XK0-006 System Management Practice Question
A system administrator is investigating a performance issue and wants to view kernel-related messages. Which three commands can be used to access kernel ring buffer messages? (Choose three.)
⚠ Common exam trap
XK0-006 often tests whether candidates distinguish kernel-specific log access (dmesg, journalctl -k, /var/log/kern.log) from general system logs (/var/log/syslog) and service status commands (systemctl status) — picking syslog because it 'contains kernel messages' is the classic mistake.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dmesg
Option B (dmesg) is correct because dmesg directly reads and prints the kernel ring buffer, which is exactly the kernel-related message store the administrator needs. Option C (cat /var/log/kern.log) is correct because on many Linux distributions the kernel ring buffer messages are persisted to /var/log/kern.log, so reading that file exposes kernel messages. Option D (journalctl -k) is correct because the -k (or --dmesg) flag restricts systemd journal output to kernel messages only, providing access to kernel ring buffer content. Option A (tail -f /var/log/syslog) is not correct here because syslog is a general system log that may include kernel messages only indirectly and is not the kernel ring buffer itself. Option E (systemctl status) is not correct because it reports the status of systemd units and does not display kernel ring buffer messages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tail -f /var/log/syslog
Why it's wrong here
/var/log/syslog holds userspace and service messages forwarded by the logging daemon, not the kernel ring buffer. It is tempting because tailing syslog is the standard way to watch live system events, and would be correct when tracing service or authentication activity rather than kernel messages.
- ✓
dmesg
Why this is correct
`dmesg` reads the kernel ring buffer directly, satisfying the requirement to view kernel-related messages. It exposes boot-time hardware detection, driver initialisation and runtime kernel warnings, and supports filtering by facility or severity. Unlike journal-based tools, it needs no persistent logging daemon, so it works even when systemd-journald is unavailable.
- ✓
cat /var/log/kern.log
Why this is correct
Reading /var/log/kern.log exposes kernel messages persisted to disk by a logging daemon such as rsyslog, satisfying the requirement to access kernel ring buffer content. Unlike dmesg, which reads the live buffer directly, this file retains historical entries across reboots, so it works when past kernel events must be reviewed.
- ✓
journalctl -k
Why this is correct
`journalctl -k` reads only kernel messages from the systemd journal, which is populated by the kernel ring buffer. This satisfies the requirement to access kernel-related messages on systemd-based distributions, unlike `journalctl` without `-k`, which returns all units and services indiscriminately.
- ✗
systemctl status
Why it's wrong here
systemctl status reports a unit's state and recent journal entries, not the kernel ring buffer itself; it reads the journal rather than /dev/kmsg. It is tempting because it surfaces boot and service diagnostics, and would suit checking whether a specific daemon failed to start.
Go deeper
Related to this question
Learn chapter
File Permissions and Ownership
Key term
journalctl
Journalctl is a command-line tool used to view and query logs collected by the systemd journal, which stores system and application messages on Linux systems.
Key term
systemd
systemd is a system and service manager for Linux operating systems that initializes and manages processes, services, and system resources after the kernel boots.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.