Prepare for Linux interview questions grouped by experience level, from freshers to staff engineers.
Linux Interview Question & Answers
0-2 Years
Linux is genuinely the kernel, the core software managing hardware, memory, and processes. Ubuntu, along with Fedora, Debian, and many others, is a genuine distribution, bundling that Linux kernel together with other software, utilities, a package manager, a desktop environment, into one complete, usable operating system.
A distribution packages the Linux kernel with genuinely additional software, utilities, and configuration choices, into a complete operating system. So genuinely many exist because different distributions genuinely target different priorities, some optimizing for server stability, others for desktop ease of use, or for a genuinely specific use case like embedded systems.
The kernel is the genuinely core software managing hardware directly. A shell is a genuine command-line interpreter, like bash, letting a user actually type commands that get translated into the actual system calls the kernel then genuinely executes.
A terminal is the genuine program providing a text-based window for actually interacting with the system. A shell is the genuine program running inside that terminal, actually interpreting the commands a user types and genuinely executing them.
Open-source software is genuinely any software whose source code is publicly available and can genuinely be modified and redistributed. Linux is a genuinely specific example of open-source software, the kernel itself, though many, but not genuinely all, Linux distributions and the software running on them are also open-source.
Ubuntu is genuinely popular for both desktop use and servers, known for being approachable. CentOS and Red Hat Enterprise Linux (RHEL) are genuinely common in enterprise server environments. Debian is genuinely known for stability, often used as a base for other distributions.
The root directory, represented by a genuine single forward slash /, is the genuine top of the entire file system hierarchy. Every other file and directory on the system, genuinely regardless of which physical disk or partition it actually lives on, sits somewhere underneath this one single root.
/home genuinely holds user's personal files. /etc genuinely holds system configuration files. /var genuinely holds variable data, like logs, that changes frequently. /bin and /usr/bin genuinely hold executable programs.
An absolute path genuinely starts from the root directory, /, and fully specifies a file's genuine, exact location regardless of your current directory. A relative path is genuinely interpreted relative to your current working directory, and points to a genuinely different actual location depending on where you currently are.
A hidden file's genuine name starts with a dot, like .bashrc, and it doesn't appear in a genuinely normal directory listing by default. Running ls -a genuinely shows every file, including these hidden ones, in the current directory.
A file genuinely stores actual data, text, an image, executable code. A directory genuinely organizes files (and other, genuinely nested directories) into a hierarchical structure, without itself storing genuine file content directly.
A symbolic link (or symlink) is a genuinely special file pointing to another file or directory elsewhere on the system, letting you actually access that target through a genuinely convenient, alternate path or name, similar in spirit to a shortcut on Windows.
ls lists the files and directories in the genuinely current location. ls -la genuinely shows a detailed, long-format listing including genuinely hidden files, which the plain ls command genuinely doesn't show by default.
cd /path/to/directory genuinely changes your current working directory to the specified path. cd .. genuinely moves up one directory level, and cd ~ (or just cd with no argument) genuinely returns you to your own home directory.
cp genuinely copies a file, leaving the original in place. mv genuinely moves (or renames) a file, removing it from its genuinely original location entirely.
mkdir new_directory genuinely creates a new, empty directory with that specific name. mkdir -p parent/child genuinely creates a genuinely nested directory structure in one single command, automatically creating any missing parent directory along the way.
cat filename genuinely prints a file's entire contents directly to the terminal. For a genuinely large file, less filename lets you actually scroll through it page by page, rather than dumping everything at once.
rm filename genuinely deletes a file. rm -r directory_name genuinely deletes a directory and everything inside it recursively. Both commands genuinely delete permanently, with no built-in trash or recycle bin to actually recover from, so they need to be used carefully.
Read (r), letting you genuinely view a file's contents. Write (w), letting you genuinely modify it. Execute (x), letting you genuinely run it as a program or a script.
Owner, the specific genuine user who owns the file. Group, other users belonging to the genuine group associated with the file. Others, genuinely everyone else on the system not covered by the first two categories.
The genuine first character indicates the file type (- for a regular file). The next three characters (rwx) are the owner's permissions. The next three (r-x) are the group's permissions. The genuinely last three (r--) are permissions for everyone else.
chmod changes a file's genuine permissions. The three digits genuinely represent permissions for the owner, the group, and everyone else respectively, each digit genuinely combining read (4), write (2), and execute (1) values, so 755 genuinely gives the owner full read-write-execute access and gives everyone else read and execute access only.
chown changes a file's genuine owner (and optionally its group), like chown user:group filename, letting you actually transfer ownership of a specific file to a genuinely different user or group.
A genuinely new file typically doesn't have execute permission set by default, so attempting to run it directly, like ./script.sh, genuinely fails with a permission denied error until chmod +x script.sh actually grants that specific permission.
The root user has genuinely unrestricted access to every file and every operation on the entire system. It requires careful use because a genuine mistake made while logged in as root, like accidentally deleting a critical system file, can genuinely damage or break the whole system with nothing genuinely stopping that mistake from actually happening.
sudo lets a genuinely authorized regular user run one specific command with root privileges temporarily, keeping a genuine audit log of what was actually run. Logging in directly as root genuinely grants unrestricted access for the entire session, with no per-command logging or that same, deliberate friction sudo genuinely introduces.
useradd username (or adduser on some distributions, which is genuinely more interactive) creates a genuinely new user account, and passwd username then genuinely sets that user's own initial password.
A group is a genuine collection of users, letting you actually grant a shared set of permissions to every user in that group at once, rather than needing to genuinely configure permissions individually for each single user separately.
whoami genuinely prints the currently logged-in user's username, a quick, simple way to actually confirm your genuine current identity, especially useful after switching users with su or sudo.
/etc/passwd genuinely stores basic user account information, like the username and home directory, and is genuinely readable by everyone on the system. /etc/shadow genuinely stores the actual encrypted password hashes, and is genuinely restricted to root only, for real security reasons.
A process is a genuinely running instance of a program. ps aux genuinely lists every currently running process on the system, showing details like the process ID, the user running it, and its current resource usage.
A PID is a genuinely unique number the kernel assigns to every running process, letting you actually reference a specific process directly, for instance to actually terminate it with a command like kill, without ambiguity about which process you actually mean.
A foreground command genuinely occupies your terminal until it actually finishes, blocking you from typing another command in the meantime. Appending & to a command genuinely runs it in the background instead, letting you actually continue using the terminal for other tasks while it runs.
kill PID genuinely sends a termination signal to the process with that specific ID, asking it to genuinely shut down gracefully. kill -9 PID genuinely sends a much more forceful signal that the process genuinely can't ignore, used when a normal kill doesn't actually work.
ps genuinely gives a one-time, static snapshot of currently running processes. top genuinely provides a continuously updating, real-time, interactive view, letting you actually watch resource usage change live as the system continues running.
free -h genuinely displays total, used, and available memory in a human-readable format, along with swap usage. Checking the available column specifically is generally more useful than the free column alone, since Linux genuinely uses otherwise-idle memory for disk caching, which free actually reclaims automatically the moment an application genuinely needs it.
3-6 Years
A shell script is a genuine text file containing a sequence of commands, executed together as one single program. It solves the genuine problem of needing to manually type the exact same sequence of commands repeatedly, letting you actually automate that sequence into one, reusable script instead.
name='Anu' declares a genuine variable, and echo $name genuinely prints its value. Note that there's genuinely no space around the equals sign when assigning a variable in bash, which is a genuinely common early mistake.
for i in 1 2 3 4 5; do echo $i; done genuinely iterates over the given list of values, printing each one in turn, similar in spirit to a for loop in most other genuinely common programming languages.
Inside the script, $1 genuinely refers to the first argument passed when the script was actually run, $2 the second, and so on, letting a script genuinely behave differently based on the actual arguments a user supplied when running it.
#!/bin/bash at the genuinely very top of a script tells the system which interpreter should actually execute the rest of the file, letting you run the script genuinely directly, like ./script.sh, rather than needing to explicitly type bash script.sh every single time.
grep searches text for lines genuinely matching a specific pattern. grep 'error' logfile.txt genuinely prints every line in logfile.txt containing the actual word error, which is genuinely commonly used to quickly search through a large log file for a specific term.
grep -r 'pattern' directory/ genuinely searches recursively through every file within the specified directory (and its own subdirectories), rather than genuinely searching only the files directly inside that one top-level directory.
sed is a stream editor, genuinely used to actually transform text, most commonly for find-and-replace. sed 's/old/new/g' file.txt genuinely replaces every occurrence of old with new throughout the specified file, printing the genuinely modified result.
awk processes text genuinely organized into columns, letting you actually extract or manipulate specific fields. awk '{print $1}' file.txt genuinely prints just the first column of every line in the specified file, treating whitespace as the genuine default column separator.
wc -l filename genuinely counts and prints the number of lines in the specified file, a genuinely quick way to check a file's size in terms of line count without needing to actually open and read through it manually.
A package manager, like apt on Debian-based systems or yum/dnf on Red Hat-based systems, automates installing, updating, and removing software, along with automatically genuinely handling that software's own dependencies. It solves the genuine problem of manually tracking and installing every required dependency by hand.
sudo apt install package_name genuinely installs the specified package, and sudo apt update genuinely refreshes the local list of available packages and their versions before actually installing anything, ensuring you're actually installing the genuinely latest available version.
dpkg genuinely handles installing and managing individual .deb package files directly, but doesn't automatically genuinely resolve or install dependencies. apt is a genuinely higher-level tool built on top of dpkg, automatically handling dependency resolution and genuinely fetching packages from a remote repository.
A repository is a genuine remote server hosting a collection of software packages a package manager can actually download and install from, and a system's configured list of repositories genuinely determines which specific packages and versions are actually available to install.
sudo apt autoremove package_name genuinely removes the specified package along with any of its own dependencies that were genuinely installed only for it and aren't actually needed by anything else currently installed on the system.
SIGTERM (the genuine default for the kill command) asks a process to genuinely shut down gracefully, letting it actually clean up before exiting. SIGKILL (kill -9) genuinely, immediately terminates the process with no chance to actually clean up at all, used when a process genuinely isn't responding to a normal SIGTERM.
nice adjusts a genuine process's scheduling priority when it's actually started, letting you actually run a genuinely lower-priority background task without it competing as aggressively for CPU time against more genuinely important, time-sensitive processes.
Pressing Ctrl+Z genuinely suspends the foreground process, and then typing bg genuinely resumes it running in the background, freeing up your terminal to actually accept genuinely new commands while that process continues running.
A zombie process has genuinely already finished executing, but its exit status hasn't yet actually been read by its parent process, leaving a genuine entry in the process table. An orphan process is one whose genuine parent has already terminated, and it's automatically genuinely re-parented to the init process instead.
ping sends a genuine small network packet to a specified host and measures how long it takes to actually get a response back, commonly used to quickly check whether a genuinely remote host is actually reachable and roughly how much latency exists to reach it.
netstat (or ss) genuinely shows active network connections and listening ports on a system, letting you actually check, for instance, whether a specific service is genuinely running and listening for connections on the port you expect it to be.
curl transfers data to or from a genuinely specified URL. curl https://example.com genuinely fetches that page's content and prints it directly to the terminal, commonly used to actually test an API endpoint or download a genuinely small file quickly from the command line.
find /path -name 'filename.txt' genuinely searches recursively through the given directory tree for a file matching that exact name, letting you actually locate a file whose specific location you don't already know, rather than manually browsing through each directory one at a time.
curl is genuinely more flexible, supporting a wide range of protocols and letting you actually inspect or manipulate the request and response in detail. wget is genuinely more focused specifically on actually downloading a file, and handles a genuinely recursive download or a resumed download particularly well.
6-8 Years
greet() { echo 'Hello, ' $1; } defines a genuine function, and calling greet 'Anu' later in the script genuinely runs it, passing 'Anu' as the function's own first argument, letting you actually organize a script's logic into genuinely reusable, named pieces.
Checking $? genuinely right after a command reads its actual exit status, 0 genuinely meaning success and any genuinely non-zero value indicating a real failure, letting a script actually branch its behavior based on whether the previous command actually succeeded.
set -e genuinely causes the entire script to immediately stop executing the moment any single command within it actually fails, rather than genuinely continuing on to execute subsequent commands despite that earlier failure, which helps avoid a script continuing in a genuinely broken, inconsistent state.
A cron job schedules a genuine command or script to actually run automatically at a specified, recurring time, solving the genuine problem of needing a task, like a nightly backup, to actually run periodically without requiring a person to manually trigger it every single time.
0 2 * * * /path/to/script.sh genuinely schedules that script to actually run at 2:00 AM every single day, following cron's own standard field format of minute, hour, day of month, month, and day of week.
command1 | command2 genuinely takes command1's own standard output and feeds it directly as command2's standard input, letting you actually chain several simple commands together to genuinely accomplish something more complex than any single one of them alone could.
systemd is the genuine init system and service manager used by most modern Linux distributions, responsible for actually starting services at boot, managing their genuine dependencies, and providing tools to actually start, stop, and check the status of a specific service.
systemctl status service_name genuinely shows whether that specific service is actually currently running, along with genuinely recent log output, letting you actually quickly diagnose whether a specific service is healthy or has actually failed.
journalctl genuinely displays the system's own centralized log, and journalctl -u service_name genuinely filters that log to show only entries from a specific, named service, letting you actually investigate a specific service's own recent behavior.
df -h genuinely shows overall disk space usage across every mounted filesystem, in a genuinely human-readable format. du -sh directory/ genuinely shows the actual total size of a specific directory, letting you actually pinpoint what's genuinely consuming disk space.
A mount point is a genuine directory where a separate storage device or partition is actually attached into the overall file system hierarchy, letting you actually access that separate storage as if it were genuinely just another directory within the single, unified file system.
8-10 Years
top or htop genuinely shows real-time CPU and memory usage per process, quickly revealing whether a genuinely specific process is consuming excessive resources. iostat and vmstat genuinely reveal whether the actual bottleneck is disk I/O or memory pressure instead.
Load average represents the genuine average number of processes actively using or waiting for the CPU, over the last 1, 5, and 15 minutes. A load average genuinely, consistently higher than the actual number of available CPU cores suggests the system is genuinely CPU-bound and struggling to keep up.
ps aux --sort=-%mem genuinely sorts every running process by memory usage in descending order, letting you actually quickly identify the specific process consuming the genuinely most memory at that moment, a common first step when actually diagnosing a memory issue.
strace traces the genuine system calls a running program actually makes, revealing exactly which files it's genuinely trying to open, which network calls it's genuinely making, and where it might actually be failing or hanging, giving genuinely deep visibility into a program's real, actual behavior.
Combining grep to actually filter for relevant error messages with awk or a genuine timestamp range check lets you actually narrow a genuinely enormous log file down to just the relevant lines from the specific time window an incident actually occurred in.
A core dump is a genuine file capturing a process's memory contents at the exact moment it actually crashed, letting a developer actually load it into a debugger afterward to examine the genuine program state right before the crash, rather than needing to genuinely reproduce the crash live to actually investigate it.
A tool like tcpdump captures genuine network packets directly at the interface level, letting you actually inspect the raw traffic to verify whether expected traffic is genuinely arriving, or whether an unexpected connection is genuinely happening, beyond what a higher-level tool like netstat alone would reveal.
SELinux and AppArmor genuinely enforce mandatory access control, restricting what a specific process is actually allowed to do, beyond what standard read-write-execute file permissions alone would restrict, adding a genuinely additional layer of security specifically designed to contain the real damage a compromised process could actually cause.
ufw allow 22 genuinely allows incoming traffic on port 22 (commonly used for SSH), and ufw enable genuinely activates the firewall with the currently defined rules, providing a genuinely simpler, more approachable interface than directly writing raw iptables rules by hand.
Disabling direct root login over SSH, genuinely using key-based authentication instead of a password, and changing the genuinely default SSH port are all common practices that meaningfully reduce the actual attack surface exposed to an automated, opportunistic attacker.
It means genuinely granting only the minimum permissions and access actually needed for a specific task, rather than broad, genuinely excessive access just in case it might be needed later. Applied to a Linux server, this means running a service under a genuinely dedicated, restricted user rather than as root whenever that's actually possible.
ss -tulnp genuinely lists every listening port along with the specific process actually bound to it, letting you actually identify and investigate any genuinely unexpected service that shouldn't be actually running or exposed on that particular server.
A chroot jail genuinely restricts a process's view of the file system to a specific, isolated subdirectory, making that directory appear to be the entire root of the file system from that process's own perspective. It solves the genuine problem of limiting what a potentially compromised process could actually access elsewhere on the real system.
A symmetric approach uses the exact same key for both encrypting and decrypting, requiring that shared secret to somehow already be securely exchanged beforehand. SSH uses an asymmetric key pair instead, a public key that can be freely shared and placed on a server, and a private key kept secret on the client, letting authentication happen without ever needing to transmit a shared secret over the network at all.
10+ Years
I'd weigh genuine long-term support availability, existing team familiarity, and how well a specific distribution's own package ecosystem fits the organization's own actual technology stack, favoring a genuinely well-supported, widely-used distribution over a genuinely niche one unless there's a specific, concrete reason to choose otherwise.
I'd document the handful of conventions that actually matter most, consistent error handling, required logging, avoiding a genuinely risky pattern like an unquoted variable in a critical script, with genuine, concrete examples of a real problem each one actually prevents.
I check whether it genuinely handles a command failure appropriately rather than silently continuing, whether it's genuinely idempotent if it's meant to be run repeatedly, and whether a genuinely destructive operation, like a file deletion, includes an appropriate safeguard against an accidental, unintended run.
Automate hardening through a configuration management tool, like Ansible, applying a genuinely consistent baseline automatically to every server, rather than relying on manual, one-off configuration that's genuinely prone to drifting inconsistently across a large fleet over time.
I'd weigh the genuine benefit, security patches, newer package versions, against the real cost and genuine risk of a migration, testing thoroughly in a genuinely lower-risk environment first and migrating incrementally rather than attempting one single, large, disruptive migration across the entire fleet all at once.
du -sh /* run from the root directory genuinely reveals which top-level directory is actually consuming the most space, letting you drill down further into the specific genuine subdirectory actually responsible, commonly logs or a genuinely runaway temporary file that was never actually cleaned up.
Track CPU, memory, disk usage, and load average across every server, alerting on meaningful deviation from an established, normal baseline rather than only on an outright, hard failure. A slowly growing disk usage trend is often a genuine early warning sign well before it actually causes a full outage.
Treat the playbook's actual behavior as a genuine contract with every server it manages. Testing a genuine change against a lower-risk, non-production environment first, before rolling it out to genuinely critical production servers, avoids a subtle configuration change unexpectedly breaking something already actually working.
I'd check whether it's genuinely still reachable over the network at all first, since that quickly narrows down whether the issue is genuinely at the network layer or the server itself, then check its console or an out-of-band management interface if available, since a genuinely unresponsive server often can't be diagnosed through SSH alone.
I'd monitor genuine resource utilization trends proactively across the existing fleet, and identify well ahead of time whether the coming bottleneck is genuinely likely to be CPU, memory, or disk I/O, since each of those calls for a meaningfully different scaling response.
This is a judgment question interviewers use to see how you reason under genuine uncertainty, not to test a specific textbook fact. A strong answer names the actual constraint that forced the decision, the realistic options that were genuinely on the table, why you picked one knowing it wasn't guaranteed to be right, and what you'd do differently with what you know now.
I'd walk through an actual, real incident, or a near-miss, caused by exactly that kind of mistake, showing concretely how genuinely small a typo or a wrong assumption about the current directory can lead to a genuinely serious, real consequence, rather than simply warning about it in the abstract.
I wouldn't lead with automation as an abstract best practice. I'd point to a specific, real, already-experienced incident caused by an inconsistency between two genuinely, supposedly identical servers, and show concretely how automated, consistent configuration would have genuinely prevented that exact same specific problem.
I'd frame it around genuine complexity and how often that automation needs to genuinely run across multiple different servers consistently. A genuinely simple, one-off task fits a shell script well, while something genuinely needing to be applied consistently and repeatedly across many servers usually fits a configuration management tool better.
I'd translate the investment into terms leadership already tracks: the cost of a specific past incident traced back to an inconsistent or unhardened server, and the ongoing risk of a similar incident recurring if left unaddressed. Framed as risk reduction with a concrete, already-incurred cost behind it, it competes far better for prioritization than framed as a general infrastructure cleanup.




