Linux
Linux fundamentals as a working engineer needs them: processes, filesystems, permissions, users and groups, the boot path, and the /proc and /sys views into the kernel. Nearly every backend, DevOps, and SRE interview leans on some part of this.
part ofLinux & distributionsoverview, primer and where to startread it →on this pageshowhide
explore
- Kernel and Boot Process22 questions
- Boot chain and init handoff6 questions
- Kernel modules6 questions
- /proc, /sys and sysctl5 questions
- User space, kernel space and syscalls5 questions
- Filesystem Hierarchy22 questions
- Filesystem Hierarchy Standard6 questions
- Inodes, links and dentries5 questions
- Mounts and fstab6 questions
- Filesystem types and trade-offs5 questions
- Permissions and Users33 questions
- Mode bits, ownership and umask6 questions
- setuid, setgid and the sticky bit5 questions
- POSIX ACLs5 questions
- Linux capabilities5 questions
- Users, groups and sudo6 questions
- SELinux and AppArmor6 questions
- Processes and Signals27 questions
- Process lifecycle: fork and exec5 questions
- Signals and kill4 questions
- Scheduling, nice and priorities6 questions
- Namespaces and cgroups6 questions
- Virtual memory, swap and the OOM killer6 questions
- Networking Stack28 questions
- Interfaces and the ip command6 questions
- Routing tables and forwarding5 questions
- Netfilter hook points and NAT6 questions
- Name resolution path5 questions
- Sockets and connection state6 questions
- Services and Packages11 questions
- Init models: runlevels and targets5 questions
- Distribution package models6 questions
- Backend Developerroleanchors this topic
- Blockchain Developerroleanchors this topic
- Data Engineerroleanchors this topic
- DevSecOps Engineerroleanchors this topic
- Full Stack Developerroleanchors this topic
- Java Backend Developerroleanchors this topic
- Java SDETroleanchors this topic
- Kotlin Backend Developerroleanchors this topic
- MLOps Engineerroleanchors this topic
- PostgreSQL DBAroleanchors this topic
- QA Engineerroleanchors this topic
- Cyber Security Expertrole
- DevOps / SRE Engineerrole
- Forward Deployed Engineerrole
- Linuxskill
- Network Engineerrole
- Shell & Bashskill
questions
143 · 6 sectionsOn Linux, what is a loadable kernel module, and how does a driver compiled as a module (=m) differ at runtime from the same driver built into the kernel image (=y)?
basics
~20 sA loadable kernel module is kernel code — typically a driver or filesystem — shipped as a separate .ko file and inserted into the running kernel on demand. Code built in with =y is part of the kernel image itself and can never be unloaded.
On Linux, `ls -l /proc/meminfo` reports a size of 0 bytes, yet reading the file returns pages of text. What kind of filesystem is /proc, and where does that content come from?
basics
~20 s/proc is procfs, a virtual filesystem with no storage behind it. The kernel generates each file's contents at the moment a process reads it, so the reported size is 0 while the data returned is a live snapshot of kernel state.
On Linux, what is the difference between user space and kernel space, and by what mechanism does a user-space process get the kernel to do work on its behalf?
basics
~20 sUser space is the unprivileged CPU mode, where a process sees only its own virtual memory and cannot touch hardware; kernel space is the privileged mode. A process crosses over only by issuing a system call, a hardware trap that enters the kernel at one fixed, kernel-chosen entry point.
Walk through what happens on an x86-64 Linux server from power-on until the first long-lived user-space process is running: which component hands off to which, and what is each stage responsible for?
basics
~20 sFirmware initialises the hardware and loads a bootloader; the bootloader loads the compressed kernel plus an initramfs into memory; the kernel unpacks itself, runs the initramfs to reach the real root filesystem, switches onto it, and execs the system's init as PID 1.
On Linux, why does `modprobe ext4` usually succeed where running `insmod` directly on the same ext4 module file fails, and what do depmod and modules.dep have to do with it?
basics
~20 smodprobe resolves dependencies: it looks the module up by name in modules.dep under /lib/modules/<kernel release> and loads everything it needs first, in order. insmod inserts exactly one file, so a module whose prerequisites are missing fails with an unknown-symbol error.
You are handed a shell on an unfamiliar Linux server. Where do you expect a service's configuration, its persistent state and its log files to live, and what is the rule that puts those three things in different top-level directories?
basics
~20 sConfiguration lives under /etc, persistent state under /var/lib and logs under /var/log. The split is by mutability and ownership: /usr holds static package-owned code, /etc holds locally editable configuration, /var holds data the machine writes while it runs.
On a Linux filesystem, what is the difference between a hard link and a symbolic link, and what can each one do that the other cannot?
basics
~20 sA hard link is an extra name for the same inode, so every name is equal and the data survives until the last one is removed. A symbolic link is a separate small file holding a path string, resolved at every access.
An /etc/fstab entry names a disk as /dev/sdb1. Why is that fragile on a Linux server, and how do UUID=, LABEL= and PARTUUID= differ as replacements?
basics
~20 sKernel names like /dev/sdb1 depend on device discovery order, so a new disk or a slow controller can renumber them and mount the wrong filesystem. Prefer UUID= from the filesystem superblock, or PARTUUID= from the partition table.
You build a tool from source on a Linux server and run `make install`. Under the FHS, why does it belong in /usr/local rather than /usr, and when is /opt the right home instead?
basics
~20 s/usr is owned by the distribution's package manager, so an upgrade can overwrite or conflict with anything you drop there. /usr/local is reserved for software the administrator installs and packages never touch. /opt holds self-contained third-party bundles in their own subtree.
On an ext4 filesystem, what does the journal actually protect after an unclean shutdown, and how do the data=ordered, data=writeback and data=journal mount options differ?
basics
~20 sext4's journal protects filesystem metadata consistency, not file contents. The default data=ordered flushes data blocks before committing the metadata that points at them; data=writeback drops that ordering and can expose stale bytes; data=journal journals data too, more slowly.
On Linux, how do capabilities split up root's privilege, and which capability lets a process that is not running as root bind a socket to TCP port 80?
basics
~20 sLinux capabilities break root's all-or-nothing power into more than forty independent privileges that can be granted to a process or an executable one at a time. CAP_NET_BIND_SERVICE is the one that allows binding to ports below 1024.
On a RHEL host, what is the difference between SELinux running in enforcing mode, permissive mode, and being disabled, and why is `setenforce 0` not the same as setting SELINUX=disabled in /etc/selinux/config?
basics
~20 sEnforcing blocks policy violations and logs them. Permissive blocks nothing but still logs every would-be denial. Disabled loads no policy and stops maintaining file labels. setenforce 0 switches to permissive only until reboot; /etc/selinux/config sets the mode chosen at boot.
On Linux, `ls -l` prints a file's mode as a string such as `-rw-r--r--`. Explain what each part of that string means and what the equivalent octal number is.
basics
~20 sThe first character gives the file type; the next nine are three rwx triads for owner, group and others. So -rw-r--r-- is a regular file the owner can read and write while everyone else can only read: octal 644.
On a Linux system, what does each of /etc/passwd, /etc/shadow and /etc/group hold, and why was the password hash moved out of /etc/passwd?
basics
~20 s/etc/passwd holds one line per account — name, UID, primary GID, real name, home directory and login shell — and is world-readable. /etc/shadow holds the password hashes and ageing fields, readable only by root. /etc/group lists groups and their extra members.
You grant a named user write access to a file with `setfacl`, but `getfacl` prints `#effective:r--` beside that entry and the user still cannot write. What is the POSIX ACL mask, and what typically leaves it too restrictive?
basics
~20 sThe mask entry is an upper bound on every named user, named group and the owning group; rights above it are granted but not effective. It is most often narrowed by a later chmod, because on an ACL-bearing file the group-class mode bits map to the mask, not to the owning group.
On a Linux host, what is the difference between a namespace and a cgroup, and which of the two would you use to stop one process starving the machine of memory?
basics
~20 sNamespaces control what a process can see: its own PIDs, mounts, network stack, hostname. Cgroups control how much it may consume: CPU time, memory, I/O, process count. Starving the machine is a resource problem, so the answer is a cgroup.
On Linux, the `kill` command sends SIGTERM by default and `kill -9` sends SIGKILL. What is the difference between the two signals, and why can a process never handle SIGKILL?
basics
~20 sSIGTERM is a polite request: the process can catch it and shut down cleanly. SIGKILL is enforced by the kernel — the target never runs code for it, so buffers, lock files and in-flight work are abandoned as they are.
On a Linux host, a program has finished running but still shows up in the process list as `<defunct>` in state Z. What is that entry, and what makes it go away?
basics
~20 sA zombie is a process that has already terminated but whose parent has not yet collected its exit status. The kernel keeps only its process-table entry, PID and exit code; it disappears as soon as the parent waits on it.
On a Linux server with 32 GB of RAM, `free` reports only about 200 MB free, several gigabytes under buff/cache, and 20 GB available. Is that machine short of memory, and what is the kernel doing with the RAM?
basics
~20 sNo. Linux spends otherwise-idle RAM on page cache for file data and reclaims it on demand, so near-zero free memory is normal and healthy. The number that matters is available, which estimates what a new process could still get.
On Linux, what does a process's nice value control, what range can it take, and why can an ordinary user raise a process's nice value but not lower it again?
basics
~20 sA nice value biases how much CPU a Linux task gets when CPUs are contended. It runs from -20 (most favoured) to 19 (least favoured), default 0. Lowering it needs privilege, so an unprivileged renice is a one-way trip.
What do the `nameserver` lines in /etc/resolv.conf do on a Linux host, and are those servers used as a load-balanced pool or in a fixed order?
basics
~20 sEach nameserver line gives the C library's resolver one DNS server address to query. They are tried strictly in the listed order, not load-balanced: the next one is used only after the previous fails or times out, and glibc reads at most three.
On a Linux host, what does the `default` entry in the output of `ip route show` mean, and what happens to a packet whose destination matches no route in the table at all?
basics
~20 sThe default route is the 0.0.0.0/0 catch-all entry telling the kernel where to send packets that no more specific route matches, normally via a gateway. With no match at all the send fails locally and immediately with ENETUNREACH, "Network is unreachable".
A client opening TCP connections to a Linux host gets an instant "connection refused" on one port, while a connect to another port on the same host hangs for around two minutes before failing. What is the kernel doing differently in each case?
basics
~20 sConnection refused means the SYN reached the host and the kernel answered with a TCP RST because no socket was listening on that port. A hang means no answer came back at all, usually a dropped packet, so the client keeps retransmitting the SYN until it gives up.
On a Linux host, `dig app.example.com` returns the address you expect, but a program running on that same host resolves the name to something else or fails outright. What explains the difference?
basics
~20 sThey use different code paths. dig speaks DNS straight to a nameserver, while applications call getaddrinfo(), which follows the hosts: line of /etc/nsswitch.conf — static files, local modules, then DNS. A source ahead of DNS can answer first.
You run `ip addr add 10.0.0.50/24 dev enp3s0` on a Linux server; the address works immediately, but it is gone after a reboot — and sometimes it disappears minutes later without one. What is happening, and where does the address actually belong?
basics
~20 sip only edits live kernel state, which is never written to disk, so a reboot discards it. Persistence belongs to whichever manager owns the interface — NetworkManager, systemd-networkd, or netplan rendering to one of them — and that manager can also overwrite your address while running.
On a systemd-managed Linux host, what is the difference between `systemctl start nginx` and `systemctl enable nginx`, and what does enabling actually change on disk?
basics
~20 sstart activates a service right now; enable makes it come up automatically at boot. Enabling only creates a symlink so a boot target pulls the unit in — it launches nothing immediately, and starting alone does not survive a reboot.
On a Linux system, what is the difference between the low-level package installer (dpkg on Debian-family systems, rpm on RHEL-family systems) and the higher-level dependency resolver layered on top of it, and why does installing a downloaded .deb or .rpm file directly so often fail?
basics
~20 sLow-level tools (dpkg, rpm) install exactly the one file you hand them and merely report unmet dependencies. The resolver above them (apt, dnf, zypper) reads repository metadata, computes a complete transaction, fetches the missing packages, and only then calls the low-level tool.
When a package manager plans an install or an upgrade on a Debian- or RPM-based Linux host, what problem is its dependency solver actually solving, and what does it mean when it reports unmet or broken dependencies?
basics
~20 sThe solver searches for a set of package versions that satisfies every declared relationship — requires, conflicts, obsoletes, provides — given what is installed plus everything the enabled repositories offer. Unmet means no such set exists; broken means the local database is already inconsistent.
On a systemd host, what is the practical difference between rescue.target and emergency.target, and how do they relate to the old single-user mode?
basics
~20 srescue.target is the successor of single-user mode: basic system initialisation and local filesystems are up, with one root shell and no network or multi-user services. emergency.target is far more minimal — essentially just the root filesystem, often read-only, and a shell, used when the system cannot even reach rescue.
In systemd, what is a target unit, and why is it not simply a renamed SysV runlevel?
basics
~20 sA systemd target is a named unit that groups other units and acts as a synchronisation point. Unlike a SysV runlevel, which was a single number with exactly one value active, many targets are active at once and reaching them is dependency-driven, not a numbered sequence.