Certification862 problems· 22 reviewed

RHCSA

862 incident response problems that help with RHCSA prep.

All problems (862)

LINUX-1265A reverse proxy only breaks WebSocket auth flowsLinux incident scenario used for structured troubleshooting practice.LinuxIntermediate16 minProLINUX-1270A reverse proxy only breaks WebSocket auth flowsAn authentication layer added at the reverse proxy works for ordinary pages and suddenly breaks upgraded connections or live UI channels.LinuxIntermediate16 minProLINUX-1259A reverse proxy serves normal HTTP but WebSocket clients still failA proxy migration succeeds for normal requests while browsers or clients using WebSockets begin failing immediately.LinuxIntermediate16 minProLINUX-240A sudo rule matches a command path before alternatives flips the symlink to a new binary during a failover rehearsalPrivilege logic was tied to one pathname and the real executable moved beneath it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProLINUX-300A sudoers include grants the right command path while the shell wrapper now invokes a different binary via env indirection during a failover rehearsalThe human command looks the same and the executed path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProLINUX-121A systemd tmpfiles cleanup rule removes the idle service socket directory and the next connection starts failing long after bootThe host looks stable until the age-based cleanup task deletes a path the application expected to persist.LinuxAdvanced16 minProLINUX-152A thin pool autoextend threshold is correct, but the monitoring alert watches data percent while metadata is the first resource to exhaustOperators think storage headroom is fine until metadata starvation freezes writes.LinuxAdvanced16 minProLINUX-1286A tmpfiles.d rule recreates a directory at boot with permissive ownership, undoing the tighter mode that the service requires after every restartPermissions look correct after manual fixes, yet the next reboot reopens the security hole because tmpfiles policy rebuilds the directory differently from the service's expectation.LinuxAdvanced16 minProLINUX-144nftables helper tracking is disabled globally, and active FTP works only until a maintenance reboot restores the stricter defaultThe fix looked stable, but it only lived in transient runtime state and did not survive policy reload.LinuxAdvanced16 minProLINUX-192Noise suppression removes the repeated signal analysts rely on for brute-force detection during a failover rehearsalThe logs are cleaner and the incident pattern disappears with the noise. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxIntermediate16 minProLINUX-1223Restore script is idempotent on paper but reruns still breakAn automation unit can run repeatedly only until one failed attempt leaves a lock file that blocks all future executions.LinuxAdvanced16 minProLINUX-1228The cron job succeeds interactively but fails overnightA maintenance script works during manual testing and later breaks only when cron runs it unattended.LinuxIntermediate16 minProLINUX-387A bonded uplink survives failover while one LLDP or MTU assumption remained on the old primary member only during a staged decommissionLink redundancy works and the operational metadata does not fail over with it. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.LinuxAdvanced17 minProLINUX-1267A cloned VM mounts the wrong disk after rebootA machine restored or cloned from another system starts booting into the wrong data volume even though fstab references UUIDs.LinuxAdvanced17 minProLINUX-1300A containerized file sync daemon falls behindA container-based sync or watcher service becomes inconsistent only during large deploy bursts or mass file replacement.LinuxAdvanced17 minProLINUX-133A custom SELinux fcontext regex loads before the broader application path rule and restorecon applies the wrong label setThe policy file looks correct, yet precedence inside the matching rules changes the final label assignment.LinuxAdvanced17 minProLINUX-143A dracut regeneration succeeds, but the host boots with the stale UEFI entry that still points at the previous initramfs pathThe recovery artifact exists, yet firmware is not loading it.LinuxAdvanced17 minProLINUX-159A host firewall marks packets for policy routing, but rp_filter on the return path still drops asymmetric replies after failoverForward policy is correct, yet kernel anti-spoofing logic rejects the recovery path.LinuxAdvanced17 minProLINUX-149A kdump target path exists, but the crash kernel reserves too little memory after a kernel update and dumps truncate silentlyCrash capture remains enabled in config, yet one sizing assumption no longer holds for the new kernel footprint.LinuxAdvanced17 minProLINUX-180A live firewall helper tweak fixes traffic until policy reload restores stricter persisted defaults during a failover rehearsalThe symptom disappears immediately and returns at the next state boundary. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.LinuxAdvanced17 minPro