Courseiva
Troubleshooting →mediumMultiple Choice

XK0-006 Troubleshooting Practice Question

A Linux system is running slowly with high I/O wait as shown by vmstat. To investigate the I/O activity of a specific process that is suspected of causing the bottleneck, which of the following commands would be used to trace its system calls related to I/O?

⚠ Common exam trap

XK0-006 often tests the distinction between system-wide I/O monitoring tools (iostat, vmstat) and per-process syscall tracing tools (strace), and candidates may pick iostat when the question specifically asks for tracing a process's system calls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

strace -p <pid>

strace attaches to a running process and traces its system calls, including I/O-related calls like read, write, open, and fsync, making it the right tool to pinpoint which syscalls a specific process is issuing. By using 'strace -p <pid>', the administrator can observe the exact I/O behavior of the suspect process. This directly addresses the need to trace system calls related to I/O for a specific PID.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    iostat -x 1

    Why it's wrong here

    iostat -x 1 reports extended per-device I/O statistics once per second, aggregating activity by block device rather than by process, and traces no system calls. It is tempting for spotting the busy disk, but strace is what follows a specific process's I/O-related syscalls.

  • ✓

    strace -p <pid>

    Why this is correct

    'strace -p <pid>' attaches to the running process and traces its system calls, exposing read, write and fsync activity that drives I/O wait. This satisfies the requirement to investigate a specific suspect process rather than system-wide I/O statistics.

  • ✗

    dmesg | tail

    Why it's wrong here

    dmesg prints the kernel ring buffer, showing driver and hardware messages already logged; it cannot follow a running process or trace its system calls. It is tempting for spotting I/O errors, but the stem requires per-process syscall tracing, which strace provides.

  • ✗

    free -h

    Why it's wrong here

    free -h reports memory and swap usage, not per-process system calls, so it cannot trace I/O activity. It is tempting because high I/O wait often accompanies memory pressure and swapping, making memory statistics a plausible first check; however, strace is the tool that traces a process's I/O-related syscalls.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.