All certifications / RHCSA / Cheat sheet
RHCSA EX200 (RHEL 10) cheat sheet
Domain 1: Understand and use essential tools (12%)
Exam tips
- The shell, not the command, expands globs, variables and ~. If a result surprises you, put echo in front of the command to see exactly which arguments the program will receive.
- Order matters:
> file 2>&1captures both streams in the file, but2>&1 > fileleaves errors on the terminal. Also remember a single > overwrites; use >> when the task says append. - In a regex, * does not mean 'anything' as it does in a shell glob; it means 'zero or more of the previous character'. The regex for 'anything' is .* and patterns belong in single quotes.
- su asks for the TARGET user's password; sudo asks for YOUR password. And always use the dash (su -) when you need the other user's full environment.
- Match the letter to the extension: z = .gz, j = .bz2, J = .xz. Keep f last in the option group so the archive name follows it directly.
- If vim seems to ignore your typing or does strange things, you are in the wrong mode: press Esc, then use :wq to save or :q! to abandon changes.
- Know which command preserves what: mv within a file system keeps everything (including the old SELinux context), cp without -a takes new ownership and default attributes, and cp -a preserves them.
- Hard links: same inode, same file system only, no directories, survive deletion of the other name. Symlinks: separate file holding a path, can cross file systems and point to directories, break if the target moves.
- Deleting a file depends on write permission on the DIRECTORY, not on the file. And remember the owner class is checked first: an owner with fewer rights than the group does not inherit the group's rights.
- If
man -kreturns 'nothing appropriate', the index has not been built yet: run mandb as root and search again. Use the section number (man 5 ...) when you need a file format rather than a command.
Key terms
- Shell
- The program (Bash on RHEL) that reads your command lines, expands them and starts the requested programs.
- Option
- A word beginning with - or -- that changes how a command behaves, such as -l or --all.
- Argument
- A word after the options that the command acts on, usually a file or directory name.
- Glob
- A wildcard pattern such as *.conf or file?.txt that the shell expands into matching file names.
- Tab completion
- Pressing Tab to have Bash finish a command or path name, reducing typing errors.
- stdin, stdout, stderr
- File descriptors 0, 1 and 2: the standard input, normal output and error output of every process.
- > and >>
- Redirect stdout to a file, overwriting it (>) or appending to it (>>).
- 2>&1
- Redirect stderr to wherever stdout currently points; place it after the stdout redirection.
- Pipe (|)
- Connects one command's stdout to the next command's stdin.
- tee
- Copies its input both to the screen (stdout) and to files; -a appends.
- Regular expression
- A pattern language for describing text, used by grep, sed, vim and many other tools.
- Anchor
- ^ matches the start of a line and $ matches the end; they match positions, not characters.
- Character class
- A bracket expression such as [a-z] that matches one character from the listed set; [^...] negates it.
- -v
- grep option that prints lines that do NOT match the pattern.
- -E
- grep option that enables extended regular expressions, making + ? | {} and () special.
- SSH
- Secure Shell: an encrypted protocol and client (ssh) for logging in to and running commands on remote systems.
- su -
- Switch user with a full login shell and that user's environment; asks for the target user's password.
- sudo -i
- Start a root login shell after authenticating with your own password, as allowed by the sudoers policy.
- wheel group
- The group whose members RHEL's default sudoers policy allows to run any command with sudo.
- multi-user.target
- The systemd target for a text-mode system with networking and services but no graphical login.
- Archive
- A single file that bundles many files and directories along with their metadata; created with tar.
- -c / -x / -t
- tar actions: create an archive, extract it, or list (table of contents) without extracting.
- -f
- tar option naming the archive file; the file name must immediately follow it.
- -z / -j / -J
- Use gzip, bzip2 or xz compression respectively.
- -C
- tar option that changes to a directory before extracting (or archiving).
- Normal mode
- Vim's default mode, in which keys are commands for moving, deleting, copying and pasting.
- Insert mode
- Vim mode entered with i, a or o in which typed keys become text; Esc leaves it.
- :wq / :q!
- Vim commands to save and quit, or to quit discarding unsaved changes.
- visudo
- Safely edits the sudoers file, locking it and checking syntax before saving.
- Swap file
- A .swp recovery file vim keeps while editing; a leftover one signals a concurrent or crashed edit.
- mkdir -p
- Create a directory and any missing parent directories; no error if it already exists.
- cp -a
- Archive copy: recursive, preserving permissions, ownership, timestamps, links and extended attributes such as SELinux contexts.
- mv
- Moves or renames files; within one file system it keeps the file's metadata unchanged.
- rm -r
- Recursively remove a directory and all of its contents.
- Absolute path
- A path starting at the root directory /, independent of the current directory.
- Inode
- The on-disk structure holding a file's metadata and data locations, identified by a number unique within its file system.
- Hard link
- An additional directory entry pointing to the same inode; created with ln.
- Symbolic link
- A special file containing a path to another file or directory; created with ln -s.
- Link count
- The number of hard links (names) referring to an inode, shown in the second column of ls -l.
- Dangling link
- A symbolic link whose target no longer exists.
- ugo
- The three permission classes: user (owner), group and others; a means all three.
- Octal mode
- Numeric permissions where r=4, w=2 and x=1 are summed per class, e.g. 755 or 640.
- Symbolic mode
- chmod notation such as u+x, g-w or o=r that changes specific permissions.
- Execute on a directory
- Permission to enter the directory and access items within it.
- chown
- Changes a file's owning user and optionally its group (user:group).
- man page
- A manual page viewed with man, organised into standard sections such as SYNOPSIS, OPTIONS and EXAMPLES.
- Man section
- A numbered category of man pages: 1 user commands, 5 file formats, 8 administration commands.
- man -k
- Searches man page names and descriptions for a keyword; equivalent to apropos.
- mandb
- Builds or updates the index database that man -k searches.
- /usr/share/doc
- Directory holding installed packages' extra documentation and sample configuration files.
Domain 2: Manage software (7%)
Exam tips
- baseurl must point to the directory that contains repodata/. On RHEL, BaseOS and AppStream are separate repositories, so you normally need two sections, each with its own unique ID.
- config-manager --add-repo does not configure a GPG key. Check the generated file and add gpgcheck or gpgkey yourself, then confirm with dnf repolist.
- Prefer
dnf install ./file.rpmoverrpm -i file.rpmfor local packages: dnf resolves dependencies from the repositories and records the change in dnf history. - When a task names a command, not a package, reach for
dnf provides command(quote globs like '*/bin/name'). Use dnf search when you only know what the software does. - Map the letters: a = all, i = info, l = list files, c = config files, f = which package owns this file, p = query a package file instead of the database.
- Quote group names with spaces or use their IDs, and remember optional packages are not installed unless you add --with-optional.
- Check whether the task wants a system-wide remote (run as root, the default) or a per-user one (--user). The remote name you choose must match the task exactly.
- Use the application ID (reverse-DNS name) with flatpak commands, and verify Flatpak tasks with flatpak list; rpm and dnf know nothing about Flatpak apps.
Key terms
- Repository
- A collection of RPM packages plus metadata (repodata) that dnf can download from.
- Repository ID
- The unique name in square brackets that starts a section of a .repo file.
- baseurl
- The URL of the directory containing the repository's repodata; may use http, https, ftp or file schemes.
- gpgcheck
- Setting that makes dnf verify package signatures (1) or skip verification (0).
- gpgkey
- Location of the public key used to verify package signatures when gpgcheck=1.
- dnf config-manager
- dnf plugin command for adding repositories and enabling or disabling them.
- --add-repo
- Creates a .repo file in /etc/yum.repos.d from a repository URL or a downloaded .repo file.
- dnf repolist
- Lists enabled repositories; add all to include disabled ones, -v for details.
- dnf clean all
- Removes cached repository metadata and packages so dnf fetches fresh data.
- --enablerepo / --disablerepo
- Options that enable or disable a repository for one dnf command only.
- dnf install
- Installs packages and their dependencies from enabled repositories or local RPM files.
- dnf remove
- Uninstalls packages together with packages that depend on them.
- dnf update
- Upgrades installed packages to the newest available versions; also called dnf upgrade.
- dnf reinstall
- Reinstalls the current version of a package, restoring its files.
- dnf history undo
- Reverses the changes made by a specific recorded dnf transaction.
- dnf search
- Searches package names and summaries (or with --all, descriptions too) for keywords.
- dnf provides
- Finds which package contains a given file, command or path glob; also called whatprovides.
- dnf info
- Displays details about a package, such as version, repository, size and description.
- dnf list
- Lists installed and available packages matching a name pattern.
- @System
- Label dnf uses to show that a package is installed locally rather than available from a repository.
- RPM database
- The local database recording every installed package and its files, queried with rpm -q.
- rpm -qa
- Lists all installed packages.
- rpm -ql / -qc
- Lists all files, or only the configuration files, installed by a package.
- rpm -qf
- Shows which installed package owns a given file.
- rpm -qi
- Shows detailed information about an installed package.
- Package group
- A named set of related packages defined in repository metadata, installable in one step.
- Environment group
- A larger bundle of groups representing a complete system type, such as Server with GUI.
- Mandatory / default / optional
- Package classes within a group; dnf installs mandatory and default unless told --with-optional.
- dnf group info
- Shows the packages contained in a group, sorted by class.
- @group syntax
- Shorthand for groups in dnf install, e.g. dnf install @development; @^ marks an environment group.
- Flatpak
- A system for distributing sandboxed applications that ship with their own runtimes, independent of RPM packages.
- Remote
- A named Flatpak repository from which applications and runtimes are installed.
- Runtime
- A shared set of libraries and services that Flatpak applications run on top of.
- .flatpakrepo file
- A descriptor containing a remote's URL, title and GPG key, used with flatpak remote-add.
- System vs user installation
- System remotes and apps are shared by all users (/var/lib/flatpak); --user ones live in the user's home.
- Application ID
- A reverse-DNS style identifier for a Flatpak app, such as org.example.Editor.
- Ref
- A full Flatpak reference combining type, ID, architecture and branch, e.g. app/ID/x86_64/stable.
- flatpak install
- Installs an application and its required runtime from a remote.
- flatpak run
- Starts an installed Flatpak application in its sandbox.
- flatpak uninstall --unused
- Removes runtimes and extensions no longer needed by any installed application.
Domain 3: Create simple shell scripts (7%)
Exam tips
- Running a script by name needs all three: a correct shebang on line 1, execute permission, and a location in PATH. Otherwise you must use ./script or bash script.
- Use -eq/-gt/-lt for numbers and = / != for strings, keep spaces inside the brackets, and quote every variable in a test.
- $? is overwritten by every command, including echo and [ ]; save it to a variable (rc=$?) right away if you need it later.
- Loop over files with a glob (for f in /dir/*), not with $(ls), and read files line by line with while read -r ... done < file rather than for line in $(cat file), which splits on every space.
- Use "$@" (with quotes) to loop over or pass on all arguments; unquoted $@ or $* splits arguments that contain spaces.
- $( ) captures stdout only and strips trailing newlines. Quote it ("$(cmd)") unless you intentionally want the output split into separate words.
- No spaces around = in assignments, double quotes around every $variable, single quotes when you want text taken literally.
'$HOME'prints $HOME;"$HOME"prints /root. - case uses shell glob patterns, not regex, stops at the first match, and needs ;; after each clause and esac at the end. Put the catch-all *) last.
Key terms
- Shebang
- The #! first line naming the interpreter, e.g. #!/bin/bash, used when the file is executed.
- Execute permission
- The x permission that lets a file be run as a program; set with chmod +x.
- PATH
- Environment variable listing directories the shell searches, in order, for commands.
- /usr/local/bin
- Conventional system-wide directory in PATH for locally created scripts and programs.
- source
- Runs a script in the current shell rather than a child process; also written as a dot.
- test / [ ]
- Command that evaluates a condition and returns exit status 0 (true) or 1 (false); spaces around brackets are required.
- -f / -d / -e
- Tests for a regular file, a directory, or any existing path.
- -z / -n
- Tests whether a string is empty or not empty.
- -eq / -gt / -lt
- Numeric comparison operators: equal, greater than, less than (also -ne, -ge, -le).
- elif
- Additional condition checked only if the previous if or elif was false.
- Exit status
- A number 0 to 255 returned by every command; 0 means success, non-zero means failure.
- $?
- Special variable holding the exit status of the last command that finished.
- &&
- Runs the next command only if the previous one succeeded (exit status 0).
- ||
- Runs the next command only if the previous one failed (non-zero exit status).
- exit
- Built-in that ends a script immediately with a given status code.
- for loop
- Repeats a block once for each word in a list, assigning the word to a variable.
- while loop
- Repeats a block as long as its condition command returns exit status 0.
- read
- Built-in that reads one line of input into variables; returns non-zero at end of input.
- seq
- Command that prints a sequence of numbers, e.g. seq 1 10.
- IFS
- Internal Field Separator: the characters read and word splitting use to split text.
- Positional parameters
- The arguments passed to a script, available as $1, $2 and so on.
- $0
- The name of the script as it was invoked.
- $#
- The number of arguments passed to the script.
- "$@"
- All arguments as separate, correctly quoted words; the right form for loops and passing arguments on.
- shift
- Discards $1 and renumbers the remaining arguments down by one.
- Command substitution
- $(command): replaces itself with the standard output of the command.
- Backticks
- The older
commandform of command substitution; equivalent but harder to nest. - cut
- Extracts fields or character ranges from each line, e.g. cut -d: -f1.
- awk '{print $N}'
- Prints the Nth whitespace-separated field of each line.
- Subshell
- A child copy of the shell in which the substituted command runs.
- Variable assignment
- name=value with no spaces around =; referenced later as $name or ${name}.
- export
- Marks a variable for inclusion in the environment of child processes.
- read -p
- Reads a line of input into variables after displaying a prompt.
- Double quotes
- Allow $ expansion but prevent word splitting and globbing.
- Single quotes
- Prevent all expansion; the text is taken literally.
- case ... esac
- Statement that compares a value against patterns and runs the first matching clause.
- ;;
- Terminates a case clause; execution then continues after esac.
- Pattern alternatives
- Several patterns in one clause separated by |, such as start|up).
- *) default clause
- A final clause matching anything not matched earlier, typically for usage errors.
- bash -n
- Checks a script's syntax without running it.
Domain 4: Operate running systems (12%)
Exam tips
- systemctl set-default changes what happens at the NEXT boot; systemctl isolate changes the target NOW. The exam grades the system after a reboot, so test by rebooting.
- Rescue mounts all file systems; emergency mounts only root, read-only. If fstab is broken, rescue fails, so use emergency and remember to remount / read-write before editing.
- Remember the order: remount,rw /sysroot, chroot /sysroot, passwd, touch /.autorelabel, exit, exit. Skipping the autorelabel leaves /etc/shadow mislabeled and logins fail under SELinux.
- Try SIGTERM (15, the default) before SIGKILL (9). SIGKILL cannot be caught, so the process gets no chance to clean up. Use a minus in --sort=-%cpu for highest first.
- Higher nice number = lower priority. Anyone can raise a value (be nicer); only root can lower it or set a negative value.
- The profile is applied by the tuned service, so make sure it is enabled and running (systemctl enable --now tuned). Don't guess the recommended profile: ask tuned-adm recommend.
- journalctl -p err shows err AND everything more severe (crit, alert, emerg). Authentication problems go to /var/log/secure, not /var/log/messages.
- Storage=auto only persists if /var/log/journal exists; Storage=persistent creates it. Either way, restart systemd-journald and confirm with journalctl --list-boots after a reboot.
- A task that says the service must be running and persistent needs both start and enable: systemctl enable --now. Then prove it with systemctl is-enabled, is-active and ss -tlnp.
- In rsync, a trailing slash on the source means 'the contents of this directory'; without it the directory itself is copied into the destination. scp uses -P for port, while ssh uses -p.
Key terms
- systemd
- The init system and service manager, process 1 on RHEL, which starts and stops everything else.
- systemctl reboot / poweroff
- Cleanly restart the system or shut it down and power it off.
- Target
- A systemd unit that groups other units to describe a system state, e.g. multi-user.target.
- Default target
- The target systemd starts at boot; shown by systemctl get-default and changed by set-default.
- initramfs
- Initial RAM file system loaded with the kernel, containing what is needed to mount the real root file system.
- GRUB 2
- The boot loader on RHEL; its menu lets you choose and temporarily edit kernel entries.
- Kernel command line
- Parameters on the linux line in GRUB, passed to the kernel and systemd at boot.
- rescue.target
- Minimal target that mounts all local file systems and provides a root shell, without networking.
- emergency.target
- Most minimal target: only root mounted read-only and a root shell.
- systemd.unit=
- Kernel parameter telling systemd which target to start instead of the default.
- rd.break
- Kernel parameter that makes the initramfs stop and open a shell before switching to the real root.
- /sysroot
- Where the real root file system is mounted inside the initramfs, read-only by default.
- chroot
- Runs a shell with a given directory treated as the root /, here /sysroot.
- /.autorelabel
- Empty file that triggers a full SELinux relabel of the file system at the next boot.
- dracut
- The tool that builds the initramfs and understands rd.* kernel parameters.
- PID
- Process ID: the unique number identifying a running process.
- top
- Interactive, live view of processes sorted by resource use; M sorts by memory, P by CPU, k kills.
- ps aux --sort=-%cpu
- Snapshot of all processes sorted by descending CPU usage.
- SIGTERM (15)
- Default kill signal requesting a clean shutdown; the process may catch it.
- SIGKILL (9)
- Signal that terminates a process immediately; it cannot be caught or ignored.
- Nice value
- A number from -20 (highest priority) to 19 (lowest) that influences a process's CPU share; default 0.
- nice
- Starts a command with a specified nice value; default adjustment is 10.
- renice
- Changes the nice value of running processes by PID, user or group.
- PR
- The priority column in top; for normal processes it is 20 plus the nice value.
- Scheduler
- The kernel component that decides which runnable process uses a CPU next.
- tuned
- The RHEL service that applies tuning profiles adjusting kernel and hardware settings for a workload.
- Tuning profile
- A named set of performance and power settings, such as balanced or virtual-guest.
- tuned-adm active
- Shows the currently active tuning profile.
- tuned-adm recommend
- Shows the profile tuned recommends for the detected system.
- tuned-adm profile
- Switches to and persistently saves the given profile.
- systemd-journald
- Service that collects log messages into the structured systemd journal.
- rsyslog
- Syslog daemon that writes messages to text files under /var/log according to /etc/rsyslog.conf.
- /var/log/secure
- Text log for authentication and security events such as logins and sudo.
- journalctl -u
- Shows journal entries for a specific systemd unit.
- Syslog priority
- Severity level from emerg (0) to debug (7); journalctl -p shows that level and more severe ones.
- Storage=
- journald.conf option choosing where the journal is kept: persistent, volatile, auto or none.
- /var/log/journal
- On-disk location of a persistent journal.
- /run/log/journal
- In-memory (tmpfs) location of a volatile journal, lost at reboot.
- journalctl --list-boots
- Lists the boots recorded in the journal; more than one indicates persistence.
- Service unit
- A systemd unit (name.service) that describes how to run and manage a daemon.
- start vs enable
- start runs the service now; enable makes it start at boot. enable --now does both.
- systemctl status
- Shows a unit's load, enable and active state, main PID and recent log lines.
- ss -tlnp
- Lists listening TCP sockets numerically with the owning process.
- mask
- Links a unit to /dev/null so it cannot be started until unmasked.
- scp
- Secure copy: copies files to or from remote hosts over SSH using user@host:path syntax.
- sftp
- Interactive file transfer client over SSH with commands like get, put, ls and lcd.
- rsync
- Synchronises files, transferring only differences, over SSH by default.
- rsync -a
- Archive mode: recursive, preserving permissions, times, links, and ownership where possible.
- --delete
- rsync option removing destination files that are absent from the source; test first with -n.
Domain 5: Configure local storage (12%)
Exam tips
- Run lsblk before touching any disk to be sure you have the right device name, and use blkid (or lsblk -f) to get the UUID for /etc/fstab. NVMe partitions include a p: nvme0n1p1.
- fdisk and gdisk change nothing until you press w; parted applies each command immediately. Creating a new label (g, o, mklabel) on a disk with data wipes its partitions.
- Build LVM bottom up (partition, pvcreate, vgcreate, lvcreate, mkfs, mount) and dismantle it top down. pvremove fails while a PV still belongs to a volume group.
- Read the task for an extent size: vgcreate -s must be set at creation. Later, an LV of -l 50 in a VG with 16 MiB extents is 800 MiB, not 200 MiB.
- Capital -L is a size with units; lowercase -l is a count of extents (or a percentage). Multiply extents by the VG's PE size to know the real size.
- Always run mount -a (and ideally findmnt --verify) after editing /etc/fstab. A typo you catch now is a two-second fix; the same typo at boot drops you into emergency mode.
- Never recreate a partition table or run pvcreate/mkfs on something that holds data. Append to fstab with >> (or edit it), and test with mount -a and swapon -a before rebooting.
- Persistence is the part graders check. A swap area activated only with swapon disappears at reboot, so the task fails unless the /etc/fstab line exists and swapon -a activates it cleanly.
Key terms
- Block device
- A storage device such as a disk or partition accessed in blocks, found under /dev.
- lsblk
- Lists block devices as a tree with size, type and mount point; -f adds file system details.
- blkid
- Shows UUID, file system type and label of devices with recognised signatures.
- fdisk -l
- Lists partition tables, showing table type (dos or gpt) and each partition's size and type.
- UUID
- Universally unique identifier assigned to a file system or other signature, stable across device renaming.
- GPT
- GUID Partition Table: modern scheme supporting many partitions and very large disks, with a backup table.
- MBR (dos)
- Older partition scheme limited to four primary partitions and 2 TiB disks.
- Partition type
- Identifier describing a partition's purpose, such as Linux LVM (8e00) or Linux swap (8200).
- mklabel
- parted command that creates a new, empty partition table (msdos or gpt).
- partprobe
- Asks the kernel to reread a disk's partition table after changes.
- LVM
- Logical Volume Manager: pools block devices into volume groups and allocates flexible logical volumes.
- Physical volume (PV)
- A disk or partition initialised with an LVM label so it can join a volume group.
- pvcreate
- Initialises devices as physical volumes.
- pvs / pvdisplay
- Show physical volumes in brief (pvs) or detailed (pvdisplay) form.
- pvremove
- Removes the LVM label from a device that is not in any volume group.
- Volume group (VG)
- An LVM storage pool made from one or more physical volumes.
- Physical extent (PE)
- The fixed-size allocation unit of a volume group; 4 MiB by default.
- vgcreate -s
- Creates a volume group with a specified physical extent size.
- vgextend
- Adds physical volumes to an existing volume group to increase its capacity.
- vgdisplay
- Shows detailed volume group information including PE size and free extents.
- Logical volume (LV)
- A volume allocated from a volume group that holds a file system or swap, like a flexible partition.
- lvcreate -L
- Creates an LV with a size given in units such as M or G.
- lvs / lvdisplay
- List LVs briefly, or show details such as Current LE and path.
- lvremove
- Deletes a logical volume; unmount it and remove it from fstab first.
- /etc/fstab
- File listing file systems to mount at boot: device, mount point, type, options, dump and fsck order.
- Mount point
- An existing directory where a file system's contents are attached.
- UUID=
- fstab device syntax using a file system's universally unique identifier, stable across device renaming.
- LABEL=
- fstab device syntax using a human-assigned file system label.
- mount -a
- Mounts all fstab entries not yet mounted; used to test fstab before rebooting.
- Free space
- Unallocated area on a disk or free extents in a volume group, where new storage can be added safely.
- Swap space
- Disk space used by the kernel to hold memory pages when RAM is under pressure.
- mkswap
- Writes a swap signature to a device, preparing it for use as swap.
- swapon / swapoff
- Activate or deactivate swap areas; swapon -a activates all fstab swap entries.
- swapon --show
- Lists active swap areas with their size, usage and priority.
Domain 6: Create and configure file systems (10%)
Exam tips
- Match the requested type exactly. A grader checking for ext4 will fail an XFS volume even if it mounts and works, so confirm with lsblk -f or blkid before moving on.
- Never reboot after editing /etc/fstab without running mount -a and findmnt --verify. A typo can leave the exam system in emergency mode and cost you time on every other task.
- Exam questions often ask what the fifth and sixth fields mean. Dump is legacy and set to 0; fsck order is 1 for root, 2 for others, and 0 for XFS, swap and network mounts.
- Include _netdev on network mounts in /etc/fstab. It documents that the mount needs the network and keeps boot and shutdown ordering correct, and it is the option exam answers look for.
- Do not create the subdirectories under an autofs base or add fstab lines for them. An empty ls of the base directory is expected; test by accessing the full path.
- The most common failure is growing the LV but not the file system. Use lvextend -r every time, and check df -h, not just lvs, before moving on.
- Order is everything when shrinking: file system first, then logical volume. For growing it is the reverse: volume first, then file system. The -r option handles both orders for you.
- Linux applies only the first matching class: owner, then group, then other. And access needs x on every parent directory, which namei -l reveals in one command.
Key terms
- XFS
- The default RHEL file system; high performance and growable online, but it cannot be shrunk.
- ext4
- The fourth extended file system; mature, growable online and shrinkable while unmounted.
- vfat
- The Linux driver for FAT file systems, used for EFI partitions and removable media; it stores no Linux ownership or permissions.
- blkid
- Prints the UUID, label and file system type of block devices, used when writing /etc/fstab entries.
- Mount point
- An existing directory where a file system is attached to the directory tree.
- mount -a
- Mounts every file system listed in /etc/fstab that is not already mounted, used to test new entries.
- findmnt --verify
- Checks /etc/fstab for errors such as missing mount points, bad types or unknown devices without mounting.
- target is busy
- The umount error shown when a process has open files or a working directory inside the file system.
- /etc/fstab
- The file that lists file systems and swap to mount or activate at boot, one six-field line each.
- defaults
- The option set rw, suid, dev, exec, auto, nouser and async.
- fsck order
- The sixth fstab field: 0 skips checking, 1 is root, 2 is other file systems checked after root.
- nofail
- An fstab option that lets boot continue if the device is not present.
- NFS
- Network File System; a protocol for sharing directories from a server so clients can mount them over the network.
- Export
- A directory an NFS server makes available to clients.
- _netdev
- An fstab option marking a file system as network-dependent so it mounts after networking starts.
- Root squash
- An NFS server behavior that maps a client's root user to an unprivileged account, the default for exports.
- autofs
- A service that mounts file systems automatically when a path is accessed and unmounts them when idle.
- Master map
- The top-level autofs configuration, in /etc/auto.master and /etc/auto.master.d/*.autofs, mapping base directories to map files.
- Indirect map
- A map whose keys are names relative to a base directory given in the master map.
- Wildcard entry
- A map line with * as the key and & in the location, so any key name maps to a matching server path.
- lvextend
- Increases the size of a logical volume, optionally resizing its file system with -r.
- xfs_growfs
- Grows a mounted XFS file system to fill its device; takes the mount point.
- resize2fs
- Resizes an ext2, ext3 or ext4 file system; it can grow online and shrink offline.
- Physical extent
- The fixed-size unit (4 MiB by default) in which LVM allocates space, so LV sizes round to multiples of it.
- Shrink
- Reducing a file system and its volume to a smaller size; supported offline by ext4 and not at all by XFS.
- e2fsck -f
- Forces a full consistency check of an ext file system, required by resize2fs before shrinking.
- lvreduce
- Decreases the size of a logical volume; with -r it shrinks the file system first.
- fsadm
- A helper used by lvextend -r and lvreduce -r to resize the file system on a logical volume.
- namei -l
- Lists each component of a path with its owner, group and mode, used to find where traversal fails.
- Execute bit on a directory
- Permission to enter a directory and access entries inside it, needed on every directory in a path.
- chmod
- Changes permission bits using symbolic (u+x, g-w) or numeric (755) modes.
- chown
- Changes the owner, and optionally the group, of files with the form user:group.
Domain 7: Deploy, configure and maintain systems (10%)
Exam tips
- Know which cron format needs a user field: personal crontabs never do, /etc/crontab and /etc/cron.d files always do. And remember to enable the .timer unit, not the .service, for systemd timers.
- Enabled and active are independent. Exam answers that only start a service, or only enable it, are both incomplete; enable --now covers both.
- set-default changes the next boot only; isolate changes the current state only. A task that says the system must boot into a text console needs set-default.
- In chronyc sources output, the asterisk after the caret marks the source you are actually synchronized to. No asterisk means the configuration is not working yet.
- A .repo file must end in .repo and each section needs a unique ID in brackets and a baseurl. A typo there makes every later install task fail, so confirm with dnf repolist straight away.
- If dnf repolist is empty on a fresh RHEL install, the system is probably not registered. Registration, not a missing .repo file you wrote, is what provides the CDN repositories.
- Menu settings like the timeout need /etc/default/grub plus grub2-mkconfig. Per-kernel arguments are easiest with grubby, which updates existing entries immediately.
- Edits made at the GRUB menu with e last for one boot only. If a task says persistent, use grubby (or /etc/default/grub with grub2-mkconfig) and verify after a reboot.
Key terms
- at
- Schedules a one-time job, run by the atd service; atq lists and atrm removes jobs.
- crontab
- A per-user table of recurring jobs with five time fields and a command, edited with crontab -e.
- /etc/cron.d
- A directory of system cron files whose lines include a user field between the schedule and the command.
- Timer unit
- A systemd .timer file that starts a matching service on a calendar schedule (OnCalendar=) or after an event (OnBootSec=).
- Unit
- An object managed by systemd, such as a .service, .socket, .timer, .mount or .target.
- enable --now
- Configures a unit to start at boot and starts it immediately in one command.
- mask
- Links a unit to /dev/null so it cannot be started manually or as a dependency until unmasked.
- daemon-reload
- Makes systemd reread unit files after they are created or changed.
- Target
- A systemd unit that groups other units to define a system state, replacing runlevels.
- multi-user.target
- A full non-graphical system state with networking and services, the usual default for servers.
- graphical.target
- multi-user.target plus a graphical login manager.
- isolate
- A systemctl command that switches the running system to a target, stopping units not required by it.
- NTP
- Network Time Protocol, used to synchronize clocks with time servers over the network.
- chronyd
- The RHEL NTP daemon, configured in /etc/chrony.conf.
- iburst
- A chrony server option that sends several quick requests at startup to synchronize faster.
- timedatectl
- A systemd tool to view and set the time, time zone and whether NTP synchronization is on.
- dnf
- The RHEL package manager that installs, updates and removes RPM packages and resolves dependencies from repositories.
- .repo file
- A file in /etc/yum.repos.d/ that defines repositories with an ID, name, baseurl, enabled and gpgcheck settings.
- BaseOS and AppStream
- The two main RHEL repositories: core operating system packages, and applications and runtimes.
- GPG check
- Verification of a package's signature against a trusted key before installing it.
- subscription-manager
- The command-line tool that registers a RHEL system with Red Hat and manages its repositories.
- Developer subscription
- A no-cost Red Hat subscription for individuals that allows registering RHEL systems for development and learning.
- Simple content access
- Red Hat's model where a registered system can use entitled content without attaching subscriptions to each machine.
- Activation key
- A preconfigured key used with an organization ID to register systems without a username and password.
- GRUB 2
- The RHEL boot loader that presents the boot menu and loads the kernel with its command line.
- /etc/default/grub
- The file of global GRUB settings such as GRUB_TIMEOUT and GRUB_CMDLINE_LINUX, applied by grub2-mkconfig.
- grub2-mkconfig
- Regenerates /boot/grub2/grub.cfg from /etc/default/grub and /etc/grub.d scripts.
- grubby
- A tool that reads and edits boot entries directly, including default kernel and kernel arguments.
- Kernel argument
- An option on the kernel command line that changes kernel or systemd behavior at boot.
- grubby --set-default
- Sets the default boot entry by kernel path, persisting across reboots.
- uname -r
- Prints the release of the currently running kernel.
- /proc/cmdline
- A virtual file showing the command line the running kernel was booted with.
Domain 8: Manage basic networking (8%)
Exam tips
- nmcli con mod saves the profile but does not apply it. Always follow with nmcli con up (and be aware this can drop an SSH session if the address changes).
- Hand-edited keyfiles need mode 600 and root ownership, and a reload. If a question mentions ifcfg files for RHEL 10, the answer is that keyfiles in /etc/NetworkManager/system-connections replaced them.
- If the wrong settings come back after reboot, look for another autoconnect profile on the same device. Either delete it, set autoconnect to no, or raise the priority of the one you want.
- Do not fix DNS by editing /etc/resolv.conf directly on RHEL; NetworkManager rewrites it. Set ipv4.dns on the connection and bring it up again.
- getent hosts shows what applications will resolve; dig and host bypass /etc/hosts. Pick the tool that matches the question being asked.
- For network services, check three things before calling a task done: the service is enabled, the connection autoconnects, and the firewall rule is permanent. Then reboot and test.
- A --permanent change without --reload does nothing yet; a change without --permanent is gone after the next reload or reboot. The exam grader reboots, so permanent plus reload is the safe pattern.
- nmtui saves the profile but may not apply it; deactivate and reactivate the connection afterwards, exactly as you would run nmcli con up after nmcli con mod.
Key terms
- NetworkManager
- The RHEL service that configures and manages network interfaces using connection profiles.
- Connection profile
- A saved set of network settings that NetworkManager applies to a device when activated.
- ipv4.method
- The property that selects auto (DHCP), manual (static), link-local or disabled addressing.
- CIDR notation
- An address followed by a slash and prefix length, such as 192.168.10.20/24, giving address and netmask together.
- Keyfile
- NetworkManager's INI-style profile format, stored as .nmconnection files in /etc/NetworkManager/system-connections/.
- ifcfg file
- The legacy shell-style network configuration format in /etc/sysconfig/network-scripts/, not supported in RHEL 10.
- nmcli con reload
- Tells NetworkManager to reread connection files from disk after manual edits.
- address1=
- The keyfile key for the first static address in CIDR form, optionally followed by a comma and the gateway.
- nmcli con up
- Activates a connection profile on its device, applying its current settings.
- connection.autoconnect
- A profile property that makes NetworkManager activate it automatically at boot and when the device appears.
- autoconnect-priority
- A number that decides which of several autoconnect profiles wins for a device; higher wins.
- nmcli device disconnect
- Deactivates a device and prevents automatic reactivation until a connection is brought up manually or the system restarts.
- hostnamectl
- The tool that shows and sets the system hostname, writing the static name to /etc/hostname.
- /etc/hosts
- A local file of address-to-name mappings consulted before DNS by default.
- /etc/resolv.conf
- The resolver file listing nameserver and search domains, generated by NetworkManager on RHEL.
- ipv4.dns
- The NetworkManager connection property holding DNS server addresses for that profile.
- ip addr
- Shows network interfaces with their state and IPv4 and IPv6 addresses.
- Default gateway
- The router that receives traffic for destinations not on a directly connected network, shown as default via in ip route.
- getent hosts
- Resolves a name using the system's configured order (nsswitch), including /etc/hosts and DNS.
- ICMP
- Internet Control Message Protocol, used by ping for echo requests and replies.
- enable --now
- Enables a unit to start at boot and starts it immediately.
- network-online.target
- A systemd target reached when the network is fully configured, used to order services that need working networking.
- ss -tlnp
- Lists listening TCP sockets with numeric ports and the owning processes.
- Permanent firewall rule
- A firewalld change saved with --permanent so it survives reloads and reboots.
- firewalld
- The RHEL firewall service that manages packet filtering rules through zones, services and ports.
- Zone
- A named trust level holding allowed services and ports, applied to interfaces or source addresses.
- --permanent
- Saves a firewall-cmd change to configuration without applying it until a reload.
- --reload
- Reloads firewalld so the permanent configuration becomes the running configuration, discarding runtime-only changes.
- nmtui
- A text-based, menu-driven NetworkManager interface for editing connections, activating them and setting the hostname.
- NetworkManager-tui
- The package that provides the nmtui command.
- Automatically connect
- The nmtui check box that sets connection.autoconnect for a profile.
- Activate a connection
- The nmtui menu for bringing profiles up or down so saved changes take effect.
Domain 9: Manage users and groups (8%)
Exam tips
- usermod -G without -a replaces every supplementary group. When a task says add a user to a group, use usermod -aG group user.
- No interactive shell on the exam means -s /sbin/nologin. It blocks shell logins but not authentication itself, so combine with locking when an account must be fully disabled.
- chage -d 0 forces a password change at next login; chage -E 0 or a past date expires the whole account. Mixing them up either locks the user out or does nothing useful.
- login.defs and /etc/default/useradd change only accounts created afterwards. If existing users must comply, run chage on them as well.
- Both usermod -aG and gpasswd -a add one group without removing others. The trap is usermod -G without -a, which wipes a user's existing supplementary groups.
- A user's primary group is set by the GID field in /etc/passwd, not listed in /etc/group. Use id to see all memberships at once.
- Always use visudo; a syntax error in a sudoers file can remove everyone's sudo access. And a drop-in file whose name contains a dot is silently ignored.
- usermod -L and passwd -l block only password logins; chage -E 0 blocks every login method, including SSH keys. Choose based on what the task says must be prevented.
Key terms
- UID
- User ID, the number the kernel uses to identify a user; regular users start at 1000 on RHEL.
- Primary group
- The group assigned to new files a user creates, set with -g and stored in /etc/passwd.
- Supplementary group
- An additional group membership that grants group permissions, set with -G.
- usermod -aG
- Appends supplementary groups to a user without removing existing ones.
- Service account
- An account used by a program rather than a person, typically created with useradd -r.
- /sbin/nologin
- A shell that politely refuses interactive login, used to block logins for service accounts.
- Login shell
- The program started when a user logs in, stored in the last field of /etc/passwd.
- /etc/shells
- The list of valid login shells on the system.
- chage
- Views and changes password aging and account expiration for a user.
- Maximum password age
- Days a password stays valid before the user must change it, set with chage -M.
- Minimum password age
- Days a user must wait between password changes, set with chage -m.
- Account expiration
- A date after which the account cannot be used at all, set with chage -E.
- /etc/login.defs
- Configuration for new accounts: default password aging, UID and GID ranges, CREATE_HOME, UMASK and hashing method.
- /etc/default/useradd
- useradd defaults such as base home directory, default shell, skeleton directory and expiry, shown with useradd -D.
- /etc/skel
- The skeleton directory whose files are copied into every new user's home directory.
- PASS_MAX_DAYS
- The login.defs setting for default maximum password age applied to new accounts.
- GID
- Group ID, the number identifying a group in /etc/group.
- groupadd -g
- Creates a group with a specific GID.
- gpasswd
- Administers /etc/group and /etc/gshadow: add or remove members, set the member list and assign group administrators.
- /etc/gshadow
- The secure group file holding group passwords, administrators and members.
- /etc/passwd
- The world-readable account file with seven fields: name, x, UID, GID, comment, home and shell.
- /etc/shadow
- The root-only file holding password hashes and aging fields for each account.
- /etc/group
- The group file with name, x, GID and a list of supplementary members.
- getent
- Queries system databases such as passwd and group through NSS, including local and network sources.
- sudo
- Runs a command as root or another user according to sudoers rules, logging the action.
- wheel group
- The RHEL administrative group granted full sudo rights by the default sudoers rule %wheel ALL=(ALL) ALL.
- visudo
- Edits sudoers files safely with locking and syntax checking; -f edits a drop-in and -c checks all files.
- /etc/sudoers.d/
- A directory of drop-in sudoers files that keeps local rules separate from the main file.
- Password lock
- An exclamation mark prefixed to the shadow hash by usermod -L or passwd -l, which blocks password authentication only.
- Account expiry
- The shadow expiration date; chage -E 0 sets it in the past so every login method is refused.
- passwd -S
- Shows the password status of an account, including whether it is locked.
- chage -E -1
- Removes an account's expiration date, reversing chage -E 0.
Domain 10: Manage security (14%)
Exam tips
- Source bindings take priority over interface zones. Compare firewall-cmd --list-all with --permanent --list-all to be sure your runtime and saved rules agree.
- Subtract the umask from 666 for files and 777 for directories. With umask 027, files are 640 and directories 750.
- Most key failures are permissions: ~/.ssh must be 700, authorized_keys 600, and the home directory not group- or world-writable. Check journalctl -u sshd on the server for the reason.
- setenforce changes only the running mode; /etc/selinux/config sets the mode at boot. A persistent change needs the file, and graders check after a reboot.
- mv keeps a file's old context while cp creates a new file with the directory's context. A moved file with the wrong type is a classic exam trap.
- semanage fcontext only records the rule; it does not change any file. Always follow it with restorecon -Rv on the path, and prefer this pair over chcon for persistence.
- A service moved to a non-standard port needs three things: its own config, an SELinux port label, and a firewall rule. If the port already has another type, use -m instead of -a.
- setsebool without -P is lost at reboot. When a task asks for a persistent change, check afterwards with semanage boolean -l -C, which lists only locally changed booleans.
- Read the tcontext of the denial: a wrong file type means restorecon or semanage fcontext, name_bind means semanage port, and an optional behavior means a boolean. Never leave SELinux permissive as the fix.
Key terms
- Source binding
- Assigning a source address or network to a zone so packets from it use that zone's rules.
- Default zone
- The zone used for interfaces and traffic not assigned to any other zone, public unless changed.
- Runtime configuration
- The firewall rules currently in effect, lost on reload or reboot unless saved.
- --runtime-to-permanent
- Saves the current runtime firewall configuration as the permanent configuration.
- umask
- A per-process mask of permission bits removed from new files and directories.
- Default creation mode
- The mode programs request before masking: 666 for files and 777 for directories.
- ~/.bashrc
- A per-user shell startup file where a persistent umask for that user can be set.
- /etc/profile.d/
- A directory of shell scripts run at login for all users, a clean place for site-wide settings like umask.
- Key pair
- A private key kept on the client and a matching public key placed on servers for authentication.
- authorized_keys
- The file ~/.ssh/authorized_keys on a server listing public keys allowed to log in as that user.
- ssh-copy-id
- Copies a public key into a remote user's authorized_keys file with correct permissions.
- PermitRootLogin
- An sshd setting controlling root logins: yes, no or prohibit-password (key only).
- SELinux
- Security-Enhanced Linux, kernel mandatory access control based on labels and policy.
- Enforcing mode
- SELinux applies the policy, denying and logging forbidden access.
- Permissive mode
- SELinux logs policy violations but allows them, used for troubleshooting.
- /etc/selinux/config
- The file setting the SELinux mode and policy type used at boot.
- Security context
- An SELinux label of the form user:role:type:level attached to files, processes and ports.
- Type
- The context field ending in _t that targeted policy uses to decide access.
- Type enforcement
- SELinux policy rules that allow a process type specific access to object types.
- unconfined_t
- The type of normal user login sessions, which targeted policy does not restrict.
- restorecon
- Resets file SELinux labels to the values defined in policy; -R recurses and -v reports changes.
- semanage fcontext
- Adds, modifies, deletes or lists the policy rules mapping path patterns to file types.
- chcon
- Changes a file's label directly; the change is lost on restorecon or relabel.
- (/.*)?
- The regular expression suffix that matches a directory and everything beneath it in fcontext rules.
- Port type
- An SELinux label on a network port, such as http_port_t or ssh_port_t, that controls which process types may use it.
- name_bind
- The permission a process needs to listen on a port; denials of it indicate a missing port label.
- semanage port -a
- Adds a port number and protocol to an SELinux port type.
- semanage port -m
- Modifies a port that is already defined with another type.
- SELinux boolean
- A policy switch that turns an optional set of permissions on or off without writing new policy.
- getsebool -a
- Lists all booleans and their current values.
- setsebool -P
- Sets a boolean and makes the change persistent across reboots.
- semanage boolean -l
- Lists booleans with current value, default value and description.
- AVC denial
- An audit log record of an access blocked by SELinux, naming the permission, source context, target context and class.
- auditd
- The audit daemon that writes SELinux denials and other events to /var/log/audit/audit.log.
- ausearch
- Searches the audit log by message type, time and command; -m AVC selects SELinux denials.
- sealert
- A setroubleshoot tool that explains denials in plain language and suggests fixes.
Study RHCSA for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the RHCSA study planLessons, quizzes, exam simulations and hands-on labs.