Skip to content

1Z0-106 Oracle Linux 8 Advanced System Administration Practice Questions

Prepare for 1Z0-106 with more than an answer.

205 questions in the full set17 sample questionsUpdated Jan 25, 2026
Exam fee
$245 USD
Level
Professional
Valid for
Typically does not expire
Domains covered on the exam 21
  1. Understanding and Configuring the Linux Boot Process and Service Administration8%
  2. Understanding System Configuration Options8%
  3. Installing and Maintaining Packages6%
  4. Automating Tasks5%
  5. Oracle Ksplice5%
  6. Managing Users and Groups6%
  7. Managing Filesystems and Swap8%
  8. Managing Storage Devices8%
  9. Managing the Network Configuration8%
  10. Using OpenSSH6%
  11. Managing Linux Security8%
  12. Managing System Logging6%
  13. Monitoring and Troubleshooting Linux8%
  14. Managing Pluggable Authentication Modules (PAM)4%
  15. Advanced Networking6%
  16. Advanced Storage Administration6%
  17. Managing File Sharing6%
  18. Security Enhanced Linux (SELinux)8%
  19. Control Groups (Cgroups)5%
  20. Container Services8%
  21. Linux Auditing System4%
  1. 1

    Case Study

    An administrator is configuring a new Oracle Linux 8 server to host a secure file transfer service. The requirements are:

    1. The server must use a dedicated 1TB partition mounted at /var/ftp/pub.
    2. Anonymous uploads must be permitted but files should not be visible to other anonymous users until approved.
    3. All uploaded files must be owned by the ftp user and ftp group.
    4. SELinux is in Enforcing mode.

    Which combination of actions meets the SELinux requirement for anonymous uploads to work correctly?

    Show answer details

    Correct answer: A

    For anonymous FTP uploads to work with SELinux enforcing, two things are needed: the boolean ftpd_anon_write must be enabled (setsebool -P ftpd_anon_write 1), and the directory where uploads are stored must have the label public_content_rw_t so the FTP daemon has write access.

  2. 2

    You need to configure a new Stratis pool named my_pool using two block devices /dev/sdb and /dev/sdc. Which command correctly initializes this pool on Oracle Linux 8?

    Show answer details

    Correct answer: A

    The stratis CLI tool uses the syntax stratis pool create ... to initialize a new storage pool. Stratis manages the underlying layers automatically.

  3. 3

    A system administrator needs to define a custom audit rule that monitors open system calls on all files within /etc/security/. The rule should tag log entries with the key security_access. Which auditctl command accomplishes this?

    Show answer details

    Correct answer: A

    The -w flag sets a watch on a file system object (directory or file). The -p flag specifies permissions to watch (read, write, attribute change, execute). The -k flag adds a key for searching logs.

  4. 4

    You are preparing to install a group of packages related to 'Development Tools' on an Oracle Linux 8 server. You want to see which packages are included in this group before installing. Which dnf command should you use?

    Show answer details

    Correct answer: A

    dnf group info displays details about a specific package group, including the list of mandatory, default, and optional packages it contains.

  5. 5

    Which TWO of the following statements about Control Groups version 2 (cgroup v2) in Oracle Linux 8 are correct? (Select TWO)

    Show answer details

    Correct answer: A, C

    Cgroup v2 simplifies the architecture by using a single unified hierarchy for all resource controllers, unlike v1 which used separate hierarchies for cpu, memory, etc.

    Systemd is the primary cgroup manager in OL8 and uses three unit types to organize processes: Services (for daemons), Scopes (for ad-hoc groups of processes), and Slices (for hierarchical organization).

  6. 6

    You need to configure the chronyd service to act as an NTP server for the local network 192.168.100.0/24. Which line must be added to /etc/chrony.conf to allow clients from this subnet to query the server?

    Show answer details

    Correct answer: A

    The allow directive in chrony.conf specifies which subnets or hosts are permitted to query the server for time synchronization.

  7. 7

    An administrator deploys a custom web service that is configured to listen on TCP port 8080. The service fails to start, and the journalctl logs show a "Permission denied" error when trying to bind to the port. The system is running in SELinux enforcing mode. The administrator confirms that firewalld is not blocking the port. What is the correct, persistent method to allow the web service to bind to port 8080?

    flowchart TD Start([Start]) --> CheckService{Service fails to start} CheckService --> CheckLogs{journalctl} CheckLogs --> |'Permission Denied'| IsSELinux{SELinux Enforcing?} IsSELinux --> |Yes| IsFirewall{Firewall Blocking?} IsFirewall --> |No| SELinuxPortContext{Check SELinux Port Context} SELinuxPortContext --> Solution[Apply Correct Port Context] Solution --> Restart[Restart Service] Restart --> Success([Success])

    Show answer details

    Correct answer: C

    The issue is that SELinux policy, by default, only allows services with the httpd_t context to bind to ports labeled http_port_t (like 80, 443, 8008, etc.). Port 8080 is typically labeled http_cache_port_t or may not have a web-related label. The correct and persistent solution is to use semanage port to add a new rule to the SELinux policy, labeling port 8080 with the http_port_t type. This allows the web service to bind to it successfully. Disabling SELinux is insecure. Using audit2allow is for cases where no appropriate label exists, but http_port_t is the correct existing label for this purpose. setsebool is for toggling booleans, not for defining port labels.

  8. 8

    You are configuring a new Oracle Linux 8 server that will serve as a high-performance database node. The network team has provisioned a specific static IP address, gateway, and DNS servers. You need to configure the 'eno1' interface using nmcli in a single command line to minimize downtime. Which command successfully creates and activates this connection with the specified parameters?

    Show answer details

    Correct answer: A

    This command correctly adds a new connection profile of type ethernet with manual IPv4 configuration, specifying the address, gateway, and DNS servers in the correct format, and immediately activates it. The syntax for ipv4.dns accepts space-separated IPs within quotes.

Create an account to continue.