220-1102 grep Practice Question
A technician is supporting a shared training-room workstation. The immediate goal is to find matching error entries in Linux logs. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
The trap here is that candidates familiar with Windows tools may instinctively choose Event Viewer, forgetting that the question specifies a Linux environment, where `grep` is the standard command-line utility for pattern matching in logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
grep against log files
The `grep` command is the correct tool because it allows the technician to search for specific patterns (e.g., error codes, timestamps, or keywords) across one or multiple Linux log files, such as `/var/log/syslog` or `/var/log/messages`. This directly fulfills the goal of finding matching error entries in a shared training-room workstation environment where log analysis is essential for troubleshooting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
grep against log files
Why this is correct
grep searches file contents line by line for a specified pattern, returning matching entries from Linux log files. It directly satisfies the immediate goal of locating matching error entries, unlike tools that filter by metadata or require structured queries.
- ✗
Event Viewer
Why it's wrong here
Event Viewer reads Windows event logs, not Linux syslog or journal files, so it cannot surface matching Linux error entries. It tempts because it is the standard log-search console on Windows, which would be correct for troubleshooting a Windows workstation.
- ✗
Local Users and Groups
Why it's wrong here
Local Users and Groups manages accounts and group membership, not log content, so it cannot find matching Linux error entries. It tempts because it is a familiar administrative console for access issues, which would be correct when adjusting user permissions.
- ✗
System Restore
Why it's wrong here
System Restore reverts Windows system files and registry to an earlier snapshot; it holds no Linux log data and cannot search text. It is tempting because it recovers a Windows workstation after a bad change, but matching error entries in Linux logs requires grep, journalctl or similar text-search tooling.
Go deeper
Related to this question
Learn chapter
Windows Recovery Environment (WinRE)
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
Key term
Syslog
Syslog is a standard protocol used to send and store log messages from network devices and servers to a central logging server for monitoring and troubleshooting.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.