Home/Linux Administration/Linux Interview Preparation
💼

Level 24 of 24

Linux Interview Preparation

Real operational interview questions across admin, cloud, DevOps, and security roles.

Real operational interview questions, grouped by role focus, each with the kind of answer that demonstrates actual hands-on understanding — not memorized trivia. This is a starting set that will grow over time, prioritizing genuinely useful questions over an inflated count.

Prerequisites

  • • Levels 1–21, as relevant to each question

By the end of this level, you can

  • ✓ Answer common Linux administrator interview questions with real understanding, not memorized scripts
  • ✓ Explain the reasoning behind an answer, which is what interviewers actually probe for

General Linux Administration Questions

Core questions covering permissions, processes, and everyday administration. · 12 min

Q: What's the difference between a hard link and a symbolic link? A: A hard link is a second filename pointing to the exact same inode — the data persists as long as any hard link to it exists, and it cannot cross filesystems. A symbolic link is a separate file that stores a path to another file, can cross filesystems and point to directories, but breaks ("dangles") if the target is moved or deleted. (Level 3)

Q: A user reports "permission denied" on a file they should be able to read. How do you diagnose it? A: Start with `ls -l` to check owner, group, and permission bits. Confirm the user's actual UID/group membership with `id`. If permissions look correct but access is still denied on a RHEL-family system, check SELinux with `ausearch -m avc -ts recent` — a context mismatch is the classic explanation for "permissions look right but access is still denied". (Levels 4, 11)

Q: What's the difference between `kill` and `kill -9`? A: Plain `kill` sends SIGTERM, a polite request that gives the process a chance to clean up and exit gracefully. `kill -9` sends SIGKILL, which the kernel enforces immediately with no chance for the process to clean up. Always try SIGTERM first; reserve SIGKILL for a genuinely unresponsive process. (Level 5)

Q: How do you find what's listening on a specific port? A: `ss -tulpn | grep :PORT` — shows the process and PID bound to that port, for both TCP and UDP. (Level 7)

Q: What does `chmod 755` actually set? A: Owner gets read/write/execute (7), group gets read/execute (5), others get read/execute (5) — the standard permission for an executable script or a directory others need to traverse. (Level 4)

Q: Explain the difference between `systemctl start` and `systemctl enable`. A: `start` runs a service immediately for the current boot only. `enable` configures it to start automatically on future boots. They're independent — a service can be running now but not enabled (won't survive a reboot), or enabled but not currently running. (Level 5)

Q: What's the purpose of /etc/fstab? A: It defines filesystems to be mounted automatically at boot, referencing each by a stable identifier (UUID, preferably, rather than a device name that can shift) along with its mount point, filesystem type, and mount options. (Level 8)

Q: How would you check disk usage and find what's actually consuming space? A: `df -h` shows usage per mounted filesystem; `du -sh /path/*` narrows down which directory within a filesystem is the actual culprit — df alone tells you a filesystem is full, du tells you why. (Levels 8, 21)

Takeaway: Interviewers are almost always probing for the reasoning behind an answer, not the memorized command alone — practice explaining why a diagnostic step comes before another, not just reciting the command.

Cloud & DevOps Linux Questions

Questions bridging Linux fundamentals with cloud and automation contexts. · 8 min

Q: A port is open in your VM's OS-level firewall but the service still isn't reachable from the internet. What else could be blocking it? A: On any major cloud provider, a cloud-level firewall (a Security Group on AWS, an NSG on Azure) sits in front of the instance's own OS firewall — both must independently allow the traffic. This is one of the most common real cloud networking gotchas. (Level 19)

Q: What makes a container different from a virtual machine? A: A container is an ordinary process on the host's existing kernel, isolated via namespaces and limited via cgroups — no separate kernel or hypervisor. A VM virtualizes hardware and runs a genuinely separate kernel. Containers start faster and share resources more efficiently; VMs provide stronger isolation. (Level 16)

Q: Why is idempotency important in configuration management tools like Ansible? A: An idempotent task checks current state before acting and does nothing if the desired state already exists — this is what makes it safe to re-run a playbook repeatedly (including as a scheduled job) without cumulative or duplicated side effects, unlike a raw imperative script. (Level 18)

Q: What's the difference between apt and dnf, and why does it matter? A: apt (Debian/Ubuntu, .deb packages) and dnf (RHEL/Rocky/Alma/Fedora, .rpm packages) are genuinely different tools with different syntax on top of different package formats — commands and even package names sometimes differ between them, so identifying the distribution family first (`cat /etc/os-release`) is a prerequisite to running the right command. (Level 6)

Takeaway: Cloud and DevOps interview questions usually test whether you understand that the cloud/container layer adds to, rather than replaces, the Linux fundamentals underneath it.

Linux Security Questions

Questions on hardening, SELinux, and secure remote access. · 8 min

Q: Why is disabling SSH password authentication considered a meaningful security improvement? A: It eliminates the entire class of automated password brute-force attacks against SSH — with password auth disabled, there is no password to guess at all; access requires possessing the actual private key. (Level 9)

Q: What's the difference between SELinux and standard Unix permissions? A: Standard permissions answer "does this user/group have read/write/execute on this file". SELinux enforces a separate, independent policy layer based on security contexts/labels — a process can have correct standard permissions and still be denied by SELinux policy, and vice versa in terms of the two systems being evaluated independently. (Level 11)

Q: Why shouldn't you just disable SELinux when you hit a confusing denial? A: Disabling it removes a real, independent security layer permanently to solve what's usually a narrow, specific context mismatch — the correct fix is almost always diagnosing the actual denial with `ausearch` and fixing the context with `restorecon`, not disabling enforcement altogether. (Level 11)

Q: What's the principle of least privilege, applied to sudo? A: Granting a user or role access to only the specific commands they need (via a scoped `/etc/sudoers` entry) rather than blanket root access — this limits the blast radius if that account is ever compromised or misused, and preserves a meaningful audit trail of who ran what. (Level 4)

Q: Why does a disk filling up matter as a security consideration, not just an operational one? A: A full disk can prevent logging from continuing to write — which can mean an attacker's activity during that window goes unrecorded — and can also cause services to fail in unpredictable, sometimes insecure default states. Unmanaged log growth (Level 12) is a real, common path to this exact scenario.

Takeaway: Security interview questions consistently probe whether you understand the reasoning behind a control (why it reduces risk) rather than just being able to name the control itself.

Sponsor / Advertisement