You have covered the filesystem, permissions, processes, text tools, scripting, services, networking, security and a full deployment. This final chapter compresses all of it into a reference you can scan in a minute, then works through the questions that come up in Linux, DevOps and backend interviews — with answers that show understanding rather than memorised commands. Use the cheat sheet daily until you no longer need it, and use the questions to find the chapters worth rereading.
| Task | Command |
|---|---|
| Where am I / go home / go back | pwd, cd, cd - |
| List with details, hidden, sorted by time | ls -la, ls -lt, ls -lhS |
| Create / copy / move / delete | mkdir -p, cp -r, mv, rm -ri |
| Symbolic link | ln -s target name |
| View / page / first / last / follow | cat, less, head -n, tail -n, tail -f |
| Find by name, type, size, age | find . -name "*.log" -type f -size +10M -mtime +7 |
| Disk usage / free space / mounts | du -sh dir, df -h, lsblk -f |
| Archive / extract | tar czf a.tgz dir, tar xzf a.tgz -C dest |
| Permissions / owner / defaults | chmod 640 f, chown u:g f, umask |
| Task | Command |
|---|---|
| Search / recursive / count / context | grep -n, grep -rn, grep -c, grep -C3 |
| Extended regex / only the match | grep -E, grep -oE 'pattern' |
| Replace in place with backup | sed -i.bak 's/old/new/g' file |
| Print column / sum column | awk '{print $2}', awk '{s+=$3} END{print s}' |
| Field by delimiter | cut -d, -f2 |
| Sort numeric / unique / frequency | sort -n, sort -u, sort \| uniq -c \| sort -rn |
| Redirect out / err / both / append | > f, 2> f, &> f, >> f |
| Pipe / tee / arguments from input | a \| b, a \| tee log, find ... -print0 \| xargs -0 cmd |
| Command output as text / as file | $(cmd), <(cmd) |
| Task | Command |
|---|---|
| List / tree / live | ps aux, pstree -p, htop |
| Stop gracefully / force / by name | kill PID, kill -9 PID, pkill name |
| Background / jobs / survive logout | cmd &, jobs, fg, nohup cmd &, tmux |
| Service control | systemctl start\|stop\|restart\|enable\|status name |
| Service logs / follow / errors today | journalctl -u name, -f, -p err --since today |
| Load / memory / disk I/O | uptime, free -h, iostat -xz 1 |
| Schedule | crontab -e (m h dom mon dow cmd), systemctl list-timers |
| Task | Command |
|---|---|
| Addresses / routes / DNS | ip -br addr, ip route, dig +short host |
| Listening ports / connections | sudo ss -tulpn, ss -tn state established |
| Reachability / path / port | ping -c4, traceroute, nc -zv host 443 |
| HTTP request / headers / JSON POST | curl -s url, curl -I url, curl -X POST -H 'Content-Type: application/json' -d '{}' url |
| Remote shell / copy / sync | ssh host, scp f host:path, rsync -avz src/ host:dest/ |
| Keys / install / tunnel | ssh-keygen -t ed25519, ssh-copy-id host, ssh -L 5433:localhost:5432 host |
| Firewall / bans | ufw allow 443/tcp, ufw status, fail2ban-client status sshd |
#!/usr/bin/env bash
set -Eeuo pipefail
trap 'echo "error at line $LINENO" >&2' ERR
usage() { echo "usage: $0 [-v] <file>" >&2; exit 64; }
verbose=0
while getopts ":v" o; do case "$o" in v) verbose=1 ;; *) usage ;; esac; done
shift $((OPTIND - 1))
file="${1:?missing file}"
[[ -r "$file" ]] || { echo "cannot read $file" >&2; exit 66; }
while IFS= read -r line; do
(( verbose )) && echo "processing: $line"
done < "$file"What happens when you type ls -l /tmp and press Enter? The shell parses the line into a command and arguments, checks aliases and builtins, searches each directory in PATH for an executable named ls, forks a child process, executes the binary with the arguments and its stdout connected to the terminal, waits for it to exit and stores the exit status in $?.
kill versus kill -9? kill sends SIGTERM, which the process can catch to shut down cleanly. kill -9 sends SIGKILL, which the kernel enforces immediately with no chance to clean up. Use -9 only when TERM is ignored.
The disk is full but du cannot find the space. Why? A process still holds a deleted file open, so its blocks are not released. Find it, then restart the process (or truncate the file next time instead of deleting it). Also rule out inode exhaustion.
sudo lsof +L1 | head # open files with zero links
df -i / # inode usageHow do you find which process is using port 8080? Ask the socket table; the output includes the PID and program name.
sudo ss -tulpn | grep :8080What is the difference between > and >>, and how do you capture stderr? > truncates and writes, >> appends. 2> redirects stderr, and 2>&1 duplicates it onto stdout — order matters, so cmd > f 2>&1 sends both to the file. &> is the bash shorthand.
What is the load average? The average number of runnable or uninterruptibly waiting processes over 1, 5 and 15 minutes. Interpret it relative to the core count: 4.0 on four cores is fully busy; on one core it is heavily overloaded.
Which command reveals space held by files that were deleted while still open?
ls, find, du/df, tar, chmod/chown; text: grep -E, sed -i, awk, sort | uniq -c; pipes and redirection tie them together.ps/htop, signals, nohup/tmux, systemd units and journalctl; schedule with cron or timers.ip, ss -tulpn, dig, curl, ssh/rsync; secure with keys, ufw, fail2ban and updates.[[ ]]/(( )), while read -r, functions with exit codes, shellcheck.Next lesson: What to learn next — continue with the Docker course to package the applications you can now deploy, the Cyber Security course to deepen the hardening chapter, and revisit any chapter here whose commands you cannot yet write from memory.