup.tar.gz, but exclude the.tmpfile. Write the list of entries contained in that archive, inLC_ALL=C sortorder, to/root/exam/arch/members.txt. - Create a group
opswith GID 4200 and a groupauditwith GID 4201. Create a userdeploywith UID 4300 with primary groupops, supplementary groupaudit, login shell/bin/bash, and home/home/deploy, actually create the home directory, and set its permissions to750and its ownership todeploy:ops. Set the password policy ofdeployto a minimum change interval of 7 days, a maximum usage period of 60 days, and 14 days of expiry warning, and specify the account expiry date as 2027-06-30. - Create a user
internwith UID 4301. Set the login shell to/usr/sbin/nologin, actually create the home, and put it inopsas a supplementary group. Set a password forinternonce, and then lock that account. Finally, change the defaults in/etc/login.defstoPASS_MAX_DAYS 90,PASS_MIN_DAYS 7,PASS_WARN_AGE 14, andUMASK 027. - Create the directories
/srv/dataand/srv/scratchand add two entries to/etc/fstab. The first has the deviceUUID=2f9c1a70-0007-4e00-9a00-000000000007, mount point/srv/data, typeext4, optionsdefaults,nofail, dump0, and pass2. The second has the devicetmpfs, mount point/srv/scratch, typetmpfs, optionsrw,nosuid,nodev,noexec,size=256m, dump0, and pass0. You cannot runmountin this Pod, so stop at writing the entries. - Create
/root/exam/storage/data.imgwith exactly 134217728 bytes and make an ext4 filesystem on that file. The volume label isEXAMDATAand the reserved block percentage is 1%. Write the UUID of the created filesystem on one line to/root/exam/storage/data.uuid. - Create
/root/exam/storage/sparse.imgas a sparse file with an apparent size of 536870912 bytes (its actual usage must be nearly 0). Create/root/exam/storage/dense.imgas a file with 4 MiB actually allocated. Then write the three lines below to/root/exam/storage/usage.txt. The values are integers in KiB.sparse_apparent_kib=<sparse.img 의 겉보기 크기>(the apparent size of sparse.img)sparse_actual_kib=<sparse.img 이 실제로 차지하는 크기>(the size sparse.img actually occupies)dense_actual_kib=<dense.img 이 실제로 차지하는 크기>(the size dense.img actually occupies) - Create the shared directory
/srv/team, and set its ownership toroot:opsand its permissions to2770. With ACLs givedeployrwxandinternr-x, and set a default ACL so that files newly created under this directory haverwxfor the owning group and no permissions for other users. The owner entry of the default ACL isrwx. - In
/etc/hosts, register10.60.0.11asweb1.lab.internalwith the short nameweb1, and10.60.0.12asdb1.lab.internalwith the short namedb1. Then makefilescome beforednsin thehosts:line of/etc/nsswitch.conf. All four names must resolve withgetent hosts. - Create
/etc/ssh/sshd_config.d/90-exam.confand write the following seven items in this file:PermitRootLogin no,PasswordAuthentication no,MaxAuthTries 3,ClientAliveInterval 300,ClientAliveCountMax 2,AllowTcpForwarding no,X11Forwarding no. The configuration must be syntactically correct and the final values sshd interprets must be exactly these. You do not need to restart the daemon. - Start, in the background, a process that accepts connections on TCP port
9101of127.0.0.1and keep it alive until the exam ends. Then find the process holding that socket and write the three lines below to/root/exam/net/listener.txt:port=9101,pid=<그 프로세스의 PID>,comm=<그 프로세스의 이름>(pid= followed by that process's PID, and comm= followed by that process's name). - Query this Pod's current network state and write it to
/root/exam/net/facts.txtin four lines:iface=<기본 경로가 나가는 인터페이스 이름>,ipv4=<그 인터페이스의 IPv4 주소를 프리픽스까지 포함해>,mtu=<그 인터페이스의 MTU>,gateway=<기본 경로의 게이트웨이 주소>(respectively: the name of the interface the default route goes out through, that interface's IPv4 address including the prefix, that interface's MTU, and the default route's gateway address). - Create
/usr/local/bin/labhub-batch.sh, give it execute permission, and write the unit file/etc/systemd/system/labhub-batch.service.[Unit]must have a Description, and bothWantsandAftermust benetwork-online.target. In[Service], Type isoneshot, ExecStart is/usr/local/bin/labhub-batch.sh, and WorkingDirectory is/srv/data. In[Install], WantedBy ismulti-user.target. In this Pod systemd does not run as PID 1, sosystemctl enabledoes not work, so create by hand the symbolic link that command would make,/etc/systemd/system/multi-user.target.wants/labhub-batch.service. - Create
/usr/local/bin/labhub-report.shand/usr/local/bin/labhub-weekly.shand set both to permissions755. Create/etc/cron.d/labhub-reportand register it to run/usr/local/bin/labhub-report.shevery 15 minutes asroot, with that file's permissions644and ownershiproot:root. And in root's crontab, register a line that runs/usr/local/bin/labhub-weekly.shevery Sunday at 02:30. - Create
/var/log/labhub-app.logand write/etc/logrotate.d/labhub-appso that this log is rotated daily and up to 14 are kept. Turn oncompress,delaycompress,missingok, andnotifempty, and make the new file after rotation be created withcreate 0640 root adm. - Create
/usr/local/bin/exam-worker.shand give it permissions755. The first line must start with a shebang, and the content can be anything that keeps running without exiting. Run it in the background with a nice value of 15, and write that process's PID on one line to/run/exam-worker.pid. The process must be alive until grading time. - Install the packages
figletandpv(this environment has no internet and the/opt/localrepooffline repository is already registered). Write the names and versions of the two installed packages to/root/exam/ops/pkg.txt, one per line, in the format<패키지 이름> <버전>(package name, then version). Finally, lock onlypvso that it is excluded from automatic upgrades.
Notes
- Start with a timer running. The time limit on the screen is set to 120 minutes.
- If
man -kfinds nothing, there is no index.aproposuses the same index. In that case, look at<명령> --helpand/usr/share/doc/<패키지>/(the placeholders are the command and the package). /etc/hostsis held by the Pod as a bind mount, so methods likesed -ithat replace the file by creating it anew fail withDevice or resource busy. Use append redirection ortee -a. The same thing happens on a real server if it is inside a container.- This Pod cannot run
mount,umount,systemctl, oriptables. There is no task that requires those three, so if such a command fails, you misread the question. - One more common mistake — for every task that says to write a value to a file, the grader recomputes that value right now and compares. If you fixed something you made earlier, recreate the report file too.
Picking files that match size and link conditions with find
The unit of -size +100k is KiB, and -links +1 selects those with a hard link count of 2 or more. To print only names, use %f of -printf, and fix the sorting with LC_ALL=C sort. A hard link is ln and a symbolic link is ln -s.
Filtering entries from /etc/services by condition
The second field of each line has the form 포트/프로토콜 (port/protocol). Split on the slash with split() in awk and then compare the numbers. Sorting by port ascending and removing duplicates is done with a single sort -n -u.
Making a tar archive excluding a particular extension
In tar, c is create, z is gzip, and f is the file name. Exclude with --exclude, and wrap the pattern in quotes so that the shell does not expand it first. Extract the contained list again with tar -tzf.
Creating groups and users, and the password expiry policy
Combine groupadd -g and the -u -g -G -s -m -d of useradd. Set the password policy with chage, and the account expiry date is chage -E. Look at man 8 useradd and man 1 chage. You may need to set the home directory's permissions and ownership separately after useradd has created it.
A login-blocked account and the default password policy
If you give the shell as /usr/sbin/nologin, login is blocked. Locking is usermod -L or passwd -l, but if you lock an account that has no password at all, only the lock marker remains and there is no hash. Put in the password first with chpasswd and then lock. The defaults are in /etc/login.defs.
Writing two fstab entries
man 5 fstab gives the meaning of all six fields. The order is device, mount point, type, options, dump, pass. You must create the mount point directories beforehand. To check only the syntax, use findmnt --verify --tab-file /etc/fstab.
Making ext4 on a file and reading the superblock
Making an empty file of an exact size is truncate -s. mkfs.ext4 can also make a filesystem on a file that is not a block device, but it requires -F. The label is -L and the reserved block percentage is -m. Reading the values after making it is tune2fs -l or dumpe2fs -h.
Sparse files and reporting the actual occupied size
truncate only punches holes to make a sparse file, and fallocate actually takes blocks. The apparent size is du --apparent-size, the actual occupancy is plain du, and the KiB unit is -k. Comparing %s and %b of stat also shows the difference.
A setgid shared directory and a default ACL
The leading 2 of chmod 2770 is setgid. An ACL is setfacl -m, and the default ACL to pass on to files that will be created is -d -m. Check the entries currently set with getfacl. The examples section of man 1 setfacl is especially short and useful.
Static name resolution and resolution order
If you write one address and several names on one line, the ones written after become aliases. To check, use getent hosts <이름> (the placeholder is the name). The resolution order is decided by the hosts: line of /etc/nsswitch.conf, and it is explained in man 5 nsswitch.conf.
SSH server configuration and checking the final values
The main configuration includes sshd_config.d/*.conf at the very top, and sshd uses the value read first if the same keyword appears several times. To check the syntax use sshd -t, and to check the final interpreted values use sshd -T. man 5 sshd_config has all the keywords.
Finding the process that opens a port
To see the listening TCP sockets together with the processes that own them, use ss -ltnp. To filter by port, write it like ss -ltnp 'sport = :9101'. The process name is also in /proc/<PID>/comm. Start it so that it does not die when you close the shell.
Reading and writing down the current interface and route
The default route is seen with ip route show default and the address with ip -o -4 addr show dev <이름> (the placeholder is the interface name). With -o it comes out on one line, which makes it easy to pull out fields. The MTU is also in ip link, and you may read /sys/class/net/<이름>/mtu directly as well.
Writing a systemd unit file and the enable link
A unit file is in ini format made of three sections, [Unit], [Service], and [Install]. To check the syntax, use systemd-analyze verify <경로> (the placeholder is the path). All that systemctl enable actually does is create a symbolic link in the .wants directory of the target that WantedBy in [Install] points to. Look at man 5 systemd.service.
A cron.d entry and root's crontab
A line in /etc/cron.d has one more user field, so it has six fields. A user's crontab does not have that field. Every 15 minutes is */15, and Sunday is 0 in the day-of-week position. To check the registration, use crontab -l -u root. Look at man 5 crontab.
Writing a log rotation configuration
A configuration block has the form 경로 { 지시어들 } (path, then directives in braces). To see only what the parser read without actually rotating, use logrotate -d <설정파일> (the placeholder is the configuration file). A misspelled directive shows up in that output as error:. man 8 logrotate has all the directives.
A lowered-priority background job and a PID file
Start it with lowered priority using nice -n 15 <명령> (the placeholder is the command). To keep it alive even if you close the shell, start it with nohup ... &. The PID of the process you just started is in the shell variable $!. To check the current nice value, use ps -o pid,ni,comm -p <PID>. The shebang on the first line of the script is written like #!/bin/bash.
Package installation and upgrade lock
This environment has no internet and /opt/localrepo is registered as a repository, so apt-get install works as is. To pull out only the versions of the installed packages, use the format string of dpkg-query -W -f. Excluding from upgrades is apt-mark hold, and to check use apt-mark showhold.