skip to content

Linux

Linux fundamentals as a working engineer needs them: processes, filesystems, permissions, users and groups, the boot path, and the /proc and /sys views into the kernel. Nearly every backend, DevOps, and SRE interview leans on some part of this.

part ofLinux & distributionsoverview, primer and where to startread it →
on this pageshow

explore

questions

143 · 6 sections

On Linux, what is a loadable kernel module, and how does a driver compiled as a module (=m) differ at runtime from the same driver built into the kernel image (=y)?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A loadable kernel module is kernel code — typically a driver or filesystem — shipped as a separate .ko file and inserted into the running kernel on demand. Code built in with =y is part of the kernel image itself and can never be unloaded.

open as a page

On Linux, `ls -l /proc/meminfo` reports a size of 0 bytes, yet reading the file returns pages of text. What kind of filesystem is /proc, and where does that content come from?

level: juniorimportance: must knowfreq 70%
basics
~20 s

/proc is procfs, a virtual filesystem with no storage behind it. The kernel generates each file's contents at the moment a process reads it, so the reported size is 0 while the data returned is a live snapshot of kernel state.

open as a page

On Linux, what is the difference between user space and kernel space, and by what mechanism does a user-space process get the kernel to do work on its behalf?

level: juniorimportance: must knowfreq 72%
basics
~20 s

User space is the unprivileged CPU mode, where a process sees only its own virtual memory and cannot touch hardware; kernel space is the privileged mode. A process crosses over only by issuing a system call, a hardware trap that enters the kernel at one fixed, kernel-chosen entry point.

open as a page

Walk through what happens on an x86-64 Linux server from power-on until the first long-lived user-space process is running: which component hands off to which, and what is each stage responsible for?

level: middleimportance: must knowfreq 72%
basics
~20 s

Firmware initialises the hardware and loads a bootloader; the bootloader loads the compressed kernel plus an initramfs into memory; the kernel unpacks itself, runs the initramfs to reach the real root filesystem, switches onto it, and execs the system's init as PID 1.

open as a page

On Linux, why does `modprobe ext4` usually succeed where running `insmod` directly on the same ext4 module file fails, and what do depmod and modules.dep have to do with it?

level: middleimportance: must knowfreq 60%
basics
~20 s

modprobe resolves dependencies: it looks the module up by name in modules.dep under /lib/modules/<kernel release> and loads everything it needs first, in order. insmod inserts exactly one file, so a module whose prerequisites are missing fails with an unknown-symbol error.

open as a page

You are handed a shell on an unfamiliar Linux server. Where do you expect a service's configuration, its persistent state and its log files to live, and what is the rule that puts those three things in different top-level directories?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Configuration lives under /etc, persistent state under /var/lib and logs under /var/log. The split is by mutability and ownership: /usr holds static package-owned code, /etc holds locally editable configuration, /var holds data the machine writes while it runs.

open as a page

An /etc/fstab entry names a disk as /dev/sdb1. Why is that fragile on a Linux server, and how do UUID=, LABEL= and PARTUUID= differ as replacements?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Kernel names like /dev/sdb1 depend on device discovery order, so a new disk or a slow controller can renumber them and mount the wrong filesystem. Prefer UUID= from the filesystem superblock, or PARTUUID= from the partition table.

open as a page

You build a tool from source on a Linux server and run `make install`. Under the FHS, why does it belong in /usr/local rather than /usr, and when is /opt the right home instead?

level: middleimportance: must knowfreq 55%
basics
~20 s

/usr is owned by the distribution's package manager, so an upgrade can overwrite or conflict with anything you drop there. /usr/local is reserved for software the administrator installs and packages never touch. /opt holds self-contained third-party bundles in their own subtree.

open as a page

On an ext4 filesystem, what does the journal actually protect after an unclean shutdown, and how do the data=ordered, data=writeback and data=journal mount options differ?

level: middleimportance: must knowfreq 62%
basics
~20 s

ext4's journal protects filesystem metadata consistency, not file contents. The default data=ordered flushes data blocks before committing the metadata that points at them; data=writeback drops that ordering and can expose stale bytes; data=journal journals data too, more slowly.

open as a page

On Linux, how do capabilities split up root's privilege, and which capability lets a process that is not running as root bind a socket to TCP port 80?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Linux capabilities break root's all-or-nothing power into more than forty independent privileges that can be granted to a process or an executable one at a time. CAP_NET_BIND_SERVICE is the one that allows binding to ports below 1024.

open as a page

On a RHEL host, what is the difference between SELinux running in enforcing mode, permissive mode, and being disabled, and why is `setenforce 0` not the same as setting SELINUX=disabled in /etc/selinux/config?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Enforcing blocks policy violations and logs them. Permissive blocks nothing but still logs every would-be denial. Disabled loads no policy and stops maintaining file labels. setenforce 0 switches to permissive only until reboot; /etc/selinux/config sets the mode chosen at boot.

open as a page

On Linux, `ls -l` prints a file's mode as a string such as `-rw-r--r--`. Explain what each part of that string means and what the equivalent octal number is.

level: juniorimportance: must knowfreq 82%
basics
~20 s

The first character gives the file type; the next nine are three rwx triads for owner, group and others. So -rw-r--r-- is a regular file the owner can read and write while everyone else can only read: octal 644.

open as a page

On a Linux system, what does each of /etc/passwd, /etc/shadow and /etc/group hold, and why was the password hash moved out of /etc/passwd?

level: juniorimportance: must knowfreq 74%
basics
~20 s

/etc/passwd holds one line per account — name, UID, primary GID, real name, home directory and login shell — and is world-readable. /etc/shadow holds the password hashes and ageing fields, readable only by root. /etc/group lists groups and their extra members.

open as a page

You grant a named user write access to a file with `setfacl`, but `getfacl` prints `#effective:r--` beside that entry and the user still cannot write. What is the POSIX ACL mask, and what typically leaves it too restrictive?

level: middleimportance: must knowfreq 48%
basics
~20 s

The mask entry is an upper bound on every named user, named group and the owning group; rights above it are granted but not effective. It is most often narrowed by a later chmod, because on an ACL-bearing file the group-class mode bits map to the mask, not to the owning group.

open as a page

On a Linux host, what is the difference between a namespace and a cgroup, and which of the two would you use to stop one process starving the machine of memory?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Namespaces control what a process can see: its own PIDs, mounts, network stack, hostname. Cgroups control how much it may consume: CPU time, memory, I/O, process count. Starving the machine is a resource problem, so the answer is a cgroup.

open as a page

On Linux, the `kill` command sends SIGTERM by default and `kill -9` sends SIGKILL. What is the difference between the two signals, and why can a process never handle SIGKILL?

level: juniorimportance: must knowfreq 85%
basics
~20 s

SIGTERM is a polite request: the process can catch it and shut down cleanly. SIGKILL is enforced by the kernel — the target never runs code for it, so buffers, lock files and in-flight work are abandoned as they are.

open as a page

On a Linux host, a program has finished running but still shows up in the process list as `<defunct>` in state Z. What is that entry, and what makes it go away?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A zombie is a process that has already terminated but whose parent has not yet collected its exit status. The kernel keeps only its process-table entry, PID and exit code; it disappears as soon as the parent waits on it.

open as a page

On a Linux server with 32 GB of RAM, `free` reports only about 200 MB free, several gigabytes under buff/cache, and 20 GB available. Is that machine short of memory, and what is the kernel doing with the RAM?

level: juniorimportance: must knowfreq 72%
basics
~20 s

No. Linux spends otherwise-idle RAM on page cache for file data and reclaims it on demand, so near-zero free memory is normal and healthy. The number that matters is available, which estimates what a new process could still get.

open as a page

On Linux, what does a process's nice value control, what range can it take, and why can an ordinary user raise a process's nice value but not lower it again?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A nice value biases how much CPU a Linux task gets when CPUs are contended. It runs from -20 (most favoured) to 19 (least favoured), default 0. Lowering it needs privilege, so an unprivileged renice is a one-way trip.

open as a page

What do the `nameserver` lines in /etc/resolv.conf do on a Linux host, and are those servers used as a load-balanced pool or in a fixed order?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Each nameserver line gives the C library's resolver one DNS server address to query. They are tried strictly in the listed order, not load-balanced: the next one is used only after the previous fails or times out, and glibc reads at most three.

open as a page

On a Linux host, what does the `default` entry in the output of `ip route show` mean, and what happens to a packet whose destination matches no route in the table at all?

level: juniorimportance: must knowfreq 75%
basics
~20 s

The default route is the 0.0.0.0/0 catch-all entry telling the kernel where to send packets that no more specific route matches, normally via a gateway. With no match at all the send fails locally and immediately with ENETUNREACH, "Network is unreachable".

open as a page

A client opening TCP connections to a Linux host gets an instant "connection refused" on one port, while a connect to another port on the same host hangs for around two minutes before failing. What is the kernel doing differently in each case?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Connection refused means the SYN reached the host and the kernel answered with a TCP RST because no socket was listening on that port. A hang means no answer came back at all, usually a dropped packet, so the client keeps retransmitting the SYN until it gives up.

open as a page

On a Linux host, `dig app.example.com` returns the address you expect, but a program running on that same host resolves the name to something else or fails outright. What explains the difference?

level: middleimportance: must knowfreq 56%
basics
~20 s

They use different code paths. dig speaks DNS straight to a nameserver, while applications call getaddrinfo(), which follows the hosts: line of /etc/nsswitch.conf — static files, local modules, then DNS. A source ahead of DNS can answer first.

open as a page

You run `ip addr add 10.0.0.50/24 dev enp3s0` on a Linux server; the address works immediately, but it is gone after a reboot — and sometimes it disappears minutes later without one. What is happening, and where does the address actually belong?

level: middleimportance: must knowfreq 62%
basics
~20 s

ip only edits live kernel state, which is never written to disk, so a reboot discards it. Persistence belongs to whichever manager owns the interface — NetworkManager, systemd-networkd, or netplan rendering to one of them — and that manager can also overwrite your address while running.

open as a page

On a systemd-managed Linux host, what is the difference between `systemctl start nginx` and `systemctl enable nginx`, and what does enabling actually change on disk?

level: juniorimportance: must knowfreq 75%
basics
~20 s

start activates a service right now; enable makes it come up automatically at boot. Enabling only creates a symlink so a boot target pulls the unit in — it launches nothing immediately, and starting alone does not survive a reboot.

open as a page

On a Linux system, what is the difference between the low-level package installer (dpkg on Debian-family systems, rpm on RHEL-family systems) and the higher-level dependency resolver layered on top of it, and why does installing a downloaded .deb or .rpm file directly so often fail?

level: juniorimportance: must knowfreq 65%
basics
~20 s

Low-level tools (dpkg, rpm) install exactly the one file you hand them and merely report unmet dependencies. The resolver above them (apt, dnf, zypper) reads repository metadata, computes a complete transaction, fetches the missing packages, and only then calls the low-level tool.

open as a page

When a package manager plans an install or an upgrade on a Debian- or RPM-based Linux host, what problem is its dependency solver actually solving, and what does it mean when it reports unmet or broken dependencies?

level: middleimportance: must knowfreq 55%
basics
~20 s

The solver searches for a set of package versions that satisfies every declared relationship — requires, conflicts, obsoletes, provides — given what is installed plus everything the enabled repositories offer. Unmet means no such set exists; broken means the local database is already inconsistent.

open as a page

On a systemd host, what is the practical difference between rescue.target and emergency.target, and how do they relate to the old single-user mode?

level: middleimportance: should knowfreq 42%
basics
~20 s

rescue.target is the successor of single-user mode: basic system initialisation and local filesystems are up, with one root shell and no network or multi-user services. emergency.target is far more minimal — essentially just the root filesystem, often read-only, and a shell, used when the system cannot even reach rescue.

open as a page

In systemd, what is a target unit, and why is it not simply a renamed SysV runlevel?

level: middleimportance: should knowfreq 60%
basics
~20 s

A systemd target is a named unit that groups other units and acts as a synchronisation point. Unlike a SysV runlevel, which was a single number with exactly one value active, many targets are active at once and reaching them is dependency-driven, not a numbered sequence.

open as a page