After an unexplained reboot you run `journalctl -b -1` and are told that no persistent journal was found, although the current boot's messages are readable. What makes the previous boot's messages available in future?

LPIC-1 Exam 101-500, objective 101. System architecture hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct Create /var/log/journal (or set Storage=persistent in /etc/systemd/journald.conf) and restart systemd-journald

Correct. With the default Storage=auto, journald writes to disk only if /var/log/journal already exists; otherwise it keeps the journal in /run/log/journal, which is tmpfs and is emptied at every boot.

Not correct Raise SystemMaxUse in /etc/systemd/journald.conf

Wrong. SystemMaxUse caps how much disk space the persistent journal may occupy. It has no effect while no persistent journal is being written at all.

Not correct Run `journalctl --vacuum-time=2weeks` to stop old boots being discarded

Wrong, and backwards. The vacuum options delete journal files that are older or larger than a given bound; they only ever remove data.

Not correct Install and enable rsyslog so that the journal is forwarded to /var/log/messages

Wrong for the question asked. Forwarding to a syslog daemon does give you plain-text files that survive a reboot, but it does not create a journal, so journalctl -b -1 still has no previous boot to offer.

Why

journald's Storage setting decides where records go: volatile means /run/log/journal only, persistent means /var/log/journal and creates the directory, and the default auto means persistent only if that directory already exists. Because /run is a tmpfs, a volatile journal cannot outlive the boot that wrote it, which is why boot offsets such as -b -1 fail on an otherwise healthy system. Once persistence is in place, `journalctl --list-boots` enumerates the boots the journal still holds and each gets its own boot ID.

Where this comes from

Cited
manual page journald.conf(5)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 101 and space the ones you get wrong.

Practise LPIC-1 Exam 101-500

More questions on this objective

All questions on System architecture

Practise LPIC-1 Exam 101-500