XK0-006 Troubleshooting Practice Question
A system administrator wants to review kernel-related log messages from the current boot session. Which journalctl command should be used to filter the kernel messages?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
journalctl -k
journalctl -k shows kernel messages from the current boot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
journalctl -p err
Why it's wrong here
-p err filters by priority, not kernel messages.
- ✗
journalctl -b -u systemd-journald
Why it's wrong here
The -u flag restricts output to the systemd-journald unit's own messages, not kernel messages. Unit filtering is the right approach when investigating one specific service's behaviour, but the kernel facility is not a unit, so this returns journald daemon logs instead.
- ✓
journalctl -k
Why this is correct
The -k flag restricts journalctl output to kernel messages only, drawing from the kernel ring buffer captured by systemd-journald. This directly satisfies the requirement to isolate kernel-related entries from the current boot session, excluding user-space service and application logs.
- ✗
journalctl --since today
Why it's wrong here
The --since today filter limits output by timestamp only, returning all facilities logged today rather than kernel messages. Time-window filtering is correct when correlating events around an incident, but the stem requires facility-based selection, which -k supplies.
Go deeper
Related to this question
Key term
journalctl
Journalctl is a command-line tool used to view and query logs collected by the systemd journal, which stores system and application messages on Linux systems.
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
About these practice questions
This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.