As an unprivileged user you run `sudo echo 'net.ipv4.ip_forward=1' > /etc/sysctl.d/99-fw.conf` and the shell answers with a permission error, even though sudo works for other commands. Which command line writes the file successfully?
LPIC-1 Exam 101-500, objective 103. GNU and Unix commands medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct echo 'net.ipv4.ip_forward=1' | sudo tee /etc/sysctl.d/99-fw.conf
Correct. The redirection is gone; tee itself opens the file, and tee is the process running under sudo, so the open succeeds. tee also echoes the line to standard output, which is why the text appears on the terminal.
Not correct sudo echo 'net.ipv4.ip_forward=1' >> /etc/sysctl.d/99-fw.conf
Wrong. >> appends instead of truncating, but the file is still opened by your own shell before sudo runs, so it fails with the same permission error.
Not correct sudo echo 'net.ipv4.ip_forward=1' | tee /etc/sysctl.d/99-fw.conf
Wrong. sudo is on the wrong side of the pipe: echo gains privileges it does not need, while tee, the process that actually opens the file, runs as you.
Not correct echo 'net.ipv4.ip_forward=1' | sudo cat > /etc/sysctl.d/99-fw.conf
Wrong. cat under sudo merely copies the text to its standard output, and that output is redirected by your unprivileged shell, so the open still fails.
Why
Redirections are performed by the shell that parses the command line, before the command is executed, so a > target is opened with the privileges of that shell and not with those granted by sudo. Piping into `sudo tee file` moves the file-opening into the privileged process. `sudo tee -a` is the append variant, and `sudo sh -c 'cmd > file'` works for the same reason: the redirecting shell is itself privileged.
Where this comes from
- Cited
- manual page tee(1)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 103 and space the ones you get wrong.
More questions on this objective
- A user starts a new terminal window in a running graphical desktop session, which launches bash as an interactive shell that is NOT a login shell. Which file in the user's home directory does bash read in that case? machine-checked
- In bash, which history expansion re-runs the entire previous command line? machine-checked
- Which bash command prints the literal five characters $USER instead of the current user name? machine-checked
- You want /opt/bin searched for executables, after all the directories already in PATH, in the current bash session and in every command started from it. Which command does that? machine-checked
- There is a passwd manual page in section 1 (the command) and another in section 5 (the /etc/passwd file format). Which command opens the section 5 page? machine-checked
- Select the TWO true statements about shell variables and the environment in bash. machine-checked