All certifications / Linux+ / Cheat sheet
Linux+ XK0-006 cheat sheet
Domain 1: System management (23%)
Exam tips
- Map the symptom to the stage: no GRUB menu points to firmware or the boot loader, a 'cannot find root' error points to the initramfs or root= argument, and a boot that stops at an emergency shell after the kernel loads usually points to systemd units or /etc/fstab.
- Remember that /proc and /sys take no disk space and are rebuilt every boot; exam questions about viewing CPU, memory or kernel parameters usually point to /proc, while device and driver details point to /sys.
- Watch for the persistence trap: modprobe and sysctl -w changes vanish at reboot; persistence comes from /etc/modprobe.d or /etc/modules-load.d for modules and /etc/sysctl.d for kernel parameters.
- If a question says the link must work across partitions or to a directory, the answer is a symbolic link; if it says the data must remain accessible after the original name is deleted, the answer is a hard link.
- If a scenario asks why a server hung in emergency mode after a disk was removed or renamed, suspect an fstab entry by device name without nofail; the fix is to use UUID= and add nofail where appropriate.
- If an LV was extended but df still shows the old size, the filesystem was not resized; the fix is resize2fs (ext4) or xfs_growfs (XFS), or using lvextend -r next time.
- Exam items love the XFS shrink trap: XFS cannot be reduced in size, so shrinking requires backing up, recreating the filesystem smaller and restoring.
- If a question asks which change survives a reboot, ip addr add is the wrong answer; persistent changes come from nmcli connection profiles, netplan YAML or the distribution's config files.
- uniq only removes adjacent duplicates, so answers that pipe unsorted data into uniq -c are usually wrong; look for sort before uniq.
- Match the tar letters carefully: z is gzip, j is bzip2, J is xz; and c, x and t are create, extract and list.
- virsh destroy only forces a guest off, like pulling the power cord; it does not delete the VM. Removing the definition is virsh undefine.
Key terms
- UEFI
- Unified Extensible Firmware Interface: modern firmware that boots EFI executables from an EFI System Partition and supports Secure Boot.
- ESP
- EFI System Partition: a small FAT partition, usually mounted at /boot/efi, that holds UEFI boot loaders.
- GRUB2
- The standard Linux boot loader; configured through /etc/default/grub and a generated grub.cfg.
- initramfs
- A compressed temporary root filesystem loaded into RAM that contains the drivers and scripts needed to mount the real root filesystem.
- dracut / mkinitramfs
- Tools that build the initramfs image: dracut on Red Hat-family and SUSE, mkinitramfs/update-initramfs on Debian-family.
- systemd target
- A unit that groups other units into a system state, such as multi-user.target or graphical.target, replacing SysV runlevels.
- Secure Boot
- A UEFI feature that only runs boot loaders and kernels signed with trusted keys.
- FHS
- Filesystem Hierarchy Standard: the convention that defines the purpose of top-level Linux directories.
- /etc
- The directory for host-specific configuration files.
- /var
- The directory for variable data such as logs, spools, caches and application state.
- /usr/local
- The area reserved for locally installed software that the package manager will not touch.
- /proc
- A virtual filesystem exposing process and kernel information, including tunables under /proc/sys.
- /sys
- Sysfs, a virtual filesystem exposing devices, drivers and kernel objects.
- /dev
- The directory of device files, such as /dev/sda and /dev/null, maintained by udev.
- Kernel module
- A loadable piece of kernel code (.ko file), such as a driver, that can be inserted or removed while the system runs.
- modprobe
- Loads or removes (-r) a module together with its dependencies, reading options from /etc/modprobe.d.
- modinfo
- Displays a module's file path, description, dependencies and supported parameters.
- depmod
- Builds the modules.dep dependency map that modprobe uses to load dependencies.
- Blacklist
- A modprobe.d directive that prevents a module from being loaded automatically by its alias.
- sysctl
- A tool to view and set kernel runtime parameters under /proc/sys; persistent values go in /etc/sysctl.d/*.conf.
- Inode
- The on-disk structure holding a file's metadata and pointers to its data; directory entries map names to inode numbers.
- Hard link
- An additional directory entry for the same inode; cannot cross filesystems and survives deletion of the other names.
- Symbolic link
- A separate file that stores a path to a target; can cross filesystems but breaks if the target is removed.
- mtime vs ctime
- mtime changes when file contents change; ctime changes when metadata such as permissions or ownership changes.
- find -exec
- A find action that runs a command on each matched file, with {} replaced by the file name.
- locate
- A fast file-name search that uses a database built by updatedb, so it can miss recently created files.
- GPT
- GUID Partition Table: modern partition scheme supporting very large disks, many partitions and a backup table.
- MBR
- Master Boot Record: legacy partition scheme limited to four primary partitions and roughly 2 TiB disks.
- UUID
- A unique identifier stored in a filesystem, used in /etc/fstab so mounts do not depend on device names.
- partprobe
- Asks the kernel to reread a disk's partition table so changes take effect without a reboot.
- nofail
- An fstab option that lets boot continue if the device is not present.
- noexec
- An fstab option that prevents executing binaries stored on that filesystem.
- PV / VG / LV
- Physical volume (a disk prepared for LVM), volume group (a pool of PVs) and logical volume (a usable volume carved from the pool).
- Extent
- The fixed-size unit of space LVM allocates from a volume group to logical volumes.
- lvextend -r
- Extends a logical volume and resizes its filesystem in the same command.
- vgextend
- Adds a new physical volume to an existing volume group to increase its free space.
- mdadm
- The Linux tool for creating, monitoring and managing software RAID arrays (/dev/mdN).
- /proc/mdstat
- A kernel status file showing each software RAID array, its members and any rebuild progress.
- RAID 5
- Striping with distributed parity across at least three disks, surviving the loss of one disk.
- Journaling
- A technique where a filesystem logs pending metadata changes so it can recover consistently after a crash.
- XFS
- A high-performance journaling filesystem, default on RHEL, that can grow online but cannot shrink.
- Btrfs
- A copy-on-write filesystem with subvolumes, snapshots, checksums and integrated multi-device support.
- resize2fs
- Grows or shrinks an ext2/3/4 filesystem to fit its device.
- xfs_growfs
- Grows a mounted XFS filesystem, specified by its mount point.
- df vs du
- df reports free and used space per filesystem; du totals the space used by files and directories.
- Inode exhaustion
- A filesystem running out of inodes, so no new files can be created even though free blocks remain; seen with df -i.
- iproute2 (ip)
- The modern suite for viewing and changing interfaces, addresses, routes and neighbors; changes are not persistent.
- nmcli
- Command-line client for NetworkManager that manages persistent connection profiles.
- netplan
- Ubuntu's YAML-based network configuration system that renders settings for systemd-networkd or NetworkManager.
- hostnamectl
- systemd tool that shows and permanently sets the system hostname.
- /etc/resolv.conf
- Lists DNS nameservers and search domains used by the system resolver.
- nsswitch.conf
- Defines the order of lookup sources (files, dns, sss, etc.) for hosts, users, groups and more.
- File descriptor
- A number identifying an open stream: 0 is stdin, 1 is stdout and 2 is stderr.
- Pipe
- The | operator that sends one command's standard output to another command's standard input.
- export
- Marks a shell variable so it is passed to child processes as an environment variable.
- tee
- Copies its standard input to a file and to standard output at the same time.
- sed
- A stream editor used mainly for search-and-replace and line filtering; -i edits files in place.
- awk
- A pattern-scanning language that splits lines into fields ($1, $2 ...) for filtering and reporting.
- tar
- Archiving tool that bundles files while preserving metadata; -c create, -x extract, -t list, -f file, with -z/-j/-J for gzip/bzip2/xz.
- rsync
- Incremental file synchronization tool that transfers only differences, locally or over SSH.
- dd
- Block-level copy tool used for disk images and writing raw devices; if= input, of= output.
- cpio
- Archiver that takes file lists on stdin, commonly paired with find; used in initramfs and RPM payloads.
- xz
- A compressor that usually achieves higher compression than gzip or bzip2 at the cost of speed.
- rsync --delete
- Removes files from the destination that no longer exist at the source, producing an exact mirror.
- KVM
- Kernel-based Virtual Machine: kernel modules that use CPU virtualization extensions to make Linux a hypervisor.
- QEMU
- The emulator that supplies virtual hardware and, with KVM, runs guests at near-native speed.
- libvirt / virsh
- A management API and daemon for hypervisors, and its command-line client for controlling guests.
- qcow2
- A thin-provisioned QEMU disk format supporting snapshots, backing files and compression.
- Raw image
- A plain byte-for-byte disk image with no metadata features, valued for simplicity and performance.
- virtio
- Paravirtualized device drivers that give guests fast disk and network I/O.
- Backing file
- A read-only base image that a qcow2 overlay refers to, storing only the overlay's changes.
Domain 2: Services and user management (20%)
Exam tips
- The classic trap is usermod -G without -a: it replaces all supplementary groups. When a question says 'add to a group without affecting existing memberships', the answer includes -aG.
- Remember which file holds what: hashes and aging live in /etc/shadow, supplementary group members live in /etc/group, and defaults for new accounts come from /etc/login.defs and /etc/skel.
- Know the difference in strength: stop affects now, disable affects boot, and mask blocks the unit entirely until unmasked.
- Count the fields: a user crontab has five time fields before the command, but /etc/crontab and /etc/cron.d files add a username as the sixth field.
- The correct escalation is SIGTERM first, SIGKILL only if the process ignores it; and a zombie cannot be killed at all, since it is already dead, so you deal with its parent.
- apt update only refreshes package lists; apt upgrade actually installs newer versions. Many wrong answers confuse the two.
- The standard source build order is ./configure, make, make install; only the last step normally needs root.
- Read -p mappings as host:container. A question showing -p 8443:443 means clients connect to the host on 8443 to reach the container's 443.
- Keep the three roles straight: a pod runs containers, a deployment keeps the right number of pods running and updates them, and a service gives them a stable network address.
- In rsyslog forwarding, one @ means UDP and two @@ mean TCP; and in journalctl, -b -1 means the previous boot.
Key terms
- UID / GID
- Numeric user and group identifiers the kernel actually uses for ownership and permission checks.
- Primary group
- The group assigned to a user in /etc/passwd and given to files the user creates.
- Supplementary group
- Additional groups a user belongs to, listed in /etc/group, that grant extra access.
- usermod -aG
- Appends a user to supplementary groups without removing existing memberships.
- chage
- Command that views and sets password aging and account expiry for a user.
- System account
- A low-privilege account created with useradd -r for running a service, usually with no login shell.
- /etc/passwd
- World-readable account database with seven fields: name, x, UID, GID, GECOS, home and shell.
- /etc/shadow
- Root-only file holding password hashes and password aging and expiry fields.
- /etc/group
- Group database listing group name, GID and supplementary members.
- /etc/skel
- Template directory whose files are copied into new users' home directories.
- /etc/login.defs
- Configuration of defaults for account tools, such as UID ranges and password aging.
- vipw / vigr
- Tools that lock and safely edit the passwd and group files (and their shadow versions with -s).
- Unit
- A systemd configuration object such as a .service, .socket, .timer, .mount or .target.
- enable vs start
- enable configures a unit to start at boot; start runs it now. Neither implies the other.
- mask
- Links a unit to /dev/null so it cannot be started manually or as a dependency.
- Drop-in override
- A .conf file in /etc/systemd/system/<unit>.d/ that overrides selected settings of a unit.
- daemon-reload
- Tells systemd to reread unit files after they change on disk.
- WantedBy=
- An [Install] setting naming the target that should pull the unit in when it is enabled.
- crontab
- A per-user table of scheduled jobs, edited with crontab -e, using five time fields plus a command.
- at
- Schedules a command to run once at a future time; managed with atq and atrm and run by atd.
- systemd timer
- A .timer unit that activates a matching .service unit on a schedule.
- OnCalendar
- A timer setting that defines wall-clock schedules, such as Mon..Fri *-*-* 02:30:00.
- Persistent=true
- A timer option that runs a missed job at the next opportunity after downtime.
- cron.allow / cron.deny
- Files that control which users may create crontabs; if cron.allow exists, only listed users may.
- PID / PPID
- Process ID and parent process ID, used to identify processes and their relationships.
- SIGTERM vs SIGKILL
- SIGTERM (15) asks a process to exit cleanly; SIGKILL (9) forces termination and cannot be caught.
- SIGHUP
- Signal 1, sent on terminal hangup and used by many daemons as a request to reload configuration.
- Nice value
- A priority adjustment from -20 (most favored) to 19 (least favored); only root can lower it.
- Zombie process
- A terminated process whose exit status has not yet been collected by its parent, shown with state Z.
- nohup
- Runs a command immune to hangup signals so it keeps running after the user logs out.
- rpm / dpkg
- Low-level package tools that install and query individual package files without resolving dependencies.
- dnf / apt
- High-level package managers that download from repositories and resolve dependencies.
- Repository
- A server or location holding packages and signed metadata, configured in /etc/yum.repos.d or /etc/apt/sources.list(.d).
- rpm -qf / dpkg -S
- Queries that report which installed package owns a given file.
- dnf provides
- Searches repositories for the package that supplies a given file or command.
- rpm -V
- Verifies installed package files against the package database and reports changes.
- gpgcheck
- A repository setting that requires valid GPG signatures on packages before installation.
- make
- A build tool that reads a Makefile and runs the steps to compile software; make install copies it into place.
- ./configure
- A script that checks build dependencies and generates a Makefile, often with --prefix to set the install path.
- pip
- Python's package installer, best used inside a virtual environment.
- Virtual environment
- An isolated Python environment created with python3 -m venv so project packages do not affect the system.
- Flatpak
- A sandboxed universal packaging format mainly for desktop apps, commonly installed from Flathub.
- Snap
- Canonical's sandboxed package format managed by snapd, with automatic refreshes and confinement modes.
- Image
- A read-only, layered template (name:tag) from which containers are created.
- Container
- An isolated process running from an image with its own writable layer, sharing the host kernel.
- Namespaces and cgroups
- Kernel features that give containers isolated views of the system and limit their resource use.
- Port publishing
- The -p host:container option that maps a host port to a port inside the container.
- Volume
- Persistent storage managed by the container engine or bind-mounted from the host, surviving container removal.
- Rootless container
- A container run by an unprivileged user, as Podman supports, limiting the impact of a compromise.
- Pod
- The smallest Kubernetes unit: one or more containers sharing an IP address and volumes.
- Deployment
- An object that declares an image and replica count, maintains that many pods and performs rolling updates.
- Service
- A stable virtual IP and DNS name that load-balances traffic to pods selected by labels.
- kubectl
- The command-line client that talks to the Kubernetes API server.
- Declarative configuration
- Describing desired state in manifests and letting controllers reconcile the cluster to match it.
- Secret
- A Kubernetes object for sensitive values, base64-encoded by default rather than encrypted.
- systemd-journald
- The systemd logging service that stores structured log data queried with journalctl.
- rsyslog
- A syslog daemon that routes messages by facility and priority to files or remote servers.
- Facility and priority
- Syslog categories for the message source (auth, cron, kern, local0...) and severity (debug through emerg).
- logrotate
- A utility that rotates, compresses and prunes log files according to rules in /etc/logrotate.d.
- Persistent journal
- Journal storage under /var/log/journal that survives reboots.
- logger
- A command that writes a test message into the system log with a chosen facility and priority.
Domain 3: Security (18%)
Exam tips
- Compute umask results by removing the umask bits from 666 for files and 777 for directories; a umask of 027 yields 640 files and 750 directories.
- Map the letters to positions: s in the user slot is SUID, s in the group slot is SGID, t in the others slot is the sticky bit; a + after the permissions means ACLs exist.
- The best-practice answer is almost never 'disable SELinux'; look for restorecon, semanage fcontext, semanage port or setsebool -P instead, and use permissive mode only temporarily to confirm SELinux is the cause.
- If a firewalld rule works now but disappears after reboot, it was added without --permanent; if a --permanent rule has no effect yet, the firewall was not reloaded.
- Order matters in hardening: confirm key-based login works before disabling PasswordAuthentication, and keep an existing session open while testing. 'Stop root logging in directly' is PermitRootLogin no, not removing root's password.
- Always choose visudo (or visudo -f for a drop-in) over editing sudoers with a normal editor, and remember that % in sudoers means a group. su needs the target's password; sudo needs your own.
- Remember the PAM control flags: requisite fails immediately, required fails at the end of the stack, and sufficient can end the stack early with success. Lockouts are pam_faillock; complexity is pam_pwquality.
- A checksum proves integrity only; a signature proves integrity and authenticity. Encryption (LUKS for data at rest, TLS for data in transit) is what provides confidentiality.
- After legitimate updates, the AIDE baseline must be updated, or every patched binary shows up as a change and real intrusions hide in the noise. disable stops startup at boot; mask blocks the unit entirely.
- Know the audit tool trio: auditctl manages rules, ausearch finds specific events, and aureport produces summaries. Persistent rules belong in /etc/audit/rules.d/, not only in auditctl.
Key terms
- Octal permissions
- Numeric notation where r=4, w=2, x=1 are summed for user, group and others, such as 750.
- Symbolic permissions
- Notation using u, g, o, a with +, - or = and r, w, x to change specific bits.
- Execute on a directory
- Permission to enter a directory and access its contents by name.
- Capital X
- A symbolic chmod bit that adds execute only to directories and files already executable by someone.
- chown
- Changes a file's owner and/or group owner, for example chown alice:devs file.
- umask
- A mask of permission bits removed from the defaults (666 files, 777 directories) when new files are created.
- SUID
- Special bit (4000) that makes an executable run with its owner's privileges; shown as s in the user execute slot.
- SGID
- Special bit (2000) that runs a program with the file's group or makes new files in a directory inherit its group.
- Sticky bit
- Directory bit (1000) that allows only a file's owner, the directory owner or root to delete or rename it.
- ACL
- Access control list: extra per-user or per-group permission entries managed with setfacl and getfacl.
- Default ACL
- An ACL on a directory that new files and subdirectories inherit when they are created.
- ACL mask
- The ACL entry that limits the maximum effective permissions for named users, named groups and the owning group.
- MAC
- Mandatory access control: a system-enforced policy that restricts programs regardless of file ownership.
- SELinux context
- The user:role:type:level label on files and processes; the type drives most targeted-policy decisions.
- restorecon
- Resets file SELinux labels to the defaults defined in policy.
- semanage fcontext
- Defines a persistent default SELinux label for a path pattern, applied by restorecon.
- SELinux boolean
- A policy switch toggled with setsebool (-P for persistent) to allow optional behaviors.
- AVC denial
- An access vector cache message in the audit log recording an action SELinux blocked or would block.
- AppArmor profile
- A path-based policy for one program, running in enforce or complain mode.
- netfilter
- The Linux kernel framework that performs packet filtering and NAT, configured by firewall tools.
- firewalld zone
- A named trust level with its own allowed services and ports, bound to interfaces or source addresses.
- --permanent
- firewall-cmd option that saves a change to configuration; it takes effect after --reload.
- Rich rule
- A firewalld rule with finer conditions, such as allowing a service only from a specific source subnet.
- ufw
- Uncomplicated Firewall, Ubuntu's simplified front end with persistent rules.
- nftables
- The modern netfilter rule framework managed with nft, replacing iptables.
- DROP vs REJECT
- DROP silently discards a packet; REJECT discards it and returns an error to the sender.
- Key-based authentication
- Logging in by proving possession of a private key whose public half is listed in the server's authorized_keys file.
- ssh-copy-id
- A helper that appends your public key to a remote account's authorized_keys and sets correct permissions.
- PermitRootLogin
- The sshd_config setting that controls whether root may log in directly over SSH (no, prohibit-password or yes).
- PasswordAuthentication
- The sshd_config setting that enables or disables password logins; set to no once keys work.
- StrictModes
- An sshd check that refuses keys when the home directory, ~/.ssh or authorized_keys are writable by other users.
- sshd -t
- Tests sshd configuration syntax without restarting the daemon.
- known_hosts
- The client file recording server host keys you have accepted, used to detect man-in-the-middle attacks.
- sudo
- Runs a command as root or another user after checking sudoers rules, using the caller's own password and logging the command.
- visudo
- Edits sudoers files with locking and syntax checking so a mistake cannot break sudo.
- /etc/sudoers.d
- A directory of drop-in sudoers files, each edited with visudo -f and ignored if the name contains a dot or ends in ~.
- su -
- Switches to another user, root by default, with a full login environment, using the target account's password.
- wheel / sudo group
- Groups granted full sudo rights on RHEL-family and Debian-family systems respectively.
- NOPASSWD
- A sudoers tag that lets a rule run without a password prompt, useful for automation but weaker.
- polkit
- A framework that authorizes unprivileged processes to perform specific privileged actions through system services, using rules in /etc/polkit-1/rules.d/.
- PAM
- Pluggable Authentication Modules, the framework through which Linux programs delegate authentication, account checks, password changes and session setup.
- Control flag
- The PAM keyword (required, requisite, sufficient, optional) that decides how a module's result affects the stack.
- pam_faillock
- A PAM module that locks an account after a set number of failed logins; managed with the faillock command.
- pam_pwquality
- A PAM module that enforces password strength rules from /etc/security/pwquality.conf when passwords change.
- SSSD
- The System Security Services Daemon, which connects Linux to LDAP, FreeIPA or Active Directory and caches identities and credentials.
- Kerberos TGT
- A ticket-granting ticket issued by the KDC after login, used to obtain service tickets without re-entering a password.
- MFA
- Multi-factor authentication, requiring two or more different factor types such as a password and a TOTP code.
- Hash
- A fixed-length, one-way digest of data that changes completely if the data changes; used to check integrity.
- GPG signature
- A value made with a private key that anyone with the matching public key can verify, proving integrity and authenticity.
- X.509 certificate
- A CA-signed document binding a public key to a name, used by TLS servers.
- CSR
- A certificate signing request containing a public key and identity details, sent to a CA to be signed.
- SAN
- Subject Alternative Name, the certificate field listing the host names the certificate is valid for.
- LUKS
- Linux Unified Key Setup, the standard format for full block-device encryption managed with cryptsetup.
- Key slot
- One of several LUKS entries that can each unlock the same volume with a different passphrase or key file.
- Attack surface
- The total set of services, software and interfaces an attacker could try to exploit.
- systemctl mask
- Links a unit to /dev/null so it cannot be started manually or as a dependency until unmasked.
- Secure Boot
- A UEFI feature that allows only signed boot loaders, kernels and modules to run.
- MOK
- Machine Owner Key, a locally enrolled key used to sign kernels or modules so they load under Secure Boot.
- AIDE
- Advanced Intrusion Detection Environment, a file integrity tool that compares files against a stored baseline of hashes and attributes.
- Patch management
- The process of finding, testing, applying and verifying software updates, prioritizing security fixes.
- Defense in depth
- Layering several independent controls so the failure of one does not expose the system.
- auditd
- The Linux audit daemon that records kernel-level security events to /var/log/audit/audit.log.
- Audit rule key (-k)
- A label attached to audit rules so related events can be found with ausearch -k.
- auid
- The audit user ID, the original login identity kept even after sudo or su.
- ausearch / aureport
- Tools that search audit logs for specific events and produce summary reports.
- CVE / CVSS
- Standard identifiers for known vulnerabilities and the scoring system used to rate their severity.
- CIS Benchmark
- A consensus-based, prioritized secure configuration guide for a specific operating system or application.
- OpenSCAP
- A tool that evaluates and can remediate systems against SCAP compliance profiles and produces reports.
Domain 4: Automation, orchestration, and scripting (17%)
Exam tips
- Look for spaces around = in assignments and unquoted variables; both are common deliberate errors in exam script questions. % trims from the end, # trims from the start.
- Numbers compare with -eq, -lt and -gt inside [ ], while = and != compare strings; using > in single brackets silently creates a file instead of comparing.
- Know what each strict-mode flag catches: -e failed commands, -u unset variables, and pipefail failures hidden inside pipelines. set -e does not fire inside if conditions or before ||.
- Pick the data type by need: a set for uniqueness and comparisons, a dict for key-value lookups, a list when order and duplicates matter, and a tuple for fixed records. Use a venv, not sudo pip.
- For shared branches, choose revert over reset and merge over rebase; history-rewriting commands belong only on local, unpublished work.
- Ansible is agentless and push-based over SSH; when a question contrasts it with Puppet or Chef, that difference is usually the point. command and shell are not idempotent unless guarded.
- Distinguish the models: Puppet is agent-based and pull; Ansible is agentless and push; OpenTofu/Terraform provision infrastructure, where plan previews and apply makes changes.
- In GitOps the rollback answer is almost always 'revert the commit in Git', not 'fix it directly on the server or cluster'. Delivery has a human gate; deployment does not.
- When a question asks for the best practice with AI-generated scripts, pick the answer that combines review, testing in a non-production environment and keeping credentials out of prompts, not the one that runs the output directly.
Key terms
- Shebang
- The #! first line that names the interpreter the kernel should use to run a script.
- Positional parameters
- The script's arguments, available as $1, $2 and so on, with $# as the count and $@ as the full list.
- Parameter expansion
- Shell syntax such as ${var:-default} or ${file%.txt} that substitutes or transforms variable values.
- Command substitution
- $(command), which replaces itself with the command's output.
- Exit status ($?)
- The 0 to 255 code a command returns, where 0 means success; $? holds the most recent one.
- source
- Runs a script in the current shell so its variables and directory changes persist.
- test / [ ]
- The command that evaluates file, string and integer expressions and returns 0 for true.
- [[ ]]
- Bash's extended test with pattern matching, =~ regular expressions and safer handling of unquoted variables.
- case
- A statement that matches one value against patterns, with ;; ending each branch and esac ending the block.
- while read loop
- while IFS= read -r line; do ...; done < file, the safe way to process a file line by line.
- local
- Declares a variable visible only inside the current function.
- Associative array
- A Bash array indexed by strings, created with declare -A.
- set -e
- Exits the script when a command fails outside a condition or || list.
- set -u
- Treats use of an unset variable as an error that stops the script.
- pipefail
- Makes a pipeline's exit status reflect the last failing command rather than only the final one.
- trap
- Registers a command to run on a signal or on EXIT, commonly used for cleanup.
- mktemp
- Creates a uniquely named temporary file or directory safely.
- Input validation
- Checking arguments and data against expected formats or allow-lists before using them.
- ShellCheck
- A static analysis tool that reports common shell script bugs with codes such as SC2086.
- list vs tuple
- Both are ordered sequences; lists can be changed, tuples cannot.
- set
- An unordered collection of unique items supporting union, intersection and difference.
- dict
- A mapping of keys to values, read with d[key] or d.get(key, default).
- venv
- A Python virtual environment that isolates a project's installed packages from the system Python.
- pip
- The Python package installer, used inside a venv to install libraries.
- requirements.txt
- A file listing exact package versions so an environment can be recreated with pip install -r.
- Commit
- A recorded snapshot of staged changes with an author, message and unique ID.
- Staging area
- The index where changes are prepared with git add before being committed.
- Branch
- A movable pointer to a line of commits, used to work on changes in isolation.
- merge vs rebase
- merge joins histories, possibly with a merge commit; rebase replays commits onto a new base for a linear history with new IDs.
- git revert
- Creates a new commit that undoes an earlier one without rewriting history.
- git reset
- Moves the branch pointer to an earlier commit, rewriting local history; --hard also discards changes.
- Pull request
- A hosting-platform request to review and merge a pushed branch, often gated by checks and approvals.
- Inventory
- The list of managed hosts and groups, in INI or YAML, optionally with host and group variables.
- Module
- A small unit of work, such as dnf or copy, that Ansible pushes to a host and runs.
- Ad hoc command
- A single module run from the command line against a host pattern, such as ansible all -m ping.
- Playbook
- A YAML file of plays and tasks describing the desired state of target hosts.
- Handler
- A task that runs only when notified by a change, typically to restart or reload a service.
- Idempotence
- The property that repeating an operation leaves an already-correct system unchanged.
- ansible-vault
- The tool that encrypts files or strings containing secrets for use in playbooks.
- Agent-based configuration management
- A model where software on each node pulls and enforces its configuration from a central server.
- Puppet catalog
- The compiled description of a node's desired state that the Puppet server sends to the agent.
- Facter
- The Puppet tool that gathers facts about a node, such as OS and IP addresses.
- Infrastructure as code
- Defining servers, networks and other resources in version-controlled declarative files.
- plan
- The OpenTofu/Terraform command that previews creations, changes and destructions without applying them.
- State file
- The record mapping configuration to real resource IDs, kept in a secured, locked backend.
- Drift
- Differences between the declared configuration and the real system, often caused by manual changes.
- Continuous integration
- Merging small changes frequently, with each change automatically built and tested.
- Continuous delivery vs deployment
- Delivery keeps every passing change releasable behind a manual approval; deployment releases automatically.
- Pipeline
- A version-controlled definition of stages and jobs that build, test and deploy changes.
- Artifact
- An output of a pipeline job, such as a package or container image, passed to later stages.
- GitOps
- Operating systems by declaring desired state in Git and having an agent reconcile the live environment to it.
- Canary release
- Sending a small share of traffic to a new version before rolling it out fully.
- Human in the loop
- A person reviews and approves AI output before it is used or run.
- Hallucination
- Confident but incorrect AI output, such as a nonexistent option or package.
- Prompt data leakage
- Sensitive information exposed by pasting it into an external AI service.
- Sanitization
- Replacing secrets and identifying details with placeholders before sharing text.
- Acceptable use policy
- An organization's rules for how tools such as AI assistants may be used and with what data.
- Dry run
- A mode that shows what a script or tool would do without making changes.
Domain 5: Troubleshooting (22%)
Exam tips
- If df -h shows free space but writes fail, think inodes (df -i). If df shows full but du cannot find the data, think deleted-but-open files (lsof +L1).
- A high load average does not automatically mean high CPU; check wa and iostat, because processes stuck waiting on I/O also count toward load on Linux.
- Work bottom-up: link and IP, gateway, remote IP, DNS name, then the service port. If IPs work but names fail, focus on DNS and nsswitch rather than routing.
- Emergency mode right after a storage change almost always means /etc/fstab; a kernel panic right after an update usually means booting the previous kernel from GRUB.
- Exit codes in the 200s come from systemd before the program runs, so check the unit file (paths, User=, directories); small codes like 1 usually mean the application itself reported an error in its logs.
- When access fails but permissions look fine on an SELinux system, check ausearch -m avc before touching chmod; the fix is usually restorecon, semanage or a boolean, never disabling SELinux.
- An array showing [U_] in /proc/mdstat is degraded: it still works, but the failed member must be replaced before another disk fails. RAID is not a backup.
- Certificate 'not yet valid' errors on a single host, Kerberos 'clock skew too great' messages and rejected MFA codes are all classic signs of a wrong system clock.
- Repository GPG errors are fixed by importing the correct, verified key, not by setting gpgcheck=0 or trusting unsigned repositories. 'Kept back' means look for holds or new dependencies.
- Check logs first, then inspect: podman logs explains most application crashes, and podman inspect reveals exit codes, OOM kills, mounts and port mappings.
Key terms
- Inode
- The on-disk structure holding a file's metadata; each file needs one.
- Inode exhaustion
- Running out of inodes so no new files can be created even though free blocks remain.
- Deleted-but-open file
- A deleted file whose data stays allocated because a process still holds it open.
- lsof +L1
- Lists open files with a link count below one, meaning they have been deleted.
- fsck / e2fsck
- Checks and repairs ext2/3/4 filesystems; run on unmounted devices.
- xfs_repair
- Checks and repairs XFS filesystems on an unmounted device; -L zeroes the log as a last resort.
- Reserved blocks
- The share of an ext4 filesystem kept for root, adjustable with tune2fs -m.
- Load average
- The 1, 5 and 15 minute averages of runnable plus uninterruptible processes, read relative to core count.
- I/O wait (wa)
- CPU time spent idle while waiting for disk or network I/O to complete.
- Available memory
- The estimate in free of memory that can be given to applications without swapping.
- vmstat
- Reports run queue, blocked processes, swap activity, I/O and CPU in periodic samples.
- iostat
- Reports per-device I/O rates, await and %util; part of sysstat.
- sar
- The sysstat tool that records and reports historical CPU, memory, I/O and network data.
- OOM killer
- The kernel mechanism that kills a process to free memory when RAM and swap are exhausted.
- Default route
- The route used for destinations with no more specific entry, shown as default via in ip route.
- ss
- The socket statistics tool that lists listening ports, connections and owning processes.
- dig
- A DNS query tool that shows answers, TTLs and the responding server.
- resolvectl
- The client for systemd-resolved, showing per-link DNS servers and resolving names through the system resolver.
- mtr
- A tool combining ping and traceroute to show per-hop loss and latency continuously.
- tcpdump
- A command-line packet capture tool with filters, able to save pcap files.
- nmap
- A port scanner that reports open, closed and filtered ports and can identify services.
- GRUB rescue prompt
- A minimal GRUB shell shown when the boot loader cannot find its configuration or modules.
- Previous kernel
- An older installed kernel selectable from the GRUB menu, used when a new one fails.
- initramfs
- The initial RAM filesystem with drivers and tools needed to mount the real root filesystem.
- rescue.target
- A single-user systemd target with local filesystems mounted and minimal services.
- emergency.target
- The most minimal systemd target, with root mounted read-only and almost nothing else started.
- chroot
- Runs commands with a different directory as root, used to repair an installed system from rescue media.
- nofail
- An fstab option that lets boot continue if that filesystem cannot be mounted.
- 203/EXEC
- A systemd exit status meaning the ExecStart program could not be executed.
- start-limit-hit
- A result meaning systemd stopped restarting a unit after too many failures in a short period.
- Requires= / After=
- Requires pulls in a hard dependency; After only orders startup and pulls nothing in.
- daemon-reload
- systemctl daemon-reload, which makes systemd reread changed unit files.
- Address already in use
- The bind error when another process already listens on the requested address and port.
- Config test
- An application's own syntax checker, such as nginx -t or apachectl configtest, run before restarting.
- AVC denial
- An SELinux access vector cache message recording a blocked access, found with ausearch -m avc.
- restorecon
- Resets SELinux file labels to the values defined by policy.
- semanage fcontext
- Adds a persistent SELinux labeling rule for a path, applied with restorecon.
- SELinux boolean
- An on/off policy switch such as httpd_can_network_connect, set persistently with setsebool -P.
- StrictModes
- The sshd check that refuses keys when home, ~/.ssh or authorized_keys permissions are too open.
- namei -l
- Shows permissions for every component of a path, revealing a missing execute bit on a parent directory.
- passwd -S
- Shows an account's password status, including whether it is locked.
- dmesg
- Prints the kernel ring buffer of hardware detection, driver and error messages.
- lspci -k
- Lists PCI devices together with the kernel driver in use for each.
- lsusb
- Lists USB devices, with -t for a tree view.
- SMART
- Self-Monitoring, Analysis and Reporting Technology, the health data disks keep about themselves, read with smartctl.
- Reallocated sectors
- Bad sectors a disk has remapped to spares; a rising count signals a failing drive.
- Degraded array
- A RAID array still serving data after losing a member, but without redundancy.
- mdadm
- The tool for creating, monitoring and repairing Linux software RAID arrays.
- NTP
- Network Time Protocol, which synchronizes clocks with time servers over UDP port 123.
- chrony
- The common Linux NTP implementation, with chronyd as the daemon and chronyc as the client.
- timedatectl
- Shows and sets system time, time zone and whether NTP synchronization is enabled.
- RTC
- The real-time (hardware) clock that keeps time while the system is powered off.
- Stratum
- An NTP server's distance from a reference clock; lower numbers are closer.
- Clock skew
- The difference between clocks on different systems, which breaks time-sensitive protocols.
- Dependency conflict
- A situation where required package versions cannot all be satisfied together.
- apt --fix-broken install
- Attempts to complete or repair broken dependencies on Debian-family systems.
- dpkg --configure -a
- Finishes configuring packages left half-installed by an interruption.
- NO_PUBKEY
- An apt error meaning the repository's signing key is not installed.
- apt-mark hold
- Prevents a package from being upgraded on Debian-family systems.
- dnf versionlock
- A dnf plug-in that locks packages at their current version.
- dnf history undo
- Rolls back a recorded dnf transaction.
- Exit code 137
- A container exit caused by SIGKILL (128 + 9), often from the OOM killer or a memory limit.
- podman ps -a
- Lists all containers, including stopped ones, with their status.
- podman inspect
- Shows detailed container configuration and state, including exit code, OOMKilled, mounts and ports.
- registries.conf
- The file that defines registries and how short image names are resolved.
- podman system df
- Summarizes disk space used by images, containers and volumes.
- Z volume option
- The :Z or :z suffix on -v that relabels a bind mount for SELinux container access.
- Rootless container
- A container run by an unprivileged user, with UIDs mapped to subordinate IDs on the host.
Study Linux+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Linux+ study planLessons, quizzes, exam simulations and hands-on labs.