Courseiva
easyMultiple Choice

220-1102 Practice Question: A junior admin needs to list all files in…

A junior admin needs to list all files in /var/log that were modified in the last 24 hours. Which command accomplishes this?

⚠ Common exam trap

The A+ exam often tests the distinction between `-mtime` (modification time) and `-atime` (access time), trapping candidates who confuse the two or who think `ls` with `grep` can perform time-based filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

find /var/log -mtime 0

The `find` command with `-mtime 0` searches for files whose modification time is within the last 24 hours. The `-mtime` argument uses a 24-hour period, where `0` means modified less than 24 hours ago, making it the precise tool for this task.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ls -la /var/log | grep '24 hours'

    Why it's wrong here

    ls -la prints modification timestamps as dates, not ages, and grep '24 hours' matches filenames or nothing, so no file is filtered by recency. It tempts as a quick pipe-based filter, but ls offers no relative-time predicate; find -mtime 0 evaluates each file's age directly.

  • ✓

    find /var/log -mtime 0

    Why this is correct

    find's -mtime test compares file modification time against 24-hour periods, so -mtime 0 matches files modified within the last day. It recurses through /var/log and prints each matching path, satisfying the requirement without extra flags.

  • ✗

    find /var/log -atime 0

    Why it's wrong here

    Using -atime 0 matches files accessed within the last 24 hours, not modified; access time updates on reads, so untouched-but-read files appear and modified-but-unread files are missed. It tempts because -atime is the natural flag when you conflate access with modification; -mtime 0 is correct for modification.

  • ✗

    locate /var/log | sort -m

    Why it's wrong here

    locate queries a prebuilt filename database and cannot filter by modification time, so it lists matching paths regardless of age; sort -m only merges presorted inputs. find /var/log -mtime -1 walks the directory and tests timestamps directly. locate suits fast name lookups when timestamps are irrelevant.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.