General Linux Administration Questions
Core questions covering permissions, processes, and everyday administration. · 12 min
Q: What's the difference between a hard link and a symbolic link? A: A hard link is a second filename pointing to the exact same inode — the data persists as long as any hard link to it exists, and it cannot cross filesystems. A symbolic link is a separate file that stores a path to another file, can cross filesystems and point to directories, but breaks ("dangles") if the target is moved or deleted. (Level 3)
Q: A user reports "permission denied" on a file they should be able to read. How do you diagnose it? A: Start with `ls -l` to check owner, group, and permission bits. Confirm the user's actual UID/group membership with `id`. If permissions look correct but access is still denied on a RHEL-family system, check SELinux with `ausearch -m avc -ts recent` — a context mismatch is the classic explanation for "permissions look right but access is still denied". (Levels 4, 11)
Q: What's the difference between `kill` and `kill -9`? A: Plain `kill` sends SIGTERM, a polite request that gives the process a chance to clean up and exit gracefully. `kill -9` sends SIGKILL, which the kernel enforces immediately with no chance for the process to clean up. Always try SIGTERM first; reserve SIGKILL for a genuinely unresponsive process. (Level 5)
Q: How do you find what's listening on a specific port? A: `ss -tulpn | grep :PORT` — shows the process and PID bound to that port, for both TCP and UDP. (Level 7)
Q: What does `chmod 755` actually set? A: Owner gets read/write/execute (7), group gets read/execute (5), others get read/execute (5) — the standard permission for an executable script or a directory others need to traverse. (Level 4)
Q: Explain the difference between `systemctl start` and `systemctl enable`. A: `start` runs a service immediately for the current boot only. `enable` configures it to start automatically on future boots. They're independent — a service can be running now but not enabled (won't survive a reboot), or enabled but not currently running. (Level 5)
Q: What's the purpose of /etc/fstab? A: It defines filesystems to be mounted automatically at boot, referencing each by a stable identifier (UUID, preferably, rather than a device name that can shift) along with its mount point, filesystem type, and mount options. (Level 8)
Q: How would you check disk usage and find what's actually consuming space? A: `df -h` shows usage per mounted filesystem; `du -sh /path/*` narrows down which directory within a filesystem is the actual culprit — df alone tells you a filesystem is full, du tells you why. (Levels 8, 21)
Takeaway: Interviewers are almost always probing for the reasoning behind an answer, not the memorized command alone — practice explaining why a diagnostic step comes before another, not just reciting the command.