XK0-006 Troubleshooting Practice Question
A Linux administrator receives reports that a database server becomes unresponsive every day around 02:00. Reviewing logs, the administrator notices repeated messages about 'blocked for more than 120 seconds' and high I/O wait. Which command should be used to identify which process is generating the most disk I/O during this period?
⚠ Common exam trap
The trap here is assuming that any I/O monitoring tool will identify the responsible process, when many only report device-level or system-wide statistics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
iotop -o -d 5
The administrator must attribute heavy disk I/O to a specific process. iotop is designed for per-process I/O monitoring and the -o flag filters out idle processes, making it ideal for identifying the culprit during the nightly issue. Other tools show device-level or system-wide I/O but cannot tie activity to a process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
iotop -o -d 5
Why this is correct
iotop displays per-process I/O usage, and the -o option shows only processes actively performing I/O. With -d 5, it refreshes every five seconds, allowing the administrator to identify the process generating heavy disk activity during the 02:00 window. This directly addresses the need to attribute I/O to a specific process.
- ✗
iostat -x 5
Why it's wrong here
iostat reports per-device and per-partition I/O statistics, including await and %util, but it does not attribute I/O to individual processes. It would show that a disk is saturated, yet the administrator needs to know which process is responsible. Thus, iostat alone cannot pinpoint the offending process and is not the best tool for this scenario.
- ✗
vmstat 5
Why it's wrong here
vmstat provides system-wide statistics on processes, memory, paging, block I/O, traps, and CPU, but it does not break down I/O by process. It would show elevated 'bo' (blocks out) and high wa (I/O wait), confirming a problem, but not which process causes it. Therefore, it cannot identify the specific culprit process.
- ✗
sar -d 5 3
Why it's wrong here
sar -d reports disk activity statistics per device, similar to iostat, but again lacks per-process attribution. It is useful for historical trending when sysstat is configured, but it will not reveal which process is generating the I/O. Hence, it does not meet the requirement of identifying the responsible process.
Go deeper
Related to this question
Learn chapter
Installing Linux and Package Management
Key term
Process
In IT service management, a process is a structured set of activities designed to accomplish a specific objective, such as managing incidents or changes, by transforming inputs into defined outputs.
Key term
Linux
Linux is an open-source operating system that manages computer hardware and software, widely used in servers, desktops, and embedded systems.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.