LCA Certified Linux Administrator Exam — Questions and Answers
Question 1: Which command would you use to restore a specific file 'etc/passwd' from a tar archive 'backup.tar.gz'?
- tar -rzf backup.tar.gz etc/passwd
- tar -tzf backup.tar.gz etc/passwd
- tar -xzf backup.tar.gz etc/passwd (Correct answer)
- tar -czf backup.tar.gz etc/passwd
Correct answer: tar -xzf backup.tar.gz etc/passwd
tar -xzf extracts (-x) from a gzip-compressed (-z) archive file (-f), and specifying 'etc/passwd' restores only that file.
Question 2: Which file contains the persistent mount information in Linux?
- /etc/disktab
- /etc/mount.conf
- /etc/fstab (Correct answer)
- /etc/mtab
Correct answer: /etc/fstab
The `/etc/fstab` file stores persistent mount information, meaning it defines file systems that should be mounted automatically every time the system boots. Each entry in this file specifies a device, its mount point, file system type, and various options. This ensures that critical partitions and devices are always available.
Question 3: In the context of LCA certification, what is the most important consideration when implementing web server & database administration?
- Minimizing documentation to save time
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Delegating all responsibilities to junior staff
- Completing implementation as quickly as possible regardless of quality
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing web server & database administration, LCA professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 4: Which command lists all cron jobs configured for a specific user named 'webadmin'?
- crontab -u webadmin -l (Correct answer)
- crontab --user webadmin --list
- cat /etc/cron.d/webadmin
- crontab -l webadmin
Correct answer: crontab -u webadmin -l
crontab -u <username> -l lists the crontab entries for the specified user; this requires root or sudo privileges to view another user's crontab.
Question 5: What does 'mkswap /dev/sdf1' followed by 'swapon /dev/sdf1' accomplish?
- Encrypts the partition and uses it as swap
- Formats and activates a swap partition for virtual memory use (Correct answer)
- Formats sdf1 as ext4 and mounts it as /swap
- Creates a swap file on sdf1
Correct answer: Formats and activates a swap partition for virtual memory use
mkswap writes the swap signature to the partition, and swapon enables it for immediate use as virtual memory.
Question 6: What is the effect of the Apache directive 'Options -Indexes' in a Directory block?
- Prevents Apache from generating directory listings when no index file exists (Correct answer)
- Disables all mod_rewrite rules
- Blocks access to hidden files
- Removes execute permissions from CGI scripts
Correct answer: Prevents Apache from generating directory listings when no index file exists
Options -Indexes prevents Apache from generating a directory listing, returning a 403 Forbidden instead when no index file is found.
Question 7: Which command tests whether TCP port 80 on host 203.0.113.5 is open without using nmap?
- nc -zv 203.0.113.5 80 (Correct answer)
- ping -p 80 203.0.113.5
- curl -v telnet://203.0.113.5:80
- traceroute -p 80 203.0.113.5
Correct answer: nc -zv 203.0.113.5 80
'nc -zv host port' attempts a TCP connection without sending data (-z) and reports the result verbosely (-v).
Question 8: A sysadmin needs to add a second disk to an existing LVM volume group. Which sequence is correct?
- fdisk → lvextend → vgextend
- vgcreate → pvcreate → lvextend
- vgextend → pvcreate → lvextend
- pvcreate → vgextend → lvextend (Correct answer)
Correct answer: pvcreate → vgextend → lvextend
You must first initialize the disk as a physical volume (pvcreate), then add it to the volume group (vgextend), then optionally extend logical volumes (lvextend).
Question 9: Which command shows the logs of a container running in a Kubernetes pod named 'webserver'?
- kubectl describe pod webserver
- kubectl logs pod/webserver (Correct answer)
- kubectl get events --pod=webserver
- kubectl exec webserver -- journalctl
Correct answer: kubectl logs pod/webserver
'kubectl logs pod/webserver' streams the stdout/stderr of the container running in the specified pod.
Question 10: What is the effect of running 'chmod 4755' on an executable?
- Removes all special permission bits
- Sets the SUID bit so the file runs with the owner's privileges (Correct answer)
- Sets the SGID bit so the file runs with group privileges
- Sets the sticky bit and makes it world-writable
Correct answer: Sets the SUID bit so the file runs with the owner's privileges
The leading '4' in octal notation sets the Set-UID bit, causing execution under the file owner's UID.
Question 11: What does the 'x' in the password field of /etc/passwd indicate?
- The account is disabled
- The account has no password
- The password uses MD5 hashing
- The password is stored in /etc/shadow (Correct answer)
Correct answer: The password is stored in /etc/shadow
An 'x' in the password field of /etc/passwd means the actual hashed password is stored in the shadowed /etc/shadow file.
Question 12: How should LCA professionals handle confidential information related to web server & database administration?
- Share freely with all colleagues for transparency
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Store information without any security measures
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 13: What does 'bare metal recovery' refer to in disaster recovery?
- Recovering only user data files without reinstalling the OS
- Restoring a complete system to new or wiped hardware with no prior OS installed (Correct answer)
- Restoring virtual machine snapshots
- Recovering from a RAID failure
Correct answer: Restoring a complete system to new or wiped hardware with no prior OS installed
Bare metal recovery restores an entire system image (OS, applications, and data) onto hardware that has no existing operating system.
Question 14: Which configuration directive in /etc/resolv.conf allows the resolver to try multiple domain suffixes when resolving a short hostname?
- nameserver
- search (Correct answer)
- options ndots
- domain
Correct answer: search
The 'search' directive specifies a list of domain suffixes appended when a hostname without dots is queried.
Question 15: Which of the following best describes a key competency required for virtualization & container management in LCA practice?
- The ability to work independently without any oversight
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Memorization of all relevant regulations without understanding context
- Reliance on a single methodology for all situations
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
LCA professionals working in virtualization & container management need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 16: Which construct in bash is used to perform pattern matching in a case statement?
- match $VAR with pattern -> ...
- if $VAR == pattern; then ...
- switch $VAR { pattern: ... }
- case $VAR in pattern) ... ;; esac (Correct answer)
Correct answer: case $VAR in pattern) ... ;; esac
The `case ... esac` construct uses glob patterns to match values and execute corresponding code blocks.
Question 17: You observe high retransmission rates in 'ss -s' output. What does this most likely indicate?
- The firewall is blocking UDP traffic
- The DNS server is unreachable
- The MTU is set too low for the interface
- Network congestion or packet loss causing TCP to resend unacknowledged segments (Correct answer)
Correct answer: Network congestion or packet loss causing TCP to resend unacknowledged segments
TCP retransmissions occur when acknowledgments are not received in time, typically due to packet loss or congestion.
Question 18: In SELinux, what does the Boolean 'httpd_can_network_connect' control?
- Whether the httpd process can initiate outbound network connections (Correct answer)
- Whether Apache can bind to privileged ports
- Whether SELinux enforces labels on Apache config files
- Whether Apache can read NFS-mounted directories
Correct answer: Whether the httpd process can initiate outbound network connections
This Boolean allows or denies the Apache httpd daemon from making outbound TCP connections, useful for reverse-proxy scenarios.
Question 19: A differential backup strategy is used. Sunday is a full backup; Tuesday's differential is corrupt. Which backups are needed to restore to Wednesday?
- Wednesday differential only
- Sunday full + all incrementals Mon-Wed
- Sunday full + Tuesday differential + Wednesday differential
- Sunday full + Wednesday differential (Correct answer)
Correct answer: Sunday full + Wednesday differential
Differential backups always include all changes since the last full backup, so Wednesday's differential plus Sunday's full backup is sufficient regardless of Tuesday.
Question 20: Which command displays the UUID of a block device?
- fdisk -l
- lsblk -f
- blkid (Correct answer)
- df -h
Correct answer: blkid
blkid queries block device attributes including UUID, filesystem type, and label.
Question 21: Which feature of LVM is commonly used to enable consistent online backups of a running system?
- LVM mirroring
- LVM thin provisioning
- LVM snapshots (Correct answer)
- LVM striping
Correct answer: LVM snapshots
LVM snapshots create a point-in-time copy of a logical volume that can be backed up while the source volume remains online and in use.
Question 22: What does the 'noatime' mount option do?
- Disables updating access timestamps on reads (Correct answer)
- Prevents file creation timestamps from being set
- Removes modification times from files
- Stops journaling of time metadata
Correct answer: Disables updating access timestamps on reads
The 'noatime' option prevents the kernel from updating the access time (atime) on every file read, reducing disk write overhead.
Question 23: When a LCA professional encounters an unfamiliar challenge in performance monitoring & tuning, what is the recommended first course of action?
- Proceed based on personal intuition alone
- Postpone addressing the issue indefinitely
- Apply the solution used for the most recent similar problem without adaptation
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 24: Which file controls which services are started at boot in a systemd system?
- /etc/init.d/
- /etc/services
- /etc/rc.local
- /etc/systemd/system/default.target.wants/ (Correct answer)
Correct answer: /etc/systemd/system/default.target.wants/
Symlinks in /etc/systemd/system/default.target.wants/ (or similar .wants directories) define which units are enabled to start at the default target.
Question 25: A system fails to boot after editing /etc/fstab. Which rescue mode command removes a bad entry without a GUI?
- mount --repair /etc/fstab
- fsck /etc/fstab
- fdisk /etc/fstab
- vi /etc/fstab after mounting root read-write (Correct answer)
Correct answer: vi /etc/fstab after mounting root read-write
In rescue mode, remounting the root filesystem read-write with 'mount -o remount,rw /' then editing /etc/fstab with vi corrects bad entries.
Question 26: Which Bacula daemon runs on the backup client and is responsible for reading/writing data on the client system?
- bacula-mon (Monitor)
- bacula-fd (File Daemon) (Correct answer)
- bacula-dir (Director)
- bacula-sd (Storage Daemon)
Correct answer: bacula-fd (File Daemon)
The Bacula File Daemon (bacula-fd) runs on each client and handles local file I/O during backup and restore operations.
Question 27: Which Linux installation method allows installation over the network?
- PXE Boot Network installation (Correct answer)
- USB stick installation.
- Live CD installation.
- Dual boot installation.
Correct answer: PXE Boot Network installation
PXE (Preboot eXecution Environment) Boot Network installation is a method that allows a computer to boot and install an operating system over a network without needing local storage or an optical drive. This is particularly useful for deploying Linux to multiple machines efficiently in a corporate or data center environment. It centralizes the installation process and reduces manual effort.
Question 28: What is the purpose of Apache's mod_proxy_fcgi module?
- Proxies WebSocket connections to backend servers
- Caches FastCGI responses on disk
- Forwards requests to FastCGI backends such as PHP-FPM (Correct answer)
- Provides load balancing across multiple Apache instances
Correct answer: Forwards requests to FastCGI backends such as PHP-FPM
mod_proxy_fcgi allows Apache to forward requests to FastCGI applications (like PHP-FPM) using the FastCGI protocol.
Question 29: What does 'restorecon -Rv /var/www/html' do?
- Reloads the SELinux policy from /etc/selinux
- Restores SELinux file contexts based on policy for the directory tree (Correct answer)
- Changes all files to the httpd_sys_content_t context regardless of policy
- Recursively removes SELinux contexts from the directory
Correct answer: Restores SELinux file contexts based on policy for the directory tree
restorecon applies the correct SELinux contexts as defined in the policy database, -R for recursive, -v for verbose.
Question 30: How should LCA professionals handle confidential information related to network configuration & troubleshooting?
- Share freely with all colleagues for transparency
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Delete all records after project completion
- Store information without any security measures
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 31: Which Nginx directive defines a named location block for internal redirects only?
- location #name {}
- location ~name {}
- location internal /name {}
- location @name {} (Correct answer)
Correct answer: location @name {}
A named location prefixed with @ (e.g., location @fallback) is only accessible via internal Nginx directives like try_files or error_page, not directly by clients.
Question 32: A file has permissions -rwsr-xr-x. What does the 's' in the owner execute position indicate?
- SGID bit is set
- The file is a symbolic link
- Sticky bit is set
- SUID bit is set (Correct answer)
Correct answer: SUID bit is set
An 's' replacing the owner execute bit means the SUID bit is set, causing the file to run as its owner.
Question 33: When a LCA professional encounters an unfamiliar challenge in web server & database administration, what is the recommended first course of action?
- Proceed based on personal intuition alone
- Postpone addressing the issue indefinitely
- Apply the solution used for the most recent similar problem without adaptation
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 34: Which bootloader configuration file must be updated after adding a new kernel in a GRUB 2 system?
- /etc/grub.conf
- /etc/default/grub
- /boot/grub2/grub.cfg (Correct answer)
- /boot/grub/grub.cfg
Correct answer: /boot/grub2/grub.cfg
On GRUB 2 systems, /boot/grub2/grub.cfg is the active config file, but it should be regenerated with grub2-mkconfig rather than edited directly.
Question 35: A host has two NICs: eth0 (192.168.1.10/24) and eth1 (10.0.0.5/24). Traffic to 10.0.0.0/24 is unexpectedly using eth0. What is the most likely cause?
- A more specific route for 10.0.0.0/24 is missing, so the default route via eth0 is used (Correct answer)
- The NIC driver is outdated
- IPv6 is interfering with IPv4 routing
- The firewall is redirecting packets
Correct answer: A more specific route for 10.0.0.0/24 is missing, so the default route via eth0 is used
Without a specific route for 10.0.0.0/24 via eth1, the kernel falls back to the default route, which exits through eth0.
Question 36: What is the 3-2-1 backup rule?
- 3 servers, 2 SANs, 1 cloud provider
- 3 full backups, 2 incremental, 1 differential per week
- 3 copies of data, on 2 different media types, with 1 offsite copy (Correct answer)
- 3 daily backups, 2 weekly, 1 monthly
Correct answer: 3 copies of data, on 2 different media types, with 1 offsite copy
The 3-2-1 rule is a best practice: keep 3 total copies of data, stored on 2 different media types, with at least 1 copy stored offsite.
Question 37: What is the purpose of 'dracut' on Red Hat-based systems?
- Manages systemd unit files
- Installs kernel modules
- Generates the initramfs image (Correct answer)
- Configures GRUB bootloader entries
Correct answer: Generates the initramfs image
dracut is the tool used on Red Hat/Fedora systems to build the initramfs (initial RAM filesystem) image that the bootloader passes to the kernel.
Question 38: Which fail2ban component reads log files and triggers bans based on defined filters?
- fail2ban-server (Correct answer)
- fail2ban-client
- jail.conf
- filter.d
Correct answer: fail2ban-server
fail2ban-server is the daemon that monitors logs and communicates with the firewall to block offending IPs.
Question 39: What is the most effective way to measure success in package management & software installation within LCA professional practice?
- Rely solely on supervisor opinion
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Compare only with industry averages without considering context
- Count only the number of activities completed
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 40: Which LVM command extends a logical volume AND resizes its ext4 filesystem in one step?
- lvextend -r -L +10G /dev/vg0/lv0 (Correct answer)
- lvextend -L +10G /dev/vg0/lv0
- lvresize /dev/vg0/lv0
- vgextend vg0 /dev/sdb
Correct answer: lvextend -r -L +10G /dev/vg0/lv0
The -r flag with lvextend calls resize2fs automatically after extending the logical volume, handling both the LV and filesystem resize in one command.
Question 41: Which log file should an administrator check first to view SELinux AVC denial messages?
- /var/log/audit/audit.log (Correct answer)
- /var/log/selinux.log
- /var/log/messages
- /var/log/secure
Correct answer: /var/log/audit/audit.log
The auditd daemon writes AVC (Access Vector Cache) denial records to /var/log/audit/audit.log.
Question 42: What octal permission value sets read+write for owner, read-only for group, and no permissions for others?
- 644
- 620
- 660
- 640 (Correct answer)
Correct answer: 640
640 = owner rw- (6), group r-- (4), others --- (0).
Question 43: In Nginx, which block directive defines a group of backend servers for load balancing?
- backend
- server
- proxy_pass
- upstream (Correct answer)
Correct answer: upstream
The upstream block in Nginx defines a group of servers that can be referenced by proxy_pass for load balancing.
Question 44: Which bootloader is most commonly installed with Linux systems?
- GRUB (Correct answer)
- NTLDR
- LILO
- Syslinux
Correct answer: GRUB
GRUB (GRand Unified Bootloader) is the most commonly installed bootloader with modern Linux systems. Its primary function is to load the operating system kernel into memory and pass control to it, allowing the system to start up. GRUB supports multiple operating systems and offers a flexible configuration for booting various kernels or even other operating systems installed on the same machine.
Question 45: What is the purpose of the /etc/hosts.deny file in TCP Wrappers?
- Denies access to specified hosts for wrapped services (Correct answer)
- Configures iptables blacklist rules
- Sets kernel network security parameters
- Lists services exempt from firewall rules
Correct answer: Denies access to specified hosts for wrapped services
TCP Wrappers checks /etc/hosts.allow first, then /etc/hosts.deny to determine whether to permit a connection.
Question 46: Which partition table format supports disks larger than 2TB and more than 4 primary partitions?
- MBR
- GPT (Correct answer)
- APM
- BSD disklabel
Correct answer: GPT
GUID Partition Table (GPT) supports disks over 2TB and allows up to 128 partitions by default, overcoming MBR's limitations.
Question 47: What does 'apt-get install --no-install-recommends' do differently from a standard install?
- Installs without asking for confirmation
- Installs only required dependencies, skipping recommended packages (Correct answer)
- Skips optional and suggested packages only
- Installs recommended packages instead of required ones
Correct answer: Installs only required dependencies, skipping recommended packages
The --no-install-recommends flag tells apt to install only mandatory dependencies, not the 'Recommends' listed by the package.
Question 48: What command runs a shell script named 'myscript.sh'?
- start myscript.sh
- execute myscript.sh
- run myscript.sh
- sh myscript.sh (Correct answer)
Correct answer: sh myscript.sh
To run a shell script named `myscript.sh`, you can explicitly invoke the shell interpreter, such as `sh` (for Bourne shell compatible scripts) or `bash` (for Bash scripts), followed by the script's filename. This tells the system to execute the script using the specified shell. Alternatively, if the script has execute permissions and a shebang line, you can run it directly with `./myscript.sh`.
Question 49: What is the role of 'createrepo' command on RPM-based systems?
- Creates a new empty RPM repository
- Creates an RPM spec file
- Downloads RPMs to create a local repo
- Creates repository metadata from a directory of RPM files (Correct answer)
Correct answer: Creates repository metadata from a directory of RPM files
createrepo generates the repodata/ directory with XML metadata that makes a directory of RPMs usable as a YUM/DNF repository.
Question 50: What command permanently adds HTTP service to the active firewalld zone?
- firewall-cmd --permanent --add-service=http (Correct answer)
- firewall-cmd --add-service=http
- firewall-cmd --reload --add-service=http
- firewall-cmd --zone=public --add-service=http
Correct answer: firewall-cmd --permanent --add-service=http
The --permanent flag ensures the rule persists across reboots; --reload is then needed to apply it.
Question 51: A directory has the sticky bit set (drwxrwxrwt). What restriction does this impose?
- Files inherit the directory's group
- Only root can delete files in it
- Users can only delete files they own (Correct answer)
- No new files can be created in it
Correct answer: Users can only delete files they own
The sticky bit on a directory prevents users from deleting or renaming files owned by others, even with write access.
Question 52: Which iptables target silently drops packets without sending any response?
- BLOCK
- REJECT
- DENY
- DROP (Correct answer)
Correct answer: DROP
DROP silently discards the packet, whereas REJECT sends an ICMP error back to the sender.
Question 53: Which kernel parameter passed at boot disables SELinux for a single session?
- enforcing=0
- security=none
- selinux=permissive
- selinux=0 (Correct answer)
Correct answer: selinux=0
Passing selinux=0 on the kernel command line completely disables SELinux for that boot session without permanently changing the policy configuration.
Question 54: In the context of LCA certification, what is the most important consideration when implementing user & permission management?
- Minimizing documentation to save time
- Completing implementation as quickly as possible regardless of quality
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Delegating all responsibilities to junior staff
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing user & permission management, LCA professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 55: Which command is used to check the status of the firewall on a Linux system?
- ufw status
- systemctl firewall status
- iptables --status
- firewalld-cmd --state (Correct answer)
Correct answer: firewalld-cmd --state
For systems using `firewalld`, the `firewall-cmd --state` command is used to check if the `firewalld` service is running. It will output "running" if the firewall daemon is active, or indicate if it's not. This is the standard way to quickly ascertain the operational status of `firewalld`.
Question 56: What does the command 'newgrp developers' accomplish?
- Renames the current group to developers
- Creates a new group named developers
- Adds the current user to the developers group permanently
- Starts a subshell with developers as the effective primary group (Correct answer)
Correct answer: Starts a subshell with developers as the effective primary group
newgrp opens a new shell session where the specified group becomes the user's effective primary group for that session.
Question 57: Which of the following best describes a key competency required for backup & disaster recovery in LCA practice?
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Reliance on a single methodology for all situations
- The ability to work independently without any oversight
- Memorization of all relevant regulations without understanding context
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
LCA professionals working in backup & disaster recovery need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 58: In bash, what is a here-document used for?
- Providing multi-line input to a command inline in the script (Correct answer)
- Importing another script
- Defining a function
- Creating a temporary file automatically
Correct answer: Providing multi-line input to a command inline in the script
A here-document (`<< DELIMITER ... DELIMITER`) feeds multiple lines of text directly as stdin to a command without needing a separate file.
Question 59: Which command saves a Docker image to a tar archive file?
- docker commit
- docker save (Correct answer)
- docker dump
- docker export
Correct answer: docker save
'docker save' exports an image (including all layers and metadata) to a tar file for offline transfer.
Question 60: Which command adds an existing physical volume /dev/sde to volume group 'vg_data'?
- pvextend vg_data /dev/sde
- vgadd /dev/sde vg_data
- lvextend vg_data /dev/sde
- vgextend vg_data /dev/sde (Correct answer)
Correct answer: vgextend vg_data /dev/sde
vgextend adds one or more initialized PVs to an existing volume group, increasing its total capacity.
LCA Certified Linux Administrator Exam
The LCA Certified Linux Administrator certification validates the fundamental skills required to administer Linux systems, including installation, configuration, and basic troubleshooting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds