RHCSA sample questions with answers

10 free RHCSA sample questions across the exam's domains, each with its answer and an explanation. No account needed.

RHCSA sample questions

Red Hat Certified System Administrator (RHCSA), Red Hat.

  1. Question 1

    Domain: Understand and use essential tools

    What is the difference between su - alice and su alice?

    1. `su - alice` does not ask for a password; `su alice` always asks for alice's password first
    2. `su - alice` runs a single command as alice and returns; `su alice` opens an interactive shell
    3. `su - alice` starts a login shell with alice's environment; `su alice` keeps most of the caller's
    4. `su - alice` switches to root first and then to alice; `su alice` switches to alice directly
    Show the answer

    Answer: C. `su - alice` starts a login shell with alice's environment; `su alice` keeps most of the caller's

    The `-` (same as `-l` or `--login`) makes su start a login shell, resetting the environment and changing to the target user's home directory as if they had logged in. Password prompting is identical in both forms; it depends on who runs su, not on the dash.

    Checked against: https://man7.org/linux/man-pages/man1/su.1.html

  2. Question 2

    Domain: Manage software

    A repository file has gpgcheck=1. Installing a package from it fails because the public key for the package signature is not installed. Company policy forbids installing unsigned or unverified packages.

    Which action fixes the error while keeping signature verification?

    1. Import the vendor's public key with `rpm --import` and run the installation again
    2. Run `dnf install --nogpgcheck` for this package and keep gpgcheck=1 for the others
    3. Run `dnf clean all` to delete the cached metadata and keys, then retry the install
    4. Set enabled=0 and install the package with `rpm -ivh` directly from the repository
    Show the answer

    Answer: A. Import the vendor's public key with `rpm --import` and run the installation again

    The error means the package is signed with a key that is not in the RPM database; importing the key (directly or through gpgkey=) lets DNF verify the signature. `--nogpgcheck` would make the install succeed, but only by skipping the very verification the policy requires.

    Checked against: https://rpm.org/docs/latest/man/rpmkeys.8

  3. Question 3

    Domain: Create simple shell scripts

    A script contains name="" followed by if [ -n $name ]; then echo set; fi, and it prints 'set'.

    Why does the then-branch run?

    1. `-n` tests whether the variable is defined, and name is defined even though it is empty
    2. `[` treats every empty string as true, so -n must be combined with -z
    3. The variable is exported, and exported variables always have a length greater than zero
    4. The unquoted empty variable disappears, leaving `[ -n ]`, and a one-argument test is true because '-n' is a non-empty string
    Show the answer

    Answer: D. The unquoted empty variable disappears, leaving `[ -n ]`, and a one-argument test is true because '-n' is a non-empty string

    After word splitting, `[ -n $name ]` with an empty name becomes `[ -n ]`; with a single argument test returns true if that argument is non-null, and '-n' is non-null. Quoting the variable as `[ -n "$name" ]` keeps an empty argument and gives the expected false result.

    Checked against: https://www.gnu.org/software/bash/manual/bash.html#index-test

  4. Question 4

    Domain: Operate running systems

    A colleague ran shutdown -r +30 "Kernel update", but the maintenance window has been postponed.

    Which command cancels the pending shutdown?

    1. systemctl reboot --cancel
    2. shutdown -c
    3. atrm shutdown
    4. shutdown -h now
    Show the answer

    Answer: B. shutdown -c

    `shutdown -c` cancels a shutdown that was scheduled with a time argument. Scheduled shutdowns are not at jobs, so atrm cannot remove them, and `shutdown -h now` would do the opposite of what you want.

    Checked against: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/using_systemd_unit_files_to_customize_and_optimize_your_system/shutting-down-suspending-and-hibernating-the-system

  5. Question 5

    Domain: Configure local storage

    An XFS file system was created with mkfs.xfs -L appdata /dev/vgdata/lvapp.

    Which /etc/fstab line mounts the file system at /app by its label at boot?

    1. /app LABEL=appdata xfs defaults 0 0
    2. LABEL=appdata /app xfs defaults 0 0
    3. UUID=appdata /app xfs defaults 0 0
    4. label:appdata /app xfs defaults 0 0
    Show the answer

    Answer: B. LABEL=appdata /app xfs defaults 0 0

    The first fstab field identifies the device and accepts LABEL=<label> or UUID=<uuid>; the second field is the mount point. UUID= expects the file system's UUID, not its label, so that entry would never match a device.

    Checked against: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/managing_file_systems/persistently-mounting-file-systems

  6. Question 6

    Domain: Create and configure file systems

    You created /etc/auto.master.d/nfs.conf containing /nfs /etc/auto.nfs and a valid /etc/auto.nfs map, then restarted autofs. Accessing /nfs/data does nothing.

    Why does nothing mount?

    1. The nfs-server service must be running on the client before autofs can mount any share
    2. The mount point /nfs must be listed in /etc/fstab with the noauto option first
    3. autofs reads map files only after a reboot, so the configuration is correct but pending
    4. Files in /etc/auto.master.d must end in .autofs; rename it to nfs.autofs and restart autofs
    Show the answer

    Answer: D. Files in /etc/auto.master.d must end in .autofs; rename it to nfs.autofs and restart autofs

    The default auto.master includes the directory /etc/auto.master.d, and only files whose names end in .autofs are read from it. An autofs client needs nfs-utils, not a running NFS server, and autofs mount points must not also be listed in /etc/fstab.

    Checked against: https://man7.org/linux/man-pages/man5/auto.master.5.html

  7. Question 7

    Domain: Deploy, configure, and maintain systems

    Which crontab entry runs /usr/local/bin/backup.sh at 02:30 on Monday through Friday?

    1. 30 2 * * 1-5 /usr/local/bin/backup.sh
    2. 2 30 * * 1-5 /usr/local/bin/backup.sh
    3. 30 2 1-5 * * /usr/local/bin/backup.sh
    4. 30 2 * 1-5 * /usr/local/bin/backup.sh
    Show the answer

    Answer: A. 30 2 * * 1-5 /usr/local/bin/backup.sh

    The five time fields are minute, hour, day of month, month and day of week, and days 1-5 in the last field are Monday to Friday. Putting 1-5 in the third field means the 1st to the 5th day of each month instead.

    Checked against: https://man7.org/linux/man-pages/man5/crontab.5.html

  8. Question 8

    Domain: Manage basic networking

    You ran nmcli connection modify eth0 ipv4.method manual ipv4.addresses 192.0.2.10/24 ipv4.gateway 192.0.2.1 over the console. ip address show eth0 still shows the old DHCP address.

    Why is the old address still in use, and what fixes it?

    1. NetworkManager ignores ipv4.addresses unless ipv4.method is also set to auto
    2. The address is applied only after `systemctl restart network` is run as root
    3. The profile changed on disk only; reactivate it with `nmcli connection up eth0`
    4. Static addresses need the keyfile deleted so the profile is written again
    Show the answer

    Answer: C. The profile changed on disk only; reactivate it with `nmcli connection up eth0`

    `nmcli connection modify` updates the saved profile, but a device keeps its current settings until the profile is activated again, for example with `nmcli connection up`. RHEL 10 has no network service; NetworkManager manages the connections.

    Checked against: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/configuring_and_managing_networking/configuring-an-ethernet-connection

  9. Question 9

    Domain: Manage users and groups

    alice is already a member of the wheel and finance groups.

    Which command adds alice to devops without removing her from her other supplementary groups?

    1. usermod -G devops alice
    2. usermod -aG devops alice
    3. usermod --gid devops alice
    4. groupmod -G devops alice
    Show the answer

    Answer: B. usermod -aG devops alice

    `-G` sets the list of supplementary groups and `-a` appends to it instead of replacing it. Without `-a`, alice would be removed from every supplementary group not listed; `-g` (`--gid`) changes her primary group instead.

    Checked against: https://man7.org/linux/man-pages/man8/usermod.8.html

  10. Question 10

    Domain: Manage security

    A developer created index.html in their home directory and moved it into /var/www/html with mv. httpd returns 403 Forbidden, and ls -Z shows the file labelled user_home_t.

    Which command fixes the problem?

    1. chcon -R -t user_home_t /var/www/html
    2. semanage fcontext -d '/var/www/html(/.*)?'
    3. restorecon -Rv /var/www/html
    4. setenforce 0 && systemctl restart httpd
    Show the answer

    Answer: C. restorecon -Rv /var/www/html

    mv preserves the file's existing label, so the moved files keep user_home_t, which httpd may not read; restorecon resets them to the policy default for that path, httpd_sys_content_t. Setting permissive mode hides the symptom and removes protection instead of fixing the labels.

    Checked against: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/using_selinux/troubleshooting-problems-related-to-selinux

More practice

A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.

RHCSA course and practice exam: Red Hat Certified System Administrator (EX200): the exam guide, with the format, cost, pass mark and domains from the vendor.