The blueprint
A mock lab here has 17 tasks in 2 hours, split across the domains in the same proportions as the official exam guide. The official pass mark is 67%. FixOps scores practice against a target of 67%.
-
01
Operations Deployment
-
02
Networking
-
03
Storage
-
04
Essential Commands
-
05
Users and Groups
The free sample lab
Two tasks from the bank, on a simulated Ubuntu server you drive from its shell. You are graded on the state you leave behind, not on the commands you type.
- Turn on IPv4 forwarding, now and after a reboot. Change a kernel parameter at runtime and persist it in /etc/sysctl.d.
- Create a user and a shared group. Add a group with a fixed GID and a user that belongs to it.
Revision notes: Operations Deployment
The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.
Kernel parameters, processes and systemd services, unit files, scheduled jobs, packages, recovery from boot and filesystem failures, virtual machines, containers and SELinux.
Kernel parameters
- sysctl -a lists every parameter, sysctl NAME reads one, and sysctl -w NAME=VALUE changes the running kernel only.
- A setting survives a reboot when it is in /etc/sysctl.conf or in a file in /etc/sysctl.d/ whose name ends in .conf.
- sysctl --system loads every settings file and sysctl -p FILE loads one; without either, a new file does nothing until the next boot.
- Files in /etc/sysctl.d are applied in name order and a later file overrides an earlier one, so a key set twice gets the value from the file that sorts last.
- Every parameter is also a file under /proc/sys: net.ipv4.ip_forward is /proc/sys/net/ipv4/ip_forward, and writing to it is the same as sysctl -w.
- Common ones are net.ipv4.ip_forward=1 to route packets, vm.swappiness for how readily memory is swapped, and fs.file-max for the system-wide limit of open files.
Processes and services
- ps aux, or ps -eo pid,user,%cpu,%mem,comm --sort=-%cpu, lists processes; top and htop show them live.
- kill PID sends SIGTERM (15), which a process can handle and clean up after; kill -9 sends SIGKILL, which it cannot; pkill and killall select by name.
- nice -n 10 COMMAND starts a process with lower priority and renice changes a running one; only root can raise priority (a lower nice value).
- systemctl start, stop, restart and reload act now; enable and disable decide about boot; enable --now and disable --now do both.
- systemctl status UNIT shows the state and the last log lines, journalctl -u UNIT the whole log, and systemctl --failed lists the units that failed.
- A process that belongs to a service with a Restart= policy comes back when only the process is killed: stop and disable the unit, or mask it so nothing can start it.
Unit files
- Local unit files go in /etc/systemd/system; packaged ones are in /usr/lib/systemd/system, and a file in /etc with the same name replaces the packaged one.
- A minimal service has Description in [Unit], ExecStart in [Service] and WantedBy=multi-user.target in [Install]; Restart=on-failure restarts it after a crash or a non-zero exit.
- systemctl daemon-reload is needed after creating or editing a unit file, before start or enable sees the change.
- systemctl edit UNIT writes a drop-in under /etc/systemd/system/UNIT.d/ that overrides single settings; systemctl cat UNIT shows the unit with its drop-ins.
- systemctl get-default and set-default choose the boot target, and systemctl isolate rescue.target switches to a target now.
Scheduled jobs
- A crontab line is minute, hour, day of month, month, day of week, command: 30 2 * * * runs at 02:30 every day.
- crontab -e edits your own table and crontab -l lists it; root adds -u USER to work on someone else's.
- Files in /etc/cron.d and /etc/crontab have an extra user field before the command; scripts in /etc/cron.hourly, cron.daily, cron.weekly and cron.monthly are run by run-parts.
- at runs a command once (at 02:00 tomorrow), atq lists the queue and atrm removes a job.
- A systemd timer is a NAME.timer unit with OnCalendar= or OnBootSec= that starts NAME.service; systemctl list-timers shows the next runs.
Packages
- On Debian and Ubuntu, apt update refreshes the package lists and apt install, remove and purge manage packages; purge also deletes the configuration files.
- dpkg -l lists installed packages, dpkg -L PACKAGE its files, dpkg -S /path the package that owns a file, and dpkg -i installs a local .deb file.
- Repositories are listed in /etc/apt/sources.list and /etc/apt/sources.list.d/, with their signing keys under /etc/apt/keyrings or /usr/share/keyrings.
- On RHEL-family systems dnf install, remove, provides and repolist do the same jobs, with rpm -qa, rpm -ql and rpm -qf underneath and repositories in /etc/yum.repos.d/.
- apt-mark hold PACKAGE keeps a package at its version during upgrades, and apt-mark unhold releases it.
Recovery, virtual machines, containers and SELinux
- A wrong line in /etc/fstab can stop the boot in emergency mode: fix the line, check with findmnt --verify and mount -a, and use the nofail option for disks that may be absent.
- fsck (e2fsck for ext4) and xfs_repair for XFS repair a filesystem and must be run while it is unmounted.
- virsh list --all shows libvirt virtual machines; virsh start, shutdown, destroy (power off), autostart and undefine manage them, and virt-install creates one.
- docker run -d --name NAME -p HOST:CONTAINER --restart unless-stopped IMAGE starts a container that comes back after a reboot; podman takes the same options.
- docker ps lists running containers (add -a for stopped ones); docker logs, exec -it NAME sh, stop and rm cover day-to-day work, and docker build -t NAME . builds an image from a Dockerfile.
- getenforce reads the SELinux mode and setenforce 0 or 1 switches between permissive and enforcing until reboot; /etc/selinux/config sets the mode at boot.
- ls -Z and ps -Z show SELinux contexts, restorecon -R resets them to the policy's defaults, semanage fcontext -a adds a default and setsebool -P changes a boolean for good.
Easy to mix up
- sysctl -w changes the running kernel and is lost at reboot; a file in /etc/sysctl.d is permanent but does nothing until sysctl --system or a reboot loads it. A task usually wants both.
- enable is about boot and start is about now: an enabled service can be stopped, and a running one can be disabled.
- disable removes the unit from boot; mask links it to /dev/null so that nothing can start it at all, not even by hand.
- A user's crontab has five time fields and the command; /etc/crontab and the files in /etc/cron.d have a sixth field, the user, before the command.
- apt remove keeps a package's configuration files; apt purge deletes them too.
- kill sends SIGTERM by default, which is a request; kill -9 cannot be caught and gives the process no chance to clean up.