Courseiva
Troubleshooting →mediumMultiple Select

XK0-006 Troubleshooting Practice Question

A system is experiencing boot failures. The administrator wants to view kernel messages from the current boot to diagnose the issue. Which two commands can be used to see these messages? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse `dmesg` with `cat /proc/kmsg` or think `boot.log` contains kernel messages, when in fact `dmesg` and `journalctl -k` are the standard tools for viewing kernel ring buffer output from the current boot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

journalctl -k

Option A, journalctl -k, is correct because the -k (--dmesg) filter restricts systemd-journald output to kernel messages only, and by default journalctl shows the current boot's entries, so it displays kernel messages from the present boot. Option D, dmesg, is correct because it reads the kernel ring buffer, which contains the kernel messages generated during the current boot, making it ideal for diagnosing boot failures. Option B, cat /proc/kmsg, is not a good choice because /proc/kmsg is a blocking, consume-once interface intended for a single reader such as klogd or dmesg; reading it directly can steal messages and it does not cleanly present the current boot log. Option C, tail -f /var/log/boot.log, is incorrect because boot.log contains service startup output from the init/boot process, not kernel messages, and it may not exist on systemd systems. Option E, vmstat -f, is incorrect because it reports the number of forks since boot, which is unrelated to viewing kernel messages.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    journalctl -k

    Why this is correct

    `journalctl -k` reads the kernel ring buffer through systemd's journal, filtering entries to kernel-originated messages only. Because the journal persists per-boot metadata, it can restrict output to the current boot, directly satisfying the requirement to inspect kernel messages from the present boot rather than earlier ones.

  • ✗

    cat /proc/kmsg

    Why it's wrong here

    Reading /proc/kmsg consumes the kernel ring buffer as a stream and typically requires root, so it is not the intended way to review messages from the current boot. It is tempting because it does expose kernel messages, and would be correct when continuously monitoring new kernel output rather than inspecting an existing boot's log.

  • ✗

    tail -f /var/log/boot.log

    Why it's wrong here

    /var/log/boot.log holds service start-up output from the init system, not kernel messages, and may not exist on systemd hosts. journalctl -k or dmesg would be selected when kernel-level boot messages are needed, as the scenario specifies.

  • ✓

    dmesg

    Why this is correct

    `dmesg` reads the kernel ring buffer directly, exposing hardware detection, driver and boot-time messages from the current session. This satisfies the stem's requirement to view kernel messages from the current boot without querying persistent logs, and it works even when the system has not fully reached a graphical target.

  • ✗

    vmstat -f

    Why it's wrong here

    vmstat -f reports the number of forks since boot, a virtual-memory statistic, and reads no kernel log buffer. dmesg or journalctl -k would be chosen when the requirement is kernel messages from the current boot, which is exactly what the scenario asks for.

About these practice questions

One of 781 original XK0-006 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.