1Z0-106 Sample Questions

1Z0-106 Sample Questions & Answers

You'll be tested on firewalld, nftables and SELinux protections, managing users, groups and PAM modules, LVM and software RAID storage, DNF package installs, network configuration, system logging, control groups, container services, and the boot process.

Launch the full 1Z0-106 simulator →

Showing 8 of 17 free samples.

  1. Question 1Beginner

    Understanding and Configuring the Linux Boot Process and Service Administration · Describe the configure systemd system and service manager

    An administrator needs to analyze the boot time of an Oracle Linux 8 server to identify which services are slowing down the startup process. Which command provides a hierarchical view of the critical chain of units, highlighting the time each unit took to initialize and which units delayed the boot?

    Show answer & explanation

    Correct answer: B

    systemd-analyze critical-chain displays a tree of the time-critical chain of units. It shows how much time each unit took to start and highlights units that significantly delayed the boot process.

  2. Question 2Beginner

    Understanding System Configuration options · Configure and maintain kernel parameters using the /proc filesystem and the sysctl utility

    You are managing an Oracle Linux 8 system and need to persistently modify a kernel parameter related to network performance. You want to ensure this setting survives reboots and takes precedence over default system settings. Which is the recommended location to create a new configuration file for this parameter?

    Show answer & explanation

    Correct answer: D

    The /etc/sysctl.d/ directory is the standard location for custom kernel parameter configuration files in Oracle Linux 8. Files are processed in lexicographical order, so prefixing with a high number (like 99) ensures it overrides defaults found in /usr/lib/sysctl.d/.

  3. Question 3Intermediate

    Managing Filesystems and Swap · Create and manage Linux Filesystems - ext, xfs, btrfs

    A critical application requires the xfs filesystem on /dev/mapper/data_vg-app_lv to be expanded while mounted and online. The underlying logical volume has already been extended. Which command must be run to resize the filesystem to occupy the newly available space?

    Show answer & explanation

    Correct answer: A

    The xfs_growfs command is used to resize XFS filesystems. Crucially, it takes the mount point as the argument (e.g., /mnt/app_data), not the device path, and it supports online expansion.

  4. Question 4Intermediate

    Security Enhanced Linux (SELinux) · Describe and configure SELinux modes, policies, and booleans

    You have configured a custom service listening on TCP port 9090. SELinux is in Enforcing mode, and the service fails to bind to the port. You have identified that the port type http_port_t is appropriate for this service. Which command persistently adds port 9090 to the http_port_t SELinux policy?

    Show answer & explanation

    Correct answer: B

    The semanage port command is used to manage network port definitions in the SELinux policy. The -a flag adds a definition, -t specifies the type (http_port_t), and -p specifies the protocol and port number. This change is persistent.

  5. Question 5Advanced

    Managing Linux Security · Create and maintain a chroot jail

    A security audit requires that the fapolicyd service (File Access Policy Daemon) is configured to block execution of any untrusted binaries. After installing the package, what is the correct sequence of steps to enable the service and ensure it starts protecting the system immediately?

    Show answer & explanation

    Correct answer: B

    fapolicyd relies on a rules database. After configuring rules (or using defaults), you must update the internal database using fapolicyd-cli --update before starting the service to ensure it recognizes trusted files. Then enable and start it.

  6. Question 6Intermediate

    Container Services · Describe container concepts and Podman configuration

    You are creating a systemd unit file for a Podman container that needs to start automatically at boot. You have created the container named web_app. Which command generates a systemd unit file that can manage this container using runc directly or through Podman, and handles container restarts properly?

    Show answer & explanation

    Correct answer: A

    The podman generate systemd command creates a systemd unit file for a container. The --new flag ensures that the container is created fresh when the service starts and removed when it stops, which is the recommended practice for reproducibility and stability.

  7. Question 7Advanced

    Managing File Sharing · Describe, configure and maintain the automounter

    Your organization uses LDAP for centralized authentication. You need to configure the autofs service to mount user home directories from an NFS server. The map information is stored in LDAP. Which configuration file must be modified to instruct autofs to look up map information in LDAP?

    Show answer & explanation

    Correct answer: A

    The /etc/nsswitch.conf file controls the order and sources of name service lookups. To enable LDAP for automount maps, you must add or modify the automount: entry to include ldap (e.g., automount: files ldap).

  8. Question 8Advanced

    Managing File Sharing · Describe and configure vsftpd

    Case Study

    An administrator is configuring a new Oracle Linux 8 server to host a secure file transfer service. The requirements are:

    1. The server must use a dedicated 1TB partition mounted at /var/ftp/pub.
    2. Anonymous uploads must be permitted but files should not be visible to other anonymous users until approved.
    3. All uploaded files must be owned by the ftp user and ftp group.
    4. SELinux is in Enforcing mode.

    Which combination of actions meets the SELinux requirement for anonymous uploads to work correctly?

    Show answer & explanation

    Correct answer: A

    For anonymous FTP uploads to work with SELinux enforcing, two things are needed: the boolean ftpd_anon_write must be enabled (setsebool -P ftpd_anon_write 1), and the directory where uploads are stored must have the label public_content_rw_t so the FTP daemon has write access.

Ready for the real thing?

The full 1Z0-106 simulator has every exam-style question, timed mode, and instant scoring.