RHCSA (Red Hat Certified System Administrator)
The Red Hat Certified System Administrator (RHCSA) certification is one of the most respected credentials in the Linux world. Unlike exams where you pick answers from a list, RHCSA is entirely performance-based β you sit in front of a live Red Hat Enterprise Linux system and complete real tasks within a time limit. If you can pass it, employers know you can actually do the work.
This guide walks through the exam objectives, key concepts you need to master, and practical exercises to build the skills that get tested.
Exam Details at a Glance
| Detail | Information |
|---|---|
| Exam Code | EX200 |
| Format | Performance-based (hands-on tasks on a live system) |
| Duration | 2.5 hours |
| Number of Tasks | Typically 10β15 tasks |
| Passing Score | 210 out of 300 (70%) |
| Cost | Approximately $500 USD |
| Prerequisites | None required, but RHCSA-level experience recommended |
| Validity | 3 years |
| Based On | Red Hat Enterprise Linux 9 (current version) |
Exam Objectives Overview
Red Hat publishes official exam objectives that change with each RHEL version. The following covers the major domains:
RHCSA Exam Domains
βββ Understand and Use Essential Tools
β βββ Access shell prompts and issue commands
β βββ Use input/output redirection
β βββ Use grep and regular expressions
β βββ Access remote systems using SSH
β βββ Log in and switch users
β βββ Archive, compress, unpack, and decompress files
β βββ Create and edit text files
β βββ Create, delete, copy, and move files and directories
β βββ Create hard and soft links
βββ Create Simple Shell Scripts
β βββ Conditionals (if/then, case)
β βββ Loops (for, while)
β βββ Process script inputs ($1, $2, etc.)
β βββ Process output of shell commands within a script
βββ Operate Running Systems
β βββ Boot, reboot, and shut down normally
β βββ Boot into different targets manually
β βββ Interrupt boot process to gain access (reset root password)
β βββ Identify CPU/memory-intensive processes and kill them
β βββ Adjust process scheduling
β βββ Manage tuning profiles
β βββ Locate and interpret system log files
β βββ Preserve system journals
βββ Configure Local Storage
β βββ List, create, delete partitions (MBR and GPT)
β βββ Create and remove physical volumes
β βββ Assign physical volumes to volume groups
β βββ Create and delete logical volumes
β βββ Configure systems to mount file systems at boot
β βββ Configure and manage swap space
β βββ Create and configure file systems (ext4, xfs)
β βββ Mount and unmount network file systems (NFS)
βββ Create and Configure File Systems
β βββ Create, mount, unmount, and use ext4 and xfs
β βββ Mount and unmount network file systems (NFS, CIFS)
β βββ Configure autofs
β βββ Extend existing logical volumes
β βββ Create and configure set-GID directories
βββ Deploy, Configure, and Maintain Systems
β βββ Schedule tasks using cron and at
β βββ Start and stop services, configure services to start at boot
β βββ Configure systems to boot into a specific target
β βββ Install and update software packages
β βββ Modify the system bootloader
β βββ Configure time service clients
βββ Manage Basic Networking
β βββ Configure IPv4 and IPv6 addresses
β βββ Configure hostname resolution
β βββ Configure network services to start at boot
β βββ Restrict network access using firewalld
βββ Manage Users and Groups
β βββ Create, delete, and modify local user accounts
β βββ Change passwords and adjust password aging
β βββ Create, delete, and modify local groups
β βββ Configure superuser access
β βββ Configure key-based authentication for SSH
βββ Manage Security
β βββ Configure firewall settings using firewalld
β βββ Manage default file permissions
β βββ Configure SELinux modes (enforcing, permissive, disabled)
β βββ List and identify SELinux file and process contexts
β βββ Restore default file contexts
β βββ Manage SELinux port labels
β βββ Use boolean settings to modify SELinux policy
β βββ Diagnose and address routine SELinux policy violations
βββ Manage Containers
βββ Find and retrieve container images
βββ Inspect container images
βββ Perform container management (run, start, stop, list, inspect, remove)
βββ Run a service inside a container
βββ Configure a container to start automatically as a systemd service
βββ Attach persistent storage to a container
Essential Tools
This section covers the foundational commands and techniques you need. Everything else builds on these skills.
Working with Files and Directories
You should be able to perform these operations without hesitation:
# Create a directory structure
mkdir -p /home/user/project/{docs,src,bin}
# Copy files preserving permissions and ownership
cp -a /source/dir /destination/
# Create hard and soft links
ln /path/to/original /path/to/hardlink
ln -s /path/to/original /path/to/symlink
# Find files by various criteria
find / -name "*.conf" -type f 2>/dev/null
find /home -user student -size +1M
find /var -mtime -7 -name "*.log"
Input/Output Redirection and Pipes
Redirection shows up in nearly every exam task, even when it's not the main objective:
# Redirect stdout and stderr separately
command > output.txt 2> errors.txt
# Redirect both to the same file
command &> all_output.txt
# Append instead of overwrite
command >> output.txt 2>&1
# Use pipes to chain commands
ps aux | grep httpd | grep -v grep
cat /etc/passwd | cut -d: -f1 | sort
Using grep and Regular Expressions
# Search for a pattern in files
grep "failed" /var/log/secure
# Case-insensitive search
grep -i "error" /var/log/messages
# Show line numbers
grep -n "root" /etc/passwd
# Use extended regular expressions
grep -E "^(root|admin)" /etc/passwd
# Recursive search through directories
grep -r "ServerName" /etc/httpd/
Archiving and Compression
# Create a compressed tar archive
tar czf archive.tar.gz /path/to/directory
# Extract a tar archive
tar xzf archive.tar.gz
# List contents without extracting
tar tzf archive.tar.gz
# Create with bzip2 compression
tar cjf archive.tar.bz2 /path/to/directory
# Extract to a specific directory
tar xzf archive.tar.gz -C /target/directory
Operating Running Systems
Changing Boot Targets
The exam often asks you to configure the system to boot into a specific target:
# Check current default target
systemctl get-default
# Set default target to multi-user (no GUI)
systemctl set-default multi-user.target
# Set default target to graphical
systemctl set-default graphical.target
# Switch to a different target immediately
systemctl isolate rescue.target
Resetting the Root Password
This is a classic RHCSA task. You need to know the exact steps because you won't have internet access during the exam:
Step-by-step root password reset:
1. Reboot the system
2. At the GRUB menu, press 'e' to edit the boot entry
3. Find the line starting with 'linux'
4. Append: rd.break
5. Press Ctrl+X to boot
6. At the switch_root prompt:
mount -o remount,rw /sysroot
chroot /sysroot
passwd root
touch /.autorelabel
exit
exit
7. System reboots with new root password
The touch /.autorelabel step is critical when SELinux is enforcing β without it, the password change won't stick because the SELinux context on /etc/shadow will be wrong.
Managing Processes
# Find processes consuming the most CPU
top -bn1 | head -20
# Kill a process by PID
kill -9 <PID>
# Find and kill a process by name (find PID first)
ps aux | grep "process_name"
kill <PID>
# Change process priority
nice -n 10 command
renice -n 5 -p <PID>
Configuring Local Storage
Partitioning with fdisk and gdisk
# List existing partitions
lsblk
fdisk -l
# Create a new partition (interactive)
fdisk /dev/sdb
# n (new), p (primary), accept defaults or set size, w (write)
# For GPT partitions
gdisk /dev/sdb
LVM (Logical Volume Management)
LVM tasks appear on almost every RHCSA exam. Know these commands cold:
# Create a physical volume
pvcreate /dev/sdb1
# Create a volume group
vgcreate myvg /dev/sdb1
# Create a logical volume (500MB)
lvcreate -L 500M -n mylv myvg
# Format the logical volume
mkfs.xfs /dev/myvg/mylv
# Mount it
mkdir /mnt/mydata
mount /dev/myvg/mylv /mnt/mydata
# Make it persistent in /etc/fstab
echo "/dev/myvg/mylv /mnt/mydata xfs defaults 0 0" >> /etc/fstab
# Extend a logical volume and resize the filesystem
lvextend -L +200M /dev/myvg/mylv
xfs_growfs /mnt/mydata # for xfs
# or
resize2fs /dev/myvg/mylv # for ext4
Swap Space
# Create a swap partition or file
dd if=/dev/zero of=/swapfile bs=1M count=512
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile
# Make persistent
echo "/swapfile swap swap defaults 0 0" >> /etc/fstab
# Verify
swapon --show
free -h
Managing Users and Groups
# Create a user with specific UID and home directory
useradd -u 1500 -d /home/jsmith -s /bin/bash jsmith
# Set password
passwd jsmith
# Create a group
groupadd developers
# Add user to supplementary group
usermod -aG developers jsmith
# Configure password aging
chage -M 90 -W 7 -I 14 jsmith
# View password aging info
chage -l jsmith
# Configure sudo access
visudo
# Add: jsmith ALL=(ALL) NOPASSWD: ALL
Managing Security
SELinux
SELinux questions are guaranteed on the RHCSA. Many candidates fail because they don't practice this enough:
# Check current SELinux mode
getenforce
sestatus
# Set SELinux to enforcing
setenforce 1
# Make permanent (survives reboot)
# Edit /etc/selinux/config and set SELINUX=enforcing
# View file contexts
ls -Z /var/www/html/
# Restore default context
restorecon -Rv /var/www/html/
# Change file context
semanage fcontext -a -t httpd_sys_content_t "/custom/path(/.*)?"
restorecon -Rv /custom/path
# Manage SELinux ports
semanage port -a -t http_port_t -p tcp 8888
semanage port -l | grep http
# Toggle SELinux booleans
getsebool -a | grep httpd
setsebool -P httpd_enable_homedirs on
# Troubleshoot SELinux denials
ausearch -m AVC -ts recent
sealert -a /var/log/audit/audit.log
Firewall Configuration
# Check firewall status
firewall-cmd --state
# List current rules
firewall-cmd --list-all
# Add a service permanently
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
# Add a specific port
firewall-cmd --permanent --add-port=8080/tcp
# Reload to apply changes
firewall-cmd --reload
# Verify changes
firewall-cmd --list-all
Networking
# View current network configuration
ip addr show
ip route show
# Configure a static IP using nmcli
nmcli con mod "System eth0" ipv4.addresses 192.168.1.100/24
nmcli con mod "System eth0" ipv4.gateway 192.168.1.1
nmcli con mod "System eth0" ipv4.dns "8.8.8.8 8.8.4.4"
nmcli con mod "System eth0" ipv4.method manual
nmcli con up "System eth0"
# Configure hostname
hostnamectl set-hostname server1.example.com
# Configure hostname resolution
# Edit /etc/hosts for local resolution
echo "192.168.1.50 server2.example.com server2" >> /etc/hosts
Scheduling Tasks
# Create a cron job for user
crontab -e
# Add: 0 2 * * * /usr/local/bin/backup.sh
# Create a cron job that runs every 15 minutes
# */15 * * * * /path/to/script.sh
# Schedule a one-time task with at
at 3:00 PM
# at> /usr/local/bin/maintenance.sh
# at> Ctrl+D
# Manage systemd timers (modern alternative)
systemctl list-timers
Managing Containers
Container management is a newer addition to the RHCSA objectives (RHEL 9):
# Log in to a container registry
podman login registry.redhat.io
# Search for images
podman search httpd
# Pull an image
podman pull registry.redhat.io/rhel9/httpd-24
# Run a container
podman run -d --name myweb -p 8080:8080 registry.redhat.io/rhel9/httpd-24
# List running containers
podman ps
# Inspect a container
podman inspect myweb
# Create a systemd service for a container (rootless)
mkdir -p ~/.config/systemd/user/
cd ~/.config/systemd/user/
podman generate systemd --name myweb --files --new
systemctl --user daemon-reload
systemctl --user enable container-myweb.service
systemctl --user start container-myweb.service
# Attach persistent storage
podman run -d --name myweb -v /host/data:/var/www/html:Z registry.redhat.io/rhel9/httpd-24
The :Z flag at the end of the volume mount tells podman to apply the correct SELinux context to the mounted directory. Forgetting this is a common mistake when SELinux is in enforcing mode.
Practice Makes Perfect
Start Here (Beginner)
Set up your lab:
- Install Rocky Linux or AlmaLinux in a virtual machine (these are free RHEL-compatible distributions that closely match the exam environment; avoid CentOS Stream as it's a rolling release that may differ from stable RHEL)
- Give it two virtual disks (one for the OS, one for practice partitioning)
- Allocate at least 2GB RAM
Master the basics:
- Create users, groups, and set passwords without looking at notes
- Practice file operations (copy, move, link, find) until they're automatic
- Set up SSH key-based authentication between two VMs
Next Level (Intermediate)
Storage tasks:
- Create partitions, physical volumes, volume groups, and logical volumes
- Extend logical volumes and resize filesystems
- Configure
/etc/fstabentries and verify withmount -a - Set up swap space using both partitions and files
Service management:
- Install and configure Apache (
httpd) - Configure it to start at boot with
systemctl enable - Open the correct firewall ports
- Fix SELinux contexts for custom document roots
Advanced Challenges
Full scenario practice:
- Reset the root password using the
rd.breakmethod - Configure a container to run as a systemd service
- Set up autofs for NFS mounts
- Configure network interfaces using
nmcli
Timed practice exam:
- Set a 2.5-hour timer
- Work through all the tasks you can create from the exam objectives
- Use only
manpages and--helpfor reference - Reboot your VM at the end to verify persistence
Click for hints and tips
Critical things that must survive a reboot:
/etc/fstabentries (usemount -ato test before rebooting)- Firewall rules (always use
--permanentflag then--reload) - SELinux settings (use
-Pflag withsetsebool) - Systemd service enablement (
systemctl enable) - Network configuration changes made persistent via
nmcli
Time management during the exam:
- Quickly read through all tasks first
- Do easy tasks first to bank points
- Don't spend more than 15 minutes on any single task
- If stuck, move on and come back later
- Save 10 minutes at the end to verify persistence
Common pitfalls:
- Forgetting
restoreconafter changing SELinux file contexts - Using
firewall-cmdwithout--permanent - Not testing
/etc/fstabwithmount -abefore rebooting - Missing the
:Zflag on container volume mounts with SELinux - Not running
systemctl daemon-reloadafter modifying unit files
What's Next?
After passing the RHCSA, consider these paths:
- RHCE Preparation β Focuses on Ansible automation and advanced system administration
- Linux Certification Overview β Compare other certification options
- LFCS Certification Guide β See how the Linux Foundation certification compares
Helpful Resources
Official Red Hat Resources
- RHCSA Exam Page (EX200) β Official exam details and registration
- RHCSA Exam Objectives β Current exam objectives
- Red Hat Training β Official courses (RH124, RH134)
Related Notes in This Repository
- SELinux β Deep dive into SELinux configuration and troubleshooting
- Logical Volume Management β Comprehensive LVM guide
- Managing Users β User and group administration
- Firewall β Firewall configuration with firewalld
- Services β Systemd service management
- Networking β Network configuration fundamentals
Ready to start studying? Set up your practice lab first, then work through each exam objective systematically. The Linux Certification Overview can help you confirm that RHCSA is the right choice for your career goals.
Challenges
- Set up a practice lab by installing a Red Hat-based distribution (such as CentOS Stream, Rocky Linux, or AlmaLinux) in a virtual machine. Create a non-root user account, configure sudo access, and verify that you can perform administrative tasks. Explain why using a Red Hat-compatible distribution is essential for RHCSA exam preparation.
- Practice managing file permissions and ownership by creating a shared directory for a group of users. Set appropriate permissions using
chmod,chown, andchgrp, and configure the setgid bit so that new files inherit the group ownership. Verify the configuration by creating files as different users. - Configure SELinux on your practice system by switching between enforcing, permissive, and disabled modes. Change the SELinux context of a file or directory, troubleshoot an SELinux denial using
ausearchandsetsebool, and explain why SELinux is a critical component of the RHCSA exam. - Create and manage LVM storage by setting up physical volumes, a volume group, and logical volumes. Practice extending a logical volume while the filesystem is mounted, and create a snapshot of a logical volume. Explain the advantages of LVM over traditional partitioning for system administrators.
- Configure a network connection using
nmcliornmtuiby setting a static IP address, gateway, and DNS server. Verify connectivity and test hostname resolution. Troubleshoot a simulated network misconfiguration and document the commands you used to resolve the issue. - Manage systemd services by enabling, starting, stopping, and masking services. Create a custom systemd service unit that executes a script at boot, and configure it to restart automatically on failure. Explain the differences between
enable,start,mask, anddisablein the context of systemd. - Schedule tasks using both
cronandat. Create a cron job that performs a daily backup of a directory and anatjob that runs a one-time maintenance script at a specified time. Verify that both tasks execute as expected and explain when each scheduling method is most appropriate. - Configure the firewall using
firewalldby creating a custom zone, adding services and ports, and setting up rich rules to restrict access from specific IP ranges. Make the rules persistent, reload the firewall, and verify the configuration. Discuss how firewalld zones provide flexible network security management. - Set up autofs to automatically mount an NFS share or a local filesystem when a user accesses a specific directory. Configure the auto.master and auto.misc files, test the automount behavior, and explain the advantages of autofs over static mounts in
/etc/fstab. - Simulate an RHCSA exam scenario by completing a multi-objective task under a time limit. For example, configure a web server, create user accounts with specific group memberships and password policies, set up LVM storage, configure firewall rules, and ensure SELinux is enforcing. Review your work against the RHCSA exam objectives and identify areas where you need further practice.