RHCSA (Red Hat Certified System Administrator) Exam — Questions and Answers
Question 1: Which file contains the default shell for the root user?
- /etc/profile
- /etc/shells
- /etc/shadow
- /etc/passwd (Correct answer)
Correct answer: /etc/passwd
The /etc/passwd file stores each user's default shell in the seventh colon-delimited field.
Question 2: What is the effect of setting 'net.ipv4.ip_forward = 1' in /etc/sysctl.conf?
- Enables the system to forward IPv4 packets between interfaces (Correct answer)
- Enables IPv4 fragmentation forwarding only
- Allows the system to accept ICMP redirects
- Disables reverse path filtering
Correct answer: Enables the system to forward IPv4 packets between interfaces
ip_forward = 1 enables kernel-level packet forwarding, making the host act as a router.
Question 3: Which command unmounts /mnt/usb and ensures all pending writes are flushed before removal?
- eject /mnt/usb
- sync && umount /mnt/usb
- mount -o remount,ro /mnt/usb
- umount /mnt/usb (Correct answer)
Correct answer: umount /mnt/usb
umount itself flushes buffers and ensures data is written before unmounting; running sync beforehand is redundant but harmless.
Question 4: A file has permissions rwxr-x---. Which octal notation represents this?
- 740
- 750 (Correct answer)
- 755
- 760
Correct answer: 750
rwx=7, r-x=5, ---=0 combines to octal 750.
Question 5: What does the fifth field (dump) in an /etc/fstab entry control?
- The dump speed of the filesystem in MB/s
- Whether the dump backup utility backs up the filesystem (Correct answer)
- Whether the filesystem is exported via NFS
- The number of inodes allocated during formatting
Correct answer: Whether the dump backup utility backs up the filesystem
The dump field (0 or 1) tells the legacy dump utility whether to include this filesystem in backups; 0 means skip.
Question 6: Which command creates a new logical volume named 'data' of size 5GB in volume group 'vg0'?
- lvcreate -s 5G -n data vg0
- lvcreate -L 5G -n data vg0 (Correct answer)
- vgcreate -L 5G -n data vg0
- lvextend -L 5G -n data vg0
Correct answer: lvcreate -L 5G -n data vg0
lvcreate -L specifies size and -n specifies the logical volume name within the volume group.
Question 7: How do you configure a system to use 192.168.1.1 as the DNS server persistently using NetworkManager?
- Edit /etc/hosts
- Run dns-set 192.168.1.1
- Edit /etc/resolv.conf directly
- nmcli con mod <conn> ipv4.dns 192.168.1.1, then restart connection (Correct answer)
Correct answer: nmcli con mod <conn> ipv4.dns 192.168.1.1, then restart connection
nmcli con mod sets the DNS in NetworkManager's connection profile, which persists and rebuilds /etc/resolv.conf on reconnect.
Question 8: What is the effect of running `chmod g+s /shared/dir`?
- Files in the dir inherit the group of the directory (Correct answer)
- The sticky bit is set on the directory
- Files in the dir inherit the owner's UID
- The directory is only accessible by the group
Correct answer: Files in the dir inherit the group of the directory
The setgid bit on a directory causes new files created inside to inherit the directory's group rather than the creator's primary group.
Question 9: A volume group shows 'partial' status. What does this indicate?
- One or more PVs in the VG are missing or unavailable (Correct answer)
- The VG has been exported but not imported
- The VG is partially activated
- The VG has less than 50% free space
Correct answer: One or more PVs in the VG are missing or unavailable
A 'partial' VG means at least one physical volume member is missing, making some LV data inaccessible.
Question 10: Which file would you edit to set a static hostname permanently on RHEL 9?
- /etc/hostname (Correct answer)
- /proc/sys/kernel/hostname
- /etc/sysconfig/network
- /etc/hosts
Correct answer: /etc/hostname
/etc/hostname contains the system's static hostname and is read at boot by systemd.
Question 11: A user needs to be added to the 'wheel' group without removing them from their existing groups. Which command accomplishes this?
- gpasswd -r wheel alice
- usermod -g wheel alice
- groupmod -a alice wheel
- usermod -aG wheel alice (Correct answer)
Correct answer: usermod -aG wheel alice
usermod -aG appends the group to the user's supplementary groups without removing existing ones.
Question 12: What type of filesystem is created by the command 'mkfs.vfat /dev/sdc1'?
- An ext2-compatible legacy filesystem
- Virtual filesystem for proc entries
- FAT32/FAT filesystem compatible with Windows (Correct answer)
- A FUSE-based filesystem
Correct answer: FAT32/FAT filesystem compatible with Windows
mkfs.vfat creates a FAT filesystem (commonly FAT32) on the partition, widely compatible with Windows and USB drives.
Question 13: Which command permanently changes the SELinux context of /srv/web to httpd_sys_content_t and updates the policy database?
- setenforce httpd /srv/web
- setfattr httpd_sys_content_t /srv/web
- semanage fcontext -a -t httpd_sys_content_t '/srv/web(/.*)?' && restorecon -Rv /srv/web (Correct answer)
- chcon -t httpd_sys_content_t /srv/web
Correct answer: semanage fcontext -a -t httpd_sys_content_t '/srv/web(/.*)?' && restorecon -Rv /srv/web
semanage fcontext adds a persistent policy rule; restorecon applies it, making the change survive a 'restorecon' or relabel.
Question 14: After loading a custom SELinux module with 'semodule -i custom.pp', how do you verify it is loaded?
- sestatus | grep custom
- audit2why | grep custom
- semodule -l | grep custom (Correct answer)
- restorecon -v / | grep custom
Correct answer: semodule -l | grep custom
semodule -l lists all installed policy modules; grep filters for the specific module name.
Question 15: What is the purpose of `set -e` at the beginning of a Bash script?
- Enforce read-only variables
- Enable extended globbing
- Echo every command before running it
- Exit the script immediately if any command returns a non-zero status (Correct answer)
Correct answer: Exit the script immediately if any command returns a non-zero status
`set -e` causes the script to exit immediately when any command exits with a non-zero (failure) status.
Question 16: Which systemd unit type is used to mount a filesystem defined in /etc/fstab at a specific path?
- .path
- .automount
- .service
- .mount (Correct answer)
Correct answer: .mount
`.mount` units represent filesystem mount points and correspond to entries in `/etc/fstab`.
Question 17: What happens when you run 'dnf upgrade' with no package name specified?
- All installed packages with available updates are upgraded (Correct answer)
- Only packages in the Base group are upgraded
- The system prompts for which packages to upgrade
- Only security updates are applied
Correct answer: All installed packages with available updates are upgraded
'dnf upgrade' with no arguments updates all installed packages for which newer versions exist in enabled repositories.
Question 18: Which command displays the full path of the currently active shell executable?
- type shell
- where bash
- which bash (Correct answer)
- echo $SHELL
Correct answer: which bash
which searches PATH directories and prints the full path of the named executable.
Question 19: Which command displays the ACL entries for the file /etc/myconfig?
- getfacl /etc/myconfig (Correct answer)
- stat --acl /etc/myconfig
- ls -acl /etc/myconfig
- setfacl -l /etc/myconfig
Correct answer: getfacl /etc/myconfig
getfacl prints the access control list entries for a file or directory.
Question 20: How do you reference the first argument passed to a shell script?
- $0
- $@
- $#
- $1 (Correct answer)
Correct answer: $1
`$1` holds the value of the first positional parameter passed to the script on the command line.
Question 21: Which `systemctl` command shows the current default boot target?
- systemctl show default.target
- systemctl get-default (Correct answer)
- systemctl list-targets --default
- systemctl target --current
Correct answer: systemctl get-default
`systemctl get-default` prints the symlink destination of `default.target`.
Question 22: What does the 'nologin' shell (e.g., /sbin/nologin) do when a user tries to log in interactively?
- Locks the account permanently
- Displays a message and refuses the interactive login (Correct answer)
- Deletes the user session
- Redirects to /bin/sh
Correct answer: Displays a message and refuses the interactive login
/sbin/nologin prints a polite message and exits, preventing interactive logins while still allowing services like FTP.
Question 23: A system needs to have kernel updates excluded permanently. Which file and directive would you use?
- Run 'dnf mark exclude kernel'
- Add 'exclude=kernel*' to /etc/yum.conf
- Add 'exclude=kernel*' to /etc/dnf/dnf.conf (Correct answer)
- Add 'skip_if_unavailable=kernel' to dnf.conf
Correct answer: Add 'exclude=kernel*' to /etc/dnf/dnf.conf
Adding 'exclude=kernel*' to the [main] section of /etc/dnf/dnf.conf permanently excludes kernel packages from all DNF operations.
Question 24: How do you configure a NetworkManager connection to use the static IP 192.168.1.50/24 with gateway 192.168.1.1?
- nmcli con add ipv4.addresses 192.168.1.50/24 ipv4.gateway 192.168.1.1
- nmtui set eth0 192.168.1.50/24 gw 192.168.1.1
- nmcli con mod eth0 ipv4.addresses 192.168.1.50/24 ipv4.gateway 192.168.1.1 ipv4.method manual (Correct answer)
- ip addr add 192.168.1.50/24 dev eth0 && ip route add default via 192.168.1.1
Correct answer: nmcli con mod eth0 ipv4.addresses 192.168.1.50/24 ipv4.gateway 192.168.1.1 ipv4.method manual
nmcli con mod modifies an existing connection profile; ipv4.method manual disables DHCP and applies the static address.
Question 25: Which command copies your public SSH key to a remote host for passwordless login?
- ssh-copy-id user@host (Correct answer)
- ssh-add user@host
- scp ~/.ssh/id_rsa.pub user@host
- ssh-keygen -c user@host
Correct answer: ssh-copy-id user@host
`ssh-copy-id` appends your public key to the remote user's `~/.ssh/authorized_keys` file automatically.
Question 26: Which command is used to create a new logical volume named `lv_web` of size 10 Gigabytes from a volume group named `vg_data`?
- C. `lvcreate -L 10G -n lv_web vg_data` (Correct answer)
- D. `pvcreate -L 10G -n lv_web vg_data`
- A. `vgcreate -n lv_web -L 10G vg_data`
- B. `lvnew -s 10G -n lv_web vg_data`
Correct answer: C. `lvcreate -L 10G -n lv_web vg_data`
The `lvcreate` command is used to create a new logical volume. The `-L` option specifies the size of the logical volume (10G), and the `-n` option specifies its name (lv_web). The final argument is the name of the volume group from which to allocate the space (vg_data).
Question 27: Which command displays the current SELinux enforcement mode?
- sestatus --mode
- getenforce (Correct answer)
- ls -Z /etc/selinux
- selinuxmode
Correct answer: getenforce
The `getenforce` command prints the current SELinux mode: Enforcing, Permissive, or Disabled.
Question 28: A directory has permissions drwxrws---. What does the 's' in the group field indicate?
- The directory is a symbolic link
- The setuid bit is set on the directory
- The sticky bit is set on the directory
- The setgid bit is set on the directory (Correct answer)
Correct answer: The setgid bit is set on the directory
An 's' in the group execute position indicates the setgid bit is set and the execute bit is also set.
Question 29: A process with PID 1234 is unresponsive. Which signal terminates it immediately without cleanup?
- kill -15 1234
- kill -1 1234
- kill -9 1234 (Correct answer)
- kill -2 1234
Correct answer: kill -9 1234
Signal 9 (SIGKILL) cannot be caught or ignored and forces the kernel to terminate the process immediately.
Question 30: Which command mounts all filesystems listed in /etc/fstab that are not currently mounted?
- fstab-mount
- mount -a (Correct answer)
- mount --all
- systemctl mount-all
Correct answer: mount -a
mount -a reads /etc/fstab and attempts to mount all filesystems that have the 'auto' option and are not already mounted.
Question 31: What is the purpose of the 'tee' command?
- Reads from stdin and writes to both stdout and a file simultaneously (Correct answer)
- Duplicates a file
- Appends output of two commands together
- Displays last lines of a file like tail
Correct answer: Reads from stdin and writes to both stdout and a file simultaneously
tee splits the output stream so it goes to both the terminal (stdout) and a specified file at the same time.
Question 32: You want to allow Samba to share home directories. Which boolean must be enabled?
- smbd_anon_write
- use_samba_home_dirs
- samba_export_all_rw
- samba_enable_home_dirs (Correct answer)
Correct answer: samba_enable_home_dirs
samba_enable_home_dirs allows the Samba daemon to read and share user home directories under SELinux.
Question 33: After noticing a file has extended ACLs, indicated by a `+` sign in the `ls -l` output, a system administrator wants to completely remove all ACL entries and revert to standard POSIX permissions. Which command should be used?
- setfacl -x /path/to/file
- setfacl -k /path/to/file
- chmod 755 /path/to/file
- setfacl -b /path/to/file (Correct answer)
Correct answer: setfacl -b /path/to/file
The `setfacl` command with the `-b` (or `--remove-all`) option is the correct way to strip all extended ACL entries from a file or directory, leaving only the base permissions for the owner, group, and others. The `+` sign in the `ls -l` output will disappear after this command is successfully executed.
Question 34: What cron schedule expression runs a job every day at 2:30 AM?
- 30 2 * * * (Correct answer)
- * * 2 30 *
- 2 30 * * *
- 30 * 2 * *
Correct answer: 30 2 * * *
The expression `30 2 * * *` means minute=30, hour=2, any day, any month, any weekday — i.e., 2:30 AM daily.
Question 35: A unit file has `ConditionPathExists=/etc/myapp.conf`. What happens if that file does not exist when the unit is started?
- Systemd creates the file automatically
- The unit is skipped silently as if it succeeded (Correct answer)
- The unit fails with an error
- The unit enters the 'waiting' state
Correct answer: The unit is skipped silently as if it succeeded
When a `Condition*=` check fails, systemd skips the unit without error — it reports as 'success' but does nothing.
Question 36: You want to create a striped logical volume across /dev/sdb and /dev/sdc with 2 stripes. Which command is correct?
- lvcreate -L 10G -n lv_stripe -i 2 vg0
- lvcreate -L 10G -n lv_stripe -s 2 vg0
- lvcreate -L 10G -n lv_stripe -i 2 /dev/sdb /dev/sdc vg0 (Correct answer)
- lvcreate -L 10G -n lv_stripe --stripes 2 vg0
Correct answer: lvcreate -L 10G -n lv_stripe -i 2 /dev/sdb /dev/sdc vg0
Use -i to specify stripe count and list the specific PVs to stripe across at the end of the command.
Question 37: For Perfect Solutions Inc., you are a network administrator. The business's network is built on Linux. A Linux server's configuration file has to be changed. Which of the aforementioned tools will you employ to complete the task?
- VI (Correct answer)
- NMAP
- MS Word
- GZIP
Correct answer: VI
On a Linux computer, users may create, change, and store files using the VI, a visual interactive text editor. It operates in the below modes: <br> Command: This is the command's default mode. In this mode, several commands can modify the opened text. <br> Text entry: In this mode, users can type straight into the text screen area.
Question 38: To perform an in-place replacement of every occurrence of the IP address `10.0.1.50` with `10.0.2.50` within the file `/etc/config.txt`, which `sed` command should be used?
- sed 's/10.0.1.50/10.0.2.50/g' /etc/config.txt
- sed -i 's/10.0.1.50/10.0.2.50/g' /etc/config.txt (Correct answer)
- sed -i 's/10.0.1.50/10.0.2.50/' /etc/config.txt
- sed 's/10.0.1.50/10.0.2.50/' /etc/config.txt > /etc/config.txt
Correct answer: sed -i 's/10.0.1.50/10.0.2.50/g' /etc/config.txt
The correct command is `sed -i 's/10.0.1.50/10.0.2.50/g' /etc/config.txt`. The `-i` flag modifies the file in-place. The `s/.../.../` is the substitute command. The `g` flag at the end ensures the replacement is global, affecting all occurrences on a line, not just the first. Redirecting output to the same file you are reading from can truncate the file, and omitting the `g` flag will only replace the first match on each line.
Question 39: Which `sshd_config` directive sets the maximum number of concurrent unauthenticated SSH connections?
- MaxSessions
- LoginLimit
- MaxConnections
- MaxStartups (Correct answer)
Correct answer: MaxStartups
`MaxStartups` limits unauthenticated connection attempts, helping protect against connection-based brute-force attacks.
Question 40: Which command creates a hard link named 'link1' pointing to 'file1'?
- ln file1 link1 (Correct answer)
- link file1 link1
- ln -s file1 link1
- cp --link file1 link1
Correct answer: ln file1 link1
ln without -s creates a hard link; both names refer to the same inode on the same filesystem.
Question 41: Which of the following SHELL commands shows the tasks and users that are presently logged in?
- finger
- whoami
- who
- w (Correct answer)
Correct answer: w
The w command shows the tasks and users that are presently logged in.
Question 42: What is the purpose of `systemd-analyze blame`?
- Displays units that are blocking the current target
- Identifies which units caused the last system crash
- Shows units that failed during the last boot
- Lists each unit and the time it took to initialize during boot (Correct answer)
Correct answer: Lists each unit and the time it took to initialize during boot
`systemd-analyze blame` shows each service unit's initialization time, helping identify boot bottlenecks.
Question 43: Which command would you use to restore the default SELinux context on a file?
- setsebool -P /path/file
- restorecon /path/file (Correct answer)
- chcon --restore /path/file
- semanage fcontext -r /path/file
Correct answer: restorecon /path/file
`restorecon` resets a file's SELinux context to the policy default stored in the file context database.
Question 44: Where should custom drop-in configuration files for an existing systemd unit be placed?
- /usr/lib/systemd/system/<unit>.d/
- /etc/systemd/conf.d/<unit>/
- /etc/systemd/system/<unit>.d/ (Correct answer)
- /run/systemd/system/<unit>.conf.d/
Correct answer: /etc/systemd/system/<unit>.d/
Drop-in override files go in `/etc/systemd/system/<unit>.d/` as `*.conf` files so they survive package updates.
Question 45: You cannot continue with the installation once you have chosen your root password. What is the most probable explanation?
- You also need to create a user.
- The password is unsecure, and unsecure passwords are not accepted.
- The password does not meet requirements in the password policy.
- If an unsecure password is used, you need to click Done twice. (Correct answer)
Correct answer: If an unsecure password is used, you need to click Done twice.
The most likely reason for being unable to proceed in the installation after setting the root password is that the password you entered is considered weak or insecure. In some installation processes, there are specific password strength requirements that need to be met to ensure security. If the password you entered does not meet these requirements, the installation may not allow you to proceed until a stronger password is provided.
Question 46: Which command removes a local container image named 'myimage:latest' from Podman storage?
- podman image rm --force myimage:latest
- podman image delete myimage:latest
- podman rmi myimage:latest (Correct answer)
- podman remove image myimage:latest
Correct answer: podman rmi myimage:latest
'podman rmi myimage:latest' removes the specified image from local storage; mirrors the 'docker rmi' command.
Question 47: A systemd timer unit should run a job every day at 02:30. Which `OnCalendar=` value is correct?
- *-*-* 02:30:00 (Correct answer)
- 0 2 30 * *
- daily 02:30
- 02:30:00 daily
Correct answer: *-*-* 02:30:00
The systemd calendar format for daily at 02:30 is `*-*-* 02:30:00` (year-month-day hour:minute:second).
Question 48: A script needs to run as root at reboot via cron. Which crontab time field triggers this?
- @boot
- 0 0 * * 0
- @reboot (Correct answer)
- * * * * * reboot
Correct answer: @reboot
@reboot is a cron shorthand that runs the command once when the cron daemon starts, typically at system boot.
Question 49: After making several changes to the permanent firewalld configuration, a sysadmin wants to activate them. What is the key difference between running `firewall-cmd --reload` and `systemctl restart firewalld`?
- There is no functional difference; both commands achieve the same outcome.
- `--reload` keeps existing stateful connections alive, while `restart` drops all active connections. (Correct answer)
- `--reload` only applies new rules, while `restart` applies new rules and removes old ones.
- `--reload` applies both runtime and permanent rules, while `restart` only applies permanent rules.
Correct answer: `--reload` keeps existing stateful connections alive, while `restart` drops all active connections.
The `firewall-cmd --reload` command loads the permanent configuration into the running firewall without losing the state information of current network connections. In contrast, `systemctl restart firewalld` stops and then starts the entire daemon, which will drop all active connections as the stateful firewall information is lost. For applying new permanent rules without interrupting service, `--reload` is the preferred method.
Question 50: What is the exit status of a Bash command that completes successfully?
- 127
- 1
- 0 (Correct answer)
- 255
Correct answer: 0
A successful command returns exit status `0`, while any non-zero value indicates an error or abnormal termination.
Question 51: Which command lists all locally stored container images in Podman?
- podman image find
- podman list images
- podman images (Correct answer)
- podman show images
Correct answer: podman images
'podman images' displays all images stored in the local image cache, including their tags and sizes.
RHCSA (Red Hat Certified System Administrator) Exam
The RHCSA (Red Hat Certified System Administrator) Exam exam validates essential knowledge and skills required for certification or licensure in this field.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds