Reviewed 10 October 2026 against the linked published scope. Performance exam based on RHEL 10. Practice on disposable RHEL systems; memorising descriptions alone is insufficient.
Memory hook: Make it work now, make it persist, reboot and prove both.
Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.
Shell, software and running systems
- Verify identity and path with
id,pwdandls -labefore modification. Quote paths/variables; understand glob expansion.>replaces output,>>appends,2>redirects errors and|pipes stdout. Order matters when combining descriptors. grep,find,sort,cut,head,tailand text editors locate/transform data. A hard link references the same inode; a symbolic link stores a pathname and can dangle. Useman,infoand packaged documentation to check exact syntax.- Shell scripts need correct interpreter, inputs, quoting, tests, branches, loops and exit status.
$1is the first argument;$?is the prior command's exit status. Test both success and failure paths. - RPM queries/verifies packages; DNF resolves repositories/dependencies. Configure trusted repositories before installing. Flatpak uses remotes, applications and runtimes; distinguish per-user from system-wide installation scope.
systemctl startchanges current service state;enableconfigures boot activation;enable --nowdoes both. Inspect status andjournalctl -u NAME -bbefore changing files. Configure journal persistence when required.- Use
ps,top,free,vmstatanddfto locate the actual resource constraint.nice/reniceadjust scheduling priority under privilege rules; tuned profiles apply supported system tuning. Killing a process is not a durable service fix.
Identity, permissions and security
- Manage users/groups and supplementary membership deliberately.
usermod -aGappends memberships; omitting-awith-Gcan replace them.chagegoverns password aging; use authorized sudo configuration for privilege. - File rwx and directory rwx have different effects: directory execute allows traversal, read lists names and write changes directory entries. Ownership, group, mode and applicable ACLs combine with mount/security policy.
- A setgid directory helps inherit its group; sticky bit restricts deletion in suitable shared directories. Umask removes default permissions from creation modes; it does not rewrite existing files.
- SELinux is an independent control layer. Inspect
getenforce,ls -Z,ps -Zand relevant logs. Persistent file-context rules plusrestoreconfix labels;chconalone may not survive relabeling. Manage required port types and booleans rather than disabling enforcement. - SSH uses client private keys and server authorized public keys. Protect ownership/modes and verify authentication before removing an alternate access path.
scp/sftptransfer through SSH.
Storage, networking and boot persistence
- Inspect
lsblk -f,blkid,findmnt,pvs,vgsandlvs. LVM layers PV → VG → LV → filesystem → mount. Extending an LV and growing its filesystem are distinct operations; do not format an existing data filesystem during expansion. - XFS grows mounted and cannot shrink; ext4 has different supported procedures. Create appropriate VFAT/ext4/XFS only on the intended new target. Prefer stable UUID/label references in
/etc/fstab; validate before reboot. - Swap needs initialization, activation and persistence. NFS requires export, network and client configuration; autofs mounts on demand through configured maps. Inspect mount state and permissions from the intended user.
- NetworkManager profiles preserve IPv4/IPv6, gateway and DNS settings. Inspect
nmcli,ip address,ip routeand name resolution. A temporaryipcommand does not replace persistent configuration. - firewalld runtime and permanent rules differ. Assign the right zone/interface and permitted service/port, reload appropriately and test from a client. Opening a port does not start a listener.
systemctl get-default/set-defaultconcern boot targets; isolate changes current target. Follow supported bootloader/recovery procedures and ensure SELinux labeling remains valid after recovery.- Cron schedules repeating work, at one-time work and systemd timers service activation. Check user/environment, logs and persistence. Chrony maintains time; inspect sources/tracking.
Practical finish
- Check exact requested state, ownership, access, service health and reboot behavior. A correct-looking file that is ignored by the system does not satisfy the task.
- RHEL 10 is the published EX200 target here. Do not substitute an older container-heavy outline for the current software/Flatpak and administration objectives.
Final active recall
1. Does systemctl start guarantee activation after reboot?
No. Enablement is a separate setting.
2. SELinux blocks a service despite permissive Unix modes. Disable SELinux?
No. Diagnose labels, port types, booleans and policy, then apply the appropriate persistent fix.
3. What can usermod -G without -a do?
Replace supplementary group memberships instead of adding to them.
4. Can XFS be shrunk?
No. Plan storage changes accordingly.
5. What is the strongest final check of persistent administration tasks?
Reboot the practice system, then verify mounts, networking, services, security and required behavior.
Sources and further practice
- Official exam scope
- Objective-to-topic coverage map. Each full topic links to its supporting primary technical documentation.
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Shell Tools and Scripts
Memory hook: Quote paths; check status; know where output goes.
Must remember
pwd, ls -la, cd, mkdir, cp, mv and rm manipulate the filesystem. Quote expansions such as "$path" so spaces and wildcard characters are not interpreted unexpectedly. man, info and /usr/share/doc are local references; use man -k to find a topic.
| Syntax | Meaning |
|---|---|
command >file / >>file |
Replace / append standard output. |
2>errors |
Redirect standard error. |
>out 2>&1 |
Send both streams to out; order matters. |
| `a | b` |
| `grep -E '^(error | warn)' file` |
tar -czf backup.tar.gz directory |
Archive and gzip; list with tar -tf before extracting with -xf. |
Gzip and bzip2 compress streams; tar bundles files and metadata. A hard link is another name for the same inode on the same filesystem; a symbolic link stores a path and may cross filesystems or become dangling. ln source hard and ln -s target soft differ accordingly.
Scripts need an interpreter line and execute permission when run directly. $1 is the first argument, $? the previous exit status; zero conventionally means success. $(command) captures output. A simple pattern:
#!/bin/bash
if [ -f "$1" ]; then
for word in ready set go; do
printf '%s\n' "$word"
done
else
printf '%s\n' 'File not found' >&2
exit 1
fi
Use ssh user@host for a remote shell and su - user for a login-like user environment. Edit with a terminal editor and verify the saved content; an unsaved editor buffer is not configuration.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Find matching text | grep with the appropriate basic or extended expression. |
| Preserve file identity under another name | Hard link, provided both names can share a filesystem. |
| Capture output in a script | Command substitution, with quoted use of the result. |
Traps
- A pipe does not automatically include stderr.
- A symlink does not keep its target alive after the target is removed.
02 · Users, Permissions and SELinux
Memory hook: Identity, mode bits and labels must all agree.
Must remember
useradd,usermod,userdel,groupaddandgroupmodmanage local accounts.id USERverifies identity and supplementary groups;getent passwd USERrespects configured identity sources. Useusermod -aGto append group membership; omitting-acan replace existing supplementary groups.passwdchanges passwords andchage -l USERinspects aging. Locking a password does not necessarily revoke SSH keys or existing sessions. Usesudofor delegated privilege; edit sudoers throughvisudoto check syntax.- For a regular file, r/w/x mean read/change/execute. For a directory, they mean list names/change entries/traverse. Deleting a file depends mainly on its parent directory permissions, with sticky-bit rules when present.
chmod 640 filegives owner rw, group r, others none.chown user:group filechanges ownership. Setgid on a shared directory helps new files inherit its group; sticky limits removal of other users' entries.umaskremoves default permission bits; it does not add execute permission to ordinary newly created files.- SELinux adds mandatory policy checks beyond Unix permissions. Enforcing blocks prohibited actions; permissive records denials without enforcing them. Inspect
getenforce,ls -Z,ps -eZand audit messages. restoreconrestores configured labels.semanage fcontextdefines persistent path-label rules;chconalone may be overwritten by relabeling.semanage portmaps a nonstandard service port to its allowed type.getseboolinspects booleans;setsebool -Ppersists a supported policy toggle.
Practical drill: create a shared directory for a group, then explain why a web service still needs the correct SELinux type even when Unix permissions allow reading.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Group-shared directory | Correct group ownership, directory permissions and setgid where needed. |
| Service denied despite mode bits | Inspect SELinux labels and AVC denials. |
| Permanent label for a custom web path | Define an fcontext rule, then apply restorecon. |
Traps
- Do not solve a labeling error by disabling SELinux.
- chmod 777 does not bypass SELinux and usually grants excessive access.
03 · Software, Services and Logs
Memory hook: Installed is not running; running is not enabled.
Must remember
RPM is the package format/database; rpm -q checks installed packages and rpm -V verifies recorded file properties. DNF resolves dependencies and repository metadata. dnf repolist, dnf info, dnf install, dnf remove and dnf upgrade serve different jobs. Repository definitions normally live under /etc/yum.repos.d/; understand base URLs, enabled flags and signature checking.
Flatpak applications use remotes, application IDs and runtimes. flatpak remotes, flatpak search, flatpak list, flatpak install and flatpak uninstall manage this separate ecosystem. User installations and system installations differ; the account and scope must match the task.
systemctl start affects the present; enable configures boot activation. enable --now does both. disable does not automatically stop a running service; mask prevents activation via its normal unit path. Use status, is-active, is-enabled and list-units to verify. After editing a unit or drop-in, run daemon-reload before restarting the service.
journalctl -u SERVICE -b narrows logs to one service and boot; journalctl -b -1 reads the previous boot when retained. Persistent journaling requires appropriate journal storage configuration and a persistent journal directory; otherwise reboot may discard useful evidence. Traditional logs under /var/log remain relevant.
Use ps, top, free, vmstat and df to separate CPU, memory and storage pressure. kill -TERM requests graceful termination; SIGKILL cannot be handled for cleanup. A higher nice value means lower scheduling priority. nice starts with an adjustment; renice changes one. Inspect tuned-adm active and available profiles before selecting a workload-specific tuning profile.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Service must survive reboot | Enable it and verify its boot behavior. |
| Find startup failure | Service status plus its boot journal. |
| Install an application from a Flatpak remote | Use Flatpak in the requested user/system scope, not DNF. |
Traps
- Masking is stronger than disabling.
- Installing a package does not prove its daemon is configured or listening.
04 · Storage, Filesystems and Persistent Mounts
Memory hook: Disk to PV to VG to LV to filesystem to mount.
Must remember
Inspect before modifying: lsblk -f, blkid, findmnt, pvs, vgs and lvs reveal the device graph. A partition table such as GPT divides a disk; creating or formatting the wrong device destroys data. Practice only on disposable disks.
LVM layers physical volumes into a volume group, then allocates logical volumes. pvcreate, vgcreate/vgextend and lvcreate operate at those layers. Extending the LV alone does not necessarily grow the filesystem. lvextend -r can resize the supported filesystem as well; understand the underlying operation and available free extents.
XFS can grow while mounted and cannot shrink. ext4 supports growth and can shrink while unmounted with the correct sequence. Never shrink an LV below its filesystem. VFAT suits compatibility but lacks normal Unix ownership/permission semantics; mount options supply effective access behavior.
An ephemeral mount command does not survive reboot. /etc/fstab records source, mountpoint, filesystem type, options, dump and fsck fields. UUIDs or filesystem labels avoid unstable device-name assumptions. Test a change with findmnt --verify and an appropriate mount check before reboot; a bad required mount can interrupt boot.
Swap can use a suitable partition or LV: initialise it with mkswap, activate with swapon, verify with swapon --show, and configure persistence. Do not reinitialise a device containing useful data.
For NFS, match server export, network access and client mount options. autofs uses maps to mount paths on demand and expire idle mounts; verify by accessing the trigger path, not only looking at an idle mount table. Ownership IDs and permissions still matter on shared storage.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Add capacity without deleting data | Extend the correct LVM layers and filesystem after inspection. |
| Mount after reboot | Use a tested fstab entry with a stable source identifier. |
| Mount NFS only when used | Configure autofs maps and test path access. |
Traps
- XFS does not support shrinking.
- A mounted directory can hide existing files beneath the mountpoint without deleting them.
05 · Networking, SSH and Firewalls
Memory hook: Address, route, name, socket, policy.
Must remember
Diagnose in layers. ip -br address shows addresses; ip route/ip -6 route show routes; getent hosts NAME tests configured name resolution; ss -lntup identifies listening sockets. A successful ping does not prove a TCP service works.
NetworkManager connection profiles preserve settings. nmcli connection show lists profiles; nmcli device status shows devices. Know how to set IPv4/IPv6 addresses, prefix, gateway, DNS and automatic activation on the intended profile, then activate and verify it. A temporary ip address add is not a persistent profile. A hostname can be set with hostnamectl; /etc/hosts and DNS resolve names through configured lookup order.
firewalld assigns connections/interfaces to zones. Services bundle ports; explicit port rules name port and protocol. Runtime changes affect now; --permanent changes saved configuration and needs a reload to become runtime state. A reload can discard unsaved runtime rules. Check --get-active-zones, --list-all and both runtime/permanent settings for the correct zone.
SSH key authentication uses a private key on the client and a public key in the server account's authorized keys. Protect ownership and modes of the home directory, .ssh and authorized_keys; SELinux labels also matter. Validate daemon syntax with sshd -t before a controlled reload. Keep a recovery session when changing remote connectivity in a practice VM.
scp and sftp transfer data through SSH. Confirm source/destination syntax and preserve the correct owner and labels afterward. A running service, enabled boot unit, listening address, firewall rule and valid authentication are independent checks.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Persistent static addressing | Modify and activate the NetworkManager profile. |
| Port works until reboot | Check saved firewalld and service activation settings. |
| Host resolves but connection fails | Check routes, listener address, firewall and authentication. |
Traps
- Opening a firewall port does not make an application listen.
- A rule in the wrong zone may have no effect on the intended interface.
06 · Boot, Scheduled Work and Recovery
Memory hook: Make it work now, at boot and after failure.
Must remember
systemd targets group units. get-default inspects the default boot target; set-default changes future boots; isolate transitions the running system and can stop unrelated services. Know multi-user, graphical, rescue and emergency behavior rather than treating every target as a simple runlevel synonym.
The bootloader loads a kernel and initial RAM filesystem before the real root filesystem is mounted. For authorised recovery on a disposable RHEL VM, practise interrupting boot, editing kernel arguments, entering the supported recovery environment, remounting the necessary root filesystem writable and changing the intended configuration. Password recovery may require a chroot and subsequent SELinux relabel. Firmware, bootloader passwords or encrypted storage can change the process: do not memorise one sequence as universal.
Use grubby to inspect or manage supported kernel arguments and keep boot configuration consistent with the system's bootloader layout. A working current boot is not proof that changed boot arguments will work next time.
at schedules a one-time job; inspect pending jobs with atq. cron repeats using minute, hour, day-of-month, month and day-of-week fields. User crontabs and system crontabs differ because system entries include the execution user. Jobs run with a limited environment; use absolute paths and handle output.
systemd timers activate service units using calendar or monotonic timing. systemctl list-timers verifies scheduling. Persistent calendar timers can catch a missed run when configured accordingly. Enable the timer, not merely the one-shot service.
chrony synchronises time; inspect chronyc sources and chronyc tracking. The daemon running is not proof of synchronisation. Correct time supports authentication, certificates and trustworthy logs.
Practical finish: verify changes, reboot the practice VM, then retest mounts, network access, services, SELinux and scheduled work. Persistent results are part of EX200 preparation.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| One-off future task | at; verify the queue and execution user. |
| Service-integrated scheduled task | A systemd timer activating a service. |
| Wrong time despite running daemon | Inspect selected time source, reachability and tracking status. |
Traps
- set-default does not immediately isolate the running system.
- An enabled timer with a broken service command still fails its job.