Courseiva
Troubleshooting →hardMultiple Choice

XK0-006 Troubleshooting Practice Question

After applying a kernel update, a Linux server boots but the root filesystem is mounted read-only, and dmesg shows I/O errors on /dev/sda2. The administrator needs to determine whether the filesystem is corrupted and, if so, repair it safely. Which sequence of actions should the administrator take?

⚠ Common exam trap

The trap here is running fsck -y directly on the mounted root filesystem, which can turn recoverable corruption into permanent data loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Boot into rescue mode, run fsck -n on /dev/sda2 first, then run fsck -y if errors are reported.

A read-only root mount after I/O errors usually means the kernel detected filesystem problems and remounted defensively. Repair requires the filesystem to be offline, so rescue mode is appropriate. fsck -n first confirms and characterizes the damage without risk; if it reports errors, fsck -y applies repairs. Running fsck on a mounted filesystem, forcing a read-write remount, or reformatting are all unsafe or premature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Recreate the filesystem with mkfs.ext4 /dev/sda2 and restore from the most recent backup.

    Why it's wrong here

    Recreating the filesystem destroys all existing data and is a last resort after repair attempts fail and backups are verified. It is not a diagnostic step and is unnecessary if fsck can fix the errors. The scenario asks to determine whether corruption exists and repair it safely, not to rebuild.

  • ✓

    Boot into rescue mode, run fsck -n on /dev/sda2 first, then run fsck -y if errors are reported.

    Why this is correct

    Booting to rescue mode ensures the root filesystem is not mounted, which is required for a safe check. fsck -n performs a read-only check and reports problems without modifying anything; if errors appear, fsck -y repairs them automatically. This order verifies corruption before committing changes.

  • ✗

    Remount the root filesystem read-write with mount -o remount,rw / and continue using the server.

    Why it's wrong here

    Remounting read-write ignores the underlying I/O errors and filesystem damage. If the filesystem is corrupted, writing to it can worsen the damage and lose data. The read-only mount is a protective response by the kernel, so the correct action is to investigate and repair, not to force writes.

  • ✗

    From the running system, run fsck -y /dev/sda2 immediately to repair the errors.

    Why it's wrong here

    Running fsck on a mounted filesystem, especially the read-only root, can corrupt metadata because the kernel may still hold cached state. Even a read-only mount does not guarantee consistency for repair tools. The filesystem must be unmounted or the system booted into rescue mode before a repair run.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.