Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 676–750

781 questions total · 11pages · All types, answers revealed

Page 9

Page 10 of 11

Page 11
676
MCQmedium

A systems administrator creates a bash script that processes log files. The script uses a for loop to iterate over files in /var/log and runs a command on each. Which of the following would prevent the script from failing if no files match the pattern?

A.set -u
B.set -e
C.shopt -s failglob
D.shopt -s nullglob
AnswerD

By default bash leaves an unmatched glob pattern literal, so the loop runs once with the unexpanded string and the command fails. nullglob makes bash expand a non-matching pattern to nothing, so the loop body never executes.

Why this answer

`shopt -s nullglob` causes the shell to expand a glob pattern that matches no files into an empty string rather than leaving the pattern literal. Without this setting, if no files match the pattern in `/var/log`, the for loop receives the literal pattern string (e.g., `*.log`) and attempts to process it as a filename, which would cause the command to fail or produce unexpected results. Enabling nullglob ensures the loop body simply does not execute when no matches exist, preventing script failure.

Exam trap

The trap here is that candidates often confuse `nullglob` with `failglob` or assume that `set -e` or `set -u` can handle glob failures, when in fact only `nullglob` prevents the literal pattern string from being passed as an argument, thereby avoiding a command failure.

How to eliminate wrong answers

Option A is wrong because `set -u` treats unset variables as an error and causes the script to exit when referencing an undefined variable, but it does not affect how glob patterns are expanded when no files match. Option B is wrong because `set -e` causes the script to exit immediately if any command returns a non-zero exit status, but it does not change the behavior of glob expansion; a failed glob pattern would still be passed as a literal string, potentially causing a command failure that `set -e` would then propagate. Option C is wrong because `shopt -s failglob` causes the shell to print an error and exit if a glob pattern matches no files, which is the opposite of preventing script failure — it would actively cause the script to fail.

677
MCQmedium

A technician wants to check the disk I/O statistics, focusing on the average I/O wait time and utilization percentage. Which command provides this information?

A.sar -b
B.vmstat -d
C.free -h
D.iostat -x
AnswerD

`iostat -x` reports extended disk statistics, including average I/O wait time (await) and device utilisation percentage (%util), satisfying the stem's focus on both metrics. Plain `iostat` omits the extended columns, so the `-x` flag is what exposes per-device await and %util figures.

Why this answer

The iostat -x command displays extended disk I/O statistics, including per-device metrics such as average wait time (await), utilization percentage (%util), and queue sizes. The -x flag is specifically what surfaces these extended columns, making it the correct tool for analyzing I/O wait and utilization. sar -b reports overall block device activity but not per-device extended metrics like await and %util.

Exam trap

XK0-006 often tests the distinction between sar -b (aggregate block activity) and iostat -x (per-device extended metrics), so candidates who only remember 'sar does system activity' pick the wrong tool.

How to eliminate wrong answers

Option A is wrong because sar -b reports aggregate block I/O activity (tps, rtps, wtps, bread/s, bwrtn/s) but does not provide per-device average wait time or utilization percentage. Option B is wrong because vmstat -d shows disk statistics such as reads, writes, and I/O counts per device, but does not report average wait time or utilization percentage. Option C is wrong because free -h only displays memory and swap usage, not disk I/O statistics at all.

678
MCQmedium

A Linux administrator notices that a production server's root filesystem is 100% full, but du reports only 40 GB used on a 100 GB partition. Which command should the administrator use to identify deleted files still held open by running processes?

A.fuser -mv /
B.df -i
C.lsof +L1
D.find / -size +1G -exec ls -l {} \;
AnswerC

lsof +L1 lists all open files whose link count is less than 1, which indicates deleted files still held open by processes. This is exactly the situation where disk space is consumed but du cannot see it because the directory entry is gone. The +L1 filter is specifically designed to find these orphaned inodes, allowing the administrator to identify and restart the offending process.

Why this answer

The discrepancy between df and du indicates deleted files still held open by processes. lsof +L1 specifically lists open files with a link count of zero, which are deleted files still consuming disk space. This allows the administrator to identify the process holding the file and restart it to release the space.

Exam trap

The trap here is assuming that df and du should always match, but deleted files held open by processes cause df to show more usage than du reports.

679
MCQeasy

Which command will run a container in detached mode with the name 'web' and map host port 8080 to container port 80, using the nginx image?

A.docker run -d --name web -p 8080:80 nginx
B.docker exec -d --name web -p 8080:80 nginx
C.docker start -d --name web -p 8080:80 nginx
D.docker run -it --name web -p 8080:80 nginx
AnswerA

The -d flag detaches the container, --name web assigns the required name, and -p 8080:80 maps host port 8080 to container port 80. Specifying nginx as the image completes the command, satisfying every constraint in the stem exactly.

Why this answer

`docker run` creates and starts a new container. The `-d` flag runs it in detached mode (background), `--name web` assigns the name 'web', `-p 8080:80` maps host port 8080 to container port 80, and `nginx` specifies the image to use. This is the standard syntax for deploying a container with port mapping and a custom name.

Exam trap

CompTIA often tests the distinction between `docker run` (create + start) and `docker start` (start existing container), and the requirement for `-d` versus `-it` to achieve detached mode, causing candidates to confuse the subcommands or flags.

How to eliminate wrong answers

Option B is wrong because `docker exec` is used to run a command inside an existing container, not to create or start a new container; it does not accept `-d` for detached mode in the same way, and `-p` is not a valid flag for `docker exec`. Option C is wrong because `docker start` is used to start an existing stopped container, not to create a new one; it does not accept `-p` for port mapping, and the `nginx` argument would be interpreted as a container name, not an image. Option D is wrong because `-it` runs the container in interactive mode with a TTY, not detached mode; the question specifically requires detached mode (`-d`).

680
MCQeasy

Which directory in the Filesystem Hierarchy Standard (FHS) contains essential user commands available to all users, such as 'ls' and 'cp'?

A./sbin
B./opt
C./bin
D./usr/bin
AnswerC

/bin holds essential user binaries such as ls and cp, required for single-user mode and all users. The FHS reserves /sbin for system administration binaries and /usr/bin for non-essential user commands, so /bin uniquely satisfies the stem's requirement for essential commands available to everyone.

Why this answer

The /bin directory in the FHS contains essential user commands that must be available in single-user mode and for all users, such as ls, cp, mv, and cat. These binaries are required for basic system operation and are on the root filesystem so they are available even when other filesystems are not mounted. This matches the question's description precisely.

Exam trap

XK0-006 often tests the FHS distinction between /bin and /usr/bin, and candidates pick /usr/bin because it contains the same commands, forgetting that /bin is specifically for essential commands available during early boot and single-user mode.

How to eliminate wrong answers

Option A is wrong because /sbin contains essential system binaries intended for system administration and root use, such as fdisk, mkfs, and reboot — not general user commands like ls and cp. Option B is wrong because /opt is reserved for optional add-on application software packages, not core user commands. Option D is wrong because /usr/bin contains most user commands, but these are not considered essential for single-user mode or early boot; the FHS distinguishes /bin (essential, root filesystem) from /usr/bin (non-essential, may be on a separate filesystem).

681
MCQhard

An administrator wants to change the default systemd target to multi-user.target so the system boots to a text console. Which command should be used?

A.systemctl isolate multi-user.target
B.systemctl set-default multi-user.target
C.systemctl enable multi-user.target
D.systemctl mask multi-user.target
AnswerB

systemctl set-default multi-user.target writes the default target symlink, so systemd boots to a text console on subsequent starts. This directly satisfies the requirement to change the default boot target persistently, unlike isolate, which only affects the running session.

Why this answer

systemctl set-default multi-user.target sets the default target. systemctl isolate changes the current target but not the default. enable and mask are for services, not targets.

682
MCQhard

An administrator wants to run a script on multiple remote servers using Ansible. The script requires a variable that differs per host. Where should the administrator define this variable to follow best practices?

A.In the playbook under vars:
B.In host_vars/<hostname>.yml
C.In the inventory file as a variable
D.In group_vars/all.yml
AnswerB

Host-specific variables belong in host_vars/<hostname>.yml, which Ansible loads automatically for that inventory host. This keeps per-host values isolated from group and playbook scope, so the differing variable is applied only to the intended server without overriding other hosts' configuration.

Why this answer

Ansible best practice is to define host-specific variables in host_vars/<hostname>.yml, where the filename matches the inventory hostname. This keeps per-host configuration separate from the playbook and inventory, making it easy to maintain, version-control, and override at the appropriate precedence level. Variables defined here automatically apply only to that host, which is exactly what the scenario requires.

Exam trap

XK0-006 often tests Ansible variable precedence and file layout — candidates pick group_vars/all.yml because it is 'centralised', but that applies to all hosts, not per-host as the question requires.

How to eliminate wrong answers

Option A is wrong because defining the variable under vars: in the playbook applies it to all hosts in the play, not per-host, and hardcodes host-specific data into the playbook. Option C is wrong because defining variables inline in the inventory file works but is discouraged for anything beyond simple cases — it mixes inventory with configuration and is harder to maintain. Option D is wrong because group_vars/all.yml applies to every host in the inventory, which is the opposite of per-host differentiation.

683
MCQhard

An administrator is troubleshooting a boot issue. The system boots to a console with limited functionality. Which systemd target should be used to bring up the system with network and multi-user support?

A.emergency.target
B.graphical.target
C.rescue.target
D.multi-user.target
AnswerD

The multi-user.target starts systemd's non-graphical multi-user mode, activating networking and allowing multiple concurrent logins without a display manager. It satisfies the stem's requirement for network and multi-user support from a limited console, unlike graphical.target, which additionally requires a graphical session.

Why this answer

multi-user.target provides a non-graphical multi-user system with network.

684
Multi-Selectmedium

An administrator needs to grant read and write access to the 'developers' group on a directory while preserving existing permissions for the owner and others. Which TWO commands can be used to modify ACLs? (Choose two.)

Select 1 answer
A.chmod g+rw /dir
B.getfacl /dir
C.setfacl -m u:developers:rw /dir
D.setfacl -x g:developers /dir
E.setfacl -m g:developers:rw /dir
AnswersE

setfacl -m g:developers:rw sets an ACL entry for the 'developers' group, granting read and write access. This directly fulfills the requirement and is correct.

Why this answer

setfacl -m g:developers:rw /dir is the correct command to grant read-write access to the developers group. Option C uses u:developers, which sets an ACL for a user named 'developers', not the developers group, so it does not satisfy the requirement. chmod changes standard permissions, getfacl only displays ACLs, and setfacl -x removes ACL entries. Therefore, only option E is correct.

Exam trap

Candidates often confuse the user and group flags in setfacl. The -m option can specify either u: for user or g: for group. Ensure the correct entity type is used based on whether you need to assign permissions to a user or a group.

685
MCQhard

A security administrator is hardening a Linux server that uses firewalld. The server hosts a web application that must be accessible only from the internal network 192.168.1.0/24 on port 443. The administrator wants to implement this using a rich rule in the public zone and ensure it persists across reboots. Which sequence of commands should the administrator use?

A.firewall-cmd --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --runtime-to-permanent
B.firewall-cmd --permanent --zone=public --add-service=https && firewall-cmd --reload
C.firewall-cmd --permanent --zone=public --add-source=192.168.1.0/24 --add-port=443/tcp && firewall-cmd --reload
D.firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="192.168.1.0/24" port port="443" protocol="tcp" accept' && firewall-cmd --reload
AnswerD

This command adds a permanent rich rule to the public zone that accepts IPv4 traffic from the specified subnet to TCP port 443, then reloads firewalld to apply the change immediately. The --permanent flag ensures the rule survives reboots, and the reload activates it without dropping existing connections.

Why this answer

Using a rich rule with --permanent allows granular control, specifying source address, port, and protocol in one rule. The subsequent reload applies the permanent configuration to the runtime environment. This meets the requirement of restricting access to the internal subnet on port 443 and ensuring persistence.

Exam trap

The trap here is confusing the --permanent flag with the need to reload, or assuming that adding a service or separate source/port achieves the same granular restriction as a rich rule.

686
MCQeasy

A team uses Ansible for configuration management. A playbook fails with the error 'ERROR! Syntax Error while loading YAML script'. Which of the following is the most likely cause?

A.Missing SSH key
B.Incorrect indentation in the YAML file
C.Invalid module name
D.Playbook not executable
AnswerB

YAML defines structure through indentation rather than braces, so misaligned keys or list items break parsing before any task executes. Ansible reports this as a syntax error while loading the YAML script, matching the stem exactly.

Why this answer

The error 'Syntax Error while loading YAML script' indicates that Ansible's YAML parser encountered a structural problem in the playbook file. The most common cause in YAML is incorrect indentation, because YAML relies on consistent spacing (typically 2 spaces per level) to define the hierarchy of tasks, plays, and variables. A missing SSH key would produce a connection or authentication error, not a YAML syntax error.

Exam trap

The trap here is that candidates may confuse a YAML parsing error with a runtime execution error, such as an SSH key issue or an invalid module, because they all prevent the playbook from running successfully.

How to eliminate wrong answers

Option A is wrong because a missing SSH key causes an authentication failure (e.g., 'Permission denied (publickey)') during the connection phase, not a YAML syntax error during parsing. Option C is wrong because an invalid module name results in a module-specific error (e.g., 'ERROR! couldn't resolve module/action'), not a YAML syntax error. Option D is wrong because playbooks are not executed as standalone scripts; Ansible runs them via the `ansible-playbook` command, so the executable bit is irrelevant — the error would be a 'Permission denied' if the file were executed directly, not a YAML syntax error.

687
MCQmedium

A security policy requires that user passwords must expire every 90 days. Which command can enforce this policy for user 'jsmith'?

A.usermod -e 90 jsmith
B.chage -M 90 jsmith
C.passwd -x 90 jsmith
D.chfn -f 90 jsmith
AnswerB

`chage -M 90 jsmith` sets the maximum password age to 90 days, satisfying the policy's expiry requirement. Unlike `passwd`, which handles only the current user's own password, `chage` lets an administrator modify another account's aging fields directly, so jsmith's password must be changed every 90 days.

Why this answer

The `chage -M 90 jsmith` command sets the maximum number of days a password is valid for user 'jsmith' to 90, which enforces the 90-day expiration policy. The `-M` option directly modifies the `PASS_MAX_DAYS` field in `/etc/shadow`, and `chage` is the standard tool for managing password aging on Linux systems.

Exam trap

The trap here is that candidates confuse `usermod -e` (account expiry) with `chage -M` (password expiry), or assume `passwd -x` works without the correct syntax, leading them to pick a command that either targets the wrong attribute or has an invalid option order.

How to eliminate wrong answers

Option A is wrong because `usermod -e` sets the account expiration date (in YYYY-MM-DD format), not the password aging interval; `-e 90` would be interpreted as a date offset from epoch, not a day count. Option C is wrong because `passwd -x 90` is not a valid syntax; the `passwd` command uses `-x` to set maximum password days, but it requires the username immediately after the option (e.g., `passwd -x 90 jsmith`), and even then it is less commonly used than `chage` for policy enforcement. Option D is wrong because `chfn -f 90` changes the user's full name (GECOS field), not password expiration; `-f` expects a string, not a numeric day value.

688
MCQhard

A system administrator is tuning a server for a high-performance computing workload and needs to disable NUMA (Non-Uniform Memory Access) at boot to improve memory access latency. Which kernel boot parameter should be added to the GRUB_CMDLINE_LINUX line in /etc/default/grub?

A.maxcpus=1
B.numa=off
C.acpi=off
D.noapic
AnswerB

Appending numa=off to GRUB_CMDLINE_LINUX passes the parameter to the kernel at boot, disabling NUMA awareness so memory is treated as a single uniform node. This reduces cross-node access latency for the high-performance workload, as the scenario requires.

Why this answer

The `numa=off` kernel boot parameter explicitly disables NUMA support in the Linux kernel, forcing memory to be treated as a single contiguous block (UMA). This eliminates the latency penalty of remote memory accesses, which is beneficial for high-performance computing workloads that require consistent, low-latency memory access across all CPUs.

Exam trap

The trap here is that candidates often confuse `numa=off` with other hardware-disabling parameters like `acpi=off` or `noapic`, assuming any 'disable hardware feature' parameter will fix memory latency, when only `numa=off` directly addresses NUMA memory access behavior.

How to eliminate wrong answers

Option A is wrong because `maxcpus=1` limits the system to a single CPU core, which severely reduces parallel processing capability and is counterproductive for high-performance computing workloads. Option C is wrong because `acpi=off` disables Advanced Configuration and Power Interface, which can cause loss of power management, thermal control, and hardware enumeration features, but does not directly affect NUMA behavior. Option D is wrong because `noapic` disables the Advanced Programmable Interrupt Controller, which may affect interrupt routing but has no impact on NUMA memory access or latency.

689
MCQeasy

A user is unable to create new files in a directory. Which command can the administrator use to view the Access Control Lists (ACLs) associated with that directory?

A.getfacl
B.ls -l
C.setfacl
D.chmod
AnswerA

`getfacl` reads and displays a file or directory's full ACL entries, including the owner, group, other permissions and any extended access control entries. Since the user cannot create files, inspecting those extended entries reveals whether write and execute permissions are missing for that user or group, which standard `ls -l` output cannot show.

Why this answer

The `getfacl` command displays the Access Control Lists (ACLs) for a file or directory, showing both the standard POSIX permissions and any additional ACL entries (e.g., specific users or groups). Since the user cannot create new files, ACLs may be restricting write access beyond the basic mode bits, making `getfacl` the correct tool to inspect these extended permissions.

Exam trap

The trap here is that candidates often confuse `ls -l` with ACL viewing, assuming the standard permission string (e.g., `drwxr-xr-x`) fully represents access rights, when in fact ACLs can override or extend those bits without changing the mode display.

How to eliminate wrong answers

Option B is wrong because `ls -l` shows only the traditional Unix permission bits (owner, group, other) and cannot display extended ACL entries that might be blocking file creation. Option C is wrong because `setfacl` is used to modify or set ACLs, not to view them; using it without the `-g` or `-m` options would not show current ACLs. Option D is wrong because `chmod` changes the basic permission mode bits and cannot read or display ACL entries.

690
MCQmedium

A Linux administrator is configuring a persistent mount for a new 2TB XFS filesystem on /dev/sdb1 so it mounts automatically at /data with quota accounting enabled. The administrator edits /etc/fstab and adds the entry, then runs mount -a to validate it. Which fstab field combination correctly applies user and group quota accounting on this XFS mount?

A./dev/sdb1 /data xfs defaults,quota 0 0
B./dev/sdb1 /data xfs defaults,uquota,gquota 0 0
C./dev/sdb1 /data xfs defaults,noquota 0 0
D./dev/sdb1 /data xfs defaults,usrquota,grpquota 0 0
AnswerB

The XFS driver recognizes uquota and gquota as the correct mount options to activate user and group quota accounting. Placing them in the fourth fstab field ensures the filesystem mounts with quota accounting enabled at boot. After mounting, the administrator still must run xfs_quota to assign limits, but accounting itself is correctly enabled by these options combined with defaults.

Why this answer

XFS uses its own quota mount keywords rather than the legacy ext-family usrquota/grpquota options. Specifying uquota and gquota in the fourth fstab field enables both user and group quota accounting each time the filesystem mounts, which satisfies the requirement for automatic quota enforcement at boot. The remaining options either use unsupported keywords or disable quotas entirely.

Exam trap

The trap here is assuming XFS accepts the same usrquota and grpquota keywords that ext4 uses, when XFS actually requires its own uquota and gquota mount options.

691
MCQhard

A technician needs to create a new ext4 filesystem on /dev/sdb1 and mount it persistently at /mnt/data. Which set of commands accomplishes this?

A.mkfs -t ext4 /dev/sdb1; mount /dev/sdb1 /mnt/data; echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab
B.mkfs.ext4 /dev/sdb1; echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab
C.mkfs.ext4 /dev/sdb1; mount /dev/sdb1 /mnt/data
D.echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab; mount -a
E.fdisk /dev/sdb1; mount /dev/sdb1 /mnt/data; echo '/dev/sdb1 /mnt/data ext4 defaults 0 2' >> /etc/fstab
AnswerA

mkfs -t ext4 creates the filesystem, mount attaches it at /mnt/data, and the /etc/fstab entry with dump 0 and pass 2 makes the mount persistent across reboots. The pass value 2 suits a non-root filesystem.

Why this answer

The correct sequence must (1) create the filesystem with mkfs, (2) mount it now so it is usable immediately, and (3) add an /etc/fstab entry so the mount persists across reboots. Option A does all three in the right order using mkfs -t ext4, mount, and an fstab line with dump=0 and fsck pass=2. The fsck pass value of 2 is appropriate for a non-root filesystem.

Exam trap

The trap here is conflating 'persistent' with 'immediately usable' — candidates forget that fstab alone does not mount the filesystem, and that mkfs must precede any mount attempt.

How to eliminate wrong answers

Option B is wrong because it creates the filesystem and writes fstab but never mounts the filesystem, so /mnt/data is not active until reboot or a manual mount -a. Option C is wrong because it mounts the filesystem but omits the /etc/fstab entry, so the mount is not persistent. Option D is wrong because it writes fstab and runs mount -a but never creates the ext4 filesystem, so mount -a would fail or mount an unrecognized filesystem.

Option E is wrong because fdisk is a partitioning tool, not a filesystem creation tool; running fdisk on /dev/sdb1 would attempt to partition a partition and does not create ext4.

692
Multi-Selectmedium

A Linux administrator is configuring secure remote access to a server. Which three of the following are recommended best practices for securing SSH? (Choose three.)

Select 3 answers
A.Enable public key authentication.
B.Use password authentication only.
C.Disable root login via SSH.
D.Change the default SSH port to a non-standard port.
E.Allow only specific users or groups.
AnswersA, C, E

Key-based authentication is more secure than passwords.

Why this answer

Public key authentication (Option A) is a recommended best practice because it uses asymmetric cryptography (RSA, ECDSA, or Ed25519) to authenticate users without transmitting passwords over the network. This eliminates the risk of password interception via man-in-the-middle attacks or brute-force attempts, as the private key never leaves the client and the server verifies only the corresponding public key.

Exam trap

The trap here is that candidates often mistake changing the default SSH port (Option D) for a genuine security control, when it is merely obscurity and not a recommended best practice in the Linux+ exam objectives.

693
MCQeasy

Which Kubernetes resource is used to store non-sensitive configuration data as key-value pairs that can be consumed by pods?

A.Deployment
B.Secret
C.Namespace
D.ConfigMap
AnswerD

ConfigMaps hold non-sensitive configuration as key-value pairs, decoupling configuration from pod images. Pods consume them via environment variables, command-line arguments, or mounted volumes. Sensitive data belongs in Secrets instead, which store base64-encoded values and support encryption at rest.

Why this answer

ConfigMaps are used for non-sensitive configuration data. Secrets are for sensitive data like passwords. Deployments manage replicas of pods.

Namespaces isolate resources.

694
Multi-Selecteasy

An administrator needs to create a hard link to an existing file. Which two statements are true about hard links? (Choose two.)

Select 2 answers
A.Hard links can be created for directories
B.Hard links can be created across different filesystems
C.Hard links are indistinguishable from the original file
D.Hard links share the same inode number
E.Deleting the original file removes the hard link
AnswersC, D

Hard links share the same inode as the original file, so both directory entries reference identical metadata and data blocks. No separate inode exists to distinguish them, satisfying the stem's requirement that the link is indistinguishable from the original. Deleting either name leaves the other fully functional until the link count reaches zero.

Why this answer

Option C is correct because a hard link is simply another directory entry that points to the same inode, so it has identical permissions, ownership, timestamps, and content as the original file and cannot be distinguished from it by normal file operations. Option D is correct because creating a hard link with ln (without -s) increments the inode's link count and gives the new name the same inode number as the original file, which is why both names reference the same data blocks. Option A is wrong because hard links to directories are prohibited on Linux filesystems to prevent cycles in the directory tree.

Option B is wrong because a hard link must reside on the same filesystem as the target file, since inode numbers are only unique within a single filesystem. Option E is wrong because deleting the original name only decrements the link count; the data remains accessible through the remaining hard link until the link count reaches zero.

695
MCQmedium

A DevOps engineer is writing a unit file for a systemd service that should start after the network-online.target. Which directive should be added to the [Unit] section?

A.Requires=network-online.target
B.Wants=network-online.target
C.BindsTo=network-online.target
D.After=network-online.target
AnswerD

After=network-online.target establishes ordering only, ensuring the unit starts once network-online.target has activated, which satisfies the stem's requirement to start after the network is online. Pair it with Wants=network-online.target to also pull that target in; After alone does not create a dependency.

Why this answer

The 'After=' directive in the [Unit] section of a systemd unit file specifies the ordering relationship, ensuring that the current service starts only after the named unit (network-online.target) has reached the 'active' state. This is the correct directive for controlling startup order without creating a dependency that would force the target to start if it is not already enabled.

Exam trap

The trap here is that candidates confuse ordering directives ('After=', 'Before=') with dependency directives ('Requires=', 'Wants=', 'BindsTo='), assuming that 'Requires=' or 'Wants=' also imply ordering, which they do not without an explicit 'After='.

How to eliminate wrong answers

Option A is wrong because 'Requires=' creates a hard dependency that will cause the service to fail if network-online.target is not started, but it does not enforce ordering; the service could start before the target unless 'After=' is also used. Option B is wrong because 'Wants=' creates a soft dependency that attempts to start network-online.target but does not enforce ordering; the service may start before the target completes. Option C is wrong because 'BindsTo=' creates a stronger dependency than 'Requires=' where the service will stop if network-online.target stops, and it also does not imply ordering; it is used for tightly coupled services, not for simple startup sequencing.

696
MCQmedium

A Linux server's /var/log partition is 100% full and rsyslogd has stopped writing logs. The administrator needs to find which directories under /var/log consume the most space without deleting anything. Which command should the administrator run?

A.ls -laR /var/log | less
B.du -sh /var/log/* | sort -rh | head -n 10
C.df -h /var/log
D.find /var/log -type f -size +100M -delete
AnswerB

This command summarizes the disk usage of each immediate item under /var/log in human-readable form, sorts them in descending order, and shows the top ten. It identifies the largest directories or files without modifying anything, which directly addresses the need to locate space consumers on the full partition.

Why this answer

To find what is filling a filesystem, aggregate usage per directory and sort by size. du -sh with a glob gives one line per item under /var/log, and sort -rh orders them largest first, so the top offenders are immediately visible. df only shows the filesystem total, find -delete destroys data, and recursive ls provides no aggregation.

Exam trap

The trap here is reaching for df, which confirms the partition is full but cannot identify which subdirectory or file is consuming the space.

697
MCQeasy

An administrator wants to find all files larger than 100MB in the /var directory. Which command should be used?

A.find /var -size +100kb
B.find /var -type f -size +100M
C.ls -l /var | grep 100M
D.du -sh /var/* | grep M
AnswerB

The -size +100M predicate matches regular files exceeding 100 mebibytes, and -type f restricts results to files rather than directories. This satisfies the stem's requirement to locate files larger than 100MB within /var using a single find invocation.

Why this answer

The find command with -size +100M searches for files larger than 100 megabytes, and -type f restricts results to regular files. Running 'find /var -type f -size +100M' correctly locates all regular files under /var exceeding 100MB. This is the standard, precise way to search by size in Linux.

Exam trap

XK0-006 often tests whether candidates confuse size units (kb vs M vs G) and forget that find requires -type f to exclude directories, leading them to pick options that match the wrong unit or miss subdirectories.

How to eliminate wrong answers

Option A is wrong because '+100kb' searches for files larger than 100 kilobytes, not 100 megabytes, and it omits -type f so it may match directories. Option C is wrong because 'ls -l /var | grep 100M' only lists the immediate contents of /var and greps for the literal string '100M', which does not reliably match file sizes and misses subdirectories. Option D is wrong because 'du -sh /var/*' shows the total size of each top-level item in /var, not individual files larger than 100MB, and grep 'M' matches any size containing 'M'.

698
MCQmedium

A system is experiencing high memory usage. The administrator wants to see a brief summary of memory usage in human-readable format, including buffers and cache. Which command is most appropriate?

A.free -h
B.iostat -m
C.cat /proc/meminfo
D.vmstat -s
AnswerA

`free -h` reads `/proc/meminfo` and prints a concise table of total, used, free, shared, buff/cache and available memory, with the `-h` flag scaling values into human-readable units such as MiB and GiB. This satisfies the stem's requirement for a brief summary that explicitly includes buffers and cache.

Why this answer

free -h is correct because it prints a concise summary of total, used, free, shared, buff/cache, and available memory in human-readable units (MiB/GiB), directly satisfying the requirement to include buffers and cache. The -h flag converts raw kilobytes into readable values, making it the most appropriate single command for a quick memory overview.

Exam trap

The trap here is confusing memory tools with I/O tools: candidates see 'human-readable' and 'buffers and cache' and may pick /proc/meminfo or vmstat -s, but only free -h provides the brief, formatted summary the question demands.

How to eliminate wrong answers

Option B is wrong because iostat -m reports CPU utilization and disk I/O statistics in megabytes per second, not memory usage. Option C is wrong because cat /proc/meminfo dumps dozens of raw kernel counters in kilobytes with no human-readable formatting and no summary, requiring manual interpretation. Option D is wrong because vmstat -s prints a long list of memory-related event counters and statistics rather than a brief human-readable summary with buffers and cache.

699
MCQeasy

A bash script uses a for loop to iterate over files in a directory. Which of the following correctly assigns each filename to the variable FILE?

A.for FILE in $(ls *.txt); do
B.for FILE in *.txt; do
C.for FILE in 'ls *.txt'; do
D.for FILE = *.txt; do
AnswerB

The glob *.txt undergoes pathname expansion, so the for loop assigns each matching filename in the current directory to FILE on successive iterations. Quoting the pattern or using command substitution would break that per-file assignment.

Why this answer

The shell expands the wildcard pattern `*.txt` into a list of matching filenames before the `for` loop executes, and each filename is assigned to the variable `FILE` in turn. This approach is safe and efficient because it avoids parsing the output of `ls`, which can break with filenames containing spaces or special characters.

Exam trap

The trap here is that candidates often choose `$(ls *.txt)` (Option A) because they think they need to explicitly list files with `ls`, not realizing that the shell's built-in globbing is safer and more efficient, and that `ls` output parsing is fragile.

How to eliminate wrong answers

Option A is wrong because `$(ls *.txt)` uses command substitution to run `ls`, which parses its output and can break on filenames with spaces, newlines, or glob characters; it also forks an unnecessary subshell. Option C is wrong because `'ls *.txt'` is a literal string (single quotes prevent expansion), so the loop would iterate over the single string `ls *.txt` instead of actual filenames. Option D is wrong because the syntax `for FILE = *.txt` uses an equals sign instead of the required `in` keyword, which is a syntax error in bash.

700
MCQmedium

A Linux administrator needs to configure a system to use a central authentication service. The service requires that user credentials are sent over the network in an encrypted format and that the client validates the server's certificate. Which of the following should the administrator configure?

A.Configure Kerberos with a keytab file and set the default realm in /etc/krb5.conf.
B.Configure NIS with a secured map and use ypbind with a password.
C.Configure SSSD with ldap_id_use_start_tls = true and ldap_tls_reqcert = never.
D.Configure LDAP with TLS using the ldaps:// URI and set TLS_REQCERT to demand in /etc/ldap/ldap.conf.
AnswerD

Using LDAPS (LDAP over TLS) encrypts the authentication traffic. Setting TLS_REQCERT to demand enforces certificate validation, ensuring the client verifies the server's certificate. This meets both the encryption and validation requirements. It is a standard way to secure LDAP communications.

Why this answer

LDAP with TLS (LDAPS) encrypts authentication traffic, and setting TLS_REQCERT to demand ensures the client validates the server's certificate. This combination meets both the encryption and validation requirements. The other options either lack certificate validation or use insecure protocols.

Exam trap

The trap here is confusing encryption with certificate validation; some options encrypt traffic but do not verify the server's identity.

701
MCQhard

A company is implementing a security policy that requires all files created in a shared directory /data to be owned by the group 'engineers' and have group read/write permissions, regardless of the user's umask. Which approach should be used?

A.Set the setgid bit only on /data
B.Set the sticky bit on /data
C.Configure ACL default permissions only on /data
D.Set the setgid bit and configure ACL default permissions on /data
AnswerD

The setgid bit forces new files to inherit the directory's group ('engineers') rather than the creator's primary group, while default ACLs apply group rw permissions regardless of umask. Together they satisfy both constraints: group ownership and group read/write on every file created in /data.

Why this answer

Setting the setgid bit on /data ensures that new files inherit the group ownership of the directory (engineers), but it does not override the user's umask for permissions. Configuring ACL default permissions on /data explicitly sets the group read/write permissions for new files, overriding the umask. Together, they guarantee both correct group ownership and group rw permissions regardless of the user's umask.

Exam trap

The trap here is that candidates often assume the setgid bit alone is sufficient for both ownership and permissions, overlooking that it does not override the umask for permission bits.

How to eliminate wrong answers

Option A is wrong because the setgid bit alone only forces group ownership inheritance; it does not control the permissions applied to new files, which are still subject to the user's umask. Option B is wrong because the sticky bit restricts file deletion to owners or root; it does not affect ownership or permissions of new files. Option C is wrong because ACL default permissions alone set the permissions for new files but do not enforce group ownership inheritance; without the setgid bit, new files may be owned by the user's primary group, not 'engineers'.

702
Matchingmedium

Match each Linux kernel parameter category to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

General kernel behavior

Virtual memory management

Network settings

Filesystem parameters

Device-specific settings

Why these pairings

Linux sysctl parameters are organized under categories such as kernel, vm, net, and fs. The kernel category handles general system limits, vm manages virtual memory, net controls networking, and fs deals with filesystem settings. Ensure each description matches its correct category.

703
Multi-Selecthard

A Linux administrator needs to grant temporary, time-limited administrative access to a contractor on a production server. The contractor must be able to run only `/usr/bin/systemctl restart nginx` as root without a password, and all actions must be logged. The administrator plans to use sudo. Which two steps are required to meet these requirements? (Choose two.)

Select 2 answers
A.Create a file in /etc/sudoers.d/ with a rule like `contractor ALL=(root) NOPASSWD: /usr/bin/systemctl restart nginx` and validate it with visudo -c.
B.Add the contractor to the wheel group and rely on the default `%wheel ALL=(ALL) ALL` rule.
C.Enable sudo I/O logging by adding `Defaults log_output` and ensure the sudo log file or syslog destination is writable.
D.Set the contractor account's shell to /sbin/nologin to limit interactive access.
E.Add `contractor ALL=(ALL) NOPASSWD: ALL` to /etc/sudoers to simplify future administration.
AnswersA, C

A drop-in file under /etc/sudoers.d provides the specific command authorization, and NOPASSWD satisfies the no-password requirement. Restricting the command to the exact systemctl restart nginx invocation follows least privilege. Running visudo -c validates syntax and prevents a malformed sudoers file from locking out sudo, which is essential when editing production access controls.

Why this answer

Satisfying the requirement needs both a narrowly scoped sudo rule and audit logging. A drop-in file in /etc/sudoers.d with a command-specific NOPASSWD rule authorizes exactly the restart operation, while validating with visudo -c protects sudo integrity. Enabling log_output and ensuring the log destination is writable provides the session logging demanded for all actions.

Together these implement least privilege and accountability without granting broad root access.

Exam trap

The trap here is equating 'administrative access' with full sudo via wheel or NOPASSWD: ALL, when the scenario explicitly limits the allowed command to one systemctl invocation.

704
MCQmedium

A process is consuming excessive CPU and needs to be terminated immediately. The PID is 1234. Which command will terminate the process with the most forceful signal?

A.kill -15 1234
B.kill -1 1234
C.kill -9 1234
D.kill -19 1234
AnswerC

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 1234 immediately without allowing cleanup — satisfying the stem's demand for the most forceful signal. Weaker signals such as SIGTERM (15) can be trapped or deferred, which would not guarantee immediate termination.

Why this answer

kill -9 (SIGKILL) forcibly terminates the process. SIGTERM (15) is graceful; SIGHUP (1) reloads config; SIGSTOP (19) suspends.

705
MCQmedium

A Linux server's root filesystem is filling rapidly. The administrator suspects a process is writing to a deleted file that still holds space. They want to identify which running process has an open file descriptor to a deleted file. Which command should they use?

A.vmstat 1 5
B.ps aux --sort=-%mem
C.lsof +L1
D.df -i /
AnswerC

The lsof +L1 option lists open files with a link count less than one, which identifies deleted files still held open by a process. This directly reveals processes writing to unlinked files that continue to consume disk space. The output shows the PID, command, and file path with a (deleted) marker, giving the administrator exactly the information needed to restart or kill the offending process and reclaim space.

Why this answer

When a process holds a deleted file open, the inode and its blocks remain allocated until the process closes or exits, so the space does not return to the filesystem. The lsof command with +L1 filters open files whose link count is below one, precisely matching deleted-but-open files. It outputs the responsible PID and command, enabling the administrator to restart the process and reclaim the space.

Exam trap

The trap here is assuming that deleting a file immediately frees disk space, when an open file descriptor keeps the inode and blocks allocated until the process releases them.

706
Multi-Selectmedium

A system administrator needs to monitor real-time process information and system resource usage. Which two commands can be used for this purpose? (Choose two.)

Select 2 answers
A.kill
B.top
C.htop
D.jobs
E.ps aux
AnswersB, C

top reads /proc to display live per-process CPU, memory and load statistics, refreshing periodically. It satisfies the real-time process and resource monitoring requirement, complementing htop, which offers the same underlying data with an enhanced interactive interface.

Why this answer

Option B (top) is correct because it launches an interactive, real-time process viewer that continuously refreshes CPU, memory, load average, and per-process statistics, exactly matching the requirement for live process and resource monitoring. Option C (htop) is also correct because it is an enhanced interactive process viewer that provides the same real-time monitoring with additional features such as colorized output, scrollable process lists, and per-core CPU meters. Option A (kill) is incorrect because it only sends signals to terminate or control existing processes and does not display monitoring data.

Option D (jobs) is incorrect because it merely lists jobs in the current shell session and shows no system resource usage. Option E (ps aux) is incorrect because it produces a static snapshot of processes at the moment of execution rather than continuous real-time monitoring.

Exam trap

The trap here is confusing static process-listing tools like ps and jobs with true real-time monitoring tools; candidates who see 'process information' and reflexively pick ps aux miss the 'real-time' qualifier that only top and htop satisfy.

707
MCQmedium

An administrator needs to generate a self-signed certificate and private key for a web server. Which openssl command accomplishes this?

A.openssl genrsa -out key.pem 2048 && openssl req -new -x509 -key key.pem -out cert.pem -days 365
B.openssl req -new -key key.pem -out csr.pem
C.openssl ca -in csr.pem -out cert.pem
D.openssl x509 -req -in csr.pem -signkey key.pem -out cert.pem
AnswerA

Chaining genrsa with req -new -x509 produces both the private key and a self-signed certificate in one pass. The -x509 flag makes req emit a certificate rather than a signing request, satisfying the self-signed requirement without a separate CA step.

Why this answer

It first generates a 2048-bit RSA private key using `openssl genrsa`, then uses `openssl req -new -x509` to create a self-signed X.509 certificate directly from that key, bypassing the need for a Certificate Signing Request (CSR). The `-x509` flag tells OpenSSL to output a self-signed certificate instead of a CSR, and `-days 365` sets the validity period. This two-step process produces both the private key (`key.pem`) and the self-signed certificate (`cert.pem`) required for a web server.

Exam trap

The trap here is that candidates may confuse the `openssl req -new -x509` command with the CSR-only `openssl req -new` command, or think that a CSR is required for self-signed certificates, when in fact the `-x509` flag directly outputs a self-signed certificate without needing a separate CSR step.

How to eliminate wrong answers

Option B is wrong because `openssl req -new -key key.pem -out csr.pem` only generates a Certificate Signing Request (CSR), not a self-signed certificate; it requires a CA to sign the CSR to produce a certificate. Option C is wrong because `openssl ca -in csr.pem -out cert.pem` assumes a CA infrastructure is already set up and configured, and it signs an existing CSR using the CA's own key and certificate, which is not a self-signed certificate generation process. Option D is wrong because `openssl x509 -req -in csr.pem -signkey key.pem -out cert.pem` creates a self-signed certificate from a CSR, but it requires a CSR to already exist (generated by a separate command), making it a two-step process that is less direct than Option A; more importantly, it does not generate the private key, so it is incomplete for the stated requirement.

708
MCQeasy

Which command is used to display the current process hierarchy in a tree format?

A.pstree
B.lsproc
C.ps aux
D.top
AnswerA

pstree reads the process table and renders parent-child relationships as an indented tree, showing the hierarchy from init or the specified PID downwards. This directly satisfies the requirement to display the current process hierarchy in tree format.

Why this answer

The pstree command displays running processes as a tree, showing parent-child relationships with branches, which is exactly what the question asks for. It reads process information from /proc and renders the hierarchy visually, optionally with -p to show PIDs and -u to show users. None of the other commands present the hierarchy in tree format.

Exam trap

The trap is confusing 'list all processes' (ps aux, top) with 'show process hierarchy as a tree' — candidates who skim the question pick ps aux because it is the most familiar process-listing command.

How to eliminate wrong answers

Option B is wrong because lsproc is not a standard Linux command — there is no such utility in coreutils or procps, so it cannot display a process tree. Option C is wrong because ps aux lists all processes in a flat, tabular format with columns for user, PID, CPU, memory, and command, but it does not show parent-child relationships as a tree. Option D is wrong because top provides a real-time, dynamically refreshing view of processes sorted by resource usage, again in a flat list rather than a hierarchical tree.

709
Multi-Selecthard

A Linux server is experiencing intermittent connectivity issues. The administrator reviews the system logs and finds the following messages: 'NETDEV WATCHDOG: eth0: transmit queue 0 timed out'. Which THREE actions are likely to resolve this issue? (Choose three.)

Select 3 answers
A.Disable NIC offloading features using 'ethtool -K eth0 tx off sg off'.
B.Update the network interface card (NIC) driver to the latest version.
C.Increase the transmit queue length using 'ifconfig eth0 txqueuelen 10000'.
D.Change the MTU on the interface to 9000.
E.Replace the NIC with a known good one.
AnswersA, B, E

Offloading can cause driver bugs; disabling it may stabilize the interface.

Why this answer

The 'NETDEV WATCHDOG: eth0: transmit queue 0 timed out' error often indicates that the NIC's hardware offloading features (such as TCP segmentation offload, scatter-gather) are causing the driver to hang or fail to complete transmissions. Disabling these offloads with 'ethtool -K eth0 tx off sg off' forces the CPU to handle packet segmentation and reduces the load on the NIC, which can resolve the timeout.

Exam trap

The trap here is that candidates may confuse transmit queue timeout with a simple buffer exhaustion issue and incorrectly choose to increase the transmit queue length (option C), when the real cause is a driver or hardware fault that requires disabling offloads, updating the driver, or replacing the NIC.

710
MCQeasy

A user cannot write to a directory that has permissions 755. The user is not the owner but belongs to the group. Which command would allow the user to write?

A.chmod 770 /directory
B.chmod 755 /directory
C.chmod 777 /directory
D.chmod 700 /directory
AnswerA

chmod 770 grants the group read, write and execute, so the non-owner group member gains write access to the directory. The existing 755 gave the group only read and execute, which is why writing failed.

Why this answer

The directory currently has permissions 755, meaning the owner has rwx (7), the group has r-x (5), and others have r-x (5). Since the user belongs to the group but is not the owner, they need group write permission. The chmod 770 command sets the group permission to rwx (7), granting the user write access while preserving owner and group ownership semantics.

Exam trap

The trap here is that candidates may choose chmod 777 thinking it is the only way to grant write access, overlooking that the user is already in the group and only group write permission is needed.

How to eliminate wrong answers

Option B is wrong because chmod 755 sets group permission to r-x (5), which does not include write permission, so the user still cannot write. Option C is wrong because chmod 777 grants write permission to everyone (owner, group, and others), which is overly permissive and violates the principle of least privilege; it would work but is not the minimal correct solution. Option D is wrong because chmod 700 sets group permission to --- (0), removing all group access, which would prevent the user from even reading or executing the directory.

711
MCQeasy

A security audit reveals that the /etc/shadow file has permissions 777. Which command should be used to correct this vulnerability?

A.chmod 660 /etc/shadow
B.chmod 600 /etc/shadow
C.chmod 644 /etc/shadow
D.chmod 640 /etc/shadow
AnswerB

chmod 600 grants read and write only to root, removing world and group access that 777 permits. This satisfies the audit requirement by restricting /etc/shadow to its owner, preventing unprivileged users from reading password hashes.

Why this answer

The /etc/shadow file stores hashed user passwords and must be readable only by root to prevent unauthorized access. Permissions 777 allow any user to read, write, and execute the file, which is a critical security vulnerability. The correct command is `chmod 600 /etc/shadow`, which sets read and write permissions for the owner (root) only, denying all access to group and others.

Exam trap

The trap here is that candidates often confuse the required permissions for /etc/shadow with those for /etc/passwd (which is 644), leading them to choose 644 or 640 instead of the more restrictive 600.

How to eliminate wrong answers

Option A is wrong because 660 grants read and write to both owner and group, which would allow members of the group (often 'shadow') to read password hashes, violating the principle of least privilege. Option C is wrong because 644 grants read access to everyone, exposing password hashes to all users on the system. Option D is wrong because 640 grants read access to the group, which is still too permissive for a file containing sensitive password data.

712
MCQeasy

Which log file typically records authentication failures and successes on a Debian-based system?

A./var/log/auth.log
B./var/log/messages
C./var/log/syslog
D./var/log/secure
AnswerA

On Debian-based systems, the PAM and SSH authentication subsystems write both successful and failed login events to /var/log/auth.log, making it the file that records authentication outcomes. Other distributions use /var/log/secure instead, but Debian's convention is auth.log.

Why this answer

On Debian-based systems (including Ubuntu), /var/log/auth.log is the default log file where the system's authentication subsystem writes both successful and failed authentication events. It captures output from PAM, sudo, su, sshd, and other login-related services, making it the canonical place to audit who logged in or failed to log in. Because Debian's rsyslog configuration routes authpriv facility messages to this file, it is the correct answer for authentication success and failure records.

Exam trap

XK0-006 often tests the Debian-vs-RHEL log file split, tricking candidates who memorize /var/log/secure or /var/log/messages as universal authentication logs when those are Red Hat conventions.

How to eliminate wrong answers

Option B is wrong because /var/log/messages is the general system log on Red Hat-based distributions (RHEL, CentOS, Fedora), not the authentication-specific log on Debian; Debian does not create it by default. Option C is wrong because /var/log/syslog aggregates general system and kernel messages on Debian, but authentication events are split out into auth.log via the authpriv facility, so syslog is not the primary authentication record. Option D is wrong because /var/log/secure is the authentication log used by Red Hat-based systems, not Debian-based ones, and does not exist by default on Debian.

713
Multi-Selectmedium

An Ansible playbook is being written to manage web servers. Which TWO modules can be used to ensure a package is installed? (Select TWO.)

Select 2 answers
A.copy
B.service
C.apt
D.yum
E.template
AnswersC, D

The apt module manages Debian-family packages via dpkg and APT repositories, so it satisfies the requirement to ensure a package is installed on Debian or Ubuntu web servers. It provides idempotent state=present handling, unlike command or shell, which would re-run unconditionally.

Why this answer

The apt module is for Debian-based systems, and yum is for Red Hat-based systems. Both manage packages.

714
MCQeasy

Which command displays the current SELinux mode?

A.selinuxenabled
B.getsebool -a
C.chcon
D.sestatus
AnswerD

Running `sestatus` queries the SELinux kernel subsystem and prints the current enforcement mode (Enforcing, Permissive, or Disabled) alongside policy version and loaded policy name. This directly satisfies the stem's requirement to display the current mode, unlike `setenforce`, which changes it, or `getenforce`, which shows only the mode.

Why this answer

The 'sestatus' command displays the current SELinux mode, including whether it is enforcing, permissive, or disabled, along with other SELinux status information.

715
MCQeasy

A junior administrator is tasked with setting up a file server using NFS on a Linux server. The /etc/exports file currently contains: /srv/nfs *(rw,sync,no_subtree_check). The administrator wants to restrict access to only the 192.168.10.0/24 network and require clients to use a privileged port (less than 1024) for added security. Additionally, the administrator wants to prevent root users on the client from having root access to the NFS share. Which exports configuration meets these requirements?

A./srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,no_all_squash)
B./srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,insecure,root_squash)
C./srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,secure,root_squash)
D./srv/nfs 192.168.10.0/24(rw,sync,no_subtree_check,secure,no_root_squash)
AnswerC

This entry restricts the export to the 192.168.10.0/24 subnet, and secure enforces the privileged source port requirement. root_squash maps remote root to an anonymous user, preventing client root from gaining root access to the share, meeting all three stated constraints.

Why this answer

It restricts access to the 192.168.10.0/24 network, uses the 'secure' option to require client connections from a privileged port (less than 1024), and applies 'root_squash' to map root users on the client to the anonymous 'nobody' user, preventing root-level access to the NFS share.

Exam trap

The trap here is that candidates often confuse 'secure' with 'insecure' — the 'secure' option requires privileged ports, while 'insecure' allows any port, and many mistakenly think 'insecure' is needed for security or that 'no_root_squash' is the default safe behavior.

How to eliminate wrong answers

Option A is wrong because 'no_all_squash' does not prevent root access; it actually preserves the UID mapping, including root, which is the opposite of what is required. Option B is wrong because 'insecure' allows clients to connect from non-privileged ports (1024 or higher), violating the requirement to use a privileged port. Option D is wrong because 'no_root_squash' allows root users on the client to retain root access to the share, directly contradicting the requirement to prevent that.

716
MCQmedium

Which command will display the disk usage of each directory in the current directory, in human-readable format?

A.du -h
B.fdisk -l
C.ls -lh
D.df -h
AnswerA

du reports disk usage per directory, and the -h flag converts block counts into human-readable units such as KB, MB and GB. Running it in the current directory lists each subdirectory's consumption, matching the requirement for readable per-directory usage figures.

Why this answer

The `du -h` command displays disk usage for each directory in the current directory, with the `-h` flag converting sizes into human-readable formats (e.g., K, M, G). This is the correct tool for per-directory disk usage reporting.

Exam trap

The trap here is that candidates confuse `df -h` (filesystem-level usage) with `du -h` (directory-level usage), often picking `df -h` because it also shows human-readable output.

How to eliminate wrong answers

Option B is wrong because `fdisk -l` lists partition tables on block devices, not directory-level disk usage. Option C is wrong because `ls -lh` lists file and directory names with sizes, but it does not compute recursive disk usage for directories. Option D is wrong because `df -h` shows filesystem-level free and used space, not per-directory usage.

717
MCQeasy

A systems administrator needs to automate the execution of a backup script every day at 2:00 AM using a systemd service. Which unit type should the administrator create?

A.A .service unit
B.A .path unit
C.A .mount unit
D.A .timer unit
AnswerD

A .timer unit schedules activation of a paired service unit, satisfying the daily 2:00 AM requirement through OnCalendar expressions. Unlike cron, systemd timers integrate with journald logging and dependency management, and can trigger missed runs via Persistent=true. The .service unit holds the backup script itself; the timer governs when it executes.

Why this answer

A .timer unit is the correct choice because systemd timers are designed to schedule and trigger the execution of other units (such as services) at specific times or intervals. By creating a .timer unit that activates at 2:00 AM daily and a corresponding .service unit for the backup script, the administrator can automate the backup using systemd's built-in scheduling mechanism, which is more reliable and integrated than cron for systemd-managed systems.

Exam trap

The trap here is that candidates often confuse .timer units with .service units, mistakenly thinking a .service unit alone can handle scheduling, but systemd requires a separate timer unit to define the schedule and trigger the service.

How to eliminate wrong answers

Option A is wrong because a .service unit defines how to start, stop, and manage a process, but it does not include scheduling logic; it must be triggered by another unit (like a .timer) to run at a specific time. Option B is wrong because a .path unit monitors file system changes (e.g., file creation or modification) and activates a service when those events occur, not for time-based scheduling. Option C is wrong because a .mount unit controls the mounting of file systems and has no capability to schedule periodic execution of scripts.

718
MCQmedium

A Linux server's root filesystem was extended with LVM, but after a reboot users report that only the original capacity is available again. Running 'df -h' shows the mount smaller than the logical volume, and 'lvextend' completed successfully before the reboot. Which command should the administrator run to make the filesystem use the additional space on an XFS root volume?

A.resize2fs /dev/mapper/vg0-root
B.xfs_growfs /
C.parted /dev/sda resizepart 2 100%
D.vgchange -ay vg0
AnswerB

xfs_growfs expands an XFS filesystem online to fill its underlying block device. Because the logical volume was already enlarged with lvextend, running xfs_growfs against the mount point '/' resizes the filesystem to consume the new extents. This is the correct tool for XFS, which cannot be grown with resize2fs, and it works while the root filesystem is mounted.

Why this answer

XFS filesystems must be grown with xfs_growfs rather than resize2fs, and the operation can be performed online on a mounted root filesystem. Since lvextend already expanded the logical volume, the remaining step is to tell XFS to claim the new space by pointing xfs_growfs at the mount point. Without this step the filesystem keeps its original size even though the block device is larger.

Exam trap

The trap here is assuming that any Linux filesystem can be enlarged with resize2fs, when that utility is limited to the ext family and silently fails on XFS.

719
MCQeasy

Which command displays the disk usage of files and directories in a human-readable format (e.g., KB, MB)?

A.df -h
B.ls -lh
C.stat -h
D.du -h
AnswerD

The `du -h` command satisfies the human-readable requirement by appending the `-h` flag, which converts raw byte counts into scaled units such as KB, MB and GB. Unlike `df`, which reports filesystem-level capacity, `du` measures actual disk usage of files and directories, matching the stem precisely.

Why this answer

The `du -h` command (disk usage with human-readable flag) recursively summarizes disk usage for files and directories, appending size suffixes like K, M, G for kilobytes, megabytes, and gigabytes. This directly matches the question's requirement to display disk usage in a human-readable format.

Exam trap

The trap here is that candidates confuse `df -h` (filesystem-level free space) with `du -h` (per-file/directory disk usage), or assume `ls -lh` shows disk usage when it actually shows logical file size, not the blocks consumed on disk.

How to eliminate wrong answers

Option A is wrong because `df -h` reports filesystem-level disk space usage (free/used blocks on mounted partitions), not the disk usage of individual files and directories. Option B is wrong because `ls -lh` lists file sizes in human-readable format but does not compute or display disk usage (the actual blocks consumed on disk), which can differ from file size due to sparse files or block allocation. Option C is wrong because `stat -h` is not a valid Linux command; `stat` uses `-c` or `--format` for custom output and does not have a `-h` flag for human-readable sizes.

720
MCQeasy

A Linux administrator needs to grant a user named 'bob' the ability to run the /usr/bin/systemctl command as root without being prompted for a password. Which entry should be added to the sudoers file to accomplish this?

A.bob ALL=(ALL) NOPASSWD: ALL
B.bob ALL=(root) NOPASSWD: systemctl
C.bob ALL=(ALL) PASSWD: /usr/bin/systemctl
D.bob ALL=(ALL) NOPASSWD: /usr/bin/systemctl
AnswerD

This sudoers entry allows user bob to run /usr/bin/systemctl as any user (including root) without a password prompt. The NOPASSWD tag disables the password requirement, and the command is specified with its full path as required by sudoers syntax. This precisely meets the requirement to grant passwordless systemctl execution.

Why this answer

The sudoers entry must specify the user, hosts, target user, the NOPASSWD tag, and the full path to the command. The line 'bob ALL=(ALL) NOPASSWD: /usr/bin/systemctl' grants exactly the intended permission without a password, while other options either require a password, lack the full path, or grant excessive privileges. Always use visudo to edit sudoers to avoid syntax errors.

Exam trap

The trap here is forgetting that sudoers requires absolute paths for commands and misplacing the NOPASSWD tag, leading to a non-functional or overly permissive rule.

721
Multi-Selectmedium

A Linux administrator is hardening a server and needs to ensure that the system is protected against unauthorized access. The administrator wants to implement account lockout after multiple failed login attempts and enforce password complexity. Which TWO actions should the administrator take to achieve these goals? (Choose two.)

Select 2 answers
A.Add the line 'auth required pam_tally2.so deny=5' to /etc/pam.d/sshd to lock accounts after five failed SSH login attempts.
B.Configure the pam_faillock module in /etc/pam.d/system-auth and /etc/pam.d/password-auth to lock accounts after a specified number of failed attempts.
C.Set the PASS_MAX_DAYS parameter to 90 in /etc/login.defs to enforce password expiration.
D.Edit /etc/security/pwquality.conf to set minlen=12, ucredit=-1, lcredit=-1, dcredit=-1, and ocredit=-1.
E.Set the UMASK value to 077 in /etc/login.defs to restrict default file permissions.
AnswersB, D

The pam_faillock module is designed to lock user accounts after a defined number of consecutive failed authentication attempts. Configuring it in the PAM files for system-auth and password-auth ensures that lockout applies to both login and password change operations. This directly addresses the requirement to implement account lockout, and it is the standard method on modern Linux distributions.

Why this answer

To implement account lockout, the pam_faillock module must be configured in the PAM system-auth and password-auth files, which enforces lockout across authentication services. To enforce password complexity, the /etc/security/pwquality.conf file must be edited to set parameters like minlen and character class requirements. Together, these actions meet both requirements.

Exam trap

The trap here is confusing password aging with complexity and assuming that a single PAM file or a deprecated module like pam_tally2 is sufficient for comprehensive lockout.

722
MCQhard

Refer to the exhibit. An API call returns HTTP 200 but an empty body. What is the most likely cause?

A.The request is missing required query parameters, such as pagination or filters.
B.The server is experiencing a network timeout.
C.The SSL certificate is expired or invalid.
D.The API endpoint has been moved permanently (301).
AnswerA

A 200 with an empty body indicates the endpoint processed the request but matched no records, typically because required query parameters such as pagination or filter values were omitted, returning an empty result set rather than an error.

Why this answer

An HTTP 200 response indicates the request reached the server and was processed successfully, so the issue is not connectivity or server failure. An empty body most commonly occurs when the API requires query parameters such as pagination, filters, or a specific resource identifier, and without them the endpoint returns a valid but empty result set.

Exam trap

The trap here is assuming that a non-2xx status is required for an error; candidates forget that HTTP 200 only confirms the request was processed, not that data was returned, so they overlook missing query parameters as the cause of an empty body.

How to eliminate wrong answers

Option B is wrong because a network timeout would typically result in a connection error or a 5xx status, not a 200 with an empty body. Option C is wrong because an expired or invalid SSL certificate would cause a TLS handshake failure, preventing the request from completing at all, not a 200 response. Option D is wrong because a 301 redirect would return a 3xx status code and a Location header, not a 200 with an empty body.

723
MCQeasy

A user wants to execute a command inside a running Docker container named 'db'. Which command should be used?

A.docker attach db
B.docker start -i db
C.docker run -it db bash
D.docker exec -it db bash
AnswerD

The docker exec command runs a process inside an already-running container, with -it allocating an interactive TTY and bash as the shell. This satisfies the requirement to execute a command within the running 'db' container, unlike docker run which starts a new container.

Why this answer

'docker exec -it db bash' runs a new interactive process (bash) inside the already-running container named 'db', attaching a TTY and keeping stdin open. This is the standard way to get a shell or run a one-off command in a live container without disturbing its main process. It does not restart or replace the container's entrypoint.

Exam trap

The trap is conflating 'docker attach' (attach to PID 1 stdio) with 'docker exec' (spawn a new process), and confusing 'docker run' (new container) with operating on an existing one.

How to eliminate wrong answers

Option A is wrong because 'docker attach db' attaches to the container's existing PID 1 stdio stream, which can disrupt the main process and does not spawn a new shell; detaching can also accidentally stop the container. Option B is wrong because 'docker start -i db' starts a stopped container and attaches interactively to its main process — it does not open a shell inside a running container. Option C is wrong because 'docker run -it db bash' creates and starts a brand-new container from the 'db' image, not the running container named 'db', so it operates on a separate instance.

724
MCQhard

A Linux administrator needs to configure a service to run as a specific user and group, and to restart automatically on failure. The service is managed by systemd. Which directive in the unit file should the administrator use to specify the user and group, and which directive to ensure automatic restart?

A.User= and Group= in the [Service] section; Restart=on-abort
B.ExecStart= with su or sudo; Restart=on-abnormal
C.User= and Group= in the [Unit] section; Restart=always
D.User= and Group= in the [Service] section; Restart=on-failure
AnswerD

The User and Group directives in the [Service] section specify the user and group under which the service runs. Restart=on-failure ensures systemd restarts the service if it exits with a non-zero status or is terminated abnormally. This combination meets both requirements.

Why this answer

The correct directives are User= and Group= in the [Service] section, and Restart=on-failure. These set the execution context and restart policy. User and Group must be in [Service] because they affect how the service process runs.

Restart=on-failure restarts the service when it exits with a non-zero code or is killed by a signal, covering typical failure conditions.

Exam trap

The trap here is placing User and Group in the [Unit] section and using Restart=always instead of on-failure, or confusing the various restart conditions.

725
MCQmedium

A security audit reveals that the system's PAM configuration does not enforce password complexity. Which PAM module and configuration line should be added to /etc/pam.d/common-password to require at least one uppercase letter, one digit, and a minimum length of 12 characters?

A.password requisite pam_pwquality.so minlen=12 ucredit=-1 dcredit=-1
B.password sufficient pam_faillock.so minlen=12 ucredit=-1 dcredit=-1
C.password required pam_cracklib.so minlen=12 ucredit=-1 dcredit=-1
D.password required pam_unix.so minlen=12 ucredit=-1 dcredit=-1
AnswerA

`pam_pwquality.so` enforces complexity at password-change time, and the negative credit values are the mechanism: `ucredit=-1` and `dcredit=-1` each demand at least one uppercase letter and one digit, while `minlen=12` sets the minimum length. The `requisite` control ensures failure blocks the password change immediately, satisfying the audit's complexity requirement.

Why this answer

The pam_pwquality.so module is the modern replacement for pam_cracklib.so and provides password quality enforcement. The line 'password requisite pam_pwquality.so minlen=12 ucredit=-1 dcredit=-1' correctly sets the minimum length to 12 and requires at least one uppercase letter (ucredit=-1) and one digit (dcredit=-1). The 'requisite' control ensures that if this module fails, the password change is rejected immediately.

Exam trap

XK0-006 often tests the difference between pam_pwquality and pam_cracklib, and candidates may incorrectly choose pam_cracklib due to its historical use.

How to eliminate wrong answers

Option B is wrong because pam_faillock.so is used for account lockout after failed login attempts, not for password complexity. Option C is wrong because pam_cracklib.so is deprecated and may not support all options like ucredit and dcredit in the same way; pam_pwquality is the current standard. Option D is wrong because pam_unix.so handles traditional Unix password authentication and does not enforce complexity requirements like minlen, ucredit, or dcredit.

726
MCQmedium

A Linux administrator maintains a Bash deployment script that runs unattended from cron. The script currently contains `set -e` and `set -u`, but it silently continues past a failing command inside a pipeline such as `tar -czf backup.tgz /srv | tee /var/log/backup.log`. The administrator wants the script to abort whenever any element of that pipeline returns a non-zero status. Which line should be added to the top of the script?

A.set -v
B.set -x
C.set -n
D.set -o pipefail
AnswerD

With pipefail enabled, the exit status of a pipeline becomes the rightmost non-zero status of any command in it, so a failure in tar propagates and set -e terminates the script. This directly addresses the scenario where the pipeline's final command (tee) succeeds and masks the earlier failure, keeping unattended cron runs from continuing on corrupt backups.

Why this answer

Pipelines report only the last command's status by default, so a failing producer such as tar can be masked by a succeeding consumer such as tee. Enabling pipefail makes the pipeline return the first non-zero status encountered, which combines with set -e to abort the unattended script immediately. This preserves the existing error-handling design while closing the pipeline gap.

Exam trap

The trap here is assuming that set -e alone covers every failure, when it ignores all but the final command's status in a pipeline unless pipefail is also enabled.

727
MCQhard

A server running RHEL 8 fails to boot with a 'Dependency failed for /data' error. The /data filesystem is an ext4 partition on /dev/sdb1. Which sequence of steps should be taken to repair the filesystem?

A.Use 'xfs_repair /dev/sdb1' since it's ext4
B.Run 'fsck.ext4 -f /dev/sdb1' from the running system
C.Remount the filesystem as read-only and run fsck
D.Boot into rescue mode, run 'umount /dev/sdb1', then 'fsck.ext4 -f /dev/sdb1'
AnswerD

Rescue mode boots a minimal environment where /data stays unmounted, allowing 'umount /dev/sdb1' to ensure no active references remain before 'fsck.ext4 -f' forces a full check and repair of the ext4 partition, satisfying the need to fix the dependency failure safely.

Why this answer

To repair an ext4 filesystem that failed to mount at boot, you must boot into rescue mode (or single-user), ensure the filesystem is unmounted, then run 'fsck.ext4 -f /dev/sdb1' to force a check and repair. fsck must never run on a mounted read-write filesystem, and rescue mode gives you a clean environment where /data is not mounted. This is the standard RHEL recovery procedure.

Exam trap

XK0-006 often tests the rule that fsck must run on an unmounted filesystem — candidates pick 'run fsck from the running system' or 'remount read-only' not realizing fsck needs full unmount and that rescue mode is required.

How to eliminate wrong answers

Option A is wrong because xfs_repair is for XFS filesystems, not ext4 — running it on ext4 will fail or corrupt data. Option B is wrong because running fsck.ext4 on a mounted filesystem (especially read-write) can cause severe corruption; the running system has /data mounted. Option C is wrong because remounting read-only and running fsck is not sufficient — fsck requires the filesystem to be fully unmounted, not just read-only, and the boot failure means it may not even be mounted.

728
MCQmedium

A database server is running slow. The administrator uses iostat and notices high await times on the disk. Which of the following best explains the implication of high await?

A.The CPU is waiting too long for memory access.
B.Disk I/O requests are taking a long time to complete.
C.The disk is almost full, causing fragmentation.
D.The network filesystem is experiencing latency.
AnswerB

await measures the average time in milliseconds for I/O requests issued to the device to be served, including queue wait. High values therefore indicate requests are completing slowly, pointing to disk saturation or latency rather than throughput or capacity problems.

Why this answer

In iostat, 'await' measures the average time (in milliseconds) for I/O requests to be served by the disk, including time spent in the queue and the actual service time. A high await value indicates that disk I/O requests are taking a long time to complete, which directly explains the database server's slowness due to disk latency.

Exam trap

The trap here is that candidates confuse 'await' with CPU wait time (iowait) or assume it directly indicates disk fullness, when in fact await is a pure I/O completion latency metric that can be high due to queueing, slow media, or controller issues.

How to eliminate wrong answers

Option A is wrong because high await in iostat is a disk metric, not a memory metric; CPU waiting for memory access is indicated by high 'wait' or 'st' in CPU stats, not await. Option C is wrong because a nearly full disk can cause fragmentation, but fragmentation primarily increases seek time and is not directly measured by await; await reflects overall request completion time, which can be high due to many factors beyond fragmentation. Option D is wrong because network filesystem latency would be captured by network-specific metrics (e.g., nfsiostat, netstat) or by iostat if the disk is a remote block device, but await on a local disk does not imply network latency.

729
MCQmedium

An administrator is troubleshooting a DNS issue and needs to query the authoritative name servers for example.com. Which dig command should be used?

A.dig example.com MX
B.dig example.com NS
C.dig example.com A
D.dig example.com ANY
AnswerB

The NS record type queries the zone's authoritative name servers, so dig example.com NS returns exactly the delegation data required. Other record types such as A or MX would resolve addresses or mail routing instead, failing the stated troubleshooting goal.

Why this answer

The NS (Name Server) record type identifies the authoritative name servers for a domain. Running 'dig example.com NS' queries those NS records directly, showing which servers are authoritative for example.com. This is the correct query to enumerate authoritative name servers.

Exam trap

The trap is confusing record types — candidates may pick ANY thinking it returns everything, but ANY is unreliable and not the targeted way to query authoritative name servers.

How to eliminate wrong answers

Option A is wrong because 'dig example.com MX' returns mail exchange records, which identify mail servers, not authoritative name servers. Option C is wrong because 'dig example.com A' returns the IPv4 address record for the domain apex, not the NS records. Option D is wrong because 'dig example.com ANY' requests all record types, which is unreliable — many DNS servers (including many modern resolvers) refuse or truncate ANY queries per RFC 8482, and the output is not focused on NS records.

730
MCQhard

A containerized application is consuming excessive memory on a Linux host running Podman. Which command sets a memory limit of 512 megabytes when running a container?

A.podman run --memory=512m myimage
B.podman run --limit-memory 512 myimage
C.podman run --mem=512m myimage
D.podman run --memory-limit=512MB myimage
AnswerA

`--memory=512m` enforces a hard cgroup memory limit, capping the container's resident usage at 512 MB and triggering the OOM killer if exceeded. This directly satisfies the stem's requirement to constrain a Podman container's excessive host memory consumption, unlike flags governing CPU shares or swap behaviour.

Why this answer

Podman uses the `--memory` flag (identical to Docker's syntax) to set a hard memory limit on a container. The value `512m` specifies 512 megabytes. This directly restricts the container's memory usage via cgroups, preventing it from consuming excessive host memory.

Exam trap

CompTIA often tests the exact flag syntax and unit format, so the trap here is that candidates may confuse Podman's `--memory` with Docker's `--memory` (they are identical) or invent plausible-sounding flags like `--limit-memory` or `--mem`, or use incorrect unit capitalization like `MB` instead of `m`.

How to eliminate wrong answers

Option B is wrong because `--limit-memory` is not a valid Podman flag; the correct flag is `--memory`. Option C is wrong because `--mem` is not a valid Podman flag; the correct abbreviation is `--memory` (or `-m`). Option D is wrong because `--memory-limit` is not a valid Podman flag, and the value `512MB` uses an incorrect unit format (Podman expects lowercase 'm' for megabytes, e.g., `512m`).

731
MCQhard

An administrator needs to apply a set of permissions to an existing directory and all its contents, setting the owner to 'rwx', group to 'rx', and others to '---'. Additionally, newly created files within the directory should inherit the group. Which commands should the administrator run? (Assume the directory is /data, and the group is 'staff'.)

A.chmod -R 750 /data; chmod g+s /data
B.chmod 750 /data; chmod g+s /data
C.chmod -R 755 /data; chmod g+s /data
D.chmod -R 750 /data
AnswerA

The recursive 750 sets owner rwx, group rx and no others permissions across /data and its contents, while the setgid bit forces new files to inherit the staff group rather than the creator's primary group, meeting the inheritance constraint.

Why this answer

The command 'chmod -R 750 /data' recursively sets permissions for the directory and all its contents to owner rwx, group rx, and others none. The command 'chmod g+s /data' sets the setgid bit on the directory, ensuring that newly created files and subdirectories inherit the group ownership of the directory (staff). Together, these commands meet the requirements.

Exam trap

XK0-006 often tests the difference between recursive and non-recursive chmod, and the effect of the setgid bit on directories, leading candidates to forget the -R flag or the setgid command.

How to eliminate wrong answers

Option B is wrong because 'chmod 750 /data' without the -R flag only changes the permissions of the directory itself, not its contents. Option C is wrong because 'chmod -R 755 /data' sets others to r-x, which violates the requirement of others having no permissions (---). Option D is wrong because it lacks the 'chmod g+s /data' command, so newly created files will not inherit the group.

732
MCQmedium

A user wants to create a symbolic link to a file named 'original' in their home directory. Which command creates a symbolic link named 'link'?

A.ln original link
B.ln -s original link
C.ln -s link original
D.symlink original link
AnswerB

ln -s creates a symbolic link, with the target 'original' first and the new link name 'link' second. The -s flag distinguishes it from a hard link, satisfying the requirement for a symlink in the home directory.

Why this answer

The 'ln -s' command creates a symbolic (soft) link. The syntax is 'ln -s <target> <linkname>', so 'ln -s original link' creates a symlink named 'link' that points to 'original'. Without the -s flag, ln creates a hard link instead.

Exam trap

XK0-006 often tests the argument order of 'ln -s' and the hard-link versus symbolic-link distinction, causing candidates to reverse the target and link name or forget the -s flag.

How to eliminate wrong answers

Option A is wrong because 'ln original link' creates a hard link, not a symbolic link — hard links share the same inode and cannot span filesystems or point to directories. Option C is wrong because the arguments are reversed: 'ln -s link original' would create a symlink named 'original' pointing to 'link', which is the opposite of what was requested. Option D is wrong because 'symlink' is not a standard Linux command; the correct utility is 'ln' with the -s option.

733
MCQmedium

Which command will display the disk usage of each file and directory in the current directory?

A.df -h
B.ls -lh
C.du -sh *
D.fdisk -l
AnswerC

du reports disk usage per file and directory; -s summarises each argument into one total and -h renders sizes readably. The * glob passes every entry in the current directory, giving per-item usage rather than df's filesystem-wide view.

Why this answer

`du -sh *` calculates and displays the disk usage of each file and directory in the current directory. The `-s` flag summarizes each item, `-h` provides human-readable sizes (e.g., KB, MB), and the `*` wildcard expands to all non-hidden entries in the current directory, making it the precise command for this task.

Exam trap

CompTIA often tests the distinction between `df` (filesystem-level) and `du` (directory/file-level) disk usage, and the trap here is that candidates mistakenly choose `ls -lh` thinking it shows disk usage, when it only shows logical file size and does not account for blocks or directory contents.

How to eliminate wrong answers

Option A is wrong because `df -h` reports filesystem-level disk space usage (total, used, available) for mounted filesystems, not per-file or per-directory usage. Option B is wrong because `ls -lh` lists file sizes and metadata but does not calculate actual disk usage (it shows logical file size, not blocks consumed, and cannot handle directories recursively). Option D is wrong because `fdisk -l` is a partition table manipulation tool that lists disk partitions and their geometry, not file or directory disk usage.

734
Multi-Selectmedium

A system administrator needs to collect performance data over time to analyze CPU and memory usage trends. Which THREE of the following commands can be used to gather historical performance data? (Choose THREE.)

Select 3 answers
A.iostat
B.uptime
C.free
D.sar
E.vmstat
AnswersA, D, E

iostat reports CPU utilisation and disk I/O statistics, and with interval arguments it samples repeatedly, building a historical record of CPU trends. It writes to stdout, so redirecting output to a file captures the data over time.

Why this answer

Option A, iostat, is correct because it reports CPU utilization and disk I/O statistics and can be run repeatedly (e.g., iostat 5) or logged over time to reveal performance trends. Option D, sar, is correct because the System Activity Reporter collects and stores historical performance data via the sadc collector and sysstat service, allowing retrieval of past CPU and memory statistics with commands like sar -u or sar -r. Option E, vmstat, is correct because it samples CPU, memory, paging, and I/O statistics at intervals (e.g., vmstat 5) and its output can be captured over time for trend analysis.

Option B, uptime, is not correct because it only shows a single snapshot of load average and uptime, not historical performance data. Option C, free, is not correct because it displays a one-time snapshot of current memory usage rather than collecting data over time.

Exam trap

XK0-006 often tests the distinction between real-time monitoring tools (like uptime and free) and tools that can provide historical data (like sar and iostat), so candidates may incorrectly include free or uptime.

735
MCQhard

A Linux administrator is troubleshooting a server that becomes unresponsive under load. They want to capture a live, per-second view of CPU usage broken down by individual processor cores, along with load averages. Which command should they use?

A.iostat -x 1
B.top -b -n 1
C.mpstat -P ALL 1
D.free -m
AnswerC

mpstat from the sysstat package reports per-processor statistics. The -P ALL option shows every core, and the interval argument refreshes output each second. It includes CPU utilization percentages and, in recent versions, load averages, making it ideal for observing whether a single core is saturated while others idle. This granularity helps identify unbalanced or single-threaded load causing unresponsiveness.

Why this answer

The mpstat command with -P ALL and an interval argument produces recurring snapshots showing each processor core's utilization, which reveals whether load is spread evenly or concentrated on one core. This per-core visibility is critical when a single-threaded process saturates one CPU while others remain idle, a common cause of apparent unresponsiveness under load. Other tools lack this combination of per-core detail and live refresh.

Exam trap

The trap here is selecting top for CPU analysis, but a batch single-iteration top neither refreshes per second nor shows per-core breakdown, which is what the scenario requires.

736
MCQmedium

A Linux administrator needs to configure a system so that the service `httpd` starts automatically when the system boots into the default target. Which command should the administrator use?

A.systemctl daemon-reload
B.systemctl enable httpd
C.systemctl start httpd
D.chkconfig httpd on
AnswerB

The `systemctl enable httpd` command creates the necessary symbolic links in the systemd configuration directories to ensure the httpd service is started automatically when the system reaches the default target during boot. This is the standard method for enabling a service to start at boot on modern Linux distributions using systemd.

Why this answer

Enabling a service with `systemctl enable httpd` sets up the proper symlinks so that systemd starts the service when the default target is reached during boot. Starting the service only affects the current runtime, while enabling ensures persistence across reboots. Other commands like `chkconfig` are for older init systems and `daemon-reload` only refreshes unit definitions.

Exam trap

The trap here is confusing the immediate action of starting a service with the persistent action of enabling it at boot.

737
MCQeasy

Which tool is used for encrypting files with public-key cryptography on Linux systems?

A.bcrypt
B.LUKS
C.OpenSSL
D.GnuPG
AnswerD

GnuPG implements OpenPGP asymmetric encryption, generating RSA or ECC key pairs so files are encrypted with a recipient's public key and decrypted only with their private key. This directly satisfies the stem's requirement for public-key cryptography on Linux, unlike symmetric tools such as dm-crypt or OpenSSL's default password-based ciphers.

Why this answer

GnuPG (GNU Privacy Guard) is the correct tool because it implements the OpenPGP standard (RFC 4880) for encrypting and signing files using public-key cryptography. It allows users to generate a key pair, encrypt a file with the recipient's public key, and decrypt it with the corresponding private key, making it the standard Linux utility for asymmetric file encryption.

Exam trap

The trap here is that candidates confuse OpenSSL's ability to perform asymmetric operations (e.g., `openssl rsautl`) with it being the standard tool for public-key file encryption, while GnuPG is the dedicated utility for OpenPGP-compliant file encryption on Linux.

How to eliminate wrong answers

Option A is wrong because bcrypt is a password-hashing function based on the Blowfish cipher, designed for securely storing passwords, not for encrypting files with public-key cryptography. Option B is wrong because LUKS (Linux Unified Key Setup) is a disk encryption specification that encrypts entire block devices using symmetric keys, not public-key cryptography for individual files. Option C is wrong because OpenSSL is a cryptographic library that supports symmetric and asymmetric encryption, but it is primarily a toolkit for SSL/TLS protocols and command-line encryption of data using symmetric ciphers (e.g., `openssl enc`), not a dedicated public-key file encryption tool like GnuPG.

738
Multi-Selecteasy

Which TWO commands can be used to display the current kernel version on a Linux system?

Select 2 answers
A.modinfo
B.uname -r
C.cat /proc/version
D.lsmod
E.dmesg
AnswersB, C

`uname -r` reads the kernel release directly from the running system via the `uname` syscall, printing only the release field (for example, 6.8.0-45-generic). This satisfies the stem's requirement to display the current kernel version, unlike `uname -a`, which also lists hostname, architecture and other unrelated details.

Why this answer

Option B, uname -r, is correct because the uname command prints system information and the -r flag specifically outputs the kernel release (version) string, such as 5.15.0-91-generic. Option C, cat /proc/version, is correct because /proc/version is a virtual file exposed by the kernel that contains the kernel version, gcc version used to build it, and build timestamp. Option A, modinfo, is incorrect because it displays metadata about a specific kernel module (e.g., filename, license, parameters), not the running kernel version.

Option D, lsmod, is incorrect because it lists currently loaded kernel modules by reading /proc/modules, not the kernel version. Option E, dmesg, is incorrect because it prints the kernel ring buffer messages, which may mention the version incidentally but is not a command designed to display the current kernel version.

Exam trap

CompTIA often tests the distinction between commands that display kernel version (`uname -r`, `/proc/version`) versus commands that show kernel module information (`lsmod`, `modinfo`) or boot logs (`dmesg`), leading candidates to confuse related but incorrect options.

739
Multi-Selectmedium

Which TWO statements about container security are correct when using Docker? (Choose two.)

Select 2 answers
A.SELinux is automatically enabled inside containers.
B.Containers have their own kernel, isolated from the host.
C.Using --cap-drop=ALL removes all capabilities, making the container more secure.
D.By default, containers run with a reduced set of Linux capabilities.
E.Using --network=host increases container isolation.
AnswersC, D

Dropping every Linux capability strips privileged operations such as chown, net_raw and sys_admin from the container's processes, so a compromised workload cannot abuse kernel-level privileges. This directly reduces the container's attack surface as the statement claims.

Why this answer

Option C is correct because Docker's --cap-drop=ALL flag removes every Linux capability from the container's process, leaving it with none of the privileged operations (such as CAP_NET_RAW or CAP_SYS_ADMIN) that a compromised process could abuse, which strictly reduces the attack surface. Option D is correct because Docker's default capability set is already a reduced subset of the full root capability list — it drops dangerous capabilities like CAP_SYS_ADMIN and CAP_SYS_MODULE while retaining a limited set such as CAP_CHOWN, CAP_NET_BIND_SERVICE, and CAP_SETUID. Option A is wrong because SELinux is a host-level mandatory access control mechanism that is not automatically enabled inside containers; container processes are confined by the host's SELinux policy only if SELinux is enabled and configured on the host.

Option B is wrong because containers share the host's kernel and use namespaces and cgroups for isolation rather than having their own kernel, unlike virtual machines. Option E is wrong because --network=host removes network namespace isolation, causing the container to share the host's network stack and thus decreasing, not increasing, isolation.

Exam trap

CompTIA often tests the misconception that containers have their own kernel or that SELinux is automatically active, while the real focus is on Linux capabilities and the shared kernel model.

740
MCQmedium

A Linux administrator needs to create a new user account 'jdoe' with a home directory /home/jdoe and the default shell /bin/bash. Which command will accomplish this?

A.groupadd -m -s /bin/bash jdoe
B.adduser jdoe --home /home/jdoe --shell /bin/bash
C.useradd -m -s /bin/bash jdoe
D.usermod -d /home/jdoe -s /bin/bash jdoe
AnswerC

useradd creates a new user. The -m option creates the home directory (typically /home/jdoe) and copies skeleton files. The -s option sets the login shell to /bin/bash. This command creates the account with the specified home directory and shell, meeting all requirements.

Why this answer

The useradd command with -m creates the home directory and -s sets the shell. This is the standard non-interactive method to create a user with specific home and shell. The other commands either modify existing users, create groups, or are distribution-specific interactive tools that may not accept the given options.

Exam trap

The trap here is confusing useradd with usermod or groupadd, or assuming adduser is universally available with the same options across all distributions.

741
MCQmedium

A Linux administrator is investigating why a user cannot log in via SSH. The SSH service is running, and the network is reachable. The administrator suspects that the user's account is locked or expired. Which command should they use to check the account status and expiration details for the user 'jdoe'?

A.passwd -S jdoe
B.chage -l jdoe
C.usermod -L jdoe
D.id jdoe
AnswerB

chage -l lists account aging information, including password expiration, account expiration, and last password change. It directly shows if the account has expired or is locked due to password aging. This is the correct tool to verify if the user's account is expired or locked, which would prevent SSH login even if the service is running.

Why this answer

The chage -l command displays detailed account aging information, including expiration dates for the password and the account itself. In this scenario, it would reveal if the account is expired or if the password has expired, which are common reasons for SSH login failure despite the service running. This makes it the correct diagnostic tool.

Exam trap

The trap here is confusing password status (passwd -S) with full account aging information (chage -l), or mistakenly using a modification command like usermod -L instead of a query.

742
MCQhard

A Linux administrator is diagnosing a system that occasionally hangs during boot. The administrator suspects a hardware issue. Which command will display kernel ring buffer messages, including hardware detection and driver errors, from the current boot?

A.journalctl -b -p err
B.lsmod
C.dmesg
D.cat /var/log/boot.log
AnswerC

dmesg prints the kernel ring buffer, which contains messages about hardware detection, driver loading, and kernel events. These messages are generated during boot and runtime. It is the primary tool for viewing kernel-level diagnostics, making it ideal for identifying hardware issues causing boot hangs.

Why this answer

The dmesg command displays the kernel ring buffer, which contains low-level messages about hardware, drivers, and kernel events. These messages are generated during boot and can reveal hardware detection failures, driver errors, or other kernel issues that cause hangs. It is the most direct tool for this purpose.

Exam trap

The trap here is confusing general system logs with the kernel ring buffer, or assuming that a list of loaded modules provides diagnostic messages.

743
MCQmedium

An Ansible playbook fails with a syntax error. Which command validates the playbook syntax without running it?

A.ansible-lint playbook.yml
B.ansible-playbook --check
C.ansible-playbook --validate
D.ansible-playbook --syntax-check
AnswerD

The --syntax-check flag parses the playbook and reports YAML or structural errors without executing any tasks or connecting to managed hosts. This validates syntax safely, satisfying the requirement to check without running the playbook against live infrastructure.

Why this answer

The `--syntax-check` flag is a built-in option of `ansible-playbook` that parses the YAML file and validates its syntax without executing any tasks. This is the correct tool for catching syntax errors in a playbook before running it.

Exam trap

The trap here is that candidates may confuse `--syntax-check` with `--check` (dry run) or assume `ansible-lint` is the syntax validator, but `--syntax-check` is the only command that validates syntax without any execution.

How to eliminate wrong answers

Option A is wrong because `ansible-lint` is a separate tool that checks for best practices, style, and potential issues, but it does not perform a strict syntax validation of the playbook. Option B is wrong because `--check` performs a dry run that executes the playbook in check mode, which still runs the playbook logic and can fail on syntax errors, not just validate syntax. Option C is wrong because `--validate` is not a valid flag for `ansible-playbook`; the correct flag for syntax validation is `--syntax-check`.

744
Multi-Selectmedium

Which three are valid systemd unit types?

Select 3 answers
A.process
B.socket
C.service
D.timer
E.job
AnswersB, C, D

Socket units are a genuine systemd unit type, pairing a listening socket with a service so systemd activates the service on incoming connection. This satisfies the stem's requirement for valid unit types, alongside service, target, mount, timer and device units.

Why this answer

B (socket), C (service), and D (timer) are all valid systemd unit types. A socket unit encapsulates a local IPC or network socket in the system for socket-based activation, a service unit describes a process controlled and supervised by systemd, and a timer unit provides a mechanism for triggering activation of other units based on time events. These are among the 12 standard systemd unit types defined in the systemd documentation.

Exam trap

Candidates often mistakenly select 'process' and 'job' as valid systemd unit types because they sound plausible, but they are not part of the official list of systemd unit types. This confusion arises from general Linux terminology versus systemd-specific unit definitions.

745
Multi-Selectmedium

A system administrator is writing an Ansible playbook to manage a web server. Which three of the following are valid Ansible modules for system administration? (Choose THREE.)

Select 3 answers
A.service
B.copy
C.useradd
D.apt
E.chmod
AnswersA, B, D

The `service` module manages system daemons on the target host, starting, stopping, enabling or restarting services such as httpd or nginx. It satisfies the stem's requirement for a valid system-administration module by controlling service state declaratively, and it works across systemd, SysV init and other init systems without extra configuration.

Why this answer

apt, service, and copy are standard Ansible modules for package management, service control, and file copying.

746
MCQhard

A server has a volume group 'vg_data' with a single logical volume 'lv_data' of 100GB mounted at /data. The filesystem on lv_data is XFS. The administrator needs to extend it to 150GB. A new 60GB disk /dev/sdc has been added and partitioned as LVM. The administrator runs `pvcreate /dev/sdc1`, then `vgextend vg_data /dev/sdc1`, then `lvextend -L +50G /dev/vg_data/lv_data`. The administrator runs `df -h /data` and sees that the filesystem still shows 100GB. Which command should be run next?

A.lvreduce -L -50G /dev/vg_data/lv_data
B.fsck /dev/vg_data/lv_data
C.xfs_growfs /data
D.resize2fs /dev/vg_data/lv_data
AnswerC

lvextend grows the logical volume but not the XFS filesystem, so df still reports 100GB. XFS must be grown online against its mount point, and xfs_growfs /data expands the filesystem to use the newly added 50GB of the logical volume.

Why this answer

After extending the logical volume with lvextend, the filesystem must be grown to use the additional space. For XFS filesystems, the command is xfs_growfs, which must be run on the mount point. The df output still shows 100GB because the filesystem has not been resized.

Exam trap

The trap is that candidates might choose resize2fs because it is commonly associated with resizing filesystems, but XFS requires xfs_growfs; also, some might think the filesystem automatically grows with lvextend, which it does not.

How to eliminate wrong answers

Option A is wrong because lvreduce would shrink the logical volume, which is the opposite of what is needed and could cause data loss. Option B is wrong because fsck is a filesystem check tool, not for resizing. Option D is wrong because resize2fs is used for ext2/3/4 filesystems, not XFS.

747
MCQmedium

In the exhibit, what does 'Tasks: 11 (limit: 512)' indicate?

A.The process is using 512 MB of memory.
B.The service has been running for 512 seconds.
C.The cgroup pids controller is limiting the number of processes/threads.
D.The number of threads is limited to 512.
AnswerC

The pids controller in cgroup v2 tracks and caps the number of tasks (processes and threads) within the cgroup. The 'limit: 512' value is the ceiling set by that controller, so exceeding it blocks new fork or clone calls until tasks exit.

Why this answer

The output shown is from the `systemd-cgls` command, which displays cgroup (control group) information. The line `Tasks: 11 (limit: 512)` indicates that the cgroup's pids controller is currently tracking 11 processes/threads within that cgroup and has a configured limit of 512. This limit restricts the total number of processes and threads that can be created in that cgroup, preventing fork bombs or resource exhaustion.

Exam trap

The trap here is that candidates confuse the 'Tasks' count with memory usage or runtime, or assume it refers only to threads without recognizing the cgroup pids controller as the mechanism enforcing the limit.

How to eliminate wrong answers

Option A is wrong because the value 512 is a count of processes/threads, not a memory size in MB; memory limits are shown separately (e.g., `memory.limit_in_bytes`). Option B is wrong because the output does not display any time-related information; `Tasks` refers to process/thread count, not runtime duration. Option D is wrong because while the limit applies to both processes and threads, the statement is incomplete—it omits that the limit is enforced by the cgroup pids controller, and the output explicitly shows the cgroup context, not just a thread limit.

748
MCQhard

A Bash script uses getopts to parse command-line options. The options are -a (requires an argument) and -b (flag). Which code correctly implements this and stores the argument for -a in $optarg?

A.while getopts 'a:b' opt; do case $opt in a) arg=$OPTARG ;; b) flag=true ;; esac done
B.while getopts 'ab:' opt; do case $opt in a) arg=$OPTARG ;; b) flag=true ;; esac done
C.while getopts 'a:b' opt; do case $opt in a) arg=$optarg ;; b) flag=true ;; esac done
D.while getopts ':a:b' opt; do case $opt in a) arg=$OPTARG ;; b) flag=true ;; esac done
AnswerA

The colon after 'a' in the optstring signals that -a requires an argument, which getopts stores in $OPTARG; 'b' without a colon is a flag. The case statement then assigns $OPTARG to arg, satisfying the requirement.

Why this answer

The getopts built-in parses options and stores the option argument in the shell variable OPTARG (uppercase). The option string 'a:b' indicates that -a requires an argument (colon after a) and -b is a flag (no colon). The loop uses 'opt' as the variable to hold the current option, and the case statement correctly assigns $OPTARG to arg for -a.

This matches option A.

Exam trap

XK0-006 often tests the case sensitivity of OPTARG and the placement of colons in the option string, so candidates must remember that OPTARG is uppercase and that a colon after an option letter indicates it requires an argument.

How to eliminate wrong answers

Option B is wrong because the option string 'ab:' incorrectly specifies that -b requires an argument, not -a. Option C is wrong because it uses lowercase $optarg, but getopts sets the uppercase $OPTARG variable. Option D is wrong because the leading colon in ':a:b' changes error handling behavior (silent mode) and is not needed for the described functionality; it also does not affect the argument storage, but the question asks for correct implementation, and the leading colon is unnecessary and alters error reporting.

749
MCQhard

A company's security policy requires that all user passwords must expire every 90 days. The administrator runs 'chage -M 90 jdoe' for user jdoe. Which additional step ensures that the password expiration policy is enforced for all new users?

A.Set PASS_MAX_DAYS 90 in /etc/login.defs
B.Add 'password required pam_unix.so remember=5' to /etc/pam.d/system-auth
C.Set EXPIRE=90 in /etc/default/useradd
D.Modify /etc/shadow to set max days for each user
AnswerA

Setting `PASS_MAX_DAYS 90` in `/etc/login.defs` applies the 90-day maximum password age as the system-wide default, which `useradd` reads when creating each new account. The per-user `chage -M 90 jdoe` command only affects jdoe, so this edit satisfies the policy's requirement to enforce expiry for all future users.

Why this answer

/etc/login.defs contains default values used by useradd and other tools when creating new users. Setting PASS_MAX_DAYS 90 in this file ensures that every new user account created will automatically have a 90-day password expiration, enforcing the policy globally without manual intervention.

Exam trap

The trap here is that candidates confuse the purpose of /etc/login.defs (defaults for new users) with /etc/shadow (current user settings) or think that modifying a single user's policy with chage will propagate to all users.

How to eliminate wrong answers

Option B is wrong because the pam_unix.so remember=5 setting controls password history (preventing reuse of the last 5 passwords), not the maximum password age. Option C is wrong because /etc/default/useradd does not contain an EXPIRE parameter; the correct parameter for account expiration is EXPIRE (which sets an absolute expiry date), but there is no PASS_MAX_DAYS equivalent in that file. Option D is wrong because modifying /etc/shadow manually for each user is not scalable and does not enforce the policy for future new users; it only applies to existing accounts.

750
MCQmedium

A Linux engineer is troubleshooting a cron job that does not execute as expected. The crontab entry reads: '*/5 * * * * /usr/local/bin/backup.sh'. The script runs manually when executed as root. Which of the following is the most likely cause?

A.The cron daemon is not running.
B.The script file does not have execute permissions.
C.The system clock is incorrect.
D.The script requires environment variables that are not set in cron's shell.
AnswerD

Cron runs jobs with a minimal environment, so variables defined in root's interactive shell profile are absent. The script succeeds manually because those variables exist there, but fails under cron — matching the stem's symptom of a job that only works when run by hand.

Why this answer

D is correct because cron jobs run in a minimal shell environment (typically /bin/sh) with a very limited set of environment variables. The script /usr/local/bin/backup.sh may rely on variables like PATH, HOME, or custom variables that are not set in cron's shell, causing it to fail even though it runs fine manually as root. This is a classic cron issue where the interactive shell's environment differs from cron's non-interactive environment.

Exam trap

CompTIA often tests the misconception that a script failing in cron is due to permissions or the cron daemon status, when the real issue is the stripped-down environment that lacks variables the script depends on.

How to eliminate wrong answers

Option A is wrong because if the cron daemon were not running, no cron jobs would execute at all, but the question states only this specific job fails, and the script runs manually. Option B is wrong because the script runs manually when executed as root, which implies it has execute permissions; if permissions were missing, the manual execution would also fail. Option C is wrong because an incorrect system clock would affect all cron jobs based on timing, but the job is scheduled with '*/5 * * * *' and would still attempt to run; the issue is specific to the script's execution environment, not the timing.

Page 9

Page 10 of 11

Page 11

All pages