hardMultiple Select
XK0-006 A server crashed with a kernel panic Practice Question
A server crashed with a kernel panic. After reboot, the administrator wants to analyze the crash dump. Which THREE actions should be taken to ensure a valid core dump is captured and accessible? (Choose THREE.)
⚠ Common exam trap
Many candidates confuse post-crash verification (checking for a vmcore file) with pre-crash configuration steps, or they mistakenly think debuginfo packages are required for capturing the dump rather than for later analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a dump target in /etc/kdump.conf.
Option A is correct because /etc/kdump.conf is the kdump configuration file where you must specify the dump target (e.g., a raw device, path, NFS, or SSH location) so the vmcore is written to a persistent, accessible location after the crash. Option B is correct because the kdump service (kdump.service) must be enabled and started so the kdump initramfs is loaded and the capture mechanism is armed for the next kernel panic. Option C is correct because the crashkernel=auto (or an explicit size like crashkernel=256M) kernel parameter in the boot loader reserves memory for the secondary kernel that performs the dump; without it, no dump can be captured. Option D is not required to capture a dump; kernel-debuginfo is only needed later for analyzing the vmcore with tools like crash. Option E is incorrect because /var/crash/vmcore is the result of a successful capture, not an action taken to ensure one, and its presence cannot be guaranteed before a crash occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a dump target in /etc/kdump.conf.
Why this is correct
kdump needs a configured dump target in /etc/kdump.conf to know where to write the vmcore after a panic. Without a valid target path or device, the crash dump is discarded, so this action is required for later analysis.
- ✓
Enable and start the kdump service.
Why this is correct
Starting kdump loads the crash kernel into reserved memory at boot, so the panic handler can boot it and write the vmcore to the configured dump path. Without the service running, no capture occurs despite the kernel reservation.
- ✓
Set crashkernel=auto in the boot loader.
Why this is correct
Setting `crashkernel=auto` reserves memory for the kdump kernel at boot, so a secondary kernel can capture the panic dump when the primary kernel fails. Without this reservation, kdump cannot load and no vmcore is written, directly satisfying the requirement that a valid core dump be captured after the kernel panic.
- ✗
Install kernel-debuginfo packages.
Why it's wrong here
Debuginfo packages supply symbol information for interpreting an existing vmcore during analysis; they do not configure capture. They belong in the post-crash analysis step, where resolving function names and offsets from the dump is required.
- ✗
Ensure /var/crash has a vmcore file.
Why it's wrong here
Checking for a vmcore file in /var/crash verifies a dump already exists rather than configuring capture, so it cannot ensure a valid dump is produced. It is tempting because that path is where kdump writes vmcore after a successful capture, making it the right check when confirming a completed dump.
Go deeper
Related to this question
Learn chapter
Networking Fundamentals and Configuration
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
Key term
SSH
SSH (Secure Shell) is a cryptographic network protocol that provides secure, encrypted communication and remote administration between two devices over an unsecured network.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.