Select the THREE true statements about GNU find's time-based tests.
LPIC-1 Exam 101-500, objective 103. GNU and Unix commands hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Choose 3.
Correct -mtime +7 matches files whose contents were last modified at least eight 24-hour periods ago.
Correct. A plus sign means "greater than", and find discards the fractional part when it works out how many 24-hour periods old a file is — so to satisfy +7 the truncated age must be 8 or more, which means the file has to be at least eight days old.
Correct -mtime -1 matches files modified within the last 24 hours.
Correct. A minus sign means "less than", so -1 covers everything modified since one 24-hour period ago.
Correct -mmin -30 matches files modified within the last 30 minutes.
Correct. The -min family takes the same +, - and exact forms as the -time family but counts in minutes: -amin, -cmin, -mmin.
Not correct -atime tests when the file's inode metadata, such as its permissions or ownership, last changed.
Wrong. That is -ctime. -atime tests the last ACCESS time, which is updated when the file's contents are read.
Not correct -mtime 7 matches every file modified at any point during the last seven days.
Wrong. A bare number means exactly that many periods: -mtime 7 matches files modified between 7 and 8 days ago, because the age is truncated to a whole number of days. The "during the last seven days" test is -mtime -7.
Why
Every numeric find test reads the same way: +n means more than n, -n means fewer than n, and a bare n means exactly n, with any fractional part of the unit discarded. The three timestamps are access (-atime/-amin), inode change (-ctime/-cmin) and modification (-mtime/-mmin). Getting the sign wrong is the classic way to delete the files you meant to keep, so it is worth running the find alone before adding -delete.
Where this comes from
- Cited
- manual page find(1)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 103 and space the ones you get wrong.
More questions on this objective
- A user starts a new terminal window in a running graphical desktop session, which launches bash as an interactive shell that is NOT a login shell. Which file in the user's home directory does bash read in that case? machine-checked
- In bash, which history expansion re-runs the entire previous command line? machine-checked
- Which bash command prints the literal five characters $USER instead of the current user name? machine-checked
- You want /opt/bin searched for executables, after all the directories already in PATH, in the current bash session and in every command started from it. Which command does that? machine-checked
- There is a passwd manual page in section 1 (the command) and another in section 5 (the /etc/passwd file format). Which command opens the section 5 page? machine-checked
- Select the TWO true statements about shell variables and the environment in bash. machine-checked