Courseiva
Troubleshooting →mediumMultiple Select

XK0-006 Troubleshooting Practice Question

A Linux server reports that its root filesystem is 100 percent full, and applications are failing to write logs. The administrator needs to identify what is consuming space and reclaim it safely. Which two commands are appropriate to determine where the space is used? (Choose two.)

⚠ Common exam trap

The trap here is reaching for inode or block-device listings, which describe filesystem structure and capacity rather than identifying which directories and files actually consumed the space.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

find / -xdev -type f -size +500M -exec ls -lh {} \;

Finding what filled the root filesystem requires two complementary views: per-directory totals to narrow the search, and a scan for unusually large individual files. Staying on one filesystem with -x and -xdev prevents mounted volumes from skewing results. Together these commands point the administrator to the exact data to review or remove.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    lsblk -f

    Why it's wrong here

    lsblk -f displays block devices, their filesystems, labels, and mount points. It is useful for understanding storage topology but reports no per-directory or per-file consumption, so it cannot identify what filled the root filesystem. It answers which devices exist, not where space was consumed.

  • ✗

    df -i /

    Why it's wrong here

    df -i reports inode usage rather than block usage. It is valuable when a filesystem refuses new files despite free space, but the scenario states the root filesystem is full in terms of capacity, so inode counts do not explain where the bytes went. It would not guide the administrator to the space-consuming directories or files.

  • ✓

    find / -xdev -type f -size +500M -exec ls -lh {} \;

    Why this is correct

    This locates individual files larger than 500 MB while staying on the root filesystem thanks to -xdev, then lists them with sizes. Large single files such as runaway logs or core dumps are common causes of a full root volume, and this command pinpoints them quickly for review before deletion.

  • ✗

    fsck -n /dev/sda1

    Why it's wrong here

    fsck checks and repairs filesystem consistency, and the -n flag makes it read-only. It does not report which files or directories consume space, and running it against a mounted root filesystem is inappropriate. It is a repair and integrity tool, not a capacity-analysis tool, so it does not serve this scenario.

  • ✓

    du -xh --max-depth=1 / | sort -h

    Why this is correct

    This walks each top-level directory on the root filesystem, staying on one filesystem with -x, and prints human-readable totals sorted ascending so the largest consumers appear last. It directly answers where space is used and avoids descending into mounted filesystems that would distort the picture with unrelated data.

About these practice questions

Courseiva writes every XK0-006 question from scratch — 781 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.