XK0-006 Troubleshooting Practice Question
A Linux server reports that its root filesystem is 100 percent full, and applications are failing to write logs. The administrator needs to identify what is consuming space and reclaim it safely. Which two commands are appropriate to determine where the space is used? (Choose two.)
⚠ Common exam trap
The trap here is reaching for inode or block-device listings, which describe filesystem structure and capacity rather than identifying which directories and files actually consumed the space.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
find / -xdev -type f -size +500M -exec ls -lh {} \;
Finding what filled the root filesystem requires two complementary views: per-directory totals to narrow the search, and a scan for unusually large individual files. Staying on one filesystem with -x and -xdev prevents mounted volumes from skewing results. Together these commands point the administrator to the exact data to review or remove.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
lsblk -f
Why it's wrong here
lsblk -f displays block devices, their filesystems, labels, and mount points. It is useful for understanding storage topology but reports no per-directory or per-file consumption, so it cannot identify what filled the root filesystem. It answers which devices exist, not where space was consumed.
- ✗
df -i /
Why it's wrong here
df -i reports inode usage rather than block usage. It is valuable when a filesystem refuses new files despite free space, but the scenario states the root filesystem is full in terms of capacity, so inode counts do not explain where the bytes went. It would not guide the administrator to the space-consuming directories or files.
- ✓
find / -xdev -type f -size +500M -exec ls -lh {} \;
Why this is correct
This locates individual files larger than 500 MB while staying on the root filesystem thanks to -xdev, then lists them with sizes. Large single files such as runaway logs or core dumps are common causes of a full root volume, and this command pinpoints them quickly for review before deletion.
- ✗
fsck -n /dev/sda1
Why it's wrong here
fsck checks and repairs filesystem consistency, and the -n flag makes it read-only. It does not report which files or directories consume space, and running it against a mounted root filesystem is inappropriate. It is a repair and integrity tool, not a capacity-analysis tool, so it does not serve this scenario.
- ✓
du -xh --max-depth=1 / | sort -h
Why this is correct
This walks each top-level directory on the root filesystem, staying on one filesystem with -x, and prints human-readable totals sorted ascending so the largest consumers appear last. It directly answers where space is used and avoids descending into mounted filesystems that would distort the picture with unrelated data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.