LFCE: Linux engineering and recovery
Linux engineering with eight lessons, 50 questions, and eight cases on operations, identity, networking, services, storage, and recovery. Historical LFCE reference.
Objectives and progression
Eight lessons and 58 original decisions in fictional APS and IT-project contexts. Internal assessment of 32 decisions in 70 minutes. Guided coverage of seven historical domains; not a substitute for administration practice. PXE, package building, advanced PAM, and complete routing require later depth. LFCE exam retired 2022-05-01. This course uses historical V3.18 domains published for 2018-06-12 and technical documentation consulted 2026-09-30. It is not preparation for a current LFCE exam.
Audience: Linux administrators, APS L3 engineers, and technical infrastructure coordinators.
Prerequisites: Practice with Linux, shell, services, networking, and permissions. An isolated lab is recommended for recovery operations. No previous certification required.
445 estimated study minutes
- Control change scope and interpret simulation limits.
- Connect actual state, security controls, and recovery to verifiable evidence.
- Distinguish lookup, authentication, authorization, and session establishment.
- Follow routing and filtering with tests representing actual flows.
- Validate the selected service, authorization, and actual durability.
- Distinguish identity, capacity, presentation, and data access.
- Plan surviving capacity and promote identifiable artifacts.
- Make availability and integrity decisions with demonstrated recovery.
Modules
- Automate with evidence
- Operate and recover systems
- Identity, PAM, and SSH
- Networking, tunnels, and policies
- Services and operational contracts
- Storage across layers
- Capacity, packages, and containers
- HA, cutover, and RUN handover
Continue learning
- LFCS — Linux Foundation Certified System Administrator
- RHCSA — Red Hat Certified System Administrator
- Linux Administration
References and version
Historical LFCE V3.18 (2018-06-12); exam retired 2022-05-01; technical references inspected 2026-09-30
- LFCE exam retirement · 2026-09-30
- Historical LFCE V3.18 domains · 2026-09-30
- Revert shared changes · 2026-09-30
- Ansible execution strategies · 2026-09-30
- Ansible check-mode limits · 2026-09-30
- Ansible error handling · 2026-09-30
- Linux pressure stall information · 2026-09-30
- Linux IP forwarding controls · 2026-09-30
- nftables manual · 2026-09-30
- FRRouting BGP policies · 2026-09-30
- Apache 2.4 virtual hosts · 2026-09-30
- chronyc 4.6 monitoring · 2026-09-30
- rsyslog queue durability · 2026-09-30
- Kea DHCPv4 subnet selection · 2026-09-30
- Postfix authentication and relay configuration · 2026-09-30
- BIND zones and secondary transfers · 2026-09-30
- Squid HTTP access control · 2026-09-30
- Pacemaker 3 fencing · 2026-09-30
- Docker volume lifecycle · 2026-09-30
- Docker resource limits · 2026-09-30
- Immutable image digests · 2026-09-30
- RPM 6 package signature checks · 2026-09-30
- Production launch readiness · 2026-09-30
- Capacity and overload management · 2026-09-30
- Contingency planning and recovery exercises · 2026-09-30
- RHEL 9 SSSD offline authentication and access · 2026-09-30
- RHEL 9 iSCSI target ACLs · 2026-09-30
- Bash shell semantics · 2026-09-30
- systemd lifecycle · 2026-09-30
- Linux PAM stack controls · 2026-09-30
- OpenSSH server authentication · 2026-09-30
- OpenSSH forwarding · 2026-09-30
- NSS identity lookup · 2026-09-30
- LVM thin pool capacity · 2026-09-30
- SELinux context restoration · 2026-09-30
- SELinux persistent context mapping · 2026-09-30
- Dracut early boot · 2026-09-30
- udev device observation · 2026-09-30
- Block device attributes · 2026-09-30
- NFS export identity mapping · 2026-09-30
- Logical volume and filesystem extension · 2026-09-30
- Linux TCP and path MTU · 2026-09-30
- Linux route inspection · 2026-09-30
What you will explore
0 / 8Automate with evidence
Control change scope and interpret simulation limits.
Operate and recover systems
Connect actual state, security controls, and recovery to verifiable evidence.
Identity, PAM, and SSH
Distinguish lookup, authentication, authorization, and session establishment.
Networking, tunnels, and policies
Follow routing and filtering with tests representing actual flows.
Services and operational contracts
Validate the selected service, authorization, and actual durability.
Storage across layers
Distinguish identity, capacity, presentation, and data access.
Capacity, packages, and containers
Plan surviving capacity and promote identifiable artifacts.
HA, cutover, and RUN handover
Make availability and integrity decisions with demonstrated recovery.