Linux Foundation LFCS Hands-on 17 tasks 2 hours

Linux Foundation Certified System Administrator

A hands-on exam: you are given a terminal on a Linux server and a list of administration tasks. Practise them here on a simulated Ubuntu 24.04 host that grades the state you leave behind. Covered: kernel parameters, systemd services and failed units, process priority and runaway processes, cron and one-off at jobs, packages and holds, containers, fstab recovery and filesystem repair, name resolution, time zones and time servers, static addresses and routes with netplan, ufw, the SSH server and keys, nginx as a reverse proxy, partitions, filesystems, swap and LVM, Git, disk space, archives, mirroring with rsync, certificates, users, groups, passwords and their ageing, failed logins, sudo, ACLs and resource limits. Not simulated yet: libvirt virtual machines, SELinux, bridges and bonding, NFS and automounters, and LDAP.

The blueprint

A mock lab here has 17 tasks in 2 hours, split across the domains in the same proportions as the official exam guide. The official pass mark is 67%. FixOps scores practice against a target of 67%.

  1. 01

    Operations Deployment

    25%

  2. 02

    Networking

    25%

  3. 03

    Storage

    20%

  4. 04

    Essential Commands

    20%

  5. 05

    Users and Groups

    10%

The free sample lab

Two tasks from the bank, on a simulated Ubuntu server you drive from its shell. You are graded on the state you leave behind, not on the commands you type.

  • Turn on IPv4 forwarding, now and after a reboot. Change a kernel parameter at runtime and persist it in /etc/sysctl.d.
  • Create a user and a shared group. Add a group with a fixed GID and a user that belongs to it.

Revision notes: Operations Deployment

The notes for one domain, free to read here and in the app. FixOps Pro has them for all 5 domains.

Kernel parameters, processes and systemd services, unit files, scheduled jobs, packages, recovery from boot and filesystem failures, virtual machines, containers and SELinux.

Kernel parameters

  • sysctl -a lists every parameter, sysctl NAME reads one, and sysctl -w NAME=VALUE changes the running kernel only.
  • A setting survives a reboot when it is in /etc/sysctl.conf or in a file in /etc/sysctl.d/ whose name ends in .conf.
  • sysctl --system loads every settings file and sysctl -p FILE loads one; without either, a new file does nothing until the next boot.
  • Files in /etc/sysctl.d are applied in name order and a later file overrides an earlier one, so a key set twice gets the value from the file that sorts last.
  • Every parameter is also a file under /proc/sys: net.ipv4.ip_forward is /proc/sys/net/ipv4/ip_forward, and writing to it is the same as sysctl -w.
  • Common ones are net.ipv4.ip_forward=1 to route packets, vm.swappiness for how readily memory is swapped, and fs.file-max for the system-wide limit of open files.

Processes and services

  • ps aux, or ps -eo pid,user,%cpu,%mem,comm --sort=-%cpu, lists processes; top and htop show them live.
  • kill PID sends SIGTERM (15), which a process can handle and clean up after; kill -9 sends SIGKILL, which it cannot; pkill and killall select by name.
  • nice -n 10 COMMAND starts a process with lower priority and renice changes a running one; only root can raise priority (a lower nice value).
  • systemctl start, stop, restart and reload act now; enable and disable decide about boot; enable --now and disable --now do both.
  • systemctl status UNIT shows the state and the last log lines, journalctl -u UNIT the whole log, and systemctl --failed lists the units that failed.
  • A process that belongs to a service with a Restart= policy comes back when only the process is killed: stop and disable the unit, or mask it so nothing can start it.

Unit files

  • Local unit files go in /etc/systemd/system; packaged ones are in /usr/lib/systemd/system, and a file in /etc with the same name replaces the packaged one.
  • A minimal service has Description in [Unit], ExecStart in [Service] and WantedBy=multi-user.target in [Install]; Restart=on-failure restarts it after a crash or a non-zero exit.
  • systemctl daemon-reload is needed after creating or editing a unit file, before start or enable sees the change.
  • systemctl edit UNIT writes a drop-in under /etc/systemd/system/UNIT.d/ that overrides single settings; systemctl cat UNIT shows the unit with its drop-ins.
  • systemctl get-default and set-default choose the boot target, and systemctl isolate rescue.target switches to a target now.

Scheduled jobs

  • A crontab line is minute, hour, day of month, month, day of week, command: 30 2 * * * runs at 02:30 every day.
  • crontab -e edits your own table and crontab -l lists it; root adds -u USER to work on someone else's.
  • Files in /etc/cron.d and /etc/crontab have an extra user field before the command; scripts in /etc/cron.hourly, cron.daily, cron.weekly and cron.monthly are run by run-parts.
  • at runs a command once (at 02:00 tomorrow), atq lists the queue and atrm removes a job.
  • A systemd timer is a NAME.timer unit with OnCalendar= or OnBootSec= that starts NAME.service; systemctl list-timers shows the next runs.

Packages

  • On Debian and Ubuntu, apt update refreshes the package lists and apt install, remove and purge manage packages; purge also deletes the configuration files.
  • dpkg -l lists installed packages, dpkg -L PACKAGE its files, dpkg -S /path the package that owns a file, and dpkg -i installs a local .deb file.
  • Repositories are listed in /etc/apt/sources.list and /etc/apt/sources.list.d/, with their signing keys under /etc/apt/keyrings or /usr/share/keyrings.
  • On RHEL-family systems dnf install, remove, provides and repolist do the same jobs, with rpm -qa, rpm -ql and rpm -qf underneath and repositories in /etc/yum.repos.d/.
  • apt-mark hold PACKAGE keeps a package at its version during upgrades, and apt-mark unhold releases it.

Recovery, virtual machines, containers and SELinux

  • A wrong line in /etc/fstab can stop the boot in emergency mode: fix the line, check with findmnt --verify and mount -a, and use the nofail option for disks that may be absent.
  • fsck (e2fsck for ext4) and xfs_repair for XFS repair a filesystem and must be run while it is unmounted.
  • virsh list --all shows libvirt virtual machines; virsh start, shutdown, destroy (power off), autostart and undefine manage them, and virt-install creates one.
  • docker run -d --name NAME -p HOST:CONTAINER --restart unless-stopped IMAGE starts a container that comes back after a reboot; podman takes the same options.
  • docker ps lists running containers (add -a for stopped ones); docker logs, exec -it NAME sh, stop and rm cover day-to-day work, and docker build -t NAME . builds an image from a Dockerfile.
  • getenforce reads the SELinux mode and setenforce 0 or 1 switches between permissive and enforcing until reboot; /etc/selinux/config sets the mode at boot.
  • ls -Z and ps -Z show SELinux contexts, restorecon -R resets them to the policy's defaults, semanage fcontext -a adds a default and setsebool -P changes a boolean for good.

Easy to mix up

  • sysctl -w changes the running kernel and is lost at reboot; a file in /etc/sysctl.d is permanent but does nothing until sysctl --system or a reboot loads it. A task usually wants both.
  • enable is about boot and start is about now: an enabled service can be stopped, and a running one can be disabled.
  • disable removes the unit from boot; mask links it to /dev/null so that nothing can start it at all, not even by hand.
  • A user's crontab has five time fields and the command; /etc/crontab and the files in /etc/cron.d have a sixth field, the user, before the command.
  • apt remove keeps a package's configuration files; apt purge deletes them too.
  • kill sends SIGTERM by default, which is a request; kill -9 cannot be caught and gives the process no chance to clean up.

Practice tasks written by FixOps from the public LFCS domains and competencies. They are not real exam tasks and run in a simulator, not on a real server. FixOps is not affiliated with or endorsed by the Linux Foundation.

Your pager is ready.

Free, instant, and it works on your phone. No signup: start as a guest and save your progress later.