Career Employer

Your FREE CompTIA Linux+ Flashcards 2026 – 250+ Cards

Realistic, Linux+ (XK0-006) exam-style flashcards across all 5 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer Linux+”

By

Click Study Flashcards above to open the flashcard hub — hundreds of Linux+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official XK0-006 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.

CompTIA Linux+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.

Linux+ Flashcard Study Modes

Flip mode is for first passes and review, letting you turn each card front to back at your own speed. Match times you as you pair terms with definitions. Type shows the definition and asks you to spell the term back, so a front like LVM has to come from memory. Quiz turns the same cards into multiple choice.

Free CompTIA Linux+ flashcards from Career Employer — active recall for the XK0-006 exam

Why Flashcards Work for the Linux+

System Management is the largest block in the deck at 67 cards, matching its 23% share of the exam. The cards drill filesystem layout, storage, and file handling vocabulary, from FHS and the root directory card for / through XFS and LVM, plus archiving with tar and directory prompts such as /sys and /opt.

Troubleshooting carries 56 cards against a 22% weighting, and the fronts are mostly diagnostic commands and the symptoms they expose. Expect kernel and log inspection with dmesg, open file tracing with lsof, path testing with mtr and ping, capacity checks with df -h, and repair work with fsck.

Services and User Management has 56 cards for 20% of the exam. This section mixes package management across distributions, with apt, dnf, yum, and rpm sitting side by side, and account, privilege, and process terms such as id, sudo, PID, and job scheduling with at.

Security is 58 cards covering 18% of the exam. The fronts run from access control models like MAC and DAC to authentication plumbing in PAM and MFA, remote access with SSH, host firewalling with ufw, encryption and signing with gpg, and permission traps such as SUID.

Automation, Orchestration and Scripting closes the deck with 49 cards for 17%. Text processing dominates, with sed, awk, and grep appearing as separate fronts, alongside shell scripting mechanics like 2>&1, trap, and read, plus version control and infrastructure concepts in Git and IaC.

The Linux+ is dense with things you simply have to know cold — the FHS directories, permission octals, systemctl subcommands, package-manager commands, and troubleshooting tools.[1] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

Linux+ Flashcards by Domain

The cards are organized by the five official XK0-006 domains. Drill the highest-weighted ones first — System Management and Troubleshooting make up 45% of the exam:[1]

Linux+ flashcards by domain and weight
DomainExam weight
System Management23%
Troubleshooting22%
Services and User Management20%
Security18%
Automation, Orchestration & Scripting17%

How to Get the Most Out of These Flashcards

  • Start with System Management. It is the biggest domain at 67 cards and the heaviest at 23%, and its filesystem vocabulary underpins the troubleshooting and security cards you meet later.
  • Type-drill the terse fronts. Symbols and flags such as 2>&1 and df -h are easy to recognize and hard to reproduce, so force recall instead of settling for a comfortable flip.
  • Use Match for tool families. Grouping package managers like apt, dnf, and rpm under timed pressure exposes the ones you only half distinguish, which is exactly where exam distractors live.
  • Move to the practice test once Quiz holds up. When multiple choice stops surprising you across all five domains, switch to full-length questions and use the study guide for gaps.
  • Keep a rotating cadence. With 286 cards, work one domain per sitting, then mix a short Match round from a previously finished domain so older terms stay warm.

Linux+ Flashcards FAQ

Hundreds of free Linux+ flashcards, organized across the five XK0-006 domains — System Management, Services and User Management, Security, Automation/Orchestration/Scripting, and Troubleshooting. They're free with no account required.

Linux+ flashcard bank

All 286 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

System Management (67)

FHS
Show answer

Filesystem Hierarchy Standard — the standard layout of Linux directories under root (/).

/
Show answer

The root of the entire Linux filesystem; everything mounts beneath it.

/etc
Show answer

System-wide configuration files (text), e.g. /etc/passwd, /etc/fstab.

/var
Show answer

Variable data that changes at runtime — logs (/var/log), spools, caches, mail.

/home
Show answer

Regular users' home directories (e.g. /home/alice).

/usr
Show answer

Installed programs, libraries, and documentation (largely read-only).

/bin and /sbin
Show answer

Essential user and system binaries (often symlinked into /usr).

/tmp
Show answer

Temporary files; world-writable with the sticky bit; often cleared on reboot.

/dev
Show answer

Device files representing hardware and pseudo-devices (e.g. /dev/sda, /dev/null).

/proc
Show answer

A virtual filesystem exposing live per-process and kernel data from memory.

/sys
Show answer

A virtual filesystem exposing kernel device and subsystem information.

/boot
Show answer

Holds the kernel, initramfs, and bootloader (GRUB) files needed to start the system.

/opt
Show answer

Optional, self-contained third-party application packages.

/var/log
Show answer

The directory where system and service log files are written.

Mount point
Show answer

A directory where a filesystem is attached so its contents become accessible.

BIOS vs UEFI
Show answer

Firmware that starts the boot process; UEFI reads the EFI System Partition, legacy BIOS reads the MBR.

GRUB2
Show answer

The GRand Unified Bootloader v2 — loads the Linux kernel and initramfs at boot.

initramfs
Show answer

A temporary in-memory root filesystem holding drivers needed to mount the real root.

Kernel
Show answer

The core of the OS that manages hardware, memory, processes, and system calls.

Linux boot order
Show answer

Firmware (UEFI/BIOS) → GRUB2 → kernel + initramfs → systemd (PID 1) → target → login.

systemd
Show answer

The modern init system and service manager; runs as PID 1 and supervises units.

PID 1
Show answer

The first user-space process started by the kernel — systemd on most distributions.

Unit (systemd)
Show answer

A systemd-managed resource: a service, socket, mount, timer, or target.

Target (systemd)
Show answer

A grouping of units defining a system state; replaces SysV runlevels.

multi-user.target
Show answer

The systemd target for multi-user, command-line (non-graphical) operation.

graphical.target
Show answer

The systemd target that starts the GUI on top of multi-user.

systemctl
Show answer

The command to control systemd: start, stop, restart, enable, disable, status.

systemctl enable
Show answer

Configure a service to start automatically at boot (does not start it now).

systemctl start
Show answer

Start a service immediately (does not survive a reboot unless also enabled).

systemctl enable --now
Show answer

Enable a service at boot AND start it right now in one command.

systemctl status
Show answer

Show a service's current state, PID, and recent log lines.

journalctl
Show answer

Query the systemd journal (logs); filter by unit, boot, time, and priority.

journalctl -u
Show answer

Show the journal entries for one specific systemd unit/service.

journalctl -b
Show answer

Show journal entries from the current boot.

lsblk
Show answer

List block devices (disks and partitions) and their mount points.

fdisk / parted
Show answer

Create and manage disk partitions (parted handles GPT and large disks).

mkfs.ext4
Show answer

Create an ext4 filesystem on a partition.

mkfs.xfs
Show answer

Create an XFS filesystem on a partition (default on RHEL).

ext4
Show answer

A widely used, mature Linux journaling filesystem.

XFS
Show answer

A high-performance journaling filesystem; the default on RHEL.

Btrfs
Show answer

A modern copy-on-write Linux filesystem with snapshots and pooling.

mount
Show answer

Attach a filesystem to a mount point so its contents are accessible.

umount
Show answer

Detach a mounted filesystem from its mount point.

/etc/fstab
Show answer

Lists filesystems to mount at boot, with mount points and options (use UUIDs).

df -h
Show answer

Report filesystem disk space usage in human-readable form.

du -sh
Show answer

Show the total size of a directory (summary, human-readable).

LVM
Show answer

Logical Volume Management — pool disks into resizable logical volumes.

LVM layers
Show answer

Physical Volume (PV) → Volume Group (VG) → Logical Volume (LV).

pvcreate / vgcreate / lvcreate
Show answer

Create the LVM physical volume, volume group, and logical volume.

mdadm
Show answer

Create and manage Linux software RAID arrays.

RAID 0 vs 1
Show answer

RAID 0 stripes for speed (no redundancy); RAID 1 mirrors for redundancy.

ip addr
Show answer

Show network interfaces and their IP addresses (modern replacement for ifconfig).

ip route
Show answer

Show the routing table, including the default gateway.

nmcli
Show answer

Command-line tool to manage NetworkManager connections.

/etc/resolv.conf
Show answer

Configures the DNS resolvers (nameservers) the system uses.

/etc/hosts
Show answer

Static hostname-to-IP mappings, checked before DNS.

ss -tulpn
Show answer

List listening TCP/UDP sockets and the processes that own them.

hostnamectl
Show answer

View or set the system hostname (and related metadata).

uname -r
Show answer

Print the running kernel release/version.

lsmod / modprobe
Show answer

List loaded kernel modules / load a kernel module.

tar
Show answer

Archive multiple files into one (.tar); add -z for gzip, -j for bzip2 compression.

gzip / bzip2 / xz
Show answer

Compression tools producing .gz, .bz2, and .xz files.

ln -s
Show answer

Create a symbolic (soft) link pointing to another file or directory.

Hard vs soft link
Show answer

A hard link is another name for the same inode; a soft link is a pointer to a path.

find
Show answer

Search the filesystem for files by name, size, time, type, or permissions.

locate
Show answer

Quickly find files by name using a prebuilt index (updatedb).

chroot
Show answer

Change the apparent root directory for a process and its children (a sandbox).

Services and User Management (56)

Package manager
Show answer

A tool that installs, updates, and removes software and resolves dependencies.

apt
Show answer

The high-level package manager for Debian/Ubuntu; installs .deb packages.

dpkg
Show answer

The low-level Debian package tool that operates on a single .deb file.

dnf
Show answer

The high-level package manager for RHEL/Fedora/CentOS (successor to yum); installs .rpm.

yum
Show answer

The older RHEL-family package manager, now succeeded by dnf.

rpm
Show answer

The low-level package format and tool for RHEL-family distributions.

zypper
Show answer

The high-level package manager for openSUSE/SLES (.rpm).

apt update
Show answer

Refresh the local package index from the configured repositories (Debian/Ubuntu).

apt install
Show answer

Install a package and its dependencies on Debian/Ubuntu (apt install <pkg>).

dnf install
Show answer

Install a package and its dependencies on RHEL/Fedora (dnf install <pkg>).

snap and flatpak
Show answer

Universal, sandboxed package formats that bundle dependencies and work across distros.

Compile from source
Show answer

Build software with ./configure && make && make install.

Repository
Show answer

A configured source of packages a package manager downloads from.

Process
Show answer

A running instance of a program, identified by a PID with a state and owner.

PID
Show answer

Process ID — the unique number identifying a running process.

ps aux
Show answer

List all running processes with their owner, PID, CPU, and memory usage.

top / htop
Show answer

Show live, interactive process and resource usage (htop is friendlier).

kill
Show answer

Send a signal to a process by PID (default TERM = graceful stop).

kill -9
Show answer

Send SIGKILL to forcibly terminate a process that won't stop gracefully.

SIGTERM vs SIGKILL
Show answer

TERM (15) asks a process to exit cleanly; KILL (9) forces it immediately.

nice / renice
Show answer

Set or change a process's CPU scheduling priority (-20 highest, 19 lowest).

nohup
Show answer

Run a command immune to hangups so it keeps running after you log out.

Background job (&)
Show answer

Append & to a command to run it in the background; manage with jobs, fg, bg.

cron
Show answer

The time-based job scheduler daemon that runs jobs on a schedule.

crontab
Show answer

A user's table of scheduled cron jobs; edit with crontab -e, list with crontab -l.

cron fields
Show answer

Five fields: minute, hour, day-of-month, month, day-of-week, then the command.

0 2 * * *
Show answer

A cron schedule meaning 'run every day at 2:00 a.m.'

systemd timer
Show answer

The modern alternative to cron for scheduling systemd units.

at
Show answer

Schedule a command to run once at a specified future time.

/etc/passwd
Show answer

User account records (username, UID, GID, home directory, shell) — no passwords.

/etc/shadow
Show answer

Stores users' hashed passwords and password-aging policy.

/etc/group
Show answer

Defines groups and their members.

useradd
Show answer

Create a new user account.

usermod
Show answer

Modify an existing user account (e.g. add to a group with -aG).

userdel
Show answer

Delete a user account (use -r to also remove the home directory).

groupadd
Show answer

Create a new group.

passwd
Show answer

Set or change a user's password.

id
Show answer

Show a user's UID, GID, and group memberships.

Primary vs secondary group
Show answer

Each user has one primary group and may belong to several secondary groups.

sudo
Show answer

Run a single command as another user (usually root) per /etc/sudoers rules.

visudo
Show answer

Safely edit /etc/sudoers; it validates syntax so a typo can't break sudo.

su vs sudo
Show answer

su switches to another user entirely; sudo runs one command with elevation and logs it.

wheel / sudo group
Show answer

The group whose members are allowed to use sudo (wheel on RHEL, sudo on Debian).

/etc/sudoers.d/
Show answer

A directory for drop-in sudoers files, kept separate from /etc/sudoers.

Container
Show answer

A lightweight, isolated process packaging an app and its dependencies; shares the host kernel.

Container vs VM
Show answer

Containers share the host kernel (lightweight); VMs run a full guest OS (heavier).

Docker image
Show answer

A read-only template built from a Dockerfile; the basis for containers.

Docker container
Show answer

A running instance of a Docker image.

Dockerfile
Show answer

A text file of instructions used to build a Docker image.

docker build
Show answer

Build an image from a Dockerfile.

docker run
Show answer

Create and start a container from an image.

docker ps
Show answer

List running containers (add -a to include stopped ones).

docker images
Show answer

List the images stored locally.

Docker Compose
Show answer

Define and run multi-container applications from a YAML file.

Podman
Show answer

A daemonless, rootless container engine that is largely Docker-compatible.

Container registry
Show answer

A store for container images (e.g. Docker Hub) that you push to and pull from.

Security (58)

Linux permissions
Show answer

Read (r=4), write (w=2), execute (x=1) for owner, group, and others.

rwxr-xr--
Show answer

Owner rwx (7), group r-x (5), others r-- (4) = octal 754.

chmod
Show answer

Change a file's permission bits, numeric (754) or symbolic (u+x).

chmod 644
Show answer

Owner read/write; group and others read-only — typical for a regular file.

chmod 755
Show answer

Owner read/write/execute; group and others read/execute — typical for a script/dir.

chown
Show answer

Change a file's owner (chown user file) and optionally group (user:group).

chgrp
Show answer

Change a file's group ownership.

umask
Show answer

Subtracts default permission bits from newly created files and directories.

Execute bit on a directory
Show answer

Required to enter (cd into) the directory, not just read it.

File type character
Show answer

The first ls -l character: - file, d directory, l symlink, b/c device.

SUID
Show answer

Special bit (4) that runs a program with the privileges of its file owner (e.g. passwd).

SGID
Show answer

Special bit (2) that runs a file as its group, or makes new files inherit a dir's group.

Sticky bit
Show answer

Special bit (1) on a directory letting users delete only files they own (e.g. /tmp).

chmod 4755
Show answer

Sets the SUID bit plus rwxr-xr-x.

chmod 1777
Show answer

Sets the sticky bit plus rwxrwxrwx (the /tmp permissions).

ACL (setfacl/getfacl)
Show answer

Access Control Lists grant fine-grained per-user/per-group permissions beyond rwx.

chattr / lsattr
Show answer

Set/view extended file attributes (e.g. +i makes a file immutable).

MAC
Show answer

Mandatory Access Control — a system-enforced policy users cannot override.

DAC
Show answer

Discretionary Access Control — the file owner decides permissions (standard rwx).

SELinux
Show answer

Label-based mandatory access control; default on RHEL-family systems.

SELinux modes
Show answer

Enforcing (block + log), permissive (log only), and disabled.

getenforce
Show answer

Show the current SELinux mode (Enforcing, Permissive, or Disabled).

setenforce
Show answer

Temporarily switch SELinux between enforcing (1) and permissive (0).

sestatus
Show answer

Show detailed SELinux status and policy information.

restorecon
Show answer

Reset a file's SELinux context to the policy default.

semanage
Show answer

Manage SELinux policy (ports, file contexts, booleans) persistently.

/etc/selinux/config
Show answer

Where the persistent SELinux mode is set across reboots.

AppArmor
Show answer

Path-based mandatory access control using profiles; default on Ubuntu/SUSE.

AppArmor modes
Show answer

Enforce (apply the profile) and complain (log only).

aa-status
Show answer

Show the status of loaded AppArmor profiles.

SELinux vs AppArmor
Show answer

SELinux labels objects (RHEL); AppArmor targets program paths (Ubuntu/SUSE).

PAM
Show answer

Pluggable Authentication Modules — the framework controlling how users authenticate.

Least privilege
Show answer

Grant users and processes only the access they actually need.

SSH
Show answer

Secure Shell — an encrypted protocol for remote login and file transfer.

ssh-keygen
Show answer

Generate an SSH public/private key pair.

authorized_keys
Show answer

The server file (~/.ssh/authorized_keys) holding clients' public keys.

SSH key authentication
Show answer

Client proves it holds the private key matching a public key on the server.

ssh-copy-id
Show answer

Copy your public key to a server's authorized_keys for passwordless login.

/etc/ssh/sshd_config
Show answer

The SSH server config; harden by disabling root login and password auth.

scp / sftp
Show answer

Copy files over SSH (scp) or transfer interactively over SSH (sftp).

firewalld
Show answer

A dynamic, zone- and service-based firewall manager (RHEL family).

firewall-cmd
Show answer

The command-line client for firewalld.

ufw
Show answer

Uncomplicated Firewall — a simple front-end to iptables/nftables (Ubuntu).

iptables
Show answer

The legacy packet-filtering framework for defining firewall rules.

nftables
Show answer

The modern successor to iptables for packet filtering.

Default-deny
Show answer

A firewall posture that blocks everything except explicitly allowed traffic.

LUKS
Show answer

Linux Unified Key Setup — the standard for full-disk (block-device) encryption.

cryptsetup
Show answer

The tool used to set up and manage LUKS-encrypted volumes.

gpg
Show answer

GNU Privacy Guard — encrypt, decrypt, and digitally sign files.

Hashing
Show answer

A one-way function (e.g. sha256sum) used to verify integrity, not to encrypt.

TLS certificate
Show answer

Secures a service's traffic in transit and authenticates its identity.

Defense in depth
Show answer

Layer multiple controls (permissions, MAC, firewall, encryption) so one failure isn't fatal.

fail2ban
Show answer

Monitors logs and bans IPs after repeated failed login attempts.

Public vs private key
Show answer

Encrypt/verify with the public key; decrypt/sign with the private key.

MFA
Show answer

Multi-factor authentication — combine something you know, have, and/or are.

getfacl / setfacl
Show answer

View and set Access Control Lists for fine-grained per-user permissions.

setsebool
Show answer

Toggle an SELinux boolean to allow or deny optional policy behavior.

Open a port in firewalld
Show answer

firewall-cmd --add-service=http --permanent, then --reload.

Automation, Orchestration and Scripting (49)

Shebang
Show answer

The first script line (#!/bin/bash) naming the interpreter that runs the file.

Make a script executable
Show answer

chmod +x script.sh, then run it with ./script.sh.

Variable (Bash)
Show answer

name="value" with no spaces; reference it as $name or "$name".

Exit code ($?)
Show answer

The status of the last command: 0 = success, non-zero = error.

if statement (Bash)
Show answer

if [[ condition ]]; then ... fi — runs commands when the test is true.

test / [[ ]]
Show answer

Evaluate a condition (file checks, numeric/string comparisons) for if and while.

for loop (Bash)
Show answer

for f in *.log; do ... done — iterate over a list of items.

while loop (Bash)
Show answer

while [[ condition ]]; do ... done — repeat while the test stays true.

until loop (Bash)
Show answer

until [[ condition ]]; do ... done — repeat until the test becomes true.

case statement
Show answer

Match a variable against patterns — a cleaner multi-way branch than nested ifs.

Pipe ( | )
Show answer

Send one command's standard output as the next command's standard input.

Redirection > and >>
Show answer

> writes output to a file (overwrite); >> appends to it.

Input redirection ( < )
Show answer

Feed a file's contents to a command as standard input.

2>&1
Show answer

Redirect standard error to the same place as standard output.

grep
Show answer

Search text for lines matching a pattern (regular expression).

grep -i / -r / -v
Show answer

Ignore case / search recursively / invert the match.

sed
Show answer

A stream editor for filtering and transforming text (e.g. find-and-replace).

awk
Show answer

A text-processing language for working with columns and fields.

cut / sort / uniq
Show answer

Extract columns / sort lines / collapse or count duplicate lines.

Command substitution
Show answer

$(command) inserts a command's output into another command or variable.

&& and ||
Show answer

&& runs the next command only if the previous succeeded; || only if it failed.

Positional parameters
Show answer

$1, $2, ... are a script's arguments; $0 is the script name, $# the count.

Function (Bash)
Show answer

name() { commands; } — group reusable commands into a callable block.

trap
Show answer

Catch signals (e.g. EXIT, INT) in a script to run cleanup before exiting.

Globbing
Show answer

Shell wildcards: * (any chars), ? (one char), [abc] (a character set).

read
Show answer

Read a line of input into a variable, often for interactive scripts.

echo / printf
Show answer

Print text to standard output (printf gives precise formatting).

Git
Show answer

A distributed version-control system tracking changes via commits, branches, merges.

git clone
Show answer

Copy a remote repository to your local machine.

git add
Show answer

Stage changes so they'll be included in the next commit.

git commit
Show answer

Save a snapshot of staged changes (git commit -m "message").

git push / git pull
Show answer

Send commits to the remote / fetch and merge from the remote.

git branch / checkout
Show answer

Create branches and switch between them to work in isolation.

git merge
Show answer

Combine the changes from another branch into the current one.

git status / git log
Show answer

Show the working-tree state / view the commit history.

Kubernetes
Show answer

An orchestrator that automates deploying, scaling, and managing containers.

Ansible
Show answer

An agentless automation tool using YAML playbooks pushed over SSH.

Idempotency
Show answer

Running an automation repeatedly yields the same end state, changing only what differs.

Ansible playbook
Show answer

A YAML file describing the desired state as a series of tasks.

Ansible inventory
Show answer

A file listing the hosts (and groups) Ansible manages.

Ansible module
Show answer

A reusable unit of work (e.g. apt, copy, service) a task invokes.

Puppet
Show answer

An agent-based configuration-management tool using a declarative language.

Chef
Show answer

An agent-based configuration-management tool using Ruby 'recipes'.

Terraform
Show answer

A declarative infrastructure-as-code tool that provisions infrastructure.

IaC
Show answer

Infrastructure as Code — manage systems with version-controlled config files.

cloud-init
Show answer

Initializes a cloud instance on first boot (users, keys, packages, scripts).

YAML
Show answer

A human-readable data format (indentation-based) used by Compose, Ansible, and Kubernetes.

Environment variable
Show answer

A named value in the shell environment (export NAME=value) available to processes.

alias
Show answer

Create a shortcut for a longer command (alias ll='ls -la').

Troubleshooting (56)

Troubleshooting methodology
Show answer

Identify, theorize, test, plan, implement/escalate, verify, document.

First step of troubleshooting
Show answer

Identify the problem — gather info, question users, find what changed.

Last step of troubleshooting
Show answer

Document the findings, actions, and outcomes.

Read the logs first
Show answer

journalctl (systemd), /var/log (text logs), and dmesg (kernel) before theorizing.

df -h
Show answer

Find which filesystem is full (human-readable disk usage).

du -sh *
Show answer

Find which directory is consuming the space (sort with | sort -h).

df -i
Show answer

Check inode usage — a disk can be 'full' of inodes with free space remaining.

Inode
Show answer

A filesystem structure storing a file's metadata; exhaustion blocks new files.

Deleted-but-open file
Show answer

Space isn't freed until the holding process closes; find it with lsof | grep deleted.

fsck
Show answer

Check and repair a filesystem — run only on an unmounted filesystem.

Disk full troubleshooting
Show answer

df -h to find the filesystem, du to find the directory, df -i for inodes.

logrotate
Show answer

Rotates and compresses logs so /var/log doesn't fill the root filesystem.

ping
Show answer

Test reachability and round-trip time to a host using ICMP.

traceroute / mtr
Show answer

Show the per-hop path to a destination to find where traffic stops.

dig / nslookup
Show answer

Test DNS name resolution.

Ping by IP but not name
Show answer

Connectivity works but DNS is broken — a name-resolution problem.

tcpdump
Show answer

Capture and inspect network packets for deep analysis.

ss / netstat
Show answer

List sockets/connections and listening ports (ss is the modern tool).

No IP address
Show answer

Points to a DHCP failure or interface misconfiguration.

Can't reach the gateway
Show answer

A local connectivity or routing problem (check ip route).

top / htop
Show answer

Show live CPU, memory, load average, and per-process resource usage.

Load average
Show answer

Average processes wanting CPU over 1, 5, 15 minutes; compare to core count.

High load average
Show answer

A value well above the core count means processes are queuing for CPU.

free -h
Show answer

Show total, used, available memory and swap in human-readable form.

vmstat
Show answer

Report virtual memory, CPU, and system activity (including swap usage).

iostat
Show answer

Report CPU and per-device disk I/O statistics to find I/O bottlenecks.

sar
Show answer

Collect and report historical system activity (CPU, memory, I/O) over time.

uptime
Show answer

Show how long the system has run and the 1/5/15-minute load averages.

Zombie process
Show answer

A finished process not yet reaped by its parent; shows a Z state, harmless but a bug sign.

Orphan process
Show answer

A running process whose parent died; it's re-parented to PID 1 (systemd).

Process state D
Show answer

Uninterruptible sleep — usually blocked on disk or network I/O.

OOM killer
Show answer

The kernel terminates a process under severe memory pressure to recover.

Find OOM events
Show answer

Look in dmesg or the journal for 'Out of memory' / 'Killed process' messages.

dmesg
Show answer

Display the kernel ring buffer — hardware, driver, and boot messages.

lsof
Show answer

List open files and the processes holding them (e.g. what holds a port or deleted file).

strace
Show answer

Trace the system calls a process makes — useful for diagnosing hangs and failures.

kill / pkill
Show answer

Send a signal to stop a process by PID (kill) or by name (pkill).

Service won't start
Show answer

Check systemctl status <svc> and journalctl -u <svc> for the failure reason.

Permission denied (despite rwx)
Show answer

Suspect SELinux/AppArmor — check the audit log and contexts.

ausearch / audit2allow
Show answer

Search SELinux audit denials and suggest a policy to allow them.

Swapping / thrashing
Show answer

Heavy swap use slows the system; check free -h and vmstat for swap activity.

Boot failure: GRUB
Show answer

An error at the GRUB stage points to the bootloader or its config.

Boot failure: kernel panic
Show answer

The kernel can't continue (often a missing root or initramfs issue).

Cannot mount filesystem
Show answer

Check /etc/fstab, the device/UUID, and run fsck if corrupted.

nice value too high
Show answer

A process set to a low priority (high nice) may run slowly under contention.

Check listening ports
Show answer

ss -tulpn shows which ports are open and which process owns each.

DNS misconfigured
Show answer

Check /etc/resolv.conf and test with dig; the resolver may be wrong or down.

Time out of sync
Show answer

Check the NTP/chrony service; clock skew breaks TLS, Kerberos, and logs.

High CPU one process
Show answer

Identify it in top/htop, then renice, fix, or kill the runaway process.

Read-only filesystem
Show answer

Often a sign of filesystem errors; the kernel remounts ro to protect data — check dmesg.

mtr
Show answer

Combines ping and traceroute into a continuous per-hop network diagnostic.

Cannot resolve hostname
Show answer

Test with dig/nslookup; fix /etc/resolv.conf or the upstream DNS server.

watch
Show answer

Re-run a command at intervals to watch a value change (e.g. watch df -h).

journalctl -p err
Show answer

Filter the journal to error-priority (and worse) messages.

Quota exceeded
Show answer

A user hit a disk quota; check with quota and repquota, then adjust or clean up.

uptime load > cores
Show answer

More demand than CPUs — investigate top CPU, memory pressure, or blocked I/O.

References

  1. 1.CompTIA. “Linux+ (XK0-006) Certification Exam Objectives.” comptia.org. ↑
  2. 2.Linux Foundation. “Filesystem Hierarchy Standard 3.0.” refspecs.linuxfoundation.org. ↑
  3. 3.The Linux man-pages project. “Linux man-pages (commands & files).” man7.org. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.