Certification862 problems· 22 reviewed

RHCSA

862 incident response problems that help with RHCSA prep.

All problems (862)

LINUX-1316A chronyd recovery brings NTP back and Kerberos still failsA host boots with skew, later synchronizes, and only long-running identity-bound daemons continue failing.LinuxAdvanced15 minProLINUX-1324A firewall reload drops production trafficA firewall automation refactor is shipped and operators later see short traffic drops aligned exactly with every policy reload.LinuxAdvanced15 minProLINUX-1314A journald-backed log pipeline loses structured fieldsA service emits basic startup logs and later operators discover the ongoing structured fields they expected were never forwarded.LinuxAdvanced15 minProLINUX-1334A kernel update fixes a driver issue and a custom nftables service still failsA host kernel upgrade is followed by sporadic early boot network exposure or missing firewall enforcement until services settle.LinuxAdvanced15 minProLINUX-1327A logrotate change saves disk and starts truncating live uploadsA high-volume service rotates logs successfully and later upload or replay jobs show gaps that correlate with rotation windows.LinuxAdvanced15 minProLINUX-1356A rootless Docker host resolves DNS manually and containers failA rootless container service survives reboot and afterward only name resolution fails while network reachability remains fine.LinuxAdvanced15 minProLINUX-1372A rootless Docker service works until rebootA rootless Docker service works until reboot focuses on Runner Hygiene and asks the reader to isolate the key signal in docker. Rootless failures after reboot often come from XDG runtime path lifecycle drift, not from the...LinuxAdvanced15 minProLINUX-1346A rootless service starts (rootless-service-dns-broke-after-reboot-due-to-user-resolver-path)A rootless service starts (rootless-service-dns-broke-after-reboot-due-to... focuses on dns-resolution and asks the reader to isolate the key signal in Linux. Rootless boot persistence can change which resolver view a process...LinuxAdvanced15 minProLINUX-1320A systemd service sends READY=1 and still fails the first live requestsA service integrates with systemd notifications and later exhibits mysterious first-request failures after clean restarts.LinuxAdvanced15 minProLINUX-1318A Vault template updates the file and the service reload hook never runsA secret rotation system updates files reliably and the consuming service still never reloads the new material.LinuxAdvanced15 minProLINUX-1338An Elastic agent starts fine and never enrollsA trust bundle is rotated through symlink swaps and later one long-lived agent still rejects the same endpoint with old TLS errors.LinuxAdvanced15 minProLINUX-1378An nftables migration looks successful and one rootless service still loses egressA host firewall migration is completed and later one rootless service can no longer reach external systems although general host egress still works.LinuxAdvanced15 minProLINUX-1304Logrotate appears successful but a high-volume service still loses linesAn application under peak traffic rotates logs cleanly and later operators discover a silent gap around the rotate time.LinuxAdvanced15 minProLINUX-1375MFA is required in policy and one bastion path still bypasses itA bastion hardening change is rolled out and later one login path authenticates users without the expected MFA challenge.LinuxAdvanced15 minProLINUX-1374Split-DNS resolution works on one VPN reconnect and breaks on the nextSplit-DNS resolution works on one VPN reconnect and breaks on the next focuses on incident-response and asks the reader to isolate the key signal in Linux. Modern split-DNS failures often live in per-link resolver priority, not in the tunne...LinuxAdvanced15 minProLINUX-1306Time sync fixes itself minutes after boot but TLS clients keep failingA rebooted host later shows good time sync, but services started during the skew window continue failing outbound auth or API calls.LinuxAdvanced15 minProLINUX-1309Vault Agent keeps rotating certificates but the service never reloadsA host renews certificates automatically and the consumer still serves the old cert until manually restarted.LinuxAdvanced15 minProLINUX-155A chrony source remains reachable through an ACL exception, but NTS validation breaks after the host trust store drops the old rootTime sync traffic still flows, yet secure validation now fails for one trust-specific reason.LinuxAdvanced16 minProLINUX-1312A rootless Docker service survives restart and published ports vanishA rootless Docker service survives restart and published ports vanish focuses on cluster-bootstrap and asks the reader to isolate the key signal in Linux. Rootless runtime availability and rootless network availability can diverge after re...LinuxAdvanced16 minProLINUX-1310An NFS failover leaves applications hanging even though ICMP to the filer worksStorage failover completes and applications continue hanging despite ping and TCP checks to the filer succeeding again.LinuxAdvanced16 minPro