certslothcertsloth
← EX294 overview

Ansible Advanced Administration — RHCE Path / STUDY TOOLS

EX294 quick review

Red Hat’s current page names EX294 Advanced System Administrator in Ansible, although its URL retains the older RHCE wording. The Engineer credential has additional pathway requirements. Product versions can differ by booking: the public objectives target the newest offered version, so verify your selected RHEL/AAP environment before practicing. Notes are not permitted exam reference material.

Reviewed 10 October 2026 against the linked published scope. Practical exam: write playbooks that work on fresh systems and survive reboot. Current Red Hat naming is Advanced System Administrator in Ansible; EX200 plus EX294 forms the published RHCE in Ansible path.

Memory hook: Correct inventory + repeatable playbooks + verified persistent system state.

Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.

Environment, inventory and execution

  • EX294 builds on RHCSA administration. Be able to diagnose the target system as well as write YAML; successful automation of the wrong state is still incorrect.
  • Inventory defines hosts/groups and associated variables. Inspect effective targeting with inventory tools and --list-hosts; avoid an accidental all-host run. Host aliases and connection addresses are separate concepts.
  • Ansible configuration selection prefers explicit ANSIBLE_CONFIG, then an eligible project file, home configuration and system configuration. Inspect effective settings rather than assuming the file you edited is used.
  • Execution environments package the runtime, collections and dependencies. ansible-navigator.yml, image selection, project paths and mounted credentials influence execution. Use the environment/version specified in the booked exam.
  • Managed nodes need the relevant transport, credentials, privilege and usually Python for normal Linux modules. Ansible's ping module tests module connectivity, not an ICMP ping. become grants supported escalation; it does not repair missing SSH access.

Playbooks, variables and control flow

  • A play selects hosts and tasks; tasks invoke modules. Prefer state-aware modules over shell commands. Use fully qualified collection names to make resolution explicit.
  • Variables have defined precedence: role defaults are deliberately easy to override, and explicit extra variables have very high precedence. Facts describe discovered host state; registered variables capture task results. Do not guess precedence from file order.
  • Loops repeat tasks over items; when evaluates a condition. Quote Jinja expressions when YAML requires it, and distinguish booleans, strings and undefined values. A registered loop result contains per-item results.
  • Handlers run when notified by changed tasks and are normally deduplicated for their execution point. meta: flush_handlers can run pending handlers earlier. Correct change reporting controls whether dependent restarts happen.
  • changed_when and failed_when interpret results; they do not make an arbitrary command idempotent. Blocks group tasks, rescue handles eligible failures and always supports cleanup. Unreachable-host behavior is not identical to an ordinary failed task.
  • Use bounded retries with until for readiness. Do not hide all failures with ignore_errors. --check and --diff help inspect supported modules but cannot guarantee every future change; protect secret-bearing diffs.

Reuse and administration

  • Roles organize tasks, handlers, defaults, vars, files, templates and metadata. Collections package modules/plugins/roles under namespaces. Pin/install required content and use ansible-doc or navigator documentation for arguments and return values.
  • Static imports are processed differently from dynamic includes, affecting loops, conditions, tags and task visibility. Select deliberately; neither is a substitute for a clear interface.
  • copy transfers static files; template renders Jinja with variables/facts. Validate configuration before replacing a critical file where the module/service supports it. Notify the correct service handler only when content changes.
  • Automate package/repository, service state/enablement, users/groups, storage/mounts, networking, firewalls and SELinux with supported modules/system roles. Respect dependencies and avoid formatting existing data unintentionally.
  • Ansible Vault encrypts secrets at rest. It does not automatically hide decrypted module arguments, debug output or copied files; use appropriate no_log, permissions and secret handling.
  • Git records intended project changes; inspect status/diff, stage relevant files, commit and push when required. VS Code aids authoring but does not replace effective runtime validation.

Practical finish and traps

  • Verify syntax and inventory; run through the specified environment; inspect recap; independently test the service and persistent system state. Run again to evaluate convergence without unnecessary changes.
  • A recap with zero failures does not prove the correct hosts, permissions, data or reboot behavior.
  • The current EX294 title/pathway differs from older RHCE shorthand; check the booking's product version and credential requirements.

Final active recall

1. A task always reports changed. Why can that matter?

It can repeatedly notify handlers and cause unnecessary restarts, hiding lack of idempotence.

2. Does Vault automatically prevent debug output leaking a secret?

No. Decrypted runtime data still needs logging and permission controls.

3. What should you verify before a broad playbook run?

Effective inventory, host limit, configuration, execution environment, credentials and intended diff.

4. Why use a template instead of copy?

When file content must be rendered from host/group variables or facts.

5. What follows a clean Ansible recap?

Independent checks of the requested end state, service behavior, repeatability and reboot persistence.

Sources and further practice

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Inventory, Configuration and Execution Environments

Memory hook: Know the targets, settings and runtime before the first task.

Must remember

An inventory identifies managed hosts and groups. Static INI or YAML inventories can assign connection information and group membership; group_vars and host_vars separate data from tasks. A host in multiple groups still represents one host, and conflicting variable definitions require deliberate precedence. Use host patterns and limits to select only the intended systems.

Ansible loads the first applicable configuration file in its search order: an explicit ANSIBLE_CONFIG, a suitable current-directory file, a home file, then the system file. Environment variables and other configuration categories can override settings. Do not assume all configuration files are merged. Inspect effective configuration and inventory rather than guessing from a file you edited.

An execution environment packages Ansible runtime, collections and dependencies in a container image. ansible-navigator.yml configures navigator behavior such as the chosen execution environment and execution options. The controller filesystem, mounted project directory and container filesystem are distinct; a collection installed only on the host may not exist inside the selected environment.

Use ansible-inventory --graph or the appropriate navigator inventory view to inspect targets. --list-hosts shows which hosts a play targets without configuring them. Confirm group names, inventory path, remote user and environment before execution. A syntactically valid empty inventory can produce a successful-looking run that configured nothing.

Version the intended project configuration and collection requirements, excluding secrets and transient artifacts. Prefer an explicit reproducible runtime over relying on whatever packages happen to be installed on a workstation.

Choose under exam pressure

Requirement Choice and reason
Select a subset for a controlled run Inventory group/pattern plus an intentional limit.
Find why a setting is ignored Inspect the loaded configuration and effective overrides.
Ensure consistent dependencies A specified execution environment and collection requirements.

Traps

  • Editing an unused ansible.cfg changes nothing.
  • Host-installed collections are not automatically available in a containerized runtime.

Practise this topic

02 · Connectivity, Privilege and Safe Execution

Memory hook: Connection proves access; become proves authority; state proves success.

Must remember

Managed Linux nodes normally need reachable SSH, an authorized user and a suitable Python interpreter for most modules. SSH keys authenticate access; host-key verification establishes the server identity. Configure keys and ownership/modes deliberately. Do not solve an authentication problem by broadly disabling trust checks.

Privilege escalation uses become and related settings. The SSH connection user and become user can differ. A successful SSH login does not prove sudo authorization; a successful unprivileged fact gathering task does not prove a package install can run. Use the supplied credentials and required escalation method without exposing them in inventory or logs.

ansible.builtin.ping tests Ansible connectivity and Python/module execution; it is not ICMP ping. Distinguish unreachable hosts from task failures. Diagnose name resolution, network path, SSH authentication, interpreter availability and privilege in that order where appropriate.

Run playbooks through the specified ansible-playbook or ansible-navigator environment. Syntax checking validates structure, not business correctness. Check mode predicts changes for supported modules; skipped/unsupported tasks and registered results can limit its accuracy. Tasks explicitly disabling check mode may still execute. Diff mode can reveal sensitive file content, so scope it carefully.

Read the recap: ok, changed, failed and unreachable describe execution outcomes, not complete service validation. Re-run to inspect idempotence, verify service behavior and confirm persistence after reboot on a disposable practice system. A playbook intended for fresh machines must create its prerequisites rather than rely on manual setup left over from yesterday.

Choose under exam pressure

Requirement Choice and reason
SSH works but package tasks fail Check become/sudo and package/repository prerequisites.
Preview supported changes Check mode, understanding its limits.
Prove application availability An explicit functional check after configuration.

Traps

  • Ansible ping is not ICMP.
  • Check mode is not a universal guarantee that every task is simulated.

Practise this topic

03 · Plays, Variables, Facts and Loops

Memory hook: Describe the state once, parameterize the differences.

Must remember

A play selects hosts and applies tasks; a playbook is an ordered list of plays. Each task invokes a module with arguments. Use fully qualified collection names to identify the intended module. YAML indentation and list/mapping structure matter; quote a value that begins with a Jinja expression and quote file modes such as '0640' to avoid type surprises.

Prefer state-aware modules over shell commands. package, user, file and service modules can reason about existing state. command avoids shell interpretation; shell enables features such as pipelines but increases quoting and injection concerns. Use a shell only when its features are actually required.

Variables come from multiple scopes with defined precedence. Role defaults are intended to be easy to override; extra variables supplied with -e have very high variable precedence. Facts describe discovered host properties. A registered result records a task's return structure for that host, such as return code, stdout or changed state. Inspect the structure instead of guessing a field.

Loops repeat a task over items. With a registered loop, results are commonly a list of per-item outcomes; do not treat the aggregate as one simple stdout. Use meaningful loop variable names for nested reuse. Conditions use expressions, normally without wrapping the entire condition in Jinja delimiters.

Keep host-specific data in inventory variables and reusable logic in tasks/roles. Validate required values with assertions before changing systems. Avoid hard-coding a distribution version, device name or username when the requirement calls for inventory-driven behavior.

Choose under exam pressure

Requirement Choice and reason
Install a package only if absent A package module with the intended state.
Use a command result later register, then inspect the returned fields.
Apply the same user definition to several users A loop over structured data.

Traps

  • A registered loop result is not the same shape as one task result.
  • Using shell for everything discards useful state awareness.

Practise this topic

04 · Handlers, Failure Paths and Idempotence

Memory hook: A change should trigger only the work it requires.

Must remember

Handlers run when notified by changed tasks, typically at defined handler execution points. Multiple notifications normally coalesce for a handler rather than restarting a service for every changed line. A template task can notify a service restart after a valid configuration is deployed. Handler names/listen topics must match the intended notification.

changed_when defines when a task reports change; failed_when defines failure criteria. Use them to reflect real semantics, not to hide errors. A command returning zero can still leave the wrong state, while a documented nonzero result may represent an expected condition. If change reporting is wrong, notifications and idempotence checks become misleading.

Blocks group related tasks; rescue handles supported task failures and always runs cleanup according to Ansible's error rules. Unreachable hosts and invalid task definitions do not behave like every normal failed task. ignore_errors continues after certain failures but does not repair the underlying problem or handle every failure class.

Use retries with an until condition for transient readiness, including bounded delay and attempts. A fixed sleep waits without checking whether the service became ready. Control rollout batches with serial where availability requires it, and consider how failure thresholds affect remaining hosts.

Idempotence means repeated execution converges on the desired state without unnecessary changes. Verify a second run, but remember zero reported changes is not proof of correctness if conditions skipped everything. Confirm service behavior, security settings and reboot persistence independently. Translate imperative scripts into modules and guarded operations rather than copying each shell line into a task.

Choose under exam pressure

Requirement Choice and reason
Restart only when configuration changes Notify a handler from the changed task.
Wait for a service to become ready Bounded retries with a real condition.
Limit hosts affected at once A deliberate serial rollout and failure policy.

Traps

  • changed_when: false can hide real changes and prevent needed handlers.
  • Ignoring an error does not make the desired state true.

Practise this topic

05 · Roles, Collections and Documentation

Memory hook: A role organizes intent; a collection distributes content.

Must remember

A role organizes tasks, handlers, defaults, variables, templates, files and metadata into a reusable structure. Defaults expose override-friendly settings; role variables have different precedence and should not casually lock consumers out of configuration. Keep a role focused on a clear responsibility and document its inputs and dependencies.

A collection packages related modules, plugins, roles and other content under a namespace/name. Install the required collection version into a path visible to the execution environment. A module available in the controller's Python environment may not exist inside navigator's selected container.

Use ansible-galaxy and a requirements file for supported role/collection installation. Pin or constrain versions according to the environment, then inspect their documentation. Offline exam environments may supply content or repositories; practice finding and using those rather than relying on an internet download.

ansible-doc and navigator documentation views show module arguments, defaults, examples and return values. Confirm whether a module is in ansible.builtin, ansible.posix, community.general or a vendor/system-role collection. A short module name can hide a dependency or select an unintended implementation.

Static imports and dynamic includes differ in when content is processed, affecting conditions, loops, tags and task visibility. Understand the chosen pattern instead of interchanging them blindly. Test a role in isolation and as part of the full play, including repeated execution and multiple hosts with different variable values.

Choose under exam pressure

Requirement Choice and reason
Share a reusable configuration responsibility A role with documented defaults and inputs.
Distribute modules plus related roles A collection.
Unsure about a module parameter Installed documentation for the actual runtime version.

Traps

  • Installing a collection on the host does not necessarily install it in an execution environment.
  • Role defaults and role vars do not have the same override behavior.

Practise this topic

06 · Automating Packages, Services, Storage and Networking

Memory hook: Configure the dependency chain, then verify the service.

Must remember

Package tasks depend on usable repositories, trust/signing configuration and network access. Use the appropriate package/repository module and an explicit intended state. latest means potentially changing on future runs; present ensures installation without promising the newest package. Follow the requirement rather than applying one state everywhere.

Service state and boot enablement are separate. A service can be running now but disabled for the next boot. Firewall configuration similarly distinguishes runtime and persistent changes in relevant modules. Verify the listening application, local firewall and external reachability instead of stopping at a successful service task.

Storage automation follows devices, partitions, volume groups/logical volumes, filesystems and mounts in the correct order. Discover/validate the target device before any destructive operation. Creating a filesystem on the wrong device destroys data; shrinking is not equivalent to extending, and filesystem support differs. Use a disposable practice environment for storage exercises.

Persistent mounts need correct filesystem identity, mount path, options and boot behavior. A directory existing does not prove the filesystem is mounted. Verify with appropriate read-only system tools and after reboot. SELinux contexts and firewall permissions can still prevent a correctly mounted service directory from being usable.

Use supported system roles or network modules for repeatable network configuration, understanding connection disruption. Template only the required configuration and validate before replacing it. Archive/unarchive tasks distinguish source location and destination behavior. Scheduled jobs need the correct user, environment and idempotent entry identity.

Choose under exam pressure

Requirement Choice and reason
Run a service now and after reboot Set both started and enabled state.
Persist a new filesystem mount Create prerequisites and manage the persistent mount definition.
Deploy a repeated scheduled task A supported scheduling module with stable identity and correct user.

Traps

  • Running now does not mean enabled at boot.
  • A successful storage task can still target the wrong device if discovery was wrong.

Practise this topic

07 · Templates, Accounts, SELinux and Vault

Memory hook: Render the right file, enforce the right access, protect the secret.

Must remember

copy transfers static content; template renders Jinja using variables and facts. Quote and validate input data, set ownership/mode deliberately and use supported validation before replacing a critical configuration file. A configuration template should produce stable output when inputs have not changed.

Use user/group modules to manage identity state. Distinguish a user's primary group from supplementary groups; replacing the full supplementary group list can remove required access if append behavior was intended. Password values must use the form expected by the target module/system. SSH authorized keys need correct identity, path and file permissions.

Unix ownership/modes and SELinux policy are separate controls. Restore the appropriate labels and define persistent file-context mappings where needed; a one-time label change may not survive relabeling. Use supported SELinux booleans or policy configuration for the actual service need instead of disabling enforcement to hide a denial.

Ansible Vault encrypts sensitive variable files or values at rest. Supply the correct vault identity/password through an approved mechanism and keep that password separate from the encrypted content. Vault does not automatically protect decrypted values in logs, templates, temporary files or destination systems. Use no_log where needed while retaining enough nonsecret evidence to diagnose failures. Ansible debugging can still expose sensitive data; do not assume no_log protects every debug path.

Review rendered files and diffs for accidental secret exposure. File mode should fit the consuming process and least privilege. Backups of old configurations can contain secrets too. Re-keying Vault changes its encryption credential; rotating a real application password is a separate operation that also requires updating consumers safely.

Choose under exam pressure

Requirement Choice and reason
Host-specific configuration file Template with validated variables and controlled permissions.
Encrypted variables in source control Vault plus separately protected decryption credentials.
Service denied despite correct Unix permissions Inspect SELinux contexts/booleans and audit evidence.

Traps

  • Vault encryption does not redact every runtime use of a value.
  • Disabling SELinux does not fix the intended policy configuration.

Practise this topic

08 · Git, VS Code and Practical Exam Verification

Memory hook: Save the automation, prove the result, then prove repeatability.

Must remember

Use Git to clone the supplied project, inspect status/diffs, stage intended files, commit and push to the required repository when the task calls for it. A local commit is not a remote push. Exclude Vault passwords, private keys, execution artifacts and other secrets; encrypting one variable file does not make every project file safe to commit.

VS Code and the Ansible extension support editing, navigation and diagnostics. A development container can provide a repeatable Ansible toolchain. Confirm workspace mounts, SSH/authentication forwarding, collection availability and selected execution environment; editor syntax coloring does not prove navigator will use the same runtime.

Run navigator commands from the intended project directory and inspect its effective settings. Use installed module documentation and examples appropriate to the booked runtime. Product versions and collection availability can differ from the newest public web documentation, so do not memorize unsupported options from a newer release.

Translate the requested end state into independent checks: target hosts, package versions, configuration contents, ownership/mode, users/groups, mounted storage, listening service, firewall behavior and reboot persistence. Run against a clean baseline, then rerun to detect unnecessary changes. A playbook that only works because you manually created a directory is incomplete.

Budget time for diagnosis and verification. Fix the smallest root cause, rerun the affected scope and then confirm the overall requirement. Preserve required project files in the specified location. Practical performance is earned by correct persistent systems and reusable playbooks, not by a large number of green tasks or memorized command lists.

Choose under exam pressure

Requirement Choice and reason
Editor works but navigator cannot find content Compare container/runtime paths, mounts and installed collections.
Requirement must survive restart Verify enabled/persistent configuration and a practice reboot.
Playbook fails on a fresh node Find the missing prerequisite instead of manually patching only that node.

Traps

  • A green syntax check cannot prove the system meets the task.
  • A committed playbook is not necessarily pushed or saved in the required location.

Practise this topic

09 · Shell Tools and Scripts

Memory hook: Quote paths; check status; know where output goes.

Must remember

pwd, ls -la, cd, mkdir, cp, mv and rm manipulate the filesystem. Quote expansions such as "$path" so spaces and wildcard characters are not interpreted unexpectedly. man, info and /usr/share/doc are local references; use man -k to find a topic.

Syntax Meaning
command >file / >>file Replace / append standard output.
2>errors Redirect standard error.
>out 2>&1 Send both streams to out; order matters.
`a b`
`grep -E '^(error warn)' file`
tar -czf backup.tar.gz directory Archive and gzip; list with tar -tf before extracting with -xf.

Gzip and bzip2 compress streams; tar bundles files and metadata. A hard link is another name for the same inode on the same filesystem; a symbolic link stores a path and may cross filesystems or become dangling. ln source hard and ln -s target soft differ accordingly.

Scripts need an interpreter line and execute permission when run directly. $1 is the first argument, $? the previous exit status; zero conventionally means success. $(command) captures output. A simple pattern:

#!/bin/bash
if [ -f "$1" ]; then
  for word in ready set go; do
    printf '%s\n' "$word"
  done
else
  printf '%s\n' 'File not found' >&2
  exit 1
fi

Use ssh user@host for a remote shell and su - user for a login-like user environment. Edit with a terminal editor and verify the saved content; an unsaved editor buffer is not configuration.

Choose under exam pressure

Requirement Choice and reason
Find matching text grep with the appropriate basic or extended expression.
Preserve file identity under another name Hard link, provided both names can share a filesystem.
Capture output in a script Command substitution, with quoted use of the result.

Traps

  • A pipe does not automatically include stderr.
  • A symlink does not keep its target alive after the target is removed.

Practise this topic

10 · Users, Permissions and SELinux

Memory hook: Identity, mode bits and labels must all agree.

Must remember

  • useradd, usermod, userdel, groupadd and groupmod manage local accounts. id USER verifies identity and supplementary groups; getent passwd USER respects configured identity sources. Use usermod -aG to append group membership; omitting -a can replace existing supplementary groups.
  • passwd changes passwords and chage -l USER inspects aging. Locking a password does not necessarily revoke SSH keys or existing sessions. Use sudo for delegated privilege; edit sudoers through visudo to check syntax.
  • For a regular file, r/w/x mean read/change/execute. For a directory, they mean list names/change entries/traverse. Deleting a file depends mainly on its parent directory permissions, with sticky-bit rules when present.
  • chmod 640 file gives owner rw, group r, others none. chown user:group file changes ownership. Setgid on a shared directory helps new files inherit its group; sticky limits removal of other users' entries. umask removes default permission bits; it does not add execute permission to ordinary newly created files.
  • SELinux adds mandatory policy checks beyond Unix permissions. Enforcing blocks prohibited actions; permissive records denials without enforcing them. Inspect getenforce, ls -Z, ps -eZ and audit messages.
  • restorecon restores configured labels. semanage fcontext defines persistent path-label rules; chcon alone may be overwritten by relabeling. semanage port maps a nonstandard service port to its allowed type. getsebool inspects booleans; setsebool -P persists a supported policy toggle.

Practical drill: create a shared directory for a group, then explain why a web service still needs the correct SELinux type even when Unix permissions allow reading.

Choose under exam pressure

Requirement Choice and reason
Group-shared directory Correct group ownership, directory permissions and setgid where needed.
Service denied despite mode bits Inspect SELinux labels and AVC denials.
Permanent label for a custom web path Define an fcontext rule, then apply restorecon.

Traps

  • Do not solve a labeling error by disabling SELinux.
  • chmod 777 does not bypass SELinux and usually grants excessive access.

Practise this topic

11 · Software, Services and Logs

Memory hook: Installed is not running; running is not enabled.

Must remember

RPM is the package format/database; rpm -q checks installed packages and rpm -V verifies recorded file properties. DNF resolves dependencies and repository metadata. dnf repolist, dnf info, dnf install, dnf remove and dnf upgrade serve different jobs. Repository definitions normally live under /etc/yum.repos.d/; understand base URLs, enabled flags and signature checking.

Flatpak applications use remotes, application IDs and runtimes. flatpak remotes, flatpak search, flatpak list, flatpak install and flatpak uninstall manage this separate ecosystem. User installations and system installations differ; the account and scope must match the task.

systemctl start affects the present; enable configures boot activation. enable --now does both. disable does not automatically stop a running service; mask prevents activation via its normal unit path. Use status, is-active, is-enabled and list-units to verify. After editing a unit or drop-in, run daemon-reload before restarting the service.

journalctl -u SERVICE -b narrows logs to one service and boot; journalctl -b -1 reads the previous boot when retained. Persistent journaling requires appropriate journal storage configuration and a persistent journal directory; otherwise reboot may discard useful evidence. Traditional logs under /var/log remain relevant.

Use ps, top, free, vmstat and df to separate CPU, memory and storage pressure. kill -TERM requests graceful termination; SIGKILL cannot be handled for cleanup. A higher nice value means lower scheduling priority. nice starts with an adjustment; renice changes one. Inspect tuned-adm active and available profiles before selecting a workload-specific tuning profile.

Choose under exam pressure

Requirement Choice and reason
Service must survive reboot Enable it and verify its boot behavior.
Find startup failure Service status plus its boot journal.
Install an application from a Flatpak remote Use Flatpak in the requested user/system scope, not DNF.

Traps

  • Masking is stronger than disabling.
  • Installing a package does not prove its daemon is configured or listening.

Practise this topic

12 · Storage, Filesystems and Persistent Mounts

Memory hook: Disk to PV to VG to LV to filesystem to mount.

Must remember

Inspect before modifying: lsblk -f, blkid, findmnt, pvs, vgs and lvs reveal the device graph. A partition table such as GPT divides a disk; creating or formatting the wrong device destroys data. Practice only on disposable disks.

LVM layers physical volumes into a volume group, then allocates logical volumes. pvcreate, vgcreate/vgextend and lvcreate operate at those layers. Extending the LV alone does not necessarily grow the filesystem. lvextend -r can resize the supported filesystem as well; understand the underlying operation and available free extents.

XFS can grow while mounted and cannot shrink. ext4 supports growth and can shrink while unmounted with the correct sequence. Never shrink an LV below its filesystem. VFAT suits compatibility but lacks normal Unix ownership/permission semantics; mount options supply effective access behavior.

An ephemeral mount command does not survive reboot. /etc/fstab records source, mountpoint, filesystem type, options, dump and fsck fields. UUIDs or filesystem labels avoid unstable device-name assumptions. Test a change with findmnt --verify and an appropriate mount check before reboot; a bad required mount can interrupt boot.

Swap can use a suitable partition or LV: initialise it with mkswap, activate with swapon, verify with swapon --show, and configure persistence. Do not reinitialise a device containing useful data.

For NFS, match server export, network access and client mount options. autofs uses maps to mount paths on demand and expire idle mounts; verify by accessing the trigger path, not only looking at an idle mount table. Ownership IDs and permissions still matter on shared storage.

Choose under exam pressure

Requirement Choice and reason
Add capacity without deleting data Extend the correct LVM layers and filesystem after inspection.
Mount after reboot Use a tested fstab entry with a stable source identifier.
Mount NFS only when used Configure autofs maps and test path access.

Traps

  • XFS does not support shrinking.
  • A mounted directory can hide existing files beneath the mountpoint without deleting them.

Practise this topic

13 · Networking, SSH and Firewalls

Memory hook: Address, route, name, socket, policy.

Must remember

Diagnose in layers. ip -br address shows addresses; ip route/ip -6 route show routes; getent hosts NAME tests configured name resolution; ss -lntup identifies listening sockets. A successful ping does not prove a TCP service works.

NetworkManager connection profiles preserve settings. nmcli connection show lists profiles; nmcli device status shows devices. Know how to set IPv4/IPv6 addresses, prefix, gateway, DNS and automatic activation on the intended profile, then activate and verify it. A temporary ip address add is not a persistent profile. A hostname can be set with hostnamectl; /etc/hosts and DNS resolve names through configured lookup order.

firewalld assigns connections/interfaces to zones. Services bundle ports; explicit port rules name port and protocol. Runtime changes affect now; --permanent changes saved configuration and needs a reload to become runtime state. A reload can discard unsaved runtime rules. Check --get-active-zones, --list-all and both runtime/permanent settings for the correct zone.

SSH key authentication uses a private key on the client and a public key in the server account's authorized keys. Protect ownership and modes of the home directory, .ssh and authorized_keys; SELinux labels also matter. Validate daemon syntax with sshd -t before a controlled reload. Keep a recovery session when changing remote connectivity in a practice VM.

scp and sftp transfer data through SSH. Confirm source/destination syntax and preserve the correct owner and labels afterward. A running service, enabled boot unit, listening address, firewall rule and valid authentication are independent checks.

Choose under exam pressure

Requirement Choice and reason
Persistent static addressing Modify and activate the NetworkManager profile.
Port works until reboot Check saved firewalld and service activation settings.
Host resolves but connection fails Check routes, listener address, firewall and authentication.

Traps

  • Opening a firewall port does not make an application listen.
  • A rule in the wrong zone may have no effect on the intended interface.

Practise this topic

14 · Boot, Scheduled Work and Recovery

Memory hook: Make it work now, at boot and after failure.

Must remember

systemd targets group units. get-default inspects the default boot target; set-default changes future boots; isolate transitions the running system and can stop unrelated services. Know multi-user, graphical, rescue and emergency behavior rather than treating every target as a simple runlevel synonym.

The bootloader loads a kernel and initial RAM filesystem before the real root filesystem is mounted. For authorised recovery on a disposable RHEL VM, practise interrupting boot, editing kernel arguments, entering the supported recovery environment, remounting the necessary root filesystem writable and changing the intended configuration. Password recovery may require a chroot and subsequent SELinux relabel. Firmware, bootloader passwords or encrypted storage can change the process: do not memorise one sequence as universal.

Use grubby to inspect or manage supported kernel arguments and keep boot configuration consistent with the system's bootloader layout. A working current boot is not proof that changed boot arguments will work next time.

at schedules a one-time job; inspect pending jobs with atq. cron repeats using minute, hour, day-of-month, month and day-of-week fields. User crontabs and system crontabs differ because system entries include the execution user. Jobs run with a limited environment; use absolute paths and handle output.

systemd timers activate service units using calendar or monotonic timing. systemctl list-timers verifies scheduling. Persistent calendar timers can catch a missed run when configured accordingly. Enable the timer, not merely the one-shot service.

chrony synchronises time; inspect chronyc sources and chronyc tracking. The daemon running is not proof of synchronisation. Correct time supports authentication, certificates and trustworthy logs.

Practical finish: verify changes, reboot the practice VM, then retest mounts, network access, services, SELinux and scheduled work. Persistent results are part of EX200 preparation.

Choose under exam pressure

Requirement Choice and reason
One-off future task at; verify the queue and execution user.
Service-integrated scheduled task A systemd timer activating a service.
Wrong time despite running daemon Inspect selected time source, reachability and tracking status.

Traps

  • set-default does not immediately isolate the running system.
  • An enabled timer with a broken service command still fails its job.

Practise this topic

Search across every published topic.