Certification862 problems· 22 reviewed

RHCSA

862 incident response problems that help with RHCSA prep.

All problems (862)

LINUX-1307Published Docker ports disappear after firewall reloadA host firewall hardening reload runs cleanly and all container-published ports quietly stop receiving traffic.LinuxAdvanced16 minProLINUX-098Rsync transfer is complete but hard links were expanded and the backup target fills twice as fastThe restore path works, yet storage usage explodes because the transfer options did not preserve link semantics the source tree relied on.LinuxAdvanced16 minProLINUX-140SSH certificate authentication is configured, but the principals file permissions are too open and the daemon ignores it for security reasonsThe CA trust path is valid, yet certificate login falls back to password prompts because the principal mapping file fails ownership checks.LinuxAdvanced16 minProLINUX-137A bridge netfilter sysctl is set correctly, but unloading and reloading the module resets the value and containers start bypassing the host policyThe host remains configured at rest, yet the live module state changed under the running workload.LinuxAdvanced17 minProLINUX-1290A file watcher-based deploy misses some changesA hot-reload or config-watcher workflow becomes unreliable only after moving the same app into a containerized or overlay-backed environment.LinuxAdvanced17 minProLINUX-1288A package postrotate hook restarts the proxy too early and a dependent app loses socket activationA package upgrade modifies runtime layout and later log rotation or restart hooks begin causing downtime instead of harmless reopen events.LinuxAdvanced17 minProLINUX-141A package update rewrites the PAM stack include order, and MFA still prompts but account validation now happens after the wrong moduleAuthentication appears normal until edge-case users begin failing account checks after successful factors.LinuxAdvanced17 minProLINUX-1298A SELinux boolean change fixes one service and breaks anotherTwo services share a host path and a fast SELinux fix for one later causes unexplained failures in the other.LinuxAdvanced17 minProLINUX-1260A service starts fine by hand but fails under systemdA newly packaged service runs during testing and immediately breaks after being moved under systemd supervision.LinuxAdvanced17 minProLINUX-108A sudoers include file loads later and quietly re-enables a broad NOPASSWD rule the team thought it removedPrivilege hardening seems complete, yet one lexical include order detail restores broad administrative access after the next package update.LinuxAdvanced17 minProLINUX-127Journal forward-secure sealing is enabled, but the verification key was rotated out of sync and log integrity checks now failLogs are still written, yet the trust model behind their integrity no longer validates after a partial key update.LinuxAdvanced17 minProLINUX-093Systemd path unit keeps relaunching a failed helperThe service appears to restart itself, but the real trigger is a path unit that keeps firing on the same file activity loop.LinuxAdvanced17 minProLINUX-129The auditd backlog limit is too small and a privilege escalation burst drops the very exec events the investigation needsThe host stays online, but the audit trail is incomplete because event pressure outran the queue design.LinuxAdvanced17 minProLINUX-162A PAM include reorder leaves the visible prompts intact while the account phase now runs under the wrong module stack during a failover rehearsalLogin looks normal until a user path reaches the control phase the new order broke. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced18 minProLINUX-345A restored RAID array looks healthy while the regenerated initramfs still lacks the md metadata mode expected by the current boot entry during a staged decommissionStorage is assembled after boot, yet the boot chain itself still expects a different assembly contract. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.LinuxAdvanced18 minProLINUX-113A shell cleanup trap unmounts the bind mount before the child process exits and late writes vanish from the host pathThe script looks tidy, but teardown runs too early and data written by a still-running child process disappears into a dead mount namespace.LinuxAdvanced18 minProLINUX-126A systemd mount unit starts before network-online and the iSCSI-backed filesystem fails intermittently after fast bootsSlow boots hide the problem, but optimized startup exposes an ordering race between storage dependencies and network readiness.LinuxAdvanced18 minProLINUX-246An XFS repair clears corruption while the application still points at the previous UUID in fstab during a failover rehearsalThe filesystem is healthy again and the boot or mount contract still points somewhere else. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced18 minProK8S-104CSI node plugin is healthy but SELinux labeling blocks the kubelet from using the published socketThe DaemonSet looks ready, yet mounts fail because the host path and socket labels do not allow the kubelet domain to connect.KubernetesAdvanced18 minProLINUX-1212Socket directory vanishes after rebootA daemon expects its socket directory to exist at boot, but a cleanup rule removes it before startup recreates it.LinuxAdvanced18 minPro