200-201 Host-Based Analysis Practice Question
An analyst is examining a Linux server and notices an unusual systemd service that starts automatically. Which command would be used to disable this service?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
systemctl disable servicename
The 'systemctl disable' command prevents a service from starting automatically at boot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
systemctl disable servicename
Why this is correct
systemctl disable removes the service's symlinks from the systemd unit configuration, preventing it from starting automatically at boot while leaving the unit file intact. This directly addresses the autostart constraint, unlike stop, which only halts the running instance.
- ✗
systemctl stop servicename
Why it's wrong here
systemctl stop halts the running unit for the current session only; the service's enablement symlinks remain, so it restarts at the next boot. systemctl disable removes those symlinks, preventing automatic startup. Stopping is tempting for immediate containment during triage, but it does not satisfy the requirement to stop the service starting automatically.
- ✗
systemctl remove servicename
Why it's wrong here
systemctl has no remove subcommand; units are deleted by removing their unit files, not through systemctl. The correct action, systemctl disable, removes the enablement symlinks so the service stops starting automatically. The verb 'remove' is tempting because it sounds like deleting the service, but it is not a valid systemctl operation.
- ✗
systemctl mask servicename
Why it's wrong here
systemctl mask links the unit to /dev/null, preventing it from being started manually or as a dependency, which is stronger than the question's requirement. systemctl disable removes the enablement symlinks so the service no longer starts automatically at boot. Masking is tempting for hard-blocking a malicious unit, but it exceeds what disabling alone demands.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.