Which THREE statements about logrotate directives and how logrotate is run are correct? (Choose three.)
LPIC-1 Exam 102-500, objective 108. Essential system services medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Choose 3.
Correct `rotate 4` keeps four rotated copies; when a fifth would be created the oldest is deleted instead.
Correct. The count is the number of old versions retained, so nothing older than the fourth survives a rotation; `rotate 0` keeps none at all and the log is simply emptied.
Correct `compress` runs the rotated files through gzip.
Correct by default; the program and its arguments can be changed with compresscmd and compressoptions, and the resulting suffix with compressext.
Correct `missingok` stops logrotate from treating an absent log file as an error.
Correct. It is normal in a package's drop-in file, because a service may never have been started and so may never have created its log.
Not correct `notifempty` forces rotation even when the log file contains nothing.
Wrong, and the exact inverse: notifempty skips rotation while the file is empty. The directive that rotates regardless is ifempty, which is the default.
Not correct `copytruncate` renames the log and then creates a replacement file with the same name.
Wrong; that describes the default behaviour together with create. copytruncate keeps the original file and its inode, copying the contents away and then truncating it.
Not correct logrotate runs as its own daemon and must be enabled with `systemctl enable logrotated`.
Wrong. There is no such daemon. logrotate is a program invoked periodically, by a cron job in /etc/cron.daily or by the logrotate.timer unit, and it can be run by hand at any time.
Why
/etc/logrotate.conf carries the site-wide defaults and an include line pulling in /etc/logrotate.d/, where packages drop per-service stanzas; a directive inside a stanza overrides the global one for those files only. Because logrotate is periodic rather than resident, it decides at each run whether a stanza's interval — daily, weekly, monthly — has elapsed, using its state file, which the distribution places under /var/lib/logrotate/ and which -s can override. `logrotate -d /etc/logrotate.conf` shows what a run would do without touching anything.
Where this comes from
- Cited
- manual page logrotate(8)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 108 and space the ones you get wrong.
More questions on this objective
- You corrected the running system's clock with `date -s`, but after the next power cycle the machine came back with the old wrong time. Which command copies the corrected system clock into the hardware (RTC) clock? machine-checked
- On a systemd-based distribution, which file determines the local time zone used by the C library when formatting times? machine-checked
- A host runs chrony as its NTP client. Which command shows the list of time sources chrony is currently talking to and how it rates each one? machine-checked
- In /etc/ntp.conf you find the line `server 0.pool.ntp.org iburst`. What does the `iburst` keyword do? machine-checked
- A minimal systemd host synchronises its clock with systemd-timesyncd. Which statement about that service is accurate? machine-checked
- On a systemd host, type the single command that turns on automatic network time synchronisation (do not include a path). machine-checked