Q1 ⭐ What is the difference between absolute path and relative path?
- Absolute: starts from root (/), complete path e.g. /home/user/file.txt
- Relative: from current dir e.g. ./docs/file.txt or ../parent/file.txt
- . = current dir, .. = parent, ~ = home dir shortcut
- Use absolute paths in scripts for reliability
🔗 Follow-up: "What does the tilde (~) represent in Linux?"
Q2 ⭐ Explain the Linux file permission system. What does chmod 755 mean?
- Three sets: owner, group, others. Three permissions: r(4) w(2) x(1)
- chmod 755 = owner: rwx(7), group: r-x(5), others: r-x(5)
- chmod 644 = typical file: rw-r--r-- (owner can write, others read only)
- chmod 600 = private key: rw------- (only owner can read/write)
🔗 Follow-up: "What is the difference between chmod and chown?"
Q3 What is a pipe (|) in Linux? Give an example.
- Pipe connects stdout of one command to stdin of the next
- Example: ps aux | grep node — list processes, filter for node
- Can chain multiple: cat log | grep ERROR | wc -l
- Named pipes (mkfifo) — persistent pipe on filesystem
🔗 Follow-up: "What is the difference between > and >> redirection?"
Q4 What is the difference between rm and rmdir? What does rm -rf do?
- rmdir: removes EMPTY directories only
- rm: removes files. rm -r: recursive (directories + contents)
- rm -rf: force recursive delete — no confirmation, no recycle bin. Permanent.
- Common disaster: rm -rf / (delete root). Always double-check paths!
Q5 What is grep? How do you search recursively inside files?
- grep: Global Regular Expression Print — searches text patterns
- grep -r "pattern" ./src/ — recursive search ⭐
- Flags: -i (case-insensitive), -n (line numbers), -v (invert), -l (filenames only)
- grep -C 3 "error" log — show 3 lines context around matches
Q6 What is the difference between kill, kill -9, and pkill?
- kill PID: sends SIGTERM (15) — graceful shutdown, process can clean up
- kill -9 PID: sends SIGKILL — cannot be caught/ignored, immediate termination
- pkill name: kills by process name (uses SIGTERM by default)
- Always try SIGTERM first; use SIGKILL only if process doesn't respond
Q7 What does ps aux show? How do you find a running process?
- ps = process status. aux = all users, user-oriented, x=no tty processes
- Columns: USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
- ps aux | grep nginx — find specific process
- pgrep nginx — directly gives PID
Q8 What is sudo? What is the difference between su and sudo?
- sudo: execute single command as root/another user. Logs actions. Safer.
- su: switch user entirely (starts a new shell session)
- sudo -i: interactive root shell (equivalent to su but via sudo)
- sudoers file (/etc/sudoers) controls who can use sudo
Q9 ⭐ What are stdin, stdout, and stderr? How do you redirect them?
- stdin (0): standard input. stdout (1): standard output. stderr (2): error output
- > redirects stdout. 2> redirects stderr. 2>&1 merges stderr into stdout
- cmd > all.txt 2>&1 — save both to file. /dev/null — discard output
- tee: write to file AND continue piping (split output)
🔗 Follow-up: "What is /dev/null? Why would you redirect to it?"
Q10 ⭐ What is a shebang line? Why is #!/usr/bin/env bash preferred?
- Shebang (#!) = tells kernel which interpreter to use for the script
- #!/bin/bash = hardcoded path. May not exist on all systems.
- #!/usr/bin/env bash = finds bash in PATH — more portable across systems
- Must be the first line. Script also needs execute permission (chmod +x)
Q11 What is the difference between a hard link and a symbolic (soft) link?
- Hard link: points to same inode. If original deleted, data still accessible. Same filesystem only.
- Soft link (symlink): points to filename path. Breaks if original deleted. Can cross filesystems.
- ln target link (hard). ln -s target link (soft)
- ls -la shows l for symlink and → target
Q12 What is a cron job? Write a cron expression to run a script every day at 2 AM.
- cron = time-based job scheduler in Unix. crontab -e to edit.
- Syntax: minute hour day month weekday command
- 0 2 * * * /path/to/script.sh = daily 2AM ⭐
- @reboot = on startup. */5 = every 5 mins. Log with >> /var/log/cron.log 2>&1
Q13 What is nohup? How do you run a process that survives after SSH disconnect?
- nohup: no hangup. Ignores SIGHUP signal sent when terminal closes.
- nohup cmd & — run in background, survive logout
- Output goes to nohup.out by default
- Better alternatives: tmux/screen sessions, systemd services
Q14 What does set -euo pipefail do in a bash script?
- -e: exit immediately if any command returns non-zero exit code
- -u: treat unset variables as errors (catches typos)
- -o pipefail: pipe fails if ANY command in it fails (not just last)
- Combined = "strict mode" — makes scripts much safer and debuggable
Q15 What is the difference between ssh -L and ssh -R tunneling?
- -L (local): forward local port to remote host. Access remote service locally.
- ssh -L 5432:db-server:5432 jumphost → localhost:5432 connects to db
- -R (remote): forward remote port to local host. Expose local service to remote.
- Use case: access internal databases, bypass firewalls securely
Q16 Explain inode in Linux. What information does it store?
- Inode: data structure storing file metadata. Every file has one.
- Stores: permissions, owner, timestamps, size, data block pointers. NOT filename.
- Filename → inode number stored in directory. Hard links share same inode.
- df -i: check inode usage. ls -i: show inode numbers.
Q17 What is the use of find vs locate? When would you prefer each?
- find: real-time search of filesystem. Slower but always current. More powerful (exec, filters).
- locate: searches pre-built database (updatedb). Extremely fast. May be outdated.
- find for scripts and complex conditions. locate for quick file finding.
- find supports -exec to run commands on results.
Q18 ⭐ What happens when you type a command in the shell and press Enter? Walk through the execution.
- Shell tokenizes input: command + arguments
- Checks for alias, builtin, then searches PATH for executable
- Shell fork()s — creates child process (copy of shell)
- Child execve()s — replaces itself with the program
- Parent wait()s for child to finish, gets exit code ($?)
- Redirections and pipes set up BEFORE exec
🔗 Follow-up: "What is the difference between fork() and exec()?"
Q19 ⭐ What is a zombie process? What causes it and how do you fix it?
- Zombie (defunct): process that has finished but still in process table (parent hasn't called wait())
- Shows as Z in ps. Uses no CPU/memory. Just occupies PID + process table entry.
- Fix: fix parent to call wait(). Or kill parent → init adopts and reaps zombie.
- Many zombies = parent bug. A few is normal briefly.
Q20 Explain the Linux boot process from power-on to shell prompt.
- BIOS/UEFI → POST → finds bootable device
- Bootloader (GRUB) loads kernel + initramfs into memory
- Kernel initializes hardware, mounts root filesystem
- init/systemd (PID 1) starts — the first user process
- systemd runs targets → login shell presented
Q21 What is umask? How does it affect default file permissions?
- umask = permissions MASK subtracted from default (666 files, 777 dirs)
- umask 022: files = 666-022 = 644 (rw-r--r--), dirs = 777-022 = 755
- umask 027: files = 640 (rw-r-----), group has no write, others nothing
- Set in .bashrc/profile. Check with: umask command
Q22 How does rsync work? What makes it efficient for large transfers?
- rsync uses delta-transfer algorithm: only transfers changed parts of files
- Computes checksums of file blocks, sends only diffs
- -a = archive (preserve permissions, timestamps, symlinks). -z = compress.
- --delete: mirrors source (removes extra files at dest). --dry-run: preview.
Q23 What is a file descriptor? How does 2>&1 work at the OS level?
- File descriptor: integer handle for open files/streams. 0=stdin, 1=stdout, 2=stderr.
- 2>&1 = make FD 2 point to same place as FD 1 (duplicate)
- Order matters: cmd > file 2>&1 (correct) vs cmd 2>&1 > file (wrong — stderr still to terminal)
- Every process inherits FDs from parent. Pipes connect stdout→stdin via FD manipulation.
Q24 How would you debug a shell script? What tools and techniques would you use?
- bash -x script.sh: xtrace — prints each command before executing ⭐
- set -x inside script: enable xtrace at a specific point
- set -v: verbose — print each line as read
- echo $? after commands to check exit codes. Add echo statements for tracing.
- shellcheck: static analysis tool — catches bugs before running