StudyToCert

All certifications / Linux+ / Cheat sheet

Linux+ XK0-006 cheat sheet

Every exam tip and key term from the free Linux+ lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: System management (23%)

Exam tips

Key terms

UEFI
Unified Extensible Firmware Interface: modern firmware that boots EFI executables from an EFI System Partition and supports Secure Boot.
ESP
EFI System Partition: a small FAT partition, usually mounted at /boot/efi, that holds UEFI boot loaders.
GRUB2
The standard Linux boot loader; configured through /etc/default/grub and a generated grub.cfg.
initramfs
A compressed temporary root filesystem loaded into RAM that contains the drivers and scripts needed to mount the real root filesystem.
dracut / mkinitramfs
Tools that build the initramfs image: dracut on Red Hat-family and SUSE, mkinitramfs/update-initramfs on Debian-family.
systemd target
A unit that groups other units into a system state, such as multi-user.target or graphical.target, replacing SysV runlevels.
Secure Boot
A UEFI feature that only runs boot loaders and kernels signed with trusted keys.
FHS
Filesystem Hierarchy Standard: the convention that defines the purpose of top-level Linux directories.
/etc
The directory for host-specific configuration files.
/var
The directory for variable data such as logs, spools, caches and application state.
/usr/local
The area reserved for locally installed software that the package manager will not touch.
/proc
A virtual filesystem exposing process and kernel information, including tunables under /proc/sys.
/sys
Sysfs, a virtual filesystem exposing devices, drivers and kernel objects.
/dev
The directory of device files, such as /dev/sda and /dev/null, maintained by udev.
Kernel module
A loadable piece of kernel code (.ko file), such as a driver, that can be inserted or removed while the system runs.
modprobe
Loads or removes (-r) a module together with its dependencies, reading options from /etc/modprobe.d.
modinfo
Displays a module's file path, description, dependencies and supported parameters.
depmod
Builds the modules.dep dependency map that modprobe uses to load dependencies.
Blacklist
A modprobe.d directive that prevents a module from being loaded automatically by its alias.
sysctl
A tool to view and set kernel runtime parameters under /proc/sys; persistent values go in /etc/sysctl.d/*.conf.
Inode
The on-disk structure holding a file's metadata and pointers to its data; directory entries map names to inode numbers.
Hard link
An additional directory entry for the same inode; cannot cross filesystems and survives deletion of the other names.
Symbolic link
A separate file that stores a path to a target; can cross filesystems but breaks if the target is removed.
mtime vs ctime
mtime changes when file contents change; ctime changes when metadata such as permissions or ownership changes.
find -exec
A find action that runs a command on each matched file, with {} replaced by the file name.
locate
A fast file-name search that uses a database built by updatedb, so it can miss recently created files.
GPT
GUID Partition Table: modern partition scheme supporting very large disks, many partitions and a backup table.
MBR
Master Boot Record: legacy partition scheme limited to four primary partitions and roughly 2 TiB disks.
UUID
A unique identifier stored in a filesystem, used in /etc/fstab so mounts do not depend on device names.
partprobe
Asks the kernel to reread a disk's partition table so changes take effect without a reboot.
nofail
An fstab option that lets boot continue if the device is not present.
noexec
An fstab option that prevents executing binaries stored on that filesystem.
PV / VG / LV
Physical volume (a disk prepared for LVM), volume group (a pool of PVs) and logical volume (a usable volume carved from the pool).
Extent
The fixed-size unit of space LVM allocates from a volume group to logical volumes.
lvextend -r
Extends a logical volume and resizes its filesystem in the same command.
vgextend
Adds a new physical volume to an existing volume group to increase its free space.
mdadm
The Linux tool for creating, monitoring and managing software RAID arrays (/dev/mdN).
/proc/mdstat
A kernel status file showing each software RAID array, its members and any rebuild progress.
RAID 5
Striping with distributed parity across at least three disks, surviving the loss of one disk.
Journaling
A technique where a filesystem logs pending metadata changes so it can recover consistently after a crash.
XFS
A high-performance journaling filesystem, default on RHEL, that can grow online but cannot shrink.
Btrfs
A copy-on-write filesystem with subvolumes, snapshots, checksums and integrated multi-device support.
resize2fs
Grows or shrinks an ext2/3/4 filesystem to fit its device.
xfs_growfs
Grows a mounted XFS filesystem, specified by its mount point.
df vs du
df reports free and used space per filesystem; du totals the space used by files and directories.
Inode exhaustion
A filesystem running out of inodes, so no new files can be created even though free blocks remain; seen with df -i.
iproute2 (ip)
The modern suite for viewing and changing interfaces, addresses, routes and neighbors; changes are not persistent.
nmcli
Command-line client for NetworkManager that manages persistent connection profiles.
netplan
Ubuntu's YAML-based network configuration system that renders settings for systemd-networkd or NetworkManager.
hostnamectl
systemd tool that shows and permanently sets the system hostname.
/etc/resolv.conf
Lists DNS nameservers and search domains used by the system resolver.
nsswitch.conf
Defines the order of lookup sources (files, dns, sss, etc.) for hosts, users, groups and more.
File descriptor
A number identifying an open stream: 0 is stdin, 1 is stdout and 2 is stderr.
Pipe
The | operator that sends one command's standard output to another command's standard input.
export
Marks a shell variable so it is passed to child processes as an environment variable.
tee
Copies its standard input to a file and to standard output at the same time.
sed
A stream editor used mainly for search-and-replace and line filtering; -i edits files in place.
awk
A pattern-scanning language that splits lines into fields ($1, $2 ...) for filtering and reporting.
tar
Archiving tool that bundles files while preserving metadata; -c create, -x extract, -t list, -f file, with -z/-j/-J for gzip/bzip2/xz.
rsync
Incremental file synchronization tool that transfers only differences, locally or over SSH.
dd
Block-level copy tool used for disk images and writing raw devices; if= input, of= output.
cpio
Archiver that takes file lists on stdin, commonly paired with find; used in initramfs and RPM payloads.
xz
A compressor that usually achieves higher compression than gzip or bzip2 at the cost of speed.
rsync --delete
Removes files from the destination that no longer exist at the source, producing an exact mirror.
KVM
Kernel-based Virtual Machine: kernel modules that use CPU virtualization extensions to make Linux a hypervisor.
QEMU
The emulator that supplies virtual hardware and, with KVM, runs guests at near-native speed.
libvirt / virsh
A management API and daemon for hypervisors, and its command-line client for controlling guests.
qcow2
A thin-provisioned QEMU disk format supporting snapshots, backing files and compression.
Raw image
A plain byte-for-byte disk image with no metadata features, valued for simplicity and performance.
virtio
Paravirtualized device drivers that give guests fast disk and network I/O.
Backing file
A read-only base image that a qcow2 overlay refers to, storing only the overlay's changes.

Domain 2: Services and user management (20%)

Exam tips

Key terms

UID / GID
Numeric user and group identifiers the kernel actually uses for ownership and permission checks.
Primary group
The group assigned to a user in /etc/passwd and given to files the user creates.
Supplementary group
Additional groups a user belongs to, listed in /etc/group, that grant extra access.
usermod -aG
Appends a user to supplementary groups without removing existing memberships.
chage
Command that views and sets password aging and account expiry for a user.
System account
A low-privilege account created with useradd -r for running a service, usually with no login shell.
/etc/passwd
World-readable account database with seven fields: name, x, UID, GID, GECOS, home and shell.
/etc/shadow
Root-only file holding password hashes and password aging and expiry fields.
/etc/group
Group database listing group name, GID and supplementary members.
/etc/skel
Template directory whose files are copied into new users' home directories.
/etc/login.defs
Configuration of defaults for account tools, such as UID ranges and password aging.
vipw / vigr
Tools that lock and safely edit the passwd and group files (and their shadow versions with -s).
Unit
A systemd configuration object such as a .service, .socket, .timer, .mount or .target.
enable vs start
enable configures a unit to start at boot; start runs it now. Neither implies the other.
mask
Links a unit to /dev/null so it cannot be started manually or as a dependency.
Drop-in override
A .conf file in /etc/systemd/system/<unit>.d/ that overrides selected settings of a unit.
daemon-reload
Tells systemd to reread unit files after they change on disk.
WantedBy=
An [Install] setting naming the target that should pull the unit in when it is enabled.
crontab
A per-user table of scheduled jobs, edited with crontab -e, using five time fields plus a command.
at
Schedules a command to run once at a future time; managed with atq and atrm and run by atd.
systemd timer
A .timer unit that activates a matching .service unit on a schedule.
OnCalendar
A timer setting that defines wall-clock schedules, such as Mon..Fri *-*-* 02:30:00.
Persistent=true
A timer option that runs a missed job at the next opportunity after downtime.
cron.allow / cron.deny
Files that control which users may create crontabs; if cron.allow exists, only listed users may.
PID / PPID
Process ID and parent process ID, used to identify processes and their relationships.
SIGTERM vs SIGKILL
SIGTERM (15) asks a process to exit cleanly; SIGKILL (9) forces termination and cannot be caught.
SIGHUP
Signal 1, sent on terminal hangup and used by many daemons as a request to reload configuration.
Nice value
A priority adjustment from -20 (most favored) to 19 (least favored); only root can lower it.
Zombie process
A terminated process whose exit status has not yet been collected by its parent, shown with state Z.
nohup
Runs a command immune to hangup signals so it keeps running after the user logs out.
rpm / dpkg
Low-level package tools that install and query individual package files without resolving dependencies.
dnf / apt
High-level package managers that download from repositories and resolve dependencies.
Repository
A server or location holding packages and signed metadata, configured in /etc/yum.repos.d or /etc/apt/sources.list(.d).
rpm -qf / dpkg -S
Queries that report which installed package owns a given file.
dnf provides
Searches repositories for the package that supplies a given file or command.
rpm -V
Verifies installed package files against the package database and reports changes.
gpgcheck
A repository setting that requires valid GPG signatures on packages before installation.
make
A build tool that reads a Makefile and runs the steps to compile software; make install copies it into place.
./configure
A script that checks build dependencies and generates a Makefile, often with --prefix to set the install path.
pip
Python's package installer, best used inside a virtual environment.
Virtual environment
An isolated Python environment created with python3 -m venv so project packages do not affect the system.
Flatpak
A sandboxed universal packaging format mainly for desktop apps, commonly installed from Flathub.
Snap
Canonical's sandboxed package format managed by snapd, with automatic refreshes and confinement modes.
Image
A read-only, layered template (name:tag) from which containers are created.
Container
An isolated process running from an image with its own writable layer, sharing the host kernel.
Namespaces and cgroups
Kernel features that give containers isolated views of the system and limit their resource use.
Port publishing
The -p host:container option that maps a host port to a port inside the container.
Volume
Persistent storage managed by the container engine or bind-mounted from the host, surviving container removal.
Rootless container
A container run by an unprivileged user, as Podman supports, limiting the impact of a compromise.
Pod
The smallest Kubernetes unit: one or more containers sharing an IP address and volumes.
Deployment
An object that declares an image and replica count, maintains that many pods and performs rolling updates.
Service
A stable virtual IP and DNS name that load-balances traffic to pods selected by labels.
kubectl
The command-line client that talks to the Kubernetes API server.
Declarative configuration
Describing desired state in manifests and letting controllers reconcile the cluster to match it.
Secret
A Kubernetes object for sensitive values, base64-encoded by default rather than encrypted.
systemd-journald
The systemd logging service that stores structured log data queried with journalctl.
rsyslog
A syslog daemon that routes messages by facility and priority to files or remote servers.
Facility and priority
Syslog categories for the message source (auth, cron, kern, local0...) and severity (debug through emerg).
logrotate
A utility that rotates, compresses and prunes log files according to rules in /etc/logrotate.d.
Persistent journal
Journal storage under /var/log/journal that survives reboots.
logger
A command that writes a test message into the system log with a chosen facility and priority.

Domain 3: Security (18%)

Exam tips

Key terms

Octal permissions
Numeric notation where r=4, w=2, x=1 are summed for user, group and others, such as 750.
Symbolic permissions
Notation using u, g, o, a with +, - or = and r, w, x to change specific bits.
Execute on a directory
Permission to enter a directory and access its contents by name.
Capital X
A symbolic chmod bit that adds execute only to directories and files already executable by someone.
chown
Changes a file's owner and/or group owner, for example chown alice:devs file.
umask
A mask of permission bits removed from the defaults (666 files, 777 directories) when new files are created.
SUID
Special bit (4000) that makes an executable run with its owner's privileges; shown as s in the user execute slot.
SGID
Special bit (2000) that runs a program with the file's group or makes new files in a directory inherit its group.
Sticky bit
Directory bit (1000) that allows only a file's owner, the directory owner or root to delete or rename it.
ACL
Access control list: extra per-user or per-group permission entries managed with setfacl and getfacl.
Default ACL
An ACL on a directory that new files and subdirectories inherit when they are created.
ACL mask
The ACL entry that limits the maximum effective permissions for named users, named groups and the owning group.
MAC
Mandatory access control: a system-enforced policy that restricts programs regardless of file ownership.
SELinux context
The user:role:type:level label on files and processes; the type drives most targeted-policy decisions.
restorecon
Resets file SELinux labels to the defaults defined in policy.
semanage fcontext
Defines a persistent default SELinux label for a path pattern, applied by restorecon.
SELinux boolean
A policy switch toggled with setsebool (-P for persistent) to allow optional behaviors.
AVC denial
An access vector cache message in the audit log recording an action SELinux blocked or would block.
AppArmor profile
A path-based policy for one program, running in enforce or complain mode.
netfilter
The Linux kernel framework that performs packet filtering and NAT, configured by firewall tools.
firewalld zone
A named trust level with its own allowed services and ports, bound to interfaces or source addresses.
--permanent
firewall-cmd option that saves a change to configuration; it takes effect after --reload.
Rich rule
A firewalld rule with finer conditions, such as allowing a service only from a specific source subnet.
ufw
Uncomplicated Firewall, Ubuntu's simplified front end with persistent rules.
nftables
The modern netfilter rule framework managed with nft, replacing iptables.
DROP vs REJECT
DROP silently discards a packet; REJECT discards it and returns an error to the sender.
Key-based authentication
Logging in by proving possession of a private key whose public half is listed in the server's authorized_keys file.
ssh-copy-id
A helper that appends your public key to a remote account's authorized_keys and sets correct permissions.
PermitRootLogin
The sshd_config setting that controls whether root may log in directly over SSH (no, prohibit-password or yes).
PasswordAuthentication
The sshd_config setting that enables or disables password logins; set to no once keys work.
StrictModes
An sshd check that refuses keys when the home directory, ~/.ssh or authorized_keys are writable by other users.
sshd -t
Tests sshd configuration syntax without restarting the daemon.
known_hosts
The client file recording server host keys you have accepted, used to detect man-in-the-middle attacks.
sudo
Runs a command as root or another user after checking sudoers rules, using the caller's own password and logging the command.
visudo
Edits sudoers files with locking and syntax checking so a mistake cannot break sudo.
/etc/sudoers.d
A directory of drop-in sudoers files, each edited with visudo -f and ignored if the name contains a dot or ends in ~.
su -
Switches to another user, root by default, with a full login environment, using the target account's password.
wheel / sudo group
Groups granted full sudo rights on RHEL-family and Debian-family systems respectively.
NOPASSWD
A sudoers tag that lets a rule run without a password prompt, useful for automation but weaker.
polkit
A framework that authorizes unprivileged processes to perform specific privileged actions through system services, using rules in /etc/polkit-1/rules.d/.
PAM
Pluggable Authentication Modules, the framework through which Linux programs delegate authentication, account checks, password changes and session setup.
Control flag
The PAM keyword (required, requisite, sufficient, optional) that decides how a module's result affects the stack.
pam_faillock
A PAM module that locks an account after a set number of failed logins; managed with the faillock command.
pam_pwquality
A PAM module that enforces password strength rules from /etc/security/pwquality.conf when passwords change.
SSSD
The System Security Services Daemon, which connects Linux to LDAP, FreeIPA or Active Directory and caches identities and credentials.
Kerberos TGT
A ticket-granting ticket issued by the KDC after login, used to obtain service tickets without re-entering a password.
MFA
Multi-factor authentication, requiring two or more different factor types such as a password and a TOTP code.
Hash
A fixed-length, one-way digest of data that changes completely if the data changes; used to check integrity.
GPG signature
A value made with a private key that anyone with the matching public key can verify, proving integrity and authenticity.
X.509 certificate
A CA-signed document binding a public key to a name, used by TLS servers.
CSR
A certificate signing request containing a public key and identity details, sent to a CA to be signed.
SAN
Subject Alternative Name, the certificate field listing the host names the certificate is valid for.
LUKS
Linux Unified Key Setup, the standard format for full block-device encryption managed with cryptsetup.
Key slot
One of several LUKS entries that can each unlock the same volume with a different passphrase or key file.
Attack surface
The total set of services, software and interfaces an attacker could try to exploit.
systemctl mask
Links a unit to /dev/null so it cannot be started manually or as a dependency until unmasked.
Secure Boot
A UEFI feature that allows only signed boot loaders, kernels and modules to run.
MOK
Machine Owner Key, a locally enrolled key used to sign kernels or modules so they load under Secure Boot.
AIDE
Advanced Intrusion Detection Environment, a file integrity tool that compares files against a stored baseline of hashes and attributes.
Patch management
The process of finding, testing, applying and verifying software updates, prioritizing security fixes.
Defense in depth
Layering several independent controls so the failure of one does not expose the system.
auditd
The Linux audit daemon that records kernel-level security events to /var/log/audit/audit.log.
Audit rule key (-k)
A label attached to audit rules so related events can be found with ausearch -k.
auid
The audit user ID, the original login identity kept even after sudo or su.
ausearch / aureport
Tools that search audit logs for specific events and produce summary reports.
CVE / CVSS
Standard identifiers for known vulnerabilities and the scoring system used to rate their severity.
CIS Benchmark
A consensus-based, prioritized secure configuration guide for a specific operating system or application.
OpenSCAP
A tool that evaluates and can remediate systems against SCAP compliance profiles and produces reports.

Domain 4: Automation, orchestration, and scripting (17%)

Exam tips

Key terms

Shebang
The #! first line that names the interpreter the kernel should use to run a script.
Positional parameters
The script's arguments, available as $1, $2 and so on, with $# as the count and $@ as the full list.
Parameter expansion
Shell syntax such as ${var:-default} or ${file%.txt} that substitutes or transforms variable values.
Command substitution
$(command), which replaces itself with the command's output.
Exit status ($?)
The 0 to 255 code a command returns, where 0 means success; $? holds the most recent one.
source
Runs a script in the current shell so its variables and directory changes persist.
test / [ ]
The command that evaluates file, string and integer expressions and returns 0 for true.
[[ ]]
Bash's extended test with pattern matching, =~ regular expressions and safer handling of unquoted variables.
case
A statement that matches one value against patterns, with ;; ending each branch and esac ending the block.
while read loop
while IFS= read -r line; do ...; done < file, the safe way to process a file line by line.
local
Declares a variable visible only inside the current function.
Associative array
A Bash array indexed by strings, created with declare -A.
set -e
Exits the script when a command fails outside a condition or || list.
set -u
Treats use of an unset variable as an error that stops the script.
pipefail
Makes a pipeline's exit status reflect the last failing command rather than only the final one.
trap
Registers a command to run on a signal or on EXIT, commonly used for cleanup.
mktemp
Creates a uniquely named temporary file or directory safely.
Input validation
Checking arguments and data against expected formats or allow-lists before using them.
ShellCheck
A static analysis tool that reports common shell script bugs with codes such as SC2086.
list vs tuple
Both are ordered sequences; lists can be changed, tuples cannot.
set
An unordered collection of unique items supporting union, intersection and difference.
dict
A mapping of keys to values, read with d[key] or d.get(key, default).
venv
A Python virtual environment that isolates a project's installed packages from the system Python.
pip
The Python package installer, used inside a venv to install libraries.
requirements.txt
A file listing exact package versions so an environment can be recreated with pip install -r.
Commit
A recorded snapshot of staged changes with an author, message and unique ID.
Staging area
The index where changes are prepared with git add before being committed.
Branch
A movable pointer to a line of commits, used to work on changes in isolation.
merge vs rebase
merge joins histories, possibly with a merge commit; rebase replays commits onto a new base for a linear history with new IDs.
git revert
Creates a new commit that undoes an earlier one without rewriting history.
git reset
Moves the branch pointer to an earlier commit, rewriting local history; --hard also discards changes.
Pull request
A hosting-platform request to review and merge a pushed branch, often gated by checks and approvals.
Inventory
The list of managed hosts and groups, in INI or YAML, optionally with host and group variables.
Module
A small unit of work, such as dnf or copy, that Ansible pushes to a host and runs.
Ad hoc command
A single module run from the command line against a host pattern, such as ansible all -m ping.
Playbook
A YAML file of plays and tasks describing the desired state of target hosts.
Handler
A task that runs only when notified by a change, typically to restart or reload a service.
Idempotence
The property that repeating an operation leaves an already-correct system unchanged.
ansible-vault
The tool that encrypts files or strings containing secrets for use in playbooks.
Agent-based configuration management
A model where software on each node pulls and enforces its configuration from a central server.
Puppet catalog
The compiled description of a node's desired state that the Puppet server sends to the agent.
Facter
The Puppet tool that gathers facts about a node, such as OS and IP addresses.
Infrastructure as code
Defining servers, networks and other resources in version-controlled declarative files.
plan
The OpenTofu/Terraform command that previews creations, changes and destructions without applying them.
State file
The record mapping configuration to real resource IDs, kept in a secured, locked backend.
Drift
Differences between the declared configuration and the real system, often caused by manual changes.
Continuous integration
Merging small changes frequently, with each change automatically built and tested.
Continuous delivery vs deployment
Delivery keeps every passing change releasable behind a manual approval; deployment releases automatically.
Pipeline
A version-controlled definition of stages and jobs that build, test and deploy changes.
Artifact
An output of a pipeline job, such as a package or container image, passed to later stages.
GitOps
Operating systems by declaring desired state in Git and having an agent reconcile the live environment to it.
Canary release
Sending a small share of traffic to a new version before rolling it out fully.
Human in the loop
A person reviews and approves AI output before it is used or run.
Hallucination
Confident but incorrect AI output, such as a nonexistent option or package.
Prompt data leakage
Sensitive information exposed by pasting it into an external AI service.
Sanitization
Replacing secrets and identifying details with placeholders before sharing text.
Acceptable use policy
An organization's rules for how tools such as AI assistants may be used and with what data.
Dry run
A mode that shows what a script or tool would do without making changes.

Domain 5: Troubleshooting (22%)

Exam tips

Key terms

Inode
The on-disk structure holding a file's metadata; each file needs one.
Inode exhaustion
Running out of inodes so no new files can be created even though free blocks remain.
Deleted-but-open file
A deleted file whose data stays allocated because a process still holds it open.
lsof +L1
Lists open files with a link count below one, meaning they have been deleted.
fsck / e2fsck
Checks and repairs ext2/3/4 filesystems; run on unmounted devices.
xfs_repair
Checks and repairs XFS filesystems on an unmounted device; -L zeroes the log as a last resort.
Reserved blocks
The share of an ext4 filesystem kept for root, adjustable with tune2fs -m.
Load average
The 1, 5 and 15 minute averages of runnable plus uninterruptible processes, read relative to core count.
I/O wait (wa)
CPU time spent idle while waiting for disk or network I/O to complete.
Available memory
The estimate in free of memory that can be given to applications without swapping.
vmstat
Reports run queue, blocked processes, swap activity, I/O and CPU in periodic samples.
iostat
Reports per-device I/O rates, await and %util; part of sysstat.
sar
The sysstat tool that records and reports historical CPU, memory, I/O and network data.
OOM killer
The kernel mechanism that kills a process to free memory when RAM and swap are exhausted.
Default route
The route used for destinations with no more specific entry, shown as default via in ip route.
ss
The socket statistics tool that lists listening ports, connections and owning processes.
dig
A DNS query tool that shows answers, TTLs and the responding server.
resolvectl
The client for systemd-resolved, showing per-link DNS servers and resolving names through the system resolver.
mtr
A tool combining ping and traceroute to show per-hop loss and latency continuously.
tcpdump
A command-line packet capture tool with filters, able to save pcap files.
nmap
A port scanner that reports open, closed and filtered ports and can identify services.
GRUB rescue prompt
A minimal GRUB shell shown when the boot loader cannot find its configuration or modules.
Previous kernel
An older installed kernel selectable from the GRUB menu, used when a new one fails.
initramfs
The initial RAM filesystem with drivers and tools needed to mount the real root filesystem.
rescue.target
A single-user systemd target with local filesystems mounted and minimal services.
emergency.target
The most minimal systemd target, with root mounted read-only and almost nothing else started.
chroot
Runs commands with a different directory as root, used to repair an installed system from rescue media.
nofail
An fstab option that lets boot continue if that filesystem cannot be mounted.
203/EXEC
A systemd exit status meaning the ExecStart program could not be executed.
start-limit-hit
A result meaning systemd stopped restarting a unit after too many failures in a short period.
Requires= / After=
Requires pulls in a hard dependency; After only orders startup and pulls nothing in.
daemon-reload
systemctl daemon-reload, which makes systemd reread changed unit files.
Address already in use
The bind error when another process already listens on the requested address and port.
Config test
An application's own syntax checker, such as nginx -t or apachectl configtest, run before restarting.
AVC denial
An SELinux access vector cache message recording a blocked access, found with ausearch -m avc.
restorecon
Resets SELinux file labels to the values defined by policy.
semanage fcontext
Adds a persistent SELinux labeling rule for a path, applied with restorecon.
SELinux boolean
An on/off policy switch such as httpd_can_network_connect, set persistently with setsebool -P.
StrictModes
The sshd check that refuses keys when home, ~/.ssh or authorized_keys permissions are too open.
namei -l
Shows permissions for every component of a path, revealing a missing execute bit on a parent directory.
passwd -S
Shows an account's password status, including whether it is locked.
dmesg
Prints the kernel ring buffer of hardware detection, driver and error messages.
lspci -k
Lists PCI devices together with the kernel driver in use for each.
lsusb
Lists USB devices, with -t for a tree view.
SMART
Self-Monitoring, Analysis and Reporting Technology, the health data disks keep about themselves, read with smartctl.
Reallocated sectors
Bad sectors a disk has remapped to spares; a rising count signals a failing drive.
Degraded array
A RAID array still serving data after losing a member, but without redundancy.
mdadm
The tool for creating, monitoring and repairing Linux software RAID arrays.
NTP
Network Time Protocol, which synchronizes clocks with time servers over UDP port 123.
chrony
The common Linux NTP implementation, with chronyd as the daemon and chronyc as the client.
timedatectl
Shows and sets system time, time zone and whether NTP synchronization is enabled.
RTC
The real-time (hardware) clock that keeps time while the system is powered off.
Stratum
An NTP server's distance from a reference clock; lower numbers are closer.
Clock skew
The difference between clocks on different systems, which breaks time-sensitive protocols.
Dependency conflict
A situation where required package versions cannot all be satisfied together.
apt --fix-broken install
Attempts to complete or repair broken dependencies on Debian-family systems.
dpkg --configure -a
Finishes configuring packages left half-installed by an interruption.
NO_PUBKEY
An apt error meaning the repository's signing key is not installed.
apt-mark hold
Prevents a package from being upgraded on Debian-family systems.
dnf versionlock
A dnf plug-in that locks packages at their current version.
dnf history undo
Rolls back a recorded dnf transaction.
Exit code 137
A container exit caused by SIGKILL (128 + 9), often from the OOM killer or a memory limit.
podman ps -a
Lists all containers, including stopped ones, with their status.
podman inspect
Shows detailed container configuration and state, including exit code, OOMKilled, mounts and ports.
registries.conf
The file that defines registries and how short image names are resolved.
podman system df
Summarizes disk space used by images, containers and volumes.
Z volume option
The :Z or :z suffix on -v that relabels a bind mount for SELinux container access.
Rootless container
A container run by an unprivileged user, with UIDs mapped to subordinate IDs on the host.
Study Linux+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Linux+ study plan