Courseiva
Troubleshooting →mediumMultiple Choice

XK0-006 Troubleshooting Practice Question

A Linux administrator receives reports that a database server becomes unresponsive every day around 02:00. Reviewing logs, the administrator notices repeated messages about 'blocked for more than 120 seconds' and high I/O wait. Which command should be used to identify which process is generating the most disk I/O during this period?

⚠ Common exam trap

The trap here is assuming that any I/O monitoring tool will identify the responsible process, when many only report device-level or system-wide statistics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

iotop -o -d 5

The administrator must attribute heavy disk I/O to a specific process. iotop is designed for per-process I/O monitoring and the -o flag filters out idle processes, making it ideal for identifying the culprit during the nightly issue. Other tools show device-level or system-wide I/O but cannot tie activity to a process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    iotop -o -d 5

    Why this is correct

    iotop displays per-process I/O usage, and the -o option shows only processes actively performing I/O. With -d 5, it refreshes every five seconds, allowing the administrator to identify the process generating heavy disk activity during the 02:00 window. This directly addresses the need to attribute I/O to a specific process.

  • ✗

    iostat -x 5

    Why it's wrong here

    iostat reports per-device and per-partition I/O statistics, including await and %util, but it does not attribute I/O to individual processes. It would show that a disk is saturated, yet the administrator needs to know which process is responsible. Thus, iostat alone cannot pinpoint the offending process and is not the best tool for this scenario.

  • ✗

    vmstat 5

    Why it's wrong here

    vmstat provides system-wide statistics on processes, memory, paging, block I/O, traps, and CPU, but it does not break down I/O by process. It would show elevated 'bo' (blocks out) and high wa (I/O wait), confirming a problem, but not which process causes it. Therefore, it cannot identify the specific culprit process.

  • ✗

    sar -d 5 3

    Why it's wrong here

    sar -d reports disk activity statistics per device, similar to iostat, but again lacks per-process attribution. It is useful for historical trending when sysstat is configured, but it will not reveal which process is generating the I/O. Hence, it does not meet the requirement of identifying the responsible process.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.