StudyToCert

All certifications / RHCSA / Cheat sheet

RHCSA EX200 (RHEL 10) cheat sheet

Every exam tip and key term from the free RHCSA lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Understand and use essential tools (12%)

Exam tips

Key terms

Shell
The program (Bash on RHEL) that reads your command lines, expands them and starts the requested programs.
Option
A word beginning with - or -- that changes how a command behaves, such as -l or --all.
Argument
A word after the options that the command acts on, usually a file or directory name.
Glob
A wildcard pattern such as *.conf or file?.txt that the shell expands into matching file names.
Tab completion
Pressing Tab to have Bash finish a command or path name, reducing typing errors.
stdin, stdout, stderr
File descriptors 0, 1 and 2: the standard input, normal output and error output of every process.
> and >>
Redirect stdout to a file, overwriting it (>) or appending to it (>>).
2>&1
Redirect stderr to wherever stdout currently points; place it after the stdout redirection.
Pipe (|)
Connects one command's stdout to the next command's stdin.
tee
Copies its input both to the screen (stdout) and to files; -a appends.
Regular expression
A pattern language for describing text, used by grep, sed, vim and many other tools.
Anchor
^ matches the start of a line and $ matches the end; they match positions, not characters.
Character class
A bracket expression such as [a-z] that matches one character from the listed set; [^...] negates it.
-v
grep option that prints lines that do NOT match the pattern.
-E
grep option that enables extended regular expressions, making + ? | {} and () special.
SSH
Secure Shell: an encrypted protocol and client (ssh) for logging in to and running commands on remote systems.
su -
Switch user with a full login shell and that user's environment; asks for the target user's password.
sudo -i
Start a root login shell after authenticating with your own password, as allowed by the sudoers policy.
wheel group
The group whose members RHEL's default sudoers policy allows to run any command with sudo.
multi-user.target
The systemd target for a text-mode system with networking and services but no graphical login.
Archive
A single file that bundles many files and directories along with their metadata; created with tar.
-c / -x / -t
tar actions: create an archive, extract it, or list (table of contents) without extracting.
-f
tar option naming the archive file; the file name must immediately follow it.
-z / -j / -J
Use gzip, bzip2 or xz compression respectively.
-C
tar option that changes to a directory before extracting (or archiving).
Normal mode
Vim's default mode, in which keys are commands for moving, deleting, copying and pasting.
Insert mode
Vim mode entered with i, a or o in which typed keys become text; Esc leaves it.
:wq / :q!
Vim commands to save and quit, or to quit discarding unsaved changes.
visudo
Safely edits the sudoers file, locking it and checking syntax before saving.
Swap file
A .swp recovery file vim keeps while editing; a leftover one signals a concurrent or crashed edit.
mkdir -p
Create a directory and any missing parent directories; no error if it already exists.
cp -a
Archive copy: recursive, preserving permissions, ownership, timestamps, links and extended attributes such as SELinux contexts.
mv
Moves or renames files; within one file system it keeps the file's metadata unchanged.
rm -r
Recursively remove a directory and all of its contents.
Absolute path
A path starting at the root directory /, independent of the current directory.
Inode
The on-disk structure holding a file's metadata and data locations, identified by a number unique within its file system.
Hard link
An additional directory entry pointing to the same inode; created with ln.
Symbolic link
A special file containing a path to another file or directory; created with ln -s.
Link count
The number of hard links (names) referring to an inode, shown in the second column of ls -l.
Dangling link
A symbolic link whose target no longer exists.
ugo
The three permission classes: user (owner), group and others; a means all three.
Octal mode
Numeric permissions where r=4, w=2 and x=1 are summed per class, e.g. 755 or 640.
Symbolic mode
chmod notation such as u+x, g-w or o=r that changes specific permissions.
Execute on a directory
Permission to enter the directory and access items within it.
chown
Changes a file's owning user and optionally its group (user:group).
man page
A manual page viewed with man, organised into standard sections such as SYNOPSIS, OPTIONS and EXAMPLES.
Man section
A numbered category of man pages: 1 user commands, 5 file formats, 8 administration commands.
man -k
Searches man page names and descriptions for a keyword; equivalent to apropos.
mandb
Builds or updates the index database that man -k searches.
/usr/share/doc
Directory holding installed packages' extra documentation and sample configuration files.

Domain 2: Manage software (7%)

Exam tips

Key terms

Repository
A collection of RPM packages plus metadata (repodata) that dnf can download from.
Repository ID
The unique name in square brackets that starts a section of a .repo file.
baseurl
The URL of the directory containing the repository's repodata; may use http, https, ftp or file schemes.
gpgcheck
Setting that makes dnf verify package signatures (1) or skip verification (0).
gpgkey
Location of the public key used to verify package signatures when gpgcheck=1.
dnf config-manager
dnf plugin command for adding repositories and enabling or disabling them.
--add-repo
Creates a .repo file in /etc/yum.repos.d from a repository URL or a downloaded .repo file.
dnf repolist
Lists enabled repositories; add all to include disabled ones, -v for details.
dnf clean all
Removes cached repository metadata and packages so dnf fetches fresh data.
--enablerepo / --disablerepo
Options that enable or disable a repository for one dnf command only.
dnf install
Installs packages and their dependencies from enabled repositories or local RPM files.
dnf remove
Uninstalls packages together with packages that depend on them.
dnf update
Upgrades installed packages to the newest available versions; also called dnf upgrade.
dnf reinstall
Reinstalls the current version of a package, restoring its files.
dnf history undo
Reverses the changes made by a specific recorded dnf transaction.
dnf search
Searches package names and summaries (or with --all, descriptions too) for keywords.
dnf provides
Finds which package contains a given file, command or path glob; also called whatprovides.
dnf info
Displays details about a package, such as version, repository, size and description.
dnf list
Lists installed and available packages matching a name pattern.
@System
Label dnf uses to show that a package is installed locally rather than available from a repository.
RPM database
The local database recording every installed package and its files, queried with rpm -q.
rpm -qa
Lists all installed packages.
rpm -ql / -qc
Lists all files, or only the configuration files, installed by a package.
rpm -qf
Shows which installed package owns a given file.
rpm -qi
Shows detailed information about an installed package.
Package group
A named set of related packages defined in repository metadata, installable in one step.
Environment group
A larger bundle of groups representing a complete system type, such as Server with GUI.
Mandatory / default / optional
Package classes within a group; dnf installs mandatory and default unless told --with-optional.
dnf group info
Shows the packages contained in a group, sorted by class.
@group syntax
Shorthand for groups in dnf install, e.g. dnf install @development; @^ marks an environment group.
Flatpak
A system for distributing sandboxed applications that ship with their own runtimes, independent of RPM packages.
Remote
A named Flatpak repository from which applications and runtimes are installed.
Runtime
A shared set of libraries and services that Flatpak applications run on top of.
.flatpakrepo file
A descriptor containing a remote's URL, title and GPG key, used with flatpak remote-add.
System vs user installation
System remotes and apps are shared by all users (/var/lib/flatpak); --user ones live in the user's home.
Application ID
A reverse-DNS style identifier for a Flatpak app, such as org.example.Editor.
Ref
A full Flatpak reference combining type, ID, architecture and branch, e.g. app/ID/x86_64/stable.
flatpak install
Installs an application and its required runtime from a remote.
flatpak run
Starts an installed Flatpak application in its sandbox.
flatpak uninstall --unused
Removes runtimes and extensions no longer needed by any installed application.

Domain 3: Create simple shell scripts (7%)

Exam tips

Key terms

Shebang
The #! first line naming the interpreter, e.g. #!/bin/bash, used when the file is executed.
Execute permission
The x permission that lets a file be run as a program; set with chmod +x.
PATH
Environment variable listing directories the shell searches, in order, for commands.
/usr/local/bin
Conventional system-wide directory in PATH for locally created scripts and programs.
source
Runs a script in the current shell rather than a child process; also written as a dot.
test / [ ]
Command that evaluates a condition and returns exit status 0 (true) or 1 (false); spaces around brackets are required.
-f / -d / -e
Tests for a regular file, a directory, or any existing path.
-z / -n
Tests whether a string is empty or not empty.
-eq / -gt / -lt
Numeric comparison operators: equal, greater than, less than (also -ne, -ge, -le).
elif
Additional condition checked only if the previous if or elif was false.
Exit status
A number 0 to 255 returned by every command; 0 means success, non-zero means failure.
$?
Special variable holding the exit status of the last command that finished.
&&
Runs the next command only if the previous one succeeded (exit status 0).
||
Runs the next command only if the previous one failed (non-zero exit status).
exit
Built-in that ends a script immediately with a given status code.
for loop
Repeats a block once for each word in a list, assigning the word to a variable.
while loop
Repeats a block as long as its condition command returns exit status 0.
read
Built-in that reads one line of input into variables; returns non-zero at end of input.
seq
Command that prints a sequence of numbers, e.g. seq 1 10.
IFS
Internal Field Separator: the characters read and word splitting use to split text.
Positional parameters
The arguments passed to a script, available as $1, $2 and so on.
$0
The name of the script as it was invoked.
$#
The number of arguments passed to the script.
"$@"
All arguments as separate, correctly quoted words; the right form for loops and passing arguments on.
shift
Discards $1 and renumbers the remaining arguments down by one.
Command substitution
$(command): replaces itself with the standard output of the command.
Backticks
The older command form of command substitution; equivalent but harder to nest.
cut
Extracts fields or character ranges from each line, e.g. cut -d: -f1.
awk '{print $N}'
Prints the Nth whitespace-separated field of each line.
Subshell
A child copy of the shell in which the substituted command runs.
Variable assignment
name=value with no spaces around =; referenced later as $name or ${name}.
export
Marks a variable for inclusion in the environment of child processes.
read -p
Reads a line of input into variables after displaying a prompt.
Double quotes
Allow $ expansion but prevent word splitting and globbing.
Single quotes
Prevent all expansion; the text is taken literally.
case ... esac
Statement that compares a value against patterns and runs the first matching clause.
;;
Terminates a case clause; execution then continues after esac.
Pattern alternatives
Several patterns in one clause separated by |, such as start|up).
*) default clause
A final clause matching anything not matched earlier, typically for usage errors.
bash -n
Checks a script's syntax without running it.

Domain 4: Operate running systems (12%)

Exam tips

Key terms

systemd
The init system and service manager, process 1 on RHEL, which starts and stops everything else.
systemctl reboot / poweroff
Cleanly restart the system or shut it down and power it off.
Target
A systemd unit that groups other units to describe a system state, e.g. multi-user.target.
Default target
The target systemd starts at boot; shown by systemctl get-default and changed by set-default.
initramfs
Initial RAM file system loaded with the kernel, containing what is needed to mount the real root file system.
GRUB 2
The boot loader on RHEL; its menu lets you choose and temporarily edit kernel entries.
Kernel command line
Parameters on the linux line in GRUB, passed to the kernel and systemd at boot.
rescue.target
Minimal target that mounts all local file systems and provides a root shell, without networking.
emergency.target
Most minimal target: only root mounted read-only and a root shell.
systemd.unit=
Kernel parameter telling systemd which target to start instead of the default.
rd.break
Kernel parameter that makes the initramfs stop and open a shell before switching to the real root.
/sysroot
Where the real root file system is mounted inside the initramfs, read-only by default.
chroot
Runs a shell with a given directory treated as the root /, here /sysroot.
/.autorelabel
Empty file that triggers a full SELinux relabel of the file system at the next boot.
dracut
The tool that builds the initramfs and understands rd.* kernel parameters.
PID
Process ID: the unique number identifying a running process.
top
Interactive, live view of processes sorted by resource use; M sorts by memory, P by CPU, k kills.
ps aux --sort=-%cpu
Snapshot of all processes sorted by descending CPU usage.
SIGTERM (15)
Default kill signal requesting a clean shutdown; the process may catch it.
SIGKILL (9)
Signal that terminates a process immediately; it cannot be caught or ignored.
Nice value
A number from -20 (highest priority) to 19 (lowest) that influences a process's CPU share; default 0.
nice
Starts a command with a specified nice value; default adjustment is 10.
renice
Changes the nice value of running processes by PID, user or group.
PR
The priority column in top; for normal processes it is 20 plus the nice value.
Scheduler
The kernel component that decides which runnable process uses a CPU next.
tuned
The RHEL service that applies tuning profiles adjusting kernel and hardware settings for a workload.
Tuning profile
A named set of performance and power settings, such as balanced or virtual-guest.
tuned-adm active
Shows the currently active tuning profile.
tuned-adm recommend
Shows the profile tuned recommends for the detected system.
tuned-adm profile
Switches to and persistently saves the given profile.
systemd-journald
Service that collects log messages into the structured systemd journal.
rsyslog
Syslog daemon that writes messages to text files under /var/log according to /etc/rsyslog.conf.
/var/log/secure
Text log for authentication and security events such as logins and sudo.
journalctl -u
Shows journal entries for a specific systemd unit.
Syslog priority
Severity level from emerg (0) to debug (7); journalctl -p shows that level and more severe ones.
Storage=
journald.conf option choosing where the journal is kept: persistent, volatile, auto or none.
/var/log/journal
On-disk location of a persistent journal.
/run/log/journal
In-memory (tmpfs) location of a volatile journal, lost at reboot.
journalctl --list-boots
Lists the boots recorded in the journal; more than one indicates persistence.
Service unit
A systemd unit (name.service) that describes how to run and manage a daemon.
start vs enable
start runs the service now; enable makes it start at boot. enable --now does both.
systemctl status
Shows a unit's load, enable and active state, main PID and recent log lines.
ss -tlnp
Lists listening TCP sockets numerically with the owning process.
mask
Links a unit to /dev/null so it cannot be started until unmasked.
scp
Secure copy: copies files to or from remote hosts over SSH using user@host:path syntax.
sftp
Interactive file transfer client over SSH with commands like get, put, ls and lcd.
rsync
Synchronises files, transferring only differences, over SSH by default.
rsync -a
Archive mode: recursive, preserving permissions, times, links, and ownership where possible.
--delete
rsync option removing destination files that are absent from the source; test first with -n.

Domain 5: Configure local storage (12%)

Exam tips

Key terms

Block device
A storage device such as a disk or partition accessed in blocks, found under /dev.
lsblk
Lists block devices as a tree with size, type and mount point; -f adds file system details.
blkid
Shows UUID, file system type and label of devices with recognised signatures.
fdisk -l
Lists partition tables, showing table type (dos or gpt) and each partition's size and type.
UUID
Universally unique identifier assigned to a file system or other signature, stable across device renaming.
GPT
GUID Partition Table: modern scheme supporting many partitions and very large disks, with a backup table.
MBR (dos)
Older partition scheme limited to four primary partitions and 2 TiB disks.
Partition type
Identifier describing a partition's purpose, such as Linux LVM (8e00) or Linux swap (8200).
mklabel
parted command that creates a new, empty partition table (msdos or gpt).
partprobe
Asks the kernel to reread a disk's partition table after changes.
LVM
Logical Volume Manager: pools block devices into volume groups and allocates flexible logical volumes.
Physical volume (PV)
A disk or partition initialised with an LVM label so it can join a volume group.
pvcreate
Initialises devices as physical volumes.
pvs / pvdisplay
Show physical volumes in brief (pvs) or detailed (pvdisplay) form.
pvremove
Removes the LVM label from a device that is not in any volume group.
Volume group (VG)
An LVM storage pool made from one or more physical volumes.
Physical extent (PE)
The fixed-size allocation unit of a volume group; 4 MiB by default.
vgcreate -s
Creates a volume group with a specified physical extent size.
vgextend
Adds physical volumes to an existing volume group to increase its capacity.
vgdisplay
Shows detailed volume group information including PE size and free extents.
Logical volume (LV)
A volume allocated from a volume group that holds a file system or swap, like a flexible partition.
lvcreate -L
Creates an LV with a size given in units such as M or G.
lvs / lvdisplay
List LVs briefly, or show details such as Current LE and path.
lvremove
Deletes a logical volume; unmount it and remove it from fstab first.
/etc/fstab
File listing file systems to mount at boot: device, mount point, type, options, dump and fsck order.
Mount point
An existing directory where a file system's contents are attached.
UUID=
fstab device syntax using a file system's universally unique identifier, stable across device renaming.
LABEL=
fstab device syntax using a human-assigned file system label.
mount -a
Mounts all fstab entries not yet mounted; used to test fstab before rebooting.
Free space
Unallocated area on a disk or free extents in a volume group, where new storage can be added safely.
Swap space
Disk space used by the kernel to hold memory pages when RAM is under pressure.
mkswap
Writes a swap signature to a device, preparing it for use as swap.
swapon / swapoff
Activate or deactivate swap areas; swapon -a activates all fstab swap entries.
swapon --show
Lists active swap areas with their size, usage and priority.

Domain 6: Create and configure file systems (10%)

Exam tips

Key terms

XFS
The default RHEL file system; high performance and growable online, but it cannot be shrunk.
ext4
The fourth extended file system; mature, growable online and shrinkable while unmounted.
vfat
The Linux driver for FAT file systems, used for EFI partitions and removable media; it stores no Linux ownership or permissions.
blkid
Prints the UUID, label and file system type of block devices, used when writing /etc/fstab entries.
Mount point
An existing directory where a file system is attached to the directory tree.
mount -a
Mounts every file system listed in /etc/fstab that is not already mounted, used to test new entries.
findmnt --verify
Checks /etc/fstab for errors such as missing mount points, bad types or unknown devices without mounting.
target is busy
The umount error shown when a process has open files or a working directory inside the file system.
/etc/fstab
The file that lists file systems and swap to mount or activate at boot, one six-field line each.
defaults
The option set rw, suid, dev, exec, auto, nouser and async.
fsck order
The sixth fstab field: 0 skips checking, 1 is root, 2 is other file systems checked after root.
nofail
An fstab option that lets boot continue if the device is not present.
NFS
Network File System; a protocol for sharing directories from a server so clients can mount them over the network.
Export
A directory an NFS server makes available to clients.
_netdev
An fstab option marking a file system as network-dependent so it mounts after networking starts.
Root squash
An NFS server behavior that maps a client's root user to an unprivileged account, the default for exports.
autofs
A service that mounts file systems automatically when a path is accessed and unmounts them when idle.
Master map
The top-level autofs configuration, in /etc/auto.master and /etc/auto.master.d/*.autofs, mapping base directories to map files.
Indirect map
A map whose keys are names relative to a base directory given in the master map.
Wildcard entry
A map line with * as the key and & in the location, so any key name maps to a matching server path.
lvextend
Increases the size of a logical volume, optionally resizing its file system with -r.
xfs_growfs
Grows a mounted XFS file system to fill its device; takes the mount point.
resize2fs
Resizes an ext2, ext3 or ext4 file system; it can grow online and shrink offline.
Physical extent
The fixed-size unit (4 MiB by default) in which LVM allocates space, so LV sizes round to multiples of it.
Shrink
Reducing a file system and its volume to a smaller size; supported offline by ext4 and not at all by XFS.
e2fsck -f
Forces a full consistency check of an ext file system, required by resize2fs before shrinking.
lvreduce
Decreases the size of a logical volume; with -r it shrinks the file system first.
fsadm
A helper used by lvextend -r and lvreduce -r to resize the file system on a logical volume.
namei -l
Lists each component of a path with its owner, group and mode, used to find where traversal fails.
Execute bit on a directory
Permission to enter a directory and access entries inside it, needed on every directory in a path.
chmod
Changes permission bits using symbolic (u+x, g-w) or numeric (755) modes.
chown
Changes the owner, and optionally the group, of files with the form user:group.

Domain 7: Deploy, configure and maintain systems (10%)

Exam tips

Key terms

at
Schedules a one-time job, run by the atd service; atq lists and atrm removes jobs.
crontab
A per-user table of recurring jobs with five time fields and a command, edited with crontab -e.
/etc/cron.d
A directory of system cron files whose lines include a user field between the schedule and the command.
Timer unit
A systemd .timer file that starts a matching service on a calendar schedule (OnCalendar=) or after an event (OnBootSec=).
Unit
An object managed by systemd, such as a .service, .socket, .timer, .mount or .target.
enable --now
Configures a unit to start at boot and starts it immediately in one command.
mask
Links a unit to /dev/null so it cannot be started manually or as a dependency until unmasked.
daemon-reload
Makes systemd reread unit files after they are created or changed.
Target
A systemd unit that groups other units to define a system state, replacing runlevels.
multi-user.target
A full non-graphical system state with networking and services, the usual default for servers.
graphical.target
multi-user.target plus a graphical login manager.
isolate
A systemctl command that switches the running system to a target, stopping units not required by it.
NTP
Network Time Protocol, used to synchronize clocks with time servers over the network.
chronyd
The RHEL NTP daemon, configured in /etc/chrony.conf.
iburst
A chrony server option that sends several quick requests at startup to synchronize faster.
timedatectl
A systemd tool to view and set the time, time zone and whether NTP synchronization is on.
dnf
The RHEL package manager that installs, updates and removes RPM packages and resolves dependencies from repositories.
.repo file
A file in /etc/yum.repos.d/ that defines repositories with an ID, name, baseurl, enabled and gpgcheck settings.
BaseOS and AppStream
The two main RHEL repositories: core operating system packages, and applications and runtimes.
GPG check
Verification of a package's signature against a trusted key before installing it.
subscription-manager
The command-line tool that registers a RHEL system with Red Hat and manages its repositories.
Developer subscription
A no-cost Red Hat subscription for individuals that allows registering RHEL systems for development and learning.
Simple content access
Red Hat's model where a registered system can use entitled content without attaching subscriptions to each machine.
Activation key
A preconfigured key used with an organization ID to register systems without a username and password.
GRUB 2
The RHEL boot loader that presents the boot menu and loads the kernel with its command line.
/etc/default/grub
The file of global GRUB settings such as GRUB_TIMEOUT and GRUB_CMDLINE_LINUX, applied by grub2-mkconfig.
grub2-mkconfig
Regenerates /boot/grub2/grub.cfg from /etc/default/grub and /etc/grub.d scripts.
grubby
A tool that reads and edits boot entries directly, including default kernel and kernel arguments.
Kernel argument
An option on the kernel command line that changes kernel or systemd behavior at boot.
grubby --set-default
Sets the default boot entry by kernel path, persisting across reboots.
uname -r
Prints the release of the currently running kernel.
/proc/cmdline
A virtual file showing the command line the running kernel was booted with.

Domain 8: Manage basic networking (8%)

Exam tips

Key terms

NetworkManager
The RHEL service that configures and manages network interfaces using connection profiles.
Connection profile
A saved set of network settings that NetworkManager applies to a device when activated.
ipv4.method
The property that selects auto (DHCP), manual (static), link-local or disabled addressing.
CIDR notation
An address followed by a slash and prefix length, such as 192.168.10.20/24, giving address and netmask together.
Keyfile
NetworkManager's INI-style profile format, stored as .nmconnection files in /etc/NetworkManager/system-connections/.
ifcfg file
The legacy shell-style network configuration format in /etc/sysconfig/network-scripts/, not supported in RHEL 10.
nmcli con reload
Tells NetworkManager to reread connection files from disk after manual edits.
address1=
The keyfile key for the first static address in CIDR form, optionally followed by a comma and the gateway.
nmcli con up
Activates a connection profile on its device, applying its current settings.
connection.autoconnect
A profile property that makes NetworkManager activate it automatically at boot and when the device appears.
autoconnect-priority
A number that decides which of several autoconnect profiles wins for a device; higher wins.
nmcli device disconnect
Deactivates a device and prevents automatic reactivation until a connection is brought up manually or the system restarts.
hostnamectl
The tool that shows and sets the system hostname, writing the static name to /etc/hostname.
/etc/hosts
A local file of address-to-name mappings consulted before DNS by default.
/etc/resolv.conf
The resolver file listing nameserver and search domains, generated by NetworkManager on RHEL.
ipv4.dns
The NetworkManager connection property holding DNS server addresses for that profile.
ip addr
Shows network interfaces with their state and IPv4 and IPv6 addresses.
Default gateway
The router that receives traffic for destinations not on a directly connected network, shown as default via in ip route.
getent hosts
Resolves a name using the system's configured order (nsswitch), including /etc/hosts and DNS.
ICMP
Internet Control Message Protocol, used by ping for echo requests and replies.
enable --now
Enables a unit to start at boot and starts it immediately.
network-online.target
A systemd target reached when the network is fully configured, used to order services that need working networking.
ss -tlnp
Lists listening TCP sockets with numeric ports and the owning processes.
Permanent firewall rule
A firewalld change saved with --permanent so it survives reloads and reboots.
firewalld
The RHEL firewall service that manages packet filtering rules through zones, services and ports.
Zone
A named trust level holding allowed services and ports, applied to interfaces or source addresses.
--permanent
Saves a firewall-cmd change to configuration without applying it until a reload.
--reload
Reloads firewalld so the permanent configuration becomes the running configuration, discarding runtime-only changes.
nmtui
A text-based, menu-driven NetworkManager interface for editing connections, activating them and setting the hostname.
NetworkManager-tui
The package that provides the nmtui command.
Automatically connect
The nmtui check box that sets connection.autoconnect for a profile.
Activate a connection
The nmtui menu for bringing profiles up or down so saved changes take effect.

Domain 9: Manage users and groups (8%)

Exam tips

Key terms

UID
User ID, the number the kernel uses to identify a user; regular users start at 1000 on RHEL.
Primary group
The group assigned to new files a user creates, set with -g and stored in /etc/passwd.
Supplementary group
An additional group membership that grants group permissions, set with -G.
usermod -aG
Appends supplementary groups to a user without removing existing ones.
Service account
An account used by a program rather than a person, typically created with useradd -r.
/sbin/nologin
A shell that politely refuses interactive login, used to block logins for service accounts.
Login shell
The program started when a user logs in, stored in the last field of /etc/passwd.
/etc/shells
The list of valid login shells on the system.
chage
Views and changes password aging and account expiration for a user.
Maximum password age
Days a password stays valid before the user must change it, set with chage -M.
Minimum password age
Days a user must wait between password changes, set with chage -m.
Account expiration
A date after which the account cannot be used at all, set with chage -E.
/etc/login.defs
Configuration for new accounts: default password aging, UID and GID ranges, CREATE_HOME, UMASK and hashing method.
/etc/default/useradd
useradd defaults such as base home directory, default shell, skeleton directory and expiry, shown with useradd -D.
/etc/skel
The skeleton directory whose files are copied into every new user's home directory.
PASS_MAX_DAYS
The login.defs setting for default maximum password age applied to new accounts.
GID
Group ID, the number identifying a group in /etc/group.
groupadd -g
Creates a group with a specific GID.
gpasswd
Administers /etc/group and /etc/gshadow: add or remove members, set the member list and assign group administrators.
/etc/gshadow
The secure group file holding group passwords, administrators and members.
/etc/passwd
The world-readable account file with seven fields: name, x, UID, GID, comment, home and shell.
/etc/shadow
The root-only file holding password hashes and aging fields for each account.
/etc/group
The group file with name, x, GID and a list of supplementary members.
getent
Queries system databases such as passwd and group through NSS, including local and network sources.
sudo
Runs a command as root or another user according to sudoers rules, logging the action.
wheel group
The RHEL administrative group granted full sudo rights by the default sudoers rule %wheel ALL=(ALL) ALL.
visudo
Edits sudoers files safely with locking and syntax checking; -f edits a drop-in and -c checks all files.
/etc/sudoers.d/
A directory of drop-in sudoers files that keeps local rules separate from the main file.
Password lock
An exclamation mark prefixed to the shadow hash by usermod -L or passwd -l, which blocks password authentication only.
Account expiry
The shadow expiration date; chage -E 0 sets it in the past so every login method is refused.
passwd -S
Shows the password status of an account, including whether it is locked.
chage -E -1
Removes an account's expiration date, reversing chage -E 0.

Domain 10: Manage security (14%)

Exam tips

Key terms

Source binding
Assigning a source address or network to a zone so packets from it use that zone's rules.
Default zone
The zone used for interfaces and traffic not assigned to any other zone, public unless changed.
Runtime configuration
The firewall rules currently in effect, lost on reload or reboot unless saved.
--runtime-to-permanent
Saves the current runtime firewall configuration as the permanent configuration.
umask
A per-process mask of permission bits removed from new files and directories.
Default creation mode
The mode programs request before masking: 666 for files and 777 for directories.
~/.bashrc
A per-user shell startup file where a persistent umask for that user can be set.
/etc/profile.d/
A directory of shell scripts run at login for all users, a clean place for site-wide settings like umask.
Key pair
A private key kept on the client and a matching public key placed on servers for authentication.
authorized_keys
The file ~/.ssh/authorized_keys on a server listing public keys allowed to log in as that user.
ssh-copy-id
Copies a public key into a remote user's authorized_keys file with correct permissions.
PermitRootLogin
An sshd setting controlling root logins: yes, no or prohibit-password (key only).
SELinux
Security-Enhanced Linux, kernel mandatory access control based on labels and policy.
Enforcing mode
SELinux applies the policy, denying and logging forbidden access.
Permissive mode
SELinux logs policy violations but allows them, used for troubleshooting.
/etc/selinux/config
The file setting the SELinux mode and policy type used at boot.
Security context
An SELinux label of the form user:role:type:level attached to files, processes and ports.
Type
The context field ending in _t that targeted policy uses to decide access.
Type enforcement
SELinux policy rules that allow a process type specific access to object types.
unconfined_t
The type of normal user login sessions, which targeted policy does not restrict.
restorecon
Resets file SELinux labels to the values defined in policy; -R recurses and -v reports changes.
semanage fcontext
Adds, modifies, deletes or lists the policy rules mapping path patterns to file types.
chcon
Changes a file's label directly; the change is lost on restorecon or relabel.
(/.*)?
The regular expression suffix that matches a directory and everything beneath it in fcontext rules.
Port type
An SELinux label on a network port, such as http_port_t or ssh_port_t, that controls which process types may use it.
name_bind
The permission a process needs to listen on a port; denials of it indicate a missing port label.
semanage port -a
Adds a port number and protocol to an SELinux port type.
semanage port -m
Modifies a port that is already defined with another type.
SELinux boolean
A policy switch that turns an optional set of permissions on or off without writing new policy.
getsebool -a
Lists all booleans and their current values.
setsebool -P
Sets a boolean and makes the change persistent across reboots.
semanage boolean -l
Lists booleans with current value, default value and description.
AVC denial
An audit log record of an access blocked by SELinux, naming the permission, source context, target context and class.
auditd
The audit daemon that writes SELinux denials and other events to /var/log/audit/audit.log.
ausearch
Searches the audit log by message type, time and command; -m AVC selects SELinux denials.
sealert
A setroubleshoot tool that explains denials in plain language and suggests fixes.
Study RHCSA for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the RHCSA study plan