1Z0-106 Oracle Linux 8 Advanced System Administration Practice Questions
Prepare for 1Z0-106 with more than an answer.
- Exam fee
- $245 USD
- Level
- Professional
- Valid for
- Typically does not expire
Domains covered on the exam 21
- Understanding and Configuring the Linux Boot Process and Service Administration8%
- Understanding System Configuration Options8%
- Installing and Maintaining Packages6%
- Automating Tasks5%
- Oracle Ksplice5%
- Managing Users and Groups6%
- Managing Filesystems and Swap8%
- Managing Storage Devices8%
- Managing the Network Configuration8%
- Using OpenSSH6%
- Managing Linux Security8%
- Managing System Logging6%
- Monitoring and Troubleshooting Linux8%
- Managing Pluggable Authentication Modules (PAM)4%
- Advanced Networking6%
- Advanced Storage Administration6%
- Managing File Sharing6%
- Security Enhanced Linux (SELinux)8%
- Control Groups (Cgroups)5%
- Container Services8%
- Linux Auditing System4%
- 1
Case Study
An administrator is configuring a new Oracle Linux 8 server to host a secure file transfer service. The requirements are:
- The server must use a dedicated 1TB partition mounted at
/var/ftp/pub. - Anonymous uploads must be permitted but files should not be visible to other anonymous users until approved.
- All uploaded files must be owned by the
ftpuser andftpgroup. - SELinux is in Enforcing mode.
Which combination of actions meets the SELinux requirement for anonymous uploads to work correctly?
Show answer details
Correct answer: A
For anonymous FTP uploads to work with SELinux enforcing, two things are needed: the boolean
ftpd_anon_writemust be enabled (setsebool -P ftpd_anon_write 1), and the directory where uploads are stored must have the labelpublic_content_rw_tso the FTP daemon has write access. - The server must use a dedicated 1TB partition mounted at
- 2
You need to configure a new Stratis pool named
my_poolusing two block devices/dev/sdband/dev/sdc. Which command correctly initializes this pool on Oracle Linux 8?Show answer details
Correct answer: A
The
stratisCLI tool uses the syntaxstratis pool create ...to initialize a new storage pool. Stratis manages the underlying layers automatically. - 3
A system administrator needs to define a custom audit rule that monitors open system calls on all files within
/etc/security/. The rule should tag log entries with the keysecurity_access. Whichauditctlcommand accomplishes this?Show answer details
Correct answer: A
The
-wflag sets a watch on a file system object (directory or file). The-pflag specifies permissions to watch (read, write, attribute change, execute). The-kflag adds a key for searching logs. - 4
You are preparing to install a group of packages related to 'Development Tools' on an Oracle Linux 8 server. You want to see which packages are included in this group before installing. Which
dnfcommand should you use?Show answer details
Correct answer: A
dnf group infodisplays details about a specific package group, including the list of mandatory, default, and optional packages it contains. - 5
Which TWO of the following statements about Control Groups version 2 (cgroup v2) in Oracle Linux 8 are correct? (Select TWO)
Show answer details
Correct answer: A, C
Cgroup v2 simplifies the architecture by using a single unified hierarchy for all resource controllers, unlike v1 which used separate hierarchies for cpu, memory, etc.
Systemd is the primary cgroup manager in OL8 and uses three unit types to organize processes: Services (for daemons), Scopes (for ad-hoc groups of processes), and Slices (for hierarchical organization).
- 6
You need to configure the
chronydservice to act as an NTP server for the local network192.168.100.0/24. Which line must be added to/etc/chrony.confto allow clients from this subnet to query the server?Show answer details
Correct answer: A
The
allowdirective inchrony.confspecifies which subnets or hosts are permitted to query the server for time synchronization. - 7
An administrator deploys a custom web service that is configured to listen on TCP port 8080. The service fails to start, and the
journalctllogs show a "Permission denied" error when trying to bind to the port. The system is running in SELinux enforcing mode. The administrator confirms thatfirewalldis not blocking the port. What is the correct, persistent method to allow the web service to bind to port 8080?flowchart TD Start([Start]) --> CheckService{Service fails to start} CheckService --> CheckLogs{journalctl} CheckLogs --> |'Permission Denied'| IsSELinux{SELinux Enforcing?} IsSELinux --> |Yes| IsFirewall{Firewall Blocking?} IsFirewall --> |No| SELinuxPortContext{Check SELinux Port Context} SELinuxPortContext --> Solution[Apply Correct Port Context] Solution --> Restart[Restart Service] Restart --> Success([Success])Show answer details
Correct answer: C
The issue is that SELinux policy, by default, only allows services with the
httpd_tcontext to bind to ports labeledhttp_port_t(like 80, 443, 8008, etc.). Port 8080 is typically labeledhttp_cache_port_tor may not have a web-related label. The correct and persistent solution is to usesemanage portto add a new rule to the SELinux policy, labeling port 8080 with thehttp_port_ttype. This allows the web service to bind to it successfully. Disabling SELinux is insecure. Usingaudit2allowis for cases where no appropriate label exists, buthttp_port_tis the correct existing label for this purpose.setseboolis for toggling booleans, not for defining port labels. - 8
You are configuring a new Oracle Linux 8 server that will serve as a high-performance database node. The network team has provisioned a specific static IP address, gateway, and DNS servers. You need to configure the 'eno1' interface using
nmcliin a single command line to minimize downtime. Which command successfully creates and activates this connection with the specified parameters?Show answer details
Correct answer: A
This command correctly adds a new connection profile of type ethernet with manual IPv4 configuration, specifying the address, gateway, and DNS servers in the correct format, and immediately activates it. The syntax for
ipv4.dnsaccepts space-separated IPs within quotes.
