RHCSA sample questions with answers
10 free RHCSA sample questions across the exam's domains, each with its answer and an explanation. No account needed.
RHCSA sample questions
Red Hat Certified System Administrator (RHCSA), Red Hat.
Question 1
Domain: Understand and use essential tools
What is the difference between
su - aliceandsu alice?- `su - alice` does not ask for a password; `su alice` always asks for alice's password first
- `su - alice` runs a single command as alice and returns; `su alice` opens an interactive shell
- `su - alice` starts a login shell with alice's environment; `su alice` keeps most of the caller's
- `su - alice` switches to root first and then to alice; `su alice` switches to alice directly
Show the answer
Answer: C. `su - alice` starts a login shell with alice's environment; `su alice` keeps most of the caller's
The `-` (same as `-l` or `--login`) makes su start a login shell, resetting the environment and changing to the target user's home directory as if they had logged in. Password prompting is identical in both forms; it depends on who runs su, not on the dash.
Checked against: https://man7.org/linux/man-pages/man1/su.1.html
Question 2
Domain: Manage software
A repository file has gpgcheck=1. Installing a package from it fails because the public key for the package signature is not installed. Company policy forbids installing unsigned or unverified packages.
Which action fixes the error while keeping signature verification?
- Import the vendor's public key with `rpm --import` and run the installation again
- Run `dnf install --nogpgcheck` for this package and keep gpgcheck=1 for the others
- Run `dnf clean all` to delete the cached metadata and keys, then retry the install
- Set enabled=0 and install the package with `rpm -ivh` directly from the repository
Show the answer
Answer: A. Import the vendor's public key with `rpm --import` and run the installation again
The error means the package is signed with a key that is not in the RPM database; importing the key (directly or through gpgkey=) lets DNF verify the signature. `--nogpgcheck` would make the install succeed, but only by skipping the very verification the policy requires.
Checked against: https://rpm.org/docs/latest/man/rpmkeys.8
Question 3
Domain: Create simple shell scripts
A script contains
name=""followed byif [ -n $name ]; then echo set; fi, and it prints 'set'.Why does the then-branch run?
- `-n` tests whether the variable is defined, and name is defined even though it is empty
- `[` treats every empty string as true, so -n must be combined with -z
- The variable is exported, and exported variables always have a length greater than zero
- The unquoted empty variable disappears, leaving `[ -n ]`, and a one-argument test is true because '-n' is a non-empty string
Show the answer
Answer: D. The unquoted empty variable disappears, leaving `[ -n ]`, and a one-argument test is true because '-n' is a non-empty string
After word splitting, `[ -n $name ]` with an empty name becomes `[ -n ]`; with a single argument test returns true if that argument is non-null, and '-n' is non-null. Quoting the variable as `[ -n "$name" ]` keeps an empty argument and gives the expected false result.
Checked against: https://www.gnu.org/software/bash/manual/bash.html#index-test
Question 4
Domain: Operate running systems
A colleague ran
shutdown -r +30 "Kernel update", but the maintenance window has been postponed.Which command cancels the pending shutdown?
- systemctl reboot --cancel
- shutdown -c
- atrm shutdown
- shutdown -h now
Show the answer
Answer: B. shutdown -c
`shutdown -c` cancels a shutdown that was scheduled with a time argument. Scheduled shutdowns are not at jobs, so atrm cannot remove them, and `shutdown -h now` would do the opposite of what you want.
Question 5
Domain: Configure local storage
An XFS file system was created with
mkfs.xfs -L appdata /dev/vgdata/lvapp.Which /etc/fstab line mounts the file system at /app by its label at boot?
- /app LABEL=appdata xfs defaults 0 0
- LABEL=appdata /app xfs defaults 0 0
- UUID=appdata /app xfs defaults 0 0
- label:appdata /app xfs defaults 0 0
Show the answer
Answer: B. LABEL=appdata /app xfs defaults 0 0
The first fstab field identifies the device and accepts LABEL=<label> or UUID=<uuid>; the second field is the mount point. UUID= expects the file system's UUID, not its label, so that entry would never match a device.
Checked against: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/managing_file_systems/persistently-mounting-file-systems
Question 6
Domain: Create and configure file systems
You created /etc/auto.master.d/nfs.conf containing
/nfs /etc/auto.nfsand a valid /etc/auto.nfs map, then restarted autofs. Accessing /nfs/data does nothing.Why does nothing mount?
- The nfs-server service must be running on the client before autofs can mount any share
- The mount point /nfs must be listed in /etc/fstab with the noauto option first
- autofs reads map files only after a reboot, so the configuration is correct but pending
- Files in /etc/auto.master.d must end in .autofs; rename it to nfs.autofs and restart autofs
Show the answer
Answer: D. Files in /etc/auto.master.d must end in .autofs; rename it to nfs.autofs and restart autofs
The default auto.master includes the directory /etc/auto.master.d, and only files whose names end in .autofs are read from it. An autofs client needs nfs-utils, not a running NFS server, and autofs mount points must not also be listed in /etc/fstab.
Checked against: https://man7.org/linux/man-pages/man5/auto.master.5.html
Question 7
Domain: Deploy, configure, and maintain systems
Which crontab entry runs /usr/local/bin/backup.sh at 02:30 on Monday through Friday?
- 30 2 * * 1-5 /usr/local/bin/backup.sh
- 2 30 * * 1-5 /usr/local/bin/backup.sh
- 30 2 1-5 * * /usr/local/bin/backup.sh
- 30 2 * 1-5 * /usr/local/bin/backup.sh
Show the answer
Answer: A. 30 2 * * 1-5 /usr/local/bin/backup.sh
The five time fields are minute, hour, day of month, month and day of week, and days 1-5 in the last field are Monday to Friday. Putting 1-5 in the third field means the 1st to the 5th day of each month instead.
Checked against: https://man7.org/linux/man-pages/man5/crontab.5.html
Question 8
Domain: Manage basic networking
You ran
nmcli connection modify eth0 ipv4.method manual ipv4.addresses 192.0.2.10/24 ipv4.gateway 192.0.2.1over the console.ip address show eth0still shows the old DHCP address.Why is the old address still in use, and what fixes it?
- NetworkManager ignores ipv4.addresses unless ipv4.method is also set to auto
- The address is applied only after `systemctl restart network` is run as root
- The profile changed on disk only; reactivate it with `nmcli connection up eth0`
- Static addresses need the keyfile deleted so the profile is written again
Show the answer
Answer: C. The profile changed on disk only; reactivate it with `nmcli connection up eth0`
`nmcli connection modify` updates the saved profile, but a device keeps its current settings until the profile is activated again, for example with `nmcli connection up`. RHEL 10 has no network service; NetworkManager manages the connections.
Checked against: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/configuring_and_managing_networking/configuring-an-ethernet-connection
Question 9
Domain: Manage users and groups
alice is already a member of the wheel and finance groups.
Which command adds alice to devops without removing her from her other supplementary groups?
- usermod -G devops alice
- usermod -aG devops alice
- usermod --gid devops alice
- groupmod -G devops alice
Show the answer
Answer: B. usermod -aG devops alice
`-G` sets the list of supplementary groups and `-a` appends to it instead of replacing it. Without `-a`, alice would be removed from every supplementary group not listed; `-g` (`--gid`) changes her primary group instead.
Checked against: https://man7.org/linux/man-pages/man8/usermod.8.html
Question 10
Domain: Manage security
A developer created index.html in their home directory and moved it into /var/www/html with mv. httpd returns 403 Forbidden, and
ls -Zshows the file labelled user_home_t.Which command fixes the problem?
- chcon -R -t user_home_t /var/www/html
- semanage fcontext -d '/var/www/html(/.*)?'
- restorecon -Rv /var/www/html
- setenforce 0 && systemctl restart httpd
Show the answer
Answer: C. restorecon -Rv /var/www/html
mv preserves the file's existing label, so the moved files keep user_home_t, which httpd may not read; restorecon resets them to the policy default for that path, httpd_sys_content_t. Setting permissive mode hides the symptom and removes protection instead of fixing the labels.
Checked against: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/using_selinux/troubleshooting-problems-related-to-selinux
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
RHCSA course and practice exam: Red Hat Certified System Administrator (EX200): the exam guide, with the format, cost, pass mark and domains from the vendor.