RHCSA EX200 Cheat Sheet for RHEL 10: Commands and Quick Reference

A printable RHCSA EX200 command cheat sheet for RHEL 10 covering users, permissions, LVM, networking, systemd, SELinux, containers and troubleshooting.

May 16, 2025 - 17:24
Updated: 3 days ago
110.6k
RHCSA EX200 Cheat Sheet for RHEL 10: Commands and Quick Reference

Quick answer: RHCSA EX200 is now based on Red Hat Enterprise Linux 10. It is fully hands-on, so you need commands you can type from memory, not theory. The biggest areas are storage (partitions, LVM, fstab, autofs), users and sudo, networking with nmcli, SELinux and firewalld, and making every change survive a reboot. This cheat sheet groups the commands by the official exam objectives, so you can revise one objective at a time.

Key takeaways

  • Most candidates lose marks because their configuration does not survive a reboot, so reboot and re-check every task before submitting.
  • For the RHEL 10 version, add Flatpak repositories and tuned-adm profiles to your revision, while Podman is no longer in the published objectives.
  • Practise commands from memory with no internet access, because the exam is fully hands-on and no documentation beyond local man pages is available.

What changed for RHEL 10 (EX200 v10)

If you prepared with RHEL 9 notes, check these points first. Red Hat's published objectives for the RHEL 10 version now include:

  • Flatpak repositories sit alongside RPM repositories under "Manage software".
  • Tuning profiles (tuned-adm) are listed under "Operate running systems".
  • Container tasks (Podman) no longer appear in the published RHCSA objectives. Containers are still worth learning, but they are not where your revision time should go for this exam.

Two things haven't changed. You still get no internet during the exam, and every configuration must still work after a reboot. Most candidates who fail lose marks on the second point, not on knowing the command.

Essential tools

TaskCommand
Find lines that start with a word and save themgrep -E '^root' /etc/passwd > /root/lines.txt
Find files owned by a user and copy themfind / -user harry -type f -exec cp -a {} /root/found/ \; 2>/dev/null
Create a gzip archivetar -czvf /root/etc.tar.gz /etc
Create a bzip2 archivetar -cjvf /root/etc.tar.bz2 /etc
Extract an archivetar -xvf file.tar.gz -C /tmp/restore
Hard link and soft linkln /data/file /data/hard and ln -s /data/file /data/soft
Log in to another systemssh student@serverb
Read documentation offlineman -k partition, man 5 fstab, ls /usr/share/doc

Get used to man 5 fstab and man nmcli-examples. They have ready-made examples, and the man pages are available during the exam.

Permissions, ACLs and special bits

  • chmod 2770 /shared: group-owned collaborative directory (the 2 sets SGID, so new files inherit the group)
  • chmod +t /shared: sticky bit, so users can delete only their own files
  • chown:admins /shared: change the group owner
  • setfacl -m u:natasha:rw /var/tmp/fstab: give one user extra rights
  • setfacl -m u:harry:- /var/tmp/fstab: explicitly deny a user
  • getfacl /var/tmp/fstab: check the result
  • Default permissions: add umask 027 to a user's ~/.bashrc. For all users, use a file in /etc/profile.d/.

Software: RPM and Flatpak

Create a repository file instead of relying on a tool you might mistype:

vim /etc/yum.repos.d/exam.repo
[BaseOS]
name=BaseOS
baseurl=http://content.example.com/rhel10/BaseOS
enabled=1
gpgcheck=0 dnf repolist
dnf install -y httpd
dnf remove -y httpd

Flatpak basics:

flatpak remote-add --if-not-exists myremote https://example.com/repo/myremote.flatpakrepo
flatpak remotes
flatpak install myremote org.example.App
flatpak list

Use whatever repository URL the exam question gives you. The URLs above are placeholders.

Simple shell scripts

#!/bin/bash
# Usage:./mkusers.sh users.txt
if [ $# -ne 1 ]; then echo "Usage: $0 file"; exit 1
fi
for u in $(cat "$1"); do if id "$u" &>/dev/null; then echo "$u already exists" else useradd "$u" && echo "$u created" fi
done

Make it executable with chmod +x mkusers.sh. If the task names a path such as /usr/local/bin, put the script exactly there.

Operate running systems

  • systemctl get-default / systemctl set-default multi-user.target: boot target
  • systemctl isolate rescue.target: switch target now
  • ps aux --sort=-%cpu | head, kill -9 PID, renice -n 5 -p PID: processes
  • tuned-adm recommend, tuned-adm profile virtual-guest, tuned-adm active: tuning profiles
  • journalctl -u sshd --since today: service logs
  • Persistent journal: set Storage=persistent in /etc/systemd/journald.conf, then systemctl restart systemd-journald
  • scp file student@serverb:/tmp/ or sftp student@serverb: secure file transfer

Reset a forgotten root password

  1. Reboot. At the GRUB menu, press e on the kernel entry.
  2. Add rd.break to the end of the line that starts with linux, then press Ctrl+x.
  3. Run mount -o remount, rw /sysroot and chroot /sysroot.
  4. Run passwd root, then touch /.autorelabel. Do not skip this step, or SELinux will block logins.
  5. Type exit twice and let the system relabel and reboot.

Local storage: partitions, LVM and swap

# GPT partition
parted /dev/vdb mklabel gpt
parted /dev/vdb mkpart part1 xfs 1MiB 1025MiB
udevadm settle # LVM with a custom extent size
pvcreate /dev/vdb2
vgcreate -s 16M datavg /dev/vdb2
lvcreate -n datalv -l 20 datavg # 20 extents x 16M = 320M
mkfs.xfs /dev/datavg/datalv # Grow a logical volume and its file system in one step
lvextend -r -L +200M /dev/datavg/datalv # Swap
mkswap /dev/vdb3
swapon /dev/vdb3

lvextend -r resizes the file system too. Without -r, the volume grows but df -h still shows the old size. That's a classic lost mark.

File systems, fstab, NFS and autofs

mkfs.xfs /dev/vdb1 # XFS
mkfs.ext4 /dev/vdb4 # ext4
mkfs.vfat /dev/vdb5 # VFAT
blkid # copy the UUID # /etc/fstab
UUID=1b2c... /data xfs defaults 0 0
UUID=9f8e... none swap defaults 0 0 mkdir -p /data
systemctl daemon-reload
mount -a # no error = safe to reboot
swapon -a

Mount an NFS share and configure autofs:

dnf install -y nfs-utils autofs
mount -t nfs serverb:/shares/public /mnt # /etc/auto.master.d/shares.autofs
/remote /etc/auto.shares # /etc/auto.shares
work -rw, sync serverb:/shares/work systemctl enable --now autofs
ls /remote/work # triggers the mount

Always run mount -a before you reboot. A typo in /etc/fstab can drop the machine into emergency mode, and then everything else you configured is unreachable.

Deploy, configure and maintain systems

  • crontab -e -u natasha, then e.g. */5 * * * * logger "EX200 check": cron job
  • echo "date >> /tmp/at.log" | at now + 5 minutes: one-time job
  • systemctl list-timers: systemd timers
  • systemctl enable --now httpd: start now and at boot
  • timedatectl set-timezone Asia/Kolkata: time zone
  • Add server classroom.example.com iburst to /etc/chrony.conf, then run systemctl restart chronyd and chronyc sources: time server
  • grubby --default-kernel, grubby --set-default /boot/vmlinuz-<version>, grubby --update-kernel=ALL --args="quiet": bootloader changes
  • dnf update -y: install updates from the configured repositories

Networking

nmcli con show
nmcli con mod "eth0" ipv4.addresses 172.25.250.11/24 \ ipv4.gateway 172.25.250.254 ipv4.dns 172.25.250.254 ipv4.method manual
nmcli con mod "eth0" ipv6.addresses fd00::11/64 ipv6.method manual
nmcli con mod "eth0" connection.autoconnect yes
nmcli con up "eth0" hostnamectl set-hostname servera.lab.example.com
cat /etc/hosts # add static name resolution here if asked

If you are working over SSH, change the IP last, or you will lock yourself out of the session.

Users, groups and sudo

  • groupadd sysadmins
  • useradd -G sysadmins natasha: secondary group
  • useradd -s /sbin/nologin sarah: no interactive shell
  • useradd -u 3533 alex: specific UID
  • echo 'flectrag' | passwd --stdin natasha: set a password in one line
  • chage -M 90 natasha: password expires every 90 days
  • PASS_MAX_DAYS 60 in /etc/login.defs: default for new users only
  • visudo -f /etc/sudoers.d/sysadmins, then add %sysadmins ALL=(ALL) NOPASSWD: ALL: privileged access

Security: firewalld, SSH keys and SELinux

# Firewall
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-port=82/tcp
firewall-cmd --reload
firewall-cmd --list-all # SSH key-based login
ssh-keygen -t ed25519
ssh-copy-id student@serverb # SELinux
getenforce
setenforce 1 # runtime only
vim /etc/selinux/config # SELINUX=enforcing (persistent)
semanage port -a -t http_port_t -p tcp 82
semanage fcontext -a -t httpd_sys_content_t "/web(/.*)?"
restorecon -Rv /web
setsebool -P httpd_enable_homedirs on
getsebool -a | grep httpd

When a web server won't serve content on a custom port or directory, check the port label first, then the file context, then the Boolean. In practice exam labs, that order fixes most SELinux tasks.

A 7-day revision plan using this sheet

DayFocusHow to practise
1Essential tools, permissions, ACLsDo every command above on a fresh VM, without notes
2Users, sudo, password ageingCreate 5 users from a script and set policies
3Partitions, LVM, swapBuild, extend and reboot three times
4fstab, NFS, autofsBreak fstab on purpose and recover from emergency mode
5Networking, hostname, timeConfigure IPv4 and IPv6 with nmcli only
6SELinux and firewalldServe a website on port 82 from /web
7Full mockTimed mock exam, then reboot and re-check every task

Next steps

For the full exam walkthrough with lab tasks, read our RHCSA RHEL 10 (EX200 v10) complete guide, and check the current RHCSA exam format, duration and rescheduling rules before you book. New to the certification? Start with what RHCSA covers and who it is for. If you'd like to practise these tasks with a trainer before the exam, see the RHCSA training and exam at WebAsha Technologies in Pune and online.

Related reading

Frequently Asked Questions

Red Hat's current EX200 exam is based on Red Hat Enterprise Linux 10. Practise on RHEL 10 (a free Red Hat Developer subscription works) so commands and defaults match the exam.

Container tasks no longer appear in the published RHCSA objectives for RHEL 10. The new items to study are Flatpak repositories and tuning profiles with tuned-adm.

No. You cannot bring notes or use the internet. The documentation that ships with RHEL, such as man pages and /usr/share/doc, is normally available, so learn to find examples there quickly.

Changes that do not survive a reboot: a wrong /etc/fstab entry, a service that was started but not enabled, or SELinux contexts that were not restored. Reboot and re-check every task before you finish.

Learners with some Linux background usually need four to eight weeks of daily hands-on practice. Complete beginners should first cover RH124 and RH134 level topics, then do timed mock labs.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Aayushi Sinha

With a passion for staying on the cutting edge of technology trends, I am dedicated to delivering content that not only informs but also inspires. Whether you need in-depth analysis pieces, informative guides, or thought-provoking opinion pieces, I craft content that resonates with tech enthusiasts and professionals alike.