As an unprivileged user you run `sudo echo 'net.ipv4.ip_forward=1' > /etc/sysctl.d/99-fw.conf` and the shell answers with a permission error, even though sudo works for other commands. Which command line writes the file successfully?

LPIC-1 Exam 101-500, objective 103. GNU and Unix commands medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct echo 'net.ipv4.ip_forward=1' | sudo tee /etc/sysctl.d/99-fw.conf

Correct. The redirection is gone; tee itself opens the file, and tee is the process running under sudo, so the open succeeds. tee also echoes the line to standard output, which is why the text appears on the terminal.

Not correct sudo echo 'net.ipv4.ip_forward=1' >> /etc/sysctl.d/99-fw.conf

Wrong. >> appends instead of truncating, but the file is still opened by your own shell before sudo runs, so it fails with the same permission error.

Not correct sudo echo 'net.ipv4.ip_forward=1' | tee /etc/sysctl.d/99-fw.conf

Wrong. sudo is on the wrong side of the pipe: echo gains privileges it does not need, while tee, the process that actually opens the file, runs as you.

Not correct echo 'net.ipv4.ip_forward=1' | sudo cat > /etc/sysctl.d/99-fw.conf

Wrong. cat under sudo merely copies the text to its standard output, and that output is redirected by your unprivileged shell, so the open still fails.

Why

Redirections are performed by the shell that parses the command line, before the command is executed, so a > target is opened with the privileges of that shell and not with those granted by sudo. Piping into `sudo tee file` moves the file-opening into the privileged process. `sudo tee -a` is the append variant, and `sudo sh -c 'cmd > file'` works for the same reason: the redirecting shell is itself privileged.

Where this comes from

Cited
manual page tee(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 103 and space the ones you get wrong.

Practise LPIC-1 Exam 101-500

More questions on this objective

All questions on GNU and Unix commands

Practise LPIC-1 Exam 101-500