Study guide · Core notes

Linux Essentials and LPIC-1: commands and files

Reference notes for the facts both exams keep returning to: the shell, permissions, packages, boot targets, filesystems, users, logs, client networking, and SSH.

Essentials 2.0 · LPIC-1 5.0101-500 and 102-500Reviewed October 9, 2026

How to read these notes: Unmarked items sit on the published Linux Essentials version 2.0 objectives or the LPIC-1 version 5.0 objectives. Items tagged Extra are job context the objective list does not require. New to the exams? Start with the overview for weights and the version notice.

Shell, paths, and text

Essentials topics 012–013 and LPIC-1 topic 103. Bash is the shell both exams assume.

Shell tokens and text tools that show up on both certificates.
ItemWhat it does
PATHColon-separated directories searched for commands. The current directory is usually absent, so a local script is ./script.sh.
QuotingSingle quotes block expansion. Double quotes allow $variables. Leave globs unquoted only when you want the shell to expand them.
man, --helpman ls is the full manual. -h and --help print a short usage summary. Extra docs often live in /usr/share/doc/.
|, >, 2>A pipe connects standard output to the next command. > replaces a file. >> appends. 2> redirects standard error. 2>&1 sends errors to the same place as output.
grep -EExtended regular expressions. . is any character, * repeats the previous item, [] is a set, and ? is optional in extended syntax.
tar -czfCreates a gzip tar archive. Extract with tar -xzf. zip and unzip are a separate format. bzip2 and xz are other compressors.

Scripts: A script starts with #!/bin/bash. $1 is the first argument, $# is the count, $? is the previous exit status, and 0 means success. An if can test -f for a regular file or compare strings with =. A for loop walks a list or a glob. LPIC-1 adds while, case, and tests in [ ].

vi, the exam editor

LPIC-1 objective 103.8 expects vi. Press i to insert, Esc to return to command mode, :w to write, :q to quit, and :q! to quit without saving. dd deletes a line, yy copies it, and p pastes. /pattern searches. nano is enough for Linux Essentials awareness; it is not a substitute for vi on exam 101.

Processes and signals

ps and top show processes. free shows memory. End a job with SIGTERM (15) first: kill PID. SIGKILL (9) cannot be caught. & backgrounds a job, jobs lists them, and nohup keeps a job after logout. nice starts a process with a priority from -20 (highest) to 19 (lowest). The default is 0. Only root can raise priority.

Permissions, owners, and links

Essentials 015.3–015.4 and LPIC-1 104.5–104.6.

Permission bits and the commands that change them.
FactMeaning
4, 2, 1Read, write, execute. Add them for owner, group, and others. 755 is rwxr-xr-x. 644 is rw-r--r--.
Directory executeYou need execute to enter a directory with cd. Read lets you list names. Write lets you create and delete names inside it.
chmod, chownchmod changes mode. chown ada:staff file sets owner ada and group staff. You usually need root.
SUID, SGID, stickySpecial bits are 4, 2, and 1 in a fourth digit. 4755 is SUID. 1777 is the usual mode of /tmp: sticky, so only the owner can delete a file there.
Linksln makes a hard link: same inode, same filesystem, not for directories. ln -s makes a symlink that can cross filesystems and can point at a missing path.

Packages, shared libraries, and boot

LPIC-1 topics 101 and 102. Essentials only needs awareness of the package tools and of systemctl.

From firmware to a target

Firmware (BIOS or UEFI) runs the boot loader. GRUB loads the kernel and initramfs. The kernel starts PID 1, which on current systems is systemd. dmesg shows the kernel ring buffer. journalctl -b shows the current boot. SysVinit uses runlevels and /etc/inittab. Upstart is awareness only.

systemctl get-default shows the boot target. multi-user.target is multi-user text. graphical.target starts a display manager. rescue.target is single-user style maintenance. Change the default with systemctl set-default. shutdown -h now halts, shutdown -r now reboots, and wall warns logged-in users.

GRUB and the disk layout

grub-install writes the boot loader. grub-mkconfig rebuilds grub.cfg. Older GRUB used menu.lst or grub.conf. A UEFI system needs an EFI System Partition. Keep /boot where the firmware can read it. LVM groups physical volumes into a volume group and carves out logical volumes. Swap can be a partition or a file; mkswap and swapon enable it.

apt, dpkg, dnf, and rpm

Debian: dpkg -i installs a file, dpkg -l lists packages, dpkg -S finds which package owns a file. apt update refreshes the index from /etc/apt/sources.list. apt install fetches dependencies. RPM: rpm -q queries, rpm -qf finds the owner of a file, dnf install resolves dependencies from files in /etc/yum.repos.d/.

Libraries and guests

ldd lists shared libraries a binary needs. ldconfig rebuilds the cache from /etc/ld.so.conf. LD_LIBRARY_PATH adds search directories for one process. A cloned virtual machine must get new SSH host keys and a new D-Bus machine id. cloud-init is the usual first-boot tool on a cloud image. Guest drivers, not the hypervisor, are what exam 102.6 asks about.

Filesystems and the hierarchy

LPIC-1 topic 104. Unmount a filesystem before you check it.

Disk commands and the directories exams expect you to place files in.
ItemRole
lsblk, blkidList block devices, and print filesystem UUIDs and types. Prefer UUID in /etc/fstab so a renamed disk does not break boot.
mkfs.ext4, mkfs.xfsCreate a filesystem. VFAT and exFAT are for disks shared with other operating systems. Btrfs features are awareness: multiple devices, compression, and snapshots.
mount, umountAttach and detach. mount -a mounts everything in fstab. Do not run fsck or xfs_repair on a mounted filesystem.
/etc, /var, /homeConfiguration, changing data such as logs, and user homes. /usr holds shareable programs. /tmp is cleared and sticky. /proc and /sys are kernel views, not disks.
find, locatefind walks the tree now. locate searches a database that updatedb refreshes. which and type find commands. whereis also looks for manuals.

Users, groups, and scheduled jobs

LPIC-1 topic 107. Objective 107.1 is weight 5, the heaviest item on either exam.

Account files and the tools that edit them safely.
File or commandWhat it stores or does
/etc/passwdName, UID, GID, description, home, shell. UID 0 is root. The password field is x when hashes live in shadow.
/etc/shadowHash and aging. Root-only. chage reads and sets aging. passwd changes the password.
/etc/groupGroup name, GID, and members. /etc/skel is copied into a new home directory.
useradd, usermod, userdelCreate, change, and remove accounts. usermod -L locks an account. getent passwd name reads the account, including network sources.
crontab -eEdits your crontab. Fields are minute, hour, day of month, month, day of week. System jobs also live in /etc/cron.d and the cron.hourly through cron.monthly directories.
atRuns a command once. atq lists jobs and atrm removes one. Access is controlled by /etc/at.allow and /etc/at.deny.

Locale: LANG sets the default language and encoding. LC_ALL overrides the other LC_ variables. localectl and locale show the active values. Time zone data lives under /usr/share/zoneinfo. timedatectl sets the zone on systemd systems. systemd timers are Extra: exam 107.2 is cron and at.

Time, logging, mail, and printing

LPIC-1 topic 108. Know the client side, not a full mail-server build.

Clock

The hardware clock and the system clock can disagree. hwclock reads the hardware clock. timedatectl shows whether NTP is on. chrony and systemd-timesyncd are the usual clients. Store servers in UTC and let the zone offset handle local time.

Logs

rsyslog writes text files such as /var/log/syslog or /var/log/messages, and auth logs in /var/log/auth.log or /var/log/secure. A rule names a facility, a priority, and a file. logger sends a test message. journalctl -u ssh shows the journal for one unit. logrotate renames and compresses old files.

Mail queue

LPIC-1 expects the idea of an MTA such as Postfix, not mailbox hosting. mailq lists the queue. /etc/aliases maps addresses, and newaliases rebuilds the database. ~/.forward redirects one user’s mail.

CUPS

Printing goes through CUPS. lp and lpr submit a job, lpstat and lpq show the queue, and lprm or cancel removes a job. Configuration lives under /etc/cups.

Client networking and name resolution

Essentials 014.4 and LPIC-1 topic 109. This is the client, not routing design.

Commands and files for an interface, a route, and DNS.
ItemUse it when
ip addr, ip routeShow addresses and the routing table. ip link shows whether the interface is up. These replace the older ifconfig and route commands, which still appear in some older labs.
ssShow sockets. ss -tulpn lists listening TCP and UDP ports and the process. Exam 110.1 also names netstat for the same kind of check.
/etc/resolv.confResolver name servers. /etc/hosts is checked according to /etc/nsswitch.conf. host and dig query DNS. resolvectl is the systemd-resolved client.
Persistent configDebian can use /etc/network/interfaces. NetworkManager uses nmcli. systemd-networkd uses .network files. The exam accepts the tool the distribution actually uses, as long as the address survives a reboot.
ping, tracepathping tests reachability with ICMP. tracepath or traceroute shows hops. A failure of ping does not by itself prove DNS is broken; test the name and the address separately.

Host security, sudo, and encryption

Essentials 015.1 and LPIC-1 topic 110.

sudo and limits

Edit /etc/sudoers with visudo so a syntax error cannot lock you out. sudo -l lists what the current user may run. ulimit caps processes, file size, and memory for a shell. who, w, and last show logins. /etc/nologin blocks ordinary logins when it exists. Find SUID programs with find / -perm -4000.

Services you do not need

Turn off unused listeners. TCP wrappers use /etc/hosts.allow and /etc/hosts.deny. xinetd configuration is under /etc/xinetd.d/. On systemd, a socket unit can be disabled with systemctl disable. Shadow passwords are the default: hashes are not in the world-readable passwd file.

OpenSSH

ssh-keygen creates a key pair. The public key goes in ~/.ssh/authorized_keys on the server. The private key stays on the client. ssh-agent and ssh-add hold the key for a session. Host keys live in /etc/ssh and are recorded in known_hosts. An SSH tunnel, including an X11 forward, carries another protocol inside the encrypted session. Replace host keys when you clone a machine.

GnuPG and desktops

gpg --encrypt, --decrypt, --sign, and --verify are the four operations. Revocation is part of the objective: a revocation certificate lets correspondents reject a lost key. Keys live under ~/.gnupg. For desktops, Xorg reads /etc/X11/xorg.conf and xorg.conf.d. DISPLAY names the screen. Wayland is awareness beside X11. GNOME, KDE, and Xfce are the desktops to recognize, and VNC, Spice, and RDP are remote display protocols.

Frequently asked questions

What is the difference between sudo and su?

sudo runs one command with the rights listed in /etc/sudoers, and it asks for your password. su starts a shell as another user, root by default, and asks for that user's password.

Which boot target is multi-user without a graphical login?

multi-user.target. graphical.target adds the display manager. rescue.target is the closest systemd equivalent of single-user mode. Set the default with systemctl set-default.

Where do password hashes live?

/etc/shadow holds the password hashes and aging fields, and only root can read it. /etc/passwd holds the account name, UID, GID, home directory, and shell, and it is world-readable.

Continue the LPI study path

Use the notes, then test recall with cards and a timed exam.

LPI hub →
Available

Overview

Exam format, the 500 passing score, topic weights, and a study plan.

Available · You are here

Core Notes

Reference notes for the shell, packages, boot, filesystems, users, logs, networking, and SSH.

Available

Practice Exams

200 original questions with custom exams, explanations, and an unofficial 200–800 score.

Related Tools

Useful companions while you study.

All study topics →