Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 226–300

781 questions total · 11pages · All types, answers revealed

Page 3

Page 4 of 11

Page 5
226
MCQhard

After a system update, a server takes significantly longer to boot. The administrator wants to identify which systemd service is causing the delay. Which command provides a detailed analysis of boot time spent by each service?

A.systemd-analyze time
B.systemd-analyze blame
C.systemd-analyze critical-chain
D.systemd-analyze plot
AnswerB

`systemd-analyze blame` lists each unit's initialisation duration in descending order, directly exposing the service responsible for the slow boot. It satisfies the stem's requirement for a per-service breakdown of boot time, unlike `systemd-analyze time`, which reports only total firmware, loader and userspace durations.

Why this answer

The `systemd-analyze blame` command prints a list of all running systemd units, sorted by the time they took to initialize during boot. This directly answers the administrator's need to identify which specific service is causing the delay, as it shows the exact time spent by each service.

Exam trap

The trap here is that candidates confuse `systemd-analyze blame` with `systemd-analyze critical-chain`, mistakenly thinking the latter provides per-service timing, when in fact it only shows the dependency chain and not the individual time spent by each service.

How to eliminate wrong answers

Option A is wrong because `systemd-analyze time` only shows the total kernel, initrd, and userspace boot time, not a per-service breakdown. Option C is wrong because `systemd-analyze critical-chain` displays the critical boot chain (the tree of units that are critical for reaching the target), but it does not provide the detailed time spent by each service; it focuses on dependencies and bottlenecks in the chain. Option D is wrong because `systemd-analyze plot` generates an SVG graph of the boot timeline, which is useful for visual analysis but does not give a simple, sorted list of service times in the terminal.

227
MCQmedium

A system administrator needs to configure sudo so that members of the 'wheel' group can execute any command without a password. Which line should be added to /etc/sudoers (using visudo)?

A.%wheel ALL=(ALL) ALL
B.wheel ALL=(ALL) NOPASSWD: ALL
C.%wheel ALL=(ALL) NOPASSWD: ALL
D.%wheel ALL=NOPASSWD: ALL
AnswerC

The %wheel prefix denotes a group entry, ALL=(ALL) grants every command as any user, and NOPASSWD: ALL removes the password prompt. This line satisfies the requirement that wheel members run any command without a password.

Why this answer

To allow wheel group to run all commands without a password, the line should be '%wheel ALL=(ALL) NOPASSWD: ALL'.

228
MCQmedium

A developer wants to run a containerized application using Podman in a rootless environment. Which of the following is a key difference between Podman and Docker that the developer should be aware of?

A.Podman can run containers without a daemon
B.Podman requires a daemon to manage containers
C.Podman only supports rootful containers
D.Podman uses a different CLI syntax than Docker
AnswerA

Podman runs containers directly as child processes without a long-running daemon, which suits rootless operation because no privileged background service is needed. Docker relies on the dockerd daemon, typically requiring root or elevated privileges for container management.

Why this answer

Podman supports rootless containers natively without requiring a daemon, unlike Docker which traditionally requires a daemon (dockerd) running as root.

229
MCQhard

A security audit reveals that an SELinux boolean 'httpd_can_network_connect' is currently off, but a web application requires Apache to connect to a database server. Which command should the administrator use to enable this boolean persistently?

A.setenforce 1
B.setsebool httpd_can_network_connect 1
C.setsebool -P httpd_can_network_connect on
D.getsebool httpd_can_network_connect
AnswerC

The `-P` flag writes the change into the persistent SELinux policy, so `httpd_can_network_connect` stays enabled across reboots. Without it, `setsebool` only alters the running state, which the audit would flag again after restart. This satisfies the requirement for persistent enablement of Apache's outbound database connection.

Why this answer

The command 'setsebool -P httpd_can_network_connect on' is correct because setsebool modifies SELinux booleans at runtime, and the -P flag makes the change persistent across reboots by writing it to the policy store. This enables Apache to initiate network connections to the database server as required.

Exam trap

XK0-006 often tests the -P flag for persistence — candidates pick setsebool without -P and fail the 'persistently' requirement, or confuse setsebool with setenforce.

How to eliminate wrong answers

Option A is wrong because setenforce 1 sets SELinux to enforcing mode — it does not modify any boolean and would not enable httpd_can_network_connect. Option B is wrong because setsebool without -P only changes the boolean at runtime; the change is lost on reboot, so it is not persistent. Option D is wrong because getsebool only reads and displays the current value of a boolean — it does not change anything.

230
MCQmedium

A system administrator is troubleshooting a DNS resolution issue. The command `dig example.com` returns a response, but `ping example.com` fails with 'ping: example.com: Name or service not known'. Which of the following is the most likely cause?

A.An incorrect entry in /etc/hosts
B.The Name Service Cache Daemon (nscd) is not running
C.The system resolver is using different DNS servers than dig
D.The DNS server is not configured in /etc/resolv.conf
E.A firewall is blocking ICMP packets
AnswerC

dig uses resolver settings in /etc/resolv.conf but may use its own; inconsistent config can cause this.

Why this answer

The `dig` command bypasses the system resolver and queries the DNS server directly, so it can resolve the name even if the resolver is misconfigured. `ping` uses the system resolver (glibc's `gethostbyname` or `getaddrinfo`), which may be configured to use different DNS servers (e.g., via NetworkManager, systemd-resolved, or a local caching resolver). This mismatch causes `ping` to fail while `dig` succeeds.

Exam trap

CompTIA often tests the distinction between tools that use the system resolver (like `ping`, `ssh`, `curl`) and those that perform their own DNS resolution (like `dig`, `nslookup`, `host`), trapping candidates who assume all tools use the same resolution path.

How to eliminate wrong answers

Option A is wrong because an incorrect entry in /etc/hosts would affect both `dig` (which does not consult /etc/hosts) and `ping` (which does), but the symptom is that `dig` works and `ping` fails, so /etc/hosts is not the cause. Option B is wrong because nscd is a caching daemon; if it were not running, the system resolver would still work (just without caching), so it would not cause `ping` to fail while `dig` succeeds. Option D is wrong because if no DNS server were configured in /etc/resolv.conf, `dig` would also fail (it reads /etc/resolv.conf by default unless overridden), so this does not match the symptom.

Option E is wrong because a firewall blocking ICMP would cause `ping` to time out or show 'Destination Host Unreachable', not the specific error 'Name or service not known', which is a resolution failure, not a network reachability failure.

231
MCQmedium

A user reports that a web server is unreachable. The administrator runs 'curl -I https://example.com' and gets no response. Which command should be used next to check if the server is reachable at the network level?

A.ping -c 4 example.com
B.dig -x example.com
C.lsof -i :443
D.ss -tlnp | grep 443
AnswerA

ping -c 4 example.com sends four ICMP echo requests, testing IP-level reachability independently of HTTPS. Since curl returned nothing, this isolates whether the host responds at the network layer before investigating TLS, DNS resolution or the web service itself.

Why this answer

The `curl -I` command failed to get a response, which could be due to a network-level issue rather than an application-layer problem. The `ping` command uses ICMP echo requests to test basic IP-level connectivity to the host, bypassing higher-layer protocols like HTTP/TLS. If the server is unreachable at the network layer, `ping` will show packet loss or timeouts, confirming a routing or firewall issue.

Exam trap

The trap here is that candidates may choose `ss` or `lsof` because they are familiar with checking local services, but these commands cannot test remote reachability, which is the core of the question.

How to eliminate wrong answers

Option B is wrong because `dig -x example.com` performs a reverse DNS lookup, which checks if an IP address resolves to a hostname, not whether the server is reachable at the network level. Option C is wrong because `lsof -i :443` lists local processes listening on TCP port 443, which only checks if a service is running locally, not if the remote server is reachable. Option D is wrong because `ss -tlnp | grep 443` shows local TCP listening sockets on port 443, which is a local diagnostic tool and cannot verify network-level reachability to a remote host.

232
MCQeasy

Which command can be used to generate an SSH key pair for user authentication?

A.ssh-keyscan
B.ssh-keygen
C.ssh-copy-id
D.ssh-add
AnswerB

`ssh-keygen` generates an asymmetric key pair — a private key plus a matching public key — for public-key authentication, satisfying the stem's requirement to create an SSH key pair. It writes them to `~/.ssh/id_rsa` and `id_rsa.pub` by default, and the public half is then copied to the remote host's `authorized_keys`.

Why this answer

The `ssh-keygen` command is the standard tool for generating SSH key pairs (public and private keys) used for user authentication. It creates RSA, ECDSA, Ed25519, or DSA key files (e.g., `~/.ssh/id_rsa` and `~/.ssh/id_rsa.pub`) and supports options like `-t` for key type and `-b` for bit length, directly enabling passwordless login via public key authentication.

Exam trap

The trap here is that candidates confuse `ssh-keygen` (key generation) with `ssh-copy-id` (key deployment) or `ssh-add` (key loading), leading them to pick a command that manages existing keys rather than creating new ones.

How to eliminate wrong answers

Option A is wrong because `ssh-keyscan` is used to gather SSH public host keys from remote servers, not to generate user key pairs. Option C is wrong because `ssh-copy-id` installs an existing public key onto a remote server's `authorized_keys` file, but does not generate keys itself. Option D is wrong because `ssh-add` adds private key identities to the SSH authentication agent (`ssh-agent`), but it cannot create new key pairs.

233
MCQmedium

A technician needs to check which package provides the file /usr/bin/foo on a CentOS 8 system. Which command should be used?

A.rpm -qf /usr/bin/foo
B.rpm -V /usr/bin/foo
C.rpm -qi /usr/bin/foo
D.rpm -ql /usr/bin/foo
AnswerA

The rpm query-file option maps an installed file path back to the package that owns it, reading the local RPM database. On CentOS 8 this directly answers which package provides /usr/bin/foo, satisfying the stem's requirement without needing repository metadata.

Why this answer

On RPM-based systems, rpm -qf queries the package that owns a given file.

234
MCQmedium

A user reports being unable to log in because the password is locked. The administrator needs to unlock the account. Which command should be used?

A.usermod -L username
B.passwd -l username
C.passwd -u username
D.chage -E -1 username
AnswerC

`passwd -u username` unlocks a password-locked account by clearing the lock flag in `/etc/shadow`, directly satisfying the stem's requirement to unlock the account. The `-u` flag reverses a prior `passwd -l`, restoring the user's ability to authenticate with their existing password.

Why this answer

The passwd -u username command unlocks a previously locked user account by removing the leading '!' from the password hash in /etc/shadow. This is the direct counterpart to passwd -l, which locks the account by prepending '!' to the hash.

Exam trap

The trap is mixing up the -l (lock) and -u (unlock) flags on passwd, or confusing password locking with account expiration via chage -E.

How to eliminate wrong answers

Option A is wrong because usermod -L locks the account (same effect as passwd -l) rather than unlocking it — it prepends '!' to the password hash. Option B is wrong because passwd -l locks the account, which is the opposite of what the administrator needs. Option D is wrong because chage -E -1 sets the account expiration date to never expire; it does not remove a password lock, and if the account was locked via passwd -l, the '!' remains in /etc/shadow.

235
MCQmedium

A security policy mandates that user 'alice' must change her password every 60 days and must be warned 7 days before expiration. Which command should be used to enforce this?

A.passwd -x 60 -w 7 alice
B.chage -M 60 -W 7 alice
C.chage -m 60 -I 7 alice
D.usermod -e 2025-01-01 -f 7 alice
AnswerB

chage -M sets the maximum number of days before a password change is required, and -W sets the number of days of warning before expiration. This directly enforces the 60-day maximum and 7-day warning period for the user alice, satisfying the policy.

Why this answer

The chage command directly manipulates the password aging fields in /etc/shadow. Using -M 60 enforces the maximum days a password is valid, and -W 7 provides a warning to the user seven days before expiration. This is the correct and portable method to comply with the stated security policy.

Exam trap

The trap here is confusing the -m (minimum days) and -M (maximum days) options of chage, or assuming passwd supports the same aging flags on all distributions.

236
Multi-Selecthard

A Linux administrator is troubleshooting a service that fails to start. Which THREE files or commands should be checked to diagnose the issue? (Select THREE.)

Select 3 answers
A.dmesg
B.journalctl -u service-name
C./var/log/messages (or /var/log/syslog)
D./etc/rc.local
E.systemctl status service-name
AnswersB, C, E

journalctl -u service-name queries the systemd journal filtered to that unit, exposing the exact exit code, dependency failure or error message recorded at start time. This directly satisfies the stem's need to diagnose why the service fails, giving the most specific per-unit evidence available.

Why this answer

Option B, journalctl -u service-name, is correct because it queries the systemd journal specifically for the unit's log messages, showing startup errors, exit codes, and dependency failures for that service. Option C, /var/log/messages (or /var/log/syslog), is correct because these traditional syslog files capture daemon and service messages on many distributions, providing historical context when the journal is not persistent. Option E, systemctl status service-name, is correct because it reports the unit's current state, loaded configuration, main PID, exit code, and recent log lines, immediately revealing why the service failed.

Option A, dmesg, is not among the marked answers because it primarily shows kernel ring buffer messages and is less useful for user-space service startup failures. Option D, /etc/rc.local, is not marked because it is a legacy SysV init compatibility script and is not a diagnostic tool for systemd service failures.

Exam trap

CompTIA often tests the distinction between kernel-level logs (dmesg) and service-level logs (journalctl), and the trap here is that candidates may confuse `dmesg` with service troubleshooting because it shows boot-time messages, but it does not capture service-specific failures.

237
MCQmedium

Which command would display the disk usage of each file and directory in /home in a human-readable format, but only showing one level deep?

A.du -h --max-depth=1 /home
B.du -hs /home
C.du -h /home
D.df -h /home
AnswerA

`du -h --max-depth=1 /home` satisfies both constraints: `-h` converts block counts to human-readable units (K, M, G), while `--max-depth=1` limits recursion to the immediate children of /home, excluding deeper subdirectories. This matches the requirement for per-file and per-directory usage at exactly one level.

Why this answer

du -h --max-depth=1 /home shows human-readable sizes for each item one level deep.

238
MCQeasy

A Linux administrator needs to view the contents of a compressed log file without decompressing it. Which command should be used?

A.zcat
B.cat
C.bzcat
D.gunzip
AnswerA

zcat streams the contents of gzip-compressed files straight to standard output, decompressing on the fly in memory. This satisfies the requirement to read the log without first running gunzip and creating an uncompressed copy on disk.

Why this answer

zcat is the correct command because it decompresses and displays the contents of files compressed with gzip (or compress) to standard output without creating a decompressed file on disk. This allows viewing compressed logs directly, which is essential for troubleshooting without modifying the original file. It is functionally equivalent to 'gzip -dc' or 'gunzip -c'.

Exam trap

The trap here is confusing zcat with other decompression tools like bzcat or gunzip, or assuming cat can display compressed data. Candidates must remember that zcat is specifically for gzip-compressed files and does not create a decompressed file on disk.

How to eliminate wrong answers

Option B is wrong because cat simply outputs the raw compressed binary data, which appears as unreadable garbage. Option C is wrong because bzcat is used for bzip2-compressed files, not gzip-compressed files; using it on a gzip file would produce an error or garbage. Option D is wrong because gunzip decompresses the file and replaces the compressed file with an uncompressed one on disk, which is not viewing without decompressing.

239
Multi-Selecteasy

A Linux administrator is writing a systemd service unit file. Which three of the following directives are valid in the [Service] section? (Select THREE.)

Select 3 answers
A.Restart
B.After
C.Requires
D.User
E.ExecStart
AnswersA, D, E

Restart is a valid [Service] directive controlling whether systemd restarts the unit after exit, with values such as always, on-failure or no. It belongs in the [Service] section alongside ExecStart and User, unlike [Unit] or [Install] directives.

Why this answer

Option A, Restart, is valid in the [Service] section and controls whether and how systemd restarts the service after it exits (e.g., Restart=on-failure). Option D, User, is valid in the [Service] section and specifies the UNIX user account under which the service process is executed. Option E, ExecStart, is valid in the [Service] section and defines the command line that systemd runs to start the service.

Options B (After) and C (Requires) are not valid in [Service]; they are dependency/ordering directives that belong in the [Unit] section of the unit file.

Exam trap

CompTIA often tests the distinction between `[Unit]` and `[Service]` section directives, and the trap here is that candidates mistakenly apply dependency or ordering directives like `After` or `Requires` to the `[Service]` section, when they are only valid in `[Unit]`.

240
MCQeasy

A Linux administrator receives reports that a server's root filesystem is completely full. They run `df -h` and see that the root partition is at 100% usage. Which command should they use NEXT to identify which directories are consuming the most space?

A.du -sh /* | sort -h
B.fdisk -l
C.find / -type f -size +1G
D.ls -la /
AnswerA

The `du -sh /*` command calculates the total disk usage of each top-level directory and displays it in human-readable format, while `sort -h` orders the results by size. This directly identifies which directories are consuming the most space, allowing the administrator to drill down further. It is the most efficient next step for locating large directories on a full filesystem.

Why this answer

When a filesystem is full, the administrator must first identify which directories are consuming the most space. The `du` command with the `-s` and `-h` options provides a summary of disk usage per directory, and piping to `sort -h` orders the results by size. This quickly highlights the largest directories, enabling efficient troubleshooting.

Exam trap

The trap here is confusing disk usage reporting tools: `df` shows filesystem-level usage, while `du` shows directory-level usage, and only `du` can pinpoint the directories consuming space.

241
MCQeasy

Which command displays the current default umask value for a user?

A.chmod
B.set
C.umask
D.ls -l
AnswerC

Running `umask` with no arguments prints the current file-mode creation mask for the invoking shell, expressed in octal (for example 0022). This directly satisfies the stem's requirement to display the default umask value, since the command reads and reports the setting without modifying it.

Why this answer

The umask command, when run without arguments, prints the current file-mode creation mask for the shell session. This mask determines which permission bits are removed from newly created files and directories.

Exam trap

XK0-006 often tests the distinction between commands that modify permissions (chmod) and commands that display or set the default creation mask (umask) — candidates confuse viewing permissions with viewing the umask.

How to eliminate wrong answers

Option A is wrong because chmod changes permissions on existing files; it does not display the umask. Option B is wrong because set (or set -o) displays shell options and positional parameters, not the umask. Option D is wrong because ls -l lists file details including permissions, but it does not show the umask value.

242
Matchingmedium

Match each Linux runlevel to its standard systemd target.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

poweroff.target

rescue.target

multi-user.target

graphical.target

reboot.target

Why these pairings

Systemd targets align with traditional SysV runlevels: runlevel 0 → poweroff.target, runlevel 1 → rescue.target, runlevel 2/3/4 → multi-user.target, runlevel 5 → graphical.target, runlevel 6 → reboot.target. Common confusions involve mixing up GUI and non-GUI targets or confusing runlevels for shutdown/reboot.

243
MCQmedium

A Linux administrator is troubleshooting a server that cannot resolve hostnames. The administrator suspects a misconfiguration in the DNS resolver. Which file should be checked first to verify the DNS server addresses?

A./etc/nsswitch.conf
B./etc/hosts
C./etc/resolv.conf
D./etc/sysconfig/network-scripts/ifcfg-eth0
AnswerC

/etc/resolv.conf lists the DNS servers (nameservers) that the system queries for hostname resolution. It is the primary configuration file for the resolver. Checking this file verifies which DNS servers are configured and if they are reachable. A missing or incorrect nameserver entry here would directly cause hostname resolution failures.

Why this answer

/etc/resolv.conf is the standard file for configuring DNS resolvers on Linux. It contains nameserver entries that specify the IP addresses of DNS servers. Checking this file directly verifies the DNS server addresses in use.

Other files may influence resolution but do not store the DNS server addresses themselves.

Exam trap

The trap here is assuming that DNS server addresses are stored in interface configuration files, but on most modern systems, /etc/resolv.conf is the authoritative resolver configuration file.

244
MCQeasy

A security policy requires that user home directories have permissions set so that only the owner has access. A new user 'john' has a home directory with permissions 755. Which command should the administrator run to enforce the policy?

A.chmod 711 /home/john
B.chmod 700 /home/john
C.chmod 770 /home/john
D.chmod 750 /home/john
AnswerB

chmod 700 strips group and other permissions, leaving read, write and execute for the owner alone. The 755 setting currently grants group and world read/execute access, violating the policy's owner-only requirement, so 700 enforces it precisely.

Why this answer

The security policy requires that only the owner has access to the home directory. The current permissions 755 grant read and execute access to the group and others. The chmod 700 command sets permissions to rwx------, which gives the owner full access and removes all permissions for the group and others, enforcing the policy.

Exam trap

CompTIA often tests the difference between 700 and 750, where candidates mistakenly think group read access is acceptable, but the policy explicitly requires 'only the owner has access', meaning no group or other permissions at all.

How to eliminate wrong answers

Option A is wrong because chmod 711 sets permissions to rwx--x--x, which still allows group and others to execute (and read for the owner), violating the policy that only the owner has access. Option C is wrong because chmod 770 sets permissions to rwxrwx---, which grants full access to the group, violating the policy. Option D is wrong because chmod 750 sets permissions to rwxr-x---, which gives read and execute access to the group, violating the policy.

245
Multi-Selectmedium

A Linux administrator is hardening a server that runs a custom application. The security team requires that the system enforce password complexity and account lockout policies. The administrator decides to use PAM. Which TWO modules should be added to the appropriate PAM configuration files to enforce these requirements? (Choose two.)

Select 2 answers
A.pam_unix.so
B.pam_faillock.so
C.pam_tally2.so
D.pam_limits.so
E.pam_pwquality.so
AnswersB, E

pam_faillock.so provides account lockout after a specified number of failed authentication attempts. It is configured in the auth and account stacks of PAM configuration files, such as /etc/pam.d/system-auth and /etc/pam.d/password-auth. This module satisfies the account lockout requirement and is the current standard on Red Hat and similar distributions.

Why this answer

To enforce password complexity, pam_pwquality.so is the standard module, checking password strength against configured criteria. For account lockout, pam_faillock.so is the modern replacement for pam_tally2.so, tracking failed attempts and locking accounts after a threshold. Together, they meet the security team's requirements when placed in the correct PAM stacks.

Exam trap

The trap here is selecting the deprecated pam_tally2.so for lockout instead of the current pam_faillock.so, which is now the recommended module on modern Linux distributions.

246
MCQmedium

A Linux administrator notices that the /home directory is running low on space. They need to identify which user directories are consuming the most disk space. Which command will display the total disk usage of each immediate subdirectory under /home, in human-readable format, sorted by size?

A.du -sh /home/* | sort -h
B.ls -lS /home
C.df -h /home
D.find /home -type f -size +100M
AnswerA

The du command estimates file space usage. The -s flag summarizes each argument (here, each subdirectory via the glob), and -h prints sizes in human-readable units. Piping to sort -h orders the output numerically by human-readable size, so the largest directories appear last. This directly answers the need to find which user directories consume the most space.

Why this answer

The du command with -s and -h summarizes each specified directory in human-readable units; using a glob for immediate subdirectories and piping to sort -h orders them by size. This gives a clear ranking of which user directories consume the most space, directly addressing the low-space issue. Other tools either report filesystem-level totals or list files without per-directory aggregation.

Exam trap

The trap here is confusing filesystem-level usage reported by df with per-directory usage reported by du, or assuming ls -l shows recursive directory sizes.

247
MCQmedium

A Linux administrator needs to configure a system to automatically mount an NFS share at /mnt/data during boot. The NFS server is 192.168.1.100 exporting /export/data. Which file should the administrator edit to add the appropriate entry?

A./etc/nfs.conf
B./etc/fstab
C./etc/mtab
D./etc/exports
AnswerB

The /etc/fstab file is the standard configuration file for static filesystem mounts, including network filesystems like NFS. Adding an entry such as '192.168.1.100:/export/data /mnt/data nfs defaults 0 0' ensures the share is mounted automatically at boot. The systemd mount units generated from fstab handle the actual mounting, making this the correct and persistent method.

Why this answer

To ensure an NFS share is mounted automatically at boot, the administrator must add an entry to /etc/fstab. This file contains static filesystem information that systemd uses to generate mount units. The entry includes the server export, local mount point, filesystem type, and options.

Other files like /etc/mtab or /etc/nfs.conf serve different purposes and do not control persistent mounts.

Exam trap

The trap here is confusing client-side mount configuration with server-side export configuration, leading to editing /etc/exports instead of /etc/fstab.

248
MCQeasy

A technician needs to troubleshoot a system that is not booting. Which of the following is the most appropriate first step when using a rescue environment?

A.Mount the root filesystem to /mnt/sysimage.
B.Check the system logs in /var/log/messages.
C.Run fsck on all partitions.
D.Reinstall the bootloader immediately.
AnswerA

Mounting the root filesystem to /mnt/sysimage exposes the installed system's files, configuration and logs to the rescue environment, enabling chroot-based repair. This is the standard first step before diagnosing boot failures such as damaged bootloaders or misconfigured fstab entries.

Why this answer

When using a rescue environment, the first priority is to gain access to the system's configuration and log files by mounting the root filesystem. Mounting to /mnt/sysimage (a conventional mount point in Red Hat-based rescue modes) allows the technician to chroot into the environment and treat it as the running system, enabling further troubleshooting steps like checking logs or repairing the bootloader. This step is foundational because without the root filesystem mounted, commands like checking logs or running fsck cannot operate on the actual system data.

Exam trap

The trap here is that candidates often jump to checking logs or running fsck first, not realizing that without mounting the root filesystem, those actions are either impossible or operate on the rescue environment's own filesystem rather than the broken system's data.

How to eliminate wrong answers

Option B is wrong because checking system logs in /var/log/messages requires the root filesystem to be mounted first; without mounting, the logs are inaccessible from the rescue environment. Option C is wrong because running fsck on all partitions prematurely can cause data corruption if filesystems are already mounted or if the root filesystem is not yet accessible; fsck should be run after mounting and only on unmounted or read-only partitions as needed. Option D is wrong because reinstalling the bootloader immediately is a drastic step that should only be taken after diagnosing the actual cause of the boot failure, such as a corrupted bootloader configuration or missing kernel; doing so without mounting the root filesystem may overwrite critical boot data without understanding the underlying issue.

249
MCQeasy

Which directory in the Filesystem Hierarchy Standard (FHS) contains variable data such as logs and spool files?

A./opt
B./etc
C./var
D./tmp
AnswerC

/var holds variable data that changes during normal operation, including system logs under /var/log and print spool files under /var/spool. This directly satisfies the stem's requirement for the FHS directory designated for variable data, distinguishing it from static directories such as /usr and /etc.

Why this answer

/var is the correct directory because the Filesystem Hierarchy Standard (FHS) designates /var for variable data files that are expected to change in size and content as the system runs, such as logs, spool files, and temporary files. This includes /var/log for system logs and /var/spool for print and mail queues. It is distinct from static data like binaries or configuration.

Exam trap

The trap is confusing /var with /tmp or /etc. Candidates might think logs are in /tmp because they are temporary, but /tmp is for short-lived files, while /var is for persistent variable data. Also, /etc is for configuration, not logs.

How to eliminate wrong answers

Option A is wrong because /opt is for optional application software packages, not variable data. Option B is wrong because /etc is for host-specific system configuration files, which are typically static. Option D is wrong because /tmp is for temporary files that may be cleared on reboot, not for persistent variable data like logs.

250
MCQmedium

A Linux administrator needs to schedule a maintenance script to run every Monday at 03:15 on a systemd-based server. The script must persist across reboots and must not depend on a user being logged in. Which of the following is the BEST approach?

A.Add the entry to /etc/crontab using the root user field, then run systemctl restart crond.
B.Place a script in /etc/profile.d/ that invokes the maintenance command, ensuring it runs for every user session.
C.Create a systemd timer unit with OnCalendar=Mon 03:15:00 and a matching service unit, then enable the timer with systemctl enable --now.
D.Create an at job with at 03:15 Mon and save it with atq so it repeats weekly.
AnswerC

A systemd timer paired with a service unit is the native scheduling mechanism on systemd-based distributions. The OnCalendar directive accepts calendar expressions such as Mon 03:15:00, and enabling the timer with systemctl enable --now ensures it starts immediately and persists across reboots without requiring an interactive login session.

Why this answer

Systemd timers are the modern, native scheduling mechanism on systemd-based Linux distributions. Pairing a timer unit that defines OnCalendar=Mon 03:15:00 with a service unit that runs the script, then enabling the timer, satisfies the requirement for a recurring, reboot-persistent job that runs without any logged-in user. This approach is more robust than legacy cron or one-shot at jobs.

Exam trap

The trap here is assuming that cron is always available and preferred on systemd-based systems, when native timer units are the more reliable and integrated choice.

251
Multi-Selectmedium

A Linux administrator is configuring a new server and needs to ensure that the SSH service starts automatically at boot and that the firewall allows SSH connections. The system uses systemd and firewalld. Which two commands should the administrator run? (Choose two.)

Select 2 answers
A.systemctl start sshd
B.firewall-cmd --permanent --add-service=ssh
C.firewall-cmd --reload
D.systemctl enable sshd
E.systemctl mask sshd
AnswersB, D

firewall-cmd with --permanent and --add-service=ssh adds the SSH service to the permanent firewall configuration, allowing incoming connections on port 22. The --permanent flag ensures the rule survives a reload or reboot. After running this, a firewall-cmd --reload is needed to apply the change immediately, but the command itself is correct for enabling SSH access.

Why this answer

To ensure SSH starts at boot, the service must be enabled with systemctl enable. To allow SSH through firewalld, the SSH service must be added permanently with firewall-cmd --permanent --add-service=ssh. Together, these two commands satisfy both the startup and firewall requirements.

Starting the service without enabling it would not survive a reboot, and reloading the firewall without adding the rule would not open the port.

Exam trap

The trap here is confusing starting a service with enabling it, and forgetting that firewalld requires a permanent rule addition before reload.

252
Multi-Selectmedium

Which THREE are best practices for securing a Linux server? (Choose exactly three.)

Select 3 answers
A.Use a host-based firewall
B.Keep software up to date
C.Enable root SSH login with password
D.Disable unnecessary services
E.Set default umask to 0777
AnswersA, B, D

A host-based firewall filters inbound and outbound traffic per server, restricting which ports and services are reachable. This reduces the attack surface of the Linux host itself, satisfying the hardening requirement by blocking unnecessary network access even when other controls fail.

Why this answer

Option A (Use a host-based firewall) is correct because tools like iptables/nftables or firewalld enforce least-privilege network access at the host level, blocking unneeded inbound ports even if a service is accidentally exposed. Option B (Keep software up to date) is correct because patching via the distribution's package manager (e.g., apt, dnf, yum) closes known CVEs in the kernel, libraries, and daemons that attackers actively exploit. Option D (Disable unnecessary services) is correct because every running daemon (e.g., telnet, rsh, unused web servers) expands the attack surface, so stopping and disabling them with systemctl reduces exploitable entry points.

Option C is wrong because enabling root SSH login with a password invites brute-force and credential-stuffing attacks; best practice is PermitRootLogin no plus key-based authentication. Option E is wrong because umask 0777 removes all permissions from newly created files and directories, which is not a security best practice and would break normal system operation.

Exam trap

CompTIA often tests the misconception that a permissive umask (like 0777) is secure because it 'blocks everything,' but in reality, umask subtracts permissions, so 0777 actually removes all permissions, which is not a best practice and can cause operational issues; the trap is confusing umask subtraction with direct permission setting.

253
MCQmedium

An administrator needs to permanently mount an ext4 filesystem on /dev/sdb1 to the /data directory. Which file must be edited to ensure the mount persists across reboots?

A./etc/sysconfig/network
B./etc/default/grub
C./etc/fstab
D./etc/mtab
AnswerC

Editing /etc/fstab defines a persistent mount entry, satisfying the requirement that the ext4 filesystem on /dev/sdb1 survives reboots. Each line specifies the device, mount point (/data), filesystem type and options, which the system reads at boot to mount automatically, unlike temporary mounts made with the mount command.

Why this answer

The /etc/fstab file is the system's static filesystem table, read by systemd or the init scripts during boot to mount filesystems automatically. To make a mount persistent, you add an entry specifying the device (/dev/sdb1), mount point (/data), filesystem type (ext4), and options (e.g., defaults). This ensures the kernel mounts the filesystem on every reboot without manual intervention.

Exam trap

The trap here is confusing runtime mount information (/etc/mtab) with persistent configuration (/etc/fstab), or assuming network or GRUB config files affect filesystem mounts.

How to eliminate wrong answers

Option A is wrong because /etc/sysconfig/network configures network settings on some distributions (like RHEL) and has nothing to do with filesystem mounts. Option B is wrong because /etc/default/grub holds GRUB bootloader configuration, such as kernel command-line parameters, not mount definitions. Option D is wrong because /etc/mtab is a dynamic, read-only file maintained by the kernel that lists currently mounted filesystems; editing it does not affect boot-time mounts and is typically a symlink to /proc/self/mounts on modern systems.

254
MCQeasy

An administrator wants to use Ansible to ensure that the `httpd` package is installed on all managed nodes. Which Ansible module should be used?

A.copy
B.command
C.yum
D.service
AnswerC

The yum module manages packages on RHEL-based managed nodes, using the host's yum/dnf backend to install httpd and report idempotent state. It satisfies the stem's requirement to ensure the httpd package is present across those managed nodes.

Why this answer

The `yum` module is the correct choice because it is a dedicated Ansible module for managing packages on Red Hat-based systems using the YUM package manager. It ensures the `httpd` package is installed by setting the `state: present` parameter, and it handles idempotency by checking the package status before making changes.

Exam trap

The trap here is that candidates may confuse the `service` module (which manages service state) with package installation, or mistakenly think the `command` module is acceptable for package management despite its lack of idempotency and error handling.

How to eliminate wrong answers

Option A is wrong because the `copy` module is used to copy files from the local machine to remote nodes, not to install packages. Option B is wrong because the `command` module runs arbitrary commands but lacks idempotency and package-specific features, making it error-prone for package management. Option D is wrong because the `service` module manages the state of services (e.g., started, stopped), not the installation of packages.

255
MCQhard

A container started with the above Compose configuration fails to set the system time (clock_settime syscall). Which additional capability is required?

A.SYS_NICE
B.SYS_TIME
C.SYS_RESOURCE
D.SYS_CLOCK
AnswerB

SYS_TIME grants the clock_settime syscall directly, satisfying the container's need to set system time. Docker's default capability set excludes it, so the Compose service must add it explicitly. Unlike SYS_ADMIN, which is broader, SYS_TIME targets only time-setting operations, matching the stem's specific failure.

Why this answer

The `clock_settime` syscall requires the `SYS_TIME` capability to modify the system clock. In Docker Compose, capabilities are added via the `cap_add` directive, and without `SYS_TIME`, the container lacks the privilege to change the system time, resulting in a failure.

Exam trap

CompTIA often tests the distinction between `SYS_TIME` and the non-existent `SYS_CLOCK` to trap candidates who assume a capability name must match the syscall name exactly.

How to eliminate wrong answers

Option A is wrong because `SYS_NICE` allows changing process priority and scheduling, not system time. Option C is wrong because `SYS_RESOURCE` controls resource limits (e.g., ulimit overrides), not clock operations. Option D is wrong because `SYS_CLOCK` is not a valid Linux capability; the correct capability for clock operations is `SYS_TIME`.

256
MCQhard

A Linux server has a logical volume that is running out of space. The administrator extends the underlying volume group by adding a new physical volume, then extends the logical volume and resizes the filesystem. Which command should be used to resize the ext4 filesystem after extending the logical volume?

A.xfs_growfs /dev/vg0/lv_data
B.resize2fs /dev/vg0/lv_data
C.lvextend -r /dev/vg0/lv_data
D.vgextend vg0 /dev/sdb1
AnswerB

resize2fs is the correct utility to resize ext2, ext3, and ext4 filesystems. After extending the logical volume with lvextend, running resize2fs on the device path resizes the filesystem to use the additional space. It can be run without unmounting if the filesystem supports online resizing.

Why this answer

After extending the logical volume, the ext4 filesystem must be resized to use the new space. The resize2fs command is designed for this purpose and can resize ext4 filesystems online. It is the correct tool after lvextend.

Exam trap

The trap here is confusing the logical volume extension with filesystem resizing; lvextend only extends the LV, not the filesystem.

257
MCQhard

A Linux administrator needs to schedule a script to run every Monday at 3:00 AM. The script is located at /opt/scripts/weekly_report.sh. Which entry should be added to the crontab to accomplish this?

A.0 3 * * 1 /opt/scripts/weekly_report.sh
B.3 0 * * 1 /opt/scripts/weekly_report.sh
C.0 3 1 * * /opt/scripts/weekly_report.sh
D.0 3 * * 0 /opt/scripts/weekly_report.sh
AnswerA

The cron format is minute hour day-of-month month day-of-week command. '0 3 * * 1' means minute 0, hour 3 (3:00 AM), any day of month, any month, and day-of-week 1 (Monday). This exactly matches the requirement to run every Monday at 3:00 AM. The script path is absolute, which is best practice for cron jobs.

Why this answer

Cron entries consist of five time fields followed by the command. The correct sequence for Monday at 3:00 AM is minute 0, hour 3, any day of month, any month, and day-of-week 1. This ensures the script runs weekly on Monday at the specified time.

Other options misplace fields or use incorrect day-of-week values, leading to unintended schedules.

Exam trap

The trap here is confusing the day-of-week numbering, where 0 is Sunday and 1 is Monday, or swapping the minute and hour fields.

258
MCQmedium

A system administrator notices that a process with PID 1234 is consuming excessive CPU. The administrator wants to terminate this process gracefully. Which command should be used?

A.killall 1234
B.kill 1234
C.pkill -9 1234
D.kill -9 1234
AnswerB

`kill 1234` sends SIGTERM (signal 15) by default, which requests graceful termination and lets the process run cleanup handlers before exiting. This satisfies the stem's requirement to terminate PID 1234 gracefully, unlike `kill -9`, which sends SIGKILL and terminates immediately without cleanup.

Why this answer

The `kill` command sends SIGTERM (signal 15) by default, which requests that the process terminate gracefully — allowing it to save state, close file handles, and clean up before exiting. Since the administrator wants a graceful termination, `kill 1234` is the correct choice because it targets the specific PID with the default SIGTERM signal.

Exam trap

The trap here is conflating 'terminate' with 'force kill' — candidates see 'terminate' and reach for `-9`, but the word 'gracefully' is the key qualifier that points to the default SIGTERM.

How to eliminate wrong answers

Option A is wrong because `killall` takes a process name, not a PID, so `killall 1234` would look for a process literally named '1234' and fail. Option C is wrong because `pkill -9 1234` sends SIGKILL (signal 9) — an immediate, non-graceful termination — and `pkill` also matches by name/pattern rather than PID. Option D is wrong because `kill -9 1234` sends SIGKILL, which forcibly terminates the process without allowing cleanup, contradicting the 'gracefully' requirement.

259
Multi-Selecthard

A system administrator is troubleshooting why a user cannot execute a script in their home directory. Which TWO conditions could prevent execution? (Choose two.)

Select 2 answers
A.The script is owned by a different user
B.The user's umask is set to 022
C.The script does not have the execute permission set for the user
D.The filesystem containing the script is mounted with the noexec option
E.The script is interpreted by a shell that is not listed in /etc/shells
AnswersC, D

Without execute permission, the kernel denies execution regardless of read access, so the script cannot run. This directly satisfies the stem's execution-failure scenario: the user's effective permission bits on the file lack the x flag, blocking the execve call before any interpreter reads the contents.

Why this answer

For a user to execute a script, the file must have the execute permission bit set for that user (or for the group or others, depending on the user's relationship to the file). Without the execute permission (e.g., `chmod +x`), the shell will refuse to run the script directly, returning a 'Permission denied' error. Option D is correct because if the filesystem is mounted with the noexec option, no files on that filesystem can be executed, regardless of permissions.

Option E is incorrect because /etc/shells is only used to validate login shells; it does not affect script execution. The interpreter for a script is determined by the shebang line, and the system will attempt to run it regardless of whether it's listed in /etc/shells. Options A and B are incorrect: file ownership does not directly prevent execution as long as the user has appropriate permissions, and umask only affects default permissions of newly created files, not existing ones.

Exam trap

Common pitfalls include thinking that file ownership, umask, or the /etc/shells file prevent execution. In reality, the two key blockers are: absence of execute permission and the noexec mount option. Many candidates mistakenly believe that a shell must be listed in /etc/shells for script execution, but that file is only used for login shells.

260
MCQhard

A Linux administrator needs to schedule a recurring backup script to run every Monday at 02:30 using the system-wide cron facility on a systemd-based distribution. Which entry correctly achieves this when placed in /etc/cron.d/backup?

A.30 2 * * 1 root /usr/local/bin/backup.sh
B.30 2 1 * * root /usr/local/bin/backup.sh
C.2 30 * * 1 root /usr/local/bin/backup.sh
D.30 2 * * 1 /usr/local/bin/backup.sh
AnswerA

Files in /etc/cron.d use the extended format that includes a user field between the schedule and the command, so this entry runs the script as root at 02:30 every Monday. The five time fields map to minute, hour, day of month, month, and day of week, satisfying the requirement precisely.

Why this answer

System-wide cron files placed in /etc/cron.d require six fields: minute, hour, day of month, month, day of week, and a user, followed by the command. The correct entry uses minute 30, hour 2, wildcards for day of month and month, day of week 1 for Monday, and root as the executing user, producing a weekly Monday 02:30 run.

Exam trap

The trap here is forgetting that /etc/cron.d entries need an embedded user field, unlike personal crontabs that omit it.

261
MCQeasy

A Linux administrator needs to change the permissions of a file to allow the owner to read and write, the group to read only, and others to have no access. Which chmod command should be used?

A.chmod 640 file
B.chmod 600 file
C.chmod 755 file
D.chmod 644 file
AnswerA

chmod 640 sets the owner bits to read and write (4+2=6), the group bits to read only (4), and others to none (0), exactly matching the required permission set. The three-digit octal notation maps each digit to user, group, and other classes respectively, satisfying the stem's constraint.

Why this answer

The symbolic representation rw-r----- corresponds to octal 640. rw- = 4+2+0=6, r-- = 4+0+0=4, --- = 0+0+0=0.

262
MCQeasy

Which of the following correctly describes the purpose of the /etc/shadow file?

A.It stores the list of users who can use sudo.
B.It stores group memberships and group passwords.
C.It stores user account information including UID, GID, and shell.
D.It stores encrypted passwords and password aging fields.
AnswerD

/etc/shadow holds the encrypted password hashes plus password aging fields such as last change, minimum and maximum age, warning period, and account expiry. This separates sensitive hashes from world-readable /etc/passwd, satisfying the question's description of its purpose.

Why this answer

The /etc/shadow file stores encrypted (hashed) user passwords and password aging information such as the date of last password change, minimum/maximum password age, and account expiration. This file is readable only by root to protect password hashes from unauthorized access, unlike /etc/passwd which is world-readable.

Exam trap

The trap here is that candidates confuse the purpose of /etc/shadow with /etc/passwd, mistakenly thinking /etc/shadow stores UID, GID, and shell, when in fact those are in /etc/passwd and /etc/shadow specifically holds password hashes and aging data.

How to eliminate wrong answers

Option A is wrong because the list of users who can use sudo is stored in /etc/sudoers (or /etc/sudoers.d/), not in /etc/shadow. Option B is wrong because group memberships and group passwords are stored in /etc/group and /etc/gshadow, not in /etc/shadow. Option C is wrong because user account information including UID, GID, and shell is stored in /etc/passwd, not in /etc/shadow.

263
MCQeasy

A junior administrator is asked to automate the backup of a configuration file every night at 11 PM. The script /usr/local/bin/backup.sh already exists. Which command should the administrator run to schedule this task?

A.systemctl start backup.timer
B.at 23:00 /usr/local/bin/backup.sh
C.echo "0 23 * * * /usr/local/bin/backup.sh" | crontab -
D.nohup /usr/local/bin/backup.sh &
AnswerC

Piping the schedule into `crontab -` installs it as the invoking user's crontab, and the five fields `0 23 * * *` fire the existing script daily at 23:00, satisfying the 11 PM requirement without editing files manually.

Why this answer

The `crontab -` command reads from standard input and installs the cron job. The line `0 23 * * * /usr/local/bin/backup.sh` specifies that the script should run at 23:00 (11 PM) every day, matching the requirement exactly. This is the standard method for scheduling recurring tasks in Linux using cron.

Exam trap

The trap here is that candidates often confuse `at` (for one-time tasks) with `cron` (for recurring tasks), or assume `systemctl start` can create a timer on the fly without a pre-existing timer unit file.

How to eliminate wrong answers

Option A is wrong because `systemctl start backup.timer` would start a systemd timer unit, but no such timer has been defined or enabled; this command does not create a new schedule and would fail if the timer unit does not exist. Option B is wrong because the `at` command is used for one-time scheduled tasks, not recurring nightly backups; `at 23:00` would schedule the script to run only once at the next 11 PM, not every night. Option D is wrong because `nohup` runs the script in the background with immunity to hangups, but it does not schedule the task for a future time; it executes immediately and exits.

264
MCQmedium

A Linux administrator notices that a server's root filesystem is using 100% of its inodes, even though `df -h` shows only 60% of the disk space used. Users are unable to create new files. Which command most directly helps identify directories containing large numbers of small files that are consuming inodes?

A.find / -xdev -type f | wc -l
B.du -sh /*
C.du --inodes -s /* | sort -n
D.df -i
AnswerC

`du --inodes -s /*` summarizes inode counts for each top-level directory, and `sort -n` orders them numerically so the largest consumer appears last. This directly addresses inode exhaustion by pinpointing which directory tree holds the most inodes. Unlike disk-space tools, it counts inodes regardless of file size, making it ideal for finding directories filled with many small or empty files that exhaust the inode table.

Why this answer

The root filesystem has run out of inodes, not blocks, so tools that report disk space are ineffective. `du --inodes -s /*` followed by numeric sorting reveals which top-level directories contain the most inodes, allowing the administrator to drill down and remove unneeded small files. This approach directly targets the exhausted resource and avoids wasted effort on block-space analysis.

Exam trap

The trap here is assuming that disk-space tools like `df -h` or `du` will reveal an inode problem, when inode exhaustion is a separate resource that requires inode-aware commands such as `df -i` and `du --inodes`.

265
MCQmedium

A user is able to ping the Linux server but cannot connect via SSH. The SSH service is running and listening. Which configuration file should the administrator review FIRST?

A./etc/pam.d/login
B./etc/ssh/sshd_config
C./etc/nsswitch.conf
D./etc/hosts.allow
AnswerB

/etc/ssh/sshd_config governs the daemon's listening behaviour, authentication methods and access controls, so it is the first place to check when SSH refuses connections despite the service running. Since ping succeeds, the network path is fine; the block likely lies in directives such as AllowUsers, PermitRootLogin or ListenAddress.

Why this answer

The SSH service is running and listening, but the user cannot connect. This points to a configuration issue within the SSH daemon itself. The `/etc/ssh/sshd_config` file controls SSH server settings such as allowed authentication methods, port numbers, and user access restrictions (e.g., `AllowUsers`, `DenyUsers`, `PermitRootLogin`).

Reviewing this file first is the logical step to identify why connections are being rejected despite the service being active.

Exam trap

The trap here is that candidates often jump to `/etc/hosts.allow` or PAM files because they associate 'cannot connect' with access control or authentication, but the question specifies the service is running and listening, which narrows the issue to SSH-specific configuration in `sshd_config`.

How to eliminate wrong answers

Option A is wrong because `/etc/pam.d/login` is used for local console login authentication via PAM, not for SSH connections; SSH uses its own PAM service file (e.g., `/etc/pam.d/sshd`) if PAM is enabled. Option C is wrong because `/etc/nsswitch.conf` controls name service resolution order (e.g., files, DNS, LDAP) and does not affect SSH connectivity or authentication. Option D is wrong because `/etc/hosts.allow` is part of the TCP Wrappers system (libwrap), which is deprecated and not used by modern SSH daemons; SSH typically does not consult this file unless explicitly compiled with libwrap support, which is rare in current distributions.

266
MCQmedium

A Linux server is configured to allow SSH access for remote administration. The security team wants to limit SSH access to only users in the 'ssh-users' group. Which configuration should be added to /etc/ssh/sshd_config?

A.AllowUsers ssh-users
B.AllowGroups ssh-users
C.DenyUsers root
D.PermitRootLogin yes
AnswerB

`AllowGroups ssh-users` restricts SSH logins to members of the named group, satisfying the requirement to limit access to the 'ssh-users' group. The sshd daemon checks this directive during authentication and rejects any user not belonging to a listed group, regardless of valid credentials. It is the precise directive for group-based SSH access control.

Why this answer

The AllowGroups directive in /etc/ssh/sshd_config restricts SSH logins to only those users who are members of the specified group. By setting 'AllowGroups ssh-users', only users belonging to the 'ssh-users' group will be permitted to authenticate via SSH, directly fulfilling the security team's requirement.

Exam trap

The trap here is that candidates confuse AllowUsers (which takes usernames) with AllowGroups (which takes group names), leading them to incorrectly select option A thinking it will filter by group membership.

How to eliminate wrong answers

Option A is wrong because AllowUsers expects a list of usernames, not a group name; 'AllowUsers ssh-users' would attempt to match a user literally named 'ssh-users', not members of the group. Option C is wrong because 'DenyUsers root' only blocks the root user from SSH access, but does nothing to limit access to only users in the 'ssh-users' group. Option D is wrong because 'PermitRootLogin yes' controls whether root can log in via SSH, not which users or groups are allowed; it is irrelevant to restricting access to a specific group.

267
MCQhard

A Linux administrator is writing a script that must wait for a background process to finish before continuing. The process ID is stored in a variable. Which command should be used to wait for this process?

A.sleep 10
B.wait
C.wait $PID
D.kill -0 $PID
AnswerC

`wait $PID` suspends the shell until the specified background process terminates, satisfying the requirement to pause the script before continuing. Unlike polling with `ps` or sleeping, it blocks precisely on that process ID and returns its exit status, so subsequent commands run only after completion.

Why this answer

The `wait` command in Bash, when given a specific process ID (PID), suspends execution of the calling shell script until that background process terminates. This directly fulfills the requirement to wait for a specific background process whose PID is stored in a variable.

Exam trap

CompTIA often tests the distinction between `wait` (which waits for process completion) and `kill -0` (which only checks process existence), leading candidates to mistakenly choose `kill -0` as a waiting mechanism.

How to eliminate wrong answers

Option A is wrong because `sleep 10` simply pauses execution for a fixed 10 seconds, regardless of whether the background process has finished, and does not use the stored PID. Option B is wrong because `wait` without arguments waits for all background processes to finish, not a specific process identified by the PID variable. Option D is wrong because `kill -0 $PID` only checks whether a process with that PID exists and is accessible, sending no signal; it does not wait for the process to complete.

268
MCQeasy

An administrator wants to enforce an account lockout policy after five failed login attempts on a Linux system. Which PAM module should be added to the authentication stack?

A.pam_faillock.so
B.pam_unix.so
C.pam_pwquality.so
D.pam_tally2.so
AnswerA

`pam_faillock.so` counts consecutive failed authentications per account and locks the account once the threshold is reached, satisfying the five-attempt lockout requirement. Configure it via `pam_faillock` in both the `auth` and `account` stacks, since the `account` phase enforces the lockout after the counter trips.

Why this answer

pam_faillock is used for account lockout after failed attempts. pam_unix handles authentication, pam_pwquality checks password strength, pam_tally2 is an older module.

269
MCQeasy

Which command displays the amount of free and used disk space on all mounted file systems in a human-readable format?

A.du -h /
B.lsblk -h
C.mount -h
D.df -h
AnswerD

`df -h` reports free and used space for every mounted file system, satisfying the "all mounted file systems" constraint. The `-h` flag converts block counts into human-readable units such as gigabytes, meeting the formatting requirement. Unlike `du`, which measures directory consumption, `df` queries file system statistics directly.

Why this answer

The df command reports file system disk space usage, and the -h flag renders sizes in human-readable units (K, M, G). Running df -h shows all mounted file systems with total, used, available space, and mount point. This is the standard Linux utility for checking free and used disk space.

Exam trap

XK0-006 often tests the confusion between df (file system free space) and du (directory/file usage); candidates see '-h' and 'disk' in the question and pick du because it also measures disk usage.

How to eliminate wrong answers

Option A is wrong because du -h / estimates disk usage of files and directories under a path, not the free/used space of mounted file systems. Option B is wrong because lsblk lists block devices and their partitions/topology; the -h flag is not a human-readable size switch for lsblk (it shows help), and it does not report file system usage. Option C is wrong because mount -h prints help for the mount command and does not display disk space statistics at all.

270
MCQhard

In a Bash script, the administrator wants to capture the output of a command into a variable. Which syntax should be used?

A.$VAR
B.$((command))
C.`command`
D.$(command)
AnswerD

Command substitution with $(command) runs the command in a subshell and substitutes its standard output, which is then assigned to the variable. Backticks achieve the same but nest poorly; $(...) is the modern, preferred syntax.

Why this answer

Command substitution can be done with $(command) or backticks `command`. The latter is deprecated. $(( )) is for arithmetic expansion. $VAR is for variable expansion.

271
MCQhard

A system administrator configures PAM to enforce account lockout after 3 failed login attempts. Which PAM module should be used?

A.pam_faillock
B.pam_pwquality
C.pam_securetty
D.pam_unix
AnswerA

pam_faillock tracks failed authentication attempts per account and locks the account once the configured threshold is reached, satisfying the three-attempt lockout constraint. Unlike pam_tally2, which is deprecated, pam_faillock integrates with the auth and account stacks and supports per-user unlock intervals, making it the current standard module for this enforcement.

Why this answer

pam_faillock is the correct PAM module for enforcing account lockout after a specified number of failed login attempts. It tracks failed authentication attempts per user and can lock the account when the threshold (e.g., 3 attempts) is reached, typically by writing to a tally file like /var/log/faillock.

Exam trap

The trap here is that candidates may confuse pam_faillock with pam_tally2 (a legacy module) or assume pam_unix alone can enforce lockout, but pam_unix lacks built-in lockout tracking and requires pam_faillock or pam_tally2 for that feature.

How to eliminate wrong answers

Option B (pam_pwquality) is wrong because it enforces password quality rules (e.g., length, complexity) during password changes, not account lockout after failed logins. Option C (pam_securetty) is wrong because it restricts root login to terminals listed in /etc/securetty, not lockout policies. Option D (pam_unix) is wrong because it handles standard Unix authentication (e.g., verifying passwords via /etc/shadow) but does not provide account lockout functionality on its own.

272
MCQeasy

A security engineer needs to verify the authenticity of a downloaded file using its detached GPG signature (file.sig). Which command should be used?

A.gpg --sign file
B.gpg --list-keys
C.gpg --verify file.sig
D.gpg --decrypt file.gpg
AnswerC

This command verifies the detached signature file.sig against the original file (file).

Why this answer

The `gpg --verify file.sig` command is used to verify the authenticity of a file using its detached GPG signature. The detached signature file (file.sig) contains the cryptographic signature, and GPG checks it against the original file (which must be present in the same directory with the same base name) using the signer's public key from the local keyring. This confirms that the file was signed by the holder of the corresponding private key and has not been tampered with.

Exam trap

CompTIA often tests the distinction between detached signatures and embedded signatures, where candidates mistakenly think `--verify` requires the original file as an argument, but GPG automatically infers it from the signature filename.

How to eliminate wrong answers

Option A is wrong because `gpg --sign file` creates a new signature for the file, not verify an existing one. Option B is wrong because `gpg --list-keys` lists public keys in the keyring but does not perform any verification. Option D is wrong because `gpg --decrypt file.gpg` decrypts an encrypted file, not verify a detached signature.

273
MCQmedium

Which command displays the number of lines, words, and characters in a file?

A.wc file.txt
B.wc -w file.txt
C.cat file.txt | wc -l
D.stat file.txt
AnswerA

`wc file.txt` outputs newline, word, and byte counts in a single pass, directly satisfying the stem's requirement for all three metrics. Unlike `cat`, `grep -c`, or `sed`, which report only lines or content, `wc` is purpose-built for counting, so it returns the exact line, word, and character totals requested.

Why this answer

The `wc` command without any options displays the number of lines, words, and characters in a file, in that order. By default, `wc` counts newline characters (lines), whitespace-delimited tokens (words), and bytes (characters) in the specified file. This makes option A the correct choice for displaying all three counts.

Exam trap

The trap here is that candidates often confuse the default behavior of `wc` (which shows all three counts) with options like `-w` or `-l` that only show one metric, or they mistakenly think `stat` provides line/word counts.

How to eliminate wrong answers

Option B is wrong because `wc -w` only counts the number of words in the file, not lines or characters. Option C is wrong because `cat file.txt | wc -l` only counts the number of lines (newline characters) in the file, not words or characters. Option D is wrong because `stat file.txt` displays file metadata such as size, permissions, and timestamps, but does not count lines, words, or characters.

274
MCQhard

During boot, a Linux system displays a kernel panic indicating 'not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. Which of the following is the most likely cause?

A.Network configuration error
B.A failed filesystem check due to dirty file system
C.Incorrect GRUB timeout value
D.Missing or corrupt initramfs
AnswerD

The kernel mounts the root filesystem using drivers loaded from the initramfs. If that image is missing or corrupt, the required storage driver never loads, producing the unknown-block(0,0) panic. A missing or corrupt initramfs is therefore the likely cause.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' indicates that the kernel cannot locate or access the root filesystem. This is most commonly caused by a missing or corrupt initramfs (initial RAM filesystem), which contains the necessary drivers and modules to mount the root filesystem. Without a valid initramfs, the kernel has no way to load storage drivers (e.g., for SATA, NVMe, or LVM) and thus fails to mount the root device.

Exam trap

Candidates often confuse a 'dirty filesystem' error with the 'unknown-block(0,0)' message; the latter is specifically about the kernel's inability to find the root device due to missing drivers in the initramfs.

How to eliminate wrong answers

Option A is wrong because a network configuration error would not prevent the kernel from mounting the root filesystem; network issues typically cause problems later in the boot process (e.g., during network service startup). Option B is wrong because a failed filesystem check due to a dirty filesystem would produce a different error (e.g., 'fsck failed' or 'mount: wrong fs type') and would not result in an 'unknown-block(0,0)' message, which indicates the block device itself is unrecognized. Option C is wrong because an incorrect GRUB timeout value only affects the boot menu countdown; it does not affect the kernel's ability to locate or mount the root filesystem.

275
Multi-Selectmedium

A Linux administrator is automating container builds and needs to reduce image size and ensure reproducibility. Which TWO practices should be applied when writing the Dockerfile? (Choose two.)

Select 2 answers
A.Pin base images and package versions to specific tags or digests
B.Add a separate RUN apt-get update in every RUN instruction that installs packages
C.Copy the entire build context into the image with COPY . /app before installing dependencies
D.Combine related RUN commands and clean package caches in the same layer
E.Use the `latest` tag for all base images to always receive security updates
AnswersA, D

Referencing a mutable tag such as `latest` means a rebuild can pull a different base image, producing non-reproducible results. Pinning to an explicit version tag or image digest guarantees the same inputs are used across builds, which is the core requirement for reproducible container images in automated pipelines.

Why this answer

Image size and reproducibility are improved by minimizing layers and pinning inputs. Combining install and cleanup in one RUN prevents deleted cache files from persisting in earlier layers, and pinning base images and package versions ensures identical builds. Using mutable tags, splitting update from install, or copying the full context early all work against these goals.

Exam trap

The trap here is believing that deleting files in a later RUN removes them from the image, when earlier layers still contain them.

276
MCQmedium

A user reports that a custom application service fails to start with a 'Permission denied' error in the logs. The service runs under the 'appuser' account. Which is the most likely cause and the first step to diagnose?

A.The root password is incorrect; change root password with passwd.
B.SELinux is blocking the service; check journalctl for AVC denials and use restorecon or setsebool.
C.The service binary does not have execute permission for appuser; use chmod +x.
D.The systemd target is not set to multi-user; run systemctl set-default multi-user.target.
AnswerB

SELinux confines processes by type enforcement, so a service binary or its files carrying the wrong security context triggers 'Permission denied' even when standard Unix permissions look correct. Checking journalctl for AVC denials confirms the block, then restorecon fixes mislabelled files or setsebool adjusts the relevant boolean.

Why this answer

SELinux enforces mandatory access controls that can block a service from starting even when standard Linux file permissions are correct. The 'Permission denied' error, combined with the service running under a non-root user, strongly suggests SELinux is denying access. Checking journalctl for AVC denials is the standard first diagnostic step to confirm SELinux involvement, followed by using restorecon to fix file context labels or setsebool to adjust SELinux booleans.

Exam trap

The Linux+ exam often tests the distinction between standard Linux file permissions (chmod) and SELinux mandatory access controls, trapping candidates who immediately assume a 'Permission denied' error is due to missing execute bits rather than checking SELinux denials in journalctl.

How to eliminate wrong answers

Option A is wrong because the root password is irrelevant to a service starting under 'appuser'; the error is not about authentication but about access control, and changing the root password would not resolve a 'Permission denied' error in the service logs. Option C is wrong because while missing execute permission could cause a similar error, the question specifies the service 'fails to start' with 'Permission denied' in the logs, and SELinux denials are a far more common cause in modern Linux distributions; chmod +x would be appropriate only if standard file permissions were the issue, but the diagnostic step of checking journalctl for AVC denials is the first recommended action. Option D is wrong because the systemd target setting determines which services start at boot, not whether a specific service can start; a wrong target would prevent the service from starting at boot but would not produce a 'Permission denied' error in the service logs.

277
MCQmedium

A user reports that a recently installed application fails to start. The application was installed via a shell script that added a repository and installed the package. The user runs 'ldd /usr/bin/app' and sees several 'not found' libraries. Which of the following is the MOST likely cause?

A.The installation script did not install all required dependencies.
B.The kernel version is outdated.
C.SELinux is blocking the application.
D.The file system is corrupted.
AnswerA

The 'not found' entries from ldd mean shared libraries the binary links against are absent from the system. Since the shell script installed the package, it most likely omitted required dependency packages, leaving those libraries uninstalled.

Why this answer

The `ldd` command lists shared library dependencies for a binary. When it reports 'not found' libraries, it means the dynamic linker cannot locate the required `.so` files. Since the application was installed via a shell script that added a repository and installed the package, the most likely cause is that the script failed to install all required dependencies, leaving the binary unable to resolve its shared library links.

Exam trap

The trap here is that candidates may confuse library resolution failures with permission or security issues (like SELinux), but `ldd` output directly points to missing files, not access control.

How to eliminate wrong answers

Option B is wrong because an outdated kernel version would not cause specific shared libraries to be missing; it might cause system call incompatibilities, but `ldd` would still find the libraries if they were installed. Option C is wrong because SELinux blocks access based on security contexts, not by making libraries disappear from the filesystem; `ldd` would still resolve the libraries, though execution might be denied. Option D is wrong because file system corruption would likely cause broader system issues or error messages beyond just missing libraries in `ldd` output, and `ldd` would typically report I/O errors or file not found for the binary itself, not specific library dependencies.

278
MCQeasy

A system administrator needs to restrict SSH access to a Linux server to only users in the 'sshusers' group. Which configuration change achieves this?

A.Add 'DenyUsers *' to /etc/ssh/sshd_config
B.Set 'PermitRootLogin no' in /etc/ssh/sshd_config
C.Add 'AllowGroups sshusers' to /etc/ssh/sshd_config
D.Add 'AllowUsers sshusers' to /etc/ssh/sshd_config
AnswerC

Adding `AllowGroups sshusers` to `/etc/ssh/sshd_config` makes the SSH daemon evaluate group membership at authentication time, permitting only accounts belonging to the `sshusers` group. This directly satisfies the stem's constraint of restricting access to that single group, and it scales cleanly as membership changes without editing per-user entries.

Why this answer

The 'AllowGroups' directive in /etc/ssh/sshd_config restricts SSH access to only users who are members of the specified group. When set to 'AllowGroups sshusers', only users belonging to the 'sshusers' group will be permitted to log in via SSH, effectively blocking all others. This is the standard method for group-based access control in OpenSSH.

Exam trap

CompTIA often tests the distinction between 'AllowUsers' (which expects usernames) and 'AllowGroups' (which expects group names), leading candidates to incorrectly choose 'AllowUsers sshusers' thinking it applies to the group rather than a user literal.

How to eliminate wrong answers

Option A is wrong because 'DenyUsers *' denies all users by name, but it does not consider group membership; it would block everyone including root and any user, which is overly restrictive and not the intended group-based restriction. Option B is wrong because 'PermitRootLogin no' only disables root login via SSH, but does nothing to restrict access for other users or enforce group-based access control. Option D is wrong because 'AllowUsers sshusers' expects a list of usernames, not a group name; it would attempt to match a user literally named 'sshusers', which does not exist, effectively denying all users but for the wrong reason and without group-based logic.

279
MCQmedium

A security policy requires that all users must have passwords with at least one uppercase letter, one digit, and a minimum length of 12 characters. Which PAM configuration file and module should be used to enforce this?

A./etc/pam.d/login with pam_securetty.so
B./etc/pam.d/sshd with pam_unix.so
C./etc/pam.d/sudo with pam_permit.so
D./etc/pam.d/common-password with pam_pwquality.so
AnswerD

The pam_pwquality.so module enforces complexity rules through its ucredit, dcredit and minlen parameters, directly satisfying the policy's uppercase, digit and 12-character requirements. Placed in /etc/pam.d/common-password, it intercepts password changes via the password stack, rejecting non-compliant entries at update time.

Why this answer

The pam_pwquality.so module is specifically designed to enforce password complexity policies such as minimum length, uppercase, digit, and special character requirements. It is configured in the password stack of PAM, typically in /etc/pam.d/common-password on Debian-based systems or /etc/pam.d/system-auth on RHEL-based systems. The options for pam_pwquality (e.g., minlen=12, ucredit=-1, dcredit=-1) directly map to the policy requirements.

Therefore, /etc/pam.d/common-password with pam_pwquality.so is the correct choice.

Exam trap

XK0-006 often tests the confusion between authentication modules (like pam_unix) and password quality modules (like pam_pwquality), or mistakenly selecting a PAM file for a specific service (sshd, login) instead of the common password stack.

How to eliminate wrong answers

Option A is wrong because pam_securetty.so restricts root login to secure TTYs and does not enforce password complexity. Option B is wrong because pam_unix.so handles traditional Unix authentication and password changes but does not provide complexity checking; it relies on other modules for that. Option C is wrong because pam_permit.so is a module that always returns success and is used for granting access without authentication, not for enforcing password policies.

280
MCQeasy

A Linux administrator needs to find large log files that may be consuming disk space. Which command should be used to locate files larger than 100MB in the /var/log directory?

A.df -h
B.ls -lR /var/log
C.find /var/log -type f -size +100M
D.du -sh /var/log/*
AnswerC

`find` traverses `/var/log` recursively and filters entries by metadata, so `-type f` restricts matches to regular files and `-size +100M` selects those exceeding 100 MB, satisfying the disk-space constraint. Unlike `du` or `ls`, it locates files by size threshold rather than merely reporting directory totals.

Why this answer

The `find` command with `-type f` (regular files) and `-size +100M` (files larger than 100 megabytes) is the correct tool to locate large log files in /var/log. This directly meets the requirement to find files by size, unlike other commands that only show disk usage or directory listings without size filtering.

Exam trap

The trap here is that candidates often confuse `du` (disk usage of directories) or `df` (filesystem free space) with `find`'s file-size filtering, leading them to choose options that show aggregate usage rather than locating individual large files.

How to eliminate wrong answers

Option A is wrong because `df -h` reports filesystem-level disk usage (e.g., total, used, available space on mounted partitions), not individual file sizes. Option B is wrong because `ls -lR /var/log` recursively lists all files and directories with details but does not filter by size, requiring manual inspection to find large files. Option D is wrong because `du -sh /var/log/*` shows the total disk usage of each top-level item in /var/log, but it does not filter for files larger than 100MB and may miss files nested deeper in subdirectories.

281
MCQeasy

A Linux administrator needs to add a new user named 'jdoe' with a home directory and default shell /bin/bash. Which command should be used?

A.chage -m -s /bin/bash jdoe
B.useradd -m -s /bin/bash jdoe
C.passwd -m -s /bin/bash jdoe
D.usermod -m -s /bin/bash jdoe
AnswerB

The -m flag instructs useradd to create the home directory /home/jdoe, while -s /bin/bash sets the login shell, satisfying both stated requirements. Without -m, no home directory is created, and the default shell would otherwise come from /etc/default/useradd.

Why this answer

The useradd command creates a new user account, and the -m flag creates the home directory while -s /bin/bash sets the login shell. This is the standard Linux utility for adding users with a specified home directory and shell in a single command.

Exam trap

XK0-006 often tests the confusion between useradd (create) and usermod (modify) — candidates must recognize that only useradd can create a new account.

How to eliminate wrong answers

Option A is wrong because chage modifies password aging information (e.g., -m sets minimum days between password changes) and does not create users or set shells. Option C is wrong because passwd manages passwords and does not have -m or -s flags for creating users or setting shells. Option D is wrong because usermod modifies an existing user; it cannot create a new user, so running it for a non-existent 'jdoe' would fail.

282
MCQeasy

An administrator needs to add a script to be executed daily. The script is placed at /etc/cron.daily/myscript. After placing the script, it does not run. Based on the exhibit, what is the most likely issue?

A.The script is owned by the wrong user
B.The cron daemon is not running
C.The script is not executable
D.The script is not listed in /etc/crontab
E.Anacron is not installed
AnswerC

Cron silently skips files in /etc/cron.daily that lack the execute bit, so the job never runs. Setting the executable permission with chmod +x allows run-parts to invoke the script, resolving the failure without altering the schedule or path.

Why this answer

Scripts placed in /etc/cron.daily/ are executed by run-parts, which requires files to have the executable bit set. Without the execute permission (e.g., chmod +x), the script is skipped entirely, even if it is owned correctly and the cron daemon is active.

Exam trap

The trap here is that candidates assume ownership or the cron daemon status is the issue, but the specific requirement for the executable bit on scripts in cron.daily directories is a subtle but frequently tested detail.

How to eliminate wrong answers

Option A is wrong because ownership (typically root) does not prevent execution; the cron daemon runs as root and can execute any owned script as long as it is executable. Option B is wrong because if the cron daemon were not running, no cron jobs would execute at all, but the question indicates only this specific script fails. Option D is wrong because /etc/cron.daily/ is a directory processed by run-parts via /etc/crontab; scripts do not need to be listed individually in /etc/crontab.

Option E is wrong because anacron is used for jobs that may run on systems that are not always on, but it is not required for daily cron execution on a continuously running system.

283
Multi-Selecthard

A Linux server is experiencing intermittent network connectivity issues. The administrator needs to capture and analyze network traffic to diagnose the problem. Which TWO commands or tools can be used to capture packets on the eth0 interface? (Choose two.)

Select 2 answers
A.tcpdump -i eth0
B.netstat -i eth0
C.tshark -i eth0
D.nmap -sP 192.168.1.0/24
E.ss -t -a
AnswersA, C

tcpdump -i eth0 captures packets on the eth0 interface in real time. It is a standard command-line packet analyzer that allows filtering and inspection of network traffic. This directly addresses the need to capture packets for diagnosing intermittent connectivity issues. It provides detailed output that can be saved to a file for later analysis, making it a primary tool for network troubleshooting.

Why this answer

tcpdump and tshark are both packet capture tools that can operate on a specified interface like eth0. They allow real-time capture and analysis of network traffic, which is essential for diagnosing intermittent connectivity issues. The other commands provide statistics or connection lists but do not capture packets.

Exam trap

The trap here is confusing interface statistics or connection listings with actual packet capture tools; only tcpdump and tshark capture and record packet data.

284
MCQeasy

A user wants to change the permissions of a file to give the owner full control, the group read and execute, and others no access. Which of the following chmod commands will achieve this?

A.chmod 750 file
B.chmod 700 file
C.chmod 770 file
D.chmod 755 file
AnswerA

`chmod 750` encodes owner read/write/execute (7), group read/execute (5), and others no access (0), matching the requested permission set exactly. The three octal digits map directly to user, group, and other classes, so this single command satisfies every constraint in the scenario.

Why this answer

The numeric chmod mode 750 translates to owner=7 (read+write+execute = 4+2+1), group=5 (read+execute = 4+1), and others=0 (no access). This exactly matches the requirement: owner full control, group read and execute, others no access.

Exam trap

XK0-006 often tests the octal-to-permission mapping, so candidates who confuse the group and others digits (e.g., picking 755 or 770) fail to match the exact requirement of group read/execute and others no access.

How to eliminate wrong answers

Option B (700) is wrong because it gives the group no permissions at all, but the requirement is group read and execute. Option C (770) is wrong because it gives others read, write, and execute, which violates the 'others no access' requirement. Option D (755) is wrong because it gives others read and execute, but the requirement is others no access.

285
MCQhard

A Linux administrator is troubleshooting a system that becomes unresponsive under heavy load. They suspect that a process is causing excessive disk I/O. Which command should the administrator use to identify the process performing the most disk writes in real time?

A.iotop -o
B.iostat -x 1
C.pidstat -d 1
D.vmstat 1
AnswerA

iotop -o displays only processes that are actively performing I/O, sorted by I/O usage. It provides real-time monitoring of disk read/write bandwidth per process, making it ideal for identifying the process causing heavy disk writes. The -o option filters out idle processes, focusing on active ones.

Why this answer

To identify the process causing heavy disk writes in real time, the administrator needs a tool that shows per-process I/O activity. iotop -o displays only active I/O processes, sorted by I/O usage, making it easy to spot the culprit. While pidstat -d can also show per-process I/O, iotop is specifically designed for interactive real-time monitoring and is more commonly used for this scenario.

Exam trap

The trap here is choosing a tool that shows disk activity but not per-process attribution, or assuming that any I/O monitoring tool provides per-process detail.

286
Multi-Selectmedium

An administrator is investigating a network issue where a server cannot connect to an external website. They run `ping 8.8.8.8` successfully, but `ping google.com` fails. Which TWO of the following are the most likely causes? (Choose TWO.)

Select 2 answers
A.The network interface is down.
B.The default gateway is misconfigured.
C.The DNS server is unreachable or misconfigured.
D.The firewall is blocking ICMP traffic.
E.The /etc/hosts file has an incorrect entry for google.com.
AnswersC, E

Successful pinging of 8.8.8.8 proves IP connectivity and routing work, isolating the fault to name resolution. An unreachable or misconfigured DNS server prevents resolving google.com to an IP address, exactly matching the symptom of numeric pings succeeding while hostname pings fail.

Why this answer

Option C is correct because the successful `ping 8.8.8.8` proves IP connectivity and routing to the internet work, while the failure of `ping google.com` indicates name resolution is failing — meaning the configured DNS server is unreachable, misconfigured, or not responding on port 53. Option E is correct because an incorrect entry for google.com in /etc/hosts would cause the resolver to return a wrong IP address for that hostname before ever querying DNS, producing exactly this symptom (numeric IP works, hostname fails). Option A is wrong because a down network interface would prevent even `ping 8.8.8.8` from succeeding.

Option B is wrong because a misconfigured default gateway would break routing to external IP addresses, so the numeric ping to 8.8.8.8 would also fail. Option D is wrong because a firewall blocking ICMP would cause both pings to fail, not just the hostname-based one.

Exam trap

XK0-006 often tests the diagnostic reasoning that successful IP ping plus failed hostname ping isolates the fault to name resolution, tempting candidates to blame routing or firewalls that would have broken both pings.

287
MCQmedium

A security administrator is hardening a Linux server and wants to verify that the SSH daemon is configured to disallow direct root logins. The administrator has already edited /etc/ssh/sshd_config and set PermitRootLogin no. Which command should the administrator run to ensure the SSH daemon reloads the configuration without terminating existing SSH sessions?

A.sshd -t
B.systemctl restart sshd
C.kill -HUP $(pidof sshd)
D.systemctl reload sshd
AnswerD

This command sends a SIGHUP to the sshd service, causing it to re-read its configuration file while keeping existing connections alive. It is the standard way to apply changes to /etc/ssh/sshd_config without dropping active sessions, which is exactly what the administrator needs to verify the PermitRootLogin setting.

Why this answer

Reloading the sshd service with systemctl reload sshd causes the daemon to re-read its configuration file without dropping existing connections, which is ideal when applying changes like PermitRootLogin no. Testing the syntax with sshd -t is good practice beforehand, but it does not activate the new setting. Restarting would disrupt sessions, and direct kill is less reliable than the systemd-managed reload.

Exam trap

The trap here is assuming that restarting the service is required to apply sshd_config changes, when a reload is sufficient and preserves active sessions.

288
MCQhard

Refer to the exhibit. The service fails to start with the error 'Failed to start My Service: Unit not found'. What is the most likely cause?

A.The User specified does not exist.
B.The service file is not in the correct directory.
C.The network target is not reached.
D.The ExecStart script is missing.
AnswerB

Systemd only discovers unit files stored in the directories it scans, such as /etc/systemd/system and /usr/lib/systemd/system. A unit placed elsewhere is never loaded into the manager's search path, so systemctl reports "Unit not found" rather than a configuration error. Relocating the file to a scanned directory resolves the failure.

Why this answer

The error 'Unit not found' indicates that systemd cannot locate the service unit file. Systemd service files must be placed in specific directories such as /etc/systemd/system/ or /usr/lib/systemd/system/. If the file is in the wrong directory, systemd will not recognize the unit, causing the 'Unit not found' error.

Option B correctly identifies this as the most likely cause.

Exam trap

CompTIA often tests the distinction between 'unit not found' (file location issue) and 'command not found' or 'exec format error' (missing executable or script), leading candidates to incorrectly choose the missing ExecStart script option.

How to eliminate wrong answers

Option A is wrong because a non-existent User would cause a different error, such as 'Failed to determine user credentials' or 'User 'xxx' not found', not 'Unit not found'. Option C is wrong because the network target not being reached would result in a dependency failure or timeout, not a 'Unit not found' error. Option D is wrong because a missing ExecStart script would produce an error like 'Exec format error' or 'No such file or directory' when the service attempts to start, not a failure to find the unit itself.

289
MCQeasy

A junior administrator needs to change the ownership of the file /var/www/html/index.html from user 'www-data' to user 'apache' and group 'apache'. Which command will accomplish this?

A.usermod -g apache www-data /var/www/html/index.html
B.chown apache:apache /var/www/html/index.html
C.chmod apache:apache /var/www/html/index.html
D.chgrp apache /var/www/html/index.html
AnswerB

chown changes file owner and group. The syntax user:group sets both simultaneously. Using apache:apache sets the owner to apache and the group to apache, exactly as required. This is the standard way to change both ownership attributes in one command, and it requires appropriate privileges (usually root).

Why this answer

The chown command with user:group syntax changes both the owner and group of a file. Specifying apache:apache sets the owner and group to apache, fulfilling the requirement. Other commands either modify permissions, change only the group, or modify user account properties rather than file ownership.

Exam trap

The trap here is mixing up chmod (permissions) with chown (ownership), or using chgrp when both owner and group must change.

290
Multi-Selectmedium

A Linux administrator is troubleshooting a server that is unresponsive. They suspect a process is consuming excessive CPU. Which TWO commands can be used to identify the process with the highest CPU usage? (Choose two.)

Select 2 answers
A.vmstat 1
B.free -m
C.iostat -c
D.ps aux --sort=-%cpu | head -n 5
E.top
AnswersD, E

The `ps aux --sort=-%cpu` command lists all processes sorted by CPU usage in descending order, and piping to `head -n 5` shows the top five. This provides a snapshot of the processes with the highest CPU consumption. It is a non-interactive alternative to `top` and is useful for scripting or quick checks.

Why this answer

To identify a process consuming excessive CPU, the administrator needs tools that display per-process CPU usage. `top` provides a real-time, sorted list of processes by CPU usage. `ps aux --sort=-%cpu | head -n 5` gives a snapshot of the top CPU-consuming processes. Other commands like `free`, `vmstat`, and `iostat` show system-wide metrics but not per-process details.

Exam trap

The trap here is confusing system-wide CPU monitoring tools like vmstat and iostat with per-process tools like top and ps; only the latter can identify a specific process.

291
MCQeasy

A server is experiencing high CPU load. The administrator needs to identify which process is consuming the most CPU resources in real time. Which command should be used?

A.w
B.vmstat
C.uptime
D.ps aux --sort=-%cpu
E.top
AnswerE

`top` refreshes process statistics every few seconds, sorting by CPU consumption by default, so the administrator sees the heaviest process live. It satisfies the real-time constraint directly, unlike `ps`, which captures a single static snapshot and would require repeated manual invocations to track shifting load.

Why this answer

The `top` command provides a real-time, dynamic view of running processes, including CPU usage, and updates continuously by default. It is the standard tool for identifying which process is currently consuming the most CPU resources on a Linux system.

Exam trap

The trap here is that candidates often choose `ps aux --sort=-%cpu` because it shows CPU-sorted output, but they overlook the requirement for real-time monitoring, which `top` uniquely provides through continuous updates.

How to eliminate wrong answers

Option A is wrong because `w` displays who is logged in and what they are doing, along with system load averages, but it does not show per-process CPU usage. Option B is wrong because `vmstat` reports system-wide statistics for processes, memory, paging, block I/O, traps, and CPU activity, but it does not list individual processes sorted by CPU consumption. Option C is wrong because `uptime` only shows how long the system has been running, the number of users, and load averages, with no process-level detail.

Option D is wrong because `ps aux --sort=-%cpu` gives a snapshot of processes sorted by CPU usage, but it is not a real-time updating tool; it must be re-run manually to see changes.

292
MCQhard

A Linux administrator is troubleshooting a service that fails to start. The service unit file is located at /etc/systemd/system/myservice.service. The administrator runs 'systemctl status myservice' and sees 'Active: failed (Result: exit-code)'. Which of the following commands will provide the most detailed information about why the service failed?

A.systemctl cat myservice
B.journalctl -u myservice
C.systemctl show myservice
D.systemctl list-units --failed
AnswerB

The journalctl -u myservice command displays all log messages related to the myservice unit, including standard output and error from the service process. This is the most direct way to see why the service failed, as it shows the exact error messages and exit codes. It provides detailed context from the service's execution.

Why this answer

The journalctl -u myservice command retrieves all journal entries for the specified unit, including error messages and exit codes. This is the most detailed source of information for diagnosing why a service failed. Other commands show configuration or summary status but lack the runtime error details needed for troubleshooting.

Exam trap

The trap here is assuming that systemctl status or systemctl show provides enough detail, when in fact they only give a summary and the actual error is in the journal.

293
MCQmedium

A user reports that they cannot access a file because permission is denied. The file's permissions are -rwsr-xr-x. What special permission is set?

A.No special permission
B.SUID
C.Sticky bit
D.SGID
AnswerB

The `s` in the owner execute position of `-rwsr-xr-x` denotes SUID (Set User ID). When executed, the file runs with the owner's privileges rather than the invoking user's, satisfying the stem's requirement to identify the special permission set on this file.

Why this answer

The permissions string `-rwsr-xr-x` shows an 's' in the owner's execute position, which is the SUID (Set User ID) bit. When SUID is set on an executable, the process runs with the effective UID of the file's owner rather than the invoking user — commonly used by utilities like `passwd` to allow normal users to modify protected files.

Exam trap

The trap is misreading which position the 's' occupies — candidates who don't carefully distinguish owner vs. group execute positions will confuse SUID with SGID.

How to eliminate wrong answers

Option A is wrong because the 's' in the owner execute position is itself the special permission indicator — there is clearly a special bit set. Option C is wrong because the sticky bit appears as a 't' in the other/execute position (e.g., `drwxrwxrwt` on /tmp), not as an 's' in the owner position. Option D is wrong because SGID appears as an 's' in the group execute position (e.g., `-rwxr-sr-x`), not the owner position.

294
MCQhard

An administrator needs to capture network traffic on interface eth0, filter for packets to/from host 10.0.0.1, and save the output to a file for later analysis. Which command should be used?

A.tcpdump -i eth0 src 10.0.0.1 -w capture.pcap
B.tcpdump -i eth0 dst 10.0.0.1 -w capture.pcap
C.tcpdump -i eth0 host 10.0.0.1 -w capture.pcap
D.tcpdump -i eth0 -n host 10.0.0.1 -w capture.pcap
AnswerC

tcpdump -i eth0 host 10.0.0.1 -w capture.pcap binds capture to eth0, applies a host filter matching traffic in either direction to or from 10.0.0.1, and writes raw packets to capture.pcap for later analysis, satisfying all three requirements.

Why this answer

The `tcpdump` command with the `host` filter captures all traffic (both source and destination) to or from the specified IP address, which matches the requirement to filter for packets to/from host 10.0.0.1. The `-i eth0` specifies the interface, and `-w capture.pcap` writes the output to a file for later analysis.

Exam trap

The trap here is that candidates often confuse `src` and `dst` filters as sufficient for capturing all traffic to/from a host, forgetting that `host` is the correct primitive for bidirectional capture.

How to eliminate wrong answers

Option A is wrong because `src 10.0.0.1` only captures packets where the source IP is 10.0.0.1, missing packets destined to that host. Option B is wrong because `dst 10.0.0.1` only captures packets where the destination IP is 10.0.0.1, missing packets sourced from that host. Option D is wrong because the `-n` flag disables name resolution (which is not required by the question) but does not affect the filter; however, the primary issue is that it includes an unnecessary flag, and the question asks for the correct command, not an equivalent one with extra options.

295
MCQhard

An Apache web server (httpd) is serving content from a custom directory /webapps/company. The root directory is labeled with the default_t context, causing httpd to be denied access. Which command should the administrator use to persistently relabel the directory for httpd access?

A.restorecon -v /webapps/company
B.chcon -t httpd_sys_content_t /webapps/company
C.setsebool -P httpd_read_user_content on
D.semanage fcontext -a -t httpd_sys_content_t '/webapps/company(/.*)?'
AnswerD

The `semanage fcontext -a -t httpd_sys_content_t` command writes a persistent mapping into the SELinux file-context policy, so `/webapps/company` and its contents inherit `httpd_sys_content_t` rather than `default_t`. This satisfies the requirement for a lasting relabel that survives `restorecon` and reboot, unlike transient `chcon` changes.

Why this answer

`semanage fcontext` modifies the SELinux file context policy persistently, and the regex `/webapps/company(/.*)?` ensures the rule applies to the directory and all its contents. This is necessary because `restorecon` (option A) only applies the default context from the policy, which is `default_t` for this custom path, and `chcon` (option B) is non-persistent and will be overwritten by a file system relabel. The `setsebool` (option C) controls a boolean for user content, not the file context of a custom directory.

Exam trap

The trap here is that candidates confuse `chcon` (immediate but non-persistent) with `semanage fcontext` (persistent via policy), or they incorrectly assume `restorecon` can change the context to a non-default type when it only restores the type defined in the policy.

How to eliminate wrong answers

Option A is wrong because `restorecon -v /webapps/company` would reset the context to the default `default_t` type, which is the very context causing the denial, not the `httpd_sys_content_t` type needed for Apache access. Option B is wrong because `chcon -t httpd_sys_content_t /webapps/company` changes the context immediately but is not persistent; it will be reverted to the policy default after a file system relabel or `restorecon` run. Option C is wrong because `setsebool -P httpd_read_user_content on` enables a boolean that allows httpd to read user home directories (typically `/home/*/public_html`), not a custom directory like `/webapps/company`.

296
MCQmedium

Which of the following commands will display the last 10 lines of a log file and also output new lines as they are appended?

A.head -f logfile
B.less +F logfile
C.tail -f logfile
D.cat logfile
AnswerC

The -f flag makes tail follow the file descriptor, printing appended lines as they are written rather than exiting after the last 10. This satisfies both requirements: the default last-10-lines display plus continuous live output.

Why this answer

The `tail -f logfile` command displays the last 10 lines of the file by default and then continues to monitor the file for new lines, outputting them as they are appended. The `-f` (follow) option keeps the file open and polls for changes, making it the standard tool for real-time log monitoring.

Exam trap

The trap here is that candidates may confuse `tail -f` with `less +F` (which also works but uses a different syntax) or mistakenly think `head` can follow a file, but the exam expects precise knowledge of the `tail -f` command as the standard for real-time log viewing.

How to eliminate wrong answers

Option A is wrong because `head -f` is not a valid command; `head` does not support a `-f` flag, and even if it did, `head` reads from the beginning of the file, not the end. Option B is wrong because `less +F` does not exist; the correct syntax to follow a file in `less` is `less +F` (uppercase F) which enters follow mode, but the lowercase `+F` is invalid and will cause an error. Option D is wrong because `cat logfile` simply outputs the entire file content to stdout and does not provide any real-time monitoring or line limiting.

297
MCQhard

A system administrator runs 'umask 027' in a Bash shell. What will be the default permissions for a new directory created in that shell? (Assume no other umask changes.)

A.rwxrwxr-x (775)
B.rwxrwxrwx (777)
C.rw-rw-r-- (664)
D.rwxr-x--- (750)
AnswerD

Correct: 777 - 027 = 750.

Why this answer

The umask value 027 subtracts permissions from the base 777 for directories. 777 minus 027 equals 750, which translates to rwxr-x---. The owner gets full permissions (rwx), the group gets read and execute (r-x), and others get no permissions (---).

Exam trap

CompTIA often tests the distinction between file and directory base permissions (666 vs 777) and the fact that umask subtracts from the base, not from a fixed value like 755.

How to eliminate wrong answers

Option A is wrong because it represents permissions 775 (rwxrwxr-x), which would result from a umask of 002, not 027. Option B is wrong because it represents permissions 777 (rwxrwxrwx), which would result from a umask of 000, not 027. Option C is wrong because it represents permissions 664 (rw-rw-r--), which is the default for files (base 666) with a umask of 002, not for directories with umask 027.

298
MCQeasy

A Linux administrator discovers that a user's home directory contains a file with setuid bit set, owned by root. The file is not part of any authorized software. What is the most appropriate immediate action?

A.Move the file to /tmp for further analysis
B.Delete the file immediately to remove the threat
C.Change the file owner to the user with 'chown user:user <file>'
D.Remove the setuid bit with 'chmod u-s <file>'
AnswerD

Removing the setuid bit with chmod u-s immediately neutralises the privilege-escalation risk, since the root-owned binary would otherwise execute with root privileges. This is the fastest containment action for an unauthorised setuid file in a user's home directory.

Why this answer

The immediate priority is to neutralize the unauthorized setuid root binary, which poses a privilege escalation risk. Removing the setuid bit with 'chmod u-s' disables the ability for any user to execute the file with root privileges, containing the threat without destroying evidence that may be needed for forensic analysis. This aligns with security best practices of preserving artifacts while mitigating active risks.

Exam trap

The trap here is that candidates often choose deletion (Option B) as the 'obvious' fix, overlooking the forensic value of the file and the fact that removing the setuid bit is a less destructive and equally effective containment measure.

How to eliminate wrong answers

Option A is wrong because moving the file to /tmp does not remove the setuid bit; the file would retain its setuid root capability in /tmp, still allowing privilege escalation. Option B is wrong because deleting the file immediately destroys potential forensic evidence (e.g., timestamps, contents, metadata) that could be critical for understanding the breach or attacker's methods. Option C is wrong because changing the owner to the user does not remove the setuid bit; the file would still execute with the new owner's privileges, which could be the user themselves, failing to eliminate the privilege escalation vector.

299
MCQhard

An administrator notices that a process is running with the context 'unconfined_u:unconfined_r:unconfined_t:s0'. What does this indicate about SELinux?

A.The process is running in permissive mode.
B.The process is running in an unconfined domain.
C.SELinux is disabled.
D.The process is confined by a targeted policy.
AnswerB

The unconfined_t type places the process outside SELinux policy enforcement, so type enforcement rules do not restrict it. Confined domains such as httpd_t are limited by policy; unconfined processes retain standard discretionary access controls only.

Why this answer

The context 'unconfined_u:unconfined_r:unconfined_t:s0' indicates that the process is running in the unconfined domain (unconfined_t). In SELinux, processes in the unconfined domain are not restricted by the targeted policy, meaning they have full access subject to standard Linux permissions.

Exam trap

XK0-006 often tests the misinterpretation of 'unconfined' as permissive mode or disabled SELinux, when it actually refers to the domain type.

How to eliminate wrong answers

Option A is wrong because permissive mode is a global SELinux setting where violations are logged but not enforced; the context itself does not indicate permissive mode. Option C is wrong because if SELinux were disabled, processes would not have SELinux contexts at all. Option D is wrong because a confined process would have a specific domain type (e.g., httpd_t), not unconfined_t.

300
MCQeasy

In a Bash script, what is the difference between single quotes and double quotes?

A.Both behave the same.
B.Single quotes allow variable expansion; double quotes do not.
C.Double quotes prevent all substitutions; single quotes allow command substitution.
D.Single quotes prevent variable expansion; double quotes allow it.
AnswerD

Within single quotes, Bash treats every character literally, so $VAR stays unexpanded; double quotes permit parameter and command substitution while still suppressing word splitting and globbing. This satisfies the stem's request for the precise difference in expansion behaviour between the two quoting styles.

Why this answer

Single quotes preserve the literal value of each character, while double quotes allow variable expansion and command substitution.

Page 3

Page 4 of 11

Page 5

All pages