Entry level certification
RHCSA practice labs
EX200
Core command line, working with files, users and processes, and reading logs on a running server. Every objective below has a lab that runs a real Linux shell in your browser, so you practise the command rather than memorise the syntax.
Objectives covered
The skill areas these labs rehearse for RHCSA, written as plain descriptions of what you need to be able to do.
1Core command line skills and navigating a running server2Working with files, streams and regular expressions3Creating users, groups and managing permissions4Basic systemd: units, services and targets5Text file processing with grep and file redirection6Simple shell scripting for repeatable administration7Basic storage: partitions, mounts and disk usage8Reading logs and applying a first-line troubleshooting method
Practice these labs
- Creating FilesMake the folders you actually want, then write down what you did so you remember it tomorrow.
- The FilesystemExplore the filesystem and learn what each top level folder is for.
- Finding FilesYou have lost a download somewhere under /home/student.
- First ContactOpen a shell on the practice machine and run your first commands.
- Listing FilesA practice folder full of files, including one you have to look closely to see.
- Reading LogsEvery machine keeps a diary.
- Moving AroundMove between folders and read a file to find the configuration.
- Ports and ConnectionsRun a web server for a day and you meet four ports before lunch.
- Who Can Open WhatLinux decides who can open a file using nine characters.
- PermissionsUnderstand how rwx works before you change anything.
- Running ProcessesEverything on Linux is a process, including the ones you never see.
- Reading FilesA configuration file is sitting in your home folder.
- Writing to FilesSend command output into files.
- Searching a Whole TreeA whole tree of files, and you need three things from it.
- System InformationGet to know the machine you are sitting at: kernel, architecture, disk usage and uptime.
- Searching Textgrep is the tool you will reach for most often.
- Users and GroupsRead /etc/passwd and sort real user accounts from system ones.
- Where Am I?You are logged in.
- Creating EvidenceSet up an evidence workspace and record your first discovery for the incident report.
- The FilesystemYou have landed on a compromised server.
- File HuntThe attacker planted files across the system.
- Opening the CaseYou have been paged for case 2291 on a web server.
- Triage the DropA scanner flagged this web root.
- Log AnalysisSOC flagged suspicious SSH activity.
- Look InsideMove into a folder and read a file to find what the attacker left behind.
- Outbound ConnectionsYou captured a connection snapshot from the host before you touched it.
- Write the EvidenceFindings you cannot quote are findings you cannot act on.
- Permission AuditThe attacker may have loosened file permissions.
- Weak PermissionsPermissions are the quiet way an attacker keeps their access.
- Processes in Odd PlacesYou saved a process snapshot from the host.
- Reading FilesYou found a suspicious configuration file.
- Scattered EvidenceThe attacker scattered scripts and config files.
- Baseline the HostA finding means nothing without context.
- Correlate the Login LogAuth log exported from the host.
- Suspicious AccountsAudit the account list for anything that should not be there.
- What's Here?You're in.
- Crack the Auth LogThe auth.log is massive from a sustained attack.
- Crack the Brute Force3:12 AM, repeated SSH failures.
- Contain the Breach192.168.1.50 has root and is still inside.
- Cross-Reference SourcesThree log files, same time window.
- Eradicate PersistenceThe attacker is locked out but backdoors remain.
- Escalate and NotifyYou have 10 minutes to brief the CISO.
- Find File AnomaliesRoot-level attackers hide things in the filesystem.
- Uncover Hidden FilesThe attacker had root for hours.
- The First Five MinutesSOC alert at 04:00 AM.
- Forensic Disk CaptureThe attacker is out.
- Crack the Full InvestigationFour log files, multiple attackers.
- Verify Against Threat IntelYou found malware in /tmp.
- Threat Hunter: Incident ReportThe investigation is over.
- Build the IOC ListThe investigation is done.
- Protect the LogsRoot breach caught.
- Connect the DotsThree log sources, two attackers.
- Correlate the LogsOne log tells part of the story.
- Triage the LogsSOC alert at 3 AM.
- Hunt the MalwareThe attacker had root for 5 hours.
- Isolate the HostReverse shell detected.
- Map the Network FootprintA reverse shell on port 4444 calls back to 192.168.1.50.
- Separate Signal from NoiseThe auth.log is massive with legitimate traffic mixed with attacks.
- Expose the BackdoorsRoot was obtained 5 hours ago.
- Deep Port ScanPort scan results are in /evidence.
- Preserve EvidenceThe attacker is still logged in.
- Catch the Rogue ProcessesThe attacker is still inside.
- Hunt Rogue ProcessesRoot for 5 hours.
- Discover Open ServicesShell access to a compromised server.
- Read the System LogSyslog shows what the kernel saw.
- Fingerprint the TargetSOC alert fired.
- Rebuild the TimelineSomething happened between midnight and 4 AM.
- Threat Hunter: Timeline ReconstructionUse file timestamps to reconstruct the attacker's actions in chronological order.
- Map the User SessionsYou just SSH'd into a possibly compromised server.
- Enumerate the UsersThe attacker had root.
- Trace the Web AttackThe attacker attacked the web app too.
- Write the ReportThe breach is contained.
Linux Labs is an independent study tool. It is not affiliated with, endorsed by, or a partner of any certification body or exam provider. The exam names and codes above belong to their respective owners and are used only to identify which published objectives these labs rehearse. Linux Labs does not reproduce exam content, sell vouchers, administer exams, or issue certificates. Register for an exam through its official provider if you want a credential.