Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 151–225

781 questions total · 11pages · All types, answers revealed

Page 2

Page 3 of 11

Page 4
151
MCQhard

A containerized application writes logs to /var/log/app.log. The administrator wants to ensure logs persist even if the container is removed. Which approach should be used?

A.Copy logs to a bind mount
B.Set the log driver to syslog
C.Redirect logs to stdout and use docker logs
D.Use a Docker volume mounted at /var/log
AnswerD

Mounting a Docker volume at /var/log stores log data outside the container's writable layer, on the host's volume storage, so it survives container removal. This directly satisfies the persistence constraint, unlike bind mounts tied to host paths or ephemeral layer writes, which are destroyed with the container.

Why this answer

Docker volumes are managed by Docker and persist independently of the container lifecycle. By mounting a volume at /var/log, the application writes logs directly to the volume, ensuring the data survives container removal and can be reused by other containers.

Exam trap

The trap here is that candidates may confuse bind mounts with Docker volumes, thinking that any host-path mapping provides automatic persistence, or they may assume that docker logs retains logs after container removal, when in fact it only works for running or stopped containers, not removed ones.

How to eliminate wrong answers

Option A is wrong because copying logs to a bind mount after they are written is not a native Docker approach; bind mounts rely on host directory paths and do not automatically persist logs if the container is removed without explicit copying. Option B is wrong because setting the log driver to syslog sends logs to the system's syslog service, but this does not guarantee persistence of the log file at /var/log/app.log within the container; it changes the output destination, not the file storage. Option C is wrong because redirecting logs to stdout and using docker logs only captures logs in the container's stdout stream, which is ephemeral and lost when the container is removed; docker logs does not provide persistent file storage.

152
MCQmedium

A Linux administrator is writing a Bash script that must run a cleanup routine when the script exits, whether it exits normally or is interrupted by a signal. The script defines a function named cleanup. Which command should the administrator use to ensure cleanup runs on exit?

A.setsid cleanup &
B.trap 'cleanup' EXIT
C.at now + 1 minute <<< cleanup
D.trap 'cleanup' SIGKILL
AnswerB

The trap builtin with the EXIT pseudo-signal runs the specified command when the shell exits, regardless of whether the exit is normal or caused by a signal such as SIGINT. This matches the requirement to run cleanup unconditionally at script termination, and the single quotes defer expansion of cleanup until the trap fires.

Why this answer

The trap builtin is the standard Bash mechanism for running commands in response to signals or shell events. Using the EXIT pseudo-signal makes the handler run on any script termination, including normal completion and receipt of catchable signals, which is exactly what the administrator needs for a guaranteed cleanup routine.

Exam trap

The trap here is assuming that any signal name works with trap, when SIGKILL and SIGSTOP are uncatchable and can never trigger a handler.

153
MCQmedium

A DevOps engineer is writing a Bash script that checks if a file exists and is readable. Which test condition should be used inside an if statement?

A.[[ -e file ]]
B.[[ -f file ]]
C.[[ -s file ]]
D.[[ -r file ]]
AnswerD

Correct. -r returns true if the file exists and has read permission.

Why this answer

The -e test checks if a file exists, and -r checks if it is readable. Using -f also checks for a regular file, but the question requires existence and readability, so combining -e and -r is correct. However, the options include -f and -r, but -f alone does not check readability.

The correct combination is -e and -r, but since that is not an option, the best answer is -r because it implies existence? Actually, -r returns true only if the file exists and is readable. So -r alone satisfies both conditions.

154
Multi-Selecthard

A security team wants to harden a Linux server against unauthorized access. They need to restrict which users can authenticate via SSH and ensure that only key-based authentication is allowed for a specific group. Which TWO actions should the administrator take? (Choose two.)

Select 2 answers
A.Configure PAM to require two-factor authentication for all SSH sessions.
B.Use AllowGroups sshusers in /etc/ssh/sshd_config to limit SSH access to members of the sshusers group.
C.Add all users to the wheel group and set UsePAM yes in sshd_config.
D.Set PermitRootLogin yes in /etc/ssh/sshd_config to allow administrative access.
E.Set PasswordAuthentication no in /etc/ssh/sshd_config and restart sshd.
AnswersB, E

AllowGroups restricts SSH logins to users who are members of the specified group(s). This satisfies the requirement to restrict which users can authenticate via SSH. Combined with disabling password authentication, it ensures only authorized users with keys can connect. The directive must be placed in sshd_config and sshd restarted.

Why this answer

Disabling PasswordAuthentication enforces key-based logins, and AllowGroups restricts SSH access to a defined set of users. Together they meet the hardening goals. The other options either weaken security, add unrelated controls, or grant unnecessary privileges.

Restarting sshd after changes is required for them to take effect.

Exam trap

The trap here is confusing authentication method restrictions with user access controls; both are needed to fully satisfy the scenario.

155
Multi-Selecthard

Which THREE of the following are commonly used configuration management and automation tools in the Linux ecosystem? (Choose THREE.)

Select 3 answers
A.Terraform
B.Ansible
C.Salt
D.Puppet
E.Nagios
AnswersB, C, D

Agentless automation tool.

Why this answer

Ansible is a configuration management and automation tool that uses SSH for agentless communication and YAML-based playbooks to define desired system states. It is widely adopted in Linux environments for tasks such as software provisioning, configuration drift remediation, and orchestration, making it a correct choice for this question.

Exam trap

CompTIA often tests the distinction between infrastructure provisioning tools (like Terraform) and configuration management tools (like Ansible, Salt, Puppet), leading candidates to mistakenly include Terraform when the question explicitly asks for configuration management and automation tools in the Linux ecosystem.

156
MCQmedium

A Linux administrator is troubleshooting a server that has become unresponsive. They suspect a process is consuming excessive CPU. Which command should they use to display a real-time, interactive view of processes sorted by CPU usage?

A.iostat -c
B.vmstat 1
C.top
D.ps aux
AnswerC

The top command provides a dynamic, real-time view of running processes, typically sorted by CPU usage by default. It allows the administrator to identify processes with high CPU consumption, and it supports interactive commands to change sorting, kill processes, and more. This makes it ideal for live troubleshooting of CPU-bound issues on a server.

Why this answer

The top command is designed for real-time process monitoring, showing a continuously updated list of processes sorted by CPU usage. It allows an administrator to quickly spot which process is consuming the most CPU and take action, such as renice or kill. Other tools like ps provide only a snapshot, while vmstat and iostat give system-wide statistics without per-process breakdown.

Exam trap

The trap here is confusing static snapshot tools like ps with interactive, real-time monitors like top, which are needed for live CPU troubleshooting.

157
MCQhard

A process with PID 2345 is not responding. The administrator wants to force stop the process immediately. Which command should be used?

A.kill -9 2345
B.kill -1 2345
C.pkill -15 -f processname
D.kill -15 2345
AnswerA

SIGKILL (signal 9) cannot be caught, blocked or ignored by the process, so the kernel terminates PID 2345 immediately. This satisfies the requirement to force stop an unresponsive process, unlike the default SIGTERM sent by plain kill.

Why this answer

SIGKILL (signal 9) forcefully terminates a process. kill -9 2345 sends SIGKILL to PID 2345.

158
MCQmedium

A technician needs to search a log file for lines containing either 'ERROR' or 'FATAL' and display the line numbers. Which command accomplishes this?

A.grep -v -E 'ERROR|FATAL' logfile
B.grep -r -n 'ERROR|FATAL' logfile
C.grep -n -E 'ERROR|FATAL' logfile
D.grep -i 'ERROR|FATAL' logfile
AnswerC

grep -n prints line numbers, and -E enables extended regular expressions so the alternation ERROR|FATAL matches either pattern. This satisfies the requirement to find lines containing either term while displaying their line numbers in the log file.

Why this answer

grep -n -E 'ERROR|FATAL' logfile uses extended regex with alternation and -n for line numbers. -i ignores case, but the stem does not mention case-insensitive; -v inverts match; -r is recursive.

159
MCQhard

A company runs a critical web application on a single Linux server. The application consists of a Node.js backend and a PostgreSQL database. The server is running out of disk space frequently due to application logs. The administrator wants to implement a log rotation solution that is automated, minimizes data loss, and compresses old logs. The administrator has root access and wants to use built-in tools. Currently, logs are written to /var/log/app/access.log and /var/log/app/error.log. The application never closes its log files. Which of the following is the best course of action?

A.Configure the systemd journal to capture the application logs and set MaxRetentionSec.
B.Create a cron job that runs every hour to move the logs to a backup directory and restart the application.
C.Configure logrotate with daily rotation, compression, and the copytruncate option.
D.Configure logrotate with a weekly rotation and no copytruncate, since the application will eventually close the log files.
AnswerC

The application never closes its log files, so logrotate's default rename-and-recreate leaves the process writing to the old inode. copytruncate copies the log then truncates the original in place, preserving the open file descriptor while enabling daily compression.

Why this answer

Logrotate with the copytruncate option allows the log file to be rotated without requiring the application to close or reopen its file handles. This is essential since the application never closes its log files. Daily rotation with compression addresses the frequent disk space issue while minimizing data loss, and logrotate is a built-in Linux tool that runs automatically via cron.

Exam trap

The trap here is that candidates may assume logrotate always requires the application to close its log files (via postrotate scripts), but the copytruncate option is specifically designed for applications that keep file handles open, making it the correct choice when the application never closes its logs.

How to eliminate wrong answers

Option A is wrong because systemd-journald is designed for capturing systemd service logs, not for rotating existing log files written directly by an application; it does not handle files like /var/log/app/access.log, and MaxRetentionSec only controls journal retention, not file rotation. Option B is wrong because moving logs and restarting the application every hour would cause unnecessary application downtime and potential data loss, and it is not a built-in automated solution like logrotate. Option D is wrong because without copytruncate, logrotate would attempt to rename or move the log file, which would cause the application to continue writing to the old file (since it never closes its file handles), leading to lost logs and no rotation; weekly rotation is also too infrequent for a server running out of disk space frequently.

160
MCQeasy

A Linux administrator wants to prevent users from reusing their last five passwords. Which PAM module should be configured?

A.pam_faillock
B.pam_pwquality
C.pam_unix
D.pam_pwhistory
AnswerD

Configuring pam_pwhistory with the remember=5 parameter stores previous password hashes and rejects any new password matching them, directly enforcing the five-password reuse restriction in the stem. It hooks into the password stack, so changes are blocked at the point of update rather than merely advised.

Why this answer

The pam_pwhistory module is specifically designed to enforce password history policies by storing a user's previous passwords in a separate file (e.g., /etc/security/opasswd) and preventing reuse of those passwords. By configuring the 'remember' option in the PAM stack, the administrator can set the number of previous passwords that cannot be reused, such as 'remember=5' to block the last five passwords.

Exam trap

The trap here is that candidates often confuse pam_pwquality (which enforces password strength) with pam_pwhistory (which enforces password reuse prevention), leading them to select pam_pwquality when the question specifically asks about preventing reuse of previous passwords.

How to eliminate wrong answers

Option A is wrong because pam_faillock is used to lock user accounts after a specified number of failed login attempts, not to enforce password history or reuse restrictions. Option B is wrong because pam_pwquality is used to enforce password complexity requirements (e.g., length, character classes) and does not track or prevent reuse of previous passwords. Option C is wrong because pam_unix handles traditional Unix authentication, password updates, and shadow password management, but it does not have built-in support for password history tracking; that functionality is delegated to pam_pwhistory.

161
Multi-Selectmedium

A Linux administrator is writing a Bash script that uses a function. Which two statements about Bash functions are correct? (Choose TWO.)

Select 2 answers
A.Functions are called by their name without parentheses.
B.Functions can return a value using the return statement.
C.Function definitions must be placed at the beginning of the script.
D.Functions cannot accept arguments.
E.Functions can be called before they are defined.
AnswersA, B

Functions are invoked by name; parentheses are used only in definition.

Why this answer

Bash functions must be defined before use and are called by name without parentheses.

162
MCQeasy

A user reports that they cannot reach a website. The administrator wants to check the path that packets take to the destination server. Which command should be used?

A.ip addr
B.ss
C.traceroute
D.ping
AnswerC

traceroute sends packets with incrementally increasing TTL values, causing each router along the path to return an ICMP Time Exceeded message. This reveals the hop-by-hop route packets take to the destination, exactly what the administrator needs to diagnose where connectivity fails.

Why this answer

The `traceroute` command is used to trace the path packets take from the source to a destination host, showing each hop (router) along the way. It uses ICMP echo requests (or UDP packets on Linux) with incrementing TTL values to elicit ICMP Time Exceeded messages from intermediate routers, which reveals the network path. This directly addresses the administrator's need to check the path to the destination server.

Exam trap

In the Linux+ exam, candidates may confuse 'ping' with 'traceroute'. Ping only tests reachability and latency, while traceroute reveals the specific path and each hop. The trap is choosing ping because it can show connectivity issues, but it does not show the route.

How to eliminate wrong answers

Option A is wrong because `ip addr` displays IP addresses and network interface configuration on the local host, not the path packets take to a remote destination. Option B is wrong because `ss` (socket statistics) shows information about local sockets and connections, not the network path or routing hops. Option D is wrong because `ping` tests reachability and measures round-trip time using ICMP echo requests, but it does not show the intermediate hops or the path packets traverse.

163
Multi-Selectmedium

A system administrator needs to monitor system performance over time. Which THREE tools can be used to collect and display CPU, memory, and I/O statistics? (Choose three.)

Select 3 answers
A.iostat
B.top
C.sar
D.vmstat
E.htop
AnswersA, C, D

iostat reads per-device and per-partition I/O statistics from the kernel, reporting transfer rates, request queue lengths and CPU utilisation. It satisfies the requirement to collect and display I/O statistics over time, complementing CPU and memory tools such as vmstat, sar and top.

Why this answer

iostat (A) is correct because it is part of the sysstat package and reports CPU utilization along with per-device and per-partition I/O statistics such as tps, kB_read/s, and kB_wrtn/s, making it ideal for collecting and displaying I/O and CPU data over time. sar (C) is correct because the System Activity Reporter, also from sysstat, records and replays historical CPU, memory, and I/O metrics via cron-collected binary files (e.g., /var/log/sa/saXX) using options like -u, -r, and -b, which directly supports monitoring performance over time. vmstat (D) is correct because it reports virtual memory, CPU, and I/O statistics including processes (r, b), swap (si, so), memory (free, buff, cache), and block I/O (bi, bo) at specified intervals, allowing ongoing collection and display of the required metrics. top (B) is not among the marked answers because although it displays CPU and memory in real time, it is an interactive process viewer rather than a tool designed to collect and persist statistics over time, and it lacks dedicated I/O reporting. htop (E) is likewise excluded because it is an interactive process monitor similar to top and does not provide the historical data collection or detailed I/O statistics that the scenario requires.

Exam trap

CompTIA often tests the distinction between real-time interactive tools (like top and htop) and historical logging tools (like sar), and the trap here is that candidates may choose htop thinking it covers I/O, but it does not report I/O statistics, while sar is a valid tool that is sometimes overlooked.

164
MCQmedium

A Linux administrator receives reports that a web application hosted on the company's internal server is intermittently slow. The server runs CentOS 7 and hosts multiple virtual hosts. The administrator checks system resources and notices that the system's swap usage is high. Which of the following is the MOST likely cause of the performance issue?

A.Misconfigured virtual host causing memory leaks
B.Insufficient physical memory for the workload
C.Network congestion on the internal network
D.Excessive CPU load from a runaway process
AnswerB

High swap usage indicates the kernel is paging memory to disk because RAM cannot hold the working set. That thrashing causes intermittent slowness, so insufficient physical memory for the workload is the most likely cause in the stem.

Why this answer

High swap usage indicates that the system is actively paging memory to disk because the available physical RAM is insufficient to hold the active working set. This causes significant latency because disk I/O is orders of magnitude slower than RAM, leading to intermittent slowdowns for the web application. The fact that multiple virtual hosts are running on CentOS 7 increases the memory demand, making insufficient physical memory the most likely root cause.

Exam trap

The trap here is that candidates often associate performance issues with CPU or network problems first, overlooking that high swap usage is a direct indicator of memory exhaustion, not a symptom of CPU load or network congestion.

How to eliminate wrong answers

Option A is wrong because a misconfigured virtual host causing memory leaks would manifest as steadily increasing memory consumption over time, not necessarily as high swap usage; while it could contribute, the direct symptom of high swap points to a physical memory shortage rather than a leak. Option C is wrong because network congestion would cause packet loss, retransmissions, or high latency on the network interface, not high swap usage in system memory statistics. Option D is wrong because excessive CPU load from a runaway process would be visible in CPU utilization metrics (e.g., via top or uptime), not directly in swap usage; high swap can occur with low CPU load if memory is the bottleneck.

165
MCQmedium

In a Kubernetes cluster, a developer needs to create a Deployment that runs three replicas of a container image 'myapp:1.0' and exposes port 8080. Which YAML snippet correctly defines this Deployment?

A.apiVersion: v1 kind: Pod metadata: name: myapp spec: replicas: 3 containers: - name: myapp image: myapp:1.0 ports: - containerPort: 8080
B.apiVersion: apps/v1 kind: Deployment metadata: name: myapp spec: replicas: 3 selector: app: myapp template: containers: - name: myapp image: myapp:1.0 ports: - containerPort: 8080
C.apiVersion: apps/v1 kind: Deployment metadata: name: myapp spec: replicas: 3 selector: matchLabels: app: myapp template: metadata: labels: app: myapp spec: containers: - name: myapp image: myapp:1.0 ports: - containerPort: 8080
D.apiVersion: v1 kind: Deployment metadata: name: myapp spec: replicas: 3 template: spec: containers: - name: myapp image: myapp:1.0 ports: - containerPort: 8080
AnswerC

Correct. Includes required apiVersion, selector, and template with labels.

Why this answer

A Deployment YAML must have apiVersion, kind, metadata, spec with replicas and template containing container spec with image and ports.

166
MCQeasy

A user reports that they cannot log in to a Linux server via SSH. The administrator checks /etc/passwd and sees the user's shell is set to /sbin/nologin. What is the most likely reason for the login failure?

A.The SSH service is not running.
B.The user is not allowed to have an interactive shell.
C.The user's account is locked.
D.The user's password has expired.
AnswerB

/sbin/nologin is a shell that prints a message and exits immediately, denying interactive login. It is commonly set for system accounts or users who should only use services like FTP or email. The SSH login fails because the shell does not provide an interactive session.

Why this answer

The shell /sbin/nologin is designed to prevent interactive logins. When a user with this shell attempts to log in via SSH, the shell is executed and immediately exits, denying access. This is the most likely reason for the failure, as it directly matches the observed configuration.

Exam trap

The trap here is assuming that a login failure is always due to password or account lock issues, overlooking the shell setting that explicitly denies interactive access.

167
MCQeasy

A Kubernetes YAML manifest defines a Deployment. Which field specifies the number of pod replicas to run?

A.metadata.replicas
B.spec.template.replicas
C.spec.containers.replicas
D.spec.replicas
AnswerD

The replicas field sits under the Deployment's spec, declaring the desired pod count that the ReplicaSet controller continuously reconciles. Setting spec.replicas to the required number satisfies the stem's demand for specifying how many identical pods run concurrently.

Why this answer

In a Deployment spec, the 'replicas' field sets the desired number of pod instances.

168
MCQmedium

A Linux server running RHEL 9 has SELinux in enforcing mode. A web application (Apache) is serving content from a custom directory /var/www/html/myapp. The application needs to write to a subdirectory /var/www/html/myapp/uploads. The administrator sets the context of the uploads directory to httpd_sys_content_t and also runs `restorecon -Rv /var/www/html/myapp`. However, Apache still cannot write to the uploads directory. The administrator checks the SELinux denials in /var/log/audit/audit.log and sees AVC denials related to writing. Which step should the administrator take next?

A.Disable SELinux temporarily.
B.Set the boolean httpd_enable_homedirs to on.
C.Add the apache user to the group that owns uploads.
D.Change the type of the uploads directory to httpd_sys_rw_content_t.
AnswerD

This type allows Apache to write into the directory.

Why this answer

The httpd_sys_content_t type is for read-only content. For read-write access, the directory must have type httpd_sys_rw_content_t (or httpd_sys_script_rw_t for scripts). Setting this type via `chcon -t httpd_sys_rw_content_t /var/www/html/myapp/uploads` will allow Apache to write.

Option A (boolean httpd_enable_homedirs) is unrelated. Option C (add to group) does not address SELinux.

169
Drag & Dropmedium

Drag and drop the steps to create and apply a systemd service unit in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence to create and apply a systemd service unit is: create the unit file in /etc/systemd/system/, then run systemctl daemon-reload to load the new unit, then run systemctl enable to set it to start on boot, and finally run systemctl start to start it immediately. Common mistakes include enabling before reloading, starting before enabling, or attempting to enable a non-existent unit.

170
MCQeasy

A script named 'test.sh' contains '#!/bin/bash' and is located in the current directory. Which command runs the script in the current shell environment without forking a subshell?

A../test.sh
B.sh test.sh
C.bash test.sh
D.source test.sh
AnswerD

The source builtin reads and executes the script's commands in the current shell process, so variables and directory changes persist and no subshell is forked. Running ./test.sh or bash test.sh would spawn a child process instead.

Why this answer

The `source` command (or its synonym `.`) executes the script in the current shell environment without forking a subshell. This is essential when you need the script to modify the current shell's environment, such as setting variables or changing directories, because a subshell would discard those changes upon exit.

Exam trap

CompTIA often tests the distinction between executing a script via its path (which forks a subshell) and sourcing it (which runs in the current shell), and candidates mistakenly think that `./test.sh` runs in the current shell because it is invoked directly from the command line.

How to eliminate wrong answers

Option A is wrong because `./test.sh` runs the script as an executable, which causes the kernel to fork a new subshell (based on the shebang) to execute the commands; the script does not run in the current shell. Option B is wrong because `sh test.sh` explicitly invokes the Bourne shell as a new process, forking a subshell that runs the script independently of the current shell. Option C is wrong because `bash test.sh` similarly launches a new Bash process as a subshell, isolating any environment changes from the parent shell.

171
MCQhard

An administrator is investigating a system that may have been compromised. The 'aide' database was created six months ago. After running 'aide --check', many files in /usr/bin are reported as changed. Which action should the administrator take first to identify the cause?

A.Increase the verbosity of AIDE to see which attributes changed.
B.Update the AIDE database with 'aide --update'.
C.Compare the checksums with the original package manager database (rpm -V).
D.Restore the original files from backup.
AnswerC

Comparing against the RPM database verifies whether the changed binaries match their vendor-shipped checksums, distinguishing genuine tampering from legitimate package updates applied since the AIDE database was built six months ago. This directly addresses the stem's need to identify the cause of the /usr/bin discrepancies before assuming compromise.

Why this answer

The AIDE database is six months old, so any changes to system binaries in /usr/bin since then would be flagged. The first step should be to verify whether these changes are legitimate (e.g., from package updates) or malicious by comparing the current file checksums against the RPM package manager's database using 'rpm -V'. This distinguishes expected updates from unauthorized modifications without relying on the outdated AIDE baseline.

Exam trap

The trap here is that candidates may think updating the AIDE database (Option B) is the logical next step to stop false alerts, but this would overwrite the baseline and eliminate the ability to detect the compromise, whereas the correct first action is to cross-verify with the package manager's own integrity database.

How to eliminate wrong answers

Option A is wrong because increasing AIDE verbosity only shows which attributes (e.g., permissions, size, hash) changed, but it does not help determine whether the changes are legitimate or malicious — it still compares against the same outdated database. Option B is wrong because updating the AIDE database with 'aide --update' would overwrite the old baseline with current file states, effectively accepting all changes as valid and destroying forensic evidence of potential compromise. Option D is wrong because restoring files from backup should only be done after confirming the changes are unauthorized; prematurely restoring could reintroduce vulnerabilities or overwrite evidence needed for investigation.

172
MCQeasy

A system administrator wants to deploy a containerized application on a Linux server with minimal overhead and without a daemon. Which container runtime should be used?

A.containerd
B.LXC
C.Docker
D.Podman
AnswerD

Podman runs containers rootless and daemonless, launching each container directly as a child process rather than through a persistent background service. This satisfies the stem's explicit no-daemon constraint while keeping overhead minimal, unlike Docker's dockerd. Its OCI-compatible tooling also mirrors familiar Docker commands, easing deployment.

Why this answer

Podman is the correct choice because it is a daemonless container engine that runs containers directly under the user's process space, using a fork-exec model rather than a background daemon. This aligns with the requirement for minimal overhead and no daemon, as Podman does not require a persistent service to manage containers.

Exam trap

The trap here is that candidates often associate 'container runtime' with Docker or containerd, but the question specifically tests the distinction between daemon-based and daemonless architectures, where Podman's fork-exec model is the key differentiator.

How to eliminate wrong answers

Option A is wrong because containerd is a container runtime that operates as a daemon (typically managed by systemd) and is designed to be used as a building block for higher-level tools, not as a standalone daemonless runtime. Option B is wrong because LXC (Linux Containers) is a system-level virtualization tool that creates full system containers with an init daemon, not a lightweight application container runtime, and it relies on a daemon (lxcfs or lxc-monitord) for management. Option C is wrong because Docker uses a client-server architecture with a persistent daemon (dockerd) that runs in the background, which contradicts the requirement for no daemon and adds overhead.

173
MCQeasy

A junior administrator needs to check whether a user account named 'bob' is locked and view the password aging information. Which command should be used?

A.passwd -S bob
B.usermod -L bob
C.chage -l bob
D.id bob
AnswerA

passwd -S displays the status of a user's password, including whether the account is locked (L), has no password (NP), or has a usable password (P), along with aging fields. This directly answers whether bob is locked and shows password aging details, making it the appropriate command for the administrator's check.

Why this answer

The passwd -S command reports the password status for a user, indicating locked, no password, or usable states, and includes aging data. This single command lets the administrator verify lock status and review password aging, which matches the scenario's need for inspection without modifying the account.

Exam trap

The trap here is choosing chage for lock status because it also deals with passwords, but chage shows aging only and never reports whether the account is locked.

174
MCQmedium

A Linux administrator is configuring sudo for a team of developers. The developers need to run commands as the user 'webadmin' without being prompted for a password, but only for commands located in /usr/local/bin. Which sudoers entry correctly implements this?

A.%developers ALL=(ALL) NOPASSWD: /usr/local/bin/*
B.%developers ALL=(webadmin) PASSWD: /usr/local/bin/*
C.%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/*
D.%developers ALL=(webadmin) NOPASSWD: /usr/local/bin/
AnswerC

This entry allows members of the developers group to run any command in /usr/local/bin as webadmin without a password. The wildcard * matches any command in that directory. It correctly restricts to that path and enforces NOPASSWD. This is the intended behavior.

Why this answer

The sudoers entry must specify the group, the target user (webadmin), the NOPASSWD tag, and the command path with a wildcard to allow all commands in /usr/local/bin. The correct syntax uses (webadmin) and NOPASSWD: followed by the path with /*. Other options either target the wrong user, use the wrong tag, or incorrectly specify a directory without a wildcard.

Exam trap

The trap here is using a trailing slash to indicate a directory in sudoers, which sudo treats as a literal command name, and confusing the target user specification with the runas user.

175
MCQhard

An administrator is troubleshooting a service that fails to start with a 'Permission denied' error. The administrator runs `strace -f -o /tmp/strace.log systemctl start myservice`. Which of the following best describes what this command achieves?

A.It records the kernel messages related to the service start.
B.It traces system calls for systemctl and its children, recording them to a file.
C.It monitors network connections opened by the service.
D.It traces library calls made by the service startup.
AnswerB

strace attaches to systemctl and, with -f, follows forked child processes, while -o writes the captured system calls to /tmp/strace.log. This reveals the exact syscall returning EACCES, pinpointing the permission failure without flooding the terminal.

Why this answer

strace traces system calls; -f follows child processes; -o writes output to file.

176
MCQhard

An administrator runs 'mount -a' and receives the error shown in the exhibit. The /home partition was recently removed and replaced with a new disk. Which of the following steps should the administrator take to resolve the issue?

A.Run 'mount /dev/sda3 /home' to mount the partition manually.
B.Run 'fsck /dev/sda3' to check the filesystem.
C.Run 'mkfs.ext4 /dev/sda3' to create a new filesystem.
D.Run 'blkid /dev/sda3' to find the new UUID and update /etc/fstab.
AnswerD

Replacing the disk changed the filesystem UUID, so the old UUID in /etc/fstab no longer resolves and mount -a fails. Running blkid /dev/sda3 retrieves the new UUID, which must then replace the stale entry in /etc/fstab.

Why this answer

The error occurs because the /home partition was replaced with a new disk, so its UUID (or device identifier) in /etc/fstab no longer matches the actual disk. Running 'blkid /dev/sda3' retrieves the new UUID, which must then be updated in /etc/fstab so that 'mount -a' can mount the correct device automatically.

Exam trap

The trap here is that candidates may assume the filesystem is damaged or needs reformatting (options B or C), when in fact the error stems from a stale UUID reference in /etc/fstab after disk replacement.

How to eliminate wrong answers

Option A is wrong because manually mounting with 'mount /dev/sda3 /home' would work temporarily but does not fix the underlying fstab misconfiguration, so the error would persist on reboot. Option B is wrong because 'fsck' checks and repairs filesystem integrity, but the error here is a missing or mismatched device identifier, not a corrupt filesystem. Option C is wrong because 'mkfs.ext4' creates a new filesystem, which would destroy existing data and is unnecessary if the filesystem is already intact; the problem is purely a UUID mismatch in fstab.

177
MCQeasy

A user runs a command and receives the error 'bash: myapp: command not found'. The administrator confirms the binary exists in /usr/local/bin. Which environment variable should be checked?

A.HOME
B.SHELL
C.LD_LIBRARY_PATH
D.PATH
AnswerD

PATH determines which directories the shell searches for executables, and /usr/local/bin must appear in it for the binary to be found. If that directory is missing from PATH, bash cannot locate myapp despite the file existing, producing the "command not found" error.

Why this answer

The 'command not found' error indicates that the shell cannot locate the executable in any of the directories listed in the PATH environment variable. Even though the binary exists in /usr/local/bin, if that directory is not in PATH, the shell will not find it. Checking and correcting the PATH variable to include /usr/local/bin will resolve the issue.

Exam trap

The trap is that candidates may think HOME is responsible for sourcing profile files, but the immediate cause of 'command not found' is usually a missing or incorrect PATH. The binary exists but the shell does not search in /usr/local/bin.

How to eliminate wrong answers

Option A (HOME) is incorrect because HOME specifies the user's home directory, not the search path for executables. Option B (SHELL) is incorrect because SHELL indicates the default shell program (e.g., /bin/bash), not the directory search order. Option C (LD_LIBRARY_PATH) is incorrect because it controls the search path for shared libraries at runtime, not for executable commands.

178
MCQmedium

A cron job runs a script that fails because the command 'myapp' is not found. The script works when run manually by the same user. What is the most likely cause?

A.The user does not have a home directory
B.The cron daemon is not running
C.The script has syntax errors
D.The PATH environment variable is different
AnswerD

Cron executes with a minimal environment, so PATH typically omits the directory containing myapp. The interactive shell's profile adds that path, which is why manual runs succeed while the scheduled job cannot resolve the binary.

Why this answer

When a cron job runs, it executes with a minimal environment, typically inheriting only a limited PATH (often just /usr/bin:/bin). The 'myapp' command is not found because its location (e.g., /usr/local/bin) is not in cron's PATH. When the same user runs the script manually, their interactive shell sources profile files (like .bash_profile or .bashrc) that set a more complete PATH, including the directory containing 'myapp'.

This discrepancy is the most common cause of such failures.

Exam trap

The trap here is that candidates may assume the script has a syntax error or that the cron daemon is failing, when the real issue is the stripped-down environment (especially PATH) that cron provides, which differs from the interactive shell environment.

How to eliminate wrong answers

Option A is wrong because a missing home directory would cause other issues (e.g., cron job output not being mailed, or environment variable failures), but it does not directly prevent command resolution; cron jobs can run without a home directory. Option B is wrong because if the cron daemon were not running, the job would not execute at all, not fail with a 'command not found' error. Option C is wrong because syntax errors would cause the script to fail regardless of whether it is run manually or by cron, and the script works when run manually, ruling out syntax issues.

179
MCQhard

A Linux server experiences intermittent network connectivity issues. The administrator suspects a duplex mismatch. Which tool can best confirm duplex and speed settings on a network interface?

A.mii-tool eth0
B.dmesg | grep eth0
C.ip link show eth0
D.ethtool eth0
AnswerD

ethtool queries the NIC driver directly, reporting the negotiated speed and duplex plus advertised and supported modes, which confirms a mismatch. Unlike ip or ifconfig, it exposes duplex settings, satisfying the requirement to verify speed and duplex on eth0.

Why this answer

`ethtool eth0` is the standard Linux utility for querying and controlling network interface driver and hardware settings, including negotiated speed and duplex mode. It directly displays the current link status, speed (e.g., 1000Mb/s), and duplex (full/half), making it the best tool to confirm a duplex mismatch.

Exam trap

The trap here is that candidates confuse `ip link show` (which shows link state but not speed/duplex) with `ethtool` (which provides the actual negotiated parameters), leading them to pick option C because they think 'ip' is the modern replacement for all interface queries.

How to eliminate wrong answers

Option A is wrong because `mii-tool` is a legacy utility for MII-capable interfaces and does not support modern Ethernet hardware (e.g., 1GbE or higher), often failing or returning inaccurate results on contemporary NICs. Option B is wrong because `dmesg | grep eth0` shows kernel ring buffer messages, which may include driver initialization logs but does not provide real-time, dynamic link speed or duplex information. Option C is wrong because `ip link show eth0` displays administrative and operational state (UP/DOWN) and basic flags, but it does not report negotiated speed or duplex settings; it lacks the detailed PHY-level information that `ethtool` provides.

180
MCQmedium

An administrator notices that a web application intermittently returns 'Connection timed out' to clients on the same subnet, while the server itself responds to pings. Packet captures show the server receiving SYN packets but never replying. The host firewall is suspected. Which command should the administrator use to inspect the active ruleset and its counters on a system using nftables?

A.ss -tlnp
B.nft list ruleset
C.iptables -L -n -v
D.tcpdump -i any port 80
AnswerB

On a system using nftables, nft list ruleset prints every table, chain, and rule in the current ruleset, including any counter expressions attached to rules. This lets the administrator see whether an input rule is dropping the SYN packets and confirm it via the counter values, directly matching the symptom of received-but-unanswered SYNs.

Why this answer

Because the server receives SYNs but never answers, filtering on inbound traffic is the leading hypothesis. On a native nftables host, listing the ruleset reveals both the rules and their counters, so the administrator can identify the offending drop or reject rule and confirm it is actually matching traffic. Compatibility tools may not reflect natively created rules.

Exam trap

The trap here is trusting iptables output on a host configured natively with nftables, where it may appear empty and falsely suggest no firewall rules exist.

181
MCQmedium

A system administrator notices that the /var partition is full, causing log services to malfunction. Which command should be used to quickly reclaim space by removing compressed old log files?

A.journalctl --vacuum-size=100M
B.find /var/log -type f -name '*.gz' -delete
C.rm -rf /var/log/*.gz
D.logrotate -f
AnswerB

The `find` command targets `/var/log`, filters with `-type f` and `-name '*.gz'` to match only compressed rotated logs, then `-delete` removes them in one pass. This directly reclaims space on the full `/var` partition without touching active uncompressed logs, satisfying the requirement to remove old compressed files quickly.

Why this answer

It uses `find` to locate all files ending in `.gz` under `/var/log` and deletes them with `-delete`. Compressed old log files are typically archived with gzip, so removing them directly reclaims disk space without affecting active logs or requiring additional tools.

Exam trap

The trap here is that candidates may choose `logrotate -f` thinking it cleans up old logs, but it actually triggers rotation and compression, which can fill the partition further instead of freeing space.

How to eliminate wrong answers

Option A is wrong because `journalctl --vacuum-size=100M` only affects the systemd journal logs, not compressed old log files in `/var/log`; it reduces journal size but does not remove `.gz` files. Option C is wrong because `rm -rf /var/log/*.gz` uses a glob pattern that may fail if the file list is too long (argument list overflow) and does not handle subdirectories recursively, unlike `find`. Option D is wrong because `logrotate -f` forces a log rotation cycle, which compresses or archives current logs but does not remove already compressed old log files; it may even create new compressed files, worsening the space issue.

182
MCQhard

A Linux system experiences high CPU usage from a process that appears to be a fork bomb. The administrator wants to prevent such attacks in the future by limiting the number of processes a user can create. Which configuration file should be modified, and what parameter should be set?

A.Set 'kernel.pid_max=100' in /etc/sysctl.conf
B.Set 'DefaultLimitNPROC=100' in /etc/systemd/system.conf
C.Add 'username hard nproc 100' in /etc/security/limits.conf
D.Add 'ulimit -u 100' to /etc/profile
AnswerC

The nproc limit in /etc/security/limits.conf caps processes per user via PAM, so a hard limit of 100 stops any single account exhausting the process table. This directly addresses the fork bomb constraint by preventing runaway process creation.

Why this answer

/etc/security/limits.conf is the PAM-based configuration file used to set per-user resource limits via the 'nproc' parameter. Adding 'username hard nproc 100' enforces a hard limit of 100 processes for that user, preventing a fork bomb from exhausting system resources.

Exam trap

CompTIA often tests the distinction between system-wide PID limits (kernel.pid_max) and per-user process limits (nproc), and candidates mistakenly choose A because they confuse maximum PID number with maximum number of processes.

How to eliminate wrong answers

Option A is wrong because 'kernel.pid_max' sets the maximum PID number, not a per-user process limit; it controls the total number of possible PIDs system-wide, not user-specific restrictions. Option B is wrong because 'DefaultLimitNPROC' in /etc/systemd/system.conf applies only to systemd-managed services, not to user login sessions or interactive shells, so it would not prevent a user-launched fork bomb. Option D is wrong because adding 'ulimit -u 100' to /etc/profile only affects interactive login shells and can be overridden by the user; it is not a persistent, system-wide enforcement mechanism.

183
MCQmedium

A team wants a shared directory /srv/project where members of the group devteam can create and edit files, but files created by one member must remain editable by other members. The directory is on an ext4 filesystem, and the team does not want to manually change group ownership on every new file. Which command set achieves this?

A.setfacl -R -m g:devteam:rwx /srv/project && setfacl -R -d -m g:devteam:rwx /srv/project
B.chown :devteam /srv/project && chmod 1777 /srv/project
C.chgrp devteam /srv/project && chmod 2775 /srv/project
D.chmod g+s /srv/project && chmod o+t /srv/project
AnswerC

Setting the group to devteam and applying mode 2775 sets the setgid bit on the directory. On ext4, new files and subdirectories inherit the directory's group, so files created by any devteam member stay group-owned by devteam. Combined with group write permission (the 7 in the group position includes write), members can edit each other's files without manual chgrp.

Why this answer

The setgid bit on a directory causes new entries to inherit the directory's group rather than the creator's primary group. Pairing that with group ownership of devteam and mode 2775 gives the group read, write, and execute on the directory, so members can create and modify files. This is the traditional Unix approach for shared group workspaces and works on ext4 without additional ACL configuration.

Exam trap

The trap here is confusing the sticky bit with the setgid bit; the sticky bit controls deletion in shared directories, while setgid controls group inheritance for new files.

184
Multi-Selectmedium

An administrator wants to monitor real-time system resource usage to identify performance bottlenecks. Which two commands are suitable? (Choose two.)

Select 2 answers
A.top
B.vmstat
C.iostat
D.htop
E.sar
AnswersA, D

top renders a continuously refreshing view of CPU, memory and per-process usage, letting an administrator spot resource-hungry processes in real time. This satisfies the requirement to monitor live system resource usage for identifying performance bottlenecks.

Why this answer

Option A (top) is correct because it provides a real-time, continuously refreshing view of CPU, memory, load average, and per-process resource consumption, making it ideal for spotting live performance bottlenecks. Option D (htop) is also correct since it is an interactive process viewer that displays the same real-time system metrics as top but with a more user-friendly interface, color-coded resource bars, and scrolling, which helps identify bottlenecks as they occur. Option B (vmstat) is not the best fit here because it typically reports virtual memory, CPU, and I/O statistics at sampled intervals rather than offering an interactive real-time monitoring view.

Option C (iostat) is excluded because it focuses on I/O device and CPU statistics, usually in periodic reports, not a live interactive resource monitor. Option E (sar) is also not appropriate because it is designed to collect and report historical system activity data, often for later analysis rather than real-time bottleneck identification.

185
MCQmedium

After using 'apt-get install' to install several packages, the administrator notices that disk space is low. Which command cleans up the package cache?

A.apt-get clean
B.apt-get purge
C.apt-get autoremove
D.apt-get remove
AnswerA

`apt-get clean` deletes every cached `.deb` archive from `/var/cache/apt/archives`, immediately reclaiming the disk space consumed by the packages just installed. This directly satisfies the low-disk constraint, unlike `autoremove`, which removes orphaned dependencies rather than cached package files.

Why this answer

The 'apt-get clean' command removes all package files (.deb) from the local cache located in /var/cache/apt/archives/. This frees up disk space without affecting installed packages, as the cache is only used for future installations or reinstallations. It is the correct command to clean up the package cache after installations.

Exam trap

A common mistake on the Linux+ exam is confusing 'autoremove' (which removes orphaned dependencies) with 'clean' (which clears the download cache).

How to eliminate wrong answers

Option B (apt-get purge) is wrong because it removes a package along with its configuration files, not the package cache. Option C (apt-get autoremove) is wrong because it removes packages that were automatically installed as dependencies and are no longer needed, but it does not clean the package cache. Option D (apt-get remove) is wrong because it removes a package but leaves its configuration files and does not touch the cached .deb files.

186
Multi-Selecthard

After configuring AppArmor, an administrator wants to verify the status of all profiles and switch a profile from complain to enforce mode. Which TWO commands are appropriate? (Choose two.)

Select 2 answers
A.systemctl restart apparmor
B.aa-status
C.apparmor_parser -r /etc/apparmor.d/profile
D.aa-complain /path/to/profile
E.aa-enforce /path/to/profile
AnswersB, E

`aa-status` reports every loaded AppArmor profile with its current mode, satisfying the requirement to verify all profiles' status. It lists profiles as enforcing, complaining or unconfined, giving the administrator the baseline needed before switching one profile into enforce mode.

Why this answer

Option B (aa-status) is correct because it is the standard AppArmor utility that reports the current state of all loaded profiles, showing how many are in enforce mode, complain mode, or unconfined, which directly satisfies the requirement to verify the status of all profiles. Option E (aa-enforce /path/to/profile) is correct because aa-enforce is the dedicated command that switches the specified profile into enforce mode, exactly matching the second task of moving a profile from complain to enforce. Option A (systemctl restart apparmor) only reloads the AppArmor service and does not report profile status or change an individual profile's mode.

Option C (apparmor_parser -r /etc/apparmor.d/profile) reloads a profile definition from disk but does not by itself toggle the profile between complain and enforce mode. Option D (aa-complain /path/to/profile) is the opposite of what is needed, since it sets a profile to complain mode rather than enforce mode.

Exam trap

The trap here is that candidates confuse `aa-complain` with `aa-enforce` or think that reloading a profile with `apparmor_parser` changes its mode, when in fact the mode is set separately via the `aa-*` utilities.

187
MCQeasy

In a Bash script, what is the purpose of the shebang '#!/bin/bash'?

A.It specifies the path to the Bash executable that should run the script.
B.It defines a variable for the Bash version.
C.It sets the script's permissions to executable.
D.It enables debug mode for the script.
AnswerA

The shebang's first line tells the kernel which interpreter binary executes the file, so `#!/bin/bash` names the absolute path to Bash. This satisfies the stem's requirement by ensuring the script runs under Bash rather than the invoking shell, regardless of the user's default login shell.

Why this answer

The shebang tells the system which interpreter to use to execute the script.

188
MCQeasy

A user wants to create a hard link named 'linkfile' to an existing file 'original'. Which command accomplishes this?

A.mv original linkfile
B.ln -s original linkfile
C.ln original linkfile
D.cp original linkfile
AnswerC

ln with two arguments creates a hard link by default, so 'ln original linkfile' makes linkfile an additional directory entry pointing to original's inode. This satisfies the requirement without the -s flag, which would create a symbolic link instead.

Why this answer

The ln command without -s creates a hard link. ln -s creates a symbolic link. cp copies the file; mv moves it.

189
Matchingmedium

Match each SELinux context component to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

SELinux user identity

Part of RBAC, defines allowed roles

Main attribute for type enforcement

Sensitivity level for MLS/MCS

Optional categories for MCS

Why these pairings

SELinux contexts are structured as user:role:type:level. The user identifies the SELinux user, role defines accessible types, type controls access, and level specifies sensitivity. Common confusions involve swapping user and type definitions.

190
MCQmedium

A security audit reveals that users can change their password without meeting complexity requirements. Which PAM module should be configured to enforce password complexity?

A.pam_faillock
B.pam_unix
C.pam_tally2
D.pam_pwquality
AnswerD

pam_pwquality enforces password complexity at change time by applying configurable rules such as minimum length, character classes and dictionary checks. Configuring it in the password stack ensures users cannot set weak passwords, directly satisfying the audit finding that complexity requirements are bypassed.

Why this answer

pam_pwquality is the PAM module that enforces password complexity requirements such as minimum length, character classes, and dictionary checks on Linux. It replaced the older pam_cracklib module and is configured in /etc/security/pwquality.conf and referenced in /etc/pam.d/system-auth or /etc/pam.d/common-password. Configuring it ensures users cannot set weak passwords that violate policy.

Exam trap

The trap is confusing lockout modules (pam_faillock, pam_tally2) with complexity modules (pam_pwquality) — candidates see 'password' in the module name and pick the wrong PAM component, missing that the question is about complexity, not failed-attempt lockout.

How to eliminate wrong answers

Option A is wrong because pam_faillock enforces account lockout after repeated failed authentication attempts — it is a brute-force mitigation, not a password complexity control. Option B is wrong because pam_unix handles the actual password change and authentication against /etc/shadow; it does not evaluate complexity rules on its own. Option C is wrong because pam_tally2 is a legacy lockout module (deprecated in favor of pam_faillock) that counts failed logins and locks accounts — again, not a complexity enforcer.

191
MCQmedium

A security analyst wants to ensure that users cannot change their password more than once every 7 days. Which command and option should be used to enforce this policy for user 'jsmith'?

A.usermod -e 7 jsmith
B.chage -m 7 jsmith
C.chage -M 7 jsmith
D.passwd -n 7 jsmith
AnswerB

`chage -m 7 jsmith` sets the minimum number of days between password changes to seven, directly enforcing the required restriction. The `-m` flag defines this minimum interval, so `jsmith` cannot alter the password again until seven days have elapsed, satisfying the stem's constraint precisely.

Why this answer

The `chage -m 7 jsmith` command sets the minimum number of days required between password changes for user jsmith to 7 days. The `-m` option of `chage` specifically controls the minimum password age, preventing the user from changing their password more than once every 7 days.

Exam trap

The trap here is confusing the `-m` (minimum days) and `-M` (maximum days) options of `chage`, as candidates often mix up which option controls the minimum interval between password changes versus the password expiration period.

How to eliminate wrong answers

Option A is wrong because `usermod -e` sets an account expiration date, not a minimum password age. Option C is wrong because `chage -M` sets the maximum password age (how long a password is valid), not the minimum interval between changes. Option D is wrong because `passwd -n` is not a valid option; the correct command to set minimum password age is `chage -m`, not `passwd`.

192
MCQhard

A Linux administrator is configuring a server that must meet strict security guidelines. The server uses firewalld and should drop all incoming traffic on the public zone by default, but allow outgoing SSH connections initiated by the server itself to a remote management host. Which firewalld configuration should the administrator apply?

A.Set the target of the public zone to DROP, and add a rich rule to allow outbound SSH to the remote host.
B.Set the target of the public zone to %%REJECT%%, and create a direct rule to allow outgoing SSH to the remote host.
C.Set the target of the public zone to DROP, and ensure the default outbound behavior allows SSH to the remote host.
D.Set the target of the public zone to DROP, and add a service rule for ssh to the public zone.
AnswerC

The public zone target DROP will silently discard all incoming traffic that does not match an allowed service or port, meeting the default drop requirement. Outgoing traffic is not filtered by firewalld zones; the default policy allows all outbound connections. Therefore, SSH connections initiated by the server to the remote host will be permitted without additional configuration. This satisfies both conditions.

Why this answer

The public zone target DROP ensures all incoming traffic is silently discarded unless explicitly allowed. Outgoing traffic is not filtered by firewalld zones, so SSH connections initiated by the server are allowed by default. Adding inbound service rules or using REJECT would violate the drop requirement or send rejection messages.

Exam trap

The trap here is thinking that firewalld zones filter outbound traffic; they only filter inbound traffic, so outgoing SSH requires no special rule.

193
MCQeasy

A system administrator notices that a critical application's process is consuming too much CPU, affecting other services. The administrator needs to reduce the CPU priority of that process without affecting its memory or other resources. The process PID is 4521. Which command should the administrator use?

A.renice -n 10 -p 4521
B.nice -n 10 -p 4521
C.renice -p 4521 10
D.chrt -p 10 4521
AnswerA

renice alters the scheduling priority of an already-running process, identified here by PID 4521, without touching its memory allocation or other resource limits. The -n 10 value lowers CPU scheduling priority, reducing contention with other services as the stem requires.

Why this answer

The `renice` command is used to change the priority of an already running process. By specifying `-n 10` and `-p 4521`, the administrator sets the nice value to 10, which lowers the CPU priority (higher nice value = lower priority) without affecting the process's memory or other resources. This directly addresses the need to reduce CPU consumption for the critical application.

Exam trap

The trap here is that candidates confuse `nice` (for starting processes) with `renice` (for adjusting running processes), or they misremember the correct argument order for `renice`, leading them to choose option B or C.

How to eliminate wrong answers

Option B is wrong because `nice` is used to start a new process with a specified priority, not to change the priority of an existing process; it does not accept a `-p` flag for PID. Option C is wrong because the syntax is incorrect: `renice` requires the priority value to come before the PID (e.g., `renice -n 10 -p 4521`), and placing the PID before the priority value will cause a syntax error or unintended behavior. Option D is wrong because `chrt` manipulates real-time scheduling attributes (policy and priority), not the nice value; using `-p 10` sets a real-time priority of 10, which could increase CPU priority rather than reduce it, and it does not adjust the nice value.

194
MCQeasy

A system administrator wants to schedule a script to run every Monday at 3 AM. Which cron entry is correct?

A.0 3 1 * * /path/to/script.sh
B.3 0 * * 1 /path/to/script.sh
C.0 3 * * 2 /path/to/script.sh
D.0 3 * * 1 /path/to/script.sh
AnswerD

The five fields map to minute, hour, day-of-month, month and day-of-week. Setting minute 0 and hour 3 satisfies the 3 AM requirement, while day-of-week 1 specifies Monday; the asterisks leave day-of-month and month unrestricted, so the script runs weekly on Mondays at exactly 03:00.

Why this answer

The cron syntax for 'at 3 AM every Monday' is minute 0, hour 3, day-of-month *, month *, and day-of-week 1 (where 0 and 7 both represent Sunday, and 1 represents Monday). This matches the required schedule exactly.

Exam trap

The trap here is confusing the day-of-week numbering (where Monday is 1) with the day-of-month field, and mixing up the minute and hour positions, leading candidates to select options that run on the wrong day or at the wrong time.

How to eliminate wrong answers

Option A is wrong because '0 3 1 * *' means 'at 3:00 AM on the 1st day of every month', not every Monday. Option B is wrong because '3 0 * * 1' means 'at 12:03 AM (0:03) every Monday', not 3:00 AM. Option C is wrong because '0 3 * * 2' means 'at 3:00 AM every Tuesday' (day-of-week 2), not Monday.

195
MCQmedium

A Linux administrator needs to run a Docker container in detached mode with port mapping from host port 8080 to container port 80, and mount a host directory /data to /app/data inside the container. Which command achieves this?

A.docker run -d -p 8080:80 -v /data:/app/data --name webapp nginx
B.docker run -it -p 8080:80 -v /data:/app/data --name webapp nginx
C.docker run -d -P -v /data:/app/data --name webapp nginx
D.docker start -d -p 8080:80 -v /data:/app/data webapp
AnswerA

The -d flag detaches the container, -p 8080:80 maps host port 8080 to container port 80, and -v /data:/app/data bind-mounts the host directory. Together these satisfy every stated constraint in a single command, using the nginx image.

Why this answer

Option A is correct because it uses `docker run -d` to start the container in detached mode (background), `-p 8080:80` to map host port 8080 to container port 80, and `-v /data:/app/data` to bind-mount the host directory `/data` to the container path `/app/data`. The `--name webapp` assigns a friendly name, and `nginx` specifies the image. This combination exactly matches all requirements.

Exam trap

The trap here is confusing `-p` (specific port mapping) with `-P` (publish all exposed ports to random host ports), and mixing up `docker run` with `docker start`; candidates may also overlook that `-it` is not detached mode.

How to eliminate wrong answers

Option B is wrong because it uses `-it` (interactive with TTY) instead of `-d`, which runs the container in the foreground and attaches the terminal, not detached mode. Option C is wrong because it uses `-P` (uppercase) which publishes all exposed ports to random host ports, not the specific mapping 8080:80; also it lacks the explicit `-p 8080:80` mapping. Option D is wrong because `docker start` is used to start an existing stopped container and does not accept `-p` or `-v` flags; those options are only valid with `docker run` at container creation time.

196
MCQmedium

Refer to the exhibit. A user reports that they cannot write to /data, receiving a 'No space left on device' error. However, the df output shows 5.2G available. What is the most likely cause?

A.The /data entry in fstab is incorrect, causing the mount to fail.
B.The partition is mounted read-only.
C.The filesystem is out of inodes.
D.The UUID for /data has changed.
AnswerC

df reports block usage, not inode consumption. A filesystem can have free blocks yet exhaust its inode table through many tiny files, so creating any new file fails with 'No space left on device' despite the 5.2G shown.

Why this answer

'No space left on device' despite df showing free space is the classic symptom of inode exhaustion. Each file and directory consumes an inode, and a filesystem can run out of inodes even when blocks (space) remain available. This commonly happens with directories containing millions of tiny files, such as mail queues, session files, or cache directories.

Exam trap

XK0-006 often tests the distinction between block exhaustion and inode exhaustion, so candidates who only check df (blocks) and not df -i (inodes) misdiagnose the problem as a mount or permission issue.

How to eliminate wrong answers

Option A is wrong because an incorrect fstab entry would prevent the mount entirely, and the user would not be able to access /data at all rather than getting a write error. Option B is wrong because a read-only mount produces 'Read-only file system' errors, not 'No space left on device.' Option D is wrong because a changed UUID would cause the mount to fail or mount the wrong device, not produce a space error on an already-mounted filesystem.

197
MCQeasy

A system administrator needs to create a new user account with a home directory and the bash shell. Which command should be used?

A.useradd -r -s /bin/bash user
B.useradd -c -s /bin/bash user
C.useradd -d /home/user -s /bin/bash user
D.useradd -m -s /bin/bash user
AnswerD

The -m flag creates the home directory, satisfying that requirement, while -s /bin/bash sets bash as the login shell. Plain useradd omits both by default, so combining these flags in one invocation produces the account exactly as specified.

Why this answer

The `-m` flag tells `useradd` to create the user's home directory if it does not already exist, and `-s /bin/bash` sets the login shell to bash. This meets the requirement of creating a new user with a home directory and the bash shell.

Exam trap

The trap here is that candidates often confuse the `-d` flag (which only sets the home directory path in `/etc/passwd`) with the `-m` flag (which actually creates the directory), leading them to choose option C instead of D.

How to eliminate wrong answers

Option A is wrong because the `-r` flag creates a system account (typically with a UID below 1000 and no home directory by default), which is not appropriate for a regular user needing a home directory. Option B is wrong because the `-c` flag is used to add a comment (e.g., full name) to the user account, not to create a home directory; it also lacks the `-m` flag. Option C is wrong because while `-d /home/user` specifies the home directory path, it does not actually create the directory; the `-m` flag is required to create it, and without it the home directory will not exist.

198
MCQhard

A technician needs to trace the system calls made by a running process to debug a performance issue. Which tool should be used?

A.gdb -p PID
B.lsof -p PID
C.ltrace -p PID
D.strace -p PID
AnswerD

strace attaches to the running process identified by PID via -p and reports each system call it makes, exposing blocking calls, file or socket waits and repeated retries. This directly targets the performance issue by revealing kernel-level activity of that process.

Why this answer

`strace -p PID` intercepts and records system calls (kernel-level operations like file I/O, network, and process control) made by a running process, which is exactly what is needed to trace system calls for debugging performance issues. The `-p` flag attaches strace to an existing process by its PID, allowing real-time monitoring of kernel interactions.

Exam trap

The trap here is that candidates confuse `ltrace` (library calls) with `strace` (system calls), as both trace function calls but at different layers of the operating system stack.

How to eliminate wrong answers

Option A is wrong because `gdb -p PID` is a debugger for inspecting and modifying program state at the source-code or assembly level, not for tracing system calls; it focuses on user-space debugging, not kernel call tracing. Option B is wrong because `lsof -p PID` lists open file descriptors (files, sockets, pipes) for a process, but it does not trace system calls or their timing; it provides a static snapshot of open handles, not dynamic call tracing. Option C is wrong because `ltrace -p PID` traces library calls (user-space function calls to shared libraries like glibc), not system calls; it intercepts calls to dynamically linked library functions, whereas the question specifically asks for system calls.

199
MCQhard

During a security audit, a Linux administrator finds that an unauthorized service is listening on TCP port 4444. The service is not managed by systemd. Which of the following commands should the administrator use to identify the process and disable it?

A.Run 'ss -tlnp | grep :4444' to find the PID, then use 'kill' to terminate the process.
B.Run 'fuser 4444/tcp' to find the PID and then use 'systemctl stop' to stop the service.
C.Run 'lsof -i :4444' to find the PID, then use 'systemctl disable' to disable the service.
D.Run 'systemctl status' to find the service name, then use 'systemctl stop' to stop it.
AnswerA

ss -tlnp maps the listening socket on port 4444 to its owning PID, which is essential because the process is not managed by systemd and cannot be stopped via systemctl. Killing that PID then terminates the unauthorised listener, satisfying the audit's identification and disablement requirement.

Why this answer

'ss -tlnp' lists TCP listening sockets with numeric addresses and the associated process PID. Piping the output through 'grep :4444' isolates the unauthorized service, and the PID can then be used with 'kill' to terminate the process. Since the service is not managed by systemd, systemctl commands are irrelevant, making 'kill' the appropriate method to stop the process.

Exam trap

The trap here is that candidates assume all services are managed by systemd and reach for 'systemctl stop' or 'systemctl disable', but the question explicitly states the service is not managed by systemd, so only process-level commands like 'kill' are valid.

How to eliminate wrong answers

Option B is wrong because 'fuser 4444/tcp' requires the port to be specified in a different syntax (e.g., 'fuser 4444/tcp' is invalid; the correct syntax is 'fuser 4444/tcp' but it returns a PID, not a service name, and then using 'systemctl stop' is incorrect because the service is not managed by systemd. Option C is wrong because while 'lsof -i :4444' can find the PID, 'systemctl disable' is used to prevent a systemd service from starting at boot, not to stop a running process, and it cannot disable a non-systemd service. Option D is wrong because 'systemctl status' requires a known service name and only works with systemd-managed services; the unauthorized service is not managed by systemd, so this command cannot identify it.

200
MCQeasy

A system administrator needs to ensure that the Apache HTTP server starts automatically at boot and is started immediately without rebooting. Which command accomplishes both tasks?

A.systemctl disable --now httpd
B.systemctl enable httpd
C.systemctl start httpd
D.systemctl enable --now httpd
AnswerD

`systemctl enable --now httpd` satisfies both constraints in one invocation: `enable` creates the systemd symlink so the unit starts at boot, while `--now` immediately activates it via `start`, avoiding a reboot. This combines persistence and immediate runtime state, unlike `enable` alone or `start` alone.

Why this answer

The `systemctl enable --now httpd` command combines two actions: it creates the necessary symlinks to start the Apache HTTP server automatically at boot (enable) and immediately starts the service without rebooting (start). The `--now` flag is the key to performing both tasks in a single command, fulfilling the requirement exactly.

Exam trap

The trap here is that candidates often think `systemctl enable` alone starts the service, or they confuse `--now` with a reboot requirement, leading them to pick option B or C instead of the combined D.

How to eliminate wrong answers

Option A is wrong because `systemctl disable --now httpd` stops the service and removes the boot-time symlinks, which is the opposite of what is needed. Option B is wrong because `systemctl enable httpd` only configures the service to start at boot but does not start it immediately; a separate `systemctl start` would be required. Option C is wrong because `systemctl start httpd` starts the service immediately but does not enable it for automatic startup at boot, so it would not survive a reboot.

201
MCQmedium

A technician notices that a user can execute a binary with elevated privileges even though the user is not in the sudoers file. The binary has the SUID bit set. Which command would remove the SUID bit from the binary?

A.chmod u-s /path/to/binary
B.chmod g-s /path/to/binary
C.chmod o-s /path/to/binary
D.chmod 0755 /path/to/binary
AnswerA

`chmod u-s /path/to/binary` clears only the owner's SUID bit, directly satisfying the stem's requirement to strip elevated execution rights from a binary whose owner lacks sudoers membership. The `u-s` symbolic mode targets the setuid permission on the user class, leaving group and other bits untouched.

Why this answer

`chmod u-s /path/to/binary` is the direct command to remove the SUID bit from the file. It unsets the setuid permission for the owner, which immediately prevents the binary from running with the owner's privileges. While `chmod 0755 /path/to/binary` also removes the SUID bit, it additionally resets all permission bits to a specific numeric mode (755), which may not be desired or necessary.

The question asks only for removing the SUID bit, so `chmod u-s` is the most precise and correct answer.

Exam trap

Candidates might think that using a numeric mode like 0755 is required because it 'resets permissions safely,' but the question specifically asks only to remove the SUID bit. Using `chmod u-s` accomplishes exactly that without altering other permissions. The exam expects the direct method, not an overhanded numeric reset.

How to eliminate wrong answers

Option A is wrong because `chmod u-s` correctly removes the SUID bit from the user (owner) — this is actually a valid command to remove the SUID bit, but the question asks for the command that would remove it, and while this works, the exam expects the numeric mode (0755) as the 'correct' answer because it is more explicit and also removes any other special bits like SGID or sticky bit. Option B is wrong because `chmod g-s` removes the SGID (setgid) bit, not the SUID bit; the SGID bit affects group privileges, not user-level elevation. Option C is wrong because `chmod o-s` attempts to remove the 'sticky bit' or other special bits for 'others', but the 's' permission for 'others' is not a standard Linux permission; this command would have no effect on the SUID bit and may produce an error or be ignored.

202
MCQmedium

An administrator needs to replace all occurrences of 'oldhost' with 'newhost' in the file /etc/hosts. Which sed command should be used?

A.sed -e 's/oldhost/newhost/' /etc/hosts
B.sed -n 's/oldhost/newhost/gp' /etc/hosts
C.sed 's/oldhost/newhost/' /etc/hosts
D.sed -i 's/oldhost/newhost/g' /etc/hosts
AnswerD

The `-i` flag edits /etc/hosts in place, satisfying the requirement to replace content within that file directly. The `g` suffix applies the substitution to every occurrence per line, not merely the first, matching "all occurrences". Without `g`, only the initial match on each line would change.

Why this answer

sed -i 's/oldhost/newhost/g' /etc/hosts performs an in-place substitution globally.

203
MCQeasy

A technician wants to find all files owned by user 'jane' in the /home directory. Which command accomplishes this?

A.grep -r jane /home
B.ls -lR /home | grep jane
C.locate jane /home
D.find /home -type f -user jane
AnswerD

The -user predicate filters by owner, -type f restricts matches to regular files, and /home scopes the search to the required directory. This combination returns exactly the files owned by jane, satisfying the stem's ownership constraint without listing directories.

Why this answer

The find command with -user option searches for files owned by a specific user.

204
MCQmedium

A system administrator is troubleshooting a network issue where a server cannot reach the internet. The server's IP address is 192.168.1.10/24, and the default gateway is 192.168.1.1. Which command should be used to verify the default gateway configuration?

A.ip neigh show
B.ip addr show
C.ip route show
D.ip link show
AnswerC

The server's routing table holds the default gateway entry, so 'ip route show' displays it directly, confirming whether 192.168.1.1 is configured as the default route for the 192.168.1.0/24 interface. This satisfies the requirement to verify gateway configuration rather than merely testing reachability.

Why this answer

The `ip route show` command displays the kernel's IPv4 routing table, which includes the default gateway entry (destination 0.0.0.0/0 via 192.168.1.1). This directly verifies whether the default gateway is configured correctly for the server to reach external networks.

Exam trap

The trap here is that candidates often confuse `ip addr show` (which shows IP addresses) with `ip route show` (which shows routing table), leading them to select the wrong command when asked to verify the default gateway.

How to eliminate wrong answers

Option A is wrong because `ip neigh show` displays the ARP cache (neighbor table), showing MAC-to-IP mappings for directly connected hosts, not the default gateway configuration. Option B is wrong because `ip addr show` displays IP addresses and interface properties, not routing information such as the default gateway. Option D is wrong because `ip link show` shows link-layer (Layer 2) interface status and MTU, not Layer 3 routing entries.

205
MCQmedium

A Linux administrator receives reports that a server becomes unresponsive for several seconds at a time. Running `uptime` shows a load average of 14.2 on a system with 4 CPU cores, and `vmstat 1` reports a steadily rising 'r' column with a 'wa' column near zero. Which command should the administrator run NEXT to identify which processes are consuming CPU time?

A.iostat -x 1
B.free -m
C.top -o %CPU
D.df -h
AnswerC

Running top sorted by CPU usage immediately surfaces the processes consuming the most processor time, which is exactly what a high run-queue count with negligible I/O wait points to. It refreshes live, so the administrator can watch the offending process and confirm whether a single runaway task or many busy tasks are driving the load average far above the four-core capacity.

Why this answer

A load average of 14.2 on four cores with a growing run queue and almost no I/O wait indicates CPU contention, not storage or memory pressure. The fastest way to attribute that contention is a live, CPU-sorted process view, which shows exactly which tasks are runnable and consuming cycles so the administrator can decide whether to renice, restart, or investigate further.

Exam trap

The trap here is assuming a high load average always means disk or memory trouble, when a large run queue with near-zero wait points squarely at CPU contention.

206
MCQeasy

In a Bash script, what is the correct way to check if a file named '/etc/passwd' exists and is a regular file?

A.if [ -r /etc/passwd ]
B.if [ -e /etc/passwd ]
C.if [ -s /etc/passwd ]
D.if [ -f /etc/passwd ]
AnswerD

The -f unary test operator returns true when the path exists and is a regular file, excluding directories and other special types. Used inside [ ], it satisfies the requirement to verify that /etc/passwd exists as a regular file.

Why this answer

The `-f` test operator in Bash returns true only if the path exists AND is a regular file (not a directory, device, or symlink to a non-regular file). This exactly matches the requirement to check that /etc/passwd exists and is a regular file.

Exam trap

The trap is assuming `-e` (exists) is sufficient when the question specifically asks for a regular file — candidates often pick `-e` because it 'checks existence'.

How to eliminate wrong answers

Option A is wrong because `-r` tests readability, not file type — a directory or device could be readable. Option B is wrong because `-e` only tests existence and returns true for directories, sockets, and devices. Option C is wrong because `-s` tests that the file exists and has a size greater than zero, which does not verify it is a regular file.

207
MCQhard

A Linux administrator is troubleshooting a systemd service that fails to start with the error 'Failed to start myservice.service: Unit myservice.service not found.' The service file exists at /etc/systemd/system/myservice.service and has correct permissions. Which command should the administrator run to resolve the issue?

A.systemctl reexec myservice.service
B.systemctl start myservice.service
C.systemctl enable myservice.service
D.systemctl daemon-reload
AnswerD

After creating or modifying a unit file, systemd must reload its configuration. The daemon-reload command rescans unit files and rebuilds the dependency tree, making the new service known to systemd. Without this, systemctl start will fail with 'Unit not found'.

Why this answer

When a new unit file is added to /etc/systemd/system/, systemd does not automatically detect it. The administrator must run 'systemctl daemon-reload' to reload the systemd manager configuration. This command scans for new or changed unit files and makes them available for starting and enabling.

Exam trap

The trap here is assuming that placing a unit file in the correct directory is sufficient, or confusing daemon-reload with daemon-reexec.

208
MCQeasy

Which command would a Linux administrator use to locate all files in the /var/log directory that have been modified within the last 7 days?

A.ls -lt /var/log | head -n 7
B.grep -mtime -7 /var/log
C.locate -mtime -7 /var/log
D.find /var/log -mtime -7
AnswerD

The -mtime -7 predicate matches files whose data was modified less than seven days ago, and find recurses through /var/log automatically. This directly satisfies the constraint of locating all files in that directory modified within the last 7 days.

Why this answer

The find command with -mtime -7 finds files modified less than 7 days ago. The other options are either incorrect or not suitable for this task.

209
MCQhard

A Linux administrator is writing a Bash script that processes a list of filenames stored one per line in a file. Some filenames contain spaces. The administrator wants the loop to treat each full line as a single item without word-splitting, and also wants to strip the trailing newline from each item. Which construct accomplishes this?

A.while read line; do process "$line"; done < filelist
B.while IFS= read -r line; do process $line; done < filelist
C.while IFS= read -r line; do process "$line"; done < filelist
D.for line in $(cat filelist); do process "$line"; done
AnswerC

Setting IFS= for the read command disables trimming of leading and trailing whitespace, and the -r flag prevents backslashes from being interpreted as escapes. read consumes one line at a time and strips the terminating newline, so filenames with embedded spaces stay intact and are passed quoted to process. This is the canonical safe line-reading loop.

Why this answer

Reading lines safely in Bash requires neutralizing both whitespace trimming and escape processing. IFS= preserves the line exactly, and -r stops backslashes from acting as escapes. Quoting the variable at every use prevents a second round of word splitting.

Only the construct that combines all three elements keeps filenames with spaces or special characters as single, unmodified arguments.

Exam trap

The trap here is fixing the read command but forgetting to quote the variable at the point of use, which re-splits the line anyway.

210
MCQeasy

An administrator wants to force a password change for user 'alice' on next login. Which command is appropriate?

A.passwd --expire alice
B.passwd -l alice
C.chage -l alice
D.usermod -f alice
AnswerA

`passwd --expire alice` immediately expires alice's password, forcing a change at her next login, which satisfies the stem's requirement. Unlike `chage -d 0`, it acts instantly without editing ageing fields, and it avoids locking the account outright, so alice can still authenticate and set a new password.

Why this answer

The `passwd --expire alice` command (equivalent to `passwd -e alice`) immediately expires alice's password by setting the shadow file's last-change date to 0, forcing a password change at her next login. This is the standard Linux mechanism for administrators to force a one-time password reset without disabling the account.

Exam trap

The trap here is confusing account lockout (`passwd -l`) with password expiry (`passwd -e`/`--expire`) — both touch /etc/shadow, but only one forces a change on next login while the other blocks access entirely.

How to eliminate wrong answers

Option B is wrong because `passwd -l alice` locks the account by prefixing the password hash with '!' in /etc/shadow, preventing login entirely rather than forcing a change. Option C is wrong because `chage -l alice` only lists the current password aging information for alice; it is a read-only query and makes no changes. Option D is wrong because `usermod -f alice` is syntactically invalid — the `-f` flag expects a numeric inactive-days value, not a username, and it controls account inactivity after password expiry, not immediate expiry.

211
MCQeasy

What does the `set -x` command do when placed at the top of a bash script?

A.Enables position parameters
B.Exits the script on error
C.Treats unset variables as errors
D.Displays each command before executing it
AnswerD

`set -x` enables the shell's trace mode, printing each command to standard error after expansion but before execution, prefixed with `+`. This satisfies the stem's requirement to reveal the actual expanded commands as the script runs, aiding debugging of variable substitution and quoting.

Why this answer

`set -x` enables a shell debugging mode that prints each command (after expansion) to stderr before executing it. This is commonly used in bash scripts to trace execution flow and debug complex logic.

Exam trap

The trap here is that candidates confuse `set -x` with `set -e` (exit on error) or `set -u` (treat unset variables as error), because all three are common debugging options but serve distinct purposes.

How to eliminate wrong answers

Option A is wrong because position parameters (like $1, $2) are enabled by default in bash scripts; `set -x` does not affect them. Option B is wrong because exiting on error is controlled by `set -e`, not `set -x`. Option C is wrong because treating unset variables as errors is controlled by `set -u`, not `set -x`.

212
MCQeasy

You are a Linux system administrator for a small company. You have written a BASH script that checks disk usage and sends an email alert if any partition exceeds 90% usage. The script works when run manually but does not produce alerts when run via cron. Which of the following is the most likely cause?

A.The cron job's PATH variable does not include the directory where the mail command is located
B.The script has incorrect file permissions
C.The cron scheduler is disabled
D.The script uses relative paths to check partitions
AnswerA

Cron runs with a minimal environment, so its PATH typically omits /usr/bin or /bin where mail resides. The script's manual success relies on your interactive PATH. Specifying the absolute path to mail, or exporting PATH within the script, resolves the missing-command failure.

Why this answer

When a script runs manually, it inherits the user's interactive shell environment, including the PATH variable that typically includes directories like /usr/bin and /usr/local/bin where the mail command resides. However, cron jobs execute in a minimal environment with a very restricted PATH (often just /usr/bin:/bin). If the mail command is located in a directory not in cron's default PATH, such as /usr/sbin or /opt/bin, the script will fail silently when attempting to send the email, even though the disk usage check itself succeeds.

This is the most common cause of scripts working manually but failing under cron.

Exam trap

CompTIA often tests the concept that cron jobs have a restricted environment, particularly PATH, and candidates mistakenly focus on script permissions or relative paths instead of the missing command path in cron's minimal shell.

How to eliminate wrong answers

Option B is wrong because incorrect file permissions would prevent the script from executing at all, whether run manually or via cron, and the question states the script works when run manually. Option C is wrong because if the cron scheduler were disabled, no cron jobs would run at all, but the question implies the script is scheduled and runs (it just doesn't produce alerts). Option D is wrong because using relative paths to check partitions would cause the script to fail regardless of whether it runs manually or via cron, unless the working directory is explicitly set; the script works manually, so relative paths are not the issue.

213
MCQmedium

A Linux administrator needs to grant the user 'alice' the ability to run all commands as root without being prompted for a password, but only from the host 'server1'. Which entry in /etc/sudoers accomplishes this?

A.alice server1=(root) NOPASSWD: /bin/bash
B.alice server1=(ALL) NOPASSWD: ALL
C.alice ALL=(server1) NOPASSWD: ALL
D.alice ALL=(ALL) NOPASSWD: server1
AnswerB

This sudoers entry allows alice to run any command as any user on the host server1 without a password. The host specification 'server1' restricts the rule to that host, and NOPASSWD: ALL removes the password prompt for all commands.

Why this answer

The sudoers file uses the format user host=(runas) command. To allow alice to run all commands as root without a password only on server1, the correct entry is 'alice server1=(ALL) NOPASSWD: ALL'. The host field restricts the rule to server1, and NOPASSWD: ALL removes the password requirement for all commands.

Exam trap

The trap here is mixing up the host and runas fields, or misplacing the NOPASSWD tag relative to the command list.

214
MCQhard

An administrator needs to monitor a service's log output and wants systemd to capture the output of a specific service unit into the journal, tagged so it can be filtered by the unit name. The administrator also wants to limit how much disk space the journal may consume so it does not fill the root filesystem. Which configuration accomplishes both goals?

A.Set RuntimeMaxUse in journald.conf and add StandardOutput=file:/var/log/report.log to the service unit
B.Set Storage=none in journald.conf and add StandardOutput=syslog to the service unit
C.Set MaxLevelStore in journald.conf and add StandardError=null to the service unit
D.Set SystemMaxUse in /etc/systemd/journald.conf and ensure the service logs to the journal via StandardOutput=journal in its unit file
AnswerD

journald collects service output when a unit uses StandardOutput=journal, and entries are tagged with the unit's identifier so journalctl -u can filter them. Setting SystemMaxUse in journald.conf caps the persistent journal's disk consumption, preventing it from filling the root filesystem. Together these satisfy both the tagging and size-limit requirements.

Why this answer

Capturing a service's output in the journal with unit tagging requires the unit to send output to the journal, and journald limits total disk usage through SystemMaxUse in journald.conf. Filtering by unit then works with journalctl -u. Disabling storage, redirecting output to files, or limiting only the runtime journal fails to both capture and cap the data as required.

Exam trap

The trap here is confusing runtime-only journal limits such as RuntimeMaxUse with persistent limits like SystemMaxUse, and assuming file redirection still populates the journal.

215
MCQmedium

A Linux administrator needs to verify which network interfaces are up and their IP addresses on a server. Which command provides this information?

A.ss -tlnp
B.nmcli dev show
C.ifconfig -a
D.ip addr
AnswerD

The ip addr command reads interface state and assigned addresses directly from the kernel, listing every interface with its UP/DOWN flag and IPv4/IPv6 addresses. It satisfies the requirement to verify which interfaces are up and their IPs.

Why this answer

The `ip addr` command displays all network interfaces along with their IP addresses, MAC addresses, and status (UP/DOWN).

216
MCQeasy

The script in the exhibit runs successfully but the administrator expects it to indicate success. What change should be made?

A.Replace $system_info with just system_info
B.Change 'exit 1' to 'exit 0'
C.Change the variable name to SYSTEM_INFO
D.Change 'exit 1' to 'exit 0' and remove the quotes around $system_info
AnswerB

Exit codes signal process outcome to the calling shell: zero denotes success, any non-zero value indicates failure. The script currently returns 1, so the administrator sees an error despite correct execution. Changing it to exit 0 satisfies the stem's requirement that the script indicate success.

Why this answer

The script uses 'exit 1' to terminate, which indicates a failure or error condition to the shell. The administrator expects the script to indicate success, so the exit code must be changed to 'exit 0', which is the standard Unix/Linux convention for successful execution. Exit codes are how scripts communicate their status to the calling process, and only exit 0 means success.

Exam trap

CompTIA often tests the fundamental distinction between exit codes 0 and 1, where candidates may mistakenly think that 'exit 1' is correct for a successful script or that variable naming or quoting affects the exit status.

How to eliminate wrong answers

Option A is wrong because removing the dollar sign from $system_info would treat it as a literal string instead of a variable reference, breaking the script's ability to use the stored value. Option C is wrong because changing the variable name to SYSTEM_INFO would not affect the exit code; variable names are case-sensitive but do not influence the script's success or failure status. Option D is wrong because while changing 'exit 1' to 'exit 0' is correct, removing the quotes around $system_info is unnecessary and could cause word splitting or globbing issues if the variable contains spaces or special characters, potentially breaking the script.

217
MCQeasy

An administrator needs to run a container using a specific user ID to match host file permissions. Which Docker option should be used when running the container?

A.-u 1001
B.-e USER=1001
C.-v /host:/container
D.--name mycontainer
AnswerA

The -u flag overrides the container's default user, running processes as UID 1001 so file ownership on the mounted host volume matches. This directly satisfies the requirement to align container identity with host file permissions, avoiding permission-denied errors when writing shared data.

Why this answer

The `-u` (or `--user`) option in Docker allows you to run the container process with a specific user ID (UID) instead of the default root (UID 0). By specifying `-u 1001`, the container's main process will run as UID 1001, which can be matched to a host user's UID to ensure proper file ownership and permissions when accessing mounted volumes. This is essential for avoiding permission denied errors when the container writes files to a bind-mounted host directory.

Exam trap

The trap here is that candidates often confuse environment variables (like `-e USER=1001`) with the actual user ID change, mistakenly thinking setting an environment variable named `USER` will alter the process's effective UID, when in reality only `-u` or the `USER` directive in a Dockerfile changes the runtime user.

How to eliminate wrong answers

Option B is wrong because `-e USER=1001` sets an environment variable named `USER` inside the container, which does not change the effective user ID of the container process; the process still runs as root unless another mechanism (like `USER` in the Dockerfile) is used. Option C is wrong because `-v /host:/container` is a volume mount that maps a host directory into the container, but it does not control the user ID under which the container runs; file permissions are still determined by the container's UID. Option D is wrong because `--name mycontainer` simply assigns a custom name to the container for identification and management purposes, and has no effect on the user ID or file permissions.

218
MCQeasy

A Linux administrator is writing a Bash script that accepts a filename as its first argument. The script should print an error and exit if the argument is missing. Which construct should the administrator use to reference the first positional parameter and test whether it is empty?

A.$0 with the -z test, as in [ -z "$0" ]
B.$1 with the -z test, as in [ -z "$1" ]
C.$# with the -z test, as in [ -z "$#" ]
D.$@ with the -z test, as in [ -z "$@" ]
AnswerB

The positional parameter $1 holds the first argument passed to the script. Wrapping it in double quotes preserves empty or whitespace-containing values, and the -z test returns true when the string length is zero, which correctly detects a missing argument and allows the script to print an error and exit.

Why this answer

The first positional parameter is referenced as $1, and quoting it preserves its value even when empty. The -z test evaluates to true for a zero-length string, so checking [ -z "$1" ] reliably detects a missing filename argument and lets the script print an error and exit before proceeding.

Exam trap

The trap here is mixing up the positional parameter variables, since $0 is the script name and $# is the argument count rather than the first argument.

219
Multi-Selecthard

An administrator needs to set up a new LVM volume. Which two commands are necessary in the initial setup before creating a logical volume?

Select 2 answers
A.mount
B.lvcreate
C.vgcreate
D.pvcreate
E.mkfs
AnswersC, D

vgcreate aggregates one or more initialised physical volumes into a volume group, the storage pool from which logical volumes are carved. It must run after pvcreate and before lvcreate, satisfying the setup sequence required before any logical volume can exist.

Why this answer

Before creating a logical volume (LV), you must first prepare the physical storage devices and then group them into a volume group. The `pvcreate` command initializes a block device (e.g., /dev/sdb) as a physical volume (PV) by writing LVM metadata to it. The `vgcreate` command then creates a volume group (VG) from one or more PVs, which serves as the pool of storage from which logical volumes are carved.

Without these two steps, the LVM subsystem has no recognized storage to allocate.

Exam trap

The trap here is that candidates often confuse the order of LVM commands, thinking `lvcreate` is the first step, but LVM requires a strict hierarchy: PV → VG → LV, and `pvcreate` and `vgcreate` must precede any logical volume creation.

220
MCQmedium

To limit the number of processes a user can create, which file should be configured?

A./etc/pam.d/login
B./etc/security/limits.conf
C./etc/ulimit.conf
D./etc/systemd/system.conf
AnswerB

/etc/security/limits.conf is read by pam_limits and defines per-user or per-group resource limits, including nproc, which caps the number of processes a user may create. This directly satisfies the requirement to limit process creation for a user.

Why this answer

The /etc/security/limits.conf file is used on Linux systems to set resource limits for users and groups, including the maximum number of processes (nproc). This file is read by PAM (Pluggable Authentication Modules) during login to apply ulimit settings. Configuring nproc there limits the number of processes a user can create.

Exam trap

The trap is confusing PAM configuration files with the actual limits configuration file, or assuming a non-existent /etc/ulimit.conf exists, leading candidates to choose incorrect paths.

How to eliminate wrong answers

Option A is wrong because /etc/pam.d/login configures PAM modules for the login service, not resource limits; it may include pam_limits.so but does not itself contain the limit values. Option C is wrong because /etc/ulimit.conf does not exist by default; ulimit settings are typically configured in /etc/security/limits.conf or shell profiles. Option D is wrong because /etc/systemd/system.conf configures systemd system-wide defaults, not per-user process limits; it does not control user process counts.

221
MCQmedium

A Linux administrator wants to allow the web server (httpd) to bind to a non-standard port, TCP 8080, without disabling SELinux. The system is running SELinux in enforcing mode. Which command should the administrator run to permanently allow httpd to listen on TCP port 8080?

A.semanage port -a -t http_port_t -p tcp 8080
B.semanage port -m -t http_port_t -p tcp 8080
C.chcon -t http_port_t /etc/httpd/conf/httpd.conf
D.setsebool -P httpd_can_network_connect 1
AnswerA

This command uses semanage to add TCP port 8080 to the http_port_t type, which is the SELinux type that httpd is allowed to bind to. The -a flag adds a new port definition, -t specifies the type, and -p specifies the protocol. This change is persistent across reboots and allows httpd to listen on port 8080 without disabling SELinux.

Why this answer

To allow httpd to listen on TCP port 8080 in enforcing mode, the port must be added to the http_port_t SELinux type using semanage port -a. This is persistent and does not require disabling SELinux. Modifying an existing port definition is only for reassigning a port that is already defined, and boolean or file context changes do not affect port bindings.

Exam trap

The trap here is confusing semanage port -a with -m; the -m option is for modifying an existing port assignment, not for adding a new one.

222
MCQhard

A security engineer must ensure that a new SSH host key is generated using the Ed25519 algorithm and stored in the default location. Which command accomplishes this?

A.ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key
B.ssh-keygen -A
C.ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519
D.ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key
AnswerA

This command generates an Ed25519 host key and writes it to the standard path /etc/ssh/ssh_host_ed25519_key, which sshd reads by default. The -t ed25519 selects the algorithm and -f sets the filename, matching the requirement for a default-location Ed25519 host key that the SSH daemon will automatically use.

Why this answer

Host keys are generated with ssh-keygen using -t to select the algorithm and -f to specify the output file. For an Ed25519 host key in the default location, the correct invocation is ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key. This ensures sshd will find and use the key without additional configuration.

Exam trap

The trap here is mixing up user authentication keys stored in ~/.ssh with host keys stored in /etc/ssh, or using -A which generates all algorithms rather than the requested one.

223
MCQeasy

A Linux administrator is tasked with adding a new 1TB hard drive to a server. The drive has been partitioned and formatted with ext4, resulting in the device /dev/sdb1. The administrator needs the drive to be mounted persistently at /data. After adding an entry to /etc/fstab, the administrator runs 'mount -a' and sees the error: 'mount: /data: mount point does not exist.' Which of the following should the administrator do first to resolve the issue?

A.Run mkfs.ext4 on /dev/sdb1
B.Reboot the server
C.Create the /data directory with mkdir
D.Run fsck on /dev/sdb1
AnswerC

The error states the mount point does not exist, so /data must exist before fstab can mount /dev/sdb1 there. Creating it with mkdir resolves the immediate failure; the fstab entry itself is already correct and needs no change.

Why this answer

The error 'mount point does not exist' indicates that the directory /data has not been created on the filesystem. The mount command requires an existing directory to attach the device to. Creating the /data directory with mkdir resolves this, allowing mount -a to succeed.

Exam trap

The trap here is that candidates may assume the mount point is automatically created by the system or that the error indicates a filesystem problem, leading them to choose fsck or reformatting instead of the simple directory creation step.

How to eliminate wrong answers

Option A is wrong because mkfs.ext4 would reformat the partition, destroying any existing filesystem and data, which is unnecessary since the drive is already formatted with ext4. Option B is wrong because rebooting will not create the missing mount point directory; it would only reattempt the same failing mount from /etc/fstab. Option D is wrong because fsck checks and repairs filesystem integrity, but the error is about a missing directory, not filesystem corruption.

224
MCQeasy

An administrator wants to schedule a script to run every Monday at 3 AM. Which crontab entry is correct?

A.0 3 * * 1 /path/to/script
B.* 3 * * 1 /path/to/script
C.0 3 * * * /path/to/script
D.0 3 1 * * /path/to/script
AnswerA

The five fields map to minute 0, hour 3, every day of month, every month, and day-of-week 1 (Monday), so the script runs weekly at 03:00. This satisfies the exact schedule constraint; alternatives misplace the weekday or hour fields.

Why this answer

The crontab syntax requires five fields: minute, hour, day of month, month, and day of week. '0 3 * * 1' means minute 0, hour 3 (3 AM), any day of month (*), any month (*), and day of week 1 (Monday). This precisely schedules the script to run at 3:00 AM every Monday.

Exam trap

CompTIA often tests the distinction between the minute field and the day-of-week field, trapping candidates who confuse the first field (minute) with the hour field, or who misinterpret the day-of-week field as the day-of-month field.

How to eliminate wrong answers

Option B is wrong because the first field is '*' instead of '0', which means the script would run every minute from 3:00 AM to 3:59 AM on Mondays, not just once at 3:00 AM. Option C is wrong because the day-of-week field is '*' (every day), so the script would run at 3:00 AM every day, not just Mondays. Option D is wrong because the third field is '1' (day of month), which schedules the script to run at 3:00 AM on the 1st day of every month, regardless of the day of week; the '1' in the day-of-week field is ignored because the day-of-month field is not '*'.

225
MCQmedium

A systems administrator needs to restrict SSH access to a Linux server so that only users in the 'sshusers' group can log in. Which configuration change should be made in /etc/ssh/sshd_config?

A.Add 'AllowUsers sshusers'
B.Add 'DenyGroups all'
C.Add 'AllowGroups sshusers'
D.Add 'PermitRootLogin no' and add users to sshusers
AnswerC

AllowGroups restricts authentication to members of the named group, so only users in sshusers can log in. Other accounts, including valid ones outside the group, are denied at the SSH layer, satisfying the restriction requirement.

Why this answer

The 'AllowGroups' directive in /etc/ssh/sshd_config restricts SSH login to only users who are members of the specified group. By adding 'AllowGroups sshusers', only users in the 'sshusers' group will be permitted to authenticate via SSH, while all others are denied. This is the standard OpenSSH mechanism for group-based access control.

Exam trap

The trap here is that candidates confuse 'AllowUsers' with 'AllowGroups', mistakenly thinking that 'AllowUsers sshusers' would restrict access to members of the 'sshusers' group, when in fact it only allows a user whose exact username is 'sshusers'.

How to eliminate wrong answers

Option A is wrong because 'AllowUsers' expects a list of individual usernames, not a group name; using 'AllowUsers sshusers' would attempt to match a user literally named 'sshusers', not a group. Option B is wrong because 'DenyGroups all' is not a valid directive; OpenSSH does not support a group named 'all', and even if it did, it would deny only that specific group, not all users. Option D is wrong because 'PermitRootLogin no' only prevents root from logging in via SSH, but does not restrict other users; adding users to 'sshusers' alone does not enforce group-based access without an 'AllowGroups' or 'DenyGroups' directive.

Page 2

Page 3 of 11

Page 4

All pages

CompTIA Linux+ (XK0-006) XK0-006 Questions 151–225 | Page 3/11 | Courseiva