{"id":78875,"date":"2026-10-06T05:26:16","date_gmt":"2026-10-06T05:26:16","guid":{"rendered":"https:\/\/www.devopsschool.com\/blog\/?p=78875"},"modified":"2026-10-06T05:26:19","modified_gmt":"2026-10-06T05:26:19","slug":"red-hat-ex342-complete-home-study-curriculum","status":"publish","type":"post","link":"https:\/\/www.devopsschool.com\/blog\/red-hat-ex342-complete-home-study-curriculum\/","title":{"rendered":"Red Hat EX342 Complete Home-Study Curriculum"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Gold-Standard Self-Study Textbook + Laboratory Manual + Exam Preparation Roadmap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Research cut-off:<\/strong>&nbsp;6 October 2026<br><strong>Primary authority:<\/strong>&nbsp;current Red Hat official EX342, certification, policy, and RHEL 10 documentation<br><strong>Learner model:<\/strong>&nbsp;100% home self-study; Red Hat training courses are optional preparation, not assumed<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Accuracy rule:<\/strong>&nbsp;If the live Red Hat EX342 page, the candidate&#8217;s assigned LMS exam version, or newer official Red Hat documentation differs from this guide, the current Red Hat source wins.<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">Executive Verification \u2014 What EX342 Is Right Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As of this guide&#8217;s research cut-off:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Item<\/th><th class=\"has-text-align-left\" data-align=\"left\">Current verified status<\/th><\/tr><\/thead><tbody><tr><td>Exam code<\/td><td><strong>EX342<\/strong><\/td><\/tr><tr><td>Exact exam name<\/td><td><strong>Red Hat Certified Advanced System Administrator in Enterprise Linux exam<\/strong><\/td><\/tr><tr><td>Credential earned by passing EX342<\/td><td><strong>Red Hat Certified Advanced System Administrator in Enterprise Linux (RHCASA \u2014 Enterprise Linux)<\/strong><\/td><\/tr><tr><td>Exam style<\/td><td><strong>Hands-on, practical \/ performance-based<\/strong><\/td><\/tr><tr><td>Current public exam platform<\/td><td><strong>Red Hat Enterprise Linux 10.2<\/strong><\/td><\/tr><tr><td>Time limit<\/td><td><strong>4 hours<\/strong><\/td><\/tr><tr><td>Outside assistance<\/td><td>Not permitted; relevant product documentation is provided in the exam environment<\/td><\/tr><tr><td>Multiple exam versions<\/td><td><strong>Yes.<\/strong>&nbsp;Red Hat states multiple versions may be in use; candidates should check the assigned version\/objectives in the Red Hat LMS<\/td><\/tr><tr><td>RHCSA required merely to earn the EX342 credential<\/td><td><strong>Not listed as a mandatory exam-registration prerequisite on the current EX342 page.<\/strong>&nbsp;RHCSA or equivalent systems-administration experience is listed under&nbsp;<strong>Recommended Preparation<\/strong><\/td><\/tr><tr><td>RHCSA required for RHCE in Enterprise Linux<\/td><td><strong>Yes.<\/strong>&nbsp;Current RHCE-Enterprise Linux requirements are&nbsp;<strong>EX200 + EX342<\/strong><\/td><\/tr><tr><td>Training course RH342 mandatory<\/td><td><strong>No.<\/strong>&nbsp;Red Hat recommends RH342&nbsp;<strong>or similar troubleshooting experience<\/strong><\/td><\/tr><tr><td>Standard list price<\/td><td><strong>USD $500<\/strong>&nbsp;in the current Red Hat Certification Program Guide; actual regional price may differ<\/td><\/tr><tr><td>Japan-specific price<\/td><td><strong>Not verified as a fixed public JPY amount. Check the live Red Hat Japan purchase\/cart page<\/strong><\/td><\/tr><tr><td>Free retake<\/td><td>Current policy provides&nbsp;<strong>one free retake<\/strong>&nbsp;after an unsuccessful paid first attempt, subject to policy terms<\/td><\/tr><tr><td>Certification currency<\/td><td>Current Red Hat certifications are&nbsp;<strong>current for 3 years<\/strong>&nbsp;and must be renewed before becoming non-current<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">The 2026 certification relationship<\/h3>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">EX342 passed\n    |\n    v\nRed Hat Certified Advanced System Administrator\nin Enterprise Linux\n    |\n    +----------------------------+\n                                 |\nEX200 \/ RHCSA -------------------+\n                                 |\n                                 v\n                Red Hat Certified Engineer\n                in Enterprise Linux\n<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>Important:<\/strong>&nbsp;EX342 is not the same exam as EX294. EX342 is the advanced Enterprise Linux troubleshooting credential. EX294 is the advanced Ansible administration credential in the Ansible track.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2026 name\/framework change<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On 11 May 2026, Red Hat moved to a specialization-based framework. The credential previously named&nbsp;<strong>Red Hat Certified Specialist in Linux Diagnostics and Troubleshooting<\/strong>&nbsp;was renamed&nbsp;<strong>Red Hat Certified Advanced System Administrator in Enterprise Linux<\/strong>. Red Hat explicitly states that for these mapped certifications the&nbsp;<strong>name changed but the exam SKU, content, description, and difficulty did not change solely because of the framework restructuring<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Official sources:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>EX342:\u00a0<a href=\"https:\/\/www.redhat.com\/en\/services\/training\/ex342-red-hat-certified-specialist-linux-diagnostics-and-troubleshooting\">https:\/\/www.redhat.com\/en\/services\/training\/ex342-red-hat-certified-specialist-linux-diagnostics-and-troubleshooting<\/a><\/li>\n\n\n\n<li>Certification framework\/catalog:\u00a0<a href=\"https:\/\/www.redhat.com\/en\/services\/certifications\">https:\/\/www.redhat.com\/en\/services\/certifications<\/a><\/li>\n\n\n\n<li>Framework FAQ:\u00a0<a href=\"https:\/\/www.redhat.com\/en\/services\/training-and-certification\/faq\">https:\/\/www.redhat.com\/en\/services\/training-and-certification\/faq<\/a><\/li>\n\n\n\n<li>RHCE in Enterprise Linux:\u00a0<a href=\"https:\/\/www.redhat.com\/en\/services\/certification\/red-hat-certified-engineer-in-enterprise-linux\">https:\/\/www.redhat.com\/en\/services\/certification\/red-hat-certified-engineer-in-enterprise-linux<\/a><\/li>\n\n\n\n<li>Certification Program Guide:\u00a0<a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index<\/a><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 1 \u2014 What Is EX342?<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">1.1 Exact current exam<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>EX342 \u2014 Red Hat Certified Advanced System Administrator in Enterprise Linux exam<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exam measures the ability to analyze RHEL systems for common issues that can cause degradation or loss of performance, correct those issues when appropriate, or gather forensic\/diagnostic information for escalation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is a&nbsp;<strong>performance-based exam<\/strong>: candidates work on live systems rather than answering conventional multiple-choice questions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The current public EX342 page states that the exam tasks are based on&nbsp;<strong>RHEL 10.2<\/strong>&nbsp;and the time limit is&nbsp;<strong>4 hours<\/strong>. Red Hat also warns that&nbsp;<strong>multiple versions of the exam are in use<\/strong>. Always verify the assigned version and objectives in the LMS before the test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1.2 What certification do you receive?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Passing EX342 earns:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Red Hat Certified Advanced System Administrator in Enterprise Linux<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That credential stands on its own.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To earn&nbsp;<strong>Red Hat Certified Engineer in Enterprise Linux<\/strong>, the current certification catalog requires both:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>EX200 \/ RHCSA<\/strong>, and<\/li>\n\n\n\n<li><strong>EX342 \/ RHCASA in Enterprise Linux<\/strong><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Pass EX342 only\n= RHCASA in Enterprise Linux\n\nPass EX200 + EX342\n= RHCE in Enterprise Linux\n<\/code><\/span><\/pre>\n\n\n<h2 class=\"wp-block-heading\">1.3 What EX342 validates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The current Red Hat scope is heavily centered on diagnosis and recovery:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>troubleshooting methodology and documentation<\/li>\n\n\n\n<li>live monitoring<\/li>\n\n\n\n<li>RHEL web console<\/li>\n\n\n\n<li>Ansible-based system configuration<\/li>\n\n\n\n<li>centralized logging<\/li>\n\n\n\n<li>file-integrity monitoring with AIDE<\/li>\n\n\n\n<li>startup and boot recovery<\/li>\n\n\n\n<li>hardware and kernel-module troubleshooting<\/li>\n\n\n\n<li>filesystem, LVM, and encrypted-storage recovery<\/li>\n\n\n\n<li>package\/RPM database troubleshooting<\/li>\n\n\n\n<li>networking and packet inspection<\/li>\n\n\n\n<li>application dependency, memory, tracing, and SELinux diagnosis<\/li>\n\n\n\n<li>PAM and local account policy<\/li>\n\n\n\n<li>kernel crash dumps<\/li>\n\n\n\n<li>support\/diagnostic data collection<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a generic &#8220;advanced Linux&#8221; exam. Every module in this guide maps back to one or more official EX342 objectives.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 2 \u2014 EX342 Prerequisites<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Requirement<\/th><th class=\"has-text-align-right\" data-align=\"right\">Mandatory?<\/th><th class=\"has-text-align-left\" data-align=\"left\">Current official Red Hat position<\/th><th class=\"has-text-align-left\" data-align=\"left\">Practical interpretation<\/th><\/tr><\/thead><tbody><tr><td>RHCSA certification<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>Not listed as mandatory to sit\/pass EX342 itself<\/strong><\/td><td>Listed under&nbsp;<strong>Recommended Preparation<\/strong>&nbsp;as &#8220;earned RHCSA or equivalent systems administration experience&#8221;<\/td><td>Strongly recommended baseline;&nbsp;<strong>required if your final goal is RHCE in Enterprise Linux<\/strong><\/td><\/tr><tr><td>EX200<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>Not listed as mandatory for the standalone EX342 credential<\/strong><\/td><td>EX200 + EX342 are required for RHCE-Enterprise Linux<\/td><td>You can treat EX342 as its own advanced credential, but RHCE requires both<\/td><\/tr><tr><td>Work experience<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>No fixed duration published<\/strong><\/td><td>Red Hat recommends RH342 or similar troubleshooting experience<\/td><td>Practical troubleshooting experience matters; no official number of years is specified<\/td><\/tr><tr><td>RH342 training course<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>No<\/strong><\/td><td>Recommended&nbsp;<strong>or similar experience<\/strong><\/td><td>Self-study is possible<\/td><\/tr><tr><td>Another certification<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>No mandatory certification shown for EX342 credential itself<\/strong><\/td><td>The EX342 page awards RHCASA on passing<\/td><td>RHCSA remains the foundation for RHCE-Enterprise Linux<\/td><\/tr><tr><td>Another exam<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>No mandatory prior exam shown for EX342 itself<\/strong><\/td><td>EX200 is a separate RHCE requirement<\/td><td>Do not confuse certification stacking with exam-registration prerequisites<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Mandatory prerequisite vs recommended preparation vs optional training<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mandatory prerequisite<\/strong>&nbsp;means Red Hat explicitly requires it before the credential can be awarded.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Recommended preparation<\/strong>&nbsp;means Red Hat recommends a background such as RHCSA-level skill or equivalent experience, but the exam page does not list it as a mandatory standalone EX342 prerequisite.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Optional training<\/strong>&nbsp;means a Red Hat course can help, but is not a requirement to self-study or sit the exam unless a future official page explicitly says otherwise.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Current public-page conclusion:<\/strong>&nbsp;The current EX342 page does not list RHCSA as a mandatory prerequisite for the standalone EX342\/RHCASA credential; it recommends RHCSA or equivalent experience. The RHCE-Enterprise Linux credential, however, requires EX200 + EX342.<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 3 \u2014 Current Official EX342 Objectives<\/h1>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">The wording below follows the current Red Hat EX342 objective page. These are the source-of-truth domains used throughout this curriculum.<\/p>\n<\/blockquote>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">#<\/th><th class=\"has-text-align-left\" data-align=\"left\">Official objective<\/th><th class=\"has-text-align-left\" data-align=\"left\">Skills represented<\/th><th class=\"has-text-align-left\" data-align=\"left\">Command\/tool families<\/th><th class=\"has-text-align-left\" data-align=\"left\">Lab priority<\/th><\/tr><\/thead><tbody><tr><td>1<\/td><td><strong>Understand and employ general methods for troubleshooting<\/strong><\/td><td>Consult documentation resources to aid in troubleshooting; Monitor systems for vital characteristics; Monitor systems with the RHEL Web console; Configure systems using Ansible; Configure systems to send log messages to a centralized host; Configure systems to monitor files and directories using AIDE<\/td><td>man\/journalctl\/top\/Cockpit\/Ansible\/rsyslog\/AIDE<\/td><td><strong>Critical<\/strong><\/td><\/tr><tr><td>2<\/td><td><strong>Diagnose and troubleshoot system startup issues<\/strong><\/td><td>Identify and resolve service failures affecting boot; Regain root control of a system; Troubleshoot boot issues; Identify hardware and hardware problems; Manage kernel modules and their parameters<\/td><td>systemctl\/journalctl\/rescue\/grubby\/kmod tools<\/td><td><strong>Critical<\/strong><\/td><\/tr><tr><td>3<\/td><td><strong>Diagnose and troubleshoot file system issues<\/strong><\/td><td>Recover corrupted file systems; Recover misconfigured or broken LVM configurations; Recover data from encrypted file systems<\/td><td>xfs_repair\/e2fsck\/LVM\/cryptsetup<\/td><td><strong>Critical<\/strong><\/td><\/tr><tr><td>4<\/td><td><strong>Resolve package management issues<\/strong><\/td><td>Resolve package management dependency issues; Recover a corrupted RPM database; Identify and report changed files<\/td><td>dnf\/rpm\/rpmdb\/package verification<\/td><td><strong>Critical<\/strong><\/td><\/tr><tr><td>5<\/td><td><strong>Troubleshoot and fix network connectivity issues<\/strong><\/td><td>Use standard tools to verify network connectivity; Identify and fix network connectivity issues; Inspect network traffic to aid troubleshooting<\/td><td>ip\/nmcli\/ss\/tcpdump\/name-resolution tools<\/td><td><strong>Critical<\/strong><\/td><\/tr><tr><td>6<\/td><td><strong>Diagnose application issues<\/strong><\/td><td>Identify library dependencies for third-party software; Identify if an application suffers from memory leaks; Use standard tools to debug an application; Identify and fix issues related to SELinux<\/td><td>ldd\/readelf\/strace\/ltrace\/valgrind\/SELinux tools<\/td><td><strong>Critical<\/strong><\/td><\/tr><tr><td>7<\/td><td><strong>Identify and fix authentication issues<\/strong><\/td><td>Identify and fix pluggable authentication module (PAM) issues; Identify and enforce local user account policies<\/td><td>authselect\/PAM\/faillock\/chage\/account tools<\/td><td><strong>Critical<\/strong><\/td><\/tr><tr><td>8<\/td><td><strong>Gather information to aid third-party investigation of issues<\/strong><\/td><td>Create kernel crash dumps; Collect system information to aid in troubleshooting<\/td><td>kdump\/sos\/journal\/kernel\/system inventory<\/td><td><strong>Critical<\/strong><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Objective coverage check<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. Understand and employ general methods for troubleshooting<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Consult documentation resources to aid in troubleshooting<\/li>\n\n\n\n<li>[ ] Monitor systems for vital characteristics<\/li>\n\n\n\n<li>[ ] Monitor systems with the RHEL Web console<\/li>\n\n\n\n<li>[ ] Configure systems using Ansible<\/li>\n\n\n\n<li>[ ] Configure systems to send log messages to a centralized host<\/li>\n\n\n\n<li>[ ] Configure systems to monitor files and directories using AIDE<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Diagnose and troubleshoot system startup issues<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Identify and resolve service failures affecting boot<\/li>\n\n\n\n<li>[ ] Regain root control of a system<\/li>\n\n\n\n<li>[ ] Troubleshoot boot issues<\/li>\n\n\n\n<li>[ ] Identify hardware and hardware problems<\/li>\n\n\n\n<li>[ ] Manage kernel modules and their parameters<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Diagnose and troubleshoot file system issues<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Recover corrupted file systems<\/li>\n\n\n\n<li>[ ] Recover misconfigured or broken LVM configurations<\/li>\n\n\n\n<li>[ ] Recover data from encrypted file systems<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Resolve package management issues<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Resolve package management dependency issues<\/li>\n\n\n\n<li>[ ] Recover a corrupted RPM database<\/li>\n\n\n\n<li>[ ] Identify and report changed files<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>5. Troubleshoot and fix network connectivity issues<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Use standard tools to verify network connectivity<\/li>\n\n\n\n<li>[ ] Identify and fix network connectivity issues<\/li>\n\n\n\n<li>[ ] Inspect network traffic to aid troubleshooting<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>6. Diagnose application issues<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Identify library dependencies for third-party software<\/li>\n\n\n\n<li>[ ] Identify if an application suffers from memory leaks<\/li>\n\n\n\n<li>[ ] Use standard tools to debug an application<\/li>\n\n\n\n<li>[ ] Identify and fix issues related to SELinux<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>7. Identify and fix authentication issues<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Identify and fix pluggable authentication module (PAM) issues<\/li>\n\n\n\n<li>[ ] Identify and enforce local user account policies<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>8. Gather information to aid third-party investigation of issues<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Create kernel crash dumps<\/li>\n\n\n\n<li>[ ] Collect system information to aid in troubleshooting<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 4 \u2014 Objective-by-Objective Breakdown<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 1 \u2014 Understand and employ general methods for troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build a repeatable troubleshooting method. Begin with the reported symptom, establish scope and timeline, collect evidence, compare actual state with intended state, test one hypothesis at a time, make the smallest safe correction, then verify persistence. EX342 explicitly includes monitoring, the RHEL web console, Ansible configuration, centralized logging, and AIDE.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Consult documentation resources to aid in troubleshooting<\/li>\n\n\n\n<li>Monitor systems for vital characteristics<\/li>\n\n\n\n<li>Monitor systems with the RHEL Web console<\/li>\n\n\n\n<li>Configure systems using Ansible<\/li>\n\n\n\n<li>Configure systems to send log messages to a centralized host<\/li>\n\n\n\n<li>Configure systems to monitor files and directories using AIDE<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>man<\/code>,&nbsp;<code>info<\/code>,&nbsp;<code>journalctl<\/code>,&nbsp;<code>dmesg<\/code>,&nbsp;<code>systemctl<\/code>,&nbsp;<code>ps<\/code>,&nbsp;<code>top<\/code>,&nbsp;<code>vmstat<\/code>,&nbsp;<code>free<\/code>,&nbsp;<code>uptime<\/code>,&nbsp;<code>iostat<\/code>,&nbsp;<code>ss<\/code>,&nbsp;<code>lsof<\/code>,&nbsp;<code>cockpit<\/code>,&nbsp;<code>ansible<\/code>,&nbsp;<code>ansible-playbook<\/code>,&nbsp;<code>logger<\/code>,&nbsp;<code>rsyslogd -N1<\/code>,&nbsp;<code>aide --init<\/code>,&nbsp;<code>aide --check<\/code>,&nbsp;<code>aide --update<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/rsyslog.conf, \/etc\/rsyslog.d\/*.conf, \/etc\/aide.conf, \/var\/lib\/aide\/, \/etc\/ansible\/ansible.cfg, inventory files<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Monitor CPU, memory, processes, storage, and network activity from both CLI and RHEL web console.<\/li>\n\n\n\n<li>Prepare a small Ansible control node and make an idempotent change on two managed nodes.<\/li>\n\n\n\n<li>Configure node2 as a centralized rsyslog receiver and send logs from node1; verify by generating messages with logger.<\/li>\n\n\n\n<li>Initialize AIDE, modify monitored files, detect the change, update the approved baseline, and verify a clean result.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Break rsyslog forwarding, corrupt an Ansible inventory entry, stop cockpit.socket, and change an AIDE-monitored file. Diagnose each from observable evidence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A managed system is not forwarding logs, a required configuration differs from the desired Ansible state, and AIDE reports a file change. Restore and verify all three.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 2 \u2014 Diagnose and troubleshoot system startup issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Startup troubleshooting requires distinguishing boot-loader, kernel\/initramfs, systemd target, mount, and service failures. RHEL 10 documentation also provides installation-media rescue mode for systems that cannot boot normally. Kernel-module tasks include inspecting loaded modules, parameters, dependencies, loading\/unloading, and persistent configuration.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identify and resolve service failures affecting boot<\/li>\n\n\n\n<li>Regain root control of a system<\/li>\n\n\n\n<li>Troubleshoot boot issues<\/li>\n\n\n\n<li>Identify hardware and hardware problems<\/li>\n\n\n\n<li>Manage kernel modules and their parameters<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>systemctl --failed<\/code>,&nbsp;<code>systemctl status<\/code>,&nbsp;<code>systemctl list-dependencies<\/code>,&nbsp;<code>journalctl -b<\/code>,&nbsp;<code>journalctl -b -1<\/code>,&nbsp;<code>dmesg<\/code>,&nbsp;<code>grubby<\/code>,&nbsp;<code>lsmod<\/code>,&nbsp;<code>modinfo<\/code>,&nbsp;<code>modprobe<\/code>,&nbsp;<code>modprobe -r<\/code>,&nbsp;<code>depmod<\/code>,&nbsp;<code>lspci<\/code>,&nbsp;<code>lsusb<\/code>,&nbsp;<code>lscpu<\/code>,&nbsp;<code>lsblk<\/code>,&nbsp;<code>fdisk -l<\/code>,&nbsp;<code>chroot<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/systemd\/system\/, \/usr\/lib\/systemd\/system\/, \/etc\/modules-load.d\/<em>.conf, \/etc\/modprobe.d\/<\/em>.conf, \/boot\/loader\/entries\/, \/etc\/default\/grub<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create a boot failure caused by a bad systemd dependency and recover from it.<\/li>\n\n\n\n<li>Boot RHEL installation media into rescue mode, mount the installed system, chroot, inspect logs and configuration, then exit safely.<\/li>\n\n\n\n<li>Load and unload a harmless kernel module, inspect its parameters, configure persistent loading, reboot, and verify.<\/li>\n\n\n\n<li>Blacklist a lab-safe module temporarily and permanently, then reverse the change.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Introduce an invalid persistent mount or failed required service; recover using console\/rescue access. Simulate a wrong kernel-module setting and confirm the effect after reboot.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A VM stops during startup because of a configuration fault. Regain administrative control, identify the failure from evidence, correct it, boot normally, and prove the fix survives another reboot.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 3 \u2014 Diagnose and troubleshoot file system issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">EX342 is recovery-focused rather than merely creation-focused. You must be able to recognize filesystem damage, choose the correct filesystem-specific recovery tool, recover LVM metadata carefully, and diagnose encrypted-volume problems without destroying recoverable data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Recover corrupted file systems<\/li>\n\n\n\n<li>Recover misconfigured or broken LVM configurations<\/li>\n\n\n\n<li>Recover data from encrypted file systems<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>lsblk -f<\/code>,&nbsp;<code>blkid<\/code>,&nbsp;<code>findmnt<\/code>,&nbsp;<code>mount<\/code>,&nbsp;<code>umount<\/code>,&nbsp;<code>xfs_repair<\/code>,&nbsp;<code>e2fsck<\/code>,&nbsp;<code>xfs_metadump<\/code>,&nbsp;<code>pvs<\/code>,&nbsp;<code>vgs<\/code>,&nbsp;<code>lvs<\/code>,&nbsp;<code>pvscan<\/code>,&nbsp;<code>vgscan<\/code>,&nbsp;<code>lvscan<\/code>,&nbsp;<code>lvmdump<\/code>,&nbsp;<code>vgcfgbackup<\/code>,&nbsp;<code>vgcfgrestore<\/code>,&nbsp;<code>pvcreate --uuid --restorefile<\/code>,&nbsp;<code>lvchange<\/code>,&nbsp;<code>cryptsetup luksDump<\/code>,&nbsp;<code>cryptsetup open<\/code>,&nbsp;<code>cryptsetup close<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/fstab, \/etc\/crypttab, \/etc\/lvm\/lvm.conf, \/etc\/lvm\/backup\/, \/etc\/lvm\/archive\/<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create XFS and ext4 lab filesystems, take snapshots, then practice safe unmount\/check\/repair procedures appropriate to each filesystem.<\/li>\n\n\n\n<li>Back up LVM metadata, damage only the disposable lab PV metadata, recover it from \/etc\/lvm\/archive, activate the LV, and verify data.<\/li>\n\n\n\n<li>Create a LUKS volume, record identifiers safely, break only its boot-time mapping configuration, recover access, and verify files.<\/li>\n\n\n\n<li>Practice collecting evidence before running destructive repair options; document when a last-resort option would risk data loss.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Wrong UUID in fstab, missing PV metadata, inactive VG\/LV, damaged XFS metadata in a disposable filesystem, incorrect crypttab entry.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Restore three storage failures: a filesystem that will not mount, an LVM stack that is incomplete, and an encrypted volume whose data must remain intact.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 4 \u2014 Resolve package management issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The objective is not generic package installation. It is diagnosing dependency problems, recovering an unusable RPM database, and identifying files that differ from package metadata. Practice DNF dependency reasoning, package ownership queries, package verification, and database recovery on disposable snapshots.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Resolve package management dependency issues<\/li>\n\n\n\n<li>Recover a corrupted RPM database<\/li>\n\n\n\n<li>Identify and report changed files<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>dnf repolist<\/code>,&nbsp;<code>dnf list<\/code>,&nbsp;<code>dnf info<\/code>,&nbsp;<code>dnf repoquery<\/code>,&nbsp;<code>dnf provides<\/code>,&nbsp;<code>dnf install<\/code>,&nbsp;<code>dnf reinstall<\/code>,&nbsp;<code>dnf remove<\/code>,&nbsp;<code>dnf clean all<\/code>,&nbsp;<code>rpm -qa<\/code>,&nbsp;<code>rpm -qf<\/code>,&nbsp;<code>rpm -ql<\/code>,&nbsp;<code>rpm -V<\/code>,&nbsp;<code>rpm -Va<\/code>,&nbsp;<code>rpm --rebuilddb<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/dnf\/dnf.conf, \/etc\/yum.repos.d\/*.repo, RPM database under \/var\/lib\/rpm\/<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create a repository\/dependency failure and determine whether the root cause is repository availability, architecture, version, or missing dependency.<\/li>\n\n\n\n<li>Modify a packaged configuration\/binary copy and use RPM verification to identify the change.<\/li>\n\n\n\n<li>On a snapshot-only lab clone, simulate RPM database trouble, preserve evidence\/backups, rebuild the database, and verify rpm\/dnf operation.<\/li>\n\n\n\n<li>Reinstall a package to restore changed package-owned files and confirm with verification.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Disable a needed repository, create an impossible package dependency in a lab RPM scenario, change a package-owned file, and damage a disposable copy of the RPM database.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Restore package management to a working state and produce evidence identifying which package-owned files had changed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 5 \u2014 Troubleshoot and fix network connectivity issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Troubleshoot systematically from link state and addressing through route selection, name resolution, socket\/listener state, firewall, and application reachability. Packet inspection is explicitly in scope, so you must know when tcpdump evidence proves where traffic stops.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use standard tools to verify network connectivity<\/li>\n\n\n\n<li>Identify and fix network connectivity issues<\/li>\n\n\n\n<li>Inspect network traffic to aid troubleshooting<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>ip link<\/code>,&nbsp;<code>ip addr<\/code>,&nbsp;<code>ip route<\/code>,&nbsp;<code>ip neigh<\/code>,&nbsp;<code>nmcli<\/code>,&nbsp;<code>ping<\/code>,&nbsp;<code>tracepath<\/code>,&nbsp;<code>getent hosts<\/code>,&nbsp;<code>resolvectl<\/code>,&nbsp;<code>ss -lntup<\/code>,&nbsp;<code>ethtool<\/code>,&nbsp;<code>tcpdump<\/code>,&nbsp;<code>curl<\/code>,&nbsp;<code>nc<\/code>,&nbsp;<code>firewall-cmd<\/code>,&nbsp;<code>journalctl -u NetworkManager<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/NetworkManager\/system-connections\/*.nmconnection, \/etc\/hosts, \/etc\/resolv.conf, \/etc\/firewalld\/<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create two static lab networks and verify L2\/L3 connectivity and routes.<\/li>\n\n\n\n<li>Break DNS while leaving IP connectivity intact; diagnose by comparing address-based and name-based tests.<\/li>\n\n\n\n<li>Create a wrong gateway or prefix and diagnose route selection.<\/li>\n\n\n\n<li>Capture ICMP and TCP handshakes with tcpdump; distinguish no route, filtered traffic, connection refused, and successful handshake.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Wrong IP\/prefix, missing route, incorrect DNS, stopped listener, firewall block, duplicate address, disabled NetworkManager profile.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A service is reachable from localhost but not from another VM. Identify the failing layer using standard tools and packet capture, fix it, and verify persistence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 6 \u2014 Diagnose application issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">EX342 expects operational application diagnosis. You should be able to inspect dynamic-library dependencies, identify memory-growth problems, trace process behavior, work with core dumps where useful, and prove whether SELinux is the cause rather than disabling it reflexively.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identify library dependencies for third-party software<\/li>\n\n\n\n<li>Identify if an application suffers from memory leaks<\/li>\n\n\n\n<li>Use standard tools to debug an application<\/li>\n\n\n\n<li>Identify and fix issues related to SELinux<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>ldd<\/code>,&nbsp;<code>readelf<\/code>,&nbsp;<code>objdump<\/code>,&nbsp;<code>file<\/code>,&nbsp;<code>strace<\/code>,&nbsp;<code>ltrace<\/code>,&nbsp;<code>gdb<\/code>,&nbsp;<code>coredumpctl<\/code>,&nbsp;<code>pgrep<\/code>,&nbsp;<code>ps<\/code>,&nbsp;<code>top<\/code>,&nbsp;<code>vmstat<\/code>,&nbsp;<code>valgrind<\/code>,&nbsp;<code>ausearch<\/code>,&nbsp;<code>journalctl -t setroubleshoot<\/code>,&nbsp;<code>getenforce<\/code>,&nbsp;<code>setenforce<\/code>,&nbsp;<code>restorecon<\/code>,&nbsp;<code>semanage<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/ld.so.conf, \/etc\/ld.so.conf.d\/*.conf, \/var\/log\/audit\/audit.log, SELinux file-context policy database<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Build or install a small test binary, inspect shared-library requirements, and diagnose a missing-library scenario.<\/li>\n\n\n\n<li>Run a deliberately leaky test program under valgrind memcheck and correlate increasing memory with process monitoring.<\/li>\n\n\n\n<li>Use strace to identify a failed file open or permission error.<\/li>\n\n\n\n<li>Create an SELinux denial using a nonstandard content path, identify the AVC record, correct the labeling\/policy-compatible configuration, and verify while enforcing.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Missing shared object, wrong library path, application permission failure, memory leak in a disposable test program, wrong SELinux label.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Diagnose why a third-party service fails after relocation to a nonstandard path, prove the root cause with tracing\/log evidence, and restore operation without disabling SELinux.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 7 \u2014 Identify and fix authentication issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Authentication faults can lock administrators out, so use snapshots and console access. Understand PAM stack order and control behavior at an operational level, authselect-generated configuration, local account aging\/locking policy, and how to distinguish authentication failure from authorization or account-expiry failure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identify and fix pluggable authentication module (PAM) issues<\/li>\n\n\n\n<li>Identify and enforce local user account policies<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>authselect current<\/code>,&nbsp;<code>authselect check<\/code>,&nbsp;<code>authselect select<\/code>,&nbsp;<code>passwd<\/code>,&nbsp;<code>chage<\/code>,&nbsp;<code>faillock<\/code>,&nbsp;<code>getent passwd<\/code>,&nbsp;<code>getent shadow<\/code>,&nbsp;<code>su<\/code>,&nbsp;<code>loginctl<\/code>,&nbsp;<code>journalctl<\/code>,&nbsp;<code>grep<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/pam.d\/<em>, \/etc\/security\/<\/em>, \/etc\/login.defs, \/etc\/passwd, \/etc\/shadow, \/etc\/nsswitch.conf, authselect profiles<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Inspect the active authselect profile and map generated PAM\/NSS configuration.<\/li>\n\n\n\n<li>Create a test account with password aging and expiration constraints; verify the resulting login behavior.<\/li>\n\n\n\n<li>Trigger and clear a lab account lockout safely.<\/li>\n\n\n\n<li>Create a custom authselect lab profile, introduce a controlled PAM problem, diagnose it from logs and stack behavior, then restore.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Expired account, locked user, invalid PAM module reference in a disposable profile, inconsistent authselect state.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A valid local user cannot authenticate. Determine whether the cause is account policy, lockout, PAM stack, or identity lookup; fix only the actual cause and verify.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Objective 8 \u2014 Gather information to aid third-party investigation of issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What does this objective mean?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">EX342 includes creating kernel crash dumps and collecting system information for escalation. Learn the purpose of kdump and the capture kernel, how to verify configuration, where crash data goes, and how to create a diagnostic archive with sos. The goal is to preserve useful evidence for a third party, not merely &#8216;make the error disappear&#8217;.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What must the candidate know and be able to do?<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create kernel crash dumps<\/li>\n\n\n\n<li>Collect system information to aid in troubleshooting<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core command families<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>kdumpctl status<\/code>,&nbsp;<code>systemctl status kdump<\/code>,&nbsp;<code>journalctl -u kdump<\/code>,&nbsp;<code>sysctl<\/code>,&nbsp;<code>grubby<\/code>,&nbsp;<code>sos report<\/code>,&nbsp;<code>uname -a<\/code>,&nbsp;<code>lsmod<\/code>,&nbsp;<code>rpm -qa<\/code>,&nbsp;<code>dmesg<\/code>,&nbsp;<code>journalctl<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configuration and evidence locations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/kdump.conf, boot\/kernel command-line configuration, \/var\/crash\/, \/var\/tmp\/ (sos archives)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on lab sequence<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Enable and verify kdump in a disposable VM with enough memory; inspect reserved crash-kernel configuration.<\/li>\n\n\n\n<li>Create an sos report on a healthy node and inventory what kinds of data it collects.<\/li>\n\n\n\n<li>Boot a lab node into RHEL rescue mode and generate an sos report from the installed system.<\/li>\n\n\n\n<li>Practice preserving logs and diagnostic data before making repairs.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Verification standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not stop at &#8216;the command completed.&#8217; Verify the requested service\/state, review logs for residual errors, and\u2014where persistence matters\u2014reboot or restart the relevant lifecycle component and verify again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshooting drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">kdump service not ready, invalid dump target in a disposable configuration, insufficient\/incorrect crash-kernel setup, sos unable to collect a chosen plugin due to missing package.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Original exam-style practice task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Prepare a failing host for escalation: verify crash-dump capability, gather a complete diagnostic archive, and document the minimum evidence needed to reproduce the incident.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Completion criteria<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] I can recognize the symptom without being told the root cause.<\/li>\n\n\n\n<li>[ ] I can collect useful evidence before changing the system.<\/li>\n\n\n\n<li>[ ] I can repair the fault without unrelated changes.<\/li>\n\n\n\n<li>[ ] I can verify the final state.<\/li>\n\n\n\n<li>[ ] I can make the fix persistent where required.<\/li>\n\n\n\n<li>[ ] I can repeat the task from a fresh snapshot without notes.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 5 \u2014 Complete EX342 Curriculum<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Module 0 \u2014 RHCSA Baseline and Safe Troubleshooting Habits<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Prerequisite\/background, not a separate EX342 objective<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">EX342 assumes you can already administer RHEL and then diagnose failures. Before beginning advanced work, you should be comfortable with users, permissions, systemd, basic storage, DNF, SELinux, NetworkManager, SSH, text editing, shell redirection, and the normal boot process. This is preparation, not a new official EX342 objective.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>man<\/code>,&nbsp;<code>info<\/code>,&nbsp;<code>apropos<\/code>,&nbsp;<code>systemctl<\/code>,&nbsp;<code>journalctl<\/code>,&nbsp;<code>dmesg<\/code>,&nbsp;<code>ps<\/code>,&nbsp;<code>top<\/code>,&nbsp;<code>ip<\/code>,&nbsp;<code>ss<\/code>,&nbsp;<code>nmcli<\/code>,&nbsp;<code>lsblk<\/code>,&nbsp;<code>findmnt<\/code>,&nbsp;<code>mount<\/code>,&nbsp;<code>dnf<\/code>,&nbsp;<code>rpm<\/code>,&nbsp;<code>getenforce<\/code>,&nbsp;<code>ausearch<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/fstab, \/etc\/default\/grub, \/etc\/systemd\/system\/, \/etc\/NetworkManager\/system-connections\/, \/etc\/selinux\/config<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Build a clean RHEL 10.2 VM and record a baseline: services, mounts, routes, repositories, SELinux state, kernel, packages.<\/li>\n\n\n\n<li>Create a rollback point, intentionally misconfigure one noncritical service, diagnose it, repair it, and document the evidence chain.<\/li>\n\n\n\n<li>Practice collecting facts first and changing configuration only after forming a hypothesis.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Introduce a wrong mount, disabled service, incorrect DNS entry, and SELinux denial one at a time. For every incident, record symptom \u2192 evidence \u2192 root cause \u2192 fix \u2192 verification.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Given a host with three independent faults, restore normal operation without reinstalling the OS and write down the exact verification commands.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 1 \u2014 General Troubleshooting, Monitoring, Cockpit, Ansible, Logging, and AIDE<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Understand and employ general methods for troubleshooting<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build a repeatable troubleshooting method. Begin with the reported symptom, establish scope and timeline, collect evidence, compare actual state with intended state, test one hypothesis at a time, make the smallest safe correction, then verify persistence. EX342 explicitly includes monitoring, the RHEL web console, Ansible configuration, centralized logging, and AIDE.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>man<\/code>,&nbsp;<code>info<\/code>,&nbsp;<code>journalctl<\/code>,&nbsp;<code>dmesg<\/code>,&nbsp;<code>systemctl<\/code>,&nbsp;<code>ps<\/code>,&nbsp;<code>top<\/code>,&nbsp;<code>vmstat<\/code>,&nbsp;<code>free<\/code>,&nbsp;<code>uptime<\/code>,&nbsp;<code>iostat<\/code>,&nbsp;<code>ss<\/code>,&nbsp;<code>lsof<\/code>,&nbsp;<code>cockpit<\/code>,&nbsp;<code>ansible<\/code>,&nbsp;<code>ansible-playbook<\/code>,&nbsp;<code>logger<\/code>,&nbsp;<code>rsyslogd -N1<\/code>,&nbsp;<code>aide --init<\/code>,&nbsp;<code>aide --check<\/code>,&nbsp;<code>aide --update<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/rsyslog.conf, \/etc\/rsyslog.d\/*.conf, \/etc\/aide.conf, \/var\/lib\/aide\/, \/etc\/ansible\/ansible.cfg, inventory files<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Monitor CPU, memory, processes, storage, and network activity from both CLI and RHEL web console.<\/li>\n\n\n\n<li>Prepare a small Ansible control node and make an idempotent change on two managed nodes.<\/li>\n\n\n\n<li>Configure node2 as a centralized rsyslog receiver and send logs from node1; verify by generating messages with logger.<\/li>\n\n\n\n<li>Initialize AIDE, modify monitored files, detect the change, update the approved baseline, and verify a clean result.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Break rsyslog forwarding, corrupt an Ansible inventory entry, stop cockpit.socket, and change an AIDE-monitored file. Diagnose each from observable evidence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A managed system is not forwarding logs, a required configuration differs from the desired Ansible state, and AIDE reports a file change. Restore and verify all three.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 2 \u2014 Startup, Boot Recovery, Hardware, and Kernel Modules<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Diagnose and troubleshoot system startup issues<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Startup troubleshooting requires distinguishing boot-loader, kernel\/initramfs, systemd target, mount, and service failures. RHEL 10 documentation also provides installation-media rescue mode for systems that cannot boot normally. Kernel-module tasks include inspecting loaded modules, parameters, dependencies, loading\/unloading, and persistent configuration.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>systemctl --failed<\/code>,&nbsp;<code>systemctl status<\/code>,&nbsp;<code>systemctl list-dependencies<\/code>,&nbsp;<code>journalctl -b<\/code>,&nbsp;<code>journalctl -b -1<\/code>,&nbsp;<code>dmesg<\/code>,&nbsp;<code>grubby<\/code>,&nbsp;<code>lsmod<\/code>,&nbsp;<code>modinfo<\/code>,&nbsp;<code>modprobe<\/code>,&nbsp;<code>modprobe -r<\/code>,&nbsp;<code>depmod<\/code>,&nbsp;<code>lspci<\/code>,&nbsp;<code>lsusb<\/code>,&nbsp;<code>lscpu<\/code>,&nbsp;<code>lsblk<\/code>,&nbsp;<code>fdisk -l<\/code>,&nbsp;<code>chroot<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/systemd\/system\/, \/usr\/lib\/systemd\/system\/, \/etc\/modules-load.d\/<em>.conf, \/etc\/modprobe.d\/<\/em>.conf, \/boot\/loader\/entries\/, \/etc\/default\/grub<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create a boot failure caused by a bad systemd dependency and recover from it.<\/li>\n\n\n\n<li>Boot RHEL installation media into rescue mode, mount the installed system, chroot, inspect logs and configuration, then exit safely.<\/li>\n\n\n\n<li>Load and unload a harmless kernel module, inspect its parameters, configure persistent loading, reboot, and verify.<\/li>\n\n\n\n<li>Blacklist a lab-safe module temporarily and permanently, then reverse the change.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Introduce an invalid persistent mount or failed required service; recover using console\/rescue access. Simulate a wrong kernel-module setting and confirm the effect after reboot.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A VM stops during startup because of a configuration fault. Regain administrative control, identify the failure from evidence, correct it, boot normally, and prove the fix survives another reboot.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 3 \u2014 Filesystem, LVM, and Encrypted-Storage Recovery<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Diagnose and troubleshoot file system issues<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">EX342 is recovery-focused rather than merely creation-focused. You must be able to recognize filesystem damage, choose the correct filesystem-specific recovery tool, recover LVM metadata carefully, and diagnose encrypted-volume problems without destroying recoverable data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>lsblk -f<\/code>,&nbsp;<code>blkid<\/code>,&nbsp;<code>findmnt<\/code>,&nbsp;<code>mount<\/code>,&nbsp;<code>umount<\/code>,&nbsp;<code>xfs_repair<\/code>,&nbsp;<code>e2fsck<\/code>,&nbsp;<code>xfs_metadump<\/code>,&nbsp;<code>pvs<\/code>,&nbsp;<code>vgs<\/code>,&nbsp;<code>lvs<\/code>,&nbsp;<code>pvscan<\/code>,&nbsp;<code>vgscan<\/code>,&nbsp;<code>lvscan<\/code>,&nbsp;<code>lvmdump<\/code>,&nbsp;<code>vgcfgbackup<\/code>,&nbsp;<code>vgcfgrestore<\/code>,&nbsp;<code>pvcreate --uuid --restorefile<\/code>,&nbsp;<code>lvchange<\/code>,&nbsp;<code>cryptsetup luksDump<\/code>,&nbsp;<code>cryptsetup open<\/code>,&nbsp;<code>cryptsetup close<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/fstab, \/etc\/crypttab, \/etc\/lvm\/lvm.conf, \/etc\/lvm\/backup\/, \/etc\/lvm\/archive\/<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create XFS and ext4 lab filesystems, take snapshots, then practice safe unmount\/check\/repair procedures appropriate to each filesystem.<\/li>\n\n\n\n<li>Back up LVM metadata, damage only the disposable lab PV metadata, recover it from \/etc\/lvm\/archive, activate the LV, and verify data.<\/li>\n\n\n\n<li>Create a LUKS volume, record identifiers safely, break only its boot-time mapping configuration, recover access, and verify files.<\/li>\n\n\n\n<li>Practice collecting evidence before running destructive repair options; document when a last-resort option would risk data loss.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Wrong UUID in fstab, missing PV metadata, inactive VG\/LV, damaged XFS metadata in a disposable filesystem, incorrect crypttab entry.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Restore three storage failures: a filesystem that will not mount, an LVM stack that is incomplete, and an encrypted volume whose data must remain intact.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 4 \u2014 Package and RPM Database Troubleshooting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Resolve package management issues<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The objective is not generic package installation. It is diagnosing dependency problems, recovering an unusable RPM database, and identifying files that differ from package metadata. Practice DNF dependency reasoning, package ownership queries, package verification, and database recovery on disposable snapshots.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>dnf repolist<\/code>,&nbsp;<code>dnf list<\/code>,&nbsp;<code>dnf info<\/code>,&nbsp;<code>dnf repoquery<\/code>,&nbsp;<code>dnf provides<\/code>,&nbsp;<code>dnf install<\/code>,&nbsp;<code>dnf reinstall<\/code>,&nbsp;<code>dnf remove<\/code>,&nbsp;<code>dnf clean all<\/code>,&nbsp;<code>rpm -qa<\/code>,&nbsp;<code>rpm -qf<\/code>,&nbsp;<code>rpm -ql<\/code>,&nbsp;<code>rpm -V<\/code>,&nbsp;<code>rpm -Va<\/code>,&nbsp;<code>rpm --rebuilddb<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/dnf\/dnf.conf, \/etc\/yum.repos.d\/*.repo, RPM database under \/var\/lib\/rpm\/<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create a repository\/dependency failure and determine whether the root cause is repository availability, architecture, version, or missing dependency.<\/li>\n\n\n\n<li>Modify a packaged configuration\/binary copy and use RPM verification to identify the change.<\/li>\n\n\n\n<li>On a snapshot-only lab clone, simulate RPM database trouble, preserve evidence\/backups, rebuild the database, and verify rpm\/dnf operation.<\/li>\n\n\n\n<li>Reinstall a package to restore changed package-owned files and confirm with verification.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Disable a needed repository, create an impossible package dependency in a lab RPM scenario, change a package-owned file, and damage a disposable copy of the RPM database.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Restore package management to a working state and produce evidence identifying which package-owned files had changed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 5 \u2014 Network Connectivity and Packet Inspection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Troubleshoot and fix network connectivity issues<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Troubleshoot systematically from link state and addressing through route selection, name resolution, socket\/listener state, firewall, and application reachability. Packet inspection is explicitly in scope, so you must know when tcpdump evidence proves where traffic stops.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>ip link<\/code>,&nbsp;<code>ip addr<\/code>,&nbsp;<code>ip route<\/code>,&nbsp;<code>ip neigh<\/code>,&nbsp;<code>nmcli<\/code>,&nbsp;<code>ping<\/code>,&nbsp;<code>tracepath<\/code>,&nbsp;<code>getent hosts<\/code>,&nbsp;<code>resolvectl<\/code>,&nbsp;<code>ss -lntup<\/code>,&nbsp;<code>ethtool<\/code>,&nbsp;<code>tcpdump<\/code>,&nbsp;<code>curl<\/code>,&nbsp;<code>nc<\/code>,&nbsp;<code>firewall-cmd<\/code>,&nbsp;<code>journalctl -u NetworkManager<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/NetworkManager\/system-connections\/*.nmconnection, \/etc\/hosts, \/etc\/resolv.conf, \/etc\/firewalld\/<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create two static lab networks and verify L2\/L3 connectivity and routes.<\/li>\n\n\n\n<li>Break DNS while leaving IP connectivity intact; diagnose by comparing address-based and name-based tests.<\/li>\n\n\n\n<li>Create a wrong gateway or prefix and diagnose route selection.<\/li>\n\n\n\n<li>Capture ICMP and TCP handshakes with tcpdump; distinguish no route, filtered traffic, connection refused, and successful handshake.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Wrong IP\/prefix, missing route, incorrect DNS, stopped listener, firewall block, duplicate address, disabled NetworkManager profile.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A service is reachable from localhost but not from another VM. Identify the failing layer using standard tools and packet capture, fix it, and verify persistence.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 6 \u2014 Application Dependencies, Memory Leaks, Debugging, and SELinux<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Diagnose application issues<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">EX342 expects operational application diagnosis. You should be able to inspect dynamic-library dependencies, identify memory-growth problems, trace process behavior, work with core dumps where useful, and prove whether SELinux is the cause rather than disabling it reflexively.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>ldd<\/code>,&nbsp;<code>readelf<\/code>,&nbsp;<code>objdump<\/code>,&nbsp;<code>file<\/code>,&nbsp;<code>strace<\/code>,&nbsp;<code>ltrace<\/code>,&nbsp;<code>gdb<\/code>,&nbsp;<code>coredumpctl<\/code>,&nbsp;<code>pgrep<\/code>,&nbsp;<code>ps<\/code>,&nbsp;<code>top<\/code>,&nbsp;<code>vmstat<\/code>,&nbsp;<code>valgrind<\/code>,&nbsp;<code>ausearch<\/code>,&nbsp;<code>journalctl -t setroubleshoot<\/code>,&nbsp;<code>getenforce<\/code>,&nbsp;<code>setenforce<\/code>,&nbsp;<code>restorecon<\/code>,&nbsp;<code>semanage<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/ld.so.conf, \/etc\/ld.so.conf.d\/*.conf, \/var\/log\/audit\/audit.log, SELinux file-context policy database<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Build or install a small test binary, inspect shared-library requirements, and diagnose a missing-library scenario.<\/li>\n\n\n\n<li>Run a deliberately leaky test program under valgrind memcheck and correlate increasing memory with process monitoring.<\/li>\n\n\n\n<li>Use strace to identify a failed file open or permission error.<\/li>\n\n\n\n<li>Create an SELinux denial using a nonstandard content path, identify the AVC record, correct the labeling\/policy-compatible configuration, and verify while enforcing.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Missing shared object, wrong library path, application permission failure, memory leak in a disposable test program, wrong SELinux label.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Diagnose why a third-party service fails after relocation to a nonstandard path, prove the root cause with tracing\/log evidence, and restore operation without disabling SELinux.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 7 \u2014 PAM and Local Account Policy Troubleshooting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Identify and fix authentication issues<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Authentication faults can lock administrators out, so use snapshots and console access. Understand PAM stack order and control behavior at an operational level, authselect-generated configuration, local account aging\/locking policy, and how to distinguish authentication failure from authorization or account-expiry failure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>authselect current<\/code>,&nbsp;<code>authselect check<\/code>,&nbsp;<code>authselect select<\/code>,&nbsp;<code>passwd<\/code>,&nbsp;<code>chage<\/code>,&nbsp;<code>faillock<\/code>,&nbsp;<code>getent passwd<\/code>,&nbsp;<code>getent shadow<\/code>,&nbsp;<code>su<\/code>,&nbsp;<code>loginctl<\/code>,&nbsp;<code>journalctl<\/code>,&nbsp;<code>grep<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/pam.d\/<em>, \/etc\/security\/<\/em>, \/etc\/login.defs, \/etc\/passwd, \/etc\/shadow, \/etc\/nsswitch.conf, authselect profiles<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inspect the active authselect profile and map generated PAM\/NSS configuration.<\/li>\n\n\n\n<li>Create a test account with password aging and expiration constraints; verify the resulting login behavior.<\/li>\n\n\n\n<li>Trigger and clear a lab account lockout safely.<\/li>\n\n\n\n<li>Create a custom authselect lab profile, introduce a controlled PAM problem, diagnose it from logs and stack behavior, then restore.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Expired account, locked user, invalid PAM module reference in a disposable profile, inconsistent authselect state.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A valid local user cannot authenticate. Determine whether the cause is account policy, lockout, PAM stack, or identity lookup; fix only the actual cause and verify.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 8 \u2014 Kernel Crash Dumps and Support Data Collection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;Gather information to aid third-party investigation of issues<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">EX342 includes creating kernel crash dumps and collecting system information for escalation. Learn the purpose of kdump and the capture kernel, how to verify configuration, where crash data goes, and how to create a diagnostic archive with sos. The goal is to preserve useful evidence for a third party, not merely &#8216;make the error disappear&#8217;.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>kdumpctl status<\/code>,&nbsp;<code>systemctl status kdump<\/code>,&nbsp;<code>journalctl -u kdump<\/code>,&nbsp;<code>sysctl<\/code>,&nbsp;<code>grubby<\/code>,&nbsp;<code>sos report<\/code>,&nbsp;<code>uname -a<\/code>,&nbsp;<code>lsmod<\/code>,&nbsp;<code>rpm -qa<\/code>,&nbsp;<code>dmesg<\/code>,&nbsp;<code>journalctl<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\/etc\/kdump.conf, boot\/kernel command-line configuration, \/var\/crash\/, \/var\/tmp\/ (sos archives)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enable and verify kdump in a disposable VM with enough memory; inspect reserved crash-kernel configuration.<\/li>\n\n\n\n<li>Create an sos report on a healthy node and inventory what kinds of data it collects.<\/li>\n\n\n\n<li>Boot a lab node into RHEL rescue mode and generate an sos report from the installed system.<\/li>\n\n\n\n<li>Practice preserving logs and diagnostic data before making repairs.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">kdump service not ready, invalid dump target in a disposable configuration, insufficient\/incorrect crash-kernel setup, sos unable to collect a chosen plugin due to missing package.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Prepare a failing host for escalation: verify crash-dump capability, gather a complete diagnostic archive, and document the minimum evidence needed to reproduce the incident.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Module 9 \u2014 Integrated Enterprise Troubleshooting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mapping:<\/strong>&nbsp;All official EX342 objectives<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Concepts<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Real incidents cross subsystem boundaries. A boot symptom can be storage; an application symptom can be SELinux or networking; an authentication symptom can be account policy rather than PAM. This module trains evidence-driven isolation across layers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Commands<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>All commands from Modules 1\u20138<\/code>,&nbsp;<code>selected by evidence rather than habit<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Important configuration\/evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">All relevant configuration from Modules 1\u20138<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required labs<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Multi-fault incident: failed boot + LVM issue + bad service dependency.<\/li>\n\n\n\n<li>Application outage: DNS + SELinux + package file drift.<\/li>\n\n\n\n<li>Authentication outage: PAM\/profile issue + account lockout.<\/li>\n\n\n\n<li>Support escalation: collect packet capture, sos report, relevant logs, RPM verification, and a concise incident timeline.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Break\/fix drill<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use random-but-documented fault injection from your own lab catalog. Never stack more faults than you can independently verify and reverse.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Timed task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Complete a timed four-host incident set while preserving persistence, documenting verification, and avoiding unnecessary configuration changes.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 6 \u2014 Home Lab Architecture<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Recommended minimum practical topology<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The following is a&nbsp;<strong>curriculum design recommendation<\/strong>, not an official Red Hat exam requirement.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                        HOME LAB\n                            |\n                    NAT \/ Internet Access\n                            |\n                    Host-only Lab Network\n                            |\n        ------------------------------------------------\n        |                      |                       |\n   mgmt01.lab.local       node01.lab.local        node02.lab.local\n   192.168.56.10          192.168.56.11           192.168.56.12\n        |                      |                       |\n Ansible control          Primary break\/fix        Logging\/peer\n Central rsyslog          Extra virtual disks      Network peer\n Documentation host       LVM\/LUKS\/filesystems     Secondary target\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Why three VMs?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A single VM can teach many commands, but current EX342 objectives explicitly include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>configuring systems using Ansible;<\/li>\n\n\n\n<li>sending logs to a centralized host;<\/li>\n\n\n\n<li>networking and packet inspection;<\/li>\n\n\n\n<li>advanced recovery.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Three VMs make those objectives realistic without requiring a corporate environment.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Suggested resources<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">VM<\/th><th class=\"has-text-align-right\" data-align=\"right\">vCPU<\/th><th class=\"has-text-align-right\" data-align=\"right\">RAM<\/th><th class=\"has-text-align-right\" data-align=\"right\">System disk<\/th><th class=\"has-text-align-left\" data-align=\"left\">Extra disks<\/th><th class=\"has-text-align-left\" data-align=\"left\">Purpose<\/th><\/tr><\/thead><tbody><tr><td>mgmt01<\/td><td class=\"has-text-align-right\" data-align=\"right\">2<\/td><td class=\"has-text-align-right\" data-align=\"right\">3\u20134 GB<\/td><td class=\"has-text-align-right\" data-align=\"right\">40 GB<\/td><td>optional<\/td><td>Ansible + log server<\/td><\/tr><tr><td>node01<\/td><td class=\"has-text-align-right\" data-align=\"right\">2<\/td><td class=\"has-text-align-right\" data-align=\"right\">4 GB<\/td><td class=\"has-text-align-right\" data-align=\"right\">50\u201360 GB<\/td><td>2\u20133 \u00d7 8\u201312 GB<\/td><td>primary recovery target<\/td><\/tr><tr><td>node02<\/td><td class=\"has-text-align-right\" data-align=\"right\">2<\/td><td class=\"has-text-align-right\" data-align=\"right\">3\u20134 GB<\/td><td class=\"has-text-align-right\" data-align=\"right\">40 GB<\/td><td>1 \u00d7 8\u201312 GB<\/td><td>peer\/log\/client target<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Host recommendation:<\/strong>&nbsp;16 GB RAM works for a careful three-VM lab; 24\u201332 GB is more comfortable. CPU\/RAM figures are study-lab recommendations, not Red Hat exam requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Networking<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use two adapters per VM where practical:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>NAT<\/strong>\u00a0\u2014 registration, package downloads, documentation access.<\/li>\n\n\n\n<li><strong>Host-only\/internal network<\/strong>\u00a0\u2014 deterministic private addressing and safe break\/fix networking.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Bridged networking is optional and should be used only when you understand the impact on your real LAN.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Snapshot strategy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Maintain at least:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>00-clean-rhel10<\/code><\/li>\n\n\n\n<li><code>10-baseline-tools<\/code><\/li>\n\n\n\n<li><code>20-storage-ready<\/code><\/li>\n\n\n\n<li><code>30-network-ready<\/code><\/li>\n\n\n\n<li><code>before-dangerous-lab<\/code><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Snapshot before filesystem corruption, LVM metadata recovery, PAM changes, bootloader work, or RPM database recovery.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab reset discipline<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After an advanced failure lab:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>verify the recovery;<\/li>\n\n\n\n<li>export your notes;<\/li>\n\n\n\n<li>restore the clean snapshot;<\/li>\n\n\n\n<li>repeat without notes;<\/li>\n\n\n\n<li>rebuild from scratch periodically so snapshot dependence does not hide gaps.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 7 \u2014 Home Lab Options<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Official RHEL access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Red Hat currently provides a&nbsp;<strong>no-cost Red Hat Developer Subscription for Individuals<\/strong>, which includes RHEL for individual development, testing, experimentation, and permitted individual use. Review current terms before use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Official information:&nbsp;<a href=\"https:\/\/developers.redhat.com\/articles\/faqs-no-cost-red-hat-enterprise-linux\">https:\/\/developers.redhat.com\/articles\/faqs-no-cost-red-hat-enterprise-linux<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Windows host<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Practical hypervisor choices include Hyper-V (where available), VMware Workstation, and VirtualBox. The hypervisor is not part of EX342; use whichever reliably supports multiple RHEL VMs, snapshots, multiple NICs, and extra disks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Avoid using WSL as the primary EX342 lab because EX342 requires boot, kernel, storage, systemd, crash-dump, and recovery exercises that need a real VM environment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">macOS host<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On Intel Mac, VMware Fusion or another x86_64-capable hypervisor can run x86_64 RHEL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Apple Silicon, use a hypervisor capable of running the current supported RHEL aarch64\/ARM64 image where available. Keep in mind that some low-level device behavior can differ by architecture; use Red Hat&#8217;s current RHEL documentation for your architecture.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Linux host<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">KVM\/libvirt is the most natural Linux-host choice. GNOME Boxes or virt-manager can simplify management. VMware\/VirtualBox may also be options depending on the host distribution.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Licensing rule<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use official RHEL downloads, valid subscriptions\/evaluations, or other legally licensed RHEL access. Do not use unauthorized images.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 8 \u2014 Learn \u2192 Configure \u2192 Verify \u2192 Break \u2192 Troubleshoot \u2192 Fix<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Use the same cycle for every major technology:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-1\" data-shcb-language-name=\"PHP\" data-shcb-language-slug=\"php\"><span><code class=\"hljs language-php\">LEARN\n  \u2193\nCONFIGURE\n  \u2193\nVERIFY\n  \u2193\n<span class=\"hljs-keyword\">BREAK<\/span>\n  \u2193\nCOLLECT EVIDENCE\n  \u2193\nFORM HYPOTHESIS\n  \u2193\nFIX\n  \u2193\nVERIFY AGAIN\n  \u2193\nREBOOT \/ LIFECYCLE TEST\n  \u2193\nTIMED TASK\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-1\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">PHP<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">php<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<h3 class=\"wp-block-heading\">Lab 1 \u2014 Basic implementation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build the feature correctly from a clean baseline.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 2 \u2014 Enterprise scenario<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use at least two hosts or multiple dependent services.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 3 \u2014 Intentional failure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Inject exactly one documented failure first. Later combine faults.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 4 \u2014 Troubleshooting<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Do not look at your fault-injection note until after you have diagnosed the problem from evidence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 5 \u2014 Timed exam-style task<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Start from a snapshot that hides the root cause. Work against a result requirement, not a command recipe.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 9 \u2014 Advanced Troubleshooting Curriculum<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Scenario<\/th><th class=\"has-text-align-left\" data-align=\"left\">First evidence<\/th><th class=\"has-text-align-left\" data-align=\"left\">Diagnostic path<\/th><th class=\"has-text-align-left\" data-align=\"left\">Typical root-cause classes<\/th><th class=\"has-text-align-left\" data-align=\"left\">Verification<\/th><\/tr><\/thead><tbody><tr><td>Boot stops\/degrades<\/td><td>console + journalctl -b + failed units<\/td><td>boot stage \u2192 mounts \u2192 units \u2192 dependencies<\/td><td>fstab, failed unit, module\/driver, boot configuration<\/td><td>normal reboot; no failed required units<\/td><\/tr><tr><td>Filesystem will not mount<\/td><td>mount error + dmesg + filesystem metadata<\/td><td>identify FS \u2192 unmount \u2192 read-only check \u2192 safe repair<\/td><td>corruption, wrong UUID\/type\/options<\/td><td>mount + file read\/write + reboot<\/td><\/tr><tr><td>VG\/LV missing<\/td><td>pvs\/vgs\/lvs + \/etc\/lvm\/archive<\/td><td>device presence \u2192 PV UUID \u2192 metadata \u2192 activation<\/td><td>missing\/damaged PV metadata, activation<\/td><td>LV active and data readable<\/td><\/tr><tr><td>Encrypted volume unavailable<\/td><td>cryptsetup status\/luksDump + crypttab\/fstab<\/td><td>device \u2192 LUKS header \u2192 mapping \u2192 FS \u2192 mount<\/td><td>wrong mapping\/config, unavailable key<\/td><td>mapping + mount + persistence<\/td><\/tr><tr><td>DNF transaction fails<\/td><td>dnf error + repo state<\/td><td>repo availability \u2192 package\/version\/arch \u2192 dependencies<\/td><td>disabled repo, version conflict, damaged metadata<\/td><td>clean transaction<\/td><\/tr><tr><td>RPM database fails<\/td><td>rpm query errors + db files<\/td><td>backup\/evidence \u2192 database recovery \u2192 verify package manager<\/td><td>rpmdb corruption<\/td><td>rpm\/dnf queries<\/td><\/tr><tr><td>Network timeout<\/td><td>ip\/nmcli\/route\/ss\/tcpdump<\/td><td>link \u2192 address \u2192 route \u2192 DNS \u2192 socket \u2192 firewall \u2192 packet<\/td><td>bad IP\/route\/DNS\/firewall\/listener<\/td><td>remote connection + packet evidence<\/td><\/tr><tr><td>App fails to start<\/td><td>systemd status\/journal + strace\/ldd<\/td><td>service \u2192 dependency \u2192 file access \u2192 SELinux \u2192 resource<\/td><td>library, permission, config, AVC<\/td><td>process healthy + logs clean<\/td><\/tr><tr><td>Memory grows<\/td><td>ps\/top\/vmstat + valgrind<\/td><td>confirm growth \u2192 reproduce \u2192 instrument<\/td><td>leak or workload\/cache misunderstanding<\/td><td>reproducible evidence<\/td><\/tr><tr><td>Login fails<\/td><td>journal + faillock\/chage\/authselect<\/td><td>identity \u2192 account state \u2192 PAM \u2192 policy<\/td><td>lockout, expiry, PAM\/profile<\/td><td>successful intended auth<\/td><\/tr><tr><td>SELinux denial<\/td><td>audit.log + ausearch<\/td><td>prove AVC \u2192 inspect context\/boolean \u2192 persistent correction<\/td><td>wrong label, nonstandard path, policy mismatch<\/td><td>enforcing + app works<\/td><\/tr><tr><td>Need vendor escalation<\/td><td>sos + journal + package\/kernel\/network state<\/td><td>collect before repair<\/td><td>insufficient evidence<\/td><td>archive + timeline + reproduction notes<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Universal incident worksheet<\/h3>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Problem statement:\nExpected state:\nObserved state:\nScope:\nWhen did it start?\nRecent change?\nEvidence collected:\nHypothesis 1:\nTest:\nResult:\nRoot cause:\nFix:\nVerification:\nPersistence\/reboot verification:\nEvidence retained for escalation:\n<\/code><\/span><\/pre>\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 10 \u2014 EX342 Command Mastery<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Command<\/th><th class=\"has-text-align-left\" data-align=\"left\">Purpose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Example<\/th><th class=\"has-text-align-left\" data-align=\"left\">Common mistake<\/th><th class=\"has-text-align-left\" data-align=\"left\">Verification<\/th><\/tr><\/thead><tbody><tr><td>man \/ info \/ apropos<\/td><td>Find local documentation<\/td><td>man 5 fstab; apropos kdump<\/td><td>Using memory instead of available documentation<\/td><td>Can explain source used<\/td><\/tr><tr><td>journalctl<\/td><td>Query systemd journal<\/td><td>journalctl -b; journalctl -u sshd<\/td><td>Looking only at current terminal error<\/td><td>Find exact failure timestamp<\/td><\/tr><tr><td>dmesg<\/td><td>Kernel ring buffer<\/td><td>dmesg -T<\/td><td>Ignoring kernel\/device evidence<\/td><td>Correlate device\/kernel event<\/td><\/tr><tr><td>systemctl<\/td><td>Service\/unit state<\/td><td>systemctl &#8211;failed; status UNIT<\/td><td>Restarting before collecting evidence<\/td><td>Unit healthy after fix<\/td><\/tr><tr><td>ps \/ top \/ vmstat \/ free<\/td><td>Process and resource monitoring<\/td><td>ps aux; top; vmstat 1<\/td><td>Treating free RAM as only memory metric<\/td><td>Baseline + changed metric<\/td><\/tr><tr><td>ss<\/td><td>Socket\/listener state<\/td><td>ss -lntup<\/td><td>Testing firewall before checking listener<\/td><td>Correct process listening<\/td><\/tr><tr><td>cockpit.socket<\/td><td>RHEL web console access<\/td><td>systemctl enable &#8211;now cockpit.socket<\/td><td>Assuming GUI state differs from system state<\/td><td>CLI and web state agree<\/td><\/tr><tr><td>ansible \/ ansible-playbook<\/td><td>Configure managed systems<\/td><td>ansible all -m ping; ansible-playbook site.yml<\/td><td>Non-idempotent shell-only playbooks<\/td><td>Second run has no unintended changes<\/td><\/tr><tr><td>logger \/ rsyslogd<\/td><td>Central logging tests<\/td><td>logger TAG; rsyslogd -N1<\/td><td>Changing config without syntax validation<\/td><td>Remote message arrives<\/td><\/tr><tr><td>aide<\/td><td>File integrity<\/td><td>aide &#8211;init; &#8211;check; &#8211;update<\/td><td>Approving suspicious drift blindly<\/td><td>Expected drift only<\/td><\/tr><tr><td>grubby<\/td><td>Inspect\/manage boot entries<\/td><td>grubby &#8211;info=ALL<\/td><td>Editing boot config without rollback<\/td><td>Expected kernel\/entry<\/td><\/tr><tr><td>lsmod \/ modinfo \/ modprobe<\/td><td>Kernel modules<\/td><td>modinfo MOD; modprobe MOD<\/td><td>Using insmod without dependency awareness<\/td><td>Module\/parameters correct<\/td><\/tr><tr><td>xfs_repair<\/td><td>XFS diagnosis\/repair<\/td><td>xfs_repair -n DEV<\/td><td>Repairing mounted FS or using -L casually<\/td><td>FS mounts and data checks<\/td><\/tr><tr><td>e2fsck<\/td><td>ext-family check\/repair<\/td><td>e2fsck -f DEV<\/td><td>Using filesystem-wrong tool<\/td><td>FS healthy<\/td><\/tr><tr><td>pvs\/vgs\/lvs<\/td><td>LVM state<\/td><td>lvs -a -o +devices<\/td><td>Changing metadata before identifying missing device<\/td><td>Topology understood<\/td><\/tr><tr><td>vgcfgrestore \/ pvcreate &#8211;restorefile<\/td><td>LVM metadata recovery<\/td><td>vgcfgrestore VG<\/td><td>Wrong PV UUID\/device<\/td><td>LV restored with data<\/td><\/tr><tr><td>cryptsetup<\/td><td>LUKS inspection\/open<\/td><td>cryptsetup luksDump DEV<\/td><td>Reformatting instead of recovering mapping<\/td><td>Existing data accessible<\/td><\/tr><tr><td>dnf<\/td><td>Package\/repo\/dependency management<\/td><td>dnf repolist; repoquery; reinstall<\/td><td>Forcing RPM operations before understanding deps<\/td><td>Clean transaction<\/td><\/tr><tr><td>rpm<\/td><td>Package ownership\/verification\/db<\/td><td>rpm -qf FILE; rpm -V PKG; rpm &#8211;rebuilddb<\/td><td>Interpreting all rpm -V differences as compromise<\/td><td>Changed files correctly reported<\/td><\/tr><tr><td>ip \/ nmcli<\/td><td>Network state and config<\/td><td>ip route; nmcli con show<\/td><td>Changing DNS when route is broken<\/td><td>Correct state + persistence<\/td><\/tr><tr><td>tcpdump<\/td><td>Packet evidence<\/td><td>tcpdump -ni IFACE host X<\/td><td>Capturing too broadly and missing signal<\/td><td>Can explain handshake\/failure<\/td><\/tr><tr><td>ldd \/ readelf \/ objdump<\/td><td>ELF\/library dependencies<\/td><td>ldd APP; readelf -d APP<\/td><td>Installing random packages to chase .so errors<\/td><td>All dependencies resolve<\/td><\/tr><tr><td>strace \/ ltrace<\/td><td>Runtime tracing<\/td><td>strace -f -o trace APP<\/td><td>Tracing without filtering or interpreting errors<\/td><td>Failure syscall\/library call identified<\/td><\/tr><tr><td>valgrind<\/td><td>Memory error\/leak evidence<\/td><td>valgrind &#8211;leak-check=full APP<\/td><td>Calling normal cache use a leak<\/td><td>Reproducible leak evidence<\/td><\/tr><tr><td>ausearch \/ restorecon \/ semanage<\/td><td>SELinux diagnosis\/fix<\/td><td>ausearch -m AVC -ts recent; restorecon -Rv PATH<\/td><td>Disabling SELinux<\/td><td>Works in enforcing<\/td><\/tr><tr><td>authselect \/ faillock \/ chage<\/td><td>Authentication\/account policy<\/td><td>authselect current; faillock &#8211;user U; chage -l U<\/td><td>Editing generated PAM files blindly<\/td><td>Login state matches policy<\/td><\/tr><tr><td>kdumpctl<\/td><td>Kdump readiness<\/td><td>kdumpctl status<\/td><td>Assuming service active means fully ready<\/td><td>Ready\/target validated<\/td><\/tr><tr><td>sos report<\/td><td>Support data<\/td><td>sos report<\/td><td>Collecting only after changing system<\/td><td>Archive preserves pre-fix evidence<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 11 \u2014 Configuration File Mastery<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">File\/directory<\/th><th class=\"has-text-align-left\" data-align=\"left\">Purpose<\/th><th class=\"has-text-align-left\" data-align=\"left\">Related objective<\/th><\/tr><\/thead><tbody><tr><td>\/etc\/rsyslog.conf, \/etc\/rsyslog.d\/*.conf<\/td><td>local\/remote logging<\/td><td>general troubleshooting<\/td><\/tr><tr><td>\/etc\/aide.conf, \/var\/lib\/aide\/<\/td><td>AIDE rules\/database<\/td><td>general troubleshooting<\/td><\/tr><tr><td>\/etc\/ansible\/ansible.cfg + inventory<\/td><td>Ansible behavior\/targets<\/td><td>general troubleshooting<\/td><\/tr><tr><td>\/etc\/systemd\/system\/, \/usr\/lib\/systemd\/system\/<\/td><td>units, overrides, dependencies<\/td><td>startup\/services<\/td><\/tr><tr><td>\/etc\/modules-load.d\/*.conf<\/td><td>persistent module loading<\/td><td>kernel modules<\/td><\/tr><tr><td>\/etc\/modprobe.d\/*.conf<\/td><td>module options\/denylisting<\/td><td>kernel modules<\/td><\/tr><tr><td>\/boot\/loader\/entries\/, bootloader config<\/td><td>boot entries<\/td><td>startup<\/td><\/tr><tr><td>\/etc\/fstab<\/td><td>persistent mounts<\/td><td>filesystem\/startup<\/td><\/tr><tr><td>\/etc\/crypttab<\/td><td>encrypted mappings<\/td><td>encrypted storage<\/td><\/tr><tr><td>\/etc\/lvm\/lvm.conf<\/td><td>LVM behavior<\/td><td>LVM recovery<\/td><\/tr><tr><td>\/etc\/lvm\/backup\/, \/etc\/lvm\/archive\/<\/td><td>LVM metadata backups<\/td><td>LVM recovery<\/td><\/tr><tr><td>\/etc\/dnf\/dnf.conf<\/td><td>DNF global config<\/td><td>package management<\/td><\/tr><tr><td>\/etc\/yum.repos.d\/*.repo<\/td><td>repositories<\/td><td>package management<\/td><\/tr><tr><td>\/etc\/NetworkManager\/system-connections\/*.nmconnection<\/td><td>persistent network profiles<\/td><td>networking<\/td><\/tr><tr><td>\/etc\/hosts, \/etc\/resolv.conf<\/td><td>name resolution inputs<\/td><td>networking<\/td><\/tr><tr><td>\/etc\/ld.so.conf, \/etc\/ld.so.conf.d\/*.conf<\/td><td>dynamic linker paths<\/td><td>application dependencies<\/td><\/tr><tr><td>\/var\/log\/audit\/audit.log<\/td><td>SELinux\/audit evidence<\/td><td>application\/SELinux<\/td><\/tr><tr><td>\/etc\/pam.d\/*<\/td><td>PAM service stacks<\/td><td>authentication<\/td><\/tr><tr><td>\/etc\/security\/*<\/td><td>PAM\/account policy parameters<\/td><td>authentication<\/td><\/tr><tr><td>\/etc\/login.defs<\/td><td>local account defaults<\/td><td>authentication<\/td><\/tr><tr><td>\/etc\/passwd, \/etc\/shadow<\/td><td>local identity\/account state<\/td><td>authentication<\/td><\/tr><tr><td>\/etc\/nsswitch.conf<\/td><td>identity lookup order<\/td><td>authentication<\/td><\/tr><tr><td>\/etc\/kdump.conf<\/td><td>crash dump target\/config<\/td><td>third-party investigation<\/td><\/tr><tr><td>\/var\/crash\/<\/td><td>kernel crash dump output<\/td><td>third-party investigation<\/td><\/tr><tr><td>\/var\/tmp\/<\/td><td>common sos report output location<\/td><td>third-party investigation<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 12 \u2014 Security Curriculum<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Current EX342 security-relevant objectives are&nbsp;<strong>narrower than a full Linux security certification<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Officially in scope<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AIDE file integrity<\/li>\n\n\n\n<li>SELinux troubleshooting<\/li>\n\n\n\n<li>PAM troubleshooting<\/li>\n\n\n\n<li>local user account policy<\/li>\n\n\n\n<li>secure recovery of encrypted filesystems<\/li>\n\n\n\n<li>logging\/evidence collection<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Useful background, but not separately named EX342 objectives<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>sudo administration<\/li>\n\n\n\n<li>firewalld as a possible network fault source<\/li>\n\n\n\n<li>file permissions\/ACLs when diagnosing application\/authentication issues<\/li>\n\n\n\n<li>SSH when reproducing remote-access problems<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Not justified as a standalone EX342 requirement by the current public objectives<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>comprehensive compliance frameworks<\/li>\n\n\n\n<li>full auditd rule design<\/li>\n\n\n\n<li>cryptographic policy engineering<\/li>\n\n\n\n<li>advanced Identity Management\/FreeIPA server deployment<\/li>\n\n\n\n<li>advanced firewall architecture<\/li>\n\n\n\n<li>security hardening baselines beyond the troubleshooting objectives<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The rule is simple: learn enough background to diagnose an official EX342 objective, but do not turn this into EX415.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 13 \u2014 Storage Curriculum<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Required storage outcomes<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You must be able to:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>identify the actual block-device\/filesystem\/LVM\/LUKS topology;<\/li>\n\n\n\n<li>distinguish filesystem corruption from mount\/configuration problems;<\/li>\n\n\n\n<li>use filesystem-specific repair workflows;<\/li>\n\n\n\n<li>recover LVM metadata from backups\/archives safely;<\/li>\n\n\n\n<li>preserve existing encrypted data while repairing mapping\/configuration failures;<\/li>\n\n\n\n<li>prove data is intact after recovery;<\/li>\n\n\n\n<li>verify persistence where applicable.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Mandatory lab chain<\/h3>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-2\" data-shcb-language-name=\"PHP\" data-shcb-language-slug=\"php\"><span><code class=\"hljs language-php\">Create disposable storage\n   \u2193\nPut test data on it\n   \u2193\nRecord UUID\/PV\/VG\/LV\/LUKS facts\n   \u2193\nSnapshot VM\n   \u2193\n<span class=\"hljs-keyword\">Break<\/span> one layer\n   \u2193\nDiagnose layer-by-layer\n   \u2193\nRecover\n   \u2193\nMount\n   \u2193\nVerify checksums\/files\n   \u2193\nReboot\n   \u2193\nVerify persistence\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-2\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">PHP<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">php<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p class=\"wp-block-paragraph\"><strong>Safety:<\/strong>&nbsp;never practice destructive metadata recovery on important data.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 14 \u2014 Networking Curriculum<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Use a layer-by-layer workflow:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-3\" data-shcb-language-name=\"PHP\" data-shcb-language-slug=\"php\"><span><code class=\"hljs language-php\">Link\n \u2193\n<span class=\"hljs-class\"><span class=\"hljs-keyword\">Interface<\/span> <span class=\"hljs-title\">state<\/span>\n \u2193\n<span class=\"hljs-title\">Address<\/span> \/ <span class=\"hljs-title\">Prefix<\/span>\n \u2193\n<span class=\"hljs-title\">Route<\/span>\n \u2193\n<span class=\"hljs-title\">Neighbor<\/span> <span class=\"hljs-title\">resolution<\/span>\n \u2193\n<span class=\"hljs-title\">DNS<\/span>\n \u2193\n<span class=\"hljs-title\">Listener<\/span>\/<span class=\"hljs-title\">socket<\/span>\n \u2193\n<span class=\"hljs-title\">Firewall<\/span>\n \u2193\n<span class=\"hljs-title\">Packet<\/span> <span class=\"hljs-title\">capture<\/span>\n \u2193\n<span class=\"hljs-title\">Application<\/span>\n<\/span><\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-3\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">PHP<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">php<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p class=\"wp-block-paragraph\">A good EX342 learner should be able to explain the difference between:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>no route to host;<\/li>\n\n\n\n<li>name-resolution failure;<\/li>\n\n\n\n<li>SYN sent but no reply;<\/li>\n\n\n\n<li>TCP reset \/ connection refused;<\/li>\n\n\n\n<li>listener bound only to localhost;<\/li>\n\n\n\n<li>firewall drop;<\/li>\n\n\n\n<li>wrong source route;<\/li>\n\n\n\n<li>service-level failure after transport succeeds.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Do not memorize tcpdump filters without learning to read basic TCP handshakes.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 15 \u2014 Services &amp; System Management<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Current service-related scope appears mainly through:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>startup failures affecting boot;<\/li>\n\n\n\n<li>monitoring and logs;<\/li>\n\n\n\n<li>application issues;<\/li>\n\n\n\n<li>logging services;<\/li>\n\n\n\n<li>cockpit;<\/li>\n\n\n\n<li>kdump;<\/li>\n\n\n\n<li>services changed by Ansible.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Practice:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>systemctl status<\/code><\/li>\n\n\n\n<li><code>systemctl --failed<\/code><\/li>\n\n\n\n<li>unit dependencies<\/li>\n\n\n\n<li>drop-in overrides<\/li>\n\n\n\n<li>enable\/disable vs start\/stop distinction<\/li>\n\n\n\n<li>journal correlation<\/li>\n\n\n\n<li>persistence after reboot<\/li>\n\n\n\n<li>finding the\u00a0<em>first causal failure<\/em>\u00a0rather than restarting everything<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Creating complex custom systemd services is useful practice, but the current EX342 objectives do not separately state &#8220;write arbitrary systemd unit files&#8221; as an objective. Treat that as supporting skill, not a standalone exam claim.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 16 \u2014 Automation<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Automation&nbsp;<strong>is<\/strong>&nbsp;explicitly in scope through:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Configure systems using Ansible.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">This does&nbsp;<strong>not<\/strong>&nbsp;make EX342 an EX294 substitute.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For EX342, focus on Ansible as an administration\/troubleshooting tool:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>inventories;<\/li>\n\n\n\n<li>managed-node connectivity;<\/li>\n\n\n\n<li>idempotent configuration;<\/li>\n\n\n\n<li>playbook syntax;<\/li>\n\n\n\n<li>variables sufficient for practical configuration;<\/li>\n\n\n\n<li>service\/package\/file configuration;<\/li>\n\n\n\n<li>RHEL system roles where useful;<\/li>\n\n\n\n<li>troubleshooting SSH\/inventory\/privilege\/module failures.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Do not spend disproportionate time on advanced Automation Platform architecture, controller administration, custom collections, or large-scale event-driven automation unless a newer EX342 objective explicitly adds them.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 17 \u2014 Performance &amp; Troubleshooting<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">The EX342 page says the exam tests issues that may cause&nbsp;<strong>degradation or loss of performance<\/strong>, and the objectives explicitly require monitoring vital characteristics and identifying application memory leaks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Use this workflow:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Observe symptom\n   \u2193\nMeasure current state\n   \u2193\nCreate\/reproduce workload\n   \u2193\nIdentify constrained resource\n   \u2193\nDetermine whether problem is system-wide or process-specific\n   \u2193\nMake smallest justified change\n   \u2193\nMeasure again\n<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">Useful current-RHEL tools include&nbsp;<code>top<\/code>,&nbsp;<code>ps<\/code>,&nbsp;<code>vmstat<\/code>,&nbsp;<code>iostat<\/code>,&nbsp;<code>free<\/code>,&nbsp;<code>ss<\/code>,&nbsp;<code>perf<\/code>, and Valgrind. Do not turn EX342 preparation into the separate EX442 Performance Tuning curriculum; use performance tools to diagnose EX342-style faults.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 18 \u2014 Enterprise Scenarios<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 1 \u2014 Production service failing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Service starts manually but fails during normal boot. Determine unit ordering\/dependency or environmental difference and restore persistent startup.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 2 \u2014 Storage full \/ filesystem unhealthy<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A service stops writing. Distinguish space exhaustion, inode exhaustion, read-only remount, underlying LVM issue, and filesystem damage.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 3 \u2014 Network service unavailable<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Local checks pass, remote checks fail. Use socket state, route, firewall, and packet capture to isolate failure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 4 \u2014 SELinux blocks an application<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">App runs only in permissive mode. Prove AVC denial and correct persistent labels\/allowed configuration while returning enforcing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 5 \u2014 Service works now but fails after reboot<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Find nonpersistent command-line changes, missing enablement, wrong fstab\/crypttab\/module\/network profile, or unit ordering.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 6 \u2014 Filesystem does not mount<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Determine whether root cause is wrong device\/UUID, encryption mapping, LVM activation, filesystem corruption, or mount options.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 7 \u2014 Performance incident<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A process consumes growing memory. Confirm actual leak behavior and capture reproducible evidence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 8 \u2014 Authentication outage<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One group of local users cannot log in after policy change. Separate identity lookup, account status, PAM, and authorization.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 9 \u2014 Package integrity incident<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A package-owned binary changed and DNF transactions fail. Report drift, fix repository\/dependency\/database state, restore supported files.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scenario 10 \u2014 Vendor escalation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before changing the host, create sos report, gather relevant journals, package state, kernel\/module state, network evidence, and a concise timeline.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 19 \u2014 Original EX342-Style Practical Tasks<\/h1>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">These are original self-study tasks. They are&nbsp;<strong>not<\/strong>&nbsp;Red Hat exam questions and do not reproduce confidential exam content.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 01 \u2014 Troubleshooting method<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A service is reported &#8216;slow&#8217; but not down.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Collect CPU, memory, I\/O, process and log evidence; identify the bottleneck; make only an evidence-backed correction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Record before\/after metrics and service health.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 02 \u2014 Documentation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A utility is unfamiliar and outside your memorized command set.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Use local man\/info\/help and provided documentation to determine safe syntax; perform the requested change.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;15 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Show the command result and relevant help\/man reference.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 03 \u2014 RHEL web console<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;CLI metrics and web-console view disagree after a service change.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Enable\/access the web console, reconcile the state, and identify what changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;15 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;cockpit.socket active; web view matches CLI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 04 \u2014 Ansible<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;Two RHEL nodes drift from a required service configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Create inventory\/playbook, apply idempotently, run twice, and show no unintended second-run changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Second play is idempotent; target state confirmed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 05 \u2014 Central logging<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;node1 messages do not arrive on loghost.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Fix rsyslog path\/transport\/listener\/firewall as needed and verify with logger.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Unique test message visible on loghost.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 06 \u2014 AIDE<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;Integrity monitoring reports one legitimate and one suspicious change.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Identify both, approve only the legitimate change, update baseline, and leave suspicious change reported.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;AIDE output reflects intended baseline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 07 \u2014 Boot service failure<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A required local service causes degraded boot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Identify the failed unit and dependency chain; repair and reboot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;No failed unit after reboot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 08 \u2014 Regain root control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;Normal login is unavailable on a disposable lab VM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Use a current supported rescue path to regain administrative control and repair the cause.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Normal boot\/login restored.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 09 \u2014 Boot issue<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;The OS drops to emergency\/rescue behavior because a persistent mount is wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Find the exact mount failure and correct persistent configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Normal boot and mount verified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 10 \u2014 Hardware evidence<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A NIC\/disk is allegedly &#8216;missing&#8217;.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Use kernel\/hardware tools and logs to determine whether hardware is absent, driver is missing, or interface is simply down.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Root cause documented with evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 11 \u2014 Kernel modules<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A required module is not loaded after reboot.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Inspect module availability\/parameters, configure persistent loading, reboot and verify.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Module loaded after reboot with intended parameter state.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 12 \u2014 Filesystem recovery<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A disposable XFS\/ext4 filesystem does not mount after simulated corruption.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Use filesystem-appropriate diagnostic and repair workflow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;30 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Filesystem mounts and test data is accessible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 13 \u2014 LVM recovery<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A VG references a missing or damaged PV in the lab.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Use LVM metadata backups\/archives to recover the mapping carefully.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;40 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;LV active and test data verified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 14 \u2014 Encrypted storage<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A LUKS-backed filesystem no longer opens automatically.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Identify mapping\/configuration problem without recreating the filesystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;30 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Volume opens; data intact; persistence restored.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 15 \u2014 DNF dependencies<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;Package installation fails because of dependency\/repository state.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Determine the exact dependency chain and fix repository\/package state.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;dnf transaction succeeds cleanly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 16 \u2014 RPM database<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;rpm\/dnf queries fail on a disposable snapshot because the rpmdb is damaged.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Preserve evidence, recover\/rebuild the database, and verify package queries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;rpm -qa and dnf operations work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 17 \u2014 Changed package files<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;An application binary\/configuration may have been modified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Use package ownership and RPM verification to report changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;15 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Produce exact changed-file evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 18 \u2014 Connectivity<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;Two hosts cannot communicate after a network change.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Check link, address, route, DNS, socket, firewall; fix the actual fault.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Bidirectional test succeeds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 19 \u2014 Packet inspection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A TCP connection times out.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Capture packets and classify whether SYN leaves, reply returns, reset occurs, or firewall silently drops.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;tcpdump evidence supports conclusion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 20 \u2014 Library dependencies<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A third-party executable fails with a missing shared library.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Identify required soname\/library and restore supported loader visibility.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Executable starts; dependency resolution shown.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 21 \u2014 Memory leak<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A test application grows in resident memory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Confirm growth and use valgrind\/memcheck or appropriate tooling to identify leak evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;30 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Report contains reproducible leak evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 22 \u2014 Application tracing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;An app returns permission denied but file mode looks correct.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Trace file\/syscall behavior and correlate with logs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Root cause proven, not guessed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 23 \u2014 SELinux<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A service works in permissive mode but not enforcing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Find AVC denial, correct label\/boolean\/policy-compatible config, return enforcing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;25 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Service works with SELinux enforcing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 24 \u2014 PAM<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A local login fails after authentication configuration was changed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Inspect authselect\/PAM state and logs; repair the stack safely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;30 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Login succeeds and authselect consistency check passes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 25 \u2014 Account policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;One user cannot log in; other users can.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Determine expiration\/lockout\/password aging state and apply the intended policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;15 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;User works; policy verified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 26 \u2014 Kdump<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A host must be ready to capture a kernel crash.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Configure\/verify kdump and its target; do not trigger unsafe crash outside disposable VM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;30 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;kdump ready\/status and dump target verified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">TASK 27 \u2014 Support data<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Scenario:<\/strong>&nbsp;A vendor requests diagnostic information before changes are made.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Requirements:<\/strong>&nbsp;Create sos report and collect targeted logs, package state, kernel, modules, and network evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time target:<\/strong>&nbsp;20 min<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Verification:<\/strong>&nbsp;Archive exists and evidence checklist complete.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Common mistakes:<\/strong>&nbsp;changing multiple subsystems at once; skipping evidence collection; using a destructive shortcut; failing to verify persistence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Expected final state:<\/strong>&nbsp;the stated service\/system outcome works, the root cause is identified, and the final configuration is stable across the relevant lifecycle\/reboot test.<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">PART 20 \u2014 Progressive Labs<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Level 1 \u2014 Foundation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Run tasks 01\u201306 with notes. Goal: build the troubleshooting method and the instrumentation\/logging foundation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Level 2 \u2014 Intermediate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Run tasks 07\u201318. Use snapshots but no step-by-step notes. Goal: recover boot, storage, packages, and networking safely.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Level 3 \u2014 Advanced<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Run tasks 19\u201327 and combine two dependent faults. Goal: diagnose applications, security\/authentication, kdump, and support data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Level 4 \u2014 Troubleshooting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Randomize fault injection:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>one symptom, one root cause;<\/li>\n\n\n\n<li>one symptom, two independent root causes;<\/li>\n\n\n\n<li>misleading symptom where the obvious subsystem is not the cause;<\/li>\n\n\n\n<li>recovery where data preservation matters.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Level 5 \u2014 Exam Simulation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Use a clean copy of all VMs, hide your fault-injection notes, set a strict timer, and require final-state\/reboot verification.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 21 \u2014 Five Full Original Mock Exams<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Mock Exam 1 \u2014 Foundation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time limit:<\/strong>&nbsp;90 minutes<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Task 01 \u2014 Troubleshooting method:<\/strong>\u00a0A service is reported &#8216;slow&#8217; but not down. Collect CPU, memory, I\/O, process and log evidence; identify the bottleneck; make only an evidence-backed correction.<\/li>\n\n\n\n<li><strong>Task 05 \u2014 Central logging:<\/strong>\u00a0node1 messages do not arrive on loghost. Fix rsyslog path\/transport\/listener\/firewall as needed and verify with logger.<\/li>\n\n\n\n<li><strong>Task 07 \u2014 Boot service failure:<\/strong>\u00a0A required local service causes degraded boot. Identify the failed unit and dependency chain; repair and reboot.<\/li>\n\n\n\n<li><strong>Task 11 \u2014 Kernel modules:<\/strong>\u00a0A required module is not loaded after reboot. Inspect module availability\/parameters, configure persistent loading, reboot and verify.<\/li>\n\n\n\n<li><strong>Task 15 \u2014 DNF dependencies:<\/strong>\u00a0Package installation fails because of dependency\/repository state. Determine the exact dependency chain and fix repository\/package state.<\/li>\n\n\n\n<li><strong>Task 18 \u2014 Connectivity:<\/strong>\u00a0Two hosts cannot communicate after a network change. Check link, address, route, DNS, socket, firewall; fix the actual fault.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Scoring guidance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">60 points total; 8 points per task + 12 points for verification\/persistence. Suggested pass mark for self-study: 80%.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution method<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Solutions are intentionally method-oriented rather than command-copy recipes: collect evidence \u2192 isolate layer \u2192 perform smallest safe repair \u2192 verify final state \u2192 reboot\/lifecycle-check where relevant. Use the matching task&#8217;s verification criterion above as the answer key.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failure rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a storage recovery task destroys data, SELinux is disabled instead of fixed, a PAM task locks out all administrative access without recovery, or persistence is not verified, mark that task failed even if the symptom temporarily disappears.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Mock Exam 2 \u2014 Intermediate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time limit:<\/strong>&nbsp;150 minutes<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Task 04 \u2014 Ansible:<\/strong>\u00a0Two RHEL nodes drift from a required service configuration. Create inventory\/playbook, apply idempotently, run twice, and show no unintended second-run changes.<\/li>\n\n\n\n<li><strong>Task 06 \u2014 AIDE:<\/strong>\u00a0Integrity monitoring reports one legitimate and one suspicious change. Identify both, approve only the legitimate change, update baseline, and leave suspicious change reported.<\/li>\n\n\n\n<li><strong>Task 09 \u2014 Boot issue:<\/strong>\u00a0The OS drops to emergency\/rescue behavior because a persistent mount is wrong. Find the exact mount failure and correct persistent configuration.<\/li>\n\n\n\n<li><strong>Task 12 \u2014 Filesystem recovery:<\/strong>\u00a0A disposable XFS\/ext4 filesystem does not mount after simulated corruption. Use filesystem-appropriate diagnostic and repair workflow.<\/li>\n\n\n\n<li><strong>Task 17 \u2014 Changed package files:<\/strong>\u00a0An application binary\/configuration may have been modified. Use package ownership and RPM verification to report changes.<\/li>\n\n\n\n<li><strong>Task 20 \u2014 Library dependencies:<\/strong>\u00a0A third-party executable fails with a missing shared library. Identify required soname\/library and restore supported loader visibility.<\/li>\n\n\n\n<li><strong>Task 23 \u2014 SELinux:<\/strong>\u00a0A service works in permissive mode but not enforcing. Find AVC denial, correct label\/boolean\/policy-compatible config, return enforcing.<\/li>\n\n\n\n<li><strong>Task 25 \u2014 Account policy:<\/strong>\u00a0One user cannot log in; other users can. Determine expiration\/lockout\/password aging state and apply the intended policy.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Scoring guidance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">80 points total; 8 points per task + 16 points for verification, evidence quality, and persistence. Suggested pass mark: 80%.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution method<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Solutions are intentionally method-oriented rather than command-copy recipes: collect evidence \u2192 isolate layer \u2192 perform smallest safe repair \u2192 verify final state \u2192 reboot\/lifecycle-check where relevant. Use the matching task&#8217;s verification criterion above as the answer key.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failure rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a storage recovery task destroys data, SELinux is disabled instead of fixed, a PAM task locks out all administrative access without recovery, or persistence is not verified, mark that task failed even if the symptom temporarily disappears.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Mock Exam 3 \u2014 Advanced<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time limit:<\/strong>&nbsp;180 minutes<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Task 05 \u2014 Central logging:<\/strong>\u00a0node1 messages do not arrive on loghost. Fix rsyslog path\/transport\/listener\/firewall as needed and verify with logger.<\/li>\n\n\n\n<li><strong>Task 08 \u2014 Regain root control:<\/strong>\u00a0Normal login is unavailable on a disposable lab VM. Use a current supported rescue path to regain administrative control and repair the cause.<\/li>\n\n\n\n<li><strong>Task 13 \u2014 LVM recovery:<\/strong>\u00a0A VG references a missing or damaged PV in the lab. Use LVM metadata backups\/archives to recover the mapping carefully.<\/li>\n\n\n\n<li><strong>Task 14 \u2014 Encrypted storage:<\/strong>\u00a0A LUKS-backed filesystem no longer opens automatically. Identify mapping\/configuration problem without recreating the filesystem.<\/li>\n\n\n\n<li><strong>Task 16 \u2014 RPM database:<\/strong>\u00a0rpm\/dnf queries fail on a disposable snapshot because the rpmdb is damaged. Preserve evidence, recover\/rebuild the database, and verify package queries.<\/li>\n\n\n\n<li><strong>Task 19 \u2014 Packet inspection:<\/strong>\u00a0A TCP connection times out. Capture packets and classify whether SYN leaves, reply returns, reset occurs, or firewall silently drops.<\/li>\n\n\n\n<li><strong>Task 21 \u2014 Memory leak:<\/strong>\u00a0A test application grows in resident memory. Confirm growth and use valgrind\/memcheck or appropriate tooling to identify leak evidence.<\/li>\n\n\n\n<li><strong>Task 24 \u2014 PAM:<\/strong>\u00a0A local login fails after authentication configuration was changed. Inspect authselect\/PAM state and logs; repair the stack safely.<\/li>\n\n\n\n<li><strong>Task 27 \u2014 Support data:<\/strong>\u00a0A vendor requests diagnostic information before changes are made. Create sos report and collect targeted logs, package state, kernel, modules, and network evidence.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Scoring guidance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">90 points total; 8 points per task + 18 points for safe recovery, persistence, and evidence. Suggested pass mark: 80%.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution method<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Solutions are intentionally method-oriented rather than command-copy recipes: collect evidence \u2192 isolate layer \u2192 perform smallest safe repair \u2192 verify final state \u2192 reboot\/lifecycle-check where relevant. Use the matching task&#8217;s verification criterion above as the answer key.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failure rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a storage recovery task destroys data, SELinux is disabled instead of fixed, a PAM task locks out all administrative access without recovery, or persistence is not verified, mark that task failed even if the symptom temporarily disappears.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Mock Exam 4 \u2014 Enterprise Scenario<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time limit:<\/strong>&nbsp;210 minutes<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Task 02 \u2014 Documentation:<\/strong>\u00a0A utility is unfamiliar and outside your memorized command set. Use local man\/info\/help and provided documentation to determine safe syntax; perform the requested change.<\/li>\n\n\n\n<li><strong>Task 04 \u2014 Ansible:<\/strong>\u00a0Two RHEL nodes drift from a required service configuration. Create inventory\/playbook, apply idempotently, run twice, and show no unintended second-run changes.<\/li>\n\n\n\n<li><strong>Task 05 \u2014 Central logging:<\/strong>\u00a0node1 messages do not arrive on loghost. Fix rsyslog path\/transport\/listener\/firewall as needed and verify with logger.<\/li>\n\n\n\n<li><strong>Task 10 \u2014 Hardware evidence:<\/strong>\u00a0A NIC\/disk is allegedly &#8216;missing&#8217;. Use kernel\/hardware tools and logs to determine whether hardware is absent, driver is missing, or interface is simply down.<\/li>\n\n\n\n<li><strong>Task 12 \u2014 Filesystem recovery:<\/strong>\u00a0A disposable XFS\/ext4 filesystem does not mount after simulated corruption. Use filesystem-appropriate diagnostic and repair workflow.<\/li>\n\n\n\n<li><strong>Task 13 \u2014 LVM recovery:<\/strong>\u00a0A VG references a missing or damaged PV in the lab. Use LVM metadata backups\/archives to recover the mapping carefully.<\/li>\n\n\n\n<li><strong>Task 18 \u2014 Connectivity:<\/strong>\u00a0Two hosts cannot communicate after a network change. Check link, address, route, DNS, socket, firewall; fix the actual fault.<\/li>\n\n\n\n<li><strong>Task 19 \u2014 Packet inspection:<\/strong>\u00a0A TCP connection times out. Capture packets and classify whether SYN leaves, reply returns, reset occurs, or firewall silently drops.<\/li>\n\n\n\n<li><strong>Task 22 \u2014 Application tracing:<\/strong>\u00a0An app returns permission denied but file mode looks correct. Trace file\/syscall behavior and correlate with logs.<\/li>\n\n\n\n<li><strong>Task 23 \u2014 SELinux:<\/strong>\u00a0A service works in permissive mode but not enforcing. Find AVC denial, correct label\/boolean\/policy-compatible config, return enforcing.<\/li>\n\n\n\n<li><strong>Task 26 \u2014 Kdump:<\/strong>\u00a0A host must be ready to capture a kernel crash. Configure\/verify kdump and its target; do not trigger unsafe crash outside disposable VM.<\/li>\n\n\n\n<li><strong>Task 27 \u2014 Support data:<\/strong>\u00a0A vendor requests diagnostic information before changes are made. Create sos report and collect targeted logs, package state, kernel, modules, and network evidence.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Scoring guidance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">120 points total; score both restoration and diagnostic reasoning. Suggested pass mark: 85%.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution method<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Solutions are intentionally method-oriented rather than command-copy recipes: collect evidence \u2192 isolate layer \u2192 perform smallest safe repair \u2192 verify final state \u2192 reboot\/lifecycle-check where relevant. Use the matching task&#8217;s verification criterion above as the answer key.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failure rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a storage recovery task destroys data, SELinux is disabled instead of fixed, a PAM task locks out all administrative access without recovery, or persistence is not verified, mark that task failed even if the symptom temporarily disappears.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Mock Exam 5 \u2014 Full EX342 Simulation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Time limit:<\/strong>&nbsp;240 minutes<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Tasks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Task 01 \u2014 Troubleshooting method:<\/strong>\u00a0A service is reported &#8216;slow&#8217; but not down. Collect CPU, memory, I\/O, process and log evidence; identify the bottleneck; make only an evidence-backed correction.<\/li>\n\n\n\n<li><strong>Task 03 \u2014 RHEL web console:<\/strong>\u00a0CLI metrics and web-console view disagree after a service change. Enable\/access the web console, reconcile the state, and identify what changed.<\/li>\n\n\n\n<li><strong>Task 04 \u2014 Ansible:<\/strong>\u00a0Two RHEL nodes drift from a required service configuration. Create inventory\/playbook, apply idempotently, run twice, and show no unintended second-run changes.<\/li>\n\n\n\n<li><strong>Task 05 \u2014 Central logging:<\/strong>\u00a0node1 messages do not arrive on loghost. Fix rsyslog path\/transport\/listener\/firewall as needed and verify with logger.<\/li>\n\n\n\n<li><strong>Task 06 \u2014 AIDE:<\/strong>\u00a0Integrity monitoring reports one legitimate and one suspicious change. Identify both, approve only the legitimate change, update baseline, and leave suspicious change reported.<\/li>\n\n\n\n<li><strong>Task 07 \u2014 Boot service failure:<\/strong>\u00a0A required local service causes degraded boot. Identify the failed unit and dependency chain; repair and reboot.<\/li>\n\n\n\n<li><strong>Task 08 \u2014 Regain root control:<\/strong>\u00a0Normal login is unavailable on a disposable lab VM. Use a current supported rescue path to regain administrative control and repair the cause.<\/li>\n\n\n\n<li><strong>Task 11 \u2014 Kernel modules:<\/strong>\u00a0A required module is not loaded after reboot. Inspect module availability\/parameters, configure persistent loading, reboot and verify.<\/li>\n\n\n\n<li><strong>Task 12 \u2014 Filesystem recovery:<\/strong>\u00a0A disposable XFS\/ext4 filesystem does not mount after simulated corruption. Use filesystem-appropriate diagnostic and repair workflow.<\/li>\n\n\n\n<li><strong>Task 13 \u2014 LVM recovery:<\/strong>\u00a0A VG references a missing or damaged PV in the lab. Use LVM metadata backups\/archives to recover the mapping carefully.<\/li>\n\n\n\n<li><strong>Task 15 \u2014 DNF dependencies:<\/strong>\u00a0Package installation fails because of dependency\/repository state. Determine the exact dependency chain and fix repository\/package state.<\/li>\n\n\n\n<li><strong>Task 16 \u2014 RPM database:<\/strong>\u00a0rpm\/dnf queries fail on a disposable snapshot because the rpmdb is damaged. Preserve evidence, recover\/rebuild the database, and verify package queries.<\/li>\n\n\n\n<li><strong>Task 18 \u2014 Connectivity:<\/strong>\u00a0Two hosts cannot communicate after a network change. Check link, address, route, DNS, socket, firewall; fix the actual fault.<\/li>\n\n\n\n<li><strong>Task 19 \u2014 Packet inspection:<\/strong>\u00a0A TCP connection times out. Capture packets and classify whether SYN leaves, reply returns, reset occurs, or firewall silently drops.<\/li>\n\n\n\n<li><strong>Task 20 \u2014 Library dependencies:<\/strong>\u00a0A third-party executable fails with a missing shared library. Identify required soname\/library and restore supported loader visibility.<\/li>\n\n\n\n<li><strong>Task 21 \u2014 Memory leak:<\/strong>\u00a0A test application grows in resident memory. Confirm growth and use valgrind\/memcheck or appropriate tooling to identify leak evidence.<\/li>\n\n\n\n<li><strong>Task 23 \u2014 SELinux:<\/strong>\u00a0A service works in permissive mode but not enforcing. Find AVC denial, correct label\/boolean\/policy-compatible config, return enforcing.<\/li>\n\n\n\n<li><strong>Task 24 \u2014 PAM:<\/strong>\u00a0A local login fails after authentication configuration was changed. Inspect authselect\/PAM state and logs; repair the stack safely.<\/li>\n\n\n\n<li><strong>Task 25 \u2014 Account policy:<\/strong>\u00a0One user cannot log in; other users can. Determine expiration\/lockout\/password aging state and apply the intended policy.<\/li>\n\n\n\n<li><strong>Task 26 \u2014 Kdump:<\/strong>\u00a0A host must be ready to capture a kernel crash. Configure\/verify kdump and its target; do not trigger unsafe crash outside disposable VM.<\/li>\n\n\n\n<li><strong>Task 27 \u2014 Support data:<\/strong>\u00a0A vendor requests diagnostic information before changes are made. Create sos report and collect targeted logs, package state, kernel, modules, and network evidence.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Scoring guidance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Practice-only scoring: 210 points, 8 per task plus 42 points for persistence, reboot verification, no destructive shortcuts, and complete final-state checks. Target 85%+ twice before booking.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Solution method<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Solutions are intentionally method-oriented rather than command-copy recipes: collect evidence \u2192 isolate layer \u2192 perform smallest safe repair \u2192 verify final state \u2192 reboot\/lifecycle-check where relevant. Use the matching task&#8217;s verification criterion above as the answer key.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failure rule<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If a storage recovery task destroys data, SELinux is disabled instead of fixed, a PAM task locks out all administrative access without recovery, or persistence is not verified, mark that task failed even if the symptom temporarily disappears.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 22 \u2014 30 \/ 45 \/ 60 \/ 90 Day Study Plans<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">30-Day Intensive<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Recommended for learners who can spend roughly 3\u20135 focused hours per day.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-right\" data-align=\"right\">Day<\/th><th class=\"has-text-align-left\" data-align=\"left\">Objective\/topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Theory<\/th><th class=\"has-text-align-left\" data-align=\"left\">Lab<\/th><th class=\"has-text-align-left\" data-align=\"left\">Troubleshooting<\/th><th class=\"has-text-align-left\" data-align=\"left\">Revision<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-right\" data-align=\"right\">1<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">2<\/td><td>Troubleshooting method<\/td><td>Evidence-first workflow, documentation<\/td><td>Task 01-02<\/td><td>Misleading symptom drill<\/td><td>Commands<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">3<\/td><td>Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01<\/td><td>Resource bottleneck<\/td><td>Metrics<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">4<\/td><td>RHEL web console<\/td><td>Cockpit monitoring\/admin<\/td><td>Task 03<\/td><td>cockpit unavailable<\/td><td>Web+CLI<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">5<\/td><td>Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04<\/td><td>inventory\/SSH failure<\/td><td>Syntax<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">6<\/td><td>Central logging<\/td><td>rsyslog client\/server<\/td><td>Task 05<\/td><td>listener\/firewall\/config fault<\/td><td>Logs<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">7<\/td><td>Review: AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06 + repeat one earlier lab<\/td><td>legit vs suspicious drift<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">8<\/td><td>Startup services<\/td><td>systemd failed units\/dependencies<\/td><td>Task 07<\/td><td>boot-affecting unit<\/td><td>Journals<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">9<\/td><td>Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08<\/td><td>no normal login<\/td><td>Recovery<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">10<\/td><td>Boot troubleshooting<\/td><td>mount\/initramfs\/boot evidence<\/td><td>Task 09<\/td><td>bad persistent mount<\/td><td>Boot<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">11<\/td><td>Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10<\/td><td>missing NIC\/disk<\/td><td>dmesg<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">12<\/td><td>Kernel modules<\/td><td>lsmod\/modinfo\/modprobe\/persistence<\/td><td>Task 11<\/td><td>module absent after reboot<\/td><td>Modules<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">13<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">14<\/td><td>Review: LVM recovery<\/td><td>metadata archives\/restore<\/td><td>Task 13 + repeat one earlier lab<\/td><td>missing PV metadata<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">15<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">16<\/td><td>DNF dependencies<\/td><td>repositories\/dependency resolution<\/td><td>Task 15<\/td><td>transaction failure<\/td><td>DNF<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">17<\/td><td>RPM database<\/td><td>database recovery<\/td><td>Task 16<\/td><td>rpmdb failure<\/td><td>RPM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">18<\/td><td>Package verification<\/td><td>ownership and changed files<\/td><td>Task 17<\/td><td>file drift<\/td><td>rpm -V<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">19<\/td><td>Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18<\/td><td>multi-layer failure<\/td><td>Network<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">20<\/td><td>Packet capture<\/td><td>tcpdump diagnosis<\/td><td>Task 19<\/td><td>timeout\/refused\/drop<\/td><td>Packets<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">21<\/td><td>Review: Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20 + repeat one earlier lab<\/td><td>missing soname<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">22<\/td><td>Memory leaks<\/td><td>process memory + valgrind<\/td><td>Task 21<\/td><td>leaky app<\/td><td>Memory<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">23<\/td><td>App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22<\/td><td>permission\/path failure<\/td><td>Tracing<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">24<\/td><td>SELinux<\/td><td>AVC evidence and correction<\/td><td>Task 23<\/td><td>label\/boolean issue<\/td><td>SELinux<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">25<\/td><td>PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24<\/td><td>login failure<\/td><td>PAM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">26<\/td><td>Account policy<\/td><td>aging\/expiration\/lockout<\/td><td>Task 25<\/td><td>single-user failure<\/td><td>Accounts<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">27<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">28<\/td><td>Review: Support data<\/td><td>sos report + evidence bundle<\/td><td>Task 27 + repeat one earlier lab<\/td><td>escalation drill<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">29<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">30<\/td><td>Full simulation<\/td><td>4-hour integrated work<\/td><td>Mock 5<\/td><td>reboot\/persistence<\/td><td>Final review<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">45-Day Balanced<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Balanced path with more repeat labs and recovery practice.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-right\" data-align=\"right\">Day<\/th><th class=\"has-text-align-left\" data-align=\"left\">Objective\/topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Theory<\/th><th class=\"has-text-align-left\" data-align=\"left\">Lab<\/th><th class=\"has-text-align-left\" data-align=\"left\">Troubleshooting<\/th><th class=\"has-text-align-left\" data-align=\"left\">Revision<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-right\" data-align=\"right\">1<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">2<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">3<\/td><td>Troubleshooting method<\/td><td>Evidence-first workflow, documentation<\/td><td>Task 01-02<\/td><td>Misleading symptom drill<\/td><td>Commands<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">4<\/td><td>Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01<\/td><td>Resource bottleneck<\/td><td>Metrics<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">5<\/td><td>Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01<\/td><td>Resource bottleneck<\/td><td>Metrics<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">6<\/td><td>RHEL web console<\/td><td>Cockpit monitoring\/admin<\/td><td>Task 03<\/td><td>cockpit unavailable<\/td><td>Web+CLI<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">7<\/td><td>Review: Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04 + repeat one earlier lab<\/td><td>inventory\/SSH failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">8<\/td><td>Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04<\/td><td>inventory\/SSH failure<\/td><td>Syntax<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">9<\/td><td>Central logging<\/td><td>rsyslog client\/server<\/td><td>Task 05<\/td><td>listener\/firewall\/config fault<\/td><td>Logs<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">10<\/td><td>AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06<\/td><td>legit vs suspicious drift<\/td><td>Files<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">11<\/td><td>AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06<\/td><td>legit vs suspicious drift<\/td><td>Files<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">12<\/td><td>Startup services<\/td><td>systemd failed units\/dependencies<\/td><td>Task 07<\/td><td>boot-affecting unit<\/td><td>Journals<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">13<\/td><td>Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08<\/td><td>no normal login<\/td><td>Recovery<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">14<\/td><td>Review: Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08 + repeat one earlier lab<\/td><td>no normal login<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">15<\/td><td>Boot troubleshooting<\/td><td>mount\/initramfs\/boot evidence<\/td><td>Task 09<\/td><td>bad persistent mount<\/td><td>Boot<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">16<\/td><td>Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10<\/td><td>missing NIC\/disk<\/td><td>dmesg<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">17<\/td><td>Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10<\/td><td>missing NIC\/disk<\/td><td>dmesg<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">18<\/td><td>Kernel modules<\/td><td>lsmod\/modinfo\/modprobe\/persistence<\/td><td>Task 11<\/td><td>module absent after reboot<\/td><td>Modules<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">19<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">20<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">21<\/td><td>Review: LVM recovery<\/td><td>metadata archives\/restore<\/td><td>Task 13 + repeat one earlier lab<\/td><td>missing PV metadata<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">22<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">23<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">24<\/td><td>DNF dependencies<\/td><td>repositories\/dependency resolution<\/td><td>Task 15<\/td><td>transaction failure<\/td><td>DNF<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">25<\/td><td>RPM database<\/td><td>database recovery<\/td><td>Task 16<\/td><td>rpmdb failure<\/td><td>RPM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">26<\/td><td>RPM database<\/td><td>database recovery<\/td><td>Task 16<\/td><td>rpmdb failure<\/td><td>RPM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">27<\/td><td>Package verification<\/td><td>ownership and changed files<\/td><td>Task 17<\/td><td>file drift<\/td><td>rpm -V<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">28<\/td><td>Review: Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18 + repeat one earlier lab<\/td><td>multi-layer failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">29<\/td><td>Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18<\/td><td>multi-layer failure<\/td><td>Network<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">30<\/td><td>Packet capture<\/td><td>tcpdump diagnosis<\/td><td>Task 19<\/td><td>timeout\/refused\/drop<\/td><td>Packets<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">31<\/td><td>Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20<\/td><td>missing soname<\/td><td>Libraries<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">32<\/td><td>Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20<\/td><td>missing soname<\/td><td>Libraries<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">33<\/td><td>Memory leaks<\/td><td>process memory + valgrind<\/td><td>Task 21<\/td><td>leaky app<\/td><td>Memory<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">34<\/td><td>App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22<\/td><td>permission\/path failure<\/td><td>Tracing<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">35<\/td><td>Review: App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22 + repeat one earlier lab<\/td><td>permission\/path failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">36<\/td><td>SELinux<\/td><td>AVC evidence and correction<\/td><td>Task 23<\/td><td>label\/boolean issue<\/td><td>SELinux<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">37<\/td><td>PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24<\/td><td>login failure<\/td><td>PAM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">38<\/td><td>PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24<\/td><td>login failure<\/td><td>PAM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">39<\/td><td>Account policy<\/td><td>aging\/expiration\/lockout<\/td><td>Task 25<\/td><td>single-user failure<\/td><td>Accounts<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">40<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">41<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">42<\/td><td>Review: Support data<\/td><td>sos report + evidence bundle<\/td><td>Task 27 + repeat one earlier lab<\/td><td>escalation drill<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">43<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">44<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">45<\/td><td>Full simulation<\/td><td>4-hour integrated work<\/td><td>Mock 5<\/td><td>reboot\/persistence<\/td><td>Final review<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">60-Day Moderate<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Moderate daily load with deliberate troubleshooting repetition.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-right\" data-align=\"right\">Day<\/th><th class=\"has-text-align-left\" data-align=\"left\">Objective\/topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Theory<\/th><th class=\"has-text-align-left\" data-align=\"left\">Lab<\/th><th class=\"has-text-align-left\" data-align=\"left\">Troubleshooting<\/th><th class=\"has-text-align-left\" data-align=\"left\">Revision<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-right\" data-align=\"right\">1<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">2<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">3<\/td><td>Troubleshooting method<\/td><td>Evidence-first workflow, documentation<\/td><td>Task 01-02<\/td><td>Misleading symptom drill<\/td><td>Commands<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">4<\/td><td>Troubleshooting method<\/td><td>Evidence-first workflow, documentation<\/td><td>Task 01-02<\/td><td>Misleading symptom drill<\/td><td>Commands<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">5<\/td><td>Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01<\/td><td>Resource bottleneck<\/td><td>Metrics<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">6<\/td><td>Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01<\/td><td>Resource bottleneck<\/td><td>Metrics<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">7<\/td><td>Review: RHEL web console<\/td><td>Cockpit monitoring\/admin<\/td><td>Task 03 + repeat one earlier lab<\/td><td>cockpit unavailable<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">8<\/td><td>RHEL web console<\/td><td>Cockpit monitoring\/admin<\/td><td>Task 03<\/td><td>cockpit unavailable<\/td><td>Web+CLI<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">9<\/td><td>Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04<\/td><td>inventory\/SSH failure<\/td><td>Syntax<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">10<\/td><td>Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04<\/td><td>inventory\/SSH failure<\/td><td>Syntax<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">11<\/td><td>Central logging<\/td><td>rsyslog client\/server<\/td><td>Task 05<\/td><td>listener\/firewall\/config fault<\/td><td>Logs<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">12<\/td><td>Central logging<\/td><td>rsyslog client\/server<\/td><td>Task 05<\/td><td>listener\/firewall\/config fault<\/td><td>Logs<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">13<\/td><td>AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06<\/td><td>legit vs suspicious drift<\/td><td>Files<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">14<\/td><td>Review: AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06 + repeat one earlier lab<\/td><td>legit vs suspicious drift<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">15<\/td><td>Startup services<\/td><td>systemd failed units\/dependencies<\/td><td>Task 07<\/td><td>boot-affecting unit<\/td><td>Journals<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">16<\/td><td>Startup services<\/td><td>systemd failed units\/dependencies<\/td><td>Task 07<\/td><td>boot-affecting unit<\/td><td>Journals<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">17<\/td><td>Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08<\/td><td>no normal login<\/td><td>Recovery<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">18<\/td><td>Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08<\/td><td>no normal login<\/td><td>Recovery<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">19<\/td><td>Boot troubleshooting<\/td><td>mount\/initramfs\/boot evidence<\/td><td>Task 09<\/td><td>bad persistent mount<\/td><td>Boot<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">20<\/td><td>Boot troubleshooting<\/td><td>mount\/initramfs\/boot evidence<\/td><td>Task 09<\/td><td>bad persistent mount<\/td><td>Boot<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">21<\/td><td>Review: Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10 + repeat one earlier lab<\/td><td>missing NIC\/disk<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">22<\/td><td>Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10<\/td><td>missing NIC\/disk<\/td><td>dmesg<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">23<\/td><td>Kernel modules<\/td><td>lsmod\/modinfo\/modprobe\/persistence<\/td><td>Task 11<\/td><td>module absent after reboot<\/td><td>Modules<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">24<\/td><td>Kernel modules<\/td><td>lsmod\/modinfo\/modprobe\/persistence<\/td><td>Task 11<\/td><td>module absent after reboot<\/td><td>Modules<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">25<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">26<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">27<\/td><td>LVM recovery<\/td><td>metadata archives\/restore<\/td><td>Task 13<\/td><td>missing PV metadata<\/td><td>LVM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">28<\/td><td>Review: LVM recovery<\/td><td>metadata archives\/restore<\/td><td>Task 13 + repeat one earlier lab<\/td><td>missing PV metadata<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">29<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">30<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">31<\/td><td>DNF dependencies<\/td><td>repositories\/dependency resolution<\/td><td>Task 15<\/td><td>transaction failure<\/td><td>DNF<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">32<\/td><td>DNF dependencies<\/td><td>repositories\/dependency resolution<\/td><td>Task 15<\/td><td>transaction failure<\/td><td>DNF<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">33<\/td><td>RPM database<\/td><td>database recovery<\/td><td>Task 16<\/td><td>rpmdb failure<\/td><td>RPM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">34<\/td><td>RPM database<\/td><td>database recovery<\/td><td>Task 16<\/td><td>rpmdb failure<\/td><td>RPM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">35<\/td><td>Review: Package verification<\/td><td>ownership and changed files<\/td><td>Task 17 + repeat one earlier lab<\/td><td>file drift<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">36<\/td><td>Package verification<\/td><td>ownership and changed files<\/td><td>Task 17<\/td><td>file drift<\/td><td>rpm -V<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">37<\/td><td>Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18<\/td><td>multi-layer failure<\/td><td>Network<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">38<\/td><td>Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18<\/td><td>multi-layer failure<\/td><td>Network<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">39<\/td><td>Packet capture<\/td><td>tcpdump diagnosis<\/td><td>Task 19<\/td><td>timeout\/refused\/drop<\/td><td>Packets<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">40<\/td><td>Packet capture<\/td><td>tcpdump diagnosis<\/td><td>Task 19<\/td><td>timeout\/refused\/drop<\/td><td>Packets<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">41<\/td><td>Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20<\/td><td>missing soname<\/td><td>Libraries<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">42<\/td><td>Review: Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20 + repeat one earlier lab<\/td><td>missing soname<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">43<\/td><td>Memory leaks<\/td><td>process memory + valgrind<\/td><td>Task 21<\/td><td>leaky app<\/td><td>Memory<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">44<\/td><td>Memory leaks<\/td><td>process memory + valgrind<\/td><td>Task 21<\/td><td>leaky app<\/td><td>Memory<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">45<\/td><td>App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22<\/td><td>permission\/path failure<\/td><td>Tracing<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">46<\/td><td>App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22<\/td><td>permission\/path failure<\/td><td>Tracing<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">47<\/td><td>SELinux<\/td><td>AVC evidence and correction<\/td><td>Task 23<\/td><td>label\/boolean issue<\/td><td>SELinux<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">48<\/td><td>SELinux<\/td><td>AVC evidence and correction<\/td><td>Task 23<\/td><td>label\/boolean issue<\/td><td>SELinux<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">49<\/td><td>Review: PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24 + repeat one earlier lab<\/td><td>login failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">50<\/td><td>PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24<\/td><td>login failure<\/td><td>PAM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">51<\/td><td>Account policy<\/td><td>aging\/expiration\/lockout<\/td><td>Task 25<\/td><td>single-user failure<\/td><td>Accounts<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">52<\/td><td>Account policy<\/td><td>aging\/expiration\/lockout<\/td><td>Task 25<\/td><td>single-user failure<\/td><td>Accounts<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">53<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">54<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">55<\/td><td>Support data<\/td><td>sos report + evidence bundle<\/td><td>Task 27<\/td><td>escalation drill<\/td><td>sos<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">56<\/td><td>Review: Support data<\/td><td>sos report + evidence bundle<\/td><td>Task 27 + repeat one earlier lab<\/td><td>escalation drill<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">57<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">58<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">59<\/td><td>Full simulation<\/td><td>4-hour integrated work<\/td><td>Mock 5<\/td><td>reboot\/persistence<\/td><td>Final review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">60<\/td><td>Full simulation<\/td><td>4-hour integrated work<\/td><td>Mock 5<\/td><td>reboot\/persistence<\/td><td>Final review<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">90-Day Part-Time<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Part-time path emphasizing repetition, rebuilds, and retention.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-right\" data-align=\"right\">Day<\/th><th class=\"has-text-align-left\" data-align=\"left\">Objective\/topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Theory<\/th><th class=\"has-text-align-left\" data-align=\"left\">Lab<\/th><th class=\"has-text-align-left\" data-align=\"left\">Troubleshooting<\/th><th class=\"has-text-align-left\" data-align=\"left\">Revision<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-right\" data-align=\"right\">1<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">2<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">3<\/td><td>Official scope + baseline<\/td><td>Verify EX342 objectives; baseline RHCSA skills<\/td><td>Build\/clone lab<\/td><td>Baseline facts<\/td><td>Review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">4<\/td><td>Troubleshooting method<\/td><td>Evidence-first workflow, documentation<\/td><td>Task 01-02<\/td><td>Misleading symptom drill<\/td><td>Commands<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">5<\/td><td>Troubleshooting method<\/td><td>Evidence-first workflow, documentation<\/td><td>Task 01-02<\/td><td>Misleading symptom drill<\/td><td>Commands<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">6<\/td><td>Troubleshooting method<\/td><td>Evidence-first workflow, documentation<\/td><td>Task 01-02<\/td><td>Misleading symptom drill<\/td><td>Commands<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">7<\/td><td>Review: Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01 + repeat one earlier lab<\/td><td>Resource bottleneck<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">8<\/td><td>Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01<\/td><td>Resource bottleneck<\/td><td>Metrics<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">9<\/td><td>Monitoring<\/td><td>CPU\/memory\/I\/O\/process\/log interpretation<\/td><td>Task 01<\/td><td>Resource bottleneck<\/td><td>Metrics<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">10<\/td><td>RHEL web console<\/td><td>Cockpit monitoring\/admin<\/td><td>Task 03<\/td><td>cockpit unavailable<\/td><td>Web+CLI<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">11<\/td><td>RHEL web console<\/td><td>Cockpit monitoring\/admin<\/td><td>Task 03<\/td><td>cockpit unavailable<\/td><td>Web+CLI<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">12<\/td><td>RHEL web console<\/td><td>Cockpit monitoring\/admin<\/td><td>Task 03<\/td><td>cockpit unavailable<\/td><td>Web+CLI<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">13<\/td><td>Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04<\/td><td>inventory\/SSH failure<\/td><td>Syntax<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">14<\/td><td>Review: Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04 + repeat one earlier lab<\/td><td>inventory\/SSH failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">15<\/td><td>Ansible<\/td><td>Inventory, playbooks, idempotent config<\/td><td>Task 04<\/td><td>inventory\/SSH failure<\/td><td>Syntax<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">16<\/td><td>Central logging<\/td><td>rsyslog client\/server<\/td><td>Task 05<\/td><td>listener\/firewall\/config fault<\/td><td>Logs<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">17<\/td><td>Central logging<\/td><td>rsyslog client\/server<\/td><td>Task 05<\/td><td>listener\/firewall\/config fault<\/td><td>Logs<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">18<\/td><td>Central logging<\/td><td>rsyslog client\/server<\/td><td>Task 05<\/td><td>listener\/firewall\/config fault<\/td><td>Logs<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">19<\/td><td>AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06<\/td><td>legit vs suspicious drift<\/td><td>Files<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">20<\/td><td>AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06<\/td><td>legit vs suspicious drift<\/td><td>Files<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">21<\/td><td>Review: AIDE<\/td><td>baseline\/check\/update<\/td><td>Task 06 + repeat one earlier lab<\/td><td>legit vs suspicious drift<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">22<\/td><td>Startup services<\/td><td>systemd failed units\/dependencies<\/td><td>Task 07<\/td><td>boot-affecting unit<\/td><td>Journals<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">23<\/td><td>Startup services<\/td><td>systemd failed units\/dependencies<\/td><td>Task 07<\/td><td>boot-affecting unit<\/td><td>Journals<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">24<\/td><td>Startup services<\/td><td>systemd failed units\/dependencies<\/td><td>Task 07<\/td><td>boot-affecting unit<\/td><td>Journals<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">25<\/td><td>Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08<\/td><td>no normal login<\/td><td>Recovery<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">26<\/td><td>Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08<\/td><td>no normal login<\/td><td>Recovery<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">27<\/td><td>Rescue\/root control<\/td><td>rescue workflow, chroot<\/td><td>Task 08<\/td><td>no normal login<\/td><td>Recovery<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">28<\/td><td>Review: Boot troubleshooting<\/td><td>mount\/initramfs\/boot evidence<\/td><td>Task 09 + repeat one earlier lab<\/td><td>bad persistent mount<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">29<\/td><td>Boot troubleshooting<\/td><td>mount\/initramfs\/boot evidence<\/td><td>Task 09<\/td><td>bad persistent mount<\/td><td>Boot<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">30<\/td><td>Boot troubleshooting<\/td><td>mount\/initramfs\/boot evidence<\/td><td>Task 09<\/td><td>bad persistent mount<\/td><td>Boot<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">31<\/td><td>Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10<\/td><td>missing NIC\/disk<\/td><td>dmesg<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">32<\/td><td>Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10<\/td><td>missing NIC\/disk<\/td><td>dmesg<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">33<\/td><td>Hardware<\/td><td>device\/driver evidence<\/td><td>Task 10<\/td><td>missing NIC\/disk<\/td><td>dmesg<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">34<\/td><td>Kernel modules<\/td><td>lsmod\/modinfo\/modprobe\/persistence<\/td><td>Task 11<\/td><td>module absent after reboot<\/td><td>Modules<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">35<\/td><td>Review: Kernel modules<\/td><td>lsmod\/modinfo\/modprobe\/persistence<\/td><td>Task 11 + repeat one earlier lab<\/td><td>module absent after reboot<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">36<\/td><td>Kernel modules<\/td><td>lsmod\/modinfo\/modprobe\/persistence<\/td><td>Task 11<\/td><td>module absent after reboot<\/td><td>Modules<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">37<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">38<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">39<\/td><td>Filesystem recovery<\/td><td>XFS\/ext4 safe repair<\/td><td>Task 12<\/td><td>corruption<\/td><td>Repair<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">40<\/td><td>LVM recovery<\/td><td>metadata archives\/restore<\/td><td>Task 13<\/td><td>missing PV metadata<\/td><td>LVM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">41<\/td><td>LVM recovery<\/td><td>metadata archives\/restore<\/td><td>Task 13<\/td><td>missing PV metadata<\/td><td>LVM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">42<\/td><td>Review: LVM recovery<\/td><td>metadata archives\/restore<\/td><td>Task 13 + repeat one earlier lab<\/td><td>missing PV metadata<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">43<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">44<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">45<\/td><td>Encrypted storage<\/td><td>LUKS evidence and recovery<\/td><td>Task 14<\/td><td>mapping failure<\/td><td>LUKS<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">46<\/td><td>DNF dependencies<\/td><td>repositories\/dependency resolution<\/td><td>Task 15<\/td><td>transaction failure<\/td><td>DNF<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">47<\/td><td>DNF dependencies<\/td><td>repositories\/dependency resolution<\/td><td>Task 15<\/td><td>transaction failure<\/td><td>DNF<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">48<\/td><td>DNF dependencies<\/td><td>repositories\/dependency resolution<\/td><td>Task 15<\/td><td>transaction failure<\/td><td>DNF<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">49<\/td><td>Review: RPM database<\/td><td>database recovery<\/td><td>Task 16 + repeat one earlier lab<\/td><td>rpmdb failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">50<\/td><td>RPM database<\/td><td>database recovery<\/td><td>Task 16<\/td><td>rpmdb failure<\/td><td>RPM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">51<\/td><td>RPM database<\/td><td>database recovery<\/td><td>Task 16<\/td><td>rpmdb failure<\/td><td>RPM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">52<\/td><td>Package verification<\/td><td>ownership and changed files<\/td><td>Task 17<\/td><td>file drift<\/td><td>rpm -V<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">53<\/td><td>Package verification<\/td><td>ownership and changed files<\/td><td>Task 17<\/td><td>file drift<\/td><td>rpm -V<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">54<\/td><td>Package verification<\/td><td>ownership and changed files<\/td><td>Task 17<\/td><td>file drift<\/td><td>rpm -V<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">55<\/td><td>Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18<\/td><td>multi-layer failure<\/td><td>Network<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">56<\/td><td>Review: Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18 + repeat one earlier lab<\/td><td>multi-layer failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">57<\/td><td>Networking<\/td><td>link\/address\/route\/DNS\/socket\/firewall<\/td><td>Task 18<\/td><td>multi-layer failure<\/td><td>Network<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">58<\/td><td>Packet capture<\/td><td>tcpdump diagnosis<\/td><td>Task 19<\/td><td>timeout\/refused\/drop<\/td><td>Packets<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">59<\/td><td>Packet capture<\/td><td>tcpdump diagnosis<\/td><td>Task 19<\/td><td>timeout\/refused\/drop<\/td><td>Packets<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">60<\/td><td>Packet capture<\/td><td>tcpdump diagnosis<\/td><td>Task 19<\/td><td>timeout\/refused\/drop<\/td><td>Packets<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">61<\/td><td>Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20<\/td><td>missing soname<\/td><td>Libraries<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">62<\/td><td>Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20<\/td><td>missing soname<\/td><td>Libraries<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">63<\/td><td>Review: Libraries<\/td><td>ELF\/shared dependencies<\/td><td>Task 20 + repeat one earlier lab<\/td><td>missing soname<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">64<\/td><td>Memory leaks<\/td><td>process memory + valgrind<\/td><td>Task 21<\/td><td>leaky app<\/td><td>Memory<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">65<\/td><td>Memory leaks<\/td><td>process memory + valgrind<\/td><td>Task 21<\/td><td>leaky app<\/td><td>Memory<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">66<\/td><td>Memory leaks<\/td><td>process memory + valgrind<\/td><td>Task 21<\/td><td>leaky app<\/td><td>Memory<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">67<\/td><td>App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22<\/td><td>permission\/path failure<\/td><td>Tracing<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">68<\/td><td>App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22<\/td><td>permission\/path failure<\/td><td>Tracing<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">69<\/td><td>App debugging<\/td><td>strace\/ltrace\/coredumps<\/td><td>Task 22<\/td><td>permission\/path failure<\/td><td>Tracing<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">70<\/td><td>Review: SELinux<\/td><td>AVC evidence and correction<\/td><td>Task 23 + repeat one earlier lab<\/td><td>label\/boolean issue<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">71<\/td><td>SELinux<\/td><td>AVC evidence and correction<\/td><td>Task 23<\/td><td>label\/boolean issue<\/td><td>SELinux<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">72<\/td><td>SELinux<\/td><td>AVC evidence and correction<\/td><td>Task 23<\/td><td>label\/boolean issue<\/td><td>SELinux<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">73<\/td><td>PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24<\/td><td>login failure<\/td><td>PAM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">74<\/td><td>PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24<\/td><td>login failure<\/td><td>PAM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">75<\/td><td>PAM<\/td><td>authselect\/PAM stack<\/td><td>Task 24<\/td><td>login failure<\/td><td>PAM<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">76<\/td><td>Account policy<\/td><td>aging\/expiration\/lockout<\/td><td>Task 25<\/td><td>single-user failure<\/td><td>Accounts<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">77<\/td><td>Review: Account policy<\/td><td>aging\/expiration\/lockout<\/td><td>Task 25 + repeat one earlier lab<\/td><td>single-user failure<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">78<\/td><td>Account policy<\/td><td>aging\/expiration\/lockout<\/td><td>Task 25<\/td><td>single-user failure<\/td><td>Accounts<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">79<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">80<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">81<\/td><td>Kdump<\/td><td>crash-dump readiness<\/td><td>Task 26<\/td><td>kdump not ready<\/td><td>Kernel crash<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">82<\/td><td>Support data<\/td><td>sos report + evidence bundle<\/td><td>Task 27<\/td><td>escalation drill<\/td><td>sos<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">83<\/td><td>Support data<\/td><td>sos report + evidence bundle<\/td><td>Task 27<\/td><td>escalation drill<\/td><td>sos<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">84<\/td><td>Review: Support data<\/td><td>sos report + evidence bundle<\/td><td>Task 27 + repeat one earlier lab<\/td><td>escalation drill<\/td><td>Timed command\/file recall<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">85<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">86<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">87<\/td><td>Integrated incident<\/td><td>cross-domain troubleshooting<\/td><td>Mock subset<\/td><td>3 faults<\/td><td>Weak areas<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">88<\/td><td>Full simulation<\/td><td>4-hour integrated work<\/td><td>Mock 5<\/td><td>reboot\/persistence<\/td><td>Final review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">89<\/td><td>Full simulation<\/td><td>4-hour integrated work<\/td><td>Mock 5<\/td><td>reboot\/persistence<\/td><td>Final review<\/td><\/tr><tr><td class=\"has-text-align-right\" data-align=\"right\">90<\/td><td>Full simulation<\/td><td>4-hour integrated work<\/td><td>Mock 5<\/td><td>reboot\/persistence<\/td><td>Final review<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">PART 23 \u2014 EX342 Readiness Checklist<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">1. Understand and employ general methods for troubleshooting<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Consult documentation resources to aid in troubleshooting<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Monitor systems for vital characteristics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Monitor systems with the RHEL Web console<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure systems using Ansible<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure systems to send log messages to a centralized host<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Configure systems to monitor files and directories using AIDE<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">2. Diagnose and troubleshoot system startup issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Identify and resolve service failures affecting boot<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Regain root control of a system<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Troubleshoot boot issues<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Identify hardware and hardware problems<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Manage kernel modules and their parameters<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">3. Diagnose and troubleshoot file system issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Recover corrupted file systems<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Recover misconfigured or broken LVM configurations<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Recover data from encrypted file systems<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">4. Resolve package management issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Resolve package management dependency issues<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Recover a corrupted RPM database<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Identify and report changed files<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">5. Troubleshoot and fix network connectivity issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Use standard tools to verify network connectivity<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Identify and fix network connectivity issues<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Inspect network traffic to aid troubleshooting<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">6. Diagnose application issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Identify library dependencies for third-party software<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Identify if an application suffers from memory leaks<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Use standard tools to debug an application<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Identify and fix issues related to SELinux<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">7. Identify and fix authentication issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Identify and fix pluggable authentication module (PAM) issues<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Identify and enforce local user account policies<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">8. Gather information to aid third-party investigation of issues<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Create kernel crash dumps<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Collect system information to aid in troubleshooting<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Understand the concept<\/li>\n\n\n\n<li>[ ] Can configure\/recover it without notes<\/li>\n\n\n\n<li>[ ] Can verify it<\/li>\n\n\n\n<li>[ ] Can troubleshoot it from symptoms<\/li>\n\n\n\n<li>[ ] Can recover from an intentional failure<\/li>\n\n\n\n<li>[ ] Can complete a practical task under time pressure<\/li>\n\n\n\n<li>[ ] Can explain persistence\/reboot implications<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Final readiness gate<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[ ] Two full four-hour simulations completed at 85%+ using the practice scoring model<\/li>\n\n\n\n<li>[ ] No destructive shortcuts used in storage recovery<\/li>\n\n\n\n<li>[ ] SELinux problems solved while returning to enforcing mode<\/li>\n\n\n\n<li>[ ] Can use documentation efficiently instead of relying on memorization<\/li>\n\n\n\n<li>[ ] Can collect evidence before restarting\/changing services<\/li>\n\n\n\n<li>[ ] Can identify the first causal failure in boot\/service chains<\/li>\n\n\n\n<li>[ ] Can perform final reboot\/persistence checks within the timer<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 24 \u2014 Exam-Day Strategy<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Officially verified exam facts<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>EX342 is hands-on\/practical.<\/li>\n\n\n\n<li>Current public time limit:\u00a0<strong>4 hours<\/strong>.<\/li>\n\n\n\n<li>Current public base:\u00a0<strong>RHEL 10.2<\/strong>.<\/li>\n\n\n\n<li>Relevant product documentation is provided in the exam environment.<\/li>\n\n\n\n<li>Outside assistance is not allowed.<\/li>\n\n\n\n<li>Multiple versions can be in use; review your assigned LMS version\/objectives.<\/li>\n\n\n\n<li>Configurations\/services must remain functional through the normal platform lifecycle without manual intervention.<\/li>\n\n\n\n<li>Current Certification Program Guide says Red Hat exams are graded on the final state and persistence matters.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Practical time-management method \u2014 study guidance, not an official Red Hat scoring rule<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Read all instructions and environment information carefully.<\/li>\n\n\n\n<li>Identify dependent tasks before changing foundational networking\/storage\/authentication.<\/li>\n\n\n\n<li>Complete high-confidence tasks first if dependencies allow.<\/li>\n\n\n\n<li>Reserve time to troubleshoot and to verify persistence.<\/li>\n\n\n\n<li>Keep a short scratch list: task \u2192 state \u2192 verification \u2192 reboot check.<\/li>\n\n\n\n<li>When stuck, stop random changes. Re-read the requirement, collect fresh evidence, and move to another independent task if necessary.<\/li>\n\n\n\n<li>Perform a final state review.<\/li>\n\n\n\n<li>Reboot only when appropriate and when you still have time to recover if a hidden persistence problem appears.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Do&nbsp;<strong>not<\/strong>&nbsp;infer unpublished scoring weights or confidential task structures from practice material.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 25 \u2014 What Not to Study<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Required for EX342 \u2014 officially supported by current objectives<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>troubleshooting methodology and documentation<\/li>\n\n\n\n<li>system monitoring<\/li>\n\n\n\n<li>RHEL web console<\/li>\n\n\n\n<li>Ansible-based system configuration<\/li>\n\n\n\n<li>centralized logging<\/li>\n\n\n\n<li>AIDE<\/li>\n\n\n\n<li>boot\/startup\/service recovery<\/li>\n\n\n\n<li>root\/admin recovery mechanisms<\/li>\n\n\n\n<li>hardware diagnosis<\/li>\n\n\n\n<li>kernel modules and parameters<\/li>\n\n\n\n<li>filesystem recovery<\/li>\n\n\n\n<li>LVM recovery<\/li>\n\n\n\n<li>encrypted-filesystem data recovery<\/li>\n\n\n\n<li>DNF\/package dependency troubleshooting<\/li>\n\n\n\n<li>corrupted RPM database recovery<\/li>\n\n\n\n<li>RPM changed-file identification\/reporting<\/li>\n\n\n\n<li>network troubleshooting<\/li>\n\n\n\n<li>packet inspection<\/li>\n\n\n\n<li>application library dependencies<\/li>\n\n\n\n<li>memory leaks<\/li>\n\n\n\n<li>application debugging<\/li>\n\n\n\n<li>SELinux issue diagnosis\/fix<\/li>\n\n\n\n<li>PAM troubleshooting<\/li>\n\n\n\n<li>local account policies<\/li>\n\n\n\n<li>kernel crash dumps<\/li>\n\n\n\n<li>support\/diagnostic data collection<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Useful background \u2014 do not mistake for a separate objective<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>firewalld mechanics<\/li>\n\n\n\n<li>SSH administration<\/li>\n\n\n\n<li>normal RHCSA storage\/network\/user\/systemd skills<\/li>\n\n\n\n<li>shell scripting for small diagnostic helpers<\/li>\n\n\n\n<li>basic C compilation to create safe debugging lab programs<\/li>\n\n\n\n<li>sudo and ACLs<\/li>\n\n\n\n<li>DNS server internals<\/li>\n\n\n\n<li>detailed performance tooling beyond what is needed to diagnose a fault<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Outside the current public EX342 objective list unless needed only as lab background<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>OpenShift\/Kubernetes administration<\/li>\n\n\n\n<li>Ceph architecture<\/li>\n\n\n\n<li>high-availability clustering<\/li>\n\n\n\n<li>Satellite deployment<\/li>\n\n\n\n<li>full Identity Management\/FreeIPA server deployment<\/li>\n\n\n\n<li>advanced Ansible Automation Platform controller architecture<\/li>\n\n\n\n<li>container orchestration<\/li>\n\n\n\n<li>advanced Linux security hardening certification material<\/li>\n\n\n\n<li>deep performance-tuning specialization<\/li>\n\n\n\n<li>enterprise storage products beyond LVM\/filesystem\/encryption recovery<\/li>\n\n\n\n<li>cloud-provider administration<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Those topics may be useful professionally or appear in other Red Hat certifications, but they should not displace time from current EX342 objectives.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 26 \u2014 EX342 vs Other Red Hat Exams<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Exam<\/th><th class=\"has-text-align-left\" data-align=\"left\">Current role in 2026 framework<\/th><th class=\"has-text-align-left\" data-align=\"left\">What it is primarily about<\/th><\/tr><\/thead><tbody><tr><td><strong>EX200<\/strong><\/td><td>Red Hat Certified System Administrator (RHCSA); foundational requirement for Enterprise Linux RHCE<\/td><td>Core RHEL system administration<\/td><\/tr><tr><td><strong>EX342<\/strong><\/td><td>Red Hat Certified Advanced System Administrator in Enterprise Linux; combines with EX200 for RHCE-Enterprise Linux<\/td><td>Advanced RHEL diagnosis, troubleshooting, recovery, evidence collection<\/td><\/tr><tr><td><strong>EX294<\/strong><\/td><td>Red Hat Certified Advanced System Administrator in Ansible; combines with EX200 for RHCE-Ansible<\/td><td>Ansible-based administration\/automation<\/td><\/tr><tr><td><strong>EX280<\/strong><\/td><td>OpenShift administrator credential\/foundation of OpenShift Engineer path<\/td><td>OpenShift administration<\/td><\/tr><tr><td><strong>EX380<\/strong><\/td><td>Advanced System Administrator in OpenShift; combines with EX280 for RHCE-OpenShift<\/td><td>Advanced OpenShift administration<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Do not study EX294 playbook breadth, EX280 cluster administration, or EX380 OpenShift objectives as substitutes for EX342. EX342 has its own current objective list.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 27 \u2014 Training vs Certification Exam<\/h1>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Red Hat training course\n        \u2260\nCertification exam\n        \u2260\nCertification credential\n<\/code><\/span><\/pre>\n\n\n<ul class=\"wp-block-list\">\n<li><strong>RH342<\/strong>\u00a0is Red Hat&#8217;s recommended diagnostics\/troubleshooting training course.<\/li>\n\n\n\n<li><strong>EX342<\/strong>\u00a0is the certification exam.<\/li>\n\n\n\n<li>Passing\u00a0<strong>EX342<\/strong>\u00a0awards the\u00a0<strong>Red Hat Certified Advanced System Administrator in Enterprise Linux<\/strong>\u00a0credential.<\/li>\n\n\n\n<li><strong>RHCE in Enterprise Linux<\/strong>\u00a0requires the matching foundational RHCSA\/EX200 plus EX342.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The current EX342 page recommends RH342&nbsp;<strong>or similar troubleshooting experience<\/strong>. This guide is designed around the second route: independent study and hands-on practice.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 28 \u2014 Cost &amp; Exam Registration<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Pricing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The current Red Hat Certification Program Guide publishes a&nbsp;<strong>standard list price of USD $500<\/strong>&nbsp;for a Red Hat certification exam and states that the actual price can vary by region and is shown in the shopping cart.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Japan:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Check the current Red Hat Japan exam purchase page\/cart for the applicable JPY price.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">A fixed Japan-specific EX342 price was not verified from a public official page during this research pass, so this guide does not guess one.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Delivery methods<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Current Red Hat information supports:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>remote individual exams;<\/li>\n\n\n\n<li>individual testing stations \/ testing centers;<\/li>\n\n\n\n<li>classroom\/on-site formats where offered.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Availability can depend on exam\/region\/scheduler.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Remote exam<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Current policies require using Red Hat&#8217;s remote exam environment and completing the compatibility test. Hardware and technical requirements can change, so use the current booking\/remote-exam documentation rather than a static third-party checklist.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Retake<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Current policy provides&nbsp;<strong>one free retake<\/strong>&nbsp;after an unsuccessful paid first attempt for eligible Individual\/Preliminary exams. The program guide states no waiting period after the first failed attempt, but the same exam may not be taken more than once in the same calendar day. Further attempts require a new paid registration and may be subject to a waiting period.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Purchase flow<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Choose the correct current exam\/version.<\/li>\n\n\n\n<li>Purchase through Red Hat or an authorized channel.<\/li>\n\n\n\n<li>Receive scheduling instructions.<\/li>\n\n\n\n<li>Choose eligible delivery format\/date\/location.<\/li>\n\n\n\n<li>For remote testing, complete the current compatibility test before exam day.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Official:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.redhat.com\/en\/about\/red-hat-training-policies\">https:\/\/www.redhat.com\/en\/about\/red-hat-training-policies<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.redhat.com\/en\/services\/certification\/individual-exams\">https:\/\/www.redhat.com\/en\/services\/certification\/individual-exams<\/a><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 29 \u2014 Certification Validity \/ Currency<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Red Hat&#8217;s current policy says certifications are&nbsp;<strong>current for three years from the date earned<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The 2026 framework introduced more flexible renewal behavior. Current official documentation describes these broad paths:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>retake the exam associated with your highest-level certification;<\/li>\n\n\n\n<li>earn another certification at the same level;<\/li>\n\n\n\n<li>advance to a higher-level certification;<\/li>\n\n\n\n<li>retake the original exam to renew that specific credential where applicable.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Renewal must be completed while the credential is still current; expired\/non-current credentials may need to be earned again according to the current policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For RHCE-Enterprise Linux, remember the stacking model:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">RHCSA \/ EX200\n    +\nRHCASA Enterprise Linux \/ EX342\n    =\nRHCE in Enterprise Linux\n<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">Always check the live Certification Portal for the exact current-until date on your transcript.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Official framework\/renewal sources:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.redhat.com\/en\/services\/training-and-certification\/faq\">https:\/\/www.redhat.com\/en\/services\/training-and-certification\/faq<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index<\/a><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 30 \u2014 Official Resource Map<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Topic<\/th><th class=\"has-text-align-left\" data-align=\"left\">Official Red Hat source<\/th><th class=\"has-text-align-left\" data-align=\"left\">Purpose<\/th><\/tr><\/thead><tbody><tr><td>EX342 current exam page<\/td><td><a href=\"https:\/\/www.redhat.com\/en\/services\/training\/ex342-red-hat-certified-specialist-linux-diagnostics-and-troubleshooting\">https:\/\/www.redhat.com\/en\/services\/training\/ex342-red-hat-certified-specialist-linux-diagnostics-and-troubleshooting<\/a><\/td><td>Exam name, RHEL version, duration, exact objectives, recommended preparation<\/td><\/tr><tr><td>RHCASA Enterprise Linux<\/td><td><a href=\"https:\/\/www.redhat.com\/en\/services\/certification\/rhcs-red-hat-enterprise-linux-diagnostics-and-troubleshooting\">https:\/\/www.redhat.com\/en\/services\/certification\/rhcs-red-hat-enterprise-linux-diagnostics-and-troubleshooting<\/a><\/td><td>Credential description and scope<\/td><\/tr><tr><td>RHCE Enterprise Linux<\/td><td><a href=\"https:\/\/www.redhat.com\/en\/services\/certification\/red-hat-certified-engineer-in-enterprise-linux\">https:\/\/www.redhat.com\/en\/services\/certification\/red-hat-certified-engineer-in-enterprise-linux<\/a><\/td><td>EX200 + EX342 Engineer relationship<\/td><\/tr><tr><td>Certification catalog<\/td><td><a href=\"https:\/\/www.redhat.com\/en\/services\/certifications\">https:\/\/www.redhat.com\/en\/services\/certifications<\/a><\/td><td>Current 2026 framework and requirements<\/td><\/tr><tr><td>Certification FAQ<\/td><td><a href=\"https:\/\/www.redhat.com\/en\/services\/training-and-certification\/faq\">https:\/\/www.redhat.com\/en\/services\/training-and-certification\/faq<\/a><\/td><td>May 2026 changes, renamed credentials, renewal rules<\/td><\/tr><tr><td>Certification Program Guide<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_learning_subscription\/1-latest\/html\/red_hat_certification_program_guide\/index<\/a><\/td><td>Pricing, format, exam policies, retake, persistence<\/td><\/tr><tr><td>RHEL 10 documentation<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10<\/a><\/td><td>Current product documentation index<\/td><\/tr><tr><td>System monitoring\/performance<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/monitoring_and_managing_system_status_and_performance\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/monitoring_and_managing_system_status_and_performance\/index<\/a><\/td><td>Monitoring, performance tools, memory diagnostics<\/td><\/tr><tr><td>RHEL web console<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/managing_systems_in_the_rhel_web_console\/getting-started-with-the-rhel-web-console\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/managing_systems_in_the_rhel_web_console\/getting-started-with-the-rhel-web-console<\/a><\/td><td>Cockpit install\/use\/monitoring<\/td><\/tr><tr><td>RHEL system roles\/Ansible<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/automating_system_administration_by_using_rhel_system_roles\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/automating_system_administration_by_using_rhel_system_roles\/index<\/a><\/td><td>Ansible control\/managed-node configuration<\/td><\/tr><tr><td>Remote\/centralized logging<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/risk_reduction_and_recovery_operations\/configuring-a-remote-logging-solution\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/risk_reduction_and_recovery_operations\/configuring-a-remote-logging-solution<\/a><\/td><td>rsyslog forwarding\/receiving<\/td><\/tr><tr><td>Security hardening\/AIDE<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/security_hardening\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/security_hardening\/index<\/a><\/td><td>AIDE installation, baseline, checks, updates<\/td><\/tr><tr><td>RHEL rescue mode<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/interactively_installing_rhel_from_installation_media\/troubleshooting-after-installation\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/interactively_installing_rhel_from_installation_media\/troubleshooting-after-installation<\/a><\/td><td>Boot-media rescue, chroot, sos in rescue<\/td><\/tr><tr><td>Kernel modules<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/managing_monitoring_and_updating_the_kernel\/managing-kernel-modules\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/managing_monitoring_and_updating_the_kernel\/managing-kernel-modules<\/a><\/td><td>lsmod\/modinfo\/modprobe\/persistent module config<\/td><\/tr><tr><td>Filesystem checking\/repair<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/managing_file_systems\/checking-and-repairing-a-file-system_\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/managing_file_systems\/checking-and-repairing-a-file-system_<\/a><\/td><td>XFS and filesystem repair guidance<\/td><\/tr><tr><td>LVM troubleshooting<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/configuring_and_managing_logical_volumes\/troubleshooting-lvm\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/configuring_and_managing_logical_volumes\/troubleshooting-lvm<\/a><\/td><td>LVM diagnostics and metadata restore<\/td><\/tr><tr><td>DNF software management<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/managing_software_with_the_dnf_tool\/managing_software_with_the_dnf_tool\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/managing_software_with_the_dnf_tool\/managing_software_with_the_dnf_tool<\/a><\/td><td>Repositories\/packages\/dependencies<\/td><\/tr><tr><td>RHEL networking<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/configuring_and_managing_networking\/index\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html-single\/configuring_and_managing_networking\/index<\/a><\/td><td>NetworkManager and network configuration\/troubleshooting<\/td><\/tr><tr><td>SELinux troubleshooting<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/using_selinux\/troubleshooting-problems-related-to-selinux\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/using_selinux\/troubleshooting-problems-related-to-selinux<\/a><\/td><td>AVC evidence and SELinux diagnosis<\/td><\/tr><tr><td>Authentication\/authselect<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/configuring_authentication_and_authorization_in_rhel\/configuring-user-authentication-using-authselect\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/configuring_authentication_and_authorization_in_rhel\/configuring-user-authentication-using-authselect<\/a><\/td><td>PAM\/NSS\/authselect behavior<\/td><\/tr><tr><td>Application debugging<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/developing_c_and_cpp_applications_in_rhel_10\/debugging-applications\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/developing_c_and_cpp_applications_in_rhel_10\/debugging-applications<\/a><\/td><td>strace\/ltrace\/core\/debug tooling<\/td><\/tr><tr><td>Kdump<\/td><td><a href=\"https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/managing_monitoring_and_updating_the_kernel\/supported-kdump-configurations-and-targets\">https:\/\/docs.redhat.com\/en\/documentation\/red_hat_enterprise_linux\/10\/html\/managing_monitoring_and_updating_the_kernel\/supported-kdump-configurations-and-targets<\/a><\/td><td>Crash dump configuration and targets<\/td><\/tr><tr><td>Developer Subscription<\/td><td><a href=\"https:\/\/developers.redhat.com\/articles\/faqs-no-cost-red-hat-enterprise-linux\">https:\/\/developers.redhat.com\/articles\/faqs-no-cost-red-hat-enterprise-linux<\/a><\/td><td>No-cost individual RHEL access<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 31 \u2014 Final Master Curriculum Matrix<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Module<\/th><th class=\"has-text-align-left\" data-align=\"left\">Official EX342 objective<\/th><th class=\"has-text-align-left\" data-align=\"left\">Knowledge<\/th><th class=\"has-text-align-left\" data-align=\"left\">Commands<\/th><th class=\"has-text-align-left\" data-align=\"left\">Configuration<\/th><th class=\"has-text-align-left\" data-align=\"left\">Lab<\/th><th class=\"has-text-align-left\" data-align=\"left\">Troubleshooting<\/th><th class=\"has-text-align-left\" data-align=\"left\">Exam practice<\/th><\/tr><\/thead><tbody><tr><td>1<\/td><td>Understand and employ general methods for troubleshooting<\/td><td>Consult documentation resources to aid in troubleshooting; Monitor systems for vital characteristics; Monitor systems with the RHEL Web console; Configure systems using Ansible; Configure systems to send log messages to a centralized host; Configure systems to monitor files and directories using AIDE<\/td><td>man, info, journalctl, dmesg, systemctl, ps\u2026<\/td><td>\/etc\/rsyslog.conf\u2026<\/td><td>4 required labs<\/td><td>Break rsyslog forwarding, corrupt an Ansible inventory entry, stop cockpit.socket, and change an AIDE-monitored file. Diagnose each from observable evidence.<\/td><td>A managed system is not forwarding logs, a required configuration differs from the desired Ansible state, and AIDE reports a file change. Restore and verify all three.<\/td><\/tr><tr><td>2<\/td><td>Diagnose and troubleshoot system startup issues<\/td><td>Identify and resolve service failures affecting boot; Regain root control of a system; Troubleshoot boot issues; Identify hardware and hardware problems; Manage kernel modules and their parameters<\/td><td>systemctl &#8211;failed, systemctl status, systemctl list-dependencies, journalctl -b, journalctl -b -1, dmesg\u2026<\/td><td>\/etc\/systemd\/system\/\u2026<\/td><td>4 required labs<\/td><td>Introduce an invalid persistent mount or failed required service; recover using console\/rescue access. Simulate a wrong kernel-module setting and confirm the effect after reboot.<\/td><td>A VM stops during startup because of a configuration fault. Regain administrative control, identify the failure from evidence, correct it, boot normally, and prove the fix survives another reboot.<\/td><\/tr><tr><td>3<\/td><td>Diagnose and troubleshoot file system issues<\/td><td>Recover corrupted file systems; Recover misconfigured or broken LVM configurations; Recover data from encrypted file systems<\/td><td>lsblk -f, blkid, findmnt, mount, umount, xfs_repair\u2026<\/td><td>\/etc\/fstab\u2026<\/td><td>4 required labs<\/td><td>Wrong UUID in fstab, missing PV metadata, inactive VG\/LV, damaged XFS metadata in a disposable filesystem, incorrect crypttab entry.<\/td><td>Restore three storage failures: a filesystem that will not mount, an LVM stack that is incomplete, and an encrypted volume whose data must remain intact.<\/td><\/tr><tr><td>4<\/td><td>Resolve package management issues<\/td><td>Resolve package management dependency issues; Recover a corrupted RPM database; Identify and report changed files<\/td><td>dnf repolist, dnf list, dnf info, dnf repoquery, dnf provides, dnf install\u2026<\/td><td>\/etc\/dnf\/dnf.conf\u2026<\/td><td>4 required labs<\/td><td>Disable a needed repository, create an impossible package dependency in a lab RPM scenario, change a package-owned file, and damage a disposable copy of the RPM database.<\/td><td>Restore package management to a working state and produce evidence identifying which package-owned files had changed.<\/td><\/tr><tr><td>5<\/td><td>Troubleshoot and fix network connectivity issues<\/td><td>Use standard tools to verify network connectivity; Identify and fix network connectivity issues; Inspect network traffic to aid troubleshooting<\/td><td>ip link, ip addr, ip route, ip neigh, nmcli, ping\u2026<\/td><td>\/etc\/NetworkManager\/system-connections\/*.nmconnection\u2026<\/td><td>4 required labs<\/td><td>Wrong IP\/prefix, missing route, incorrect DNS, stopped listener, firewall block, duplicate address, disabled NetworkManager profile.<\/td><td>A service is reachable from localhost but not from another VM. Identify the failing layer using standard tools and packet capture, fix it, and verify persistence.<\/td><\/tr><tr><td>6<\/td><td>Diagnose application issues<\/td><td>Identify library dependencies for third-party software; Identify if an application suffers from memory leaks; Use standard tools to debug an application; Identify and fix issues related to SELinux<\/td><td>ldd, readelf, objdump, file, strace, ltrace\u2026<\/td><td>\/etc\/ld.so.conf\u2026<\/td><td>4 required labs<\/td><td>Missing shared object, wrong library path, application permission failure, memory leak in a disposable test program, wrong SELinux label.<\/td><td>Diagnose why a third-party service fails after relocation to a nonstandard path, prove the root cause with tracing\/log evidence, and restore operation without disabling SELinux.<\/td><\/tr><tr><td>7<\/td><td>Identify and fix authentication issues<\/td><td>Identify and fix pluggable authentication module (PAM) issues; Identify and enforce local user account policies<\/td><td>authselect current, authselect check, authselect select, passwd, chage, faillock\u2026<\/td><td>\/etc\/pam.d\/*\u2026<\/td><td>4 required labs<\/td><td>Expired account, locked user, invalid PAM module reference in a disposable profile, inconsistent authselect state.<\/td><td>A valid local user cannot authenticate. Determine whether the cause is account policy, lockout, PAM stack, or identity lookup; fix only the actual cause and verify.<\/td><\/tr><tr><td>8<\/td><td>Gather information to aid third-party investigation of issues<\/td><td>Create kernel crash dumps; Collect system information to aid in troubleshooting<\/td><td>kdumpctl status, systemctl status kdump, journalctl -u kdump, sysctl, grubby, sos report\u2026<\/td><td>\/etc\/kdump.conf\u2026<\/td><td>4 required labs<\/td><td>kdump service not ready, invalid dump target in a disposable configuration, insufficient\/incorrect crash-kernel setup, sos unable to collect a chosen plugin due to missing package.<\/td><td>Prepare a failing host for escalation: verify crash-dump capability, gather a complete diagnostic archive, and document the minimum evidence needed to reproduce the incident.<\/td><\/tr><tr><td>9<\/td><td>All objectives<\/td><td>Cross-domain incident isolation<\/td><td>All as evidence requires<\/td><td>All relevant<\/td><td>Integrated multi-fault labs<\/td><td>Cross-layer root cause<\/td><td>Four-hour simulation<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Coverage audit<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[x]\u00a0<strong>1. Understand and employ general methods for troubleshooting<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Consult documentation resources to aid in troubleshooting<\/li>\n\n\n\n<li>[x] Monitor systems for vital characteristics<\/li>\n\n\n\n<li>[x] Monitor systems with the RHEL Web console<\/li>\n\n\n\n<li>[x] Configure systems using Ansible<\/li>\n\n\n\n<li>[x] Configure systems to send log messages to a centralized host<\/li>\n\n\n\n<li>[x] Configure systems to monitor files and directories using AIDE<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>[x]\u00a0<strong>2. Diagnose and troubleshoot system startup issues<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Identify and resolve service failures affecting boot<\/li>\n\n\n\n<li>[x] Regain root control of a system<\/li>\n\n\n\n<li>[x] Troubleshoot boot issues<\/li>\n\n\n\n<li>[x] Identify hardware and hardware problems<\/li>\n\n\n\n<li>[x] Manage kernel modules and their parameters<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>[x]\u00a0<strong>3. Diagnose and troubleshoot file system issues<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Recover corrupted file systems<\/li>\n\n\n\n<li>[x] Recover misconfigured or broken LVM configurations<\/li>\n\n\n\n<li>[x] Recover data from encrypted file systems<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>[x]\u00a0<strong>4. Resolve package management issues<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Resolve package management dependency issues<\/li>\n\n\n\n<li>[x] Recover a corrupted RPM database<\/li>\n\n\n\n<li>[x] Identify and report changed files<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>[x]\u00a0<strong>5. Troubleshoot and fix network connectivity issues<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Use standard tools to verify network connectivity<\/li>\n\n\n\n<li>[x] Identify and fix network connectivity issues<\/li>\n\n\n\n<li>[x] Inspect network traffic to aid troubleshooting<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>[x]\u00a0<strong>6. Diagnose application issues<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Identify library dependencies for third-party software<\/li>\n\n\n\n<li>[x] Identify if an application suffers from memory leaks<\/li>\n\n\n\n<li>[x] Use standard tools to debug an application<\/li>\n\n\n\n<li>[x] Identify and fix issues related to SELinux<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>[x]\u00a0<strong>7. Identify and fix authentication issues<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Identify and fix pluggable authentication module (PAM) issues<\/li>\n\n\n\n<li>[x] Identify and enforce local user account policies<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>[x]\u00a0<strong>8. Gather information to aid third-party investigation of issues<\/strong>\n<ul class=\"wp-block-list\">\n<li>[x] Create kernel crash dumps<\/li>\n\n\n\n<li>[x] Collect system information to aid in troubleshooting<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">PART 32 \u2014 Final Gold-Standard Fact Check<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Exam accuracy<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[x] EX342 currently exists<\/li>\n\n\n\n<li>[x] Exact current exam name verified<\/li>\n\n\n\n<li>[x] EX342 credential relationship verified<\/li>\n\n\n\n<li>[x] RHCE-Enterprise Linux EX200 + EX342 relationship verified<\/li>\n\n\n\n<li>[x] Current public objectives verified<\/li>\n\n\n\n<li>[x] Current public RHEL version verified as\u00a0<strong>RHEL 10.2<\/strong><\/li>\n\n\n\n<li>[x] Current time limit verified as\u00a0<strong>4 hours<\/strong><\/li>\n\n\n\n<li>[x] Performance-based format verified<\/li>\n\n\n\n<li>[x] Multiple-version\/LMS warning included<\/li>\n\n\n\n<li>[x] Recommended preparation distinguished from mandatory certification stacking<\/li>\n\n\n\n<li>[x] Current standard list price verified; regional\/Japan caveat included<\/li>\n\n\n\n<li>[x] Current free-retake policy verified<\/li>\n\n\n\n<li>[x] Three-year certification currency policy verified<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Curriculum accuracy<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[x] Every current public top-level EX342 objective covered<\/li>\n\n\n\n<li>[x] Every current public sub-objective mapped to labs<\/li>\n\n\n\n<li>[x] No historical RHCE objective inserted as a current EX342 requirement<\/li>\n\n\n\n<li>[x] Ansible included only because current EX342 explicitly lists it<\/li>\n\n\n\n<li>[x] SELinux\/PAM\/AIDE\/logging included because current EX342 explicitly lists them<\/li>\n\n\n\n<li>[x] OpenShift, Ceph, HA clustering, Satellite, deep performance tuning excluded as standalone EX342 requirements<\/li>\n\n\n\n<li>[x] Labs use original scenarios<\/li>\n\n\n\n<li>[x] Mock exams do not claim to reproduce Red Hat exam questions<\/li>\n\n\n\n<li>[x] Dangerous storage\/recovery exercises explicitly restricted to disposable\/snapshotted lab systems<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Integrity<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>[x] No confidential exam content<\/li>\n\n\n\n<li>[x] No leaked questions<\/li>\n\n\n\n<li>[x] No unpublished scoring algorithm claimed<\/li>\n\n\n\n<li>[x] No guarantee of passing<\/li>\n\n\n\n<li>[x] No Red Hat training course presented as mandatory<\/li>\n\n\n\n<li>[x] Official objectives remain the final authority<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Final Beginner \u2192 EX342 Ready Roadmap<\/h1>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-4\" data-shcb-language-name=\"PHP\" data-shcb-language-slug=\"php\"><span><code class=\"hljs language-php\">RHCSA-Level Administration Baseline\n            \u2193\nTroubleshooting Method + Evidence\n            \u2193\nMonitoring + Cockpit\n            \u2193\nAnsible + Central Logging + AIDE\n            \u2193\nBoot \/ Startup \/ Rescue\n            \u2193\nHardware + Kernel Modules\n            \u2193\nFilesystem + LVM + LUKS Recovery\n            \u2193\nDNF + RPM Database + File Verification\n            \u2193\nNetwork Troubleshooting + Packet Capture\n            \u2193\nApplication Dependencies + Memory + Tracing\n            \u2193\nSELinux\n            \u2193\nPAM + Local Account Policies\n            \u2193\nKdump + SOS \/ Support Evidence\n            \u2193\nIntegrated <span class=\"hljs-keyword\">Break<\/span>\/Fix Labs\n            \u2193\nTimed Original Practice Tasks\n            \u2193\nFive Mock Exams\n            \u2193\nTwo Clean <span class=\"hljs-number\">4<\/span>-Hour Simulations\n            \u2193\nEX342 READY\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-4\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">PHP<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">php<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<h2 class=\"wp-block-heading\">Final rule<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Do not memorize fixes. Learn to produce evidence, isolate the failing layer, make the smallest safe repair, and prove the final state.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That is the central skill pattern behind the current EX342 objective set.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Gold-Standard Self-Study Textbook + Laboratory Manual + Exam Preparation Roadmap Research cut-off:&nbsp;6 October 2026Primary authority:&nbsp;current Red Hat official EX342, certification, policy, and RHEL 10 documentationLearner model:&nbsp;100% home&#8230; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[11138],"tags":[],"class_list":["post-78875","post","type-post","status-publish","format-standard","hentry","category-best-tools"],"_links":{"self":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/comments?post=78875"}],"version-history":[{"count":1,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78875\/revisions"}],"predecessor-version":[{"id":78876,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78875\/revisions\/78876"}],"wp:attachment":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/media?parent=78875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/categories?post=78875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/tags?post=78875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}