Courseiva
Host-Based Analysis →mediumMultiple Choice

200-201 Host-Based Analysis Practice Question

An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

systemctl disable servicename

The 'systemctl disable' command prevents a service from starting automatically at boot.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    systemctl disable servicename

    Why this is correct

    systemctl disable removes the service's symlinks from the systemd unit configuration, preventing it from starting automatically at boot while leaving the unit file intact. This directly addresses the autostart constraint, unlike stop, which only halts the running instance.

  • ✗

    systemctl stop servicename

    Why it's wrong here

    systemctl stop halts the running unit for the current session only; the service's enablement symlinks remain, so it restarts at the next boot. systemctl disable removes those symlinks, preventing automatic startup. Stopping is tempting for immediate containment during triage, but it does not satisfy the requirement to stop the service starting automatically.

  • ✗

    systemctl remove servicename

    Why it's wrong here

    systemctl has no remove subcommand; units are deleted by removing their unit files, not through systemctl. The correct action, systemctl disable, removes the enablement symlinks so the service stops starting automatically. The verb 'remove' is tempting because it sounds like deleting the service, but it is not a valid systemctl operation.

  • ✗

    systemctl mask servicename

    Why it's wrong here

    systemctl mask links the unit to /dev/null, preventing it from being started manually or as a dependency, which is stronger than the question's requirement. systemctl disable removes the enablement symlinks so the service no longer starts automatically at boot. Masking is tempting for hard-blocking a malicious unit, but it exceeds what disabling alone demands.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.