certslothcertsloth
← EX200 overview

Red Hat Certified System Administrator / STUDY TOOLS

EX200 quick review

RHEL 10 objectives include Flatpak. Do not substitute an older RHEL 9 syllabus: the current public list does not make container administration a separate objective. Verify your booked exam version.

Reviewed 10 October 2026 against the linked published scope. Performance exam based on RHEL 10. Practice on disposable RHEL systems; memorising descriptions alone is insufficient.

Memory hook: Make it work now, make it persist, reboot and prove both.

Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.

Shell, software and running systems

  • Verify identity and path with id, pwd and ls -la before modification. Quote paths/variables; understand glob expansion. > replaces output, >> appends, 2> redirects errors and | pipes stdout. Order matters when combining descriptors.
  • grep, find, sort, cut, head, tail and text editors locate/transform data. A hard link references the same inode; a symbolic link stores a pathname and can dangle. Use man, info and packaged documentation to check exact syntax.
  • Shell scripts need correct interpreter, inputs, quoting, tests, branches, loops and exit status. $1 is the first argument; $? is the prior command's exit status. Test both success and failure paths.
  • RPM queries/verifies packages; DNF resolves repositories/dependencies. Configure trusted repositories before installing. Flatpak uses remotes, applications and runtimes; distinguish per-user from system-wide installation scope.
  • systemctl start changes current service state; enable configures boot activation; enable --now does both. Inspect status and journalctl -u NAME -b before changing files. Configure journal persistence when required.
  • Use ps, top, free, vmstat and df to locate the actual resource constraint. nice/renice adjust scheduling priority under privilege rules; tuned profiles apply supported system tuning. Killing a process is not a durable service fix.

Identity, permissions and security

  • Manage users/groups and supplementary membership deliberately. usermod -aG appends memberships; omitting -a with -G can replace them. chage governs password aging; use authorized sudo configuration for privilege.
  • File rwx and directory rwx have different effects: directory execute allows traversal, read lists names and write changes directory entries. Ownership, group, mode and applicable ACLs combine with mount/security policy.
  • A setgid directory helps inherit its group; sticky bit restricts deletion in suitable shared directories. Umask removes default permissions from creation modes; it does not rewrite existing files.
  • SELinux is an independent control layer. Inspect getenforce, ls -Z, ps -Z and relevant logs. Persistent file-context rules plus restorecon fix labels; chcon alone may not survive relabeling. Manage required port types and booleans rather than disabling enforcement.
  • SSH uses client private keys and server authorized public keys. Protect ownership/modes and verify authentication before removing an alternate access path. scp/sftp transfer through SSH.

Storage, networking and boot persistence

  • Inspect lsblk -f, blkid, findmnt, pvs, vgs and lvs. LVM layers PV → VG → LV → filesystem → mount. Extending an LV and growing its filesystem are distinct operations; do not format an existing data filesystem during expansion.
  • XFS grows mounted and cannot shrink; ext4 has different supported procedures. Create appropriate VFAT/ext4/XFS only on the intended new target. Prefer stable UUID/label references in /etc/fstab; validate before reboot.
  • Swap needs initialization, activation and persistence. NFS requires export, network and client configuration; autofs mounts on demand through configured maps. Inspect mount state and permissions from the intended user.
  • NetworkManager profiles preserve IPv4/IPv6, gateway and DNS settings. Inspect nmcli, ip address, ip route and name resolution. A temporary ip command does not replace persistent configuration.
  • firewalld runtime and permanent rules differ. Assign the right zone/interface and permitted service/port, reload appropriately and test from a client. Opening a port does not start a listener.
  • systemctl get-default/set-default concern boot targets; isolate changes current target. Follow supported bootloader/recovery procedures and ensure SELinux labeling remains valid after recovery.
  • Cron schedules repeating work, at one-time work and systemd timers service activation. Check user/environment, logs and persistence. Chrony maintains time; inspect sources/tracking.

Practical finish

  • Check exact requested state, ownership, access, service health and reboot behavior. A correct-looking file that is ignored by the system does not satisfy the task.
  • RHEL 10 is the published EX200 target here. Do not substitute an older container-heavy outline for the current software/Flatpak and administration objectives.

Final active recall

1. Does systemctl start guarantee activation after reboot?

No. Enablement is a separate setting.

2. SELinux blocks a service despite permissive Unix modes. Disable SELinux?

No. Diagnose labels, port types, booleans and policy, then apply the appropriate persistent fix.

3. What can usermod -G without -a do?

Replace supplementary group memberships instead of adding to them.

4. Can XFS be shrunk?

No. Plan storage changes accordingly.

5. What is the strongest final check of persistent administration tasks?

Reboot the practice system, then verify mounts, networking, services, security and required behavior.

Sources and further practice

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Shell Tools and Scripts

Memory hook: Quote paths; check status; know where output goes.

Must remember

pwd, ls -la, cd, mkdir, cp, mv and rm manipulate the filesystem. Quote expansions such as "$path" so spaces and wildcard characters are not interpreted unexpectedly. man, info and /usr/share/doc are local references; use man -k to find a topic.

Syntax Meaning
command >file / >>file Replace / append standard output.
2>errors Redirect standard error.
>out 2>&1 Send both streams to out; order matters.
`a b`
`grep -E '^(error warn)' file`
tar -czf backup.tar.gz directory Archive and gzip; list with tar -tf before extracting with -xf.

Gzip and bzip2 compress streams; tar bundles files and metadata. A hard link is another name for the same inode on the same filesystem; a symbolic link stores a path and may cross filesystems or become dangling. ln source hard and ln -s target soft differ accordingly.

Scripts need an interpreter line and execute permission when run directly. $1 is the first argument, $? the previous exit status; zero conventionally means success. $(command) captures output. A simple pattern:

#!/bin/bash
if [ -f "$1" ]; then
  for word in ready set go; do
    printf '%s\n' "$word"
  done
else
  printf '%s\n' 'File not found' >&2
  exit 1
fi

Use ssh user@host for a remote shell and su - user for a login-like user environment. Edit with a terminal editor and verify the saved content; an unsaved editor buffer is not configuration.

Choose under exam pressure

Requirement Choice and reason
Find matching text grep with the appropriate basic or extended expression.
Preserve file identity under another name Hard link, provided both names can share a filesystem.
Capture output in a script Command substitution, with quoted use of the result.

Traps

  • A pipe does not automatically include stderr.
  • A symlink does not keep its target alive after the target is removed.

Practise this topic

02 · Users, Permissions and SELinux

Memory hook: Identity, mode bits and labels must all agree.

Must remember

  • useradd, usermod, userdel, groupadd and groupmod manage local accounts. id USER verifies identity and supplementary groups; getent passwd USER respects configured identity sources. Use usermod -aG to append group membership; omitting -a can replace existing supplementary groups.
  • passwd changes passwords and chage -l USER inspects aging. Locking a password does not necessarily revoke SSH keys or existing sessions. Use sudo for delegated privilege; edit sudoers through visudo to check syntax.
  • For a regular file, r/w/x mean read/change/execute. For a directory, they mean list names/change entries/traverse. Deleting a file depends mainly on its parent directory permissions, with sticky-bit rules when present.
  • chmod 640 file gives owner rw, group r, others none. chown user:group file changes ownership. Setgid on a shared directory helps new files inherit its group; sticky limits removal of other users' entries. umask removes default permission bits; it does not add execute permission to ordinary newly created files.
  • SELinux adds mandatory policy checks beyond Unix permissions. Enforcing blocks prohibited actions; permissive records denials without enforcing them. Inspect getenforce, ls -Z, ps -eZ and audit messages.
  • restorecon restores configured labels. semanage fcontext defines persistent path-label rules; chcon alone may be overwritten by relabeling. semanage port maps a nonstandard service port to its allowed type. getsebool inspects booleans; setsebool -P persists a supported policy toggle.

Practical drill: create a shared directory for a group, then explain why a web service still needs the correct SELinux type even when Unix permissions allow reading.

Choose under exam pressure

Requirement Choice and reason
Group-shared directory Correct group ownership, directory permissions and setgid where needed.
Service denied despite mode bits Inspect SELinux labels and AVC denials.
Permanent label for a custom web path Define an fcontext rule, then apply restorecon.

Traps

  • Do not solve a labeling error by disabling SELinux.
  • chmod 777 does not bypass SELinux and usually grants excessive access.

Practise this topic

03 · Software, Services and Logs

Memory hook: Installed is not running; running is not enabled.

Must remember

RPM is the package format/database; rpm -q checks installed packages and rpm -V verifies recorded file properties. DNF resolves dependencies and repository metadata. dnf repolist, dnf info, dnf install, dnf remove and dnf upgrade serve different jobs. Repository definitions normally live under /etc/yum.repos.d/; understand base URLs, enabled flags and signature checking.

Flatpak applications use remotes, application IDs and runtimes. flatpak remotes, flatpak search, flatpak list, flatpak install and flatpak uninstall manage this separate ecosystem. User installations and system installations differ; the account and scope must match the task.

systemctl start affects the present; enable configures boot activation. enable --now does both. disable does not automatically stop a running service; mask prevents activation via its normal unit path. Use status, is-active, is-enabled and list-units to verify. After editing a unit or drop-in, run daemon-reload before restarting the service.

journalctl -u SERVICE -b narrows logs to one service and boot; journalctl -b -1 reads the previous boot when retained. Persistent journaling requires appropriate journal storage configuration and a persistent journal directory; otherwise reboot may discard useful evidence. Traditional logs under /var/log remain relevant.

Use ps, top, free, vmstat and df to separate CPU, memory and storage pressure. kill -TERM requests graceful termination; SIGKILL cannot be handled for cleanup. A higher nice value means lower scheduling priority. nice starts with an adjustment; renice changes one. Inspect tuned-adm active and available profiles before selecting a workload-specific tuning profile.

Choose under exam pressure

Requirement Choice and reason
Service must survive reboot Enable it and verify its boot behavior.
Find startup failure Service status plus its boot journal.
Install an application from a Flatpak remote Use Flatpak in the requested user/system scope, not DNF.

Traps

  • Masking is stronger than disabling.
  • Installing a package does not prove its daemon is configured or listening.

Practise this topic

04 · Storage, Filesystems and Persistent Mounts

Memory hook: Disk to PV to VG to LV to filesystem to mount.

Must remember

Inspect before modifying: lsblk -f, blkid, findmnt, pvs, vgs and lvs reveal the device graph. A partition table such as GPT divides a disk; creating or formatting the wrong device destroys data. Practice only on disposable disks.

LVM layers physical volumes into a volume group, then allocates logical volumes. pvcreate, vgcreate/vgextend and lvcreate operate at those layers. Extending the LV alone does not necessarily grow the filesystem. lvextend -r can resize the supported filesystem as well; understand the underlying operation and available free extents.

XFS can grow while mounted and cannot shrink. ext4 supports growth and can shrink while unmounted with the correct sequence. Never shrink an LV below its filesystem. VFAT suits compatibility but lacks normal Unix ownership/permission semantics; mount options supply effective access behavior.

An ephemeral mount command does not survive reboot. /etc/fstab records source, mountpoint, filesystem type, options, dump and fsck fields. UUIDs or filesystem labels avoid unstable device-name assumptions. Test a change with findmnt --verify and an appropriate mount check before reboot; a bad required mount can interrupt boot.

Swap can use a suitable partition or LV: initialise it with mkswap, activate with swapon, verify with swapon --show, and configure persistence. Do not reinitialise a device containing useful data.

For NFS, match server export, network access and client mount options. autofs uses maps to mount paths on demand and expire idle mounts; verify by accessing the trigger path, not only looking at an idle mount table. Ownership IDs and permissions still matter on shared storage.

Choose under exam pressure

Requirement Choice and reason
Add capacity without deleting data Extend the correct LVM layers and filesystem after inspection.
Mount after reboot Use a tested fstab entry with a stable source identifier.
Mount NFS only when used Configure autofs maps and test path access.

Traps

  • XFS does not support shrinking.
  • A mounted directory can hide existing files beneath the mountpoint without deleting them.

Practise this topic

05 · Networking, SSH and Firewalls

Memory hook: Address, route, name, socket, policy.

Must remember

Diagnose in layers. ip -br address shows addresses; ip route/ip -6 route show routes; getent hosts NAME tests configured name resolution; ss -lntup identifies listening sockets. A successful ping does not prove a TCP service works.

NetworkManager connection profiles preserve settings. nmcli connection show lists profiles; nmcli device status shows devices. Know how to set IPv4/IPv6 addresses, prefix, gateway, DNS and automatic activation on the intended profile, then activate and verify it. A temporary ip address add is not a persistent profile. A hostname can be set with hostnamectl; /etc/hosts and DNS resolve names through configured lookup order.

firewalld assigns connections/interfaces to zones. Services bundle ports; explicit port rules name port and protocol. Runtime changes affect now; --permanent changes saved configuration and needs a reload to become runtime state. A reload can discard unsaved runtime rules. Check --get-active-zones, --list-all and both runtime/permanent settings for the correct zone.

SSH key authentication uses a private key on the client and a public key in the server account's authorized keys. Protect ownership and modes of the home directory, .ssh and authorized_keys; SELinux labels also matter. Validate daemon syntax with sshd -t before a controlled reload. Keep a recovery session when changing remote connectivity in a practice VM.

scp and sftp transfer data through SSH. Confirm source/destination syntax and preserve the correct owner and labels afterward. A running service, enabled boot unit, listening address, firewall rule and valid authentication are independent checks.

Choose under exam pressure

Requirement Choice and reason
Persistent static addressing Modify and activate the NetworkManager profile.
Port works until reboot Check saved firewalld and service activation settings.
Host resolves but connection fails Check routes, listener address, firewall and authentication.

Traps

  • Opening a firewall port does not make an application listen.
  • A rule in the wrong zone may have no effect on the intended interface.

Practise this topic

06 · Boot, Scheduled Work and Recovery

Memory hook: Make it work now, at boot and after failure.

Must remember

systemd targets group units. get-default inspects the default boot target; set-default changes future boots; isolate transitions the running system and can stop unrelated services. Know multi-user, graphical, rescue and emergency behavior rather than treating every target as a simple runlevel synonym.

The bootloader loads a kernel and initial RAM filesystem before the real root filesystem is mounted. For authorised recovery on a disposable RHEL VM, practise interrupting boot, editing kernel arguments, entering the supported recovery environment, remounting the necessary root filesystem writable and changing the intended configuration. Password recovery may require a chroot and subsequent SELinux relabel. Firmware, bootloader passwords or encrypted storage can change the process: do not memorise one sequence as universal.

Use grubby to inspect or manage supported kernel arguments and keep boot configuration consistent with the system's bootloader layout. A working current boot is not proof that changed boot arguments will work next time.

at schedules a one-time job; inspect pending jobs with atq. cron repeats using minute, hour, day-of-month, month and day-of-week fields. User crontabs and system crontabs differ because system entries include the execution user. Jobs run with a limited environment; use absolute paths and handle output.

systemd timers activate service units using calendar or monotonic timing. systemctl list-timers verifies scheduling. Persistent calendar timers can catch a missed run when configured accordingly. Enable the timer, not merely the one-shot service.

chrony synchronises time; inspect chronyc sources and chronyc tracking. The daemon running is not proof of synchronisation. Correct time supports authentication, certificates and trustworthy logs.

Practical finish: verify changes, reboot the practice VM, then retest mounts, network access, services, SELinux and scheduled work. Persistent results are part of EX200 preparation.

Choose under exam pressure

Requirement Choice and reason
One-off future task at; verify the queue and execution user.
Service-integrated scheduled task A systemd timer activating a service.
Wrong time despite running daemon Inspect selected time source, reachability and tracking status.

Traps

  • set-default does not immediately isolate the running system.
  • An enabled timer with a broken service command still fails its job.

Practise this topic

Search across every published topic.