Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 751–781

781 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
MCQmedium

A bash script needs to test whether a string variable $NAME is non-empty and equals 'admin'. Which of the following conditionals is correct?

A.if [[ $NAME -ne '' && $NAME -eq 'admin' ]]; then
B.if [[ -n $NAME && $NAME == 'admin' ]]; then
C.if [ $NAME != '' ] && [ $NAME == 'admin' ]; then
D.if [ ! -z $NAME -a $NAME = 'admin' ]; then
AnswerB

The -n test confirms the string is non-empty, and && requires the equality check to also pass. Both conditions must hold for the branch to execute, precisely matching the stem's requirement that $NAME be populated and equal to 'admin'.

Why this answer

In bash, [[ -n $NAME ]] tests if the string is non-empty, and == compares strings. Using double brackets is safer for string comparison.

752
MCQmedium

A system is experiencing high disk I/O wait. Which command can provide disk I/O statistics such as requests per second and average wait time?

A.sar -u 1 5
B.iostat -x 1
C.free -h
D.vmstat 1 5
AnswerB

The -x flag extends iostat output with per-device metrics including requests per second, average queue size and average wait time, while the 1 sets a one-second sampling interval. This directly satisfies the requirement for disk I/O statistics during high wait.

Why this answer

The iostat -x 1 command provides extended disk I/O statistics, including requests per second (r/s, w/s), average wait time (await), and utilization (%util), refreshed every second. This directly answers the need for per-device I/O performance data during high I/O wait.

Exam trap

XK0-006 often tests the difference between CPU-focused tools (sar -u, vmstat) and disk-focused tools (iostat -x) — candidates see 'iowait' in sar or vmstat output and assume those tools provide disk-level detail, which they do not.

How to eliminate wrong answers

Option A is wrong because sar -u 1 5 reports CPU utilization statistics (user, system, idle, iowait) every second for five intervals — it shows iowait but not per-disk request rates or wait times. Option C is wrong because free -h displays memory and swap usage, which is unrelated to disk I/O statistics. Option D is wrong because vmstat 1 5 reports virtual memory, process, CPU, and some block I/O summary statistics, but it does not provide per-device requests per second or average wait time like iostat -x does.

753
MCQmedium

An administrator needs to give a user read and write access to a file without changing the file's group or adding the user to any group. Which method should be used?

A.chown user: file
B.chmod u+rw file
C.setfacl -m u:username:rw file
D.chgrp to user's primary group
AnswerC

Using `setfacl -m u:username:rw file` writes a POSIX access control list entry granting that named user read and write permission, satisfying the stem's constraint of avoiding group changes or group membership edits. Standard Unix mode bits cannot grant per-user rights without altering owner, group or other classes, so ACLs are the only mechanism here.

Why this answer

Access Control Lists (ACLs) allow granting permissions to specific users or groups beyond the traditional owner/group/other model. The command 'setfacl -m u:username:rw file' adds a named user entry to the file's ACL, giving that user read and write access without altering the file's group ownership or requiring group membership changes. This is the standard Linux method for per-user granular permissions.

Exam trap

The trap here is confusing chmod's u+rw (which affects the file owner) with granting permissions to a different user; candidates often forget that traditional chmod cannot target arbitrary users, which is precisely why ACLs exist.

How to eliminate wrong answers

Option A is wrong because 'chown user: file' changes the file's owner to the specified user, which is a broader ownership change than granting access and does not preserve the original owner. Option B is wrong because 'chmod u+rw file' modifies the permissions of the file's current owner (the 'u' refers to owner), not an arbitrary user, so it would not grant the target user access unless they already own the file. Option D is wrong because 'chgrp' changes the file's group ownership, which alters group-level access and does not add the user to any group or grant them individual access.

754
Multi-Selectmedium

Which THREE are valid SELinux modes?

Select 3 answers
A.Strict
B.Permissive
C.Enforcing
D.Disabled
E.Audit
AnswersB, C, D

Permissive is a valid SELinux mode: policy violations are logged but not blocked, unlike Enforcing. It satisfies the stem's requirement for a genuine SELinux operating mode, alongside Enforcing and Disabled, and is commonly used for troubleshooting before switching to enforcement.

Why this answer

SELinux has exactly three operational modes, and the three correct options here are B. Permissive, C. Enforcing, and D.

Disabled. Permissive mode is valid because SELinux loads the policy and logs AVC denials to the audit log but does not actually block any access, which is useful for troubleshooting. Enforcing mode is valid because it loads the policy and actively denies and logs any operation that violates the policy.

Disabled mode is valid because it turns SELinux off entirely at the kernel level, so no policy is loaded and no AVC messages are generated. The unmarked options do not belong: Strict is not a mode but rather a type of policy (targeted vs. strict policy), and Audit is not an SELinux mode at all, though auditd is the userspace daemon that records AVC denials.

Exam trap

XK0-006 often tests the confusion between SELinux modes and policy types, or between modes and related concepts like audit logging, causing candidates to select 'Strict' or 'Audit' as valid modes.

755
MCQhard

An administrator is writing a Dockerfile. They need to set a default command that can be overridden when running the container. Which instruction should be used?

A.RUN
B.CMD
C.ENTRYPOINT
D.EXPOSE
AnswerB

CMD sets the default executable or arguments for a container, and any command supplied at docker run overrides it. ENTRYPOINT instead fixes the executable and requires --entrypoint to replace, so CMD satisfies the overridable default required here.

Why this answer

CMD provides defaults that can be overridden by command-line arguments, while ENTRYPOINT cannot be easily overridden without --entrypoint.

756
Multi-Selectmedium

A user has a file with permissions set to 644. Which of the following commands will add the setuid permission to the file? (Choose two.)

Select 2 answers
A.chmod u+s file
B.chmod g+s file
C.chmod 1644 file
D.chmod 4644 file
E.chmod 2644 file
AnswersA, D

`chmod u+s file` sets the setuid bit on the file's owner-execute position, satisfying the stem's requirement to add setuid to a 644 file. The symbolic `u+s` form targets only the user (owner) permission triad, leaving the existing read and write bits untouched, which is precisely the operation requested.

Why this answer

Option A, chmod u+s file, is correct because the u+s symbolic mode adds the setuid bit to the user (owner) permission triad, which is exactly the setuid permission requested. Option D, chmod 4644 file, is correct because in the four-digit octal notation the leading digit represents special permissions, and the value 4 in that position is the setuid bit, so 4644 sets setuid while preserving the existing 644 rw-r--r-- permissions. Option B, chmod g+s file, is wrong because g+s sets the setgid bit on the group triad, not setuid.

Option C, chmod 1644 file, is wrong because the leading 1 sets the sticky bit, not setuid. Option E, chmod 2644 file, is wrong because the leading 2 sets the setgid bit, not setuid.

Exam trap

The trap here is confusing the octal values for setuid (4000), setgid (2000), and sticky (1000); candidates often pick 2644 or 1644 by mixing up which bit corresponds to which special permission.

757
MCQeasy

A Linux administrator notices that the /home filesystem is full. They want to identify which top-level directories under /home are consuming the most disk space. Which command should they run?

A.ls -lR /home
B.du -sh /home/*
C.df -h /home
D.fdisk -l /dev/sda
AnswerB

The du command estimates file space usage. With -s it summarizes each argument, and -h makes the output human-readable. Running du -sh /home/* expands to each top-level directory and file under /home, giving a per-item total. This directly answers which directories consume the most space without descending into every file, making it the appropriate first step for this scenario.

Why this answer

To find which directories under /home are using the most space, the administrator needs aggregated per-directory sizes. The du command with -s and -h summarizes each top-level directory in human-readable units, directly identifying the largest consumers. Filesystem-level tools like df only confirm fullness, while recursive file listings require manual aggregation and partition tools are unrelated to in-filesystem usage.

Exam trap

The trap here is confusing filesystem-level capacity reporting with per-directory usage accounting, leading to choosing df when the question asks which directories are consuming space.

758
MCQhard

A Linux server's clock drifts by several minutes each day. The administrator runs `timedatectl` and sees that NTP synchronization is enabled but the system clock is not synchronized. The server can reach the internet, and `chronyd` is running. Which command should the administrator use to verify which NTP sources are currently reachable and their stratum levels?

A.systemctl status chronyd
B.timedatectl show-timesync
C.ntpq -p
D.chronyc sources -v
AnswerD

`chronyc sources -v` queries the running chronyd daemon and lists configured time sources with their state, stratum, and reachability. The verbose flag adds details such as mode, poll interval, and last sample statistics. This directly shows whether the configured NTP servers are reachable and at what stratum, allowing the administrator to diagnose why synchronization is not occurring despite chronyd running.

Why this answer

With chronyd running, the correct tool to inspect configured time sources, their reachability, and stratum is `chronyc sources -v`. It queries the daemon directly and provides verbose per-source details, enabling the administrator to identify unreachable or high-stratum servers. Other commands target different NTP implementations or only report service status without source-level diagnostics.

Exam trap

The trap here is using `ntpq -p`, which is the query tool for ntpd, on a system that runs chronyd, where `chronyc` is the correct client and the two are not interchangeable.

759
Multi-Selectmedium

A security analyst is investigating a potential breach and needs to examine user login history. Which THREE commands or log files provide information about user logins? (Select THREE.)

Select 3 answers
A.last
B.lastlog
C.lastb
D./var/log/syslog
E./var/log/messages
AnswersA, B, C

The `last` command reads `/var/log/wtmp`, listing successful login sessions with usernames, terminal lines, source hosts and timestamps. This directly satisfies the analyst's need to examine user login history during breach investigation, showing who logged in, from where, and when.

Why this answer

The `last` command (A) reads /var/log/wtmp and displays a chronological list of all successful user logins, logouts, and system reboots, making it a primary tool for reviewing login history. The `lastlog` command (B) reads /var/log/lastlog and reports the most recent login for every user account, which is useful for spotting accounts that have never logged in or that logged in unexpectedly. The `lastb` command (C) reads /var/log/btmp and lists failed login attempts, which is essential when investigating a potential breach involving brute-force or unauthorized access attempts.

Options D and E are incorrect because /var/log/syslog and /var/log/messages are general-purpose system logs that capture a broad mix of kernel, service, and application messages; while they may incidentally contain authentication-related entries, they are not dedicated login-history sources like wtmp, lastlog, and btmp.

Exam trap

The trap here is that candidates often confuse general system logs like /var/log/syslog or /var/log/messages with dedicated authentication logs, but these files lack the structured login/out records that commands like last, lastlog, and lastb specifically parse.

760
MCQmedium

An administrator needs to replace all occurrences of 'oldhost' with 'newhost' in the configuration file /etc/hosts. Which command will perform the replacement and save the changes directly to the file?

A.sed 's/oldhost/newhost/g' /etc/hosts
B.awk '{gsub(/oldhost/,"newhost")}1' /etc/hosts
C.grep -r 'oldhost' /etc/hosts | sed 's/oldhost/newhost/g'
D.sed -i 's/oldhost/newhost/g' /etc/hosts
AnswerD

The `-i` flag makes sed edit /etc/hosts in place, satisfying the requirement to save changes directly to the file. The `g` suffix replaces every occurrence of 'oldhost' on each line, not merely the first, meeting the "all occurrences" constraint without redirection or a temporary file.

Why this answer

The `-i` flag (in-place editing) tells `sed` to write the changes directly back to the file specified. Without `-i`, `sed` only prints the modified output to stdout and does not alter the original file. The substitution command `s/oldhost/newhost/g` performs a global replacement of all occurrences of 'oldhost' with 'newhost' on each line.

Exam trap

The trap here is that candidates often forget the `-i` flag for in-place editing, assuming `sed` modifies the file by default, or they confuse `sed`'s stream behavior with editors like `vim` that directly change the file.

How to eliminate wrong answers

Option A is wrong because it omits the `-i` flag, so the replacement is performed on the stream and printed to stdout, but the original /etc/hosts file remains unchanged. Option B is wrong because `awk` by default writes to stdout only; it does not have an in-place editing flag, so the file is not saved. Option C is wrong because `grep -r` recursively searches for 'oldhost' in /etc/hosts (which is a single file, not a directory) and pipes matching lines to `sed`, but `sed` again lacks `-i` and the pipeline only processes matched lines, not the entire file, so the original file is not modified.

761
Multi-Selectmedium

A Linux administrator is hardening an SSH server. Which two of the following settings should be applied to /etc/ssh/sshd_config to improve security?

Select 2 answers
A.Port 2222
B.X11Forwarding yes
C.PermitRootLogin no
D.PasswordAuthentication no
E.Protocol 1
AnswersC, D

Disables root SSH login, reducing attack surface.

Why this answer

Option C, PermitRootLogin no, is correct because it prevents direct root logins over SSH, forcing administrators to authenticate as an unprivileged user and then escalate privileges via sudo or su, which removes a high-value target and preserves an audit trail. Option D, PasswordAuthentication no, is correct because disabling password authentication forces the use of SSH key pairs (or another stronger method), eliminating brute-force and credential-guessing attacks against user passwords. Option A, Port 2222, merely changes the listening port and is security through obscurity—it does not fix any authentication weakness and can be scanned just as easily.

Option B, X11Forwarding yes, is wrong because enabling X11 forwarding expands the attack surface and should typically be set to no on a hardened server. Option E, Protocol 1, is wrong because SSH protocol 1 is deprecated and cryptographically broken; modern sshd_config uses only protocol 2 (and the Protocol directive is obsolete in current OpenSSH).

Exam trap

XK0-006 often tests whether candidates can distinguish genuine hardening controls from security-through-obscurity measures like non-standard ports, and whether they recognize deprecated options such as Protocol 1 as insecure rather than secure.

762
MCQeasy

A Linux administrator needs to change the hostname of a system to 'webserver01' permanently. The system uses systemd. Which command should the administrator use?

A.hostname webserver01
B.sysctl kernel.hostname=webserver01
C.hostnamectl set-hostname webserver01
D.echo webserver01 > /etc/hosts
AnswerC

hostnamectl set-hostname updates the system hostname and writes it to /etc/hostname, ensuring persistence across reboots. It is the recommended method on systemd-based distributions. This command also updates the transient hostname immediately, so the change takes effect without a reboot.

Why this answer

On systemd-based systems, hostnamectl set-hostname is the correct command to permanently change the hostname. It updates the static hostname in /etc/hostname and applies the change immediately. Other methods either change only the runtime hostname or modify unrelated configuration files.

Exam trap

The trap here is assuming that editing /etc/hosts or using the hostname command alone will persist the change, but only hostnamectl writes to the appropriate configuration.

763
Multi-Selecthard

A DevOps team uses Podman to run containers rootlessly. Which TWO of the following characteristics apply to rootless Podman compared to Docker? (Select TWO).

Select 2 answers
A.It can only run containers as root
B.It requires a running daemon at all times
C.It uses the same CLI syntax as Docker
D.It supports running containers without root privileges
E.It relies on a central registry for all images
AnswersC, D

Podman is designed to be a drop-in replacement for Docker CLI.

Why this answer

Podman does not require a daemon (no central daemon), and it can run containers without root privileges by default using user namespaces.

764
MCQeasy

An administrator wants to ensure that only users in the 'wheel' group can use the sudo command. Which directive in /etc/sudoers enables this?

A.%wheel ALL=ALL
B.@wheel ALL=(ALL) ALL
C.%wheel ALL=(ALL) ALL
D.wheel ALL=(ALL) ALL
AnswerC

The %wheel ALL=(ALL) ALL entry grants members of the wheel group permission to run any command as any user, identified by the leading % group prefix. This restricts sudo rights to wheel members alone, satisfying the requirement that only that group may use sudo.

Why this answer

%wheel ALL=(ALL) ALL grants sudo access to all members of the wheel group.

765
MCQmedium

A security audit reveals that the /etc/shadow file has permissions 0644 and is owned by root:shadow. The auditor states that this is a security risk because any local user can read password hashes. The administrator wants to fix the permissions to ensure that only root and the shadow group can read the file, and no one else can read it. Additionally, the administrator wants to set the immutable attribute on the file to prevent accidental modification. Which set of commands achieves the desired state?

A.chmod 640 /etc/shadow; chattr +i /etc/shadow
B.chmod 640 /etc/shadow; chattr +a /etc/shadow
C.chmod 640 /etc/shadow; chmod +i /etc/shadow
D.chmod 600 /etc/shadow; chattr +i /etc/shadow
AnswerA

chmod 640 restricts read access to root and the shadow group while removing all permissions for others, and chattr +i sets the immutable attribute so the file cannot be modified, renamed or deleted even by root until the flag is cleared.

Why this answer

Chmod 640 sets the file permissions to read/write for root (owner) and read-only for the shadow group, while removing all access for others. chattr +i sets the immutable attribute, which prevents any modifications (including deletion, renaming, or content changes) even by root until the attribute is removed. This satisfies the requirement that only root and the shadow group can read the file, and no one else can read it, while also protecting against accidental modification.

Exam trap

CompTIA often tests the distinction between chmod (file permissions) and chattr (extended attributes), and the trap here is that candidates may confuse the immutable attribute (+i) with the append-only attribute (+a) or mistakenly use chmod to set it.

How to eliminate wrong answers

Option B is wrong because chattr +a sets the append-only attribute, which only allows data to be appended to the file (e.g., for log files), but does not prevent modification or deletion of existing content, so it does not fully protect against accidental modification. Option C is wrong because chmod +i is not a valid command; the immutable attribute is set via chattr, not chmod. Option D is wrong because chmod 600 sets permissions to read/write only for root, removing read access for the shadow group, which violates the requirement that the shadow group should still be able to read the file.

766
MCQmedium

An administrator needs to run a script '/usr/local/bin/cleanup.sh' every day at 2:30 AM. Which crontab entry is correct?

A.2 30 * * * /usr/local/bin/cleanup.sh
B.*/30 2 * * * /usr/local/bin/cleanup.sh
C.30 * * * * /usr/local/bin/cleanup.sh
D.30 2 * * * /usr/local/bin/cleanup.sh
AnswerD

The five fields run minute, hour, day-of-month, month, day-of-week, so `30 2 * * *` fires at 02:30 daily, satisfying the every-day-at-2:30-AM constraint. The absolute path `/usr/local/bin/cleanup.sh` executes directly, since cron's minimal environment lacks the user's PATH.

Why this answer

The correct crontab syntax is `minute hour day month weekday command`. Option D specifies minute 30, hour 2, and asterisks for all other fields, which means the script runs at 2:30 AM every day. This matches the requirement exactly.

Exam trap

CompTIA often tests the order of minute and hour fields in crontab entries, and the trap here is that candidates may swap them (placing hour first) or use `*/30` thinking it means 'at 30 minutes past the hour' rather than 'every 30 minutes'.

How to eliminate wrong answers

Option A is wrong because it places the hour (2) in the minute field and the minute (30) in the hour field, causing the script to run at 30 minutes past every hour on the 2nd day of the month. Option B is wrong because `*/30` in the minute field means 'every 30 minutes' and `2` in the hour field means 'only during hour 2', so the script runs at 2:00 AM, 2:30 AM, and 2:00 AM again (due to the 30-minute interval), not just once at 2:30 AM. Option C is wrong because it sets minute 30 and hour as `*` (every hour), so the script runs at 30 minutes past every hour, i.e., 24 times per day.

767
MCQmedium

A systems administrator needs to ensure that a custom service runs with a specific priority on a Linux server. Which command should the administrator use to achieve this?

A.renice -10 -p 1234
B.ionice -c 2 -n 0 -p 1234
C.nice -n -10 /usr/local/bin/myservice
D.chrt -r 99 /usr/local/bin/myservice
AnswerC

nice -n -10 launches the process with an explicit scheduling niceness of -10, raising its CPU priority relative to default-nice processes. This satisfies the stem's requirement to run the custom service at a specific priority, though negative values require root privileges.

Why this answer

The `nice` command adjusts the CPU scheduling priority of a process at launch time. Using `nice -n -10` sets a higher priority (lower nice value) for the new service, ensuring it runs with the specified priority from the start. This directly meets the requirement to run a custom service with a specific priority.

Exam trap

The trap here is that candidates confuse `nice` (for CPU priority at launch) with `renice` (for adjusting an already running process) or `ionice` (for I/O priority), leading them to select an option that does not set the priority at service start.

How to eliminate wrong answers

Option A is wrong because `renice` changes the priority of an already running process (by PID), not at launch time; the question asks to ensure the service runs with a specific priority, implying it should be set when the service starts. Option B is wrong because `ionice` sets I/O scheduling priority, not CPU priority; the question asks for a specific priority (likely CPU priority), and `ionice` controls disk I/O bandwidth, not CPU scheduling. Option D is wrong because `chrt -r 99` sets a real-time scheduling policy (SCHED_RR) with maximum priority, which is for real-time processes and can cause system instability if misused; the question does not specify real-time requirements, and `nice` is the standard tool for adjusting CPU priority in a non-real-time context.

768
MCQmedium

An administrator needs to configure SELinux to allow the Apache HTTP server to connect to a database server. Which SELinux boolean should be enabled?

A.httpd_can_network_connect
B.httpd_enable_cgi
C.httpd_use_nfs
D.httpd_can_network_connect_db
AnswerD

Enabling httpd_can_network_connect_db permits the httpd_t domain to open network sockets to database ports, directly satisfying the requirement that Apache connect to a database server. Other booleans govern unrelated access, such as outbound connections generally or specific database types, so this one precisely matches the stated constraint.

Why this answer

The SELinux boolean `httpd_can_network_connect_db` specifically allows the Apache HTTP server to make outbound TCP connections to database servers (e.g., MySQL, PostgreSQL). This is required when a web application needs to query a remote database. The other booleans control different aspects of httpd's behavior and do not grant network connectivity to databases.

Exam trap

A common pitfall in SELinux configuration is confusing the general network connect boolean (`httpd_can_network_connect`) with the database-specific boolean (`httpd_can_network_connect_db`). In this scenario, the database-targeted boolean is required.

How to eliminate wrong answers

Option A is wrong because `httpd_can_network_connect` allows general outbound network connections (e.g., to any TCP port), which is broader than needed and may introduce unnecessary risk; it does not specifically target database connections. Option B is wrong because `httpd_enable_cgi` controls whether httpd can execute CGI scripts, not network connectivity. Option C is wrong because `httpd_use_nfs` allows httpd to access files on NFS mounts, not to connect to a database server over the network.

769
MCQmedium

A Linux engineer is investigating high disk I/O on a server. Which command provides disk I/O statistics including %util, await, r/s, and w/s?

A.iostat -x 1
B.sar -b
C.vmstat 1 5
D.free -h
AnswerA

The -x flag extends iostat's report with per-device statistics, including %util (device busy percentage), await (average I/O wait), and r/s and w/s throughput. The 1 argument refreshes every second, exposing the sustained disk I/O pattern the engineer needs to diagnose.

Why this answer

iostat reports CPU and disk I/O statistics, with columns like %util, await, r/s, and w/s.

770
MCQmedium

A Linux administrator is troubleshooting a server that intermittently becomes unresponsive. The administrator suspects a memory leak. Which command should be used to monitor memory usage over time and identify the consuming process?

A.free -h
B.top
C.ss -tuln
D.df -h
AnswerB

top refreshes periodically and sorts processes by CPU and memory, letting the administrator watch resident memory grow over time and pinpoint the leaking process by PID. It satisfies the need for continuous monitoring rather than a single snapshot, which free alone cannot provide.

Why this answer

The `top` command provides a real-time, dynamic view of system processes, including memory usage (RES, VIRT, %MEM) and can be sorted by memory consumption. It updates continuously, making it ideal for monitoring memory usage over time and identifying the specific process responsible for a suspected memory leak.

Exam trap

The trap here is that candidates confuse system-wide memory reporting (`free -h`) with per-process monitoring (`top`), or mistake disk usage commands (`df -h`) or network tools (`ss`) for memory diagnostics.

How to eliminate wrong answers

Option A is wrong because `free -h` shows total, used, and available memory in human-readable format, but it does not display per-process memory consumption or allow monitoring over time. Option C is wrong because `ss -tuln` lists listening and connected sockets (TCP/UDP) with numeric addresses; it is a network socket statistics tool, not a memory monitoring command. Option D is wrong because `df -h` reports filesystem disk space usage, not memory (RAM) usage, and cannot identify processes consuming memory.

771
MCQmedium

A system administrator notices that the root filesystem is at 95% capacity. Which command should be used to identify the directories consuming the most space?

A.df -h
B.du -sh /*
C.fdisk -l
D.ls -la /
AnswerB

`du -sh /*` reports the apparent disk usage of each top-level directory, with `-s` summarising each argument and `-h` rendering sizes readably. This directly satisfies the stem's need to pinpoint which directories consume the most space on the near-full root filesystem, unlike tools showing only aggregate free space.

Why this answer

B is correct because `du -sh /*` calculates disk usage for each top-level directory under root, showing human-readable sizes. This directly identifies which directories consume the most space, allowing the administrator to pinpoint the source of the 95% capacity issue.

Exam trap

The trap here is that candidates often confuse `df -h` (filesystem-level overview) with `du -sh` (directory-level detail), mistakenly thinking `df` can pinpoint which directories are consuming space.

How to eliminate wrong answers

Option A is wrong because `df -h` shows filesystem-level disk usage (capacity, used, available) but does not drill down into directories to identify which ones are consuming space. Option C is wrong because `fdisk -l` lists partition tables and disk geometry, not directory-level disk usage. Option D is wrong because `ls -la /` lists file names, permissions, and metadata but does not calculate or display the actual disk space consumed by each directory.

772
Multi-Selecthard

Which TWO tools are specifically designed to detect rootkits on a Linux system?

Select 2 answers
A.lsof
B.rkhunter
C.netstat
D.clamav
E.chkrootkit
AnswersB, E

rkhunter scans for rootkit signatures, comparing file hashes and permissions against known-good databases to flag hidden binaries, suspicious kernel modules and altered system files. This satisfies the stem's requirement for a tool specifically designed for rootkit detection, rather than general malware or vulnerability scanning.

Why this answer

rkhunter (B) is a dedicated rootkit hunter that scans for known rootkit signatures, suspicious files, and hidden processes on Linux, making it specifically designed for rootkit detection. chkrootkit (E) is likewise a purpose-built tool that checks system binaries and common rootkit infection vectors on Linux. By contrast, lsof (A) only lists open files and associated processes, netstat (C) merely displays network connections and routing tables, and clamav (D) is an antivirus scanner targeting malware such as viruses and trojans rather than rootkits specifically, so none of these are specifically designed for rootkit detection.

Exam trap

The trap here is that candidates may confuse general system monitoring tools (lsof, netstat) or general antivirus (ClamAV) with specialized rootkit detection tools, but only rkhunter and chkrootkit are explicitly designed for that purpose.

773
MCQmedium

Refer to the exhibit. What is the total amount of RAM installed on the system?

A.7.7G
B.7.5G
C.8.0G
D.0.1G
AnswerA

The exhibit reports total installed memory as 7.7G, which is the sum of physical RAM recognised by the system. This figure reflects installed capacity rather than free or available memory shown separately in the output.

Why this answer

The output of `free -h` shows the total memory in the 'total' column of the 'Mem:' row, which is 7.7G. This value represents the total physical RAM installed and available to the system, as reported by the kernel from the hardware.

Exam trap

The trap here is that candidates confuse the 'total' column with the nominal hardware capacity (e.g., 8 GB) or mistakenly pick the 'used' or 'available' values, not realizing that `free -h` reports the kernel's view of installed RAM after hardware reservations.

How to eliminate wrong answers

Option B (7.5G) is wrong because it corresponds to the 'used' column, not the 'total' column, and represents memory currently in use by processes and the kernel. Option C (8.0G) is wrong because it might be the nominal installed RAM (e.g., 8 GB stick), but the system reports 7.7G due to reserved memory for hardware, firmware, or the kernel (e.g., BIOS, GPU, or kernel memory reservation). Option D (0.1G) is wrong because it is the 'available' column, which estimates memory available for starting new applications, not the total installed RAM.

774
MCQmedium

A Linux system has a directory with permissions drwxr-xr-x. A user in the group 'dev' tries to create a new file inside this directory. Which permission is missing that prevents the user from creating the file?

A.Write permission for the owner
B.Sticky bit is set
C.Write permission for the group
D.Execute permission for the group
AnswerC

Creating a file requires write permission on the containing directory, not on the file itself. The group permission set is r-x, granting read and execute (traverse) but withholding write. Adding group write (rwx) satisfies the stem's constraint, allowing the 'dev' group member to create entries within that directory.

Why this answer

The directory has write permission for the owner, but only read and execute for the group. To create a file, the user needs write permission on the directory, which is not granted to the group.

775
Multi-Selectmedium

A Linux engineer needs to restrict resource usage for users in the 'developers' group. Which TWO files or commands can be used to set ulimit values?

Select 2 answers
A.sysctl command
B./etc/security/limits.conf
C./etc/pam.d/login with pam_limits.so
D./etc/ulimit.conf
E.ulimit command
AnswersB, E

/etc/security/limits.conf defines per-user and per-group ulimit values, letting the engineer apply soft and hard resource caps to the 'developers' group through a group entry, which satisfies the requirement to restrict resource usage for that group.

Why this answer

Option B, /etc/security/limits.conf, is correct because this is the PAM configuration file where persistent per-user or per-group resource limits (such as nproc, nofile, or memlock) are defined using entries like '@developers hard nproc 20'. Option E, the ulimit command, is correct because it is the shell builtin used to view or set soft and hard resource limits for the current shell session, for example 'ulimit -u 20' to cap processes. Option C is not correct on its own because /etc/pam.d/login with pam_limits.so is the PAM module that enforces the limits defined in limits.conf, but it is not where the ulimit values themselves are set.

Option A, sysctl, is incorrect because it tunes kernel parameters at runtime (e.g., net.ipv4.ip_forward) rather than per-user resource limits. Option D, /etc/ulimit.conf, is incorrect because no such standard file exists for setting ulimit values.

Exam trap

The trap here is that candidates often confuse the configuration file (/etc/security/limits.conf) with the PAM module file (/etc/pam.d/login) or think the ulimit command alone can set persistent limits for a group, when in fact ulimit only affects the current shell session and is not persistent across logins for all group members.

776
MCQmedium

Refer to the exhibit. A web application running under Apache cannot write to /var/log/app.log. The file has permissions 664 and is owned by apache. What is the correct action to allow writes while maintaining SELinux policies?

A.Change the ownership to root.
B.Change the SELinux context of the file to httpd_log_t.
C.Set the httpd_can_network_connect boolean.
D.Disable SELinux for the httpd daemon.
AnswerB

Assigning httpd_log_t lets the Apache process, confined by the httpd_t domain, write to the file under SELinux type enforcement. The 664 mode and apache ownership already permit Unix-level writes, so the remaining constraint is the file's label; httpd_log_t is the type httpd_t is allowed to append to.

Why this answer

The file /var/log/app.log has permissions 664 and is owned by apache, so the web server should be able to write to it. However, SELinux is blocking the write because the file's SELinux context does not match the type expected for files that Apache (httpd) is allowed to write to. Changing the SELinux context to httpd_log_t tells SELinux that this file is a log file that httpd can write to, which resolves the denial while keeping SELinux enforcing.

Exam trap

The trap here is that candidates see the file is owned by apache with 664 permissions and assume the issue is file ownership or permissions, overlooking that SELinux enforces its own access controls independent of standard Linux permissions.

How to eliminate wrong answers

Option A is wrong because changing ownership to root would actually prevent the apache user from writing to the file (since root owns it and the file has 664 permissions, the apache user is in the 'others' category and can only read). Option C is wrong because the httpd_can_network_connect boolean controls whether httpd can initiate outbound network connections, not file write permissions. Option D is wrong because disabling SELinux for the httpd daemon would weaken security unnecessarily; the correct approach is to apply the proper SELinux file context rather than bypassing the policy entirely.

777
MCQmedium

A system administrator wants to limit the CPU and memory usage of a specific service to prevent it from affecting other processes. Which Linux feature should be used?

A.ulimit
B.renice
C.cgroups
D.nice
AnswerC

cgroups impose per-service CPU and memory limits by grouping processes and enforcing resource controllers, directly satisfying the requirement to stop one service starving others. Unlike nice, which only adjusts CPU scheduling priority, cgroups cap memory too, providing the hard isolation the scenario demands.

Why this answer

C is correct because cgroups (control groups) is the Linux kernel feature designed to limit, account for, and isolate resource usage (CPU, memory, disk I/O, etc.) of process groups. Unlike simple priority adjustments, cgroups enforce hard limits on resource consumption, making them ideal for preventing a specific service from starving other processes.

Exam trap

The trap here is that candidates confuse process priority tools (nice/renice) with resource limiting tools, not realizing that nice only affects CPU scheduling order, not hard caps on CPU or memory usage.

How to eliminate wrong answers

Option A is wrong because ulimit sets per-process resource limits (e.g., file size, number of open files) for a user session, not for a service as a whole, and it cannot limit CPU usage as a percentage or memory usage in a hierarchical manner. Option B is wrong because renice adjusts the scheduling priority (nice value) of a running process, which affects CPU time allocation but does not impose hard limits on CPU or memory usage. Option D is wrong because nice sets the initial scheduling priority of a process, influencing how the kernel allocates CPU time, but it cannot limit memory usage or enforce absolute resource caps.

778
MCQmedium

An administrator needs to add an ACL entry to a file that grants the user 'john' read and write permissions. The file currently has no ACLs. Which command should the administrator use?

A.chmod u+rw file
B.setfacl -x u:john file
C.setfacl -m u:john:rw file
D.getfacl -m u:john:rw file
AnswerC

setfacl with -m modifies the ACL, and u:john:rw grants john read and write. Since the file has no existing ACLs, this creates the access ACL entry directly, satisfying the requirement without altering the traditional owner, group or other permission bits.

Why this answer

The correct command is setfacl -m u:john:rw file. setfacl is used to modify ACLs. getfacl is used to display ACLs and does not support a -m option for modifying ACLs on standard Linux systems.

779
Multi-Selecteasy

Which TWO of the following are valid methods for debugging a Bash script? (Choose TWO.)

Select 2 answers
A.Add 'set -r' to restrict shell
B.Run the script with 'bash -x script.sh'
C.Add 'set -x' at the start of the script
D.Run the script with 'bash -d script.sh'
E.Add 'set -n' to check syntax
AnswersB, C

Traces each command before execution.

Why this answer

Running 'bash -x script.sh' enables an execution trace that prints each command and its arguments to stderr before executing it, which is a standard debugging method for Bash scripts. Option C is correct because adding 'set -x' at the start of the script achieves the same trace output, but from within the script itself, allowing granular control over which sections are traced.

Exam trap

CompTIA often tests the distinction between syntax checking ('set -n' or 'bash -n') and runtime tracing ('set -x' or 'bash -x'), and candidates may mistakenly choose 'set -n' as a debugging method because they confuse syntax validation with execution debugging.

780
MCQmedium

A Linux administrator receives reports that a database server becomes unresponsive every day around 02:00. Reviewing logs, the administrator notices repeated messages about 'blocked for more than 120 seconds' and high I/O wait. Which command should be used to identify which process is generating the most disk I/O during this period?

A.iotop -o -d 5
B.iostat -x 5
C.vmstat 5
D.sar -d 5 3
AnswerA

iotop displays per-process I/O usage, and the -o option shows only processes actively performing I/O. With -d 5, it refreshes every five seconds, allowing the administrator to identify the process generating heavy disk activity during the 02:00 window. This directly addresses the need to attribute I/O to a specific process.

Why this answer

The administrator must attribute heavy disk I/O to a specific process. iotop is designed for per-process I/O monitoring and the -o flag filters out idle processes, making it ideal for identifying the culprit during the nightly issue. Other tools show device-level or system-wide I/O but cannot tie activity to a process.

Exam trap

The trap here is assuming that any I/O monitoring tool will identify the responsible process, when many only report device-level or system-wide statistics.

781
Multi-Selectmedium

A compliance auditor requires that a Linux server's /home directory be mounted with options that prevent users from executing setuid binaries stored there and from creating device files. The administrator is editing /etc/fstab for the /home entry. Which TWO mount options should be added to meet these requirements? (Choose two.)

Select 2 answers
A.noatime
B.ro
C.nosuid
D.nodev
E.noexec
AnswersC, D

The nosuid mount option prevents the execution of setuid and setgid programs on that filesystem. Because the requirement is to stop users from running setuid binaries from /home, this option directly satisfies it. It is a standard hardening measure for user-writable directories and works at the kernel mount level without affecting file permissions.

Why this answer

The nosuid option blocks execution of setuid and setgid binaries, and nodev blocks the use of device files on the filesystem. Together they harden /home against privilege escalation and device-based attacks without preventing normal file storage. noexec, noatime, and ro either do not target the stated risks or impose excessive functional restrictions that the auditor did not request.

Exam trap

The trap here is reaching for noexec when the requirement is specifically to block setuid execution, since noexec is broader and does not cover device files.

Page 10

Page 11 of 11

All pages