Courseiva
Troubleshooting →mediumMultiple Select

XK0-006 Troubleshooting Practice Question

A Linux administrator is troubleshooting a service that fails to start. Which TWO commands can be used to view the last 20 lines of the systemd journal for the sshd unit?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

journalctl -u sshd -n 20

Option A, `journalctl -u sshd -n 20`, is correct because `-u sshd` filters the journal to the sshd unit and `-n 20` limits the output to the last 20 lines, exactly matching the requirement. Option B, `journalctl -u sshd | tail -20`, is also correct because `journalctl -u sshd` produces the sshd unit's journal entries and piping them to `tail -20` displays only the final 20 lines. Option C, `journalctl -k -n 20`, is wrong because `-k` restricts output to kernel messages rather than the sshd unit. Option D, `journalctl -u sshd -p err`, is wrong because `-p err` filters by priority level (error and above) instead of returning the last 20 lines. Option E, `journalctl -b -u sshd`, is wrong because `-b` limits output to the current boot but does not restrict the result to the last 20 lines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    journalctl -u sshd -n 20

    Why this is correct

    journalctl's -u flag filters entries to the sshd unit, and -n 20 limits output to the last 20 lines, satisfying both stem constraints in one invocation. This queries the systemd journal directly, showing recent sshd startup failures without piping to another utility.

  • ✓

    journalctl -u sshd | tail -20

    Why this is correct

    journalctl -u sshd filters the journal to the sshd unit, then the pipe sends that output to tail -20, which prints only the final 20 lines. This satisfies both stem constraints, though it reads the full unit history before trimming rather than limiting at the source.

  • ✗

    journalctl -k -n 20

    Why it's wrong here

    -k shows kernel messages, not sshd.

  • ✗

    journalctl -u sshd -p err

    Why it's wrong here

    The -p err filter shows only error-priority entries, so the last 20 lines are not returned and lower-priority context is lost. It is tempting because it targets sshd, and would suit isolating only error-level messages from that unit.

  • ✗

    journalctl -b -u sshd

    Why it's wrong here

    Omitting -n 20 means the entire current-boot journal for sshd is printed, not just the last 20 lines. It is tempting because -u sshd correctly scopes output to the unit, and -b alone is right when reviewing everything logged since the last boot.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.