RHCSA EX200 Cheat Sheet for RHEL 10: Commands and Quick Reference
A printable RHCSA EX200 command cheat sheet for RHEL 10 covering users, permissions, LVM, networking, systemd, SELinux, containers and troubleshooting.
Quick answer: RHCSA EX200 is now based on Red Hat Enterprise Linux 10. It is fully hands-on, so you need commands you can type from memory, not theory. The biggest areas are storage (partitions, LVM, fstab, autofs), users and sudo, networking with nmcli, SELinux and firewalld, and making every change survive a reboot. This cheat sheet groups the commands by the official exam objectives, so you can revise one objective at a time.
Key takeaways
- Most candidates lose marks because their configuration does not survive a reboot, so reboot and re-check every task before submitting.
- For the RHEL 10 version, add Flatpak repositories and tuned-adm profiles to your revision, while Podman is no longer in the published objectives.
- Practise commands from memory with no internet access, because the exam is fully hands-on and no documentation beyond local man pages is available.
What changed for RHEL 10 (EX200 v10)
If you prepared with RHEL 9 notes, check these points first. Red Hat's published objectives for the RHEL 10 version now include:
- Flatpak repositories sit alongside RPM repositories under "Manage software".
- Tuning profiles (
tuned-adm) are listed under "Operate running systems". - Container tasks (Podman) no longer appear in the published RHCSA objectives. Containers are still worth learning, but they are not where your revision time should go for this exam.
Two things haven't changed. You still get no internet during the exam, and every configuration must still work after a reboot. Most candidates who fail lose marks on the second point, not on knowing the command.
Essential tools
| Task | Command |
|---|---|
| Find lines that start with a word and save them | grep -E '^root' /etc/passwd > /root/lines.txt |
| Find files owned by a user and copy them | find / -user harry -type f -exec cp -a {} /root/found/ \; 2>/dev/null |
| Create a gzip archive | tar -czvf /root/etc.tar.gz /etc |
| Create a bzip2 archive | tar -cjvf /root/etc.tar.bz2 /etc |
| Extract an archive | tar -xvf file.tar.gz -C /tmp/restore |
| Hard link and soft link | ln /data/file /data/hard and ln -s /data/file /data/soft |
| Log in to another system | ssh student@serverb |
| Read documentation offline | man -k partition, man 5 fstab, ls /usr/share/doc |
Get used to man 5 fstab and man nmcli-examples. They have ready-made examples, and the man pages are available during the exam.
Permissions, ACLs and special bits
chmod 2770 /shared: group-owned collaborative directory (the 2 sets SGID, so new files inherit the group)chmod +t /shared: sticky bit, so users can delete only their own fileschown:admins /shared: change the group ownersetfacl -m u:natasha:rw /var/tmp/fstab: give one user extra rightssetfacl -m u:harry:- /var/tmp/fstab: explicitly deny a usergetfacl /var/tmp/fstab: check the result- Default permissions: add
umask 027to a user's~/.bashrc. For all users, use a file in/etc/profile.d/.
Software: RPM and Flatpak
Create a repository file instead of relying on a tool you might mistype:
vim /etc/yum.repos.d/exam.repo
[BaseOS]
name=BaseOS
baseurl=http://content.example.com/rhel10/BaseOS
enabled=1
gpgcheck=0 dnf repolist
dnf install -y httpd
dnf remove -y httpd
Flatpak basics:
flatpak remote-add --if-not-exists myremote https://example.com/repo/myremote.flatpakrepo
flatpak remotes
flatpak install myremote org.example.App
flatpak list
Use whatever repository URL the exam question gives you. The URLs above are placeholders.
Simple shell scripts
#!/bin/bash
# Usage:./mkusers.sh users.txt
if [ $# -ne 1 ]; then echo "Usage: $0 file"; exit 1
fi
for u in $(cat "$1"); do if id "$u" &>/dev/null; then echo "$u already exists" else useradd "$u" && echo "$u created" fi
done
Make it executable with chmod +x mkusers.sh. If the task names a path such as /usr/local/bin, put the script exactly there.
Operate running systems
systemctl get-default/systemctl set-default multi-user.target: boot targetsystemctl isolate rescue.target: switch target nowps aux --sort=-%cpu | head,kill -9 PID,renice -n 5 -p PID: processestuned-adm recommend,tuned-adm profile virtual-guest,tuned-adm active: tuning profilesjournalctl -u sshd --since today: service logs- Persistent journal: set
Storage=persistentin/etc/systemd/journald.conf, thensystemctl restart systemd-journald scp file student@serverb:/tmp/orsftp student@serverb: secure file transfer
Reset a forgotten root password
- Reboot. At the GRUB menu, press e on the kernel entry.
- Add
rd.breakto the end of the line that starts withlinux, then press Ctrl+x. - Run
mount -o remount, rw /sysrootandchroot /sysroot. - Run
passwd root, thentouch /.autorelabel. Do not skip this step, or SELinux will block logins. - Type
exittwice and let the system relabel and reboot.
Local storage: partitions, LVM and swap
# GPT partition
parted /dev/vdb mklabel gpt
parted /dev/vdb mkpart part1 xfs 1MiB 1025MiB
udevadm settle # LVM with a custom extent size
pvcreate /dev/vdb2
vgcreate -s 16M datavg /dev/vdb2
lvcreate -n datalv -l 20 datavg # 20 extents x 16M = 320M
mkfs.xfs /dev/datavg/datalv # Grow a logical volume and its file system in one step
lvextend -r -L +200M /dev/datavg/datalv # Swap
mkswap /dev/vdb3
swapon /dev/vdb3
lvextend -r resizes the file system too. Without -r, the volume grows but df -h still shows the old size. That's a classic lost mark.
File systems, fstab, NFS and autofs
mkfs.xfs /dev/vdb1 # XFS
mkfs.ext4 /dev/vdb4 # ext4
mkfs.vfat /dev/vdb5 # VFAT
blkid # copy the UUID # /etc/fstab
UUID=1b2c... /data xfs defaults 0 0
UUID=9f8e... none swap defaults 0 0 mkdir -p /data
systemctl daemon-reload
mount -a # no error = safe to reboot
swapon -a
Mount an NFS share and configure autofs:
dnf install -y nfs-utils autofs
mount -t nfs serverb:/shares/public /mnt # /etc/auto.master.d/shares.autofs
/remote /etc/auto.shares # /etc/auto.shares
work -rw, sync serverb:/shares/work systemctl enable --now autofs
ls /remote/work # triggers the mount
Always run mount -a before you reboot. A typo in /etc/fstab can drop the machine into emergency mode, and then everything else you configured is unreachable.
Deploy, configure and maintain systems
crontab -e -u natasha, then e.g.*/5 * * * * logger "EX200 check": cron jobecho "date >> /tmp/at.log" | at now + 5 minutes: one-time jobsystemctl list-timers: systemd timerssystemctl enable --now httpd: start now and at boottimedatectl set-timezone Asia/Kolkata: time zone- Add
server classroom.example.com iburstto/etc/chrony.conf, then runsystemctl restart chronydandchronyc sources: time server grubby --default-kernel,grubby --set-default /boot/vmlinuz-<version>,grubby --update-kernel=ALL --args="quiet": bootloader changesdnf update -y: install updates from the configured repositories
Networking
nmcli con show
nmcli con mod "eth0" ipv4.addresses 172.25.250.11/24 \ ipv4.gateway 172.25.250.254 ipv4.dns 172.25.250.254 ipv4.method manual
nmcli con mod "eth0" ipv6.addresses fd00::11/64 ipv6.method manual
nmcli con mod "eth0" connection.autoconnect yes
nmcli con up "eth0" hostnamectl set-hostname servera.lab.example.com
cat /etc/hosts # add static name resolution here if asked
If you are working over SSH, change the IP last, or you will lock yourself out of the session.
Users, groups and sudo
groupadd sysadminsuseradd -G sysadmins natasha: secondary groupuseradd -s /sbin/nologin sarah: no interactive shelluseradd -u 3533 alex: specific UIDecho 'flectrag' | passwd --stdin natasha: set a password in one linechage -M 90 natasha: password expires every 90 daysPASS_MAX_DAYS 60in/etc/login.defs: default for new users onlyvisudo -f /etc/sudoers.d/sysadmins, then add%sysadmins ALL=(ALL) NOPASSWD: ALL: privileged access
Security: firewalld, SSH keys and SELinux
# Firewall
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-port=82/tcp
firewall-cmd --reload
firewall-cmd --list-all # SSH key-based login
ssh-keygen -t ed25519
ssh-copy-id student@serverb # SELinux
getenforce
setenforce 1 # runtime only
vim /etc/selinux/config # SELINUX=enforcing (persistent)
semanage port -a -t http_port_t -p tcp 82
semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?"
restorecon -Rv /web
setsebool -P httpd_enable_homedirs on
getsebool -a | grep httpd
When a web server won't serve content on a custom port or directory, check the port label first, then the file context, then the Boolean. In practice exam labs, that order fixes most SELinux tasks.
A 7-day revision plan using this sheet
| Day | Focus | How to practise |
|---|---|---|
| 1 | Essential tools, permissions, ACLs | Do every command above on a fresh VM, without notes |
| 2 | Users, sudo, password ageing | Create 5 users from a script and set policies |
| 3 | Partitions, LVM, swap | Build, extend and reboot three times |
| 4 | fstab, NFS, autofs | Break fstab on purpose and recover from emergency mode |
| 5 | Networking, hostname, time | Configure IPv4 and IPv6 with nmcli only |
| 6 | SELinux and firewalld | Serve a website on port 82 from /web |
| 7 | Full mock | Timed mock exam, then reboot and re-check every task |
Next steps
For the full exam walkthrough with lab tasks, read our RHCSA RHEL 10 (EX200 v10) complete guide, and check the current RHCSA exam format, duration and rescheduling rules before you book. New to the certification? Start with what RHCSA covers and who it is for. If you'd like to practise these tasks with a trainer before the exam, see the RHCSA training and exam at WebAsha Technologies in Pune and online.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0