Linux Foundation Certified System Administrator (LFCS)
A performance-based Linux administration certification taken entirely from the command line, covering deployment, networking, storage, essential commands and user management on a live system.
- src
- The Linux Foundation — LFCS certification page, exam-only option (training.linuxfoundation.org)
- chk
The LFCS is the certification that answers "can this person actually run a Linux box?" — and it answers it the only way that means anything, by putting you at a command line on a live system for two hours and asking you to fix things.
What the weights tell you to study
Operations Deployment and Networking are 25% each: half the exam sits in services, packages, containers, SELinux, firewalls and SSH. Storage and Essential Commands take 20% each, and Users and Groups only 10%.
That last number is the useful one. User and group administration is what most Linux courses teach first and dwell on longest, and it is worth a tenth of this exam. The marks are in the operational half — the parts a course covers in one late chapter and a job exercises daily.
The 2023 revision also made the exam distribution-agnostic: you no longer pick a platform when you register. Practise the portable way of doing something, not the Ubuntu way, and know where a distribution actually diverges — package manager, firewall front-end, whether SELinux or AppArmor is in charge.
What the exam is actually like
Two hours, and the machine's own documentation. No browser, no search engine — man and --help are the reference. Finding a flag quickly in a man page is a skill worth practising deliberately, because it is the one you will lean on when a task uses an option you have never needed.
Nothing is multiple choice. A task is right or it is not, and it is graded on the state of the system afterwards. A configuration change that works but does not survive a reboot has not been made — "persistent and non-persistent" appears in the competency list for a reason.
The pass mark is 67%, so a third of the exam can go wrong. That makes triage a legitimate strategy: bank every task you can do cleanly before spending fifteen minutes on the one that is fighting you.
Where the marks are lost
Persistence, and reading the task. Kernel parameters set with sysctl and not written to a config file, a mount that works now and vanishes on reboot, an fstab line with a typo that would leave the machine unbootable — all of these are common, all of them are silent, and all are the difference between a task that scores and one that does not. Verify by re-reading the config file you wrote, not by observing that the command you just ran worked.
Before you book
The fee includes one free retake and the certification is valid for two years. That makes an early, slightly under-prepared attempt a cheap way to find out which of the five domains needs real work — and given the pass mark, a first sitting is often closer than it feels.
New to Linux and the command line?
This path assumes fundamentals you may not have yet. Our Foundations Pack is out and free — Linux, the shell and Git, with exercises that mark your work and explain why you got it wrong. We're writing an agents pack next; leave your email if you want to hear when it ships.
One email when the pack launches. No spam, unsubscribe any time.
Exam domains
Operations Deployment
25%Networking
25%Storage
20%Essential Commands
20%Users and Groups
10%Preparation path
- 1
Get a throwaway VM you are willing to destroy
Two VMs, not a container: half the exam is kernel parameters, LVM, swap and networking, none of which behave normally inside a container. Snapshot the fresh install so you can break it repeatedly and roll back in seconds instead of reinstalling.
~4 hours - 2
Learn to read man pages under time pressure
The exam gives you the system's own documentation and nothing else. Practise finding a flag in man and --help rather than recalling it, because that is the skill the format actually tests, and it is the difference between a two-minute task and a ten-minute one.
~6 hours - 3
Work Operations Deployment and Networking first
They are 50% of the score between them and the two you cannot cram — systemd unit files, package repositories, nftables rules and SELinux contexts all need repetition. Curriculum order buries networking near the end; weight order does not.
~40 hours - 4
Drill LVM and filesystems until the sequence is automatic
Storage is 20% and almost entirely procedural: pvcreate, vgcreate, lvcreate, mkfs, a correct fstab entry, mount. It is the domain where a prepared candidate reliably banks full marks, and where a hesitant one burns the time the rest of the exam needs.
~12 hours - 5
Break the machine on purpose, then fix it
Corrupt fstab so it will not boot. Fill the disk. Stop a service another one depends on. Recovering from a failure you caused teaches the symptom-to-cause mapping far faster than reading, and 'recover from filesystem failures' is a named competency.
~10 hours - 6
Sit a timed two-hour run before you book
Write yourself fifteen tasks across all five domains, set a timer and allow only the system's own documentation. The result tells you whether you are short on knowledge or short on speed, and those two problems have completely different fixes.
~6 hours
Frequently asked questions
Career Roadmaps
- Site Reliability Engineer RoadmapA path from DevOps fundamentals into the specialized discipline of site reliability engineering, covering SLOs, observability, incident response, data reliability, and capacity planning.
- DevOps Engineer RoadmapA structured path from Linux fundamentals through cloud infrastructure, automation, containers, and monitoring to a production-ready DevOps engineering career.
- Platform Engineer RoadmapThe path DevOps engineers move into — building an internal developer platform as a product, covering Kubernetes as substrate, IaC at scale, GitOps, golden paths, portals, policy, multi-tenancy and adoption.
- Database Reliability Engineer RoadmapA path into database reliability engineering — replication and consistency, restores you have actually verified, zero-downtime schema migrations, corruption detection, databases on Kubernetes, and RTO and RPO as a contract.