XK0-006 Troubleshooting Practice Question
A system is experiencing boot failures. The administrator wants to view kernel messages from the current boot to diagnose the issue. Which two commands can be used to see these messages? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse `dmesg` with `cat /proc/kmsg` or think `boot.log` contains kernel messages, when in fact `dmesg` and `journalctl -k` are the standard tools for viewing kernel ring buffer output from the current boot.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
journalctl -k
Option A, journalctl -k, is correct because the -k (--dmesg) filter restricts systemd-journald output to kernel messages only, and by default journalctl shows the current boot's entries, so it displays kernel messages from the present boot. Option D, dmesg, is correct because it reads the kernel ring buffer, which contains the kernel messages generated during the current boot, making it ideal for diagnosing boot failures. Option B, cat /proc/kmsg, is not a good choice because /proc/kmsg is a blocking, consume-once interface intended for a single reader such as klogd or dmesg; reading it directly can steal messages and it does not cleanly present the current boot log. Option C, tail -f /var/log/boot.log, is incorrect because boot.log contains service startup output from the init/boot process, not kernel messages, and it may not exist on systemd systems. Option E, vmstat -f, is incorrect because it reports the number of forks since boot, which is unrelated to viewing kernel messages.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
journalctl -k
Why this is correct
`journalctl -k` reads the kernel ring buffer through systemd's journal, filtering entries to kernel-originated messages only. Because the journal persists per-boot metadata, it can restrict output to the current boot, directly satisfying the requirement to inspect kernel messages from the present boot rather than earlier ones.
- ✗
cat /proc/kmsg
Why it's wrong here
Reading /proc/kmsg consumes the kernel ring buffer as a stream and typically requires root, so it is not the intended way to review messages from the current boot. It is tempting because it does expose kernel messages, and would be correct when continuously monitoring new kernel output rather than inspecting an existing boot's log.
- ✗
tail -f /var/log/boot.log
Why it's wrong here
/var/log/boot.log holds service start-up output from the init system, not kernel messages, and may not exist on systemd hosts. journalctl -k or dmesg would be selected when kernel-level boot messages are needed, as the scenario specifies.
- ✓
dmesg
Why this is correct
`dmesg` reads the kernel ring buffer directly, exposing hardware detection, driver and boot-time messages from the current session. This satisfies the stem's requirement to view kernel messages from the current boot without querying persistent logs, and it works even when the system has not fully reached a graphical target.
- ✗
vmstat -f
Why it's wrong here
vmstat -f reports the number of forks since boot, a virtual-memory statistic, and reads no kernel log buffer. dmesg or journalctl -k would be chosen when the requirement is kernel messages from the current boot, which is exactly what the scenario asks for.
Go deeper
Related to this question
Learn chapter
Process Management and System Monitoring
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
Key term
Output
In IT service management, output is the result or deliverable produced by a process, system, or component, such as data, reports, or services delivered to a customer.
About these practice questions
One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.