CompTIA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
20% of exam · 6 sample questions below
A Linux administrator needs to ensure that a new service, myapp.service, starts automatically at boot and is currently running. The administrator runs 'systemctl enable --now myapp.service' and receives no errors, but after a reboot the service is not running. Which of the following is the most likely cause?
The systemctl daemon-reload command was not run after creating the unit file.
The service is masked by another unit with the same name in /etc/systemd/system.
The service was started with systemctl start instead of systemctl enable --now.
The service unit file is missing the [Install] section with WantedBy=multi-user.target.
Without an [Install] section specifying WantedBy, systemctl enable --now creates no symlink in the target's .wants directory. The service starts now but will not start at boot because systemd has no dependency link to multi-user.target, so the enable action is effectively a no-op for boot.
A Linux administrator is troubleshooting a service that fails to start. The service unit file contains 'User=appuser' and 'Group=appgroup'. The administrator runs 'systemctl start app.service' and sees the error 'Failed to determine user credentials: No such process'. Which of the following is the most likely cause?
The user appuser does not exist on the system.
The error 'Failed to determine user credentials: No such process' occurs when systemd cannot resolve the User= or Group= specified in the unit. If appuser is absent from /etc/passwd and the NSS databases, systemd cannot switch to that UID, so the service fails to start. Creating the user or correcting the unit resolves it.
The service unit file has a syntax error in the [Service] section.
The service binary does not have the execute permission for appuser.
The appgroup group exists but appuser is not a member of it.
A Linux administrator needs to configure a system so that the service `httpd` starts automatically when the system boots into the default target. Which command should the administrator use?
systemctl daemon-reload
systemctl enable httpd
The `systemctl enable httpd` command creates the necessary symbolic links in the systemd configuration directories to ensure the httpd service is started automatically when the system reaches the default target during boot. This is the standard method for enabling a service to start at boot on modern Linux distributions using systemd.
systemctl start httpd
chkconfig httpd on
A Linux administrator needs to ensure that a new service, `myapp.service`, starts automatically at boot and is also started immediately, without rebooting. The service unit file is already installed in `/etc/systemd/system/`. Which sequence of commands should the administrator run?
systemctl start myapp.service && systemctl enable myapp.service
systemctl link /etc/systemd/system/myapp.service && systemctl start myapp.service
systemctl daemon-reload && systemctl enable myapp.service
systemctl enable --now myapp.service
This command both enables the unit to start at boot and starts it immediately. The `--now` flag combines `enable` and `start`, which is exactly what the administrator needs without rebooting. It is the most efficient and correct way to satisfy both requirements in a single command.
A user reports that they cannot run the command `sudo` to perform administrative tasks. The administrator checks and finds that the user is not listed in the `/etc/sudoers` file. Which command should the administrator use to safely edit the sudoers file and add the user?
echo 'username ALL=(ALL) ALL' >> /etc/sudoers
visudo
`visudo` is the recommended tool for editing the `/etc/sudoers` file because it locks the file to prevent concurrent edits and performs syntax checking before saving. This reduces the risk of introducing errors that could lock out sudo access. It is the safe and standard method for modifying sudoers.
usermod -aG sudo username
nano /etc/sudoers
A Linux administrator needs to grant the user 'alice' the ability to run all commands as root without being prompted for a password, but only from the host 'server1'. Which entry in /etc/sudoers accomplishes this?
alice server1=(root) NOPASSWD: /bin/bash
alice server1=(ALL) NOPASSWD: ALL
This sudoers entry allows alice to run any command as any user on the host server1 without a password. The host specification 'server1' restricts the rule to that host, and NOPASSWD: ALL removes the password prompt for all commands.
alice ALL=(server1) NOPASSWD: ALL
alice ALL=(ALL) NOPASSWD: server1
Want more Services and User Management practice?
Practice this domain17% of exam · 6 sample questions below
A Linux administrator wants to ensure a bash script stops execution immediately if any command fails. Which line should be added to the script?
set -x
set -u
set -e
`set -e` makes bash exit immediately when any command returns a non-zero status, satisfying the requirement that the script halt on first failure. Unlike `set -u` (unset variables) or `set -x` (trace output), it targets command failure directly, preventing subsequent commands from running after an error.
set -o pipefail
A developer is writing a Dockerfile. The application requires a configuration file that should be copied from the build context and the container should expose port 8080. Which combination of Dockerfile instructions is correct?
COPY config.txt /app/ and EXPOSE 8080
COPY transfers config.txt from the build context into the image at /app/, satisfying the file requirement, while EXPOSE 8080 documents the port the container listens on at runtime. Both instructions match the stem's constraints precisely, unlike ADD, which also handles remote URLs and archives unnecessarily here.
ADD config.txt /app/ and WORKDIR 8080
ADD config.txt /app/ and RUN expose 8080
COPY config.txt /app/ and CMD 8080
A team uses Ansible for configuration management. They want to ensure a service is running on all managed nodes. Which Ansible module should be used in the playbook?
systemd
service
The `service` module manages service state on managed nodes, directly satisfying the requirement to ensure a service is running across all hosts. It supports `state: started` and `enabled`, unlike `command` or `shell`, which execute arbitrary commands without idempotent service-state handling. This makes it the appropriate declarative choice for the playbook.
command
shell
A Docker container is running in the background. Which command allows the administrator to execute an interactive bash shell inside the running container named 'webapp'?
docker start -i webapp
docker run -it webapp bash
docker exec -it webapp bash
docker exec runs a new process inside an already running container; -it allocates an interactive TTY and keeps stdin open, and bash specifies the shell. This satisfies the requirement without restarting or attaching to the main process.
docker attach webapp
In a bash script, a developer needs to parse command-line options such as -f filename and -v (verbose). Which built-in command is best suited for this task?
getopt
getopts
getopts is a bash built-in that parses short options with arguments, such as -f filename, and sets OPTARG and OPTIND automatically. It handles the -v flag and option-argument pairing natively, unlike manual shifting or external parsers.
case
shift
An administrator is troubleshooting a Kubernetes deployment that is not receiving traffic. The deployment has one replica and the pod is running. The service is of type ClusterIP. Which command would help verify that the service endpoints are correctly associated with the pod?
kubectl describe pod
kubectl get pods -o wide
kubectl get svc
kubectl get endpoints
`kubectl get endpoints` lists each Service's backing pod IPs and ports, directly confirming whether the ClusterIP Service's selector actually matched the running pod. Since the stem's constraint is a ClusterIP Service with no external exposure, endpoint association is the failure point to verify, and this command exposes an empty or mismatched endpoint list immediately.
Want more Automation, Orchestration, and Scripting practice?
Practice this domainA Linux administrator needs to locate all files in the /var directory that have been modified within the last 30 minutes and are larger than 10MB. Which command accomplishes this task?
find /var -mmin 30 -size +10M
find /var -mmin -30 -size +10M
The -mmin -30 predicate matches files modified within the last 30 minutes, and -size +10M selects those larger than 10MB. Combining both in one find invocation over /var returns exactly the files meeting both constraints simultaneously.
locate /var -mmin -30 -size +10M
find /var -mtime -30 -size +10M
An administrator wants to grant a specific user, 'jdoe', read and write access to a file that is owned by root:root with permissions 640. The administrator does not want to change the file's owner or group. Which approach should be used?
Use setfacl -m u:jdoe:rw file
setfacl -m u:jdoe:rw adds a named user entry to the file's access control list, granting jdoe read and write access. This satisfies the constraint of not altering the file's owner or group, which chmod and chown would change.
Change file owner to jdoe
Use chmod o+rw file
Add jdoe to the root group
A user needs to view the first 15 lines of a large log file. Which command is most appropriate?
head -n 15 filename
head outputs the beginning of a file, and -n 15 limits that output to exactly 15 lines, directly satisfying the requirement to view the first 15 lines. tail would show the end, and cat would dump the entire large log.
cat filename | head -n 15
less -N 15 filename
tail -n 15 filename
A Linux administrator wants to search for all occurrences of the word 'ERROR' in log files under /var/log, ignoring case, and also print the line numbers. Which command should be used?
grep -vi 'ERROR' /var/log
grep -rin 'ERROR' /var/log
The -r flag recurses through every file under /var/log, -i matches 'ERROR' case-insensitively, and -n prefixes each match with its line number. Together these satisfy all three requirements: recursive search, case-insensitive matching, and printed line numbers.
grep -rn 'ERROR' /var/log
find /var/log -name '*ERROR*'
An administrator needs to replace all occurrences of 'oldhost' with 'newhost' in the configuration file /etc/hosts. Which command will perform the replacement and save the changes directly to the file?
sed 's/oldhost/newhost/g' /etc/hosts
awk '{gsub(/oldhost/,"newhost")}1' /etc/hosts
grep -r 'oldhost' /etc/hosts | sed 's/oldhost/newhost/g'
sed -i 's/oldhost/newhost/g' /etc/hosts
The `-i` flag makes sed edit /etc/hosts in place, satisfying the requirement to save changes directly to the file. The `g` suffix replaces every occurrence of 'oldhost' on each line, not merely the first, meeting the "all occurrences" constraint without redirection or a temporary file.
A process with PID 2345 is not responding. The administrator wants to force stop the process immediately. Which command should be used?
kill -9 2345
SIGKILL (signal 9) cannot be caught, blocked or ignored by the process, so the kernel terminates PID 2345 immediately. This satisfies the requirement to force stop an unresponsive process, unlike the default SIGTERM sent by plain kill.
kill -1 2345
pkill -15 -f processname
kill -15 2345
Want more System Management practice?
Practice this domainA Linux administrator needs to add a new user named 'jdoe' with a home directory and a bash shell. Which command accomplishes this?
usermod -m -s /bin/bash jdoe
adduser jdoe --home /home/jdoe --shell /bin/bash
useradd -m -s /bin/bash jdoe
The -m flag creates the home directory and -s /bin/bash sets the login shell, satisfying both stated requirements in one command. Without -m, useradd leaves no home directory; without -s, the system default shell applies.
passwd -m jdoe
A security audit reveals that users can change their password without meeting complexity requirements. Which PAM module should be configured to enforce password complexity?
pam_faillock
pam_unix
pam_tally2
pam_pwquality
pam_pwquality enforces password complexity at change time by applying configurable rules such as minimum length, character classes and dictionary checks. Configuring it in the password stack ensures users cannot set weak passwords, directly satisfying the audit finding that complexity requirements are bypassed.
An administrator wants to allow the user 'ops' to run only the command '/usr/bin/systemctl restart httpd' via sudo on a specific host 'webserver'. Which /etc/sudoers entry is correct?
ops webserver=(root) /usr/bin/systemctl restart httpd
This entry grants user 'ops' on host 'webserver' permission to run only that exact systemctl restart command as root, with no wildcards or broader command scope. It satisfies the least-privilege constraint by restricting sudo to the single specified command on the specified host.
ops ALL=(root) /usr/bin/systemctl restart httpd
ops webserver=(ALL) /usr/bin/systemctl restart httpd
ops webserver=(root) ALL
An AppArmor profile for a web server is in complain mode. After testing, the administrator wants to enforce the profile. Which command accomplishes this?
apparmor_parser -r /etc/apparmor.d/usr.sbin.httpd
aa-enforce /etc/apparmor.d/usr.sbin.httpd
aa-enforce switches the named AppArmor profile from complain to enforce mode, applying its deny rules. This satisfies the requirement to move the web server profile out of complain mode after testing, using the profile path as the argument.
aa-complain /etc/apparmor.d/usr.sbin.httpd
aa-status /etc/apparmor.d/usr.sbin.httpd
An administrator is hardening SSH and wants to disable root login and only allow users in the 'sshusers' group. Which two directives should be set in /etc/ssh/sshd_config?
DenyRootLogin yes and AllowGroups sshusers
PermitRootLogin prohibit-password and AllowGroups sshusers
PermitRootLogin no and AllowGroups sshusers
PermitRootLogin no blocks direct superuser SSH access, forcing administrators to log in as themselves before elevating. AllowGroups sshusers restricts authentication to members of that group via the AllowGroups directive, satisfying both hardening constraints. DenyUsers or AllowUsers would not reference group membership.
PermitRootLogin no and AllowUsers sshusers
An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?
The process is running in permissive mode.
The process is running in an unconfined domain.
The unconfined_t type places the process outside SELinux policy enforcement, so type enforcement rules do not restrict it. Confined domains such as httpd_t are limited by policy; unconfined processes retain standard discretionary access controls only.
SELinux is disabled.
The process is confined by a targeted policy.
Want more Security practice?
Practice this domainA Linux administrator needs to check which services are listening on TCP ports on a server. Which command should be used to replace the deprecated netstat command?
ss -tlnp
The `ss -tlnp` command uses the `-t` flag to filter only TCP sockets, `-l` to show only listening sockets, `-n` to display numeric addresses and ports without DNS resolution, and `-p` to reveal the process identifier and name. This directly replaces `netstat -tlnp` by reading socket information from the kernel’s `/proc/net/tcp` and `/proc/net/tcp6` files, satisfying the stem’s requirement to check services listening on TCP ports.
nmap localhost
ip link show
dig -t any localhost
A user reports that they cannot reach a website. The administrator wants to check the path that packets take to the destination server. Which command should be used?
ip addr
ss
traceroute
traceroute sends packets with incrementally increasing TTL values, causing each router along the path to return an ICMP Time Exceeded message. This reveals the hop-by-hop route packets take to the destination, exactly what the administrator needs to diagnose where connectivity fails.
ping
A Linux engineer is investigating high disk I/O on a server. Which command provides disk I/O statistics including %util, await, r/s, and w/s?
iostat -x 1
The -x flag extends iostat's report with per-device statistics, including %util (device busy percentage), await (average I/O wait), and r/s and w/s throughput. The 1 argument refreshes every second, exposing the sustained disk I/O pattern the engineer needs to diagnose.
sar -b
vmstat 1 5
free -h
During boot, a Linux system displays a kernel panic with 'VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?
Incorrect time configuration in the BIOS
Corrupt initramfs missing a necessary kernel module for the root device
The kernel mounts the root filesystem using drivers supplied by the initramfs. If that image is corrupt or omits the storage or filesystem module, the root device cannot be mounted, producing exactly this unknown-block(0,0) panic during boot.
The /etc/fstab file has an invalid filesystem type for the root partition
A defective network cable
An administrator needs to trace system calls made by a process that is misbehaving. Which command should be used to attach to the running process and display its system calls?
tcpdump -i any
ltrace -p <PID>
strace -p <PID>
`strace -p <PID>` attaches to an already-running process via ptrace and prints each system call it makes, satisfying the requirement to trace a misbehaving process without restarting it. The `-p` flag targets the live PID directly, which is exactly what the scenario demands.
lsof -p <PID>
An administrator wants to capture network traffic on interface eth0, writing the output to a file for later analysis, without resolving hostnames. Which command accomplishes this?
tcpdump -i eth0 -r capture.pcap
tcpdump -i eth0 -w capture.pcap -n
The `-i eth0` flag binds capture to the specified interface, `-w capture.pcap` writes raw packets to a file rather than printing them, and `-n` suppresses DNS and service-name resolution, satisfying the no-hostname constraint. Together these flags match every requirement in the stem.
tcpdump -i any -w capture.pcap
tcpdump -n -w eth0 capture.pcap
Want more Troubleshooting practice?
Practice this domainThe XK0-006 exam has 90 questions and must be completed in 90 minutes. The passing score is 720/1000.
Multiple-choice and performance-based questions on Linux system administration, scripting, security, storage, and virtualisation. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 5 domains: Services and User Management, Automation, Orchestration, and Scripting, System Management, Security, Troubleshooting. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official CompTIA XK0-006 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.