Courseiva
Troubleshooting →mediumMultiple Choice

XK0-006 Troubleshooting Practice Question

A system administrator is troubleshooting a service that fails to start. They want to see the recent logs for that specific service unit. Which journalctl command should be used?

⚠ Common exam trap

Test-takers frequently confuse `journalctl -u` with other common options like `-k` (kernel) or `-p` (priority), or fall back to legacy syslog commands like `tail -f /var/log/syslog`, which do not directly filter by systemd unit and may miss critical journal-only logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

journalctl -u service_name

The `-u` option in `journalctl` filters logs by the systemd unit name, allowing you to view recent logs specifically for a service. This is the correct approach when troubleshooting a service that fails to start, as it isolates the relevant log entries without noise from other system messages.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    journalctl -k

    Why it's wrong here

    journalctl -k shows only kernel ring-buffer messages, so service unit logs never appear. Kernel filtering is right for diagnosing hardware, driver or boot issues, but a failing systemd service needs the -u unit filter to display its own journal entries.

  • ✓

    journalctl -u service_name

    Why this is correct

    The -u flag filters journalctl output to a single systemd unit, matching the requirement to see logs for one specific service. Without it, journalctl returns the full merged journal, which obscures the failing unit's recent entries.

  • ✗

    tail -f /var/log/syslog

    Why it's wrong here

    Reading /var/log/syslog bypasses the journal and may omit the unit's entries entirely on journald-only systems, and tail shows no unit filtering. It is tempting because tailing a log file suits traditional syslog daemons without systemd journald managing that service.

  • ✗

    journalctl -p err

    Why it's wrong here

    journalctl -p err filters by priority across all units, returning unrelated errors rather than that unit's recent entries. Priority filtering is correct when triaging cluster-wide error bursts, but isolating one failing service requires the -u unit filter to scope output to that service.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.