Free LPIC-1 101-500 Exam Flashcards
Memorize 50 essential terms and definitions for the LPIC-1 Linux Administrator — Exam 101 (101-500). See the term, recall the definition, then flip to check yourself.
lspci vs. lsusb vs. lsmod
lspci lists PCI bus devices, lsusb lists USB devices, and lsmod lists currently loaded kernel modules. They query different hardware/kernel layers — don't mistake a USB or module problem for a PCI one.
Filter by Topic
Jump to Card
About These LPIC-1 101-500 Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the LPIC-1 Linux Administrator — Exam 101 (101-500). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
lspci vs. lsusb vs. lsmod
lspci lists PCI bus devices, lsusb lists USB devices, and lsmod lists currently loaded kernel modules. They query different hardware/kernel layers — don't mistake a USB or module problem for a PCI one.
/proc vs. /sys — what's the difference?
/proc is a virtual filesystem exposing kernel and per-process runtime info (e.g. /proc/cpuinfo, /proc/<pid>). /sys (sysfs) exposes kernel objects for devices and drivers, tied to udev, and is the modern place to inspect and tune hardware.
What is the Linux boot sequence order?
Firmware (BIOS or UEFI) initializes hardware and hands off to the bootloader, which loads the kernel and initramfs. The kernel then starts init (SysVinit or systemd), which brings the system to its target runlevel.
dmesg vs. journalctl -b
dmesg prints the kernel ring buffer: kernel messages only, held in memory and lost at reboot. journalctl -b shows the systemd journal (kernel plus service messages) for the current boot; journalctl -b -1 shows the previous boot, which works only when the journal is stored persistently.
Map systemd targets to SysVinit runlevels
Runlevel 1 maps to rescue.target (single-user maintenance), runlevels 2, 3, and 4 all map to multi-user.target (multi-user, no GUI), and runlevel 5 maps to graphical.target. Runlevel 0 is poweroff.target and runlevel 6 is reboot.target.
systemctl get-default vs. set-default vs. isolate
get-default shows the target that loads on startup. set-default changes which target loads on future boots but doesn't touch the running system. isolate switches the running system to a target immediately, with no reboot.
Why give /boot its own partition?
A separate /boot keeps the kernel and initramfs on a simple, unencrypted filesystem the bootloader can read, so the system still boots when root uses a layout the bootloader can't open — such as LUKS2 encryption GRUB 2 can't unlock, or LVM with legacy GRUB. On UEFI machines the bootloader itself lives on a separate FAT EFI System Partition (ESP).
What is a swap partition used for?
Swap extends RAM by holding pages the kernel moves out of physical memory under pressure, and it also stores the memory image during hibernation (suspend-to-disk). It can be a dedicated partition or a swap file.
grub-install vs. grub-mkconfig
grub-install writes GRUB's boot code to a disk's MBR (BIOS) or the EFI System Partition (UEFI) — needed once per disk. grub-mkconfig -o /boot/grub/grub.cfg regenerates the boot menu from templates and installed kernels; update-grub is Debian/Ubuntu's wrapper for it, and RHEL-family systems use grub2-mkconfig.
Why not hand-edit /boot/grub/grub.cfg?
grub.cfg is auto-generated from /etc/default/grub and the scripts in /etc/grub.d/. Direct edits are overwritten the next time grub-mkconfig (update-grub on Debian/Ubuntu, grub2-mkconfig on RHEL) runs — change the source files instead, then regenerate.
ldd vs. ldconfig
ldd lists the shared libraries an executable depends on and where each resolves from. ldconfig rebuilds the dynamic linker's cache (/etc/ld.so.cache) from the paths in /etc/ld.so.conf so the loader finds libraries quickly.
apt-get vs. apt-cache
apt-get performs actions that change the system: install, remove, upgrade. apt-cache only queries already-downloaded package metadata — search, show, depends — without installing, removing, or fetching new data.
dpkg -i vs. apt/apt-get install
dpkg -i installs a local .deb file directly but does not resolve or fetch dependencies. If any are missing, it unpacks the files but leaves the package unconfigured; run apt-get install -f afterward to fetch the missing dependencies and finish configuring it. apt/apt-get install resolves and downloads dependencies automatically from repositories.
rpm -qa vs. rpm -qf
rpm -qa lists every installed package on the system. rpm -qf /path/to/file instead answers a different question: which installed package owns this specific file. Same rpm -q family, different query targets.
rpm -Uvh vs. dnf/yum/zypper install
rpm -Uvh package.rpm installs or upgrades a local RPM file but does not resolve dependencies — you must supply them yourself. dnf install, yum install, and zypper install (zypper is SUSE's tool) resolve and download dependencies automatically from configured repositories.
What does cloud-init do for a cloned Linux guest?
On first boot of a cloned or templated VM/cloud instance, cloud-init reads provider-supplied metadata to set the hostname, inject SSH keys, configure networking, and create users — so clones don't all boot with identical stale settings.
Single quotes vs. double quotes in bash
Single quotes ('...') preserve every character literally — no variable expansion, no command substitution. Double quotes ("...") still expand $variables and $(command substitutions) but block filename globbing and word splitting.
export VAR=value vs. VAR=value
VAR=value creates a shell variable: the current shell and its ( ) or $( ) subshells can read it, but programs the shell starts cannot. export VAR=value marks it for the environment, so child processes — a new bash, a script, any command — inherit it.
type vs. which
type is a shell builtin that reports whether a name is an alias, function, builtin, or file, checking all of these. which only searches $PATH for an executable file, so it misses aliases, functions, and builtins.
cut -f vs. cut -c
cut -f extracts specific delimited fields from each line (needs -d to set the delimiter; default is tab). cut -c extracts specific character positions instead, ignoring any field structure entirely.
sort -u vs. uniq
sort -u sorts input and removes duplicate lines in one step, regardless of input order. uniq only removes adjacent duplicate lines, so unsorted input must go through sort first — sort file | uniq — or duplicates survive.
rm -r vs. rm -rf
rm -r removes directories and their contents recursively, but when run from a terminal it still asks before deleting write-protected files. Adding -f never prompts and stays silent about nonexistent files, so a mistyped path gives no warning. Neither option overrides a directory you lack write permission for.
cp -r vs. cp -a
cp -r copies directories recursively, but new files get the copier's ownership, the current time, and permissions filtered by umask. cp -a (archive mode, -dR --preserve=all) also preserves mode, ownership (when run as root), timestamps, hard links, and extended attributes — the closest duplicate. In GNU cp, both copy symlinks as symlinks.
Why quote wildcards passed to find -name?
Unquoted, the shell expands *.log before find runs. With no matches in the current directory, bash passes the pattern through unchanged; with one match, find searches only for that exact name; with several, GNU find fails with "paths must precede expression". Quoting ('*.log') always hands the pattern to find.
> vs. >>
> redirects output to a file, overwriting (truncating) any existing content. >> redirects output and appends to the end of the file instead, preserving what was already there.
Why does command > file 2>&1 send stderr to file, but 2>&1 > file doesn't?
Redirections apply left to right. In > file 2>&1, stdout goes to file first, then stderr is duplicated to wherever stdout now points. Reversed, stderr is duplicated to the terminal before stdout is redirected to file.
tee vs. xargs
tee reads stdin and writes it to both a file and stdout unchanged, so a pipeline can continue while also saving output. xargs reads stdin and turns it into command-line arguments for a command that doesn't read stdin itself.
kill vs. kill -9
kill with no signal sends SIGTERM (15), which a well-behaved process can catch and use to shut down cleanly. kill -9 sends SIGKILL, delivered immediately by the kernel — a process cannot catch, block, or ignore it.
ps aux vs. ps -ef
Both list every process, but with different columns: ps aux (BSD-style syntax) shows %CPU and %MEM by default, while ps -ef (UNIX-style syntax) always shows the parent process ID (PPID) column.
What does nohup actually change about a command?
nohup makes a command ignore SIGHUP, so it keeps running after its terminal closes, but it doesn't background the command; add & for that. If stdout is a terminal, output is appended to nohup.out in the current directory (or $HOME/nohup.out if that isn't writable), and stderr goes to the same file.
What is the default niceness, and who can lower it?
New processes start at niceness 0, on a scale from -20 (highest priority) to 19 (lowest). Only root can set a negative niceness; ordinary users may only increase niceness (lower priority) on their own processes.
nice vs. renice
nice sets a process's priority at launch time; plain nice command adds 10 to the default niceness of 0, or nice -n N command to add N instead. renice changes the priority of a process that is already running, identified by PID.
egrep vs. fgrep
egrep is a deprecated alias for grep -E, enabling extended regular expressions where +, ?, |, and () work unescaped. fgrep is a deprecated alias for grep -F, treating the pattern as a literal fixed string with no regex metacharacters.
Basic regex anchors: ^ and $
^ matches the start of a line and $ matches the end of a line. grep '^root' matches lines beginning with root; grep 'root$' matches lines ending with root — position matters, not just presence of the text.
Why doesn't sed 's/foo/bar/' replace every 'foo' on a line?
Without a trailing flag, sed's s/// command replaces only the first match on each line. Adding the g flag — s/foo/bar/g — makes the substitution global, replacing every match on that line.
vi's three modes: what changes between them?
Normal (command) mode is vi's default, used for navigation and commands. Insert mode, entered with i, a, or o, is for typing text. Command-line mode, entered with :, is for ex commands like :w or :q.
:w! vs. :q! vs. ZZ in vi
:w! forces a write even when normal conditions would block it, such as a read-only file you own. :q! forces an immediate quit, discarding unsaved changes. ZZ saves only if there are unsaved changes, then quits (like :x) — typed in normal mode, no colon needed.
dd, yy, and p in vi
dd deletes (cuts) the current line into vi's unnamed buffer. yy yanks (copies) the current line into that same buffer without deleting it. p pastes the buffer's contents after the cursor's current line.
MBR vs. GPT partitioning
MBR supports at most 4 primary partitions (or 3 primary plus 1 extended holding logical partitions) and addresses up to 2 TiB with 512-byte sectors. GPT supports far more partitions (128 by default) and much larger disks. GPT is the UEFI-standard scheme, but UEFI firmware can also boot MBR disks.
Can you shrink an XFS filesystem like you can ext4?
No. An XFS filesystem (mkfs.xfs) can only be grown online, never shrunk — shrinking means backing up, recreating, and restoring. ext4 supports both growing and, when unmounted, shrinking via resize2fs.
du vs. df — why can they disagree?
du sums the disk blocks actually allocated to files it can walk in the directory tree (not their apparent byte size). df reports free/used space from the filesystem's superblock. They disagree when a process holds a deleted file open — df counts that space used, du can't see the file.
Why avoid running fsck on a mounted, read-write filesystem?
fsck (e2fsck for ext filesystems) expects the filesystem to be inactive so it can safely repair structures. Running it on a mounted read-write filesystem risks corruption from concurrent writes; e2fsck normally refuses or warns unless mounted read-only.
What are the 6 fields in /etc/fstab, in order?
Device (or UUID), mount point, filesystem type, mount options, dump flag (0/1, for the dump backup utility), and fsck pass number (0/1/2, controlling check order at boot) — in that exact order.
What does mount -o remount,rw do?
It remounts an already-mounted filesystem with new options — here, switching from read-only to read-write — without unmounting first or rebooting. Useful for fixing a filesystem that mounted read-only after an error.
How is the default umask of 022 applied?
umask removes (masks off) the bits it lists from the default creation modes: 666 for files, 777 for directories. With umask 022, new files get 644 (rw-r--r--) and new directories 755 (rwxr-xr-x). It is bit masking, not subtraction: umask 033 still gives files 644, not 633.
setuid vs. setgid vs. sticky bit
setuid on an executable runs it with the file owner's privileges, not the caller's. setgid on a directory makes new files inherit that directory's group. The sticky bit on a directory (like /tmp) lets only the file's owner, the directory's owner, or root delete or rename a file.
blkid vs. lsblk for identifying filesystems
blkid prints each block device's filesystem type, UUID, and label — the values you copy into /etc/fstab. lsblk shows the device/partition tree itself (names, sizes, mountpoints) without probing filesystem metadata unless asked (lsblk -f adds type, label, and UUID). Use fstab entries by UUID, not by device name, since /dev/sdaN order can shift between boots.
Hard link vs. symbolic link
A hard link (ln src dst) shares the original's inode — it can't cross filesystems or link a directory, and the data survives as long as any hard link remains. A symlink (ln -s src dst) is a separate inode holding a path — it can cross filesystems but breaks if the target is removed.
/etc vs. /var vs. /usr — FHS purpose
/etc holds static host-specific configuration files. /var holds variable data that changes at runtime — logs, spool queues, caches. /usr holds installed programs and shared, mostly read-only application data.
find vs. locate
find searches the live filesystem in real time, so results are always current but the search can be slow. locate queries a prebuilt index database (refreshed by updatedb, configured via /etc/updatedb.conf) — much faster, but results can be stale.
Frequently Asked Questions
How many questions are on the LPIC-1 101-500 exam?
LPI's official FAQ states every LPIC exam has 60 questions to complete in 90 minutes, and objective weights are standardized to total 60 points — one question per weight point. Exam 101-500 follows this standard format.
What is the LPIC-1 101-500 passing score?
LPI's FAQ states every LPIC exam is scored on a 200-800 scale with a passing score of 500. The number of correct answers needed varies by question difficulty; LPI does not publish a fixed raw-score cutoff.
What happens if I fail the LPIC-1 101 exam?
LPI's official policy (lpi.org/policies) requires a 1-week wait after a first failed attempt, then a 14-day wait after the second and every later failed attempt. After passing, you cannot retake that same exam for at least 2 years.
What are the four topic areas on Exam 101-500, and which carries the most weight?
LPI assigns integer objective weights that total 60 for Exam 101-500: System Architecture (8), Installation and Package Management (12), GNU and Unix Commands (26 — the largest topic), and Devices/Filesystems/FHS (14).
Is 101-500 still the current LPIC-1 exam version?
Yes. LPI's official objectives page lists Exam Objectives Version 5.0 (exam codes 101-500 and 102-500) as the currently released version, with no newer version announced as of September 2026.
Do I need employer sponsorship to take the LPIC-1 101 exam?
No. Anyone can buy an LPI exam voucher directly from the LPI Marketplace and schedule at a Pearson VUE test center or through OnVUE online proctoring — no employer or sponsor approval is required.
Explore More Linux Professional Institute Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.