Courseiva
System Management →mediumMultiple Choice

XK0-006 System Management Practice Question

A Linux administrator needs to locate all files in the /var/log directory that have been modified within the last 2 days and contain the word 'error' (case-insensitive). Which command accomplishes this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

find /var/log -mtime -2 -exec grep -li 'error' {} \;

The correct command uses -mtime -2 to find files modified less than 2 days ago, and -exec grep -li 'error' to perform a case-insensitive search for 'error' in file contents, listing filenames. Option A uses -mtime +2 (files older than 2 days). Option B uses -name to match filenames, not content. Option C uses grep -l without -i, so it would miss case variations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    find /var/log -mtime +2 -exec grep -li 'error' {} \;

    Why it's wrong here

    -mtime +2 selects files modified more than two days ago, the opposite of the required window, so recent logs are excluded. It is tempting because grep -li correctly handles case-insensitive content matching, and this command would be right if the task were finding older, archived logs.

  • ✗

    find /var/log -name '*error*' -mtime -2

    Why it's wrong here

    -name '*error*' matches filenames containing 'error', not file contents, so it never inspects log text. It is tempting because it correctly applies -mtime -2 and looks like a content search, and it would be the right command if the administrator needed files named after errors rather than files containing them.

  • ✗

    find /var/log -mtime -2 -exec grep -l 'error' {} \;

    Why it's wrong here

    grep -l is case-sensitive, so 'Error' or 'ERROR' entries are missed; the stem demands case-insensitive matching, which needs grep -li. It is tempting because -mtime -2 and -exec grep are otherwise structured correctly, and this form would be right if the log entries were guaranteed lowercase.

  • ✓

    find /var/log -mtime -2 -exec grep -li 'error' {} \;

    Why this is correct

    The `-mtime -2` predicate filters files modified within the last two days, satisfying the recency constraint, while `-exec grep -li 'error' {} \;` runs a case-insensitive search on each match. The `-l` flag lists only filenames rather than matching lines, and `-i` handles the case-insensitivity requirement.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.