🧪 Lab 13 – Finding Linux Commands with Built-in Help
Lab Objective
Practice using the Linux command line to discover command purposes and options before making a system change:
- get a short command description with
whatis - inspect detailed options with
man - search manuals by task keywords with
apropos - identify safer differences between similar commands
- find the option needed for a temporary user account
Lab Environment
- Course: Google Cybersecurity Certificate
- Module: Tools of the Trade: Linux and SQL
- Activity: Get help in the command line
- Shell: Linux Bash
- Permissions: standard user; no privileged changes required
- Boundary: this lab discovers command behavior only and does not create, delete, or modify system objects
Scenario
You need to inspect files, manage temporary accounts, remove directories, and create a group, but you do not remember every command or option. Rather than guessing, use Linux’s local documentation to find an answer before running an administrative action.
Commands Practiced
| Command | Purpose |
|---|---|
whatis <command> |
Show a concise command description |
man <command> |
Open the full manual page and option reference |
apropos <keywords> |
Search manual-page descriptions by task keywords |
apropos -a <keywords> |
Require all supplied keywords to match |
q |
Exit the manual-page viewer |
Step 1 - Get a Quick Description
When I needed a short reminder of what cat does, I used:
whatis cat
The description begins with “concatenate files.” This is useful for quick orientation, but it does not replace reading the available options when an action depends on one.
Step 2 - Read the Manual Page for an Option
To inspect cat in more detail:
man cat
The manual documents -n / --number, which numbers all output lines. Use Enter for one more line, Space for the next page, and q to exit.
The same approach identifies the expiration-date option for a temporary account:
man useradd
The relevant option is -e, used to set an account expiration date. Looking this up before creating an account helps avoid leaving a temporary identity active by accident.
Step 3 - Search When the Command Name Is Unknown
When I knew the task but not the command name, I used keyword searches:
apropos -a "first part file"
apropos -a "create new group"
The first search identifies head for returning the first part of a file. The second identifies groupadd for creating a new group.
The -a option narrows results to manual entries that match all specified words. If a search is too narrow, revise the terms instead of assuming there is no suitable command.
Step 4 - Compare Similar Commands Before Use
To distinguish rm from rmdir quickly:
whatis rm
whatis rmdir
rmdir removes only empty directories. That detail matters: understanding the boundary of a command is safer than learning it after an unwanted change.
Step 5 - Use the Help Loop Before an Administrative Change
For an unfamiliar task, use this sequence:
Describe the task
↓
Search with apropos if the command name is unknown
↓
Use whatis for a quick reminder
↓
Read man page options and examples
↓
Check the target, then run the command deliberately
This creates a repeatable pause between uncertainty and action.
Security Takeaways
- Documentation is an operational control. Correct command knowledge reduces avoidable configuration and deletion mistakes.
- Current-system help is useful evidence. A local manual page describes the command available in the environment being used.
- Options change impact. A command name alone is not enough to assess risk; flags can expand or restrict its behavior.
- Keyword search is a recovery skill.
aproposhelps when the task is known but the command name is not. - Pause before privileged work. A short documentation check is cheaper than reversing an unsafe administrative action.
