Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 1–75

781 questions total · 11pages · All types, answers revealed

Page 1 of 11

Page 2
1
MCQeasy

A junior administrator reports that users cannot connect to a file server running Samba. The server is reachable via ping. Logs from the Samba service show: 'smbd: error while loading shared libraries: libgnutls.so.30: cannot open shared object file: No such file or directory'. The administrator confirms the package 'libgnutls' is installed. Which of the following is the most likely cause and solution?

A.The library path is not set; run ldconfig.
B.The system libraries are out of sync; run apt-get update.
C.The Samba package is corrupted; reinstall Samba.
D.The Samba service is not running; restart it.
AnswerA

Running `ldconfig` rebuilds the dynamic linker's cache (`/etc/ld.so.cache`), letting `smbd` resolve `libgnutls.so.30` at runtime. The package being installed but the library still unfindable points to a stale or missing cache, not a missing file — exactly the constraint the stem describes.

Why this answer

The error 'cannot open shared object file' indicates that the dynamic linker cannot find the libgnutls.so.30 library at runtime, even though the libgnutls package is installed. Running `ldconfig` updates the linker cache, which rebuilds the mapping of shared library names to their actual file paths, resolving the missing library reference for Samba.

Exam trap

The trap here is that candidates see 'package is installed' and assume the library is available, overlooking the need to update the linker cache with `ldconfig` after installation.

How to eliminate wrong answers

Option B is wrong because `apt-get update` only refreshes the package repository metadata, not the runtime linker cache; it does not fix missing shared library references. Option C is wrong because the error is a missing library dependency, not a corrupted Samba binary; reinstalling Samba would not resolve the underlying library path issue. Option D is wrong because the service is already failing to start due to the library error; restarting it without fixing the library path will produce the same error.

2
MCQhard

An administrator is managing a Kubernetes cluster. A pod is running but not responding as expected. The administrator wants to view the standard output logs from the pod's main container. Which kubectl command should be used?

A.kubectl exec <pod-name> -- cat /var/log/app.log
B.kubectl get pod <pod-name> -o yaml
C.kubectl describe pod <pod-name>
D.kubectl logs <pod-name>
AnswerD

kubectl logs retrieves stdout and stderr written by the pod's main container, satisfying the requirement to view standard output. Other verbs such as describe or exec do not stream container logs, so they fail the stated constraint.

Why this answer

The kubectl logs <pod-name> command retrieves the standard output (stdout) and standard error (stderr) logs from a pod's container, which is exactly what the administrator needs. By default it targets the main container; if multiple containers exist, -c <container> specifies one. This is the standard way to view application logs without exec'ing into the container.

Exam trap

The trap is assuming logs live in a file inside the container — candidates pick exec + cat, but Kubernetes captures stdout/stderr, and kubectl logs is the canonical command.

How to eliminate wrong answers

Option A is wrong because kubectl exec runs a command inside the container; cat /var/log/app.log assumes the app writes to that file, which is not guaranteed and does not retrieve the container's stdout stream. Option B is wrong because kubectl get pod -o yaml returns the pod's YAML manifest (spec and status), not runtime logs. Option C is wrong because kubectl describe pod shows events, conditions, and metadata about the pod, useful for troubleshooting scheduling or image pull issues, but not application stdout logs.

3
MCQmedium

An administrator wants to monitor disk I/O performance in real-time, focusing on metrics like wait time and I/O queue size. Which tool is best suited for this?

A.vmstat
B.sar -b
C.free -h
D.iostat -x 1
AnswerD

The -x flag extends iostat output to include per-device metrics such as average wait time (await) and queue size (aqu-sz), while the interval argument 1 refreshes these statistics every second, satisfying the real-time monitoring requirement in the stem.

Why this answer

iostat -x 1 provides extended disk statistics refreshed every second, including await (average wait time), svctm, %util, and avgqu-sz (average queue size), which directly match the requested metrics. The -x flag enables the extended report that exposes per-device wait and queue depth, making it the correct real-time tool.

Exam trap

XK0-006 often tests the distinction between real-time per-device tools (iostat -x) and aggregate or historical tools (vmstat, sar), so candidates who pick vmstat for 'wait time and queue size' fall into the trap of confusing summary I/O counters with extended device metrics.

How to eliminate wrong answers

Option A is wrong because vmstat reports CPU, memory, paging, and block I/O counts but does not expose per-device wait time or I/O queue size. Option B is wrong because sar -b reports historical block I/O activity rates (tps, rtps, wtps, bread/s, bwrtn/s) from collected data, not real-time per-device queue metrics. Option C is wrong because free -h only displays memory and swap usage and has nothing to do with disk I/O.

4
MCQeasy

A Linux administrator needs a cron job that runs /usr/local/bin/collect.sh at 02:30 every Monday, Wednesday, and Friday. The job must be added for the root user without editing the global /etc/crontab file. Which command should the administrator run to open the correct crontab for editing?

A.crontab -l -u root
B.systemctl edit cron
C.crontab -u root -e
D.crontab -e
AnswerC

The -u flag selects the user whose crontab is being edited, so this command always opens root's personal crontab regardless of which account is currently logged in. Entries placed there are executed as root, and the schedule field can specify 30 2 * * 1,3,5 to meet the Monday, Wednesday, and Friday requirement.

Why this answer

The crontab command with the -u option edits the named user's personal crontab, so crontab -u root -e reliably opens root's schedule for modification from any account with the needed privilege. The schedule line 30 2 * * 1,3,5 then executes collect.sh at 02:30 on Monday, Wednesday, and Friday, fulfilling the requirement without touching /etc/crontab.

Exam trap

The trap here is assuming that crontab -e always edits root's table, when it actually targets whichever user invokes it.

5
MCQmedium

A technician needs to check the kernel ring buffer for hardware errors detected during system boot. Which command should be used?

A.journalctl -k
B.lspci
C.dmesg
D.cat /var/log/boot.log
AnswerC

dmesg reads the kernel ring buffer, exposing hardware detection and driver messages logged during boot, including errors. This directly satisfies the requirement to inspect boot-time hardware faults, unlike journalctl or log files that may not capture early kernel output.

Why this answer

The kernel ring buffer contains messages emitted by the kernel, including hardware detection and error messages during boot. The 'dmesg' command reads and prints this buffer directly. It is the canonical tool for inspecting kernel-level hardware errors, driver initialization failures, and boot-time device detection.

Exam trap

The trap is that candidates pick 'journalctl -k' because it also shows kernel messages, but the question asks for the kernel ring buffer specifically, and dmesg is the direct tool for that buffer.

How to eliminate wrong answers

Option A is wrong because 'journalctl -k' also shows kernel messages, but it reads from the systemd journal, which may not capture all early boot messages if the journal is not persistent or if the kernel buffer has wrapped; dmesg reads the kernel ring buffer directly and is the traditional, reliable tool for this purpose. Option B is wrong because 'lspci' lists PCI devices and their details but does not show kernel error messages or boot-time hardware errors. Option D is wrong because '/var/log/boot.log' contains boot-time service messages from the init system, not kernel hardware error messages, and it may not exist on all distributions.

6
MCQeasy

A Linux administrator needs to extract the value of the 'version' field from a JSON file named config.json. The file contains a top-level key 'version' with a string value. Which command should be used to retrieve just the value?

A.jq -r '.version' config.json
B.grep '"version"' config.json
C.sed -n 's/.*"version": *"\(.*\)".*/\1/p' config.json
D.awk -F'"' '/version/ {print $4}' config.json
AnswerA

`jq` is a lightweight and flexible command-line JSON processor. The `-r` option outputs raw strings without quotes. The filter `.version` extracts the value of the top-level 'version' key. This is the correct and reliable way to parse JSON and retrieve a specific field's value, handling formatting and escaping properly.

Why this answer

`jq` is designed specifically for parsing JSON. Using `jq -r '.version'` extracts the value of the 'version' key and outputs it as a raw string. This approach is robust and handles JSON syntax correctly.

Other tools like `grep`, `sed`, or `awk` are text-based and may work in simple cases but are error-prone with JSON's structure and variations.

Exam trap

The trap here is using text-processing tools like `grep` or `awk` for JSON, which can fail when the JSON format changes or contains nested data.

7
MCQmedium

An organization uses Kubernetes to deploy containerized applications. A pod fails to start with an ImagePullBackOff error. What is the most likely cause?

A.The pod exceeded its memory limit
B.The container port is already in use
C.The node is out of disk space
D.The image name is misspelled or does not exist in the registry
AnswerD

A misspelled or non-existent image name causes the kubelet to receive a registry error when pulling, which Kubernetes surfaces as ImagePullBackOff. This directly satisfies the stem's constraint: the pod cannot start because the container image reference cannot be resolved or fetched from the registry.

Why this answer

The ImagePullBackOff error in Kubernetes indicates that the kubelet is unable to pull the container image from the specified registry. The most common cause is a misspelled image name or a non-existent image in the registry, which prevents the container runtime from fetching the image. This triggers a back-off mechanism where the kubelet retries the pull with increasing delays.

Exam trap

CompTIA often tests the distinction between ImagePullBackOff and CrashLoopBackOff, where candidates mistakenly attribute a pull failure to resource limits or port conflicts instead of recognizing it as a registry/image name issue.

How to eliminate wrong answers

Option A is wrong because exceeding the pod's memory limit causes an OOMKill (Out of Memory Kill) error, not ImagePullBackOff; the pod would be terminated with a CrashLoopBackOff or OOM status. Option B is wrong because a container port already in use results in a port conflict error during pod startup, typically manifesting as a 'port already allocated' or 'bind: address already in use' error, not an image pull failure. Option C is wrong because a node running out of disk space leads to an EvictionThreshold or ImageGCFailure, which may prevent pod scheduling or cause pod eviction, but the specific error for image pull failures due to disk space is usually 'ImagePullBackOff' only if the image cannot be downloaded, though the primary symptom of disk pressure is node-level eviction, not a registry-related pull error.

8
MCQmedium

A junior Linux administrator needs to run a long-running backup script as the user 'backupuser' but currently has an active SSH session as 'adminuser'. The script should continue running even if the SSH session disconnects, and no output should be sent to the terminal. Which command should the administrator use?

A.su backupuser -c '/usr/local/bin/backup.sh' &
B.screen -dmS backup sudo -u backupuser /usr/local/bin/backup.sh
C.at now + 0 minutes <<< 'sudo -u backupuser /usr/local/bin/backup.sh'
D.sudo -u backupuser nohup /usr/local/bin/backup.sh > /dev/null 2>&1 &
AnswerD

This command uses sudo -u to switch to backupuser, nohup to ignore SIGHUP, and redirects output to /dev/null. The ampersand backgrounds the process, ensuring it survives SSH disconnection. This is the correct approach for running a script as another user detached from the terminal.

Why this answer

The correct command combines sudo -u to run as backupuser, nohup to ignore hangup signals, and output redirection to /dev/null, with & to background it. This ensures the backup script continues after SSH disconnection and produces no terminal output, meeting both requirements precisely.

Exam trap

The trap here is assuming that simply backgrounding a process with & is enough to survive an SSH session ending, when in fact SIGHUP will still be sent without nohup or disown.

9
Multi-Selectmedium

A system administrator is troubleshooting a custom systemd service that fails to start. Which of the following commands should be used to diagnose the issue? (Choose two.)

Select 2 answers
A.systemctl daemon-reload
B.systemctl status myservice
C.systemctl enable myservice
D.systemctl list-units
E.journalctl -u myservice
AnswersB, E

systemctl status myservice queries systemd directly, reporting the unit's load state, active state, and the most recent log lines, including the exit code that caused the failure. This satisfies the need to diagnose why the custom unit will not start.

Why this answer

Option B, systemctl status myservice, is correct because it displays the current state of the unit, including whether it is active, failed, or inactive, along with the most recent log lines and the exit code, which directly helps diagnose why the service failed to start. Option E, journalctl -u myservice, is correct because it queries the systemd journal for all log messages associated with that specific unit, providing detailed error output, stack traces, or dependency failures needed to pinpoint the root cause. Option A, systemctl daemon-reload, only reloads unit file definitions after edits and does not diagnose a failing service.

Option C, systemctl enable myservice, merely creates symlinks for automatic startup at boot and does not reveal why the service fails. Option D, systemctl list-units, gives a broad overview of loaded units but lacks the per-unit detail and logs required for troubleshooting a specific failed service.

Exam trap

The trap here is that candidates often pick `systemctl daemon-reload` (A) thinking it will fix the issue by reloading unit files, but it does not provide diagnostic output; the exam tests the distinction between reloading configuration and retrieving failure logs.

10
Multi-Selectmedium

A system administrator is writing a Bash script that must check if a file exists and is readable. Which two test expressions can be used to achieve this? (Choose two.)

Select 2 answers
A.-e /path/to/file
B.-s /path/to/file
C.-r /path/to/file
D.-x /path/to/file
E.-f /path/to/file
AnswersA, C

The -e unary test operator returns true when the pathname resolves to an existing file or directory, regardless of type. It satisfies the existence half of the stem's requirement, letting the script confirm the file is present before attempting any read operation.

Why this answer

Option A, `-e /path/to/file`, is correct because the `-e` test in Bash returns true if the file exists, regardless of its type (regular file, directory, device, etc.), which satisfies the existence check. Option C, `-r /path/to/file`, is correct because the `-r` test returns true if the file exists and the current user has read permission on it, satisfying the readability check. Together, `-e` and `-r` cover the two required conditions of existence and readability.

Option B, `-s`, only checks that the file exists and has a size greater than zero, so it does not verify readability. Option D, `-x`, checks for execute permission rather than read permission, so it does not meet the requirement. Option E, `-f`, only checks that the path exists and is a regular file, not that it is readable.

Exam trap

The trap is assuming -f or -s implies readability; -f only checks regular-file type and -s only checks non-zero size, so neither validates the 'readable' requirement.

11
MCQmedium

An Ansible playbook includes a handler that restarts a service when a configuration file is changed. Which directive in a task triggers the handler?

A.register:
B.when:
C.handlers:
D.notify:
AnswerD

The notify directive names the handler to trigger when a task reports changed state, so a config-file modification notifies the restart handler. Handlers run once at play end, avoiding repeated service restarts during the play.

Why this answer

In Ansible, a task uses the notify: directive to name one or more handlers that should be triggered when that task reports a change (i.e., when the task's state is 'changed'). Handlers then run once at the end of the play, in the order they were notified, only if at least one notifying task changed.

Exam trap

The trap is confusing register: (capture output) or when: (conditional execution) with notify:, which is the only directive that actually triggers a handler.

How to eliminate wrong answers

Option A is wrong because register: captures a task's return values into a variable for later use — it does not trigger handlers. Option B is wrong because when: is a conditional that decides whether a task runs at all, based on a Jinja2 expression; it does not invoke handlers. Option C is wrong because handlers: is the top-level play keyword that defines the handler section, not a task-level directive that triggers one.

12
MCQmedium

After a power failure, a Linux server boots into emergency mode. The system logs indicate an unclean filesystem on /dev/sda2. Which command should the administrator run to repair the filesystem?

A.fsck -f /dev/sda2
B.badblocks /dev/sda2
C.xfs_repair /dev/sda2
D.mount -o remount,ro /
AnswerA

fsck -f /dev/sda2 forces a filesystem check and repair on the unclean partition, resolving the inconsistency that triggered emergency mode. The -f flag overrides the mount-count heuristic, ensuring the check runs despite the filesystem appearing otherwise clean.

Why this answer

After a power failure, the system logs indicate an unclean filesystem on /dev/sda2, meaning the filesystem was not properly unmounted and may contain inconsistencies. The `fsck -f /dev/sda2` command forces a filesystem check even if the filesystem appears clean, which is necessary to repair corruption on ext2/ext3/ext4 filesystems. This is the standard tool for checking and repairing such filesystems after an unclean shutdown.

Exam trap

The trap here is that candidates may confuse filesystem repair tools (fsck vs. xfs_repair) or mistake a disk surface scan (badblocks) for a filesystem consistency check, leading them to choose an inappropriate command for the specific filesystem type.

How to eliminate wrong answers

Option B is wrong because `badblocks` scans for physical bad sectors on the disk, not filesystem metadata corruption; it does not repair filesystem inconsistencies. Option C is wrong because `xfs_repair` is used for XFS filesystems, but /dev/sda2 is likely an ext4 filesystem (common on Linux) and the question does not specify XFS; using the wrong repair tool can cause further damage. Option D is wrong because `mount -o remount,ro /` only remounts the root filesystem as read-only to prevent further writes, but it does not repair the underlying filesystem corruption.

13
MCQmedium

A Linux administrator needs to change the runlevel of a systemd-based system to a state where only a single user can log in for maintenance, without starting network services. Which systemd target should the administrator use?

A.emergency.target
B.multi-user.target
C.graphical.target
D.rescue.target
AnswerD

The rescue.target is a systemd target that provides a single-user environment with basic system services, but does not start network services. It is equivalent to the traditional runlevel 1 (single-user mode). This target is designed for maintenance and allows only the root user to log in on the console.

Why this answer

The rescue.target is the systemd equivalent of single-user mode, providing a minimal environment with only essential services and no networking. It allows the administrator to log in as root for maintenance tasks. The emergency.target is more restrictive and mounts the root filesystem read-only, while multi-user and graphical targets start networking and multiple users.

Therefore, rescue.target is the correct choice.

Exam trap

The trap here is confusing rescue.target with emergency.target; rescue.target provides a usable single-user shell with basic services, while emergency.target is even more minimal and may not allow normal login.

14
MCQeasy

A Linux administrator schedules a maintenance script with cron using the entry `30 2 * * 1 /usr/local/bin/backup.sh`. The script runs but produces no output and fails silently when executed by cron, though it works when run interactively. Which action best addresses the silent failure?

A.Move the script to `/etc/cron.d/` so it inherits the system environment.
B.Redirect the script's stdout and stderr to a log file within the crontab entry or script.
C.Add the `nohup` command before the script path in the crontab line.
D.Change the schedule to run every minute so the failure is observed sooner.
AnswerB

Cron captures any output and mails it, but if mail is unconfigured the output is discarded, so failures go unnoticed. Redirecting stdout and stderr to a file captures cron's environment-specific errors, such as missing PATH entries or permissions, enabling diagnosis. This directly resolves the lack of visibility that makes the cron run appear to fail silently.

Why this answer

Cron runs jobs with a minimal environment and no terminal, so interactive successes can become silent failures. Because cron only emails output when a mail transfer agent is configured, failures frequently vanish. Capturing stdout and stderr to a log file exposes the environment-related errors, such as an incomplete PATH or missing variables, that cause the discrepancy between interactive and scheduled execution.

Exam trap

The trap here is believing that moving a cron job's location or adding `nohup` fixes environment-related failures rather than capturing their output.

15
MCQeasy

An administrator needs to allow a user to run all commands as root without a password. Which sudoers entry accomplishes this?

A.user ALL=(ALL) NOPASSWD: ALL
B.user ALL=(ALL) !ALL
C.user ALL=(ALL) PASSWD: ALL
D.user ALL=(ALL) ALL
AnswerA

The NOPASSWD tag disables the password prompt for matching commands, and ALL in the command field permits every binary. Combined with ALL=(ALL) runas and host specifications, this grants the user unrestricted root execution without authentication, exactly as the policy demands.

Why this answer

The sudoers entry `user ALL=(ALL) NOPASSWD: ALL` grants the user permission to run any command as any user (including root) without being prompted for a password. The `NOPASSWD` tag overrides the default password requirement, and the `ALL` specifications cover the host list, target user list, and command list.

Exam trap

The trap here is that candidates often confuse the default behavior of `ALL` (which still requires a password) with the `NOPASSWD` tag, leading them to select option D thinking it allows passwordless execution.

How to eliminate wrong answers

Option B is wrong because `user ALL=(ALL) !ALL` uses the negation operator `!` to deny all commands, effectively preventing the user from running any command via sudo. Option C is wrong because `user ALL=(ALL) PASSWD: ALL` explicitly requires a password (the default behavior), so the user would still be prompted for a password. Option D is wrong because `user ALL=(ALL) ALL` is the standard sudoers entry that allows all commands but still requires the user to enter their own password (unless the `NOPASSWD` tag is present).

16
MCQmedium

A container is running a web server on port 8080 internally, and the administrator wants to access it on the host on port 80. Which Docker run option accomplishes this?

A.-p 80:8080
B.-P
C.-p 8080:80
D.--expose 8080
AnswerA

Publishing with `-p 80:8080` maps host port 80 to container port 8080, satisfying the requirement to reach the internal web server on the host's privileged HTTP port. Docker's port syntax is host:container, so the left value is the externally exposed port and the right is the container's listening port.

Why this answer

The Docker -p flag maps a host port to a container port using the syntax -p HOST_PORT:CONTAINER_PORT. Since the container listens on 8080 internally and the administrator wants it reachable on host port 80, the correct mapping is -p 80:8080. This publishes the container's port 8080 to the host's port 80.

Exam trap

The trap here is reversing the -p syntax — candidates frequently write -p 8080:80 thinking the container port comes first, but Docker always expects HOST_PORT:CONTAINER_PORT.

How to eliminate wrong answers

Option B is wrong because -P (capital P) publishes all exposed ports to random ephemeral host ports, which does not guarantee port 80. Option C is wrong because -p 8080:80 reverses the mapping, publishing container port 80 to host port 8080, which does not match the requirement. Option D is wrong because --expose only documents a port for inter-container communication and does not publish it to the host at all.

17
MCQhard

A system administrator wants to create a bind mount in Docker to share a host directory `/data` with a container at `/mnt/data`. Which of the following docker run options should be used?

A.-v /data:/mnt/data
B.--mount type=volume,source=/data,target=/mnt/data
C.-v /data:ro
D.-v /mnt/data:/data
AnswerA

The `-v /data:/mnt/data` flag creates a bind mount by mapping an absolute host path to a container path, satisfying the requirement to share `/data` at `/mnt/data`. Docker interprets the leading slash as a host filesystem location rather than a named volume, giving the container direct read-write access to that directory.

Why this answer

The -v /data:/mnt/data option creates a bind mount by mapping the host directory /data to the container path /mnt/data, which is exactly the requirement. Docker interprets a host path on the left of the colon as a bind mount, distinguishing it from a named volume. This is the classic syntax for sharing a host directory with a container.

Exam trap

The trap is confusing the -v shorthand with --mount syntax — candidates pick the --mount option assuming it is 'more modern,' but type=volume is wrong for a host-directory bind mount, which requires type=bind.

How to eliminate wrong answers

Option B is wrong because --mount type=volume declares a named volume, not a bind mount — for a bind mount the correct syntax is --mount type=bind,source=/data,target=/mnt/data, and using type=volume with a host path will fail or create an unexpected volume. Option C is wrong because -v /data:ro specifies only a container path with read-only mode, missing the host path entirely, so it does not create the intended bind mount. Option D is wrong because -v /mnt/data:/data reverses the source and target, mounting the host's /mnt/data into the container at /data, which is the opposite of what was requested.

18
MCQmedium

An administrator wants to replace all occurrences of 'oldstring' with 'newstring' in a configuration file named config.cfg, and save the changes. Which sed command should be used?

A.sed -i 's/oldstring/newstring/' config.cfg
B.sed -i 's/oldstring/newstring/g' config.cfg
C.sed -i 's/oldstring/newstring/gi' config.cfg
D.sed 's/oldstring/newstring/' config.cfg
AnswerB

The -i flag edits config.cfg in place, satisfying the requirement to save changes, and the g flag replaces every occurrence of oldstring on each line with newstring. Omitting g would substitute only the first match per line, leaving later instances unchanged.

Why this answer

It uses -i for in-place editing and g to replace all occurrences on each line. Option A has -i but lacks g, so it replaces only the first occurrence per line. Option C adds an unnecessary i flag for case-insensitive matching, which deviates from the requirement to replace 'oldstring' exactly as given.

Option D lacks -i, so changes are only printed to stdout and not saved.

19
MCQeasy

A user wants to run a Docker container in detached mode, remove it automatically after it stops, and map host port 8080 to container port 80. Which command accomplishes this?

A.docker run -d --rm -p 8080:80 image
B.docker run -it --rm -p 80:8080 image
C.docker create --rm -p 8080:80 image
D.docker start -d -p 8080:80 image
AnswerA

The -d flag detaches the container, --rm deletes it automatically once stopped, and -p 8080:80 publishes host port 8080 to container port 80. All three stem constraints are satisfied in a single command, with the image name supplied last as the positional argument.

Why this answer

The `docker run` command is the correct choice because it combines container creation and startup in a single step. The `-d` flag runs the container in detached mode (in the background), `--rm` automatically removes the container filesystem when it exits, and `-p 8080:80` maps host port 8080 to container port 80. Together these flags satisfy all three requirements in one command.

Exam trap

The trap here is confusing `docker create` with `docker run` and assuming `docker start` can apply port mappings — candidates often forget that port bindings and `--rm` are fixed at container creation time and cannot be added later.

How to eliminate wrong answers

Option B is wrong because `-it` allocates an interactive TTY and keeps the container attached to the terminal, which is the opposite of detached mode, and it also reverses the port mapping to `80:8080`. Option C is wrong because `docker create` only creates the container without starting it, and `--rm` is not a valid flag for `docker create` in that context. Option D is wrong because `docker start` is used to restart an existing stopped container and does not accept `-p` port mapping or `-d` in the same way `docker run` does; port mappings must be specified at creation time.

20
MCQmedium

A system administrator wants to change the priority of a running process with PID 1234 to a lower priority (higher nice value). Which command should be used?

A.renice -n 10 -p 1234
B.renice -n -10 -p 1234
C.chrt -p 10 1234
D.nice -n 10 -p 1234
AnswerA

`renice -n 10 -p 1234` adjusts the nice value of an already-running process, satisfying the stem's requirement to alter priority without restarting it. The `-p` flag targets PID 1234 directly, and a positive nice value of 10 lowers scheduling priority, unlike `nice`, which only sets priority when launching a new process.

Why this answer

renice is used to change the nice value of an existing process. A higher nice value means lower priority.

21
MCQhard

Based on the exhibit, what is the most likely cause of the 'PV Status: not available'?

A.The volume group is corrupted.
B.The logical volume is not mounted.
C.LVM metadata is damaged.
D.The physical volume is missing or disconnected.
AnswerD

LVM marks a physical volume 'not available' when the underlying block device cannot be found, typically because the disk was removed, disconnected, or failed to initialise. Restoring the device or rescanning the volume group resolves the status.

Why this answer

The 'PV Status: not available' message in LVM indicates that the system cannot access the physical volume. This typically occurs when the underlying disk or partition is missing, disconnected, or has failed. Since LVM relies on the physical volume being present for volume group and logical volume operations, a missing or disconnected physical volume is the most direct cause.

Exam trap

The trap here is that candidates often confuse 'PV Status: not available' with LVM metadata corruption, but the status specifically indicates the device is inaccessible, not that its metadata is damaged.

How to eliminate wrong answers

Option A is wrong because a corrupted volume group would typically show errors related to the volume group itself (e.g., 'VG not found' or 'VG metadata missing'), not a per-physical-volume status of 'not available'. Option B is wrong because the mount status of a logical volume is unrelated to the physical volume's availability; a logical volume can be unmounted while its PV status remains 'available'. Option C is wrong because damaged LVM metadata would likely produce errors during LVM commands (e.g., 'metadata inconsistency' or 'failed to read metadata'), not a simple 'PV Status: not available' which points to a missing device.

22
MCQmedium

A developer is writing a Bash script that must be portable across different Linux distributions. The script needs to check if a package is installed. Which command should be used to achieve this portability?

A.which package
B.command -v package
C.dpkg -l package
D.rpm -q package
AnswerB

POSIX-compliant.

Why this answer

The `command -v package` command is the most portable way to check if a package is installed across different Linux distributions because it uses the POSIX-standard `command` shell built-in, which works in any Bourne-compatible shell (bash, sh, dash, etc.) regardless of the underlying package manager. It returns the path to the executable if the package's binary is in the PATH, or nothing if it is not installed, making it distribution-agnostic.

Exam trap

The trap here is that candidates often choose `dpkg` or `rpm` because they are familiar with checking packages on their own distribution, but the question explicitly requires portability across different Linux distributions, making the distribution-agnostic `command -v` the correct choice.

How to eliminate wrong answers

Option A is wrong because `which package` is not a POSIX-standard command and its behavior can vary across distributions; it may not be installed by default or may produce different exit codes, reducing portability. Option C is wrong because `dpkg -l package` is specific to Debian-based distributions (e.g., Ubuntu) and will fail or be unavailable on Red Hat-based or other distributions. Option D is wrong because `rpm -q package` is specific to Red Hat-based distributions (e.g., CentOS, Fedora) and will not work on Debian-based or other package management systems.

23
MCQmedium

A Linux administrator is preparing a new server that uses systemd-boot as the boot loader. The administrator wants to verify the current boot loader entries and their order. Which command should the administrator run?

A.efibootmgr -v
B.grub-mkconfig -o /boot/grub/grub.cfg
C.systemctl status systemd-boot
D.bootctl list
AnswerD

The bootctl command is the systemd-boot manager. With the list subcommand, it enumerates all boot loader entries found in the EFI system partition and shows their order, including the default entry. This directly fulfills the requirement to verify the current entries and their order on a system using systemd-boot.

Why this answer

The bootctl list command displays all systemd-boot entries and their sequence, which is exactly what the administrator needs to verify the boot loader configuration on a system using systemd-boot. The other tools either manage different boot loaders (GRUB), interact with UEFI firmware (efibootmgr), or assume systemd-boot is a service (systemctl), so they do not provide the required information.

Exam trap

The trap here is assuming that efibootmgr shows systemd-boot entry order, but efibootmgr only shows UEFI firmware boot entries, not systemd-boot configuration files.

24
MCQhard

An application running under an AppArmor profile is being denied access to log files. The administrator wants to troubleshoot by allowing all actions and logging denials. Which command will switch the profile to complain mode?

A.aa-complain /path/to/profile
B.aa-enforce /path/to/profile
C.aa-disable /path/to/profile
D.aa-status
AnswerA

Complain mode makes the AppArmor profile report denials rather than block them, satisfying the requirement to allow all actions while logging. Running aa-complain against the profile path switches it from enforce to complain, letting the application reach its log files immediately.

Why this answer

The `aa-complain` command places an AppArmor profile into complain mode, which allows all actions but logs denials to the system log. This is the correct tool for troubleshooting because it lets the administrator see what the application is trying to do without actually blocking it.

Exam trap

The trap here is confusing `aa-complain` with `aa-enforce`, as candidates often assume that logging denials requires enforcement mode, but complain mode is specifically designed for logging without blocking.

How to eliminate wrong answers

Option B is wrong because `aa-enforce` activates enforcement mode, which actively blocks denied actions and logs them, not allowing all actions as required. Option C is wrong because `aa-disable` completely disables the AppArmor profile, removing all logging and access controls, which does not meet the requirement to log denials. Option D is wrong because `aa-status` only displays the current status of AppArmor profiles (e.g., which are in enforce or complain mode) and does not change the profile mode.

25
MCQhard

A file named 'webapp.conf' is being served by Apache but users get a 'Permission denied' error. The SELinux context of the file is 'unconfined_u:object_r:admin_home_t:s0'. What is the most appropriate command to fix the SELinux context?

A.semanage fcontext -a -t httpd_sys_content_t webapp.conf && restorecon -v webapp.conf
B.setenforce 0
C.chcon -t httpd_sys_content_t webapp.conf
D.restorecon -v webapp.conf
AnswerA

The file carries the admin_home_t type, which Apache's httpd_t domain cannot read, causing the denial. `semanage fcontext -a -t httpd_sys_content_t` adds a persistent mapping in the file-context policy, and `restorecon` applies it to webapp.conf, satisfying the requirement that the file hold the httpd content type.

Why this answer

The most appropriate command. It adds a persistent SELinux file context rule with semanage fcontext and then applies it with restorecon, ensuring the correct type (httpd_sys_content_t) is set and preserved across system relabeling. Option D (restorecon alone) may not work if the file's path lacks a default mapping in the SELinux policy, making it unreliable for non-standard locations.

Therefore, only A fully addresses the requirement for a permanent and reliable fix.

Exam trap

The trap is that candidates often choose chcon (option C) because it works immediately without additional commands. However, chcon changes are not persistent across file relabeling (e.g., after a full restorecon or system policy update), making semanage fcontext the recommended approach for a permanent fix.

How to eliminate wrong answers

Option B is wrong because 'setenforce 0' disables SELinux entirely, which is a security risk and not a proper fix for the context mismatch; it only masks the issue. Option C is wrong because 'chcon -t httpd_sys_content_t webapp.conf' changes the context temporarily but does not update the SELinux policy database, so the change will be lost after a file system relabel or 'restorecon' run. Option D is wrong because 'restorecon -v webapp.conf' alone will reset the file to its default context based on the current policy, but since no persistent rule exists for this file, it will revert to 'admin_home_t' (or another default) and not fix the permission error.

26
MCQeasy

A Linux administrator wants to ensure a bash script stops execution immediately if any command fails. Which line should be added to the script?

A.set -x
B.set -u
C.set -e
D.set -o pipefail
AnswerC

`set -e` makes bash exit immediately when any command returns a non-zero status, satisfying the requirement that the script halt on first failure. Unlike `set -u` (unset variables) or `set -x` (trace output), it targets command failure directly, preventing subsequent commands from running after an error.

Why this answer

`set -e` instructs bash to exit immediately if any command returns a non-zero exit status, which is exactly the fail-fast behavior the administrator wants. This prevents subsequent commands from running after a failure, avoiding cascading errors in scripts. It is the standard idiom for making bash scripts robust in automation and CI environments.

Exam trap

The trap is that candidates confuse the four `set` flags — especially `set -u` (unset variable check) and `set -o pipefail` (pipeline exit status) — with `set -e`, which is the only one that provides the general 'exit on any command failure' behavior.

How to eliminate wrong answers

Option A is wrong because `set -x` enables trace mode, printing each command and its arguments to stderr before execution — it is a debugging aid, not an error-handling mechanism. Option B is wrong because `set -u` treats unset variables as an error and exits, which catches typos in variable names but does not stop execution on general command failures. Option D is wrong because `set -o pipefail` only changes the exit status of a pipeline to reflect the rightmost non-zero command; by itself it does not cause the script to exit on failure unless combined with `set -e`.

27
Multi-Selectmedium

A Linux administrator is packaging an internal automation tool as a container image and must ensure the resulting image is minimal, reproducible, and does not include a shell or package manager. Which TWO practices best support that goal? (Choose two.)

Select 2 answers
A.Build the application as a static binary and copy it into a scratch or distroless base image
B.Add a RUN apk add --no-cache bash step so operators can exec into the container for debugging
C.Tag the image as latest and rebuild it nightly from the moving base image to keep it current
D.Run the container as root so the entrypoint can install missing packages at startup
E.Use a multi-stage Dockerfile where the builder stage compiles the tool and the final stage copies only the artifact
AnswersA, E

A static binary needs no shared libraries, so it can run on a base image that contains no shell, package manager, or libc. This shrinks the attack surface and image size while making the runtime contents deterministic, which directly matches the requirement to exclude a shell and package manager from the shipped image.

Why this answer

Minimal container images combine a static or self-contained artifact with a base image that ships no shell or package manager, and multi-stage builds keep all compilation tooling out of the final layer. Together these practices produce small, reproducible images whose contents are limited to what the application needs at runtime, with no interactive tooling available to an attacker.

Exam trap

The trap here is treating a debugging shell or nightly rebuild as harmless convenience, when both quietly violate the minimal and reproducible image requirements.

28
MCQeasy

Which file contains the password aging information such as minimum and maximum days between password changes?

A./etc/shadow
B./etc/security/limits.conf
C./etc/passwd
D./etc/login.defs
AnswerA

/etc/shadow stores per-user password aging fields, including minimum days, maximum days, warning period and expiry, alongside the hashed password. This directly satisfies the stem's requirement for minimum and maximum days between password changes, unlike /etc/passwd, which holds account data but no aging constraints.

Why this answer

The /etc/shadow file stores encrypted password hashes along with password aging fields: the date of last password change, minimum days before change allowed, maximum days the password is valid, warning days before expiration, inactivity days, and account expiration date. These aging parameters are set by chage or passwd and are enforced by PAM. /etc/passwd no longer stores password hashes on modern systems and does not contain aging fields.

Exam trap

XK0-006 often tests the confusion between /etc/login.defs (system-wide defaults for new accounts) and /etc/shadow (per-user actual aging data), causing candidates to pick login.defs when the question asks where the aging information is stored.

How to eliminate wrong answers

Option B is wrong because /etc/security/limits.conf defines resource limits (e.g., max open files, max processes) for users and groups via PAM's pam_limits module — it has nothing to do with password aging. Option C is wrong because /etc/passwd contains user account information (username, UID, GID, GECOS, home directory, shell) and historically the password hash, but on modern systems the password field is 'x' and aging data is not present there. Option D is wrong because /etc/login.defs contains system-wide defaults for useradd and password policies (e.g., PASS_MAX_DAYS, PASS_MIN_DAYS, PASS_WARN_AGE), but it holds defaults applied at account creation, not the per-user aging information itself — the question asks for the file containing the aging information, which is /etc/shadow.

29
MCQmedium

A security analyst needs to see a list of failed login attempts on a Linux system. Which command displays this information from the /var/log/btmp log?

A.lastb
B.lastlog
C.last
D.faillog
AnswerA

`lastb` reads the binary `/var/log/btmp` record file and prints each failed login attempt with its timestamp, source host and username. Since the stem explicitly requires displaying failed logins from that specific log, `lastb` is the matching tool; `last` reads `/var/log/wtmp` for successful sessions instead.

Why this answer

The `lastb` command reads the `/var/log/btmp` file, which specifically records failed login attempts. It displays a list of bad logins, including the username, terminal, source IP, and timestamp. This is the correct tool for auditing failed authentication events on Linux.

Exam trap

The trap here is confusing the four similar-sounding commands: `lastb` (failed logins from btmp), `lastlog` (last successful login per user from lastlog), `last` (successful login history from wtmp), and `faillog` (failed login counts from faillog). Candidates often mix up `lastb` and `faillog` because both relate to failures, but only `lastb` reads btmp.

How to eliminate wrong answers

Option B is wrong because `lastlog` reads `/var/log/lastlog` and shows the most recent successful login for each user, not failed attempts. Option C is wrong because `last` reads `/var/log/wtmp` and displays successful login history, including logins, logouts, and system reboots. Option D is wrong because `faillog` reads `/var/log/faillog` and shows failed login counts and lockout information per user, but it does not list individual failed attempts from btmp.

30
MCQeasy

A Linux administrator needs to check which services are listening on TCP port 22. Which command should be used?

A.ss -tlnp | grep :22
B.ping -p 22 localhost
C.ip addr show port 22
D.traceroute -p 22 localhost
AnswerA

ss -tlnp lists TCP sockets in listening state with numeric ports and the owning process, and the grep filter narrows output to port 22. This satisfies the stem's constraint of identifying services listening on TCP 22, showing the sshd process bound to that port.

Why this answer

The 'ss' command (socket statistics) with the -tlnp flags lists TCP (-t) listening (-l) sockets with numeric ports (-n) and the owning process (-p). Piping to grep :22 filters for port 22, showing which service is listening on SSH. This is the modern replacement for netstat and is available on all current Linux distributions.

Exam trap

XK0-006 often tests the confusion between network diagnostic tools (ping, traceroute) and socket inspection tools (ss, netstat, lsof) — candidates must recognize that only ss/netstat/lsof can show listening services.

How to eliminate wrong answers

Option B is wrong because 'ping -p 22' sets the pattern of bytes in ICMP echo packets — it does not probe TCP port 22 and cannot identify listening services. Option C is wrong because 'ip addr show' displays IP addresses on interfaces; it has no concept of ports or listening services. Option D is wrong because 'traceroute -p 22' sets the destination UDP port for traceroute probes — it traces the network path, not local listening services.

31
MCQeasy

Which command is used to display the contents of the systemd journal for a specific unit?

A.systemctl status unit
B.dmesg
C.journalctl -f
D.journalctl -u
AnswerD

Using `journalctl -u` filters the systemd journal by unit name, satisfying the requirement to display entries for one specific unit. The `-u` flag accepts a unit such as `sshd.service`, restricting output to that unit's messages rather than the entire journal.

Why this answer

journalctl -u unitname displays logs for the specified systemd unit.

32
Multi-Selectmedium

Which TWO of the following are characteristics of containers compared to virtual machines? (Choose two.)

Select 2 answers
A.Containers run their own kernel.
B.Each container has its own operating system.
C.Containers use hypervisor for isolation.
D.Containers require less overhead than VMs.
E.Containers typically start in seconds.
AnswersD, E

Sharing the host kernel removes the need to run a complete guest operating system per instance, so containers consume fewer CPU, memory and storage resources than virtual machines. That reduced overhead allows higher workload density on the same physical host.

Why this answer

Option D is correct because containers share the host OS kernel and therefore avoid the resource cost of running a full guest operating system and hardware emulation, giving them a smaller footprint and lower CPU, memory, and storage overhead than VMs. Option E is correct because a container is essentially a packaged process that starts almost instantly (often in seconds or less) since it does not need to boot an entire operating system and initialize virtual hardware as a VM does. Options A and B are incorrect because containers share the host kernel and do not run their own kernel or full operating system; that is a characteristic of virtual machines.

Option C is incorrect because containers achieve isolation through OS-level mechanisms such as namespaces and cgroups, not through a hypervisor, which is used by VMs.

Exam trap

The trap here is that candidates often confuse container isolation with hypervisor-based isolation, mistakenly thinking containers run their own kernel or OS, when in fact they share the host kernel and use namespaces/cgroups.

33
MCQeasy

A user reports that the /home partition is running out of space. Which command identifies the largest directories under /home?

A.du -sh /home/*
B.df -h /home
C.ls -lhS /home
D.find /home -type d -size +100M
AnswerA

du -sh /home/* reports the total disk usage of each immediate entry under /home in human-readable form, revealing which directories consume the most space. This directly identifies the largest directories, satisfying the reported out-of-space constraint.

Why this answer

`du -sh /home/*` calculates the disk usage of each top-level item under /home, with `-s` summarizing each directory and `-h` providing human-readable sizes. This directly identifies the largest directories consuming space, which is exactly what the user needs to troubleshoot the /home partition running out of space.

Exam trap

The trap here is that candidates confuse `df` (filesystem-level usage) with `du` (directory-level usage), or assume `ls -lhS` or `find -size` can accurately report directory disk consumption, when only `du` correctly accounts for all nested file contents.

How to eliminate wrong answers

Option B is wrong because `df -h /home` shows the overall disk usage and available space of the /home filesystem, not the sizes of individual directories within it. Option C is wrong because `ls -lhS /home` lists files and directories sorted by size, but it only shows metadata (not recursive disk usage) and may miss large subdirectory contents. Option D is wrong because `find /home -type d -size +100M` looks for directories with a size attribute greater than 100 MB, but directories typically have a small metadata size (e.g., 4 KB) regardless of their contents, so this command will rarely return useful results.

34
MCQmedium

A security policy requires that system logs be rotated weekly and kept for 4 weeks. Which configuration file should be modified to achieve this for /var/log/syslog?

A./etc/security/limits.conf
B./etc/rsyslog.conf
C./etc/logrotate.conf
D./etc/audit/auditd.conf
AnswerC

Editing /etc/logrotate.conf sets global rotation defaults, where the weekly directive satisfies the seven-day rotation constraint and rotate 4 retains four weeks of archives before deletion. Per-service overrides belong in /etc/logrotate.d/, but the stem asks which file governs rotation policy, making this the correct target.

Why this answer

Log rotation is managed by logrotate, not by rsyslog or syslog itself. The /etc/logrotate.conf file contains global rotation settings, including frequency (weekly) and retention count (rotate 4). Adding or modifying a configuration block for /var/log/syslog in logrotate.conf (or a file in /etc/logrotate.d/) directly implements the policy requirement.

Exam trap

CompTIA often tests the distinction between log generation (rsyslog.conf) and log rotation (logrotate.conf), so candidates mistakenly choose /etc/rsyslog.conf because they associate it with log management, not realizing rotation is a separate function.

How to eliminate wrong answers

Option A is wrong because /etc/security/limits.conf controls system resource limits (e.g., file handles, processes) per user via PAM, not log rotation. Option B is wrong because /etc/rsyslog.conf configures the rsyslog daemon’s logging rules, outputs, and facilities, but does not handle rotation or retention of log files. Option D is wrong because /etc/audit/auditd.conf configures the audit daemon (auditd) for kernel audit events, not general system log rotation.

35
MCQhard

Based on the exhibit, what is the purpose of the audit rule?

A.Monitor open syscalls on a specific file.
B.Monitor all open syscalls by the root user.
C.Monitor all open syscalls by users with UID 1000 or higher.
D.Monitor all open syscalls except those by users with UID 1000 or higher.
AnswerC

The audit rule's filter specifies UID >= 1000, which on Linux excludes system and service accounts below that threshold. It therefore logs every syscall made by ordinary user accounts, matching the stated purpose of monitoring non-privileged user activity.

Why this answer

The audit rule `-a always,exit -F arch=b64 -S open -F uid>=1000 -k monitor_open` uses the `uid>=1000` filter to match only system calls made by users with UID 1000 or higher. This is a common Linux auditd rule to track user-level activity while excluding system accounts (typically UIDs below 1000). Option C correctly identifies that the rule monitors all open syscalls by users with UID 1000 or higher.

Exam trap

CompTIA often tests the direction of comparison operators in audit rules — candidates frequently confuse `uid>=1000` (monitor UIDs 1000 and above) with `uid<1000` (monitor UIDs below 1000), leading them to select the exclusion-based option D instead of the correct inclusion-based option C.

How to eliminate wrong answers

Option A is wrong because the rule does not specify a particular file path; it monitors the open syscall system-wide, not on a specific file. Option B is wrong because the rule uses `uid>=1000`, which excludes the root user (UID 0) from being monitored; root's open syscalls are not captured. Option D is wrong because the rule includes users with UID 1000 or higher, not excludes them; the `>=` operator means 'greater than or equal to', so it matches those UIDs.

36
MCQmedium

A server shows /dev/sda1 mounted at / is 100% full in df -h, but du -sh / shows only 50% usage. What is the most likely explanation?

A.The filesystem is corrupted
B.Hidden files are not counted by du
C.A process is still holding a deleted file open
D.The disk has many hard links
AnswerC

A deleted file whose inode remains open by a running process still consumes disk blocks, so df counts them while du cannot see the unlinked path. Restarting or reloading that process releases the space, reconciling the 100% versus 50% discrepancy.

Why this answer

When a file is deleted but still held open by a running process, the file's inode remains allocated and its disk blocks are not freed until the process closes the file descriptor. The `df` command reports filesystem usage by querying the superblock for total and free blocks, so it still counts the space occupied by the deleted-but-open file. In contrast, `du` traverses the directory tree and sums the sizes of files reachable from the specified path; since the deleted file is no longer linked in the directory, `du` does not include it, leading to the discrepancy.

Exam trap

The trap here is that candidates assume `du` and `df` should always match, and they overlook the classic Linux behavior where a file deleted while still open consumes space invisible to `du` but visible to `df`.

How to eliminate wrong answers

Option A is wrong because filesystem corruption typically causes inconsistent or erroneous output from both `df` and `du`, not a consistent discrepancy where `df` shows 100% and `du` shows 50%; corruption would likely produce errors or unmountable filesystems. Option B is wrong because `du -sh /` by default counts all files, including hidden files (those starting with a dot), as it traverses the entire directory tree; hidden files are not excluded unless specific exclusions are used. Option D is wrong because hard links do not consume additional disk space beyond the original inode; `du` counts the file's size once per inode, and `df` reports total allocated blocks, so hard links would not cause a 50% discrepancy between the two commands.

37
MCQhard

An administrator needs to schedule a backup script to run every Monday at 2:00 AM. Which crontab entry will accomplish this?

A.2 0 * * 1 /path/to/backup.sh
B.0 2 * * 0 /path/to/backup.sh
C.0 2 1 * * /path/to/backup.sh
D.0 2 * * 1 /path/to/backup.sh
AnswerD

This crontab entry specifies minute 0, hour 2, any day of month, any month, and day of week 1 (Monday). It correctly runs the backup script at 2:00 AM every Monday. The fields are in the order: minute, hour, day of month, month, day of week, command.

Why this answer

The correct crontab entry must set minute to 0, hour to 2, and day of week to 1 (Monday). The fields are minute, hour, day of month, month, day of week, command. The entry '0 2 * * 1 /path/to/backup.sh' satisfies these conditions and schedules the backup for every Monday at 2:00 AM.

Exam trap

The trap here is mixing up the order of hour and minute fields, or confusing day of week numbering where 0 is Sunday and 1 is Monday.

38
MCQmedium

An administrator needs to extend the size of a logical volume named 'lv_data' in volume group 'vg_data' by 10 GB. A new disk /dev/sdb has been added to the system. What is the correct sequence of commands?

A.pvcreate /dev/sdb; vgextend vg_data /dev/sdb; lvextend -L +10G /dev/vg_data/lv_data
B.lvextend -L +10G /dev/vg_data/lv_data; vgextend vg_data /dev/sdb; pvcreate /dev/sdb
C.vgextend vg_data /dev/sdb; pvcreate /dev/sdb; lvextend -L +10G /dev/vg_data/lv_data
D.pvcreate /dev/sdb; lvextend -L +10G /dev/vg_data/lv_data; vgextend vg_data /dev/sdb
AnswerA

Initialising /dev/sdb with pvcreate makes it a physical volume, then vgextend adds it to vg_data, supplying the free extents the 10 GB growth requires. lvextend -L +10G then extends lv_data by exactly 10 GB within that enlarged group, satisfying the stem's sequence and size constraint.

Why this answer

It follows the proper sequence for extending a logical volume when a new disk is added: first, initialize the new disk as a physical volume with pvcreate; second, add the physical volume to the volume group with vgextend; third, extend the logical volume by the desired size with lvextend. This order ensures the volume group has available physical extents before attempting to allocate them to the logical volume.

Exam trap

The trap here is that candidates often assume lvextend can be run first because they think the volume group already has space, but the question explicitly states a new disk must be added, so the correct order requires preparing the disk and volume group before extending the logical volume.

How to eliminate wrong answers

Option B is wrong because it attempts to extend the logical volume before the new disk is added to the volume group, which would fail due to insufficient free extents in vg_data. Option C is wrong because it tries to extend the volume group with a disk that has not yet been initialized as a physical volume, causing vgextend to fail. Option D is wrong because it extends the logical volume before adding the physical volume to the volume group, resulting in an error as the volume group lacks the necessary free space.

39
MCQeasy

A Linux administrator is configuring a systemd timer to run a maintenance script daily. The administrator creates maint.service and maint.timer unit files, then runs systemctl start maint.timer. The script does not run at the expected time. Which command should the administrator run to enable the timer so it starts automatically at boot and triggers on schedule?

A.systemctl reload maint.timer
B.systemctl enable maint.service
C.systemctl enable maint.timer
D.systemctl daemon-reexec
AnswerC

Enabling a timer creates the symlink needed for it to be started at boot by systemd, allowing its schedule to fire reliably. Starting a timer only activates it for the current session; enabling ensures persistence across reboots, which is required for a recurring daily maintenance task in this scenario.

Why this answer

A systemd timer must be enabled, not merely started, to be activated at boot. Enabling creates the appropriate symlink in the timer's target directory so systemd starts it automatically, and the timer then triggers the associated service according to its OnCalendar or OnUnitActiveSec schedule. Enabling the service or reloading the unit does not achieve persistent scheduled execution.

Exam trap

The trap here is confusing systemctl start, which activates a unit only for the current session, with systemctl enable, which ensures the unit starts at boot.

40
MCQeasy

Which of the following is a key difference between Docker and Podman?

A.Docker does not support container images.
B.Podman can run containers without root privileges.
C.Podman requires a daemon to run containers.
D.Docker can only run on Linux.
AnswerB

Rootless mode is Podman's defining architectural difference: it uses user namespaces to map the container's root to an unprivileged host UID, so no daemon runs as root. Docker's daemon typically requires root, making this the key security distinction the question targets.

Why this answer

Podman is a daemonless container engine that supports rootless mode, allowing unprivileged users to run containers without requiring a long-running root daemon. This is a fundamental architectural difference from Docker, which traditionally relies on a root-owned `dockerd` daemon. Rootless containers improve security by reducing the attack surface and limiting privilege escalation.

Exam trap

The trap is assuming Podman also needs a daemon like Docker, or that Docker is Linux-only — candidates who have only used Docker Desktop on macOS may incorrectly believe Docker is cross-platform while Podman is not, when the opposite architectural distinction (daemonless/rootless) is the real differentiator.

How to eliminate wrong answers

Option A is wrong because Docker absolutely supports container images — it popularized the OCI image format and Docker Hub. Option C is wrong because Podman is specifically designed to run without a daemon; it forks container processes directly, unlike Docker's client-server model. Option D is wrong because Docker runs on Windows and macOS in addition to Linux (via Docker Desktop and WSL2), so claiming Linux-only is factually incorrect.

41
MCQmedium

Refer to the exhibit. A developer is pushing an image to a private registry at `192.168.1.100:5000` but receives an error about using an insecure registry. Which part of the Docker daemon configuration allows this registry without TLS?

A.The 'insecure-registries' setting
B.The 'exec-opts' setting
C.The 'storage-driver' setting
D.The 'log-driver' setting
AnswerA

The `insecure-registries` setting in `/etc/docker/daemon.json` explicitly permits the daemon to communicate with registries lacking valid TLS certificates or using plain HTTP. Adding `192.168.1.100:5000` there satisfies the stem's constraint: pushing to a private registry without TLS, which Docker otherwise blocks by default.

Why this answer

The error indicates the Docker client is attempting to push an image to a registry over HTTP (port 5000) without TLS. By default, Docker Engine requires TLS for all registry communications. The `insecure-registries` setting in `/etc/docker/daemon.json` allows the daemon to bypass TLS verification for specified IP addresses or CIDR ranges, enabling communication with registries that lack a valid TLS certificate.

Exam trap

CompTIA often tests the distinction between daemon configuration options that affect registry communication versus those that affect container runtime or storage, leading candidates to confuse `insecure-registries` with unrelated settings like `exec-opts` or `storage-driver`.

How to eliminate wrong answers

Option B is wrong because `exec-opts` is used to pass options to the container runtime (e.g., native.cgroupdriver=systemd), not to configure registry security. Option C is wrong because `storage-driver` defines the storage backend (e.g., overlay2, aufs) for container layers, not registry TLS settings. Option D is wrong because `log-driver` configures the logging driver for containers (e.g., json-file, syslog), and has no role in registry TLS enforcement.

42
MCQmedium

A developer needs to run a one-time script after the network is up on a systemd-based server. Which unit type should be used?

A.forking
B.exec
C.simple
D.oneshot
AnswerD

A oneshot unit runs a command to completion and then exits, which suits a one-time script rather than a long-running daemon. Pairing it with `After=network-online.target` and `Wants=network-online.target` satisfies the stem's requirement that the script execute only once the network is up.

Why this answer

The `oneshot` unit type is correct because it is designed for services that run a single task to completion and then exit, making it ideal for a one-time script that must execute after the network is up. In systemd, `oneshot` units can be configured with `RemainAfterExit=no` (the default) to indicate they do not need to stay running, and they support ordering dependencies like `After=network-online.target` to ensure the network is available before the script runs.

Exam trap

The trap here is that candidates confuse `oneshot` with `simple` or `forking`, mistakenly thinking a one-time script needs to remain running (`simple`) or fork into the background (`forking`), but systemd's `oneshot` is explicitly designed for tasks that exit after completion.

How to eliminate wrong answers

Option A is wrong because `forking` is used for daemons that fork into the background after startup, and systemd tracks the parent process; a one-time script that exits does not fork, so this type is inappropriate. Option B is wrong because `exec` is not a valid systemd service type; the correct types are `simple`, `forking`, `oneshot`, `dbus`, `notify`, and `idle`. Option C is wrong because `simple` is for services that start and remain running in the foreground, which does not match a one-time script that exits after execution.

43
MCQmedium

A Linux administrator needs to locate all files in the /var/log directory that have been modified within the last 2 days and contain the word 'error' (case-insensitive). Which command accomplishes this?

A.find /var/log -mtime +2 -exec grep -li 'error' {} \;
B.find /var/log -name '*error*' -mtime -2
C.find /var/log -mtime -2 -exec grep -l 'error' {} \;
D.find /var/log -mtime -2 -exec grep -li 'error' {} \;
AnswerD

The `-mtime -2` predicate filters files modified within the last two days, satisfying the recency constraint, while `-exec grep -li 'error' {} \;` runs a case-insensitive search on each match. The `-l` flag lists only filenames rather than matching lines, and `-i` handles the case-insensitivity requirement.

Why this answer

The correct command uses -mtime -2 to find files modified less than 2 days ago, and -exec grep -li 'error' to perform a case-insensitive search for 'error' in file contents, listing filenames. Option A uses -mtime +2 (files older than 2 days). Option B uses -name to match filenames, not content.

Option C uses grep -l without -i, so it would miss case variations.

44
MCQmedium

An administrator wants to use Ansible to ensure a service is running on a remote host. Which Ansible module should be used in a playbook?

A.service
B.command
C.copy
D.shell
AnswerA

The service module manages systemd, sysvinit and similar service managers on the remote host, letting the playbook assert that a named service is started and enabled. It is the purpose-built module for service state, unlike command or shell, which would run arbitrary commands without idempotent state guarantees.

Why this answer

The Ansible 'service' module is designed to manage services on remote hosts — starting, stopping, restarting, and enabling them. To ensure a service is running, you use 'service' with state: started (and optionally enabled: yes). It abstracts underlying init systems (systemd, SysV, upstart) so the playbook works across distributions.

Exam trap

XK0-006 often tests module selection by scenario — candidates confuse 'command'/'shell' (arbitrary execution, non-idempotent) with 'service' (idempotent service state management), picking command because it 'can run systemctl'.

How to eliminate wrong answers

Option B is wrong because the 'command' module executes arbitrary commands on the remote host but does not manage service state idempotently — running 'systemctl start foo' via command would report changed every time and lacks service-specific parameters like enabled. Option C is wrong because the 'copy' module transfers files from the control node to the remote host; it has nothing to do with service management. Option D is wrong because the 'shell' module runs commands through a shell (supporting pipes/redirection) but, like command, is not idempotent for service management and does not understand service states.

45
MCQmedium

A system administrator wants to limit the number of simultaneous logins for a user to 2. Which file and parameter should be configured?

A./etc/pam.d/login: session required pam_limits.so
B./etc/security/limits.conf: username hard maxlogins 2
C./etc/security/limits.conf: @users hard maxlogins 2
D./etc/security/limits.conf: username soft nproc 2
AnswerB

Configuring `maxlogins` in `/etc/security/limits.conf` enforces a per-user cap on concurrent sessions through PAM's pam_limits module, directly satisfying the requirement to restrict simultaneous logins to 2. The `hard` type makes the limit unoverrideable by the user, ensuring the constraint holds across all login methods.

Why this answer

The `/etc/security/limits.conf` file allows setting resource limits per user or group, and the `maxlogins` parameter specifically controls the maximum number of simultaneous logins for a user. The syntax `username hard maxlogins 2` enforces a hard limit of 2 concurrent sessions for that user, which is the exact requirement. This limit is enforced by the PAM module `pam_limits.so`, which must be configured in the appropriate PAM stack file (e.g., `/etc/pam.d/login` or `/etc/pam.d/sshd`).

Exam trap

The Linux+ exam often tests the distinction between `maxlogins` (simultaneous logins) and `nproc` (number of processes), and the difference between `soft` and `hard` limits, causing candidates to confuse process limits with login limits or choose a group-based entry when a per-user entry is required.

How to eliminate wrong answers

Option A is wrong because `/etc/pam.d/login` is a PAM service configuration file, not a resource limit file; the line `session required pam_limits.so` is necessary to enable `pam_limits.so` but does not itself set any limit. Option C is wrong because `@users` refers to a group named 'users', not a specific username, and the question explicitly asks to limit a single user, not a group. Option D is wrong because `soft nproc 2` limits the number of processes (nproc) for the user, not the number of simultaneous logins (maxlogins), and using a soft limit allows the user to exceed it temporarily, which does not enforce a hard cap of 2 logins.

46
MCQhard

A technician wants to create a symbolic link in /usr/local/bin that points to /opt/myapp/bin/start.sh. The technician has write permissions to /usr/local/bin. Which command should be used?

A.ln -s /opt/myapp/bin/start.sh /usr/local/bin/start.sh
B.ln -s /usr/local/bin/start.sh /opt/myapp/bin/start.sh
C.ln /opt/myapp/bin/start.sh /usr/local/bin/start.sh
D.cp -s /opt/myapp/bin/start.sh /usr/local/bin/start.sh
AnswerA

`ln -s` creates a symbolic link, with the target path first and the link path second, satisfying the requirement to point /usr/local/bin/start.sh at /opt/myapp/bin/start.sh. Write permission on /usr/local/bin is sufficient; no elevated privileges are needed since the technician already holds them.

Why this answer

ln -s target linkname creates a symbolic link. The target should be the file to link to, and the link name is the new symlink.

47
Multi-Selectmedium

A system administrator wants to encrypt a large directory of files using GPG with a symmetric cipher. Which two steps are necessary? (Select TWO).

Select 2 answers
A.gpg --decrypt file.gpg
B.Use a passphrase to encrypt
C.gpg --encrypt --recipient user file
D.Import a public key
E.gpg --symmetric --cipher-algo AES256 file
AnswersB, E

Symmetric encryption requires a passphrase.

Why this answer

Symmetric encryption in GPG requires a passphrase to derive the encryption key. When using `gpg --symmetric`, the cipher key is generated from a passphrase provided by the user, making the passphrase the essential secret for both encryption and decryption. Without a passphrase, symmetric encryption cannot proceed.

Exam trap

The trap here is that candidates confuse symmetric encryption with asymmetric encryption and select `--recipient` or public key import, not realizing that `--symmetric` requires only a passphrase, not a key pair.

48
MCQmedium

A user reports they cannot log in after three failed password attempts. The system uses PAM with pam_faillock. Which command can the administrator use to view the number of failed attempts for the user?

A.faillock --user username
B.ausearch -m USER_LOGIN -ui username
C.pam_tally2 --user username
D.lastb username
AnswerA

The faillock utility reads the tally files that pam_faillock.so maintains and prints each user's recorded failure timestamps and count. Running it with --user username displays that account's failed attempts, letting the administrator confirm the lockout cause.

Why this answer

The faillock command is the standard tool for viewing and managing failed login attempts when using pam_faillock. Running 'faillock --user username' displays the number of failed attempts and the timestamps for the specified user. This directly answers the question.

Exam trap

XK0-006 often tests the difference between pam_faillock and pam_tally2, and candidates may choose the legacy command. The trap is to assume that pam_tally2 is still the standard for viewing failed attempts.

How to eliminate wrong answers

Option B is wrong because ausearch is used to search audit logs, and while it can show USER_LOGIN events, it does not specifically show the faillock counter; it would require parsing and may not reflect the current faillock state. Option C is wrong because pam_tally2 is a legacy module for tallying failed logins, but it has been deprecated in favor of pam_faillock on modern systems; the command 'pam_tally2 --user username' might work on older systems but is not the correct tool for pam_faillock. Option D is wrong because lastb shows a list of bad login attempts from the btmp file, but it does not show the faillock counter and is not specific to the user's current failed attempt count.

49
Multi-Selectmedium

A Linux administrator needs to view real-time information about running processes, including CPU and memory usage. Which TWO commands can be used for this purpose? (Choose two.)

Select 2 answers
A.ps aux
B.top
C.systemctl list-units
D.htop
E.kill -l
AnswersB, D

top reads /proc to render a live, refreshing table of processes with per-process CPU and memory figures, satisfying the real-time monitoring requirement. Its interactive sort and kill functions let the administrator act on what they observe without leaving the terminal.

Why this answer

Option B (top) is correct because top provides a continuously refreshing, real-time view of running processes along with per-process CPU and memory usage, load averages, and system summary statistics. Option D (htop) is correct because htop is an interactive process viewer that also displays real-time CPU and memory usage per process, with additional features like colorized output, scrolling, and process management. Option A (ps aux) is not correct here because ps produces a static snapshot of processes at the moment it is executed rather than a live, updating view.

Option C (systemctl list-units) is incorrect because it lists systemd units and their states, not per-process CPU or memory usage. Option E (kill -l) is incorrect because it only lists available signal names/numbers and provides no process resource information.

50
Multi-Selectmedium

A Linux server reports that its root filesystem is 100 percent full, and applications are failing to write logs. The administrator needs to identify what is consuming space and reclaim it safely. Which two commands are appropriate to determine where the space is used? (Choose two.)

Select 2 answers
A.lsblk -f
B.df -i /
C.find / -xdev -type f -size +500M -exec ls -lh {} \;
D.fsck -n /dev/sda1
E.du -xh --max-depth=1 / | sort -h
AnswersC, E

This locates individual files larger than 500 MB while staying on the root filesystem thanks to -xdev, then lists them with sizes. Large single files such as runaway logs or core dumps are common causes of a full root volume, and this command pinpoints them quickly for review before deletion.

Why this answer

Finding what filled the root filesystem requires two complementary views: per-directory totals to narrow the search, and a scan for unusually large individual files. Staying on one filesystem with -x and -xdev prevents mounted volumes from skewing results. Together these commands point the administrator to the exact data to review or remove.

Exam trap

The trap here is reaching for inode or block-device listings, which describe filesystem structure and capacity rather than identifying which directories and files actually consumed the space.

51
Multi-Selecteasy

Which TWO commands can be used to check disk space usage on a Linux system?

Select 2 answers
A.mount
B.lsof
C.du
D.fdisk
E.df
AnswersC, E

du reports disk space consumed by files and directories, walking the filesystem to total usage per path. It complements df, which shows free space per mounted filesystem. For checking how much space directories occupy, du is the appropriate tool.

Why this answer

The `du` command (option C) is correct because it estimates file space usage by recursively summing the sizes of files and directories, typically reporting in blocks or with `-h` for human-readable output, making it ideal for checking how much disk space specific directories consume. The `df` command (option E) is also correct because it reports filesystem-level disk space usage, showing total, used, and available space per mounted filesystem, which is the standard way to check overall disk capacity. Option A, `mount`, only lists mounted filesystems and their mount points and does not report space usage.

Option B, `lsof`, lists open files and the processes using them, which is unrelated to disk space accounting. Option D, `fdisk`, is a partitioning tool for creating and modifying disk partitions and does not report space usage.

Exam trap

The trap here is that candidates may confuse `du` and `df` with commands like `mount` or `fdisk`, which are related to filesystem management but do not directly report disk space usage.

52
MCQmedium

A system administrator wants to review kernel-related log messages from the current boot session. Which journalctl command should be used to filter the kernel messages?

A.journalctl -p err
B.journalctl -b -u systemd-journald
C.journalctl -k
D.journalctl --since today
AnswerC

The -k flag restricts journalctl output to kernel messages only, drawing from the kernel ring buffer captured by systemd-journald. This directly satisfies the requirement to isolate kernel-related entries from the current boot session, excluding user-space service and application logs.

Why this answer

journalctl -k shows kernel messages from the current boot.

53
MCQhard

A Linux server is configured with an IPsec VPN using strongSwan. The administrator needs to verify that the VPN tunnel is active and that traffic is being encrypted. Which command should be used to display the current status of the IPsec security associations?

A.ipsec statusall
B.ss -tuln
C.ip xfrm state
D.systemctl status strongswan
AnswerA

The 'ipsec statusall' command is part of the strongSwan suite and displays detailed information about all IPsec security associations (SAs), including their state, encryption algorithms, and traffic statistics. This allows the administrator to confirm that the tunnel is established and operational, and to see if any SAs are down or have errors.

Why this answer

The 'ipsec statusall' command is the standard tool in strongSwan to display the status of all IPsec security associations, including connection states, encryption details, and traffic counters. It provides a comprehensive overview that confirms whether the VPN tunnel is active and properly encrypting traffic, which is exactly what the administrator needs.

Exam trap

The trap here is assuming that checking the service status or listening ports is enough to verify VPN operation, but those do not confirm that a tunnel is established and passing traffic.

54
MCQmedium

Based on the exhibit, what is the most likely cause of the repeated connection refused errors?

A.The DNS resolution for the database host fails.
B.A firewall is blocking port 3306.
C.The database service is down.
D.The database credentials are incorrect.
AnswerC

Connection refused means the TCP port is reachable but nothing is listening, so the database service itself is not running. A firewall drop would typically time out rather than refuse, confirming the service is down.

Why this answer

The 'connection refused' error indicates that the client's TCP SYN packet reached the target host on port 3306, but the host actively rejected the connection because no process is listening on that port. This is the classic symptom of the MySQL/MariaDB database service being stopped or crashed, as the OS TCP stack sends an RST packet when a connection attempt hits a port with no listening socket.

Exam trap

CompTIA often tests the distinction between 'connection refused' (service down) and 'connection timeout' (firewall blocking) — candidates confuse the two because both prevent access, but the TCP error message uniquely identifies the cause.

How to eliminate wrong answers

Option A is wrong because DNS resolution failures would produce a 'Name or service not known' error, not a TCP-level 'connection refused'. Option B is wrong because a firewall blocking port 3306 would cause the connection to time out (no response) or be silently dropped, not produce an immediate 'connection refused' which requires a TCP RST from the target host. Option D is wrong because incorrect credentials result in an authentication failure after the TCP connection is established, typically returning 'Access denied for user' from the database server, not a transport-layer refusal.

55
MCQhard

A DevOps engineer is creating a Podman container that needs to communicate with a host service listening on a Unix socket at /run/host-service.sock. Which of the following mount options will make the socket available inside the container?

A.--device /run/host-service.sock:/run/host-service.sock
B.--bind /run/host-service.sock:/run/host-service.sock
C.--volume /run/host-service.sock:/run/host-service.sock
D.--mount type=bind,source=/run/host-service.sock,target=/run/host-service.sock
AnswerC, D

Correct. The --volume flag can bind-mount a single file like a Unix socket from the host to the container.

Why this answer

Both option C (`--volume`) and option D (`--mount type=bind,source=...,target=...`) can bind-mount a Unix socket into a Podman container. Podman's `--mount` with `type=bind` supports individual file sources, including sockets, just like Docker. The `--volume` flag is a shorthand that also works for files and directories.

Options A (`--device`) and B (`--bind`) are not valid Podman flags for this purpose.

Exam trap

Candidates may assume only `--volume` can mount files, but `--mount type=bind` also supports file and socket sources. Both C and D are valid.

How to eliminate wrong answers

Option A is wrong because `--device` is used to expose host devices (e.g., `/dev/sda`) to a container, not regular files or sockets; it does not handle Unix socket bind mounts. Option B is wrong because `--bind` is not a valid Podman or Docker flag; the correct syntax for a bind mount uses `--volume`, `--mount`, or `-v`. Option D is wrong because the `--mount` flag requires a comma-separated list of key=value pairs (e.g., `type=bind,source=/run/host-service.sock,target=/run/host-service.sock`), but the given syntax is missing the `type=bind` key and uses incorrect formatting; it would be rejected by Podman.

56
MCQmedium

A technician needs to kill a process with PID 1234 that is not responding to normal termination. Which command sends SIGKILL?

A.kill 1234
B.kill -15 1234
C.kill -9 1234
D.kill -1 1234
AnswerC

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 1234 immediately. This satisfies the stem's constraint that the process is unresponsive to normal termination, unlike SIGTERM (15), which the process may handle or defer.

Why this answer

kill -9 sends SIGKILL, which forcefully terminates the process.

57
MCQeasy

Which of the following directories in the Filesystem Hierarchy Standard (FHS) contains variable data files such as logs, spool files, and temporary files that persist across reboots?

A./opt
B./etc
C./tmp
D./var
AnswerD

/var holds variable data — logs, spool queues and persistent temporary files — which change in size and content during normal operation. The FHS reserves it precisely for data that must survive reboots, unlike /tmp, which is typically cleared. This satisfies the stem's requirement for variable files persisting across restarts.

Why this answer

/var is for variable data like logs, spool, and temporary files that persist. /tmp is for temporary files that may be cleared on reboot. /etc is for configuration files. /opt is for optional add-on software.

58
MCQmedium

An administrator needs to create a Docker image from a Dockerfile located in the current directory and tag it as 'myapp:v1'. Which command should be used?

A.docker create -t myapp:v1 .
B.docker commit myapp:v1 .
C.docker build -t myapp:v1 .
D.docker image create myapp:v1 .
AnswerC

docker build reads the Dockerfile from the specified context, and the dot sets the current directory as that context. The -t flag assigns the repository and tag myapp:v1, satisfying both the build-from-current-directory and tagging requirements in one command.

Why this answer

The correct command is `docker build -t myapp:v1 .` because `docker build` reads a Dockerfile from the specified context (the `.` means the current directory) and builds an image. The `-t` flag tags the resulting image with the name and tag `myapp:v1`. This is the standard way to create an image from a Dockerfile.

Exam trap

XK0-006 often tests the distinction between image creation commands: candidates may confuse `docker build` with `docker create` or `docker commit`, or mistakenly think `docker image create` is valid.

How to eliminate wrong answers

Option A is wrong because `docker create` creates a new container from an existing image; it does not build an image from a Dockerfile. Option B is wrong because `docker commit` creates a new image from a container's changes, not from a Dockerfile. Option D is wrong because `docker image create` is not a valid Docker command; the correct subcommand for building is `docker build` (or `docker image build` in newer versions, but `docker image create` does not exist).

59
MCQmedium

A security analyst notices repeated failed login attempts on a Linux server. They want to lock the account after 3 failed attempts using PAM. Which PAM module should be configured in /etc/pam.d/sshd or /etc/pam.d/system-auth?

A.pam_faillock.so
B.pam_tally2.so
C.pam_pwquality.so
D.pam_unix.so
AnswerA

pam_faillock.so counts consecutive authentication failures per account and locks it once the configured deny threshold is reached, directly enforcing the three-attempt lockout. It is inserted into the auth and account stacks of /etc/pam.d/sshd or system-auth.

Why this answer

pam_faillock.so is the modern PAM module designed to lock accounts after a configurable number of failed login attempts. It replaces the deprecated pam_tally2.so and is configured in /etc/pam.d/sshd or /etc/pam.d/system-auth with parameters like deny=3 to enforce the lockout threshold. It tracks failures per user and can automatically unlock accounts after a specified time.

Exam trap

XK0-006 often tests the difference between deprecated and current PAM modules, so candidates may incorrectly choose pam_tally2.so because they remember it from older study materials.

How to eliminate wrong answers

Option B is wrong because pam_tally2.so is deprecated and removed in newer Linux distributions; it was replaced by pam_faillock.so. Option C is wrong because pam_pwquality.so enforces password complexity and length policies, not account lockout on failed logins. Option D is wrong because pam_unix.so handles standard Unix authentication (password verification) but does not provide account lockout functionality.

60
Multi-Selectmedium

A technician wants to extract the third column of a tab-separated file and sort the output uniquely. Which three commands can be combined using pipes to achieve this? (Choose three.)

Select 3 answers
A.cut -f3
B.tee
C.wc -l
D.sort
E.uniq
AnswersA, D, E

`cut -f3` extracts the third tab-delimited field, satisfying the column-selection requirement. Its default delimiter is TAB, matching the tab-separated file, so no `-d` flag is needed. Piped into `sort` and `uniq`, it produces the uniquely sorted output the technician wants.

Why this answer

Option A, `cut -f3`, is correct because `cut` with the `-f3` flag extracts the third field from each line, and with tab as the default delimiter it directly targets the third column of a tab-separated file. Option D, `sort`, is correct because it orders the extracted lines so that duplicate values become adjacent, which is a prerequisite for `uniq` to collapse them. Option E, `uniq`, is correct because it removes adjacent duplicate lines, producing the unique output the technician wants when chained after `sort`.

Option B, `tee`, is not appropriate because it merely splits output to a file and standard output rather than extracting or deduplicating data. Option C, `wc -l`, is not appropriate because it only counts lines and does not extract or sort columns.

61
MCQmedium

A Linux administrator uses Ansible to manage a fleet of servers and needs to ensure a configuration file is present with specific contents on all web servers, restarting the service only when the file changes. Which Ansible module and handler pattern accomplishes this?

A.Use the `file` module with `state: touch` and a `cron` job to restart the service periodically
B.Use the `template` module with `force: no` and no handler, relying on the service to reload automatically
C.Use the `copy` module with a `notify` directive that triggers a handler containing the `service` module with `state: restarted`
D.Use the `shell` module to run `systemctl restart httpd` after writing the file with a `command` task
AnswerC

The `copy` module places the file with the specified content and reports a changed status only when the content differs. The `notify` directive then triggers the named handler, which uses the `service` module to restart the web service. This ensures the restart occurs only on change, matching the requirement exactly.

Why this answer

Idempotent configuration management requires a module that reports change status and a handler that reacts to that status. The `copy` module writes the file and reports changed only on difference, and the `notify` directive invokes a handler that restarts the service. Unconditional shell restarts, `force: no`, or timestamp-only modules all fail to deliver a restart triggered specifically by a content change.

Exam trap

The trap here is assuming that restarting the service in the same task or unconditionally is equivalent to using a handler, which only fires on change.

62
MCQmedium

A Linux system is running slowly with high I/O wait as shown by vmstat. To investigate the I/O activity of a specific process that is suspected of causing the bottleneck, which of the following commands would be used to trace its system calls related to I/O?

A.iostat -x 1
B.strace -p <pid>
C.dmesg | tail
D.free -h
AnswerB

'strace -p <pid>' attaches to the running process and traces its system calls, exposing read, write and fsync activity that drives I/O wait. This satisfies the requirement to investigate a specific suspect process rather than system-wide I/O statistics.

Why this answer

strace attaches to a running process and traces its system calls, including I/O-related calls like read, write, open, and fsync, making it the right tool to pinpoint which syscalls a specific process is issuing. By using 'strace -p <pid>', the administrator can observe the exact I/O behavior of the suspect process. This directly addresses the need to trace system calls related to I/O for a specific PID.

Exam trap

XK0-006 often tests the distinction between system-wide I/O monitoring tools (iostat, vmstat) and per-process syscall tracing tools (strace), and candidates may pick iostat when the question specifically asks for tracing a process's system calls.

How to eliminate wrong answers

Option A is wrong because iostat -x 1 reports per-device I/O statistics at the system level, not per-process system calls, so it cannot attribute I/O to a specific process. Option C is wrong because dmesg | tail shows kernel ring buffer messages (hardware errors, driver messages), not per-process I/O syscall activity. Option D is wrong because free -h displays memory usage, which is unrelated to tracing a process's I/O system calls.

63
Multi-Selecthard

A security audit reveals that a Linux system allows password-based SSH logins and has weak password policies. Which THREE actions should the administrator take to improve security? (Choose three.)

Select 3 answers
A.Change SSH port to 2222
B.Configure pam_faillock.so to lock accounts after failed attempts
C.Configure pam_pwquality.so to enforce password complexity
D.Set PasswordAuthentication no in sshd_config
E.Set PermitRootLogin yes
AnswersB, C, D

Configuring pam_faillock.so enforces account lockout after repeated failed authentication attempts, directly mitigating brute-force attacks against the weak password policy identified in the audit. It operates at the PAM authentication layer, so the protection applies across all services using PAM, not SSH alone, hardening the system beyond the password-strength weakness.

Why this answer

Option B is correct because configuring pam_faillock.so in the PAM stack enforces account lockout after a defined number of failed authentication attempts (e.g., deny=5, unlock_time=900), directly mitigating brute-force and password-guessing attacks against the weak password policy. Option C is correct because pam_pwquality.so enforces password complexity requirements such as minimum length (minlen), character classes (ucredit, lcredit, dcredit, ocredit), and dictionary checks, which addresses the audit finding of weak password policies at their source. Option D is correct because setting PasswordAuthentication no in sshd_config disables password-based SSH authentication entirely, forcing key-based authentication and eliminating the password-guessing attack surface the audit flagged; this requires reloading sshd (systemctl reload sshd) to take effect.

Option A does not belong because merely changing the SSH port to 2222 is security through obscurity and does not fix the underlying weak authentication or password policy issues. Option E does not belong because setting PermitRootLogin yes permits direct root logins over SSH, which increases risk rather than improving security; it should be set to no or prohibit-password.

64
MCQhard

A server with multiple disks is configured with RAID 5 for performance and redundancy. The administrator notices that write performance is lower than expected. Which RAID level would provide better write performance while still offering fault tolerance with the same number of disks (minimum 4)?

A.RAID 0
B.RAID 6
C.RAID 10
D.RAID 1
AnswerC

RAID 10 stripes across mirrored pairs, so every write goes to two disks without parity calculation, unlike RAID 5's read-modify-write parity penalty. With four disks it delivers fault tolerance plus markedly better write throughput, satisfying the performance and redundancy constraints.

Why this answer

RAID 10 (striping of mirrors) provides better write performance than RAID 5 because it does not incur the overhead of calculating and writing parity data on every write operation. With a minimum of four disks, RAID 10 offers fault tolerance (each mirror can survive one disk failure) while delivering the full write speed of the underlying disks, unlike RAID 5 which must update parity across all disks.

Exam trap

The trap here is that candidates often assume RAID 6 offers better fault tolerance than RAID 5 without considering that its double parity further degrades write performance, and they overlook that RAID 10 provides both performance and redundancy with the same minimum disk count.

How to eliminate wrong answers

Option A is wrong because RAID 0 offers no fault tolerance; it stripes data without redundancy, so any single disk failure causes complete data loss. Option B is wrong because RAID 6 uses double parity, which adds even more write overhead than RAID 5, resulting in worse write performance. Option D is wrong because RAID 1 (mirroring) with four disks would require all disks to be paired into mirrors, but it does not provide striping for performance gains; RAID 10 combines mirroring and striping to achieve both performance and fault tolerance.

65
MCQhard

A Linux administrator needs to schedule a script to run every Monday at 3:00 AM. The script is located at /usr/local/bin/backup.sh. The administrator wants to use a systemd timer instead of cron. Which pair of files is required to implement this?

A.A .service unit and a .socket unit
B.A .timer unit and a .path unit
C.A .service unit and a .timer unit
D.A .timer unit and a .target unit
AnswerC

systemd timers require a .timer unit that defines the schedule and a corresponding .service unit that defines the command to run. The timer activates the service based on the OnCalendar setting. Both files are necessary to schedule and execute the script as specified.

Why this answer

To schedule a task with systemd, you need a .timer unit that specifies the schedule using OnCalendar, and a .service unit that contains the ExecStart command. The timer activates the service at the defined times. Other unit types like .socket, .path, or .target serve different purposes and cannot replace the .service unit for executing the script.

Exam trap

The trap here is confusing systemd unit types, such as using a .socket or .path unit for time-based scheduling instead of a .timer with a .service.

66
MCQhard

After applying a kernel update, a Linux server boots but the root filesystem is mounted read-only, and dmesg shows I/O errors on /dev/sda2. The administrator needs to determine whether the filesystem is corrupted and, if so, repair it safely. Which sequence of actions should the administrator take?

A.Recreate the filesystem with mkfs.ext4 /dev/sda2 and restore from the most recent backup.
B.Boot into rescue mode, run fsck -n on /dev/sda2 first, then run fsck -y if errors are reported.
C.Remount the root filesystem read-write with mount -o remount,rw / and continue using the server.
D.From the running system, run fsck -y /dev/sda2 immediately to repair the errors.
AnswerB

Booting to rescue mode ensures the root filesystem is not mounted, which is required for a safe check. fsck -n performs a read-only check and reports problems without modifying anything; if errors appear, fsck -y repairs them automatically. This order verifies corruption before committing changes.

Why this answer

A read-only root mount after I/O errors usually means the kernel detected filesystem problems and remounted defensively. Repair requires the filesystem to be offline, so rescue mode is appropriate. fsck -n first confirms and characterizes the damage without risk; if it reports errors, fsck -y applies repairs. Running fsck on a mounted filesystem, forcing a read-write remount, or reformatting are all unsafe or premature.

Exam trap

The trap here is running fsck -y directly on the mounted root filesystem, which can turn recoverable corruption into permanent data loss.

67
MCQhard

During boot, a Linux system displays a kernel panic with the message 'VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?

A.Incorrect GRUB timeout setting
B.A faulty RAM module causing memory errors
C.Corrupted initramfs missing necessary storage drivers
D.Filesystem corruption on the boot partition
AnswerC

The initramfs carries the storage drivers needed to mount the root filesystem. If it is corrupted or lacks the correct driver, the kernel cannot locate the root device, producing exactly this unknown-block(0,0) panic before init runs.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates the kernel cannot locate or access the root filesystem. This is most commonly caused by a corrupted or missing initramfs that lacks the necessary storage drivers (e.g., for SATA, NVMe, or LVM) to communicate with the root device. Without these drivers, the kernel cannot read the root filesystem, resulting in a panic.

Exam trap

The trap here is that candidates often confuse this error with filesystem corruption on the boot partition (Option D), but the 'unknown-block(0,0)' message specifically points to the kernel's inability to find the root device, which is a driver/module issue in the initramfs, not a filesystem problem.

How to eliminate wrong answers

Option A is wrong because an incorrect GRUB timeout setting only affects the boot menu delay, not the kernel's ability to mount the root filesystem. Option B is wrong because a faulty RAM module typically causes random crashes, segmentation faults, or memory errors, not a specific VFS mount failure with an unknown block device. Option D is wrong because filesystem corruption on the boot partition would prevent GRUB from loading the kernel or initramfs, but the error here occurs after the kernel is loaded and fails to mount the root filesystem, indicating the initramfs is the issue.

68
MCQhard

A server running nftables has a rule set that allows incoming SSH from the management network (192.168.1.0/24). An administrator needs to insert a rule to drop SSH from all other sources. Which nft command accomplishes this? Assume the input chain is 'input' and the table is 'inet filter'.

A.nft add rule inet filter input ip saddr != 192.168.1.0/24 tcp dport 22 drop
B.nft insert rule inet filter input tcp dport 22 drop
C.nft replace rule inet filter input handle 1 tcp dport 22 drop
D.nft add rule inet filter input tcp dport 22 accept
AnswerA

The rule matches source addresses outside 192.168.1.0/24 on TCP port 22 and drops them, satisfying the requirement to block non-management SSH. Using '!=' with the saddr match and the drop verdict enforces the restriction within the inet filter input chain.

Why this answer

The correct rule uses 'nft add rule' with a source address negation (ip saddr != 192.168.1.0/24) matching TCP destination port 22 and a drop verdict, which precisely drops SSH from every source outside the management network while leaving the existing allow rule intact. This is the only option that combines the correct match criteria (source negation plus SSH port) with the drop action.

Exam trap

The trap here is that candidates pick 'insert' or a plain drop rule without the source negation, forgetting that nftables is first-match-wins and that dropping all SSH would lock out the management network — the exam tests whether you read the requirement to exclude the management subnet.

How to eliminate wrong answers

Option B is wrong because 'nft insert rule inet filter input tcp dport 22 drop' drops ALL SSH traffic including from the management network, with no source address exception — it would break the intended management access. Option C is wrong because 'nft replace rule' requires an existing rule handle to replace, and the command as written references handle 1 without confirming that handle corresponds to the intended rule; it also lacks the source negation. Option D is wrong because it adds an accept rule for SSH, which does the opposite of the requirement and would not restrict access from unauthorized sources.

69
MCQhard

A Linux administrator is configuring a server to use firewalld. The administrator wants to allow incoming traffic on TCP port 8080 only from the 192.168.1.0/24 subnet, while denying it from all other sources, without affecting other services. Which firewalld command should the administrator use to achieve this?

A.firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="8080" protocol="tcp" accept'
B.firewall-cmd --permanent --add-source=192.168.1.0/24 --add-port=8080/tcp
C.firewall-cmd --permanent --add-port=8080/tcp --source=192.168.1.0/24
D.firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="8080" protocol="tcp" drop'
AnswerA

This rich rule adds a permanent rule that accepts TCP traffic to port 8080 only from the specified source subnet. Rich rules allow granular control based on source address, port, and protocol. After adding it, the administrator must reload firewalld for the rule to take effect in the running configuration.

Why this answer

Rich rules in firewalld allow combining source addresses, ports, and actions in a single rule. The correct syntax uses --add-rich-rule with a rule that specifies source address, port, protocol, and accept action. This precisely allows TCP 8080 from 192.168.1.0/24.

Adding a port with a source argument is not supported, and adding a source to a zone does not restrict individual ports.

Exam trap

The trap here is assuming that --add-port can be combined with --source to restrict access, when source restrictions require a rich rule or zone-based source assignment.

70
MCQmedium

The system is experiencing slow disk I/O. Based on the exhibit, which step should the administrator take to improve performance?

A.Increase the filesystem block size
B.Enable write-back caching on the drive using hdparm
C.Add the 'noatime' mount option in /etc/fstab
D.Change the I/O scheduler to 'deadline'
AnswerC

Adding `noatime` stops the kernel writing an access timestamp every time a file is read, eliminating those metadata writes. On a busy filesystem this cuts a steady stream of small random writes, directly relieving the slow disk I/O the exhibit shows. It is the least disruptive fix, requiring only an `/etc/fstab` edit and remount.

Why this answer

The 'noatime' mount option disables updating the access time (atime) on every file read, which eliminates a significant source of metadata write operations. Since the exhibit indicates slow disk I/O, reducing unnecessary writes directly improves performance by freeing I/O bandwidth for actual data transfers. This is a standard, low-risk optimization for workloads where access timestamps are not required.

Exam trap

The trap here is that candidates often focus on I/O schedulers or caching mechanisms to fix slow I/O, overlooking the simple and effective filesystem mount option that reduces unnecessary write operations.

How to eliminate wrong answers

Option A is wrong because increasing the filesystem block size can improve throughput for large sequential I/O but may waste space and degrade performance for small random I/O; it does not address the root cause of slow disk I/O from excessive metadata writes. Option B is wrong because enabling write-back caching with hdparm on a drive that does not support it or without proper power-loss protection can cause data corruption; it is a risky hardware-level change, not a safe filesystem tuning step. Option D is wrong because changing the I/O scheduler to 'deadline' may help with latency for certain workloads, but it does not reduce the volume of I/O operations; the exhibit points to unnecessary metadata updates, which the scheduler cannot mitigate.

71
MCQhard

An organization is migrating from a legacy automation tool to Ansible. Which of the following best describes the role of Ansible playbooks in configuration management?

A.YAML files that declare the desired state of systems and tasks to achieve it.
B.Executable scripts written in Python that run on managed nodes.
C.Configuration files that list the inventory of managed hosts.
D.Shell scripts that execute ad-hoc commands across servers.
AnswerA

Playbooks are YAML documents describing the desired end state of managed hosts, with ordered tasks that Ansible executes idempotently to converge systems toward that state. This declarative model distinguishes Ansible from imperative legacy automation scripts that specify step-by-step commands instead of outcomes.

Why this answer

Ansible playbooks are YAML files that declare the desired state of systems and the tasks to achieve that state, making them the core configuration management tool in Ansible. They are idempotent, meaning running them multiple times yields the same result, and they use modules to enforce configurations without requiring an agent on managed nodes.

Exam trap

The trap here is confusing playbooks with ad-hoc commands or inventory files, as candidates often think playbooks are scripts that execute directly on nodes rather than declarative YAML files that define desired state and tasks.

How to eliminate wrong answers

Option B is wrong because Ansible playbooks are not executable Python scripts; they are YAML declarative files that invoke Python modules on the control node, not scripts that run directly on managed nodes. Option C is wrong because inventory files, not playbooks, list managed hosts; playbooks define tasks and desired states. Option D is wrong because playbooks are not shell scripts; they are structured YAML files that orchestrate idempotent tasks, while ad-hoc commands are run via the `ansible` command, not playbooks.

72
Multi-Selectmedium

A bash script uses a loop to iterate over files in a directory. Which TWO of the following loop constructs will correctly iterate over each .txt file in the current directory? (Select TWO).

Select 2 answers
A.for file in '*.txt'; do
B.for file in $(ls *.txt); do
C.for file in *.txt; do
D.for ((i=0; i<${#files[@]}; i++)); do
E.while IFS= read -r file; do done < <(find . -maxdepth 1 -name '*.txt')
AnswersC, E

Glob expansion by the shell resolves `*.txt` into a list of matching filenames before the loop runs, so each iteration assigns one filename to `file`. This satisfies the requirement to iterate over every .txt file in the current directory, provided matches exist.

Why this answer

Option C is correct because `for file in *.txt; do` relies on bash pathname expansion (globbing), which expands the unquoted pattern `*.txt` into the list of matching filenames in the current directory, iterating over each one. Option E is correct because `while IFS= read -r file; do ... done < <(find . -maxdepth 1 -name '*.txt')` uses process substitution to feed find's output into the loop; `IFS=` preserves leading/trailing whitespace and `read -r` prevents backslash interpretation, and `find . -maxdepth 1 -name '*.txt'` lists only .txt files directly in the current directory. Option A is wrong because quoting `'*.txt'` suppresses globbing, so the loop runs once with the literal string `*.txt`.

Option B is wrong because parsing `ls` output is fragile and breaks on filenames containing spaces, newlines, or glob characters. Option D is wrong because it iterates over indices of a `files` array that is never populated in the scenario, so it does not iterate over the .txt files.

Exam trap

XK0-006 often tests the difference between quoted and unquoted globs, and the danger of parsing ls output — candidates frequently pick $(ls *.txt) thinking it is equivalent to globbing, when it is actually a word-splitting hazard.

73
MCQmedium

A company is deploying a new web application using Docker containers. The application requires configuration values that vary between environments (development, staging, production). Which approach ensures the configuration is securely managed and applied without modifying the container image?

A.Pass configuration via environment variables and use Docker secrets for sensitive data.
B.Build separate images for each environment with the configuration baked in.
C.Store configuration in a JSON file within the base image and override it at runtime.
D.Use a Dockerfile to copy the configuration file from the host at build time.
AnswerA

Environment variables inject per-environment values at runtime without rebuilding the image, while Docker secrets keep sensitive data out of the image and plain environment dumps. Together they satisfy secure, image-independent configuration across development, staging and production.

Why this answer

Docker supports passing configuration via environment variables at runtime without altering the image, and Docker secrets securely manage sensitive data (e.g., passwords, API keys) by storing them in encrypted memory and mounting them as temporary files in `/run/secrets/`. This decouples configuration from the immutable image, adhering to the twelve-factor app methodology and ensuring environment-specific values are applied without rebuilding.

Exam trap

CompTIA often tests the misconception that environment variables alone are sufficient for all configuration, including secrets, but the trap here is that Docker secrets provide an additional security layer for sensitive data, while environment variables are appropriate for non-sensitive configuration values.

How to eliminate wrong answers

Option B is wrong because building separate images for each environment violates immutability and defeats the purpose of a single deployable artifact, leading to configuration drift and increased maintenance overhead. Option C is wrong because storing configuration in a JSON file within the base image requires modifying the image or using a bind mount at runtime, which either breaks immutability or relies on host filesystem access, not a secure or portable approach. Option D is wrong because using a Dockerfile to copy a configuration file from the host at build time bakes the configuration into the image, making it environment-specific and requiring separate builds for each environment, which is inefficient and insecure.

74
Multi-Selectmedium

An administrator needs to harden SSH access. Which TWO settings in /etc/ssh/sshd_config are recommended to improve security? (Choose two.)

Select 2 answers
A.PermitRootLogin yes
B.PermitRootLogin no
C.Protocol 1
D.PasswordAuthentication no
E.Port 22
AnswersB, D

PermitRootLogin no blocks direct root authentication over SSH, forcing administrators to log in as unprivileged users before escalating via sudo or su. This removes root as a brute-force target and preserves attributable audit trails, directly satisfying the hardening requirement to reduce remote attack surface on the SSH daemon.

Why this answer

Option B (PermitRootLogin no) is correct because disabling direct root logins over SSH forces attackers to compromise a normal user account and then escalate privileges, removing a high-value, well-known target and enabling accountability through sudo or su. Option D (PasswordAuthentication no) is correct because it disables password-based authentication, requiring key-based (public/private key) authentication instead, which is not vulnerable to brute-force or credential-guessing attacks. Option A (PermitRootLogin yes) is wrong because it explicitly allows root to log in directly, the opposite of hardening.

Option C (Protocol 1) is wrong because SSH protocol 1 is deprecated and insecure (weak integrity/crypto), and modern OpenSSH only supports protocol 2 anyway. Option E (Port 22) is wrong because it merely sets the default port and provides no real security benefit; changing the port is at most minor obscurity, not a recommended hardening control.

Exam trap

The trap here is that candidates often think changing the default SSH port (Option E) is a strong security measure, but the exam considers it a weak control compared to disabling root login and password authentication, which directly address authentication vulnerabilities.

75
Multi-Selectmedium

A Linux technician is troubleshooting a system that is experiencing high disk I/O wait times. Which TWO commands can be used to identify disk I/O performance issues? (Choose two.)

Select 2 answers
A.lsof
B.vmstat
C.iostat
D.free -h
E.dmesg
AnswersB, C

vmstat reports run-queue, blocked-process and CPU columns including wa (I/O wait), letting the technician confirm whether processes are stalled on disk. Its r and b columns distinguish CPU saturation from storage-bound waiting, directly addressing the high I/O wait symptom.

Why this answer

Option B (vmstat) is correct because it reports virtual memory statistics including the 'wa' (I/O wait) column in its CPU breakdown, which directly shows the percentage of time the CPU spent waiting on disk I/O, making it ideal for diagnosing high I/O wait times. Option C (iostat) is correct because it is specifically designed to report per-device and per-partition disk I/O statistics such as tps, kB_read/s, kB_wrtn/s, and %util, which pinpoint which block devices are saturated. Option A (lsof) lists open files and the processes using them, which can hint at file usage but does not measure disk I/O performance or wait times.

Option D (free -h) only displays memory and swap usage in human-readable form, providing no direct disk I/O metrics. Option E (dmesg) shows kernel ring buffer messages, useful for hardware or driver errors, but it does not report ongoing disk I/O performance statistics.

Exam trap

XK0-006 often tests the confusion between memory tools (free), file tools (lsof), and kernel log tools (dmesg) versus the actual I/O performance tools (vmstat, iostat, iotop).

Page 1 of 11

Page 2

All pages