hardMultiple Select
XK0-006 Practice Question: A Linux administrator is troubleshooting a…
A Linux administrator is troubleshooting a service that fails to start. Which THREE files or commands should be checked to diagnose the issue? (Select THREE.)
⚠ Common exam trap
CompTIA often tests the distinction between kernel-level logs (dmesg) and service-level logs (journalctl), and the trap here is that candidates may confuse `dmesg` with service troubleshooting because it shows boot-time messages, but it does not capture service-specific failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
journalctl -u service-name
Option B, journalctl -u service-name, is correct because it queries the systemd journal specifically for the unit's log messages, showing startup errors, exit codes, and dependency failures for that service. Option C, /var/log/messages (or /var/log/syslog), is correct because these traditional syslog files capture daemon and service messages on many distributions, providing historical context when the journal is not persistent. Option E, systemctl status service-name, is correct because it reports the unit's current state, loaded configuration, main PID, exit code, and recent log lines, immediately revealing why the service failed. Option A, dmesg, is not among the marked answers because it primarily shows kernel ring buffer messages and is less useful for user-space service startup failures. Option D, /etc/rc.local, is not marked because it is a legacy SysV init compatibility script and is not a diagnostic tool for systemd service failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
dmesg
Why it's wrong here
dmesg shows kernel ring-buffer messages, so it records hardware and driver faults, not why a systemd unit failed. It is tempting because kernel errors can stop services, but for unit failures you inspect journalctl -u and systemctl status instead.
- ✓
journalctl -u service-name
Why this is correct
journalctl -u service-name queries the systemd journal filtered to that unit, exposing the exact exit code, dependency failure or error message recorded at start time. This directly satisfies the stem's need to diagnose why the service fails, giving the most specific per-unit evidence available.
- ✓
/var/log/messages (or /var/log/syslog)
Why this is correct
/var/log/messages or /var/log/syslog captures system-wide daemon and kernel messages, including service start failures logged by syslog before or alongside systemd. Checking it satisfies the stem's diagnostic requirement by revealing errors that the unit journal alone may omit.
- ✗
/etc/rc.local
Why it's wrong here
/etc/rc.local is a legacy SysV boot script, not a diagnostic source; it holds no unit state or error output. It is tempting as a startup file, but it would be the place to launch a service, not to investigate why a systemd unit failed.
- ✓
systemctl status service-name
Why this is correct
systemctl status service-name reports the unit's load state, active state, exit code and recent log lines, immediately showing whether the service failed, is masked or hit a dependency problem. This satisfies the stem's diagnostic requirement by giving the fastest authoritative view of the unit's state.
Go deeper
Related to this question
Learn chapter
Installing Linux and Package Management
Key term
Dependency
A dependency is a piece of software, library, or package that another software application requires in order to function correctly.
Key term
systemd
systemd is a system and service manager for Linux operating systems that initializes and manages processes, services, and system resources after the kernel boots.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.