LFCA 124 🐧 LFCA Practice Questions — Domain 1
The LFCA exam asks 60 multiple-choice questions in 90 minutes. Domain 1, System Administration Fundamentals, is the heaviest domain at 30% of the exam—roughly 18 questions. It covers user and group management, file permissions, process and service management, networking fundamentals, troubleshooting methodology, and disaster recovery. These are the questions where practical familiarity with commands matters most, and where the scenario-based reasoning the exam tests is most visible.
This chapter is a set of practice questions in the style of the LFCA exam. Each question presents a scenario and asks for the best answer among four choices. The answers are explained, not just given, so the reasoning is visible. The questions are designed to match the level and format of the actual exam: no trick questions, no obscure commands, no deep implementation details. They test whether you understand what each command does and when to use it.
Key point: LFCA questions are scenario-based. They describe a situation and ask which command or action is appropriate. The correct answer is usually the one that follows the methodical approach: gather information before acting, check the layer below before the layer above, and verify before declaring success.
Why practice questions matter
The recall problem. Knowing that chmod 755 produces rwxr-xr-x is different from recognizing that a file with rw-r--r-- needs execute permission added for the owner. Practice questions force the transition from memorization to application. The exam tests application.
The timing problem. Sixty questions in ninety minutes is 1.5 minutes per question. That is comfortable if you know the material, but it is tight if you are reading each question twice. Practice builds the pattern recognition that lets you answer quickly and confidently.
The distractor problem. Every question has one correct answer and three plausible distractors. The distractors are usually commands that exist and do something related but not what the question asks. Practice teaches you to distinguish usermod -G from usermod -aG, or systemctl restart from systemctl reload, or ip addr from ip link.
The coverage problem. Domain 1 is broad. It includes users, permissions, services, logs, networking, troubleshooting, and backup. Practice questions reveal which subtopics you have internalized and which ones you are guessing on.
a. Practice questions
Question 1. A new developer joins the team. The administrator needs to create a user account with a home directory and the Bash shell. Which command accomplishes this?
A. useradd jsmith
B. useradd -m -s /bin/bash jsmith
C. adduser jsmith
D. usermod -m -s /bin/bash jsmith
Answer: B. The -m flag creates the home directory, and -s /bin/bash sets the login shell. Without -m, no home directory is created. Without -s, the user gets the system default, which may be /bin/sh. Option A omits both flags. Option C is a distribution-specific wrapper that behaves differently across systems. Option D modifies an existing user and requires the user to exist first.
Question 2. A user needs to be added to the developers group without losing their existing group memberships. Which command is correct?
A. usermod -G developers jsmith
B. usermod -aG developers jsmith
C. groupadd -a developers jsmith
D. chgrp developers jsmith
Answer: B. The -aG flag appends the group to the user’s existing supplementary groups. Option A uses -G alone, which replaces all supplementary groups with developers, silently removing the user from every other group. Option C is not a valid form of groupadd. Option D changes the group ownership of a file, not group membership.
Question 3. A file named deploy.sh has permissions -rw-r--r--. The owner needs to make it executable without changing permissions for anyone else. Which command does this?
A. chmod +x deploy.sh
B. chmod 755 deploy.sh
C. chmod u+x deploy.sh
D. chown +x deploy.sh
Answer: C. The u+x notation adds execute permission for the owner only. Option A, chmod +x, adds execute for owner, group, and others—not just the owner. Option B, chmod 755, also grants execute to group and others. Option D is not valid; chown changes ownership, not permissions.
Question 4. A service named nginx fails to start. Which command shows the most recent log entries that explain the failure?
A. systemctl start nginx
B. journalctl -u nginx
C. cat /var/log/nginx/access.log
D. systemctl enable nginx
Answer: B. The journalctl -u nginx command filters the systemd journal to the nginx unit and shows its log entries. Option A attempts to start the service again without diagnosing the failure. Option C shows access logs, not error logs or service logs. Option D enables the service at boot; it does not show why it failed.
Question 5. A server can reach external IP addresses but cannot resolve hostnames. Which file should the administrator check first?
A. /etc/hosts
B. /etc/resolv.conf
C. /etc/nsswitch.conf
D. /etc/network/interfaces
Answer: B. The /etc/resolv.conf file lists the DNS servers the system queries. If it is missing or contains an incorrect nameserver entry, hostname resolution fails while IP connectivity works. Option A can override individual hostnames but is not the primary DNS configuration. Option C controls the order of name resolution sources but not the DNS server itself. Option D configures network interfaces, not DNS.
Question 6. An administrator needs to check whether a web server is listening on port 80. Which command shows this?
A. ping localhost
B. curl localhost:80
C. ss -tulpn | grep :80
D. ip addr show
Answer: C. The ss -tulpn command lists listening TCP and UDP sockets with their port numbers and owning processes. Grepping for :80 filters to port 80. Option A tests ICMP reachability, not port state. Option B attempts an HTTP request, which may fail for reasons other than the port not being open. Option D shows interface configuration, not listening ports.
Question 7. A system is slow, and the administrator suspects a memory-hungry process. Which command shows processes sorted by memory usage?
A. ps aux --sort=-%mem | head
B. df -h
C. iostat -x 1 5
D. systemctl status
Answer: A. The ps aux --sort=-%mem command sorts processes by memory usage in descending order. Piping to head shows the top consumers. Option B shows disk usage, not memory. Option C shows disk I/O statistics. Option D shows service states, not per-process resource usage.
Question 8. A backup archive was created last week. Before relying on it, the administrator wants to verify that it can be read. Which command checks the archive’s integrity without extracting it?
A. tar -xzf backup.tar.gz
B. tar -tzf backup.tar.gz > /dev/null && echo "OK"
C. ls -lh backup.tar.gz
D. rsync -av backup.tar.gz /backup/
Answer: B. The tar -tzf command lists the archive’s contents without extracting. If the archive is corrupt or truncated, the command returns an error. The && echo "OK" confirms success. Option A extracts the archive, which is a restore, not a verification. Option C shows the file size but not the archive’s readability. Option D copies the file but does not verify its contents.
Question 9. An administrator needs to schedule a backup script to run every day at 2:00 AM. Which method provides catch-up execution if the system was powered off at the scheduled time?
A. A cron job with the schedule 0 2 * * *
B. A systemd timer with OnCalendar=*-*-* 02:00:00 and Persistent=true
C. A shell script run manually
D. An entry in /etc/rc.local
Answer: B. A systemd timer with Persistent=true runs a missed job as soon as the system is available. Option A, cron, does not run missed jobs; if the system was off at 2:00 AM, the job does not run. Option C is not automated. Option D runs once at boot, not on a schedule.
Question 10. A server can ping its gateway but cannot reach an external website by hostname or IP. Which is the most likely layer of the problem?
A. The physical link
B. The local IP configuration
C. The routing or upstream network
D. DNS resolution
Answer: C. The gateway responds, so the local link and IP configuration are working. External IP addresses also fail, which rules out DNS—DNS failures produce hostname failures while IP addresses still work. The problem is beyond the gateway, in the routing or upstream network. Option A would prevent the gateway from responding. Option B would prevent the gateway from responding. Option D would not affect IP addresses.
Question 11. An administrator needs to change the owner and group of a file to jsmith and developers, respectively. Which command does this?
A. chmod jsmith:developers file.txt
B. chown jsmith:developers file.txt
C. chgrp jsmith:developers file.txt
D. usermod jsmith:developers file.txt
Answer: B. The chown user:group file command changes both the owner and the group. Option A is not valid; chmod changes permissions, not ownership. Option C changes only the group and does not accept a user:group syntax. Option D modifies a user account, not a file.
Question 12. A service is running, but a configuration change has been made and needs to be applied without stopping the service. Which command is appropriate?
A. systemctl stop nginx && systemctl start nginx
B. systemctl reload nginx
C. systemctl enable nginx
D. systemctl disable nginx
Answer: B. The systemctl reload nginx command applies configuration changes without stopping the service, if the service supports reloading. Option A stops the service, causing downtime. Option C enables the service at boot, which is unrelated to applying configuration. Option D disables the service at boot, which is also unrelated.
Question 13. An administrator needs to see the processes a specific user is running. Which command is most direct?
A. ps -u jsmith
B. df -h
C. free -h
D. ip addr show
Answer: A. The ps -u jsmith command lists processes owned by the user jsmith. Option B shows disk usage. Option C shows memory usage. Option D shows network interface configuration. None of these are process-related.
Question 14. A disk is reported as full, but df -h shows plenty of free space. Which command should the administrator run next?
A. du -sh /var/log/*
B. df -i
C. free -h
D. iostat -x 1 5
Answer: B. The df -i command shows inode usage. A filesystem can be completely full in inodes while still reporting free space in bytes, which produces “disk full” errors even though df -h shows space available. Option A shows directory sizes, which is useful but does not address the inode hypothesis. Option C shows memory. Option D shows disk I/O.
Question 15. An administrator needs to find all files in /var/log that were modified in the last 24 hours. Which command does this?
A. ls -la /var/log
B. find /var/log -mtime -1
C. grep -r "24 hours" /var/log
D. du -sh /var/log
Answer: B. The find /var/log -mtime -1 command finds files modified within the last day. The -mtime -1 expression matches files modified less than one day ago. Option A lists files but does not filter by time. Option C searches for text, not modification time. Option D shows directory sizes.
Question 16. A new service is installed but does not start automatically after a reboot. Which command fixes this?
A. systemctl start service
B. systemctl enable service
C. systemctl reload service
D. systemctl status service
Answer: B. The systemctl enable service command creates the symbolic links that cause the service to start automatically at boot. Option A starts the service now but does not affect boot behavior. Option C reloads configuration. Option D shows status but does not change it.
Question 17. An administrator needs to test whether a remote server is accepting connections on port 443. Which command is most appropriate?
A. ping server
B. nc -zv server 443
C. ip route show
D. dig server
Answer: B. The nc -zv server 443 command tests whether a TCP connection to port 443 can be established. Option A tests ICMP reachability, which does not indicate whether the port is open. Option C shows the local routing table. Option D resolves the hostname to an IP address.
Question 18. An administrator needs to check the current IP address and subnet mask of the eth0 interface. Which command shows this?
A. ip link show eth0
B. ip addr show eth0
C. ip route show
D. ss -tulpn
Answer: B. The ip addr show eth0 command displays the IP address and subnet mask assigned to the interface. Option A shows the link-layer state and MAC address but not the IP address. Option C shows the routing table. Option D shows listening ports.
Complete Example Session
# ============================================
# PART 1: USER MANAGEMENT
# ============================================
useradd -m -s /bin/bash jsmith → creates user with home and shell
usermod -aG developers jsmith → appends group membership
passwd jsmith → sets password
# ============================================
# PART 2: PERMISSIONS
# ============================================
chmod u+x deploy.sh → owner execute only
chown jsmith:developers file.txt → change owner and group
chmod 755 script.sh → rwxr-xr-x
# ============================================
# PART 3: SERVICES AND LOGS
# ============================================
systemctl status nginx → current state and recent logs
journalctl -u nginx → full service logs
systemctl enable nginx → start at boot
# ============================================
# PART 4: NETWORK DIAGNOSTICS
# ============================================
ip addr show → IP configuration
ip route show → routing table
ping -c 3 gateway → gateway reachability
dig example.com → DNS resolution
ss -tulpn | grep :80 → listening ports
nc -zv server 443 → port connectivity
# ============================================
# PART 5: RESOURCE CHECKS
# ============================================
ps aux --sort=-%mem | head → top memory consumers
free -h → memory and swap
df -h → disk space
df -i → inode usage
iostat -x 1 5 → disk I/O
# ============================================
# PART 6: BACKUP
# ============================================
tar -czpf backup.tar.gz /etc → create archive
tar -tzf backup.tar.gz > /dev/null → verify archive
rsync -avh /home/ /backup/home/ → mirror files
The six parts summarized the command patterns tested in Domain 1: user management, permissions, services and logs, network diagnostics, resource checks, and backup.
Quick Reference
User and Group Commands
| Task | Command |
|---|---|
| Create user with home | useradd -m -s /bin/bash user |
| Add to group | usermod -aG group user |
| Set password | passwd user |
| Delete user | userdel -r user |
| List groups | groups user |
Permission Commands
| Task | Command |
|---|---|
| Owner execute | chmod u+x file |
| Numeric 755 | chmod 755 file |
| Change owner | chown user:group file |
| Change group | chgrp group file |
Service and Log Commands
| Task | Command |
|---|---|
| Check status | systemctl status svc |
| Start service | systemctl start svc |
| Enable at boot | systemctl enable svc |
| Reload config | systemctl reload svc |
| Service logs | journalctl -u svc |
Network Commands
| Task | Command |
|---|---|
| IP address | ip addr show |
| Link state | ip link show |
| Routing table | ip route show |
| DNS lookup | dig domain |
| Listening ports | ss -tulpn |
| Port test | nc -zv host port |
Resource Commands
| Task | Command |
|---|---|
| Top memory | ps aux --sort=-%mem | head |
| Memory usage | free -h |
| Disk space | df -h |
| Inode usage | df -i |
| Disk I/O | iostat -x 1 5 |
Best Practices
✅ Do This:
# Check logs before restarting services
journalctl -u service # ✅
# Use -aG to append group membership
usermod -aG developers jsmith # ✅
# Use -m with useradd for home directory
useradd -m -s /bin/bash jsmith # ✅
# Check inodes when disk appears full
df -i # ✅
# Verify archive integrity before relying on it
tar -tzf backup.tar.gz > /dev/null # ✅
# Test port connectivity with nc
nc -zv server 443 # ✅
❌ Don’t Do This:
# Don't use -G alone for group membership
usermod -G developers jsmith → replaces groups # ❌
# Don't restart without checking logs
systemctl restart service → destroys evidence # ❌
# Don't use chmod for ownership
chmod jsmith:developers file → wrong command # ❌
# Don't assume ICMP works when TCP fails
ping server → may be blocked while ports are open # ⚠️
# Don't skip the restore drill
# (untested backups are hopes) # ❌
Common Pitfalls
| Pitfall | Why It Happens | Fix |
|---|---|---|
usermod -G removes groups | Missing -a | Use -aG |
| No home directory | Missing -m | Use useradd -m |
| Service does not start at boot | Not enabled | systemctl enable |
| Disk full but space free | Inode exhaustion | Check df -i |
| Port appears closed | Service not listening | Check ss -tulpn |
| Archive corrupt | Never verified | Check tar -tzf |
Real-World Examples
1. Create User
useradd -m -s /bin/bash jsmith
passwd jsmith
2. Add to Group
usermod -aG developers jsmith
groups jsmith
3. Set Permissions
chmod u+x deploy.sh
chown jsmith:developers file.txt
4. Check Service
systemctl status nginx
journalctl -u nginx -n 20
5. Network Diagnostics
ip addr show
ip route show
ping -c 3 8.8.8.8
dig example.com
6. Port Check
ss -tulpn | grep :443
nc -zv server 443
7. Memory Check
free -h
ps aux --sort=-%mem | head
8. Disk Check
df -h
df -i
du -sh /var/log/* | sort -rh | head
9. Backup Archive
tar -czpf backup.tar.gz /etc
tar -tzf backup.tar.gz > /dev/null && echo "OK"
10. Schedule Backup
# systemd timer with Persistent=true
OnCalendar=*-*-* 02:00:00
Persistent=true
Visual
Question Distribution by Subtopic
┌─────────────────────────────────────────────────────────────┐
│ DOMAIN 1 SUBTOPICS (18 questions) │
│ │
│ User management ████████ 4 questions │
│ Permissions ██████ 3 questions │
│ Services and logs ██████ 3 questions │
│ Network diagnostics ████████ 4 questions │
│ Resources ████ 2 questions │
│ Backup ████ 2 questions │
│ │
└─────────────────────────────────────────────────────────────┘
Answer Patterns
┌─────────────────────────────────────────────────────────────┐
│ TYPES OF CORRECT ANSWERS │
│ │
│ The command that gathers information first │
│ (journalctl, ss, df -i, ip addr) │
│ │
│ The command that matches the precise flag │
│ (-aG vs -G, -m, u+x) │
│ │
│ The command that follows the layered model │
│ (check lower layer before higher) │
│ │
│ The command that verifies rather than assumes │
│ (tar -tzf, nc -zv, systemctl status) │
│ │
│ Distractors are real commands that do the wrong thing. │
│ │
└─────────────────────────────────────────────────────────────┘
Command Selection Map
┌─────────────────────────────────────────────────────────────┐
│ SCENARIO → COMMAND │
│ │
│ Create user with home → useradd -m -s /bin/bash │
│ Add to group → usermod -aG │
│ Owner execute → chmod u+x │
│ Change owner → chown user:group │
│ Service failed → journalctl -u │
│ Start at boot → systemctl enable │
│ IP address → ip addr show │
│ DNS failure → dig + cat /etc/resolv.conf │
│ Port open → ss -tulpn + nc -zv │
│ Memory hog → ps aux --sort=-%mem │
│ Disk full → df -h + df -i │
│ Backup verify → tar -tzf │
│ │
└─────────────────────────────────────────────────────────────┘
Summary
| Topic | Key Command | Common Distractor |
|---|---|---|
| User creation | useradd -m -s /bin/bash | useradd without -m |
| Group membership | usermod -aG | usermod -G |
| Owner execute | chmod u+x | chmod +x, chmod 755 |
| Change owner | chown user:group | chmod, chgrp |
| Service logs | journalctl -u | access.log |
| Start at boot | systemctl enable | systemctl start |
| DNS check | /etc/resolv.conf | /etc/hosts |
| Listening ports | ss -tulpn | ping, ip addr |
| Memory usage | ps aux --sort=-%mem | df, iostat |
| Inode check | df -i | df -h |
| Port test | nc -zv | ping |
| Archive verify | tar -tzf | tar -xzf |
Key takeaways:
- The correct answer is usually the one that gathers information before acting. When a service fails, check the logs before restarting. When a port is unreachable, test it before assuming the cause. The LFCA rewards the methodical approach.
- Flag precision matters.
usermod -aGappends groups;usermod -Greplaces them.useradd -mcreates the home directory;useraddwithout-mdoes not.chmod u+xadds owner execute;chmod +xadds it for everyone. The exam tests the distinction. - Network diagnostics follow the layered model. Check the interface, then the IP, then the gateway, then DNS, then the port, then the service. A question that says “the gateway responds but external IPs fail” is pointing at the routing layer, not the link layer or DNS.
- Verification is a distinct step. Checking that a backup exists is not the same as checking that it can be read. Checking that a service is running is not the same as checking that it is listening on the expected port. The exam tests whether you verify.
- The commands in Domain 1 are the commands you use daily.
useradd,usermod,chmod,chown,systemctl,journalctl,ip,ping,dig,ss,nc,ps,df,tar,rsync. If you have used them, the questions are straightforward. If you have only read about them, practice in a shell.
Remember: The LFCA is an entry-level exam, and Domain 1 tests practical system administration. The questions describe scenarios you will encounter on a real system: a user who needs an account, a service that failed, a network that does not work, a disk that is full, a backup that needs verification. The correct answer is the command or action that moves the investigation forward without skipping steps. Practice the commands, understand the flags, and the reasoning becomes intuitive.
Stop using slow, ad-bloated tool sites! 🤮
🔎 Search “KandZ Tools” on Google to use many professional utilities for free.
KandZ.me is the ultimate minimalist hub for:
✅ Finance (Mortgage, Interest, Inflation)
✅ Tech (Base64, JSON, Dev Suite, IP)
✅ Health (BMI, BMR, TDEE)
✅ Productivity (Timer, Workspace, QR)
⚡️ Fast & Private
🔒 No data leaves your device
💎 100% Free
🔗 Use it now: https://tools.kandz.me
🔖 Bookmark it—you’ll need it later!