XK0-006 Troubleshooting Practice Question
A Linux administrator is troubleshooting a service that fails to start. The service unit file is present and enabled, but systemctl status shows 'failed' with exit code 203. Which command should the administrator run to view the most recent log messages specific to this service?
⚠ Common exam trap
The trap here is assuming that traditional log files like /var/log/messages contain all service logs, when systemd-based systems primarily use the journal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
journalctl -u servicename.service -n 50
The administrator should use journalctl -u servicename.service -n 50 to view the most recent log entries for that unit. This command queries the systemd journal, which captures stdout/stderr from the service and systemd's own messages about start failures. It is the most direct way to diagnose why the service failed with exit code 203.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
dmesg | grep servicename
Why it's wrong here
dmesg shows kernel ring buffer messages, which are related to hardware and kernel events, not user-space service logs. While some service failures might generate kernel messages, systemd service logs are typically in the journal. This command is unlikely to provide the specific service error.
- ✗
tail -f /var/log/messages
Why it's wrong here
While /var/log/messages may contain some system logs, it is not specific to a single systemd service and may not capture all service-related messages. Modern distributions use journald, and messages may not be written to /var/log/messages. This command is less precise and may miss the relevant error.
- ✗
systemctl cat servicename.service
Why it's wrong here
systemctl cat displays the contents of the unit file, not runtime logs. It can help verify the ExecStart path and other directives, but it does not show why the service failed to start. The exit code 203 suggests an execution problem, but the unit file alone may not reveal the cause.
- ✓
journalctl -u servicename.service -n 50
Why this is correct
journalctl -u filters logs for a specific systemd unit. The -n 50 option shows the last 50 lines. This directly provides the recent log messages for the failing service, which is exactly what is needed. Exit code 203 often indicates an exec failure, and the logs will reveal the exact error.
Go deeper
Related to this question
Learn chapter
File Permissions and Ownership
Key term
journalctl
Journalctl is a command-line tool used to view and query logs collected by the systemd journal, which stores system and application messages on Linux systems.
Key term
systemctl
systemctl is the command-line tool used to inspect, start, stop, enable, or disable services managed by the systemd init system in Linux.
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.