Question Bank - Version 2.0 a well detailed practice
exam 2025/2026 graded A+ well written !!!
Advanced Multiple-Choice Questions Covering
RHCSA, RHCE, RHCA, OpenShift, Ansible
Automation, and Enterprise Linux Administration
(150 Questions)
PART 1: RHCSA — System Administration and Management (Questions 1–35)
Section 1.1: Essential Tools and Commands (Q1–Q10)
Question 1
A system administrator needs to copy a directory structure from /source to /backup while
preserving all permissions, ownership, timestamps, and also copying symbolic links as links (not
their targets). Which command should be used?
A) cp -rp /source /backup
B) cp -a /source /backup
C) rsync -av /source /backup
D) Both B and C are correct
Correct Answer: D
Rationale: cp -a (archive mode) preserves permissions, ownership, timestamps, and copies
symlinks as symlinks. rsync -av (archive + verbose) also preserves these attributes and copies
symlinks. cp -rp is similar but -a is more comprehensive (includes -d and --preserve=all). Both B
and C are correct.
,Question 2
Which command finds all files in /home that are owned by the user jdoe and have the SUID bit
set?
A) find /home -user jdoe -perm -4000
B) find /home -uid jdoe -perm /4000
C) find /home -user jdoe -perm /4000
D) find /home -user jdoe -type f -perm /4000
Correct Answer: C
Rationale: find /home -user jdoe -perm /4000 finds files owned by jdoe with SUID bit set. -perm
/4000 matches any file with SUID set. Option A uses -perm -4000 which matches exact
permissions including other bits, not just SUID. Option B uses -uid but jdoe is a username, not a
numeric UID. Option D adds -type f but is not strictly necessary and is otherwise correct, but C is
the simplest and correct.
Question 3
Which of the following correctly displays the last 15 lines of a log file and then follows new
entries, but only shows lines containing the word "error"?
A) tail -n 15 -f /var/log/messages | grep error
B) tail -n 15 -f /var/log/messages | grep --line-buffered error
C) tail -f /var/log/messages | grep -E "error" -m 15
D) tail -f /var/log/messages | grep error followed by tail -n 15 separately
Correct Answer: B
Rationale: tail -f produces output that may be buffered; grep needs --line-buffered to ensure
immediate output when following a file. Option A would work but may have buffering issues.
Option B is the proper way. Option C uses -m 15 which limits matches, not lines. Option D is not
a single command.
Question 4
What is the difference between kill and kill -9 when terminating a process?
,A) kill sends SIGTERM (graceful termination); kill -9 sends SIGKILL (immediate termination)
B) kill sends SIGKILL; kill -9 sends SIGTERM
C) Both send the same signal
D) kill only works for foreground processes; kill -9 works for all processes
Correct Answer: A
Rationale: kill (without signal number) sends SIGTERM (signal 15), which allows the process to
clean up resources. kill -9 sends SIGKILL (signal 9), which forcefully terminates the process
without cleanup. SIGKILL cannot be caught or ignored. Option D is incorrect.
Question 5
Which command can be used to securely transfer files between two RHEL systems using port
2222 and preserving file permissions?
A) scp -P 2222 -p file user@host:/path/
B) scp -p -P 2222 file user@host:/path/
C) rsync -e "ssh -p 2222" -av file user@host:/path/
D) All of the above
Correct Answer: D
Rationale: scp -P 2222 -p file... uses port 2222 and preserves permissions (-p). scp options order
does not matter. rsync -e "ssh -p 2222" -av also works with SSH on custom port and preserves
attributes (-a). All are valid.
Question 6
Which file in /etc defines the system-wide environment variables for all users' login shells?
A) /etc/profile
B) /etc/bashrc
C) /etc/environment
D) /etc/login.defs
Correct Answer: A
Rationale: /etc/profile is the system-wide initialization file for login shells. /etc/bashrc is for
non-login interactive shells. /etc/environment is used by some systems (like pam_env) but not
standard for bash on RHEL. /etc/login.defs is for user account defaults.
, Question 7
A user is unable to delete a file they own because the parent directory has the sticky bit set.
What is the purpose of the sticky bit on a directory?
A) Allows only the file owner, directory owner, or root to delete or rename files within the
directory
B) Prevents anyone from deleting files in the directory
C) Allows any user to delete files as long as they have write permission on the directory
D) Locks the directory to prevent new file creation
Correct Answer: A
Rationale: The sticky bit (mode 1000) on a directory restricts file deletion and renaming to the
file owner, directory owner, or root, even if others have write permission on the directory. This
is common in /tmp. Option B is too strict; users can still delete their own files. Option C is the
behavior without sticky bit. Option D is incorrect.
Question 8
Which command displays the current runlevel or systemd target?
A) runlevel
B) systemctl get-default
C) who -r
D) All of the above
Correct Answer: D
Rationale: runlevel shows the previous and current runlevel (legacy). systemctl get-
default shows the default target. who -r displays the current runlevel. All provide runlevel/target
information.
Question 9
What is the purpose of the umask command?
A) Sets the default file and directory permissions for newly created files
B) Sets the maximum file size for a user