Courseiva
Troubleshooting →easyMultiple Choice

XK0-006 Troubleshooting Practice Question

A Linux administrator is troubleshooting a service that fails to start. They want to view the most recent log entries for that service using systemd's journal. Which command should they use?

⚠ Common exam trap

It's easy for candidates to confuse systemctl status, which gives a summary, with journalctl -u, which provides the full log history for the service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

journalctl -u servicename

The journalctl -u command filters the systemd journal by unit, providing all log messages for that service. This is the correct tool to diagnose why a service fails to start, as it captures the service's standard output, error messages, and systemd's own messages about the unit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    dmesg | grep servicename

    Why it's wrong here

    dmesg displays kernel ring buffer messages, which are related to hardware and kernel events, not user-space service logs. It will not contain systemd service output. Grepping for the service name is unlikely to yield relevant information about why the service failed to start.

  • ✗

    systemctl status servicename

    Why it's wrong here

    systemctl status shows the current state of the service and a few recent log lines, but it is not a full log viewer. While it can indicate failure, it does not provide the complete journal history for the service. For detailed troubleshooting, journalctl -u is more comprehensive.

  • ✓

    journalctl -u servicename

    Why this is correct

    journalctl -u filters the journal by the specified systemd unit, showing all log entries for that service. This is the most direct way to see why the service failed. It includes messages from the service's startup, errors, and dependencies, making it ideal for troubleshooting a failed start.

  • ✗

    tail -f /var/log/messages

    Why it's wrong here

    /var/log/messages is a traditional syslog file and may not contain systemd service logs, especially on systems using journald exclusively. It also shows all system messages, not filtered by service. This command is not the correct way to view service-specific logs in systemd.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.