| |

LFCA 124 🐧 LFCA Practice Questions — Domain 1

The LFCA exam asks 60 multiple-choice questions in 90 minutes. Domain 1, System Administration Fundamentals, is the heaviest domain at 30% of the exam—roughly 18 questions. It covers user and group management, file permissions, process and service management, networking fundamentals, troubleshooting methodology, and disaster recovery. These are the questions where practical familiarity with commands matters most, and where the scenario-based reasoning the exam tests is most visible.

This chapter is a set of practice questions in the style of the LFCA exam. Each question presents a scenario and asks for the best answer among four choices. The answers are explained, not just given, so the reasoning is visible. The questions are designed to match the level and format of the actual exam: no trick questions, no obscure commands, no deep implementation details. They test whether you understand what each command does and when to use it.

Key point: LFCA questions are scenario-based. They describe a situation and ask which command or action is appropriate. The correct answer is usually the one that follows the methodical approach: gather information before acting, check the layer below before the layer above, and verify before declaring success.


Why practice questions matter

The recall problem. Knowing that chmod 755 produces rwxr-xr-x is different from recognizing that a file with rw-r--r-- needs execute permission added for the owner. Practice questions force the transition from memorization to application. The exam tests application.

The timing problem. Sixty questions in ninety minutes is 1.5 minutes per question. That is comfortable if you know the material, but it is tight if you are reading each question twice. Practice builds the pattern recognition that lets you answer quickly and confidently.

The distractor problem. Every question has one correct answer and three plausible distractors. The distractors are usually commands that exist and do something related but not what the question asks. Practice teaches you to distinguish usermod -G from usermod -aG, or systemctl restart from systemctl reload, or ip addr from ip link.

The coverage problem. Domain 1 is broad. It includes users, permissions, services, logs, networking, troubleshooting, and backup. Practice questions reveal which subtopics you have internalized and which ones you are guessing on.


a. Practice questions

Question 1. A new developer joins the team. The administrator needs to create a user account with a home directory and the Bash shell. Which command accomplishes this?

A. useradd jsmith
B. useradd -m -s /bin/bash jsmith
C. adduser jsmith
D. usermod -m -s /bin/bash jsmith

Answer: B. The -m flag creates the home directory, and -s /bin/bash sets the login shell. Without -m, no home directory is created. Without -s, the user gets the system default, which may be /bin/sh. Option A omits both flags. Option C is a distribution-specific wrapper that behaves differently across systems. Option D modifies an existing user and requires the user to exist first.


Question 2. A user needs to be added to the developers group without losing their existing group memberships. Which command is correct?

A. usermod -G developers jsmith
B. usermod -aG developers jsmith
C. groupadd -a developers jsmith
D. chgrp developers jsmith

Answer: B. The -aG flag appends the group to the user’s existing supplementary groups. Option A uses -G alone, which replaces all supplementary groups with developers, silently removing the user from every other group. Option C is not a valid form of groupadd. Option D changes the group ownership of a file, not group membership.


Question 3. A file named deploy.sh has permissions -rw-r--r--. The owner needs to make it executable without changing permissions for anyone else. Which command does this?

A. chmod +x deploy.sh
B. chmod 755 deploy.sh
C. chmod u+x deploy.sh
D. chown +x deploy.sh

Answer: C. The u+x notation adds execute permission for the owner only. Option A, chmod +x, adds execute for owner, group, and others—not just the owner. Option B, chmod 755, also grants execute to group and others. Option D is not valid; chown changes ownership, not permissions.


Question 4. A service named nginx fails to start. Which command shows the most recent log entries that explain the failure?

A. systemctl start nginx
B. journalctl -u nginx
C. cat /var/log/nginx/access.log
D. systemctl enable nginx

Answer: B. The journalctl -u nginx command filters the systemd journal to the nginx unit and shows its log entries. Option A attempts to start the service again without diagnosing the failure. Option C shows access logs, not error logs or service logs. Option D enables the service at boot; it does not show why it failed.


Question 5. A server can reach external IP addresses but cannot resolve hostnames. Which file should the administrator check first?

A. /etc/hosts
B. /etc/resolv.conf
C. /etc/nsswitch.conf
D. /etc/network/interfaces

Answer: B. The /etc/resolv.conf file lists the DNS servers the system queries. If it is missing or contains an incorrect nameserver entry, hostname resolution fails while IP connectivity works. Option A can override individual hostnames but is not the primary DNS configuration. Option C controls the order of name resolution sources but not the DNS server itself. Option D configures network interfaces, not DNS.


Question 6. An administrator needs to check whether a web server is listening on port 80. Which command shows this?

A. ping localhost
B. curl localhost:80
C. ss -tulpn | grep :80
D. ip addr show

Answer: C. The ss -tulpn command lists listening TCP and UDP sockets with their port numbers and owning processes. Grepping for :80 filters to port 80. Option A tests ICMP reachability, not port state. Option B attempts an HTTP request, which may fail for reasons other than the port not being open. Option D shows interface configuration, not listening ports.


Question 7. A system is slow, and the administrator suspects a memory-hungry process. Which command shows processes sorted by memory usage?

A. ps aux --sort=-%mem | head
B. df -h
C. iostat -x 1 5
D. systemctl status

Answer: A. The ps aux --sort=-%mem command sorts processes by memory usage in descending order. Piping to head shows the top consumers. Option B shows disk usage, not memory. Option C shows disk I/O statistics. Option D shows service states, not per-process resource usage.


Question 8. A backup archive was created last week. Before relying on it, the administrator wants to verify that it can be read. Which command checks the archive’s integrity without extracting it?

A. tar -xzf backup.tar.gz
B. tar -tzf backup.tar.gz > /dev/null && echo "OK"
C. ls -lh backup.tar.gz
D. rsync -av backup.tar.gz /backup/

Answer: B. The tar -tzf command lists the archive’s contents without extracting. If the archive is corrupt or truncated, the command returns an error. The && echo "OK" confirms success. Option A extracts the archive, which is a restore, not a verification. Option C shows the file size but not the archive’s readability. Option D copies the file but does not verify its contents.


Question 9. An administrator needs to schedule a backup script to run every day at 2:00 AM. Which method provides catch-up execution if the system was powered off at the scheduled time?

A. A cron job with the schedule 0 2 * * *
B. A systemd timer with OnCalendar=*-*-* 02:00:00 and Persistent=true
C. A shell script run manually
D. An entry in /etc/rc.local

Answer: B. A systemd timer with Persistent=true runs a missed job as soon as the system is available. Option A, cron, does not run missed jobs; if the system was off at 2:00 AM, the job does not run. Option C is not automated. Option D runs once at boot, not on a schedule.


Question 10. A server can ping its gateway but cannot reach an external website by hostname or IP. Which is the most likely layer of the problem?

A. The physical link
B. The local IP configuration
C. The routing or upstream network
D. DNS resolution

Answer: C. The gateway responds, so the local link and IP configuration are working. External IP addresses also fail, which rules out DNS—DNS failures produce hostname failures while IP addresses still work. The problem is beyond the gateway, in the routing or upstream network. Option A would prevent the gateway from responding. Option B would prevent the gateway from responding. Option D would not affect IP addresses.


Question 11. An administrator needs to change the owner and group of a file to jsmith and developers, respectively. Which command does this?

A. chmod jsmith:developers file.txt
B. chown jsmith:developers file.txt
C. chgrp jsmith:developers file.txt
D. usermod jsmith:developers file.txt

Answer: B. The chown user:group file command changes both the owner and the group. Option A is not valid; chmod changes permissions, not ownership. Option C changes only the group and does not accept a user:group syntax. Option D modifies a user account, not a file.


Question 12. A service is running, but a configuration change has been made and needs to be applied without stopping the service. Which command is appropriate?

A. systemctl stop nginx && systemctl start nginx
B. systemctl reload nginx
C. systemctl enable nginx
D. systemctl disable nginx

Answer: B. The systemctl reload nginx command applies configuration changes without stopping the service, if the service supports reloading. Option A stops the service, causing downtime. Option C enables the service at boot, which is unrelated to applying configuration. Option D disables the service at boot, which is also unrelated.


Question 13. An administrator needs to see the processes a specific user is running. Which command is most direct?

A. ps -u jsmith
B. df -h
C. free -h
D. ip addr show

Answer: A. The ps -u jsmith command lists processes owned by the user jsmith. Option B shows disk usage. Option C shows memory usage. Option D shows network interface configuration. None of these are process-related.


Question 14. A disk is reported as full, but df -h shows plenty of free space. Which command should the administrator run next?

A. du -sh /var/log/*
B. df -i
C. free -h
D. iostat -x 1 5

Answer: B. The df -i command shows inode usage. A filesystem can be completely full in inodes while still reporting free space in bytes, which produces “disk full” errors even though df -h shows space available. Option A shows directory sizes, which is useful but does not address the inode hypothesis. Option C shows memory. Option D shows disk I/O.


Question 15. An administrator needs to find all files in /var/log that were modified in the last 24 hours. Which command does this?

A. ls -la /var/log
B. find /var/log -mtime -1
C. grep -r "24 hours" /var/log
D. du -sh /var/log

Answer: B. The find /var/log -mtime -1 command finds files modified within the last day. The -mtime -1 expression matches files modified less than one day ago. Option A lists files but does not filter by time. Option C searches for text, not modification time. Option D shows directory sizes.


Question 16. A new service is installed but does not start automatically after a reboot. Which command fixes this?

A. systemctl start service
B. systemctl enable service
C. systemctl reload service
D. systemctl status service

Answer: B. The systemctl enable service command creates the symbolic links that cause the service to start automatically at boot. Option A starts the service now but does not affect boot behavior. Option C reloads configuration. Option D shows status but does not change it.


Question 17. An administrator needs to test whether a remote server is accepting connections on port 443. Which command is most appropriate?

A. ping server
B. nc -zv server 443
C. ip route show
D. dig server

Answer: B. The nc -zv server 443 command tests whether a TCP connection to port 443 can be established. Option A tests ICMP reachability, which does not indicate whether the port is open. Option C shows the local routing table. Option D resolves the hostname to an IP address.


Question 18. An administrator needs to check the current IP address and subnet mask of the eth0 interface. Which command shows this?

A. ip link show eth0
B. ip addr show eth0
C. ip route show
D. ss -tulpn

Answer: B. The ip addr show eth0 command displays the IP address and subnet mask assigned to the interface. Option A shows the link-layer state and MAC address but not the IP address. Option C shows the routing table. Option D shows listening ports.


Complete Example Session

# ============================================
# PART 1: USER MANAGEMENT
# ============================================
useradd -m -s /bin/bash jsmith    → creates user with home and shell
usermod -aG developers jsmith      → appends group membership
passwd jsmith                       → sets password

# ============================================
# PART 2: PERMISSIONS
# ============================================
chmod u+x deploy.sh                 → owner execute only
chown jsmith:developers file.txt    → change owner and group
chmod 755 script.sh                 → rwxr-xr-x

# ============================================
# PART 3: SERVICES AND LOGS
# ============================================
systemctl status nginx              → current state and recent logs
journalctl -u nginx                 → full service logs
systemctl enable nginx              → start at boot

# ============================================
# PART 4: NETWORK DIAGNOSTICS
# ============================================
ip addr show                        → IP configuration
ip route show                       → routing table
ping -c 3 gateway                   → gateway reachability
dig example.com                     → DNS resolution
ss -tulpn | grep :80                → listening ports
nc -zv server 443                   → port connectivity

# ============================================
# PART 5: RESOURCE CHECKS
# ============================================
ps aux --sort=-%mem | head          → top memory consumers
free -h                             → memory and swap
df -h                               → disk space
df -i                               → inode usage
iostat -x 1 5                       → disk I/O

# ============================================
# PART 6: BACKUP
# ============================================
tar -czpf backup.tar.gz /etc        → create archive
tar -tzf backup.tar.gz > /dev/null  → verify archive
rsync -avh /home/ /backup/home/     → mirror files

The six parts summarized the command patterns tested in Domain 1: user management, permissions, services and logs, network diagnostics, resource checks, and backup.


Quick Reference

User and Group Commands

TaskCommand
Create user with homeuseradd -m -s /bin/bash user
Add to groupusermod -aG group user
Set passwordpasswd user
Delete useruserdel -r user
List groupsgroups user

Permission Commands

TaskCommand
Owner executechmod u+x file
Numeric 755chmod 755 file
Change ownerchown user:group file
Change groupchgrp group file

Service and Log Commands

TaskCommand
Check statussystemctl status svc
Start servicesystemctl start svc
Enable at bootsystemctl enable svc
Reload configsystemctl reload svc
Service logsjournalctl -u svc

Network Commands

TaskCommand
IP addressip addr show
Link stateip link show
Routing tableip route show
DNS lookupdig domain
Listening portsss -tulpn
Port testnc -zv host port

Resource Commands

TaskCommand
Top memoryps aux --sort=-%mem | head
Memory usagefree -h
Disk spacedf -h
Inode usagedf -i
Disk I/Oiostat -x 1 5

Best Practices

✅ Do This:

# Check logs before restarting services
journalctl -u service                                      # ✅

# Use -aG to append group membership
usermod -aG developers jsmith                              # ✅

# Use -m with useradd for home directory
useradd -m -s /bin/bash jsmith                             # ✅

# Check inodes when disk appears full
df -i                                                      # ✅

# Verify archive integrity before relying on it
tar -tzf backup.tar.gz > /dev/null                         # ✅

# Test port connectivity with nc
nc -zv server 443                                          # ✅

❌ Don’t Do This:

# Don't use -G alone for group membership
usermod -G developers jsmith  → replaces groups             # ❌

# Don't restart without checking logs
systemctl restart service  → destroys evidence              # ❌

# Don't use chmod for ownership
chmod jsmith:developers file  → wrong command               # ❌

# Don't assume ICMP works when TCP fails
ping server  → may be blocked while ports are open          # ⚠️

# Don't skip the restore drill
# (untested backups are hopes)                             # ❌

Common Pitfalls

PitfallWhy It HappensFix
usermod -G removes groupsMissing -aUse -aG
No home directoryMissing -mUse useradd -m
Service does not start at bootNot enabledsystemctl enable
Disk full but space freeInode exhaustionCheck df -i
Port appears closedService not listeningCheck ss -tulpn
Archive corruptNever verifiedCheck tar -tzf

Real-World Examples

1. Create User

useradd -m -s /bin/bash jsmith
passwd jsmith

2. Add to Group

usermod -aG developers jsmith
groups jsmith

3. Set Permissions

chmod u+x deploy.sh
chown jsmith:developers file.txt

4. Check Service

systemctl status nginx
journalctl -u nginx -n 20

5. Network Diagnostics

ip addr show
ip route show
ping -c 3 8.8.8.8
dig example.com

6. Port Check

ss -tulpn | grep :443
nc -zv server 443

7. Memory Check

free -h
ps aux --sort=-%mem | head

8. Disk Check

df -h
df -i
du -sh /var/log/* | sort -rh | head

9. Backup Archive

tar -czpf backup.tar.gz /etc
tar -tzf backup.tar.gz > /dev/null && echo "OK"

10. Schedule Backup

# systemd timer with Persistent=true
OnCalendar=*-*-* 02:00:00
Persistent=true

Visual

Question Distribution by Subtopic

┌─────────────────────────────────────────────────────────────┐
│  DOMAIN 1 SUBTOPICS (18 questions)                          │
│                                                             │
│  User management       ████████               4 questions   │
│  Permissions           ██████                 3 questions   │
│  Services and logs     ██████                 3 questions   │
│  Network diagnostics   ████████               4 questions   │
│  Resources             ████                   2 questions   │
│  Backup                ████                   2 questions   │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Answer Patterns

┌─────────────────────────────────────────────────────────────┐
│  TYPES OF CORRECT ANSWERS                                   │
│                                                             │
│  The command that gathers information first                 │
│  (journalctl, ss, df -i, ip addr)                           │
│                                                             │
│  The command that matches the precise flag                  │
│  (-aG vs -G, -m, u+x)                                       │
│                                                             │
│  The command that follows the layered model                 │
│  (check lower layer before higher)                          │
│                                                             │
│  The command that verifies rather than assumes              │
│  (tar -tzf, nc -zv, systemctl status)                       │
│                                                             │
│  Distractors are real commands that do the wrong thing.     │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Command Selection Map

┌─────────────────────────────────────────────────────────────┐
│  SCENARIO → COMMAND                                         │
│                                                             │
│  Create user with home → useradd -m -s /bin/bash            │
│  Add to group → usermod -aG                                 │
│  Owner execute → chmod u+x                                  │
│  Change owner → chown user:group                            │
│  Service failed → journalctl -u                             │
│  Start at boot → systemctl enable                           │
│  IP address → ip addr show                                  │
│  DNS failure → dig + cat /etc/resolv.conf                   │
│  Port open → ss -tulpn + nc -zv                             │
│  Memory hog → ps aux --sort=-%mem                           │
│  Disk full → df -h + df -i                                  │
│  Backup verify → tar -tzf                                   │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Summary

TopicKey CommandCommon Distractor
User creationuseradd -m -s /bin/bashuseradd without -m
Group membershipusermod -aGusermod -G
Owner executechmod u+xchmod +x, chmod 755
Change ownerchown user:groupchmod, chgrp
Service logsjournalctl -uaccess.log
Start at bootsystemctl enablesystemctl start
DNS check/etc/resolv.conf/etc/hosts
Listening portsss -tulpnping, ip addr
Memory usageps aux --sort=-%memdf, iostat
Inode checkdf -idf -h
Port testnc -zvping
Archive verifytar -tzftar -xzf

Key takeaways:

  • The correct answer is usually the one that gathers information before acting. When a service fails, check the logs before restarting. When a port is unreachable, test it before assuming the cause. The LFCA rewards the methodical approach.
  • Flag precision matters. usermod -aG appends groups; usermod -G replaces them. useradd -m creates the home directory; useradd without -m does not. chmod u+x adds owner execute; chmod +x adds it for everyone. The exam tests the distinction.
  • Network diagnostics follow the layered model. Check the interface, then the IP, then the gateway, then DNS, then the port, then the service. A question that says “the gateway responds but external IPs fail” is pointing at the routing layer, not the link layer or DNS.
  • Verification is a distinct step. Checking that a backup exists is not the same as checking that it can be read. Checking that a service is running is not the same as checking that it is listening on the expected port. The exam tests whether you verify.
  • The commands in Domain 1 are the commands you use daily. useradd, usermod, chmod, chown, systemctl, journalctl, ip, ping, dig, ss, nc, ps, df, tar, rsync. If you have used them, the questions are straightforward. If you have only read about them, practice in a shell.

Remember: The LFCA is an entry-level exam, and Domain 1 tests practical system administration. The questions describe scenarios you will encounter on a real system: a user who needs an account, a service that failed, a network that does not work, a disk that is full, a backup that needs verification. The correct answer is the command or action that moves the investigation forward without skipping steps. Practice the commands, understand the flags, and the reasoning becomes intuitive.



Stop using slow, ad-bloated tool sites! 🤮

🔎 Search “KandZ Tools” on Google to use many professional utilities for free.

KandZ.me is the ultimate minimalist hub for:
✅ Finance (Mortgage, Interest, Inflation)
✅ Tech (Base64, JSON, Dev Suite, IP)
✅ Health (BMI, BMR, TDEE)
✅ Productivity (Timer, Workspace, QR)

⚡️ Fast & Private
🔒 No data leaves your device
💎 100% Free

🔗 Use it now: https://tools.kandz.me
🔖 Bookmark it—you’ll need it later!