Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 301–375

781 questions total · 11pages · All types, answers revealed

Page 4

Page 5 of 11

Page 6
301
Multi-Selecthard

A DevOps engineer is creating a Dockerfile for a Node.js application. Which THREE of the following instructions are valid and commonly used in a Dockerfile? (Choose THREE.)

Select 3 answers
A.EXECUTE node app.js
B.COPY . /app
C.RUN npm install
D.INSTALL package.json
E.FROM node:14
AnswersB, C, E

COPY transfers files from the build context into the image, here placing the project's source at /app. It satisfies the need to get application code into the image before running npm install and CMD. Unlike ADD, COPY performs no URL fetching or archive extraction, keeping the build predictable.

Why this answer

Option B, COPY . /app, is correct because COPY is a valid Dockerfile instruction that copies files from the build context into the image filesystem, here placing the application source into /app. Option C, RUN npm install, is correct because RUN executes commands during the image build, and npm install is the standard way to install Node.js dependencies inside the image. Option E, FROM node:14, is correct because FROM is the required first instruction in a Dockerfile that sets the base image, and node:14 is a valid Node.js base image tag.

Option A, EXECUTE node app.js, is not a Dockerfile instruction; the correct instruction for starting the container process is CMD or ENTRYPOINT. Option D, INSTALL package.json, is also not a Dockerfile instruction; dependency installation is done with RUN, and package.json is typically copied with COPY.

Exam trap

XK0-006 often tests recognition of valid Dockerfile instructions versus plausible-sounding but nonexistent ones (EXECUTE, INSTALL), so candidates must know the canonical instruction set (FROM, RUN, COPY, ADD, CMD, ENTRYPOINT, EXPOSE, WORKDIR, ENV, etc.).

302
MCQeasy

An administrator wants to verify which RPM packages are installed on a Red Hat Enterprise Linux system. Which command displays that information?

A.dpkg -l
B.apt list --installed
C.rpm -qa
D.yum list installed
AnswerC

The -q flag queries the RPM database and -a selects all installed packages, so rpm -qa lists every installed package name and version. This reads the local Berkeley DB/rpmdb metadata directly, requiring no repository or network access.

Why this answer

The `rpm -qa` command queries the RPM database and lists all installed packages on a Red Hat Enterprise Linux system. The `-q` flag enables query mode, and `-a` specifies all packages, making it the correct tool for this task.

Exam trap

The trap here is that candidates familiar with Debian-based systems might choose `dpkg -l` or `apt list --installed`, while those who use yum daily might pick `yum list installed` because it works, but the exam specifically tests knowledge of the native RPM command `rpm -qa` for direct package database queries.

How to eliminate wrong answers

Option A is wrong because `dpkg -l` is the Debian package manager command used on Debian-based systems (e.g., Ubuntu), not on Red Hat Enterprise Linux which uses RPM. Option B is wrong because `apt list --installed` is also a Debian/APT command for listing installed packages, not applicable to RHEL. Option D is wrong because `yum list installed` does display installed packages on RHEL, but the question asks for the command that displays RPM package information; while yum uses RPM under the hood, `rpm -qa` is the direct RPM command, and in the context of this exam, `yum list installed` is a higher-level tool that is not the direct RPM command being tested.

303
MCQhard

A developer reports that a Docker container on a CentOS 7 host cannot connect to the internet. The host itself can access the internet. The container is started with default bridge network. The administrator checks iptables and sees the FORWARD policy is DROP. What is the most likely cause and solution?

A.The container needs to be run with --network host.
B.The container's DNS configuration is incorrect.
C.Add iptables rules to allow forwarding and enable masquerading.
D.AppArmor is blocking outbound connections.
AnswerC

Docker's default bridge network relies on the host's IP forwarding and NAT masquerading to reach external networks. With the FORWARD chain policy set to DROP, container traffic is discarded before masquerading occurs. Adding FORWARD accept rules plus a MASQUERADE rule for the bridge subnet restores outbound connectivity, satisfying the host-forwarding constraint.

Why this answer

The default Docker bridge network relies on iptables NAT (masquerading) and FORWARD rules to allow containers to reach external networks. When the FORWARD policy is set to DROP, the host drops all forwarded packets from the container, blocking outbound internet access. Adding iptables rules to allow forwarding (e.g., `-A FORWARD -i docker0 -j ACCEPT`) and enabling masquerading (e.g., `-t nat -A POSTROUTING -s 172.17.0.0/16 -o eth0 -j MASQUERADE`) restores connectivity.

Exam trap

The trap here is that candidates may assume DNS or network mode is the issue, but the explicit mention of the FORWARD policy being DROP directly points to a missing iptables forwarding rule, which is a classic Linux networking troubleshooting scenario.

How to eliminate wrong answers

Option A is wrong because `--network host` bypasses Docker's network isolation and uses the host's network stack directly, which is unnecessary and reduces security; the issue is specifically with the default bridge and iptables forwarding, not the network mode. Option B is wrong because DNS configuration affects name resolution, not raw IP connectivity; the container cannot reach any external IP, indicating a packet forwarding problem rather than a DNS issue. Option D is wrong because AppArmor is a Linux Security Module (LSM) that confines programs via profiles, but it does not manage network forwarding or iptables policies; CentOS 7 uses SELinux by default, not AppArmor, and the symptom points to iptables, not mandatory access control.

304
MCQeasy

A Linux administrator needs to check which services are listening on TCP ports on a server. Which command should be used to replace the deprecated netstat command?

A.ss -tlnp
B.nmap localhost
C.ip link show
D.dig -t any localhost
AnswerA

The `ss -tlnp` command uses the `-t` flag to filter only TCP sockets, `-l` to show only listening sockets, `-n` to display numeric addresses and ports without DNS resolution, and `-p` to reveal the process identifier and name. This directly replaces `netstat -tlnp` by reading socket information from the kernel’s `/proc/net/tcp` and `/proc/net/tcp6` files, satisfying the stem’s requirement to check services listening on TCP ports.

Why this answer

The `ss` command is the modern replacement for `netstat`, providing socket statistics. The flags `-tlnp` specifically show TCP (`-t`) listening (`-l`) sockets with numeric ports (`-n`) and the process (`-p`) using them, which directly answers the administrator's need to see listening TCP ports and associated services.

Exam trap

The trap here is assuming that any command that can list network information (like nmap or ip) is a valid replacement for netstat, but only `ss` is designed as its direct successor with similar syntax and output.

How to eliminate wrong answers

Option B is wrong because `nmap localhost` performs a port scan, which may not show the listening process and is not a direct replacement for netstat; it also requires nmap to be installed. Option C is wrong because `ip link show` displays network interface information (Layer 2), not listening ports. Option D is wrong because `dig -t any localhost` queries DNS records for the hostname 'localhost', which is unrelated to listing listening TCP ports.

305
Multi-Selectmedium

Which TWO statements are true regarding the use of Ansible for automation? (Choose TWO.)

Select 2 answers
A.Ansible requires a dedicated master server to manage nodes.
B.Ansible playbooks are written in YAML.
C.Ansible is agentless and uses SSH for communication.
D.Ansible uses a pull-based model where nodes fetch configurations from a central server.
E.Ansible modules are written in Ruby.
AnswersB, C

YAML provides the human-readable, declarative syntax in which Ansible playbooks define tasks, plays and inventory references. This satisfies the exam's requirement for a true statement about Ansible automation, since playbooks are authored as YAML files rather than Python or shell scripts.

Why this answer

Option B is correct because Ansible playbooks are defined in YAML, a human-readable data serialization format that describes tasks, plays, and roles executed by the Ansible engine. Option C is correct because Ansible is agentless: it does not require any software installed on managed nodes and communicates over standard SSH (or WinRM for Windows hosts) to push modules and execute tasks. Option A is incorrect because Ansible can run from any control machine, including a laptop or a CI runner, and does not mandate a dedicated master server.

Option D is incorrect because Ansible uses a push-based model, where the control node pushes playbooks/modules to targets, not a pull model like Puppet or Chef agents. Option E is incorrect because Ansible modules are written in Python (or any language returning JSON), not Ruby.

Exam trap

The trap here is that candidates often confuse Ansible's push-based model with pull-based tools like Puppet or Chef, or assume a master server is required because other automation tools use a master-agent architecture.

306
MCQeasy

Based on the exhibit, what best describes the security implication?

A.The SUID bit is set, allowing users to run passwd with root privileges to change their own password.
B.The file is world-writable.
C.The SGID bit is set, allowing users to run passwd with group root.
D.The sticky bit is set, preventing deletion of the file.
AnswerA

The SUID bit on /usr/bin/passwd makes the process run with the file owner's effective UID, root, so ordinary users can update /etc/shadow. The binary restricts them to changing only their own password, which is the intended privilege escalation.

Why this answer

The SUID (Set User ID) bit is set on the /usr/bin/passwd file, as indicated by the 's' in the owner's execute position (e.g., -rwsr-xr-x). This allows any user to run the passwd command with the effective UID of the file owner (root), enabling them to change their own password by writing to /etc/shadow, which is otherwise only writable by root. This is a standard security mechanism, not a vulnerability, as the passwd binary is carefully designed to only allow password changes for the invoking user.

Exam trap

CompTIA often tests the distinction between SUID, SGID, and sticky bits by presenting a file listing with an 's' in the owner's execute position and expecting candidates to recognize it as SUID, not confusing it with SGID (which would be in the group position) or the sticky bit (which would be a 't' in the others position).

How to eliminate wrong answers

Option B is wrong because the file permissions shown (e.g., -rwsr-xr-x) indicate the file is not world-writable; the 'w' bit for 'others' is not set. Option C is wrong because the SGID bit is not set; the group execute position shows 'x' (or 's' only if SGID were set), and the group is not 'root' but typically 'shadow' or 'root' depending on the system, but the key point is that the 's' is in the owner's position, not the group's. Option D is wrong because the sticky bit is not set; the sticky bit would appear as a 't' in the 'others' execute position, and it is not present in the given permissions.

307
Drag & Dropmedium

Drag and drop the steps to configure a static IP address using the command line in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Static IP configuration involves editing the network config file and restarting the service to apply changes.

308
MCQhard

A Linux administrator is troubleshooting a systemd service that fails to start. The service unit file is located at /etc/systemd/system/myservice.service. After editing the unit file, the administrator runs systemctl start myservice, but the service still uses the old configuration. Which command should be run to ensure systemd reloads the modified unit file?

A.systemctl restart myservice
B.systemctl daemon-reload
C.systemctl reenable myservice
D.systemctl reload myservice
AnswerB

systemctl daemon-reload reloads systemd manager configuration, including all unit files. After editing a unit file, this command is necessary so systemd picks up changes. Without it, systemd continues using the cached version, causing the service to run with old settings.

Why this answer

After modifying a systemd unit file, the systemd manager must reload its configuration to recognize the changes. The systemctl daemon-reload command performs this reload, ensuring subsequent start or restart operations use the updated unit file.

Exam trap

The trap here is assuming that restarting the service is enough to apply unit file changes; systemd caches unit files until daemon-reload is executed.

309
MCQmedium

A system administrator is hardening SSH and needs to disable root login and password authentication. Which two directives should be set in /etc/ssh/sshd_config?

A.PermitRootLogin no and ChallengeResponseAuthentication no
B.DenyUsers root and PasswordAuthentication no
C.PermitRootLogin no and PasswordAuthentication no
D.PermitRootLogin prohibit-password and PasswordAuthentication yes
AnswerC

PermitRootLogin no blocks direct root SSH sessions, forcing administrators to authenticate as unprivileged users before escalating via sudo. PasswordAuthentication no disables password-based logins entirely, requiring key-based authentication instead. Together these directives satisfy both hardening constraints in the stem, eliminating brute-force and credential-guessing attack vectors against the SSH daemon.

Why this answer

Disabling root login and password authentication are two separate directives in sshd_config. PermitRootLogin no prevents direct SSH access for the root user, and PasswordAuthentication no disables password-based logins, forcing the use of key-based authentication. Both directives are required to meet the hardening goal.

Exam trap

The trap here is that candidates confuse ChallengeResponseAuthentication with PasswordAuthentication, or assume DenyUsers is a valid directive for blocking root, when the correct syntax is PermitRootLogin no.

How to eliminate wrong answers

Option A is wrong because ChallengeResponseAuthentication no disables challenge-response authentication (e.g., keyboard-interactive), but it does not disable password authentication; PasswordAuthentication must be explicitly set to no. Option B is wrong because DenyUsers root is not a valid sshd_config directive; the correct directive is PermitRootLogin no. Option D is wrong because PasswordAuthentication yes enables password authentication, which contradicts the requirement to disable it; PermitRootLogin prohibit-password allows root login with key-based authentication but does not disable password authentication for other users.

310
MCQmedium

An administrator wants to generate a self-signed certificate and private key for testing. Which command creates both in one step?

A.openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
B.openssl genrsa -out key.pem 2048
C.openssl req -new -x509 -days 365 -key key.pem -out cert.pem
D.openssl x509 -req -in req.pem -signkey key.pem -out cert.pem
AnswerA

The -x509 flag makes openssl req emit a self-signed certificate rather than a CSR, while -newkey rsa:2048 generates the private key in the same invocation. This satisfies the stem's one-step requirement, producing both key.pem and cert.pem without a separate signing command.

Why this answer

The `openssl req -x509 -newkey rsa:2048` command generates a new private key (via `-newkey`) and immediately creates a self-signed X.509 certificate (via `-x509`) in a single step. The `-keyout` and `-out` flags specify the output files for the private key and certificate, respectively, and `-nodes` ensures the private key is not encrypted with a passphrase, which is typical for testing scenarios.

Exam trap

The trap here is that candidates often confuse `openssl req -new` (which creates a CSR) with `openssl req -x509` (which creates a self-signed certificate), leading them to pick option C, which requires a pre-existing key and does not generate both in one step.

How to eliminate wrong answers

Option B is wrong because `openssl genrsa` only creates an RSA private key; it does not generate a certificate, so it fails to produce both artifacts in one step. Option C is wrong because it uses `-key key.pem` to reference an existing private key file, meaning the private key must already exist; it does not create a new private key as part of the command. Option D is wrong because `openssl x509 -req` processes a Certificate Signing Request (CSR) and signs it with a provided key; it requires a pre-existing CSR and private key, so it does not generate both in one step.

311
MCQmedium

A system administrator needs to add an iptables rule to drop incoming TCP traffic on port 22 (SSH) from the IP address 10.0.0.100. Which command should be used?

A.iptables -A INPUT -p udp --dport 22 -s 10.0.0.100 -j DROP
B.iptables -I OUTPUT -p tcp --sport 22 -d 10.0.0.100 -j DROP
C.iptables -A FORWARD -p tcp --dport 22 -s 10.0.0.100 -j DROP
D.iptables -A INPUT -p tcp --dport 22 -s 10.0.0.100 -j DROP
AnswerD

Appending to the INPUT chain with `-A` matches inbound packets, while `-p tcp --dport 22 -s 10.0.0.100` filters TCP destined for port 22 from that source, and `-j DROP` discards them silently. This satisfies the requirement to drop incoming SSH traffic from 10.0.0.100.

Why this answer

iptables -A INPUT -p tcp --dport 22 -s 10.0.0.100 -j DROP is correct because it appends a rule to the INPUT chain that matches TCP packets destined for port 22 (SSH) from source IP 10.0.0.100 and drops them. This precisely implements the requirement to block incoming SSH traffic from that specific IP address. The -p tcp specifies the protocol, --dport 22 matches the destination port, and -s sets the source address.

Exam trap

XK0-006 often tests the confusion between INPUT, OUTPUT, and FORWARD chains, and between source and destination ports; candidates may incorrectly use OUTPUT or FORWARD when the requirement is to block incoming traffic to the local system.

How to eliminate wrong answers

Option A is wrong because it uses -p udp, which matches UDP traffic, but SSH uses TCP; thus it would not block SSH. Option B is wrong because it uses the OUTPUT chain and --sport 22, which would block outgoing SSH traffic from the server to that IP, not incoming traffic. Option C is wrong because it uses the FORWARD chain, which is for packets being routed through the system, not for packets destined to the local system; incoming SSH to the server itself is handled by INPUT.

312
Multi-Selecthard

Which TWO conditions must be met for a user to successfully delete a file owned by a different user in a directory? (Choose two.)

Select 2 answers
A.The user has write permission on the file
B.The user has write permission on the directory
C.The user has execute permission on the directory
D.The user is the owner of the file
E.The user is a member of the group that owns the directory
AnswersB, C

Deleting a file modifies the directory's entries, so the kernel checks directory write permission rather than file ownership. This satisfies the stem's requirement for removing another user's file, since the file's own permissions are irrelevant to unlink.

Why this answer

To delete a file in Linux, the user does not need any permissions on the file itself; instead, the user needs write permission on the directory because deleting a file modifies the directory's contents (removing the directory entry). Additionally, execute permission on the directory is required to access the directory and its inode entries, allowing the user to traverse the directory to locate the file. These two permissions together enable the deletion of a file owned by another user.

Exam trap

The trap here is that candidates mistakenly think file write permission (Option A) or file ownership (Option D) is required for deletion, when in fact directory permissions are the sole deciding factor for removing a directory entry.

313
Multi-Selectmedium

A Linux administrator is hardening a server. Which TWO actions are effective in preventing unauthorized access via SSH? (Select TWO.)

Select 2 answers
A.Set PermitRootLogin yes
B.Set PasswordAuthentication yes
C.Disable the SSH service
D.Set PermitRootLogin no in /etc/ssh/sshd_config
E.Set PasswordAuthentication no and use SSH keys
AnswersD, E

PermitRootLogin no blocks direct root logins over SSH, forcing administrators to authenticate as an unprivileged user before escalating. This removes the highest-value target an attacker could reach through the SSH daemon, satisfying the hardening requirement.

Why this answer

Option D is correct because setting PermitRootLogin no in /etc/ssh/sshd_config prevents direct root logins over SSH, forcing attackers to compromise a normal user account first and eliminating the most privileged and commonly brute-forced target. Option E is correct because setting PasswordAuthentication no disables password-based authentication entirely, so only SSH key pairs are accepted, which defeats brute-force and credential-guessing attacks since keys cannot be feasibly guessed. The unmarked options do not belong: PermitRootLogin yes (A) explicitly allows direct root SSH access, the opposite of hardening; PasswordAuthentication yes (B) keeps password logins enabled and thus brute-forceable; and disabling the SSH service (C) would block legitimate remote administration rather than secure it, which is not a practical hardening action for a server that must be administered remotely.

Exam trap

The trap here is that candidates may think disabling the SSH service (Option C) is a valid hardening step, but the question asks for actions that prevent unauthorized access *via SSH* while still allowing legitimate remote administration.

314
Multi-Selecthard

A system administrator is investigating a performance issue and wants to view kernel-related messages. Which three commands can be used to access kernel ring buffer messages? (Choose three.)

Select 3 answers
A.tail -f /var/log/syslog
B.dmesg
C.cat /var/log/kern.log
D.journalctl -k
E.systemctl status
AnswersB, C, D

`dmesg` reads the kernel ring buffer directly, satisfying the requirement to view kernel-related messages. It exposes boot-time hardware detection, driver initialisation and runtime kernel warnings, and supports filtering by facility or severity. Unlike journal-based tools, it needs no persistent logging daemon, so it works even when systemd-journald is unavailable.

Why this answer

Option B (dmesg) is correct because dmesg directly reads and prints the kernel ring buffer, which is exactly the kernel-related message store the administrator needs. Option C (cat /var/log/kern.log) is correct because on many Linux distributions the kernel ring buffer messages are persisted to /var/log/kern.log, so reading that file exposes kernel messages. Option D (journalctl -k) is correct because the -k (or --dmesg) flag restricts systemd journal output to kernel messages only, providing access to kernel ring buffer content.

Option A (tail -f /var/log/syslog) is not correct here because syslog is a general system log that may include kernel messages only indirectly and is not the kernel ring buffer itself. Option E (systemctl status) is not correct because it reports the status of systemd units and does not display kernel ring buffer messages.

Exam trap

XK0-006 often tests whether candidates distinguish kernel-specific log access (dmesg, journalctl -k, /var/log/kern.log) from general system logs (/var/log/syslog) and service status commands (systemctl status) — picking syslog because it 'contains kernel messages' is the classic mistake.

315
MCQmedium

A Docker container needs to persistently store data that should survive container removal and be accessible by other containers. Which storage method should be used?

A.Volume
B.Bind mount
C.Container layer
D.tmpfs mount
AnswerA

Docker volumes are stored outside the container's writable layer, in a managed host directory, so their data persists after the container is removed and can be mounted by multiple containers simultaneously, satisfying both persistence and cross-container sharing.

Why this answer

Docker volumes are managed by Docker itself and stored in a dedicated area of the host filesystem (typically /var/lib/docker/volumes on Linux), which is outside the container's writable layer. Because they are independent of the container lifecycle, data in a volume persists even after the container is removed, and the same volume can be mounted into multiple containers simultaneously, enabling data sharing. This makes volumes the recommended mechanism for persistent, shareable container data.

Exam trap

The trap here is confusing bind mounts with volumes: both persist data, but only volumes are Docker-managed, portable, and shareable across containers, which is what the question's 'accessible by other containers' requirement demands.

How to eliminate wrong answers

Option B is wrong because bind mounts tie the container to a specific host path, which is less portable and not managed by Docker, so they are not the recommended method for portable persistent storage. Option C is wrong because the container layer is ephemeral — it is destroyed when the container is removed, so data written there does not survive container deletion. Option D is wrong because tmpfs mounts store data in host memory only and are removed when the container stops, providing no persistence at all.

316
MCQhard

An administrator needs to trace system calls made by a process that is misbehaving. Which command should be used to attach to the running process and display its system calls?

A.tcpdump -i any
B.ltrace -p <PID>
C.strace -p <PID>
D.lsof -p <PID>
AnswerC

`strace -p <PID>` attaches to an already-running process via ptrace and prints each system call it makes, satisfying the requirement to trace a misbehaving process without restarting it. The `-p` flag targets the live PID directly, which is exactly what the scenario demands.

Why this answer

strace is the standard Linux utility for tracing system calls made by a process. Using strace -p <PID> attaches to an already-running process and displays its system calls in real time, which is exactly what is needed to diagnose a misbehaving process at the kernel interface level. This makes it the correct tool for observing file opens, reads, writes, network calls, and signal handling.

Exam trap

The trap is confusing strace (system calls) with ltrace (library calls) — candidates who don't distinguish kernel syscalls from userspace library calls pick ltrace, or they pick lsof thinking it traces activity when it only lists open resources.

How to eliminate wrong answers

Option A is wrong because tcpdump captures network packets, not system calls, and is used for network traffic analysis rather than process-level syscall tracing. Option B is wrong because ltrace traces library calls (such as calls into libc), not system calls, so it would not show the kernel-level syscalls the question asks for. Option D is wrong because lsof lists open files and network connections held by a process, providing a snapshot rather than a live trace of system calls.

317
MCQhard

During the boot process, after the kernel is loaded and the initramfs is executed, which component is responsible for starting the user-space services and managing the system state?

A.initramfs
B.systemd
C.GRUB2
D.Kernel
AnswerB

Systemd takes over as PID 1 once the kernel hands off from initramfs, mounting remaining filesystems and activating units in dependency order to reach the requested target. It satisfies the stem's requirement for the component that starts user-space services and manages system state after initramfs execution.

Why this answer

Systemd is the init system that starts services and manages targets. GRUB2 is the bootloader that loads the kernel. The kernel itself initializes hardware.

Initramfs is an initial root filesystem used to load drivers.

318
MCQmedium

A sysadmin wants to run a containerized web application using Podman. The container needs to persist data across restarts. Which approach ensures data persistence?

A.Run the container with --restart always.
B.Mount a host directory as a volume using -v.
C.Include the data using COPY in the Dockerfile.
D.Use docker commit to save changes.
AnswerB

Binding a host directory with -v maps storage outside the container's writable layer, so data survives container restarts and recreation. The writable layer is ephemeral and is destroyed with the container, whereas the bind mount persists on the host filesystem, satisfying the persistence constraint.

Why this answer

Mounting a host directory as a volume using the `-v` flag (e.g., `podman run -v /host/path:/container/path ...`) ensures that data written inside the container is stored on the host filesystem. This data persists independently of the container's lifecycle, surviving container restarts, stops, or even removal. Podman, like Docker, treats volumes as external storage that outlives the container.

Exam trap

The trap here is that candidates confuse container restart policies (like `--restart always`) with data persistence, assuming that keeping the container running automatically preserves its data, when in fact the container's writable layer is ephemeral and lost on removal.

How to eliminate wrong answers

Option A is wrong because `--restart always` only controls the container's restart policy (e.g., after a crash or reboot), but it does not preserve data when the container is removed or its filesystem is replaced; any data written inside the container's writable layer is lost upon container deletion. Option C is wrong because the `COPY` instruction in a Dockerfile bakes data into the container image at build time, making it read-only and immutable; it cannot persist runtime data across restarts or container updates. Option D is wrong because `docker commit` creates a new image from a container's current state, which is a manual, snapshot-based approach that does not provide ongoing persistence; it also requires explicit action and bloats image layers, and is not a standard method for persistent storage in production.

319
MCQmedium

A Linux administrator is troubleshooting a service that fails to start. The audit.log shows an AVC denial related to the httpd_t domain. The administrator wants to see the full denial message and generate a policy to allow the access. Which two commands should be used in conjunction?

A.auditctl and ausearch
B.ausearch and restorecon
C.aureport and audit2why
D.ausearch and audit2allow
AnswerD

ausearch retrieves the full AVC denial records from the audit log, while audit2allow converts those denials into allow rules for a loadable policy module. Together they reveal the complete denial and generate the targeted SELinux policy.

Why this answer

`ausearch` retrieves the full AVC denial message from the audit log, and `audit2allow` generates a policy module to allow the denied access. Together, they enable the administrator to first identify the exact denial and then create a custom SELinux policy to permit the httpd_t domain's blocked action.

Exam trap

The trap here is that candidates confuse `ausearch` with `aureport` or `auditctl`, or think `restorecon` can fix AVC denials, when in fact only `ausearch` paired with `audit2allow` provides the complete solution for generating a custom policy from a denial message.

How to eliminate wrong answers

Option A is wrong because `auditctl` configures audit rules and does not retrieve denial messages, while `ausearch` alone cannot generate a policy. Option B is wrong because `restorecon` restores default SELinux contexts on files, which does not address AVC denials or generate policies. Option C is wrong because `aureport` summarizes audit events but does not produce a policy, and `audit2why` explains denials but does not generate an allow policy.

320
MCQmedium

An administrator wants to run a script every Monday at 3:00 PM using a systemd timer. Which unit file configuration is correct for the timer?

A.OnCalendar=Mon *-*-* 15:00:00
B.OnCalendar=weekly Monday 15:00
C.ExecStart=/usr/local/bin/script.sh
D.OnCalendar=daily 15:00
AnswerA

OnCalendar=Mon *-*-* 15:00:00 satisfies the Monday 3:00 PM schedule using systemd's calendar event syntax, where the weekday field precedes the date and 15:00:00 is 24-hour time. The Persistent=true directive is unnecessary here since the stem specifies no catch-up requirement for missed runs.

Why this answer

Systemd timer units use the `OnCalendar=` directive with a calendar event format that follows `DayOfWeek Year-Month-Day Hour:Minute:Second`. The pattern `Mon *-*-* 15:00:00` specifies every Monday at 15:00:00, where the asterisks act as wildcards for any year, month, and day. This matches the requirement to run a script every Monday at 3:00 PM.

Exam trap

CompTIA often tests the distinction between timer unit directives and service unit directives, and the trap here is that candidates mistakenly think `ExecStart=` belongs in the timer file or confuse the `OnCalendar=` syntax with cron-style or human-readable formats like 'weekly Monday 15:00'.

How to eliminate wrong answers

Option B is wrong because `OnCalendar=weekly Monday 15:00` is not a valid systemd calendar event format; systemd does not accept the keyword 'weekly' combined with a day name and time in that syntax, and the correct format requires a full timestamp with wildcards. Option C is wrong because `ExecStart=` is a directive for service units, not timer units; timer units use `OnCalendar=` or other time-based triggers, and `ExecStart=` would be placed in the corresponding service unit file. Option D is wrong because `OnCalendar=daily 15:00` would run the script every day at 15:00, not specifically on Mondays, failing the requirement for a weekly Monday-only schedule.

321
MCQhard

An administrator notices that an AppArmor profile is in complain mode for a service that should be enforcing. Which command changes the profile to enforce mode?

A.apparmor_parser -r /etc/apparmor.d/profile
B.aa-status --enforce /etc/apparmor.d/profile
C.aa-enforce /etc/apparmor.d/profile
D.aa-complain /etc/apparmor.d/profile
AnswerC

aa-enforce switches the named AppArmor profile from complain to enforce mode, so the kernel actively denies operations the profile disallows rather than merely logging them. Specifying the profile path targets exactly the service the stem says should be enforcing.

Why this answer

The aa-enforce command is the AppArmor userspace utility that sets a profile to enforce mode, causing the kernel to actively block operations that violate the profile. Running aa-enforce /etc/apparmor.d/profile transitions the specified profile from complain (or unconfined) to enforce. This is the standard way to harden a service after testing its profile in complain mode.

Exam trap

The trap is that candidates confuse apparmor_parser -r (reload) with mode changes — reloading a profile does not change its enforce/complain state, and aa-complain is the inverse of what's needed.

How to eliminate wrong answers

Option A is wrong because apparmor_parser -r reloads a profile from disk but does not change its mode from complain to enforce — the mode is determined by the profile file contents or by aa-complain/aa-enforce. Option B is wrong because aa-status only reports the current AppArmor state; it has no --enforce flag and cannot change profile modes. Option D is wrong because aa-complain does the opposite — it sets a profile to complain mode, which logs violations without blocking them, exactly the state the administrator wants to move away from.

322
MCQhard

An administrator is troubleshooting an AppArmor profile that is blocking a custom application. They want to set the profile to complain mode to gather violations without enforcing. Which command should they use?

A.aa-status
B.aa-complain /path/to/profile
C.apparmor_parser -r /etc/apparmor.d/profile
D.aa-enforce /path/to/profile
AnswerB

`aa-complain` switches an AppArmor profile from enforce to complain mode, logging policy violations without blocking the application. This directly satisfies the administrator's requirement to gather violations without enforcement, unlike `aa-enforce`, which would keep blocking. Passing the profile path targets that specific profile rather than all loaded profiles.

Why this answer

aa-complain sets the profile to complain mode.

323
MCQeasy

An administrator notices that the /var partition on a production server is nearly full and wants to determine which subdirectories consume the most space before deleting anything. The administrator has root privileges and wants a human-readable summary of each immediate subdirectory under /var, one line per directory. Which command accomplishes this?

A.du -sh /var/*
B.df -h /var
C.find /var -size +100M
D.ls -lhR /var
AnswerA

The du command estimates disk usage, the -s flag summarizes each argument into a single total, and -h produces human-readable sizes. Expanding /var/* passes each immediate subdirectory to du, yielding one summarized line per subdirectory. This directly identifies the largest consumers under /var, which is exactly what the administrator needs before deleting files.

Why this answer

To see which directories under /var consume the most space, du with -s and -h summarizes each argument passed via shell glob expansion, producing one human-readable line per immediate subdirectory. This gives an actionable ranking of space consumers. Filesystem-level tools like df and metadata listings like ls do not aggregate directory totals, so they cannot answer the question.

Exam trap

The trap here is confusing df, which reports filesystem capacity, with du, which reports directory consumption.

324
MCQhard

An automation engineer uses Ansible to configure a fleet of Linux servers. A playbook task installs a package and then starts a service, but the service fails to start because the package installs a configuration file only on the first run. The engineer wants the handler to notify only when the package actually changes state. Which Ansible construct ensures the service restart handler fires only when the package task reports a change?

A.Set `run_once: true` on the service handler so it executes a single time per play.
B.Use the `notify` directive on the package task referencing a handler that restarts the service.
C.Add `changed_when: true` to the package task to guarantee the handler always runs.
D.Use the `when: ansible_facts.pkg_mgr == 'apt'` conditional on the handler.
AnswerB

Handlers are only invoked when the notifying task reports `changed`, so binding the restart to the package installation via `notify` ensures the service restarts precisely when the package changes. On subsequent idempotent runs where the package is already present, the task reports `ok` and the handler does not fire, matching the requirement to act only on real state changes.

Why this answer

Ansible handlers run only when notified by a task that reports `changed`, which is exactly the behavior needed to restart a service only when its package is actually installed or upgraded. The `notify` directive wires the package task to the handler, so idempotent runs that leave the package untouched do not trigger a restart, preventing unnecessary service interruptions across the managed fleet.

Exam trap

The trap here is thinking a handler must be forced to run with `changed_when` rather than simply being notified by a genuinely changed task.

325
Multi-Selectmedium

A security audit has identified that several users have excessive sudo privileges. The administrator needs to review and modify sudo access. Which two files or commands would be used? (Choose TWO.)

Select 2 answers
A.chage
B.visudo
C.usermod -G
D./etc/sudoers
E./etc/group
AnswersB, D

`visudo` safely edits the sudoers configuration, validating syntax before saving so a malformed rule cannot lock out sudo access. It satisfies the audit requirement to review and modify excessive privileges by letting the administrator inspect and amend existing user entries, and it respects file locking to prevent concurrent edits.

Why this answer

Option B (visudo) is correct because it is the designated command for safely editing the sudo policy: it locks the sudoers file against concurrent edits, performs syntax checking before saving, and prevents a corrupt sudoers file from breaking sudo access. Option D (/etc/sudoers) is correct because it is the primary sudo policy file that defines which users and groups may run which commands as which target users, so reviewing and modifying excessive sudo privileges requires examining and changing this file. The unmarked options do not belong: chage (A) manages password aging fields such as -M, -m, and -W, not sudo rights; usermod -G (C) changes a user's supplementary group memberships, which only indirectly affects sudo if those groups are referenced in sudoers; and /etc/group (E) lists group memberships but contains no sudo command-authorization rules.

Exam trap

The trap is that candidates pick usermod -G or /etc/group thinking group membership equals sudo access — but sudo privileges are defined in /etc/sudoers, and visudo is the only safe way to edit it.

326
MCQeasy

An administrator wants to check the amount of free memory and swap usage on a system in a human-readable format. Which command should be used?

A.free -h
B.vmstat -h
C.cat /proc/meminfo
D.iostat -h
AnswerA

'free -h' reads /proc/meminfo and prints total, used and available RAM alongside swap usage, with the -h flag scaling values into human-readable units such as MiB and GiB. This directly satisfies the requirement for readable free memory and swap figures.

Why this answer

The free command displays total, used, and available physical memory and swap space, and the -h flag formats the output in human-readable units such as MiB and GiB. This directly satisfies the requirement to check free memory and swap usage in a readable format. It is the standard Linux utility for this purpose.

Exam trap

XK0-006 often tests the assumption that any command with a -h flag produces human-readable output, when in fact -h means different things (or nothing) across tools like vmstat and iostat, leading candidates away from free -h.

How to eliminate wrong answers

Option B is wrong because vmstat does not support a -h flag for human-readable output; vmstat reports virtual memory statistics in raw numbers and is used for paging and CPU activity, not formatted memory summaries. Option C is wrong because cat /proc/meminfo dumps raw kernel memory statistics in kilobytes without human-readable formatting, requiring manual conversion. Option D is wrong because iostat reports CPU and I/O device statistics, not memory or swap usage, and does not provide a human-readable memory summary.

327
MCQmedium

A system is experiencing high CPU usage due to a background process with PID 2345. The administrator wants to reduce the process's priority by 5 without stopping it. Which command should be used?

A.kill -STOP 2345
B.renice -n -5 -p 2345
C.kill -9 2345
D.renice -n +5 -p 2345
AnswerD

renice -n +5 -p 2345 raises PID 2345's nice value by 5, lowering its CPU scheduling priority without terminating it. The +5 increment and -p PID targeting match the requirement to reduce priority by 5 while keeping the process running.

Why this answer

The correct command is `renice -n +5 -p 2345` because `renice` adjusts the scheduling priority of a running process. A positive niceness value (+5) lowers the priority (makes the process 'nicer' to others), which reduces CPU usage. The `-n` flag specifies the adjustment value, and `-p` identifies the process by PID.

This matches the requirement to reduce priority by 5 without stopping the process.

Exam trap

The trap here is confusing the sign of the nice value: candidates often think a negative number reduces priority, but in Linux, a higher nice value (positive adjustment) actually lowers priority, while a negative adjustment increases it.

How to eliminate wrong answers

Option A is wrong because `kill -STOP 2345` suspends the process (sends SIGSTOP), which stops it from running entirely, rather than reducing its priority. Option B is wrong because `renice -n -5 -p 2345` increases the process's priority (makes it less 'nice'), which would worsen high CPU usage, not reduce it. Option C is wrong because `kill -9 2345` sends SIGKILL, which terminates the process immediately, violating the requirement to not stop it.

328
MCQmedium

An administrator runs the commands shown in the exhibit. The container is accessible via curl using the container IP. However, the administrator cannot access the web server using the host's IP address on port 80. What is the most likely cause?

A.The container's IP address is incorrect.
B.The container's port 80 is not published to the host.
C.Nginx is configured to listen on a different port.
D.The container is not running.
AnswerB

Docker's default bridge network isolates container ports unless explicitly published with -p. Without a published mapping, the host's IP on port 80 has no listener forwarding to the container, so only the container IP works. Publishing port 80 to the host resolves the access failure.

Why this answer

The administrator ran `docker run -d nginx` without the `-p` or `--publish` flag, which means port 80 inside the container is not mapped to any port on the host. The container is accessible via its own IP because Docker networking allows direct container-to-container communication, but the host's IP on port 80 remains unbound, so curl to the host IP fails. Publishing the port with `-p 80:80` would expose the container's port 80 on the host's interface.

Exam trap

The trap here is that candidates assume a running container with a working service is automatically accessible on the host's IP, but Docker requires explicit port publishing to bridge the host network namespace to the container's network namespace.

How to eliminate wrong answers

Option A is wrong because the container's IP address is correct—the administrator can curl the container IP successfully, proving the container is reachable at that address. Option C is wrong because Nginx inside the official nginx container listens on port 80 by default, and the successful curl to the container IP confirms the web server is responding on that port. Option D is wrong because the container is running (the `docker ps` output would show it, and curl to the container IP works), so the issue is not a stopped container.

329
MCQhard

An administrator needs to set a password expiration policy so that all users must change their password every 90 days. Which command and option accomplishes this for an existing user?

A.usermod -e 90 <username>
B.passwd -x 90 <username>
C.chage -W 90 <username>
D.chage -M 90 <username>
AnswerD

The chage command's -M option sets the maximum number of days a password remains valid before expiry. Specifying -M 90 enforces a 90-day maximum password age for the existing user, directly satisfying the stem's requirement that all users change passwords every 90 days.

Why this answer

The `chage -M 90 <username>` command sets the maximum number of days a password is valid for an existing user. The `-M` option specifies the maximum password age in days, so after 90 days the user will be forced to change their password. This directly implements the required 90-day password expiration policy.

Exam trap

The trap here is that candidates confuse the `-M` (maximum days) option with the `-W` (warning days) option, or incorrectly assume `passwd` or `usermod` can set password aging, when in fact `chage` is the dedicated utility for this purpose.

How to eliminate wrong answers

Option A is wrong because `usermod -e` sets an account expiration date (in YYYY-MM-DD format), not a password aging policy; using `-e 90` would be invalid as it expects a date, not a number of days. Option B is wrong because `passwd -x 90` sets the maximum password age, but the `passwd` command is used to change a user's own password or by root to set password attributes; however, the `-x` option is not a standard option for `passwd` on most Linux distributions (the correct command for password aging is `chage`, not `passwd`). Option C is wrong because `chage -W 90` sets the number of days before password expiration that the user receives a warning, not the maximum password age; this would warn the user 90 days before expiration, which is not the same as setting a 90-day expiration period.

330
Multi-Selectmedium

An administrator needs to identify which processes are consuming the most CPU and memory resources. Which two commands can provide this information? (Choose two.)

Select 2 answers
A.top
B.free -h
C.iostat -x
D.vmstat 1 5
E.ps aux --sort=-%mem
AnswersA, E

top presents a live, self-refreshing process list ordered by CPU consumption by default, also showing per-process memory usage. Its interactive display satisfies the requirement to identify the heaviest CPU and memory consumers in real time.

Why this answer

Option A, top, is correct because it is an interactive process monitor that displays a live, continuously refreshed list of running processes ranked by CPU usage by default, and it also shows per-process memory (RES/%MEM) so the administrator can identify the top CPU and memory consumers in one view. Option E, ps aux --sort=-%mem, is correct because it produces a static snapshot of all processes (a = all users, u = user-oriented format, x = include processes without a controlling terminal) sorted in descending order by memory percentage, which directly reveals the heaviest memory consumers and, with the aux output, their CPU usage as well. Option B, free -h, is not correct because it only reports aggregate system memory and swap usage in human-readable units, not per-process consumption.

Option C, iostat -x, is not correct because it reports extended disk I/O and CPU utilization statistics per device, not which processes are using CPU or memory. Option D, vmstat 1 5, is not correct because it samples system-wide virtual memory, CPU, and I/O statistics every second for five iterations, but it does not attribute resource usage to individual processes.

Exam trap

The key distinction is between system-wide monitoring commands (like `free`, `vmstat`, `iostat`) and per-process commands (like `top`, `ps`). Candidates mistakenly choose `free -h` or `vmstat` thinking they show per-process CPU/memory details.

331
MCQmedium

An administrator needs to find all files in /var/log that have been modified within the last 2 days. Which find command should be used?

A.find /var/log -mtime -2
B.find /var/log -mtime +2
C.find /var/log -atime -2
D.find /var/log -ctime 2
AnswerA

-mtime -2 matches files whose modification time is less than two days ago, covering the last 48 hours. The negative argument is the axis that matters: -mtime +2 would instead return files older than two days.

Why this answer

The `-mtime -2` option in `find` matches files whose data was last modified less than 2 days ago (i.e., within the last 48 hours). The minus sign means 'less than', so `-mtime -2` correctly finds files modified in the last 2 days. This is the standard way to search by modification time in Linux.

Exam trap

The trap here is confusing the sign convention: candidates often think `-mtime +2` means 'within 2 days' when it actually means 'more than 2 days ago', and they may also mix up `-mtime` with `-atime` or `-ctime`.

How to eliminate wrong answers

Option B is wrong because `-mtime +2` matches files modified more than 2 days ago (older than 48 hours), which is the opposite of what is needed. Option C is wrong because `-atime -2` checks access time (when the file was last read), not modification time; the administrator specifically asked for files modified within the last 2 days. Option D is wrong because `-ctime 2` matches files whose status (inode metadata) changed exactly 2 days ago, not within the last 2 days, and it also uses change time rather than modification time.

332
MCQhard

A Linux administrator needs to automate the deployment of a Kubernetes application from a manifest file and verify that the rollout completes successfully within a script. Which pair of actions should the script perform to apply the manifest and block until the Deployment's rollout finishes?

A.kubectl apply -f deploy.yaml followed by kubectl rollout status deployment/myapp
B.kubectl apply -f deploy.yaml followed by kubectl describe deployment/myapp
C.kubectl replace -f deploy.yaml followed by kubectl logs deployment/myapp
D.kubectl create -f deploy.yaml followed by kubectl get pods -w
AnswerA

Applying the manifest creates or updates the resources, and kubectl rollout status blocks until the Deployment's rollout completes or fails, returning a non-zero exit code on failure. This combination lets the script confirm success programmatically before proceeding to the next step in the automation workflow.

Why this answer

Idempotent automation uses kubectl apply to create or update resources from a manifest, then kubectl rollout status to block until the Deployment rollout completes, which exits non-zero on failure. Alternatives like get with watch or describe do not provide a deterministic completion signal, and create or replace are not idempotent for repeated script runs.

Exam trap

The trap here is assuming that watching pods or describing a Deployment confirms rollout success, when neither provides a reliable blocking exit status for automation.

333
MCQmedium

A team uses Ansible for configuration management. They want to ensure a service is running on all managed nodes. Which Ansible module should be used in the playbook?

A.systemd
B.service
C.command
D.shell
AnswerB

The `service` module manages service state on managed nodes, directly satisfying the requirement to ensure a service is running across all hosts. It supports `state: started` and `enabled`, unlike `command` or `shell`, which execute arbitrary commands without idempotent service-state handling. This makes it the appropriate declarative choice for the playbook.

Why this answer

The Ansible service module is the generic, cross-platform module for managing services (started, stopped, enabled, restarted) and works across systemd, SysVinit, Upstart, and other init systems. It is the correct choice when the playbook must ensure a service is running on all managed nodes regardless of the underlying init system. Using service with state: started and enabled: yes is the idiomatic way to guarantee a service is running and persists across reboots.

Exam trap

The trap is assuming systemd is always the right module because it is modern — but the question says 'all managed nodes,' implying heterogeneity, where the generic service module is safer.

How to eliminate wrong answers

Option A is wrong because the systemd module is specific to systems using systemd as the init system; it will fail on hosts using SysVinit or Upstart, so it is not the best choice for 'all managed nodes' in a heterogeneous environment. Option C is wrong because the command module runs arbitrary commands and is not idempotent for service management — it does not understand service state and would report changed every run. Option D is wrong because the shell module runs commands through a shell and, like command, lacks idempotent service-state management and is intended for shell-specific operations, not service control.

334
MCQmedium

To harden SSH, an administrator needs to disable root login over SSH. Which directive should be set in /etc/ssh/sshd_config?

A.RootLogin no
B.PermitRootLogin no
C.DenyUsers root
D.AllowUsers root
AnswerB

PermitRootLogin no directly blocks root authentication over SSH, satisfying the requirement to disable root login. The directive accepts values such as yes, no, prohibit-password and forced-commands-only; setting no rejects all root logins regardless of authentication method, which is stricter than prohibit-password. The sshd service must be reloaded for the change to take effect.

Why this answer

The correct directive in /etc/ssh/sshd_config to prevent the root account from logging in over SSH is 'PermitRootLogin no'. This is the exact keyword recognized by OpenSSH's sshd, and setting it to 'no' blocks all root logins regardless of authentication method. After editing the file, the administrator must reload or restart sshd (e.g., systemctl reload sshd) for the change to take effect.

Exam trap

XK0-006 often tests the confusion between similar-sounding directives — candidates must know the exact keyword 'PermitRootLogin' rather than plausible but invalid names like 'RootLogin' or user-list directives like DenyUsers.

How to eliminate wrong answers

Option A is wrong because 'RootLogin' is not a valid sshd_config directive — sshd would ignore it or fail to parse it, leaving root login enabled. Option C is wrong because 'DenyUsers root' is a valid directive but it is used in the context of denying specific users and is not the canonical way to disable root SSH login; more importantly, it is not the directive the question is asking for and can be overridden by AllowUsers ordering. Option D is wrong because 'AllowUsers root' does the opposite — it explicitly permits root to log in, which is the exact behavior the administrator is trying to prevent.

335
MCQmedium

A user named 'jdoe' needs to run commands as root without being given the root password. The administrator wants to grant jdoe the ability to run any command as root, but only after entering their own password. Which entry in /etc/sudoers accomplishes this?

A.jdoe ALL=(ALL) NOPASSWD: ALL
B.jdoe ALL=(root) /usr/bin/su
C.jdoe ALL= /bin/su -
D.jdoe ALL=(ALL) ALL
AnswerD

The entry jdoe ALL=(ALL) ALL grants jdoe permission to run any command as any user on all hosts, and sudo prompts for jdoe's own password by default. This satisfies both constraints: full root command access without sharing the root password.

Why this answer

The format is 'user host=(runas) commands'. The correct entry grants jdoe full root access with password authentication.

336
MCQmedium

After a system update, a custom application no longer runs due to a shared library error. The library exists on the system but is in a non-standard path. Which environment variable should be checked or set to resolve this?

A.LD_PRELOAD
B.PATH
C.LD_LIBRARY_PATH
D.LD_RUN_PATH
AnswerC

LD_LIBRARY_PATH lists extra directories the dynamic linker searches for shared objects at runtime, so exporting it to include the library's non-standard path lets the loader resolve the dependency without moving files or editing ld.so.conf. This directly satisfies the stem's constraint: the library exists but sits outside standard search paths.

Why this answer

The LD_LIBRARY_PATH environment variable tells the dynamic linker (ld.so) where to search for shared libraries before the standard system paths. When a custom application fails with a shared library error after an update, and the library exists in a non-standard path, setting LD_LIBRARY_PATH to include that path resolves the issue by allowing the linker to find the library at runtime.

Exam trap

CompTIA often tests the distinction between LD_LIBRARY_PATH (runtime library search path) and LD_RUN_PATH (link-time RPATH embedding), causing candidates to confuse the two when the question explicitly mentions a runtime error after an update.

How to eliminate wrong answers

Option A is wrong because LD_PRELOAD is used to force the loading of a specific shared library before all others, typically for overriding functions or debugging, not for adding a search path for missing libraries. Option B is wrong because PATH controls the search path for executable binaries, not for shared libraries; it is used by the shell to find commands, not by the dynamic linker. Option D is wrong because LD_RUN_PATH is used at link time (when building the application) to embed a library search path into the binary's RPATH, not at runtime to resolve a missing library after the system update.

337
MCQeasy

A system administrator is tasked with ensuring that users cannot delete files owned by other users in a shared directory. Which permission should be set on the directory?

A.Apply an ACL
B.Set the sticky bit
C.Set the SGID bit
D.Set the SUID bit
AnswerB

The sticky bit on a shared directory restricts deletion so only a file's owner, the directory owner or root may remove it. This directly prevents users from deleting files owned by others, satisfying the stated requirement.

Why this answer

The sticky bit (chmod +t) on a directory restricts deletion so that only the file owner, the directory owner, or root can remove files, even if the directory has world-writable permissions. This directly prevents users from deleting files owned by others in a shared directory, which is the requirement.

Exam trap

The trap here is that candidates often confuse the sticky bit with SUID or SGID, or think an ACL is required, but the sticky bit is the exact POSIX mechanism designed for shared directory deletion control.

How to eliminate wrong answers

Option A is wrong because an ACL (Access Control List) provides fine-grained permissions for specific users or groups but does not inherently restrict deletion to file owners; it can be configured to do so, but the standard, simplest solution is the sticky bit, not an ACL. Option C is wrong because the SGID bit (setgid) on a directory causes new files to inherit the directory's group, not restrict deletion; it addresses group ownership inheritance, not deletion prevention. Option D is wrong because the SUID bit (setuid) on a directory is ignored on most Unix/Linux systems (it has no effect on directories) and is used on executables to run with the owner's privileges, not to control file deletion.

338
MCQeasy

Which directory in the FHS contains essential user command binaries that are needed in single-user mode?

A./usr/bin
B./sbin
C./opt/bin
D./bin
AnswerD

/bin holds essential user command binaries required for single-user mode and system repair, such as ls, cp and cat. It is distinct from /sbin, which holds system administration binaries, and /usr/bin, which holds non-essential user commands.

Why this answer

The /bin directory, as defined by the Filesystem Hierarchy Standard (FHS), contains essential user command binaries (e.g., ls, cp, mv) that are required for booting, repairing, and operating the system in single-user mode. Single-user mode mounts only the root filesystem, so /bin must be on the root partition to provide these critical utilities without relying on other filesystems like /usr.

Exam trap

The trap here is that candidates confuse /sbin with /bin, assuming all essential binaries are in /sbin, but /sbin is specifically for system administration tools, while /bin holds the user command binaries required in single-user mode.

How to eliminate wrong answers

Option A is wrong because /usr/bin contains non-essential user binaries that are not guaranteed to be available in single-user mode, as /usr may be a separate filesystem that is not mounted during early boot or recovery. Option B is wrong because /sbin contains system administration binaries (e.g., fdisk, init) intended for system maintenance, not general user commands, and is separate from the user command binaries specified in the question. Option C is wrong because /opt/bin is not a standard FHS directory; /opt is reserved for add-on application software packages, and its binaries are not part of the essential system binaries needed in single-user mode.

339
Multi-Selectmedium

A Linux engineer needs to ensure a bash script runs with strict error handling. Which TWO of the following should be included? (Choose two.)

Select 2 answers
A.set -o pipefail
B.set -n
C.set -e
D.set -x
E.shopt -s histappend
AnswersA, C

set -o pipefail makes a pipeline return the rightmost non-zero exit status, so failures in earlier commands are not masked by a succeeding final command. This enforces strict error handling across pipelines, which set -e alone cannot detect.

Why this answer

Option A (set -o pipefail) is correct because it makes a pipeline return the exit status of the last command that failed rather than only the final command's status, so errors in any stage of a pipe are caught under strict error handling. Option C (set -e) is correct because it causes the shell to exit immediately when any command returns a non-zero status, which is the core of strict error handling in bash scripts. Together, set -e and set -o pipefail ensure failures are not silently ignored, which is the standard strict-mode combination.

Option B (set -n) only reads commands without executing them (syntax check), so it does not enforce error handling. Option D (set -x) merely prints commands as they execute for debugging and does not stop on errors. Option E (shopt -s histappend) only appends history to the history file instead of overwriting it, which is unrelated to script error handling.

Exam trap

CompTIA often tests the distinction between debugging options (set -x) and error-handling options (set -e, set -o pipefail), leading candidates to mistakenly choose set -x as a strict error-handling mechanism.

340
MCQmedium

In a bash script, a developer needs to parse command-line options such as -f filename and -v (verbose). Which built-in command is best suited for this task?

A.getopt
B.getopts
C.case
D.shift
AnswerB

getopts is a bash built-in that parses short options with arguments, such as -f filename, and sets OPTARG and OPTIND automatically. It handles the -v flag and option-argument pairing natively, unlike manual shifting or external parsers.

Why this answer

getopts is a bash built-in for parsing command-line options. It handles short options and requires option arguments.

341
MCQhard

An administrator is configuring a server to act as a router and needs to enable IP forwarding persistently across reboots. Which file should be modified?

A./etc/network/interfaces
B./etc/sysctl.conf
C./etc/rc.local
D./proc/sys/net/ipv4/ip_forward
AnswerB

Writing `net.ipv4.ip_forward = 1` into `/etc/sysctl.conf` makes the kernel apply the setting at every boot, satisfying the persistence requirement. The `sysctl -w` command only changes the running kernel, so it would be lost on reboot.

Why this answer

/etc/sysctl.conf is the system-wide configuration file for kernel parameters managed by sysctl. Setting net.ipv4.ip_forward = 1 in this file ensures IP forwarding is enabled persistently across reboots, as sysctl applies these settings during boot.

Exam trap

The trap here is that candidates confuse the runtime procfs file (/proc/sys/net/ipv4/ip_forward) with a persistent configuration file, leading them to choose D, which only changes the value temporarily until the next reboot.

How to eliminate wrong answers

Option A is wrong because /etc/network/interfaces is used by ifupdown to configure network interfaces (e.g., IP addresses, gateways), not to set kernel-level IP forwarding. Option C is wrong because /etc/rc.local is a legacy script for custom startup commands, but it is not the standard or recommended method for persistent kernel parameter changes; it may also not execute if the service is disabled. Option D is wrong because /proc/sys/net/ipv4/ip_forward is a runtime virtual file that changes the parameter immediately but does not persist across reboots; modifications are lost after a restart.

342
Multi-Selecthard

A security audit reveals that a service is running with an incorrect SELinux context. Which two commands can be used to relabel the file or directory to the correct context? (Choose TWO.)

Select 2 answers
A.setenforce 0
B.restorecon -R /path/to/file
C.chcon -t httpd_sys_content_t /path/to/file
D.fixfiles relabel
E.ls -Z
AnswersB, C

The `restorecon -R /path/to/file` command recursively resets SELinux contexts to the values defined in the system's file-context policy, satisfying the requirement to relabel a file or directory to its correct context. Unlike `chcon`, which applies a manually specified context, `restorecon` reads the persistent policy mapping, ensuring the audit finding is resolved durably.

Why this answer

Option B (restorecon -R /path/to/file) is correct because restorecon resets a file or directory's SELinux context to the default defined by the system's policy, and the -R flag applies this recursively to the specified path, which is exactly what is needed to fix an incorrect context. Option C (chcon -t httpd_sys_content_t /path/to/file) is correct because chcon directly changes the SELinux type of a file or directory to the specified context (here httpd_sys_content_t), allowing an administrator to manually set the correct context. Option A (setenforce 0) only switches SELinux to permissive mode and does not relabel anything.

Option D (fixfiles relabel) is a broader relabeling utility typically used to relabel the entire filesystem or all files, not to target a specific file or directory's context. Option E (ls -Z) merely displays SELinux contexts and does not modify them.

Exam trap

XK0-006 often tests the distinction between commands that modify SELinux contexts versus those that only display or change enforcement mode, and candidates may incorrectly choose 'fixfiles relabel' for a single file.

343
Multi-Selecteasy

A system administrator needs to identify which processes are consuming the most memory on a Linux server. Which two commands can be used? (Select TWO).

Select 2 answers
A.vmstat
B.ps -aux
C.free -m
D.top
E.df -h
AnswersB, D

`ps -aux` lists every process with CPU and memory percentages, letting the administrator rank memory consumers directly. It satisfies the stem's need to identify the heaviest memory users without interactive monitoring, unlike `top`, which refreshes continuously. The `-a` and `-x` flags together include processes from all users, not just the current terminal session.

Why this answer

Option B (ps -aux) is correct because it lists all running processes along with their memory usage (RSS/%MEM) and CPU usage, allowing the administrator to sort and identify the top memory consumers. Option D (top) is correct because it provides a real-time, dynamically updating view of processes sorted by resource usage, including memory, making it ideal for spotting the heaviest memory consumers interactively. Option A (vmstat) is not correct because it reports system-wide virtual memory, CPU, and I/O statistics rather than per-process memory usage.

Option C (free -m) is not correct because it only shows total, used, and free physical and swap memory in megabytes, not which processes are consuming it. Option E (df -h) is not correct because it reports filesystem disk space usage, which is unrelated to process memory consumption.

Exam trap

The trap here is that candidates confuse system-wide memory reporting commands (like `free` or `vmstat`) with per-process memory analysis tools, leading them to select options that show total memory usage rather than identifying which specific processes are consuming it.

344
MCQeasy

A junior administrator needs to view the logs of a running container named 'webapp'. Which command should be used?

A.docker attach webapp
B.docker logs webapp
C.docker inspect webapp
D.docker stats webapp
AnswerB

The docker logs command retrieves stdout and stderr output captured from a container's main process, and takes the container name or ID as its argument. Naming webapp directly targets that running container, satisfying the requirement to view its logs.

Why this answer

The `docker logs webapp` command retrieves the stdout and stderr output streams from the container's main process, which is the standard way to view logs for a running or stopped container. This is the correct approach because Docker captures these streams and stores them in a JSON file on the host, accessible via the `docker logs` command.

Exam trap

CompTIA often tests the distinction between `docker attach` (interactive session) and `docker logs` (passive log retrieval), trapping candidates who confuse attaching to a container's console with viewing its log history.

How to eliminate wrong answers

Option A is wrong because `docker attach` connects the terminal to the container's main process's stdin/stdout/stderr, which is used for interactive debugging and can block the terminal, not for viewing historical logs. Option C is wrong because `docker inspect` returns detailed metadata about the container (e.g., configuration, network settings, mounts) in JSON format, not the log output. Option D is wrong because `docker stats` displays live resource usage metrics (CPU, memory, network I/O) for running containers, not log content.

345
MCQeasy

A user cannot start the Apache web service. The command 'systemctl start httpd' returns 'Failed to start httpd.service: Unit not found.' What is the most likely cause?

A.Network configuration is incorrect
B.Incorrect file permissions on /etc/httpd/
C.The httpd package is not installed
D.Disk space is full
AnswerC

systemd reports 'Unit not found' when no unit file named httpd.service exists in its search paths, which happens when the httpd package was never installed. A stopped or masked service would still be found and produce a different error.

Why this answer

The error 'Failed to start httpd.service: Unit not found' indicates that systemd cannot locate a service unit file for httpd. This most commonly occurs when the httpd package (Apache HTTP Server) is not installed on the system. Without the package, no service unit file exists under /usr/lib/systemd/system/, so systemctl cannot start the service.

Exam trap

The trap here is that candidates may confuse a missing package with a service that is installed but not enabled or has configuration issues, leading them to select options like incorrect permissions or network configuration instead of recognizing the fundamental absence of the service unit.

How to eliminate wrong answers

Option A is wrong because an incorrect network configuration would not cause systemd to report 'Unit not found'; it would typically result in a different error such as a timeout or failure to bind to an address. Option B is wrong because incorrect file permissions on /etc/httpd/ would not prevent systemd from finding the service unit; the unit file is located in /usr/lib/systemd/system/, not in /etc/httpd/. Option D is wrong because a full disk would produce a different error, such as 'No space left on device' or a failure to write logs, not a 'Unit not found' message from systemd.

346
MCQhard

Refer to the exhibit. A user cannot access a web server, but another host on the same subnet can. What is the most likely cause?

A.The network router is blocking the user's traffic.
B.The web server is down.
C.DNS is resolving to the wrong IP for the user.
D.The user's workstation has a local firewall blocking outbound HTTPS.
AnswerD

The iptables output shows no rules, but the user's workstation gets 'Connection refused' while another host succeeds, indicating the issue is local to the workstation. A local firewall (e.g., software firewall) might be blocking outbound 443.

Why this answer

Since another host on the same subnet can reach the web server, the server itself is up and reachable, and the network path (including the router) is functional for at least some clients. The problem is isolated to the user's workstation. A local firewall on the user's machine blocking outbound HTTPS (TCP 443) would prevent that specific host from connecting while leaving other hosts unaffected, perfectly matching the symptom pattern.

Exam trap

XK0-006 often tests the misconception that network-wide issues (router, server, DNS) are the cause when the problem is isolated to a single host, leading candidates to overlook local workstation configurations like firewalls.

How to eliminate wrong answers

Option A is wrong because if the router were blocking the user's traffic, it would likely also affect the other host on the same subnet (or at least the router is not the differentiator since both hosts share the same path to the server). Option B is wrong because the web server cannot be down if another host on the same subnet is successfully accessing it. Option C is wrong because DNS resolution issues would typically affect name resolution for the user, but the scenario specifies the user cannot access the web server while another host can—if DNS were the sole issue, the user could still reach the server by IP, and DNS problems would not be isolated to a single host unless the user's DNS settings are misconfigured (which is not the most likely cause given the symptom).

347
MCQmedium

A security administrator needs to configure a Linux server so that all users must use a password of at least 12 characters and include at least one uppercase letter, one lowercase letter, one digit, and one special character. Which file should be edited to enforce these requirements?

A./etc/security/pwquality.conf
B./etc/login.defs
C./etc/shadow
D./etc/pam.d/system-auth
AnswerA

The /etc/security/pwquality.conf file is the central configuration file for the pam_pwquality module, which enforces password complexity rules. Parameters like minlen, ucredit, lcredit, dcredit, and ocredit can be set here to require minimum length and character classes. Editing this file applies the policy system-wide for all users when they change their passwords.

Why this answer

Password complexity requirements are enforced by the pam_pwquality PAM module, which reads its settings from /etc/security/pwquality.conf. This file allows administrators to set minimum length and required character classes globally. Other files like login.defs or system-auth serve different purposes and do not contain the specific parameters for password composition.

Exam trap

The trap here is assuming that /etc/pam.d/system-auth holds the password policy parameters; it only references the module, while the actual rules reside in pwquality.conf.

348
MCQeasy

A user reports that they cannot access a website by domain name but can access it by IP address. Which of the following is the most likely cause?

A.DNS resolution problem
B.Web server is down
C.Firewall blocking port 80
D.Incorrect default gateway
AnswerA

Successful access by IP address proves network routing and the web service function correctly, isolating the failure to name-to-address translation. DNS resolution is therefore the fault, since the client cannot map the domain to the reachable IP.

Why this answer

The user can access the website by IP address but not by domain name, which directly indicates that the system is unable to resolve the domain name to its corresponding IP address. This is a classic symptom of a DNS resolution problem, where the DNS client cannot query a DNS server or the DNS server fails to return the correct A or AAAA record. The fact that the web server is reachable by IP confirms that network connectivity and the web service itself are functioning correctly.

Exam trap

This question tests the distinction between connectivity issues and name resolution issues. The trap is that candidates may confuse a DNS failure with a web server or firewall problem, even though the ability to reach the server by IP clearly rules out those causes.

How to eliminate wrong answers

Option B is wrong because if the web server were down, the website would be inaccessible by both domain name and IP address, not just by domain name. Option C is wrong because a firewall blocking port 80 would prevent HTTP traffic regardless of whether the destination is specified by domain name or IP address, so both methods would fail. Option D is wrong because an incorrect default gateway would prevent all traffic destined for external networks, including both domain name resolution and direct IP access, so the user would not be able to access the site by IP address either.

349
MCQeasy

A Linux server is configured to use Pluggable Authentication Modules (PAM). Which file is used to define the authentication order for the 'sshd' service?

A./etc/authselect/sshd
B./etc/security/sshd
C./etc/pam.d/sshd
D./etc/pam.d/login
AnswerC

PAM reads per-service configuration from /etc/pam.d/, so the sshd file defines the module stack and order applied to SSH logins. Editing /etc/pam.conf or another service's file would not affect sshd, making this the file that satisfies the service-specific ordering requirement.

Why this answer

In Linux, PAM configuration files for individual services are stored in /etc/pam.d/, with the filename matching the service name. For the sshd service, the file /etc/pam.d/sshd defines the authentication order, including the modules and their control flags (e.g., required, sufficient) that PAM will consult during SSH login. This is the standard location per the Linux PAM architecture, as documented in the pam.conf man page.

Exam trap

CompTIA often tests the distinction between /etc/pam.d/sshd and /etc/pam.d/login, as candidates may confuse the SSH service file with the general login file, especially since both handle authentication but for different services.

How to eliminate wrong answers

Option A is wrong because /etc/authselect/sshd is not a standard PAM file; authselect is a tool for managing system authentication profiles, but it does not directly define per-service PAM stacks. Option B is wrong because /etc/security/sshd is not a PAM configuration file; the /etc/security/ directory typically contains files like limits.conf or access.conf, not per-service PAM definitions. Option D is wrong because /etc/pam.d/login is the PAM configuration for the login service (used for console or terminal logins), not for the SSH daemon (sshd).

350
MCQmedium

Refer to the exhibit. The system administrator runs the command 'auditctl -l' and sees the above rules. What is the purpose of these audit rules?

A.To log any changes (write or attribute) to the password, shadow, and group files
B.To log all successful login attempts on the system
C.To log any modifications to the audit configuration itself
D.To log all read accesses to /etc/passwd, /etc/shadow, and /etc/group
AnswerA

These auditctl rules watch /etc/passwd, /etc/shadow and /etc/group with write and attribute permissions, generating audit records whenever those files are modified. This satisfies the stem's requirement to log changes to the password, shadow and group files.

Why this answer

The audit rules use the `-w` flag to watch the files `/etc/passwd`, `/etc/shadow`, and `/etc/group` for `wa` (write and attribute change) syscalls. This logs any modification to these critical authentication and authorization files, such as user additions, password changes, or permission changes, which is essential for security monitoring.

Exam trap

The trap here is that candidates confuse the `-p wa` permission (write and attribute) with read access, assuming that watching these files logs all access, when in fact only modifications are recorded.

How to eliminate wrong answers

Option B is wrong because the rules watch for write and attribute changes, not login events; successful logins are typically audited via `-a exit,always -S execve` or `-w /var/log/wtmp -p wa` rules, not by watching these specific files. Option C is wrong because modifications to the audit configuration itself are logged by rules that watch `/etc/audit/audit.rules` or `/etc/audit/rules.d/`, not the password, shadow, and group files. Option D is wrong because the `-p wa` permission only captures write and attribute change operations, not read accesses; to log reads, the permission would need to be `-p r` or `-p rw`.

351
MCQeasy

A Linux administrator needs to prevent the root user from logging in via SSH. Which directive should be set in /etc/ssh/sshd_config to accomplish this?

A.PasswordAuthentication no
B.PermitRootLogin no
C.MaxAuthTries 1
D.AllowUsers root
AnswerB

PermitRootLogin no directly disables root authentication over SSH, satisfying the requirement to block root logins. The sshd daemon reads this directive at startup and rejects any authentication attempt for the root account, regardless of password or key. Other values such as prohibit-password still allow key-based root access, so only "no" fully prevents it.

Why this answer

The directive `PermitRootLogin no` in `/etc/ssh/sshd_config` explicitly disallows the root user from authenticating via SSH, regardless of the authentication method used. This is the standard way to block root SSH logins while still allowing other users to connect.

Exam trap

The trap here is that candidates often confuse `PasswordAuthentication no` with blocking root login, not realizing that root could still authenticate via SSH keys or other mechanisms if `PermitRootLogin` is not explicitly set to `no`.

How to eliminate wrong answers

Option A is wrong because `PasswordAuthentication no` disables password-based authentication for all users, but root could still log in using a public key or other methods; it does not specifically prevent root login. Option C is wrong because `MaxAuthTries 1` limits the number of authentication attempts per connection, but it does not prevent root from logging in on the first successful attempt. Option D is wrong because `AllowUsers root` explicitly permits only the root user to log in, which is the opposite of what is needed.

352
MCQmedium

An administrator needs to check the current routing table on a Linux system. Which command should be used?

A.dig -t A
B.ss -r
C.ip neigh
D.ip route
AnswerD

ip route queries the kernel's routing table through the modern iproute2 suite, listing destination networks, gateways and egress interfaces. It replaces the deprecated route command and satisfies the requirement to inspect current routing entries on the system.

Why this answer

The `ip route` command displays the kernel routing table, showing the paths that packets take to reach network destinations. This is the standard tool on modern Linux systems for viewing and manipulating routing entries, replacing the older `route -n` command.

Exam trap

The trap here is that candidates confuse `ip neigh` (which shows ARP entries) with `ip route` (which shows the routing table), as both involve network path information but serve entirely different layers of the network stack.

How to eliminate wrong answers

Option A is wrong because `dig -t A` is a DNS lookup tool that queries for A records, not a routing table viewer. Option B is wrong because `ss -r` is not a valid flag combination; `ss` is used for socket statistics, and the `-r` flag does not exist (the correct flag for resolving hostnames is `-r` in `route`, not `ss`). Option C is wrong because `ip neigh` displays the neighbor table (ARP cache), which maps IP addresses to MAC addresses on the local link, not the routing table.

353
MCQeasy

A technician is troubleshooting a network connectivity issue. They need to trace the path packets take to a remote server and see the round-trip time for each hop. Which command should they use?

A.ping
B.nslookup
C.traceroute
D.nmap
AnswerC

traceroute sends packets with incrementally increasing TTL values, causing each router along the path to return an ICMP Time Exceeded message. This reveals every hop to the remote server plus the round-trip time per hop, exactly matching the diagnostic requirement.

Why this answer

traceroute (or tracepath) shows the path and RTT per hop.

354
MCQhard

A Linux administrator is troubleshooting a Bash script that must parse each line of a file named `servers.txt` and process fields separated by colons. The script currently uses `for line in $(cat servers.txt)` and breaks on lines containing spaces. Which construct should replace the loop to correctly iterate over lines while preserving whitespace?

A.for line in $(< servers.txt); do ... done
B.while IFS= read -r line; do ... done < servers.txt
C.cat servers.txt | while read line; do ... done
D.while read -r line < servers.txt; do ... done
AnswerB

`IFS= read -r line` reads a full line without word splitting or backslash interpretation, and redirecting the file into the loop prevents the subshell problem that occurs when piping. This preserves spaces and special characters within each line. It is the standard, reliable pattern for line-by-line processing in Bash scripts.

Why this answer

Reading lines reliably requires disabling word splitting and backslash processing with `IFS= read -r line`, and attaching the input redirection to the `while` loop so the loop does not run in a subshell. Piping into the loop loses variable state, command substitution splits on whitespace, and placing the redirection on the `read` command reopens the file on each iteration instead of advancing through it.

Exam trap

The trap here is piping into `while read`, which appears to work for simple output but silently loses variable changes made inside the loop.

355
MCQhard

A server is unable to resolve hostnames via DNS. The /etc/resolv.conf file appears correct. Which command can be used to test DNS resolution and display the full query path?

A.nslookup example.com
B.host example.com
C.resolvectl query example.com
D.dig +trace example.com
AnswerD

`dig +trace` performs iterative resolution from the root servers downward, showing each delegation step to the authoritative nameserver. This satisfies the stem's requirement to display the full query path, unlike recursive tools that only report the final answer. It also bypasses `/etc/resolv.conf` recursion, isolating whether resolution itself fails.

Why this answer

The `dig +trace example.com` command performs a full iterative DNS resolution from the root nameservers down to the authoritative nameservers for the queried domain, displaying each step of the query path. This is the correct choice because the question specifically asks to 'display the full query path,' which `+trace` provides by following referrals step by step, unlike simpler queries that only show the final answer.

Exam trap

The trap here is that candidates often confuse simple DNS lookup tools (like `nslookup` or `host`) with the `dig +trace` option, assuming any DNS query tool can show the full resolution path, but only `dig +trace` explicitly performs and displays each iterative step.

How to eliminate wrong answers

Option A is wrong because `nslookup example.com` performs a recursive query to the configured DNS resolver and only returns the final answer (or an error), not the full query path. Option B is wrong because `host example.com` similarly performs a simple forward lookup and does not trace the iterative resolution steps. Option C is wrong because `resolvectl query example.com` is a systemd-resolved command that queries the local resolver cache or stub resolver, not performing a full trace of the DNS hierarchy.

356
MCQmedium

A junior administrator runs `sudo useradd -m -s /bin/bash devops` on an Ubuntu 24.04 server, then immediately tries to SSH in as devops using a key that was copied to /home/devops/.ssh/authorized_keys. The login fails with 'Permission denied (publickey)'. The sshd_config has PubkeyAuthentication yes and PasswordAuthentication no. Which command is the most appropriate next step to resolve the login failure while preserving the intended account setup?

A.Run `sudo passwd -u devops` to unlock the account, then retry SSH.
B.Append `AllowUsers devops` to /etc/ssh/sshd_config and reload sshd.
C.Run `sudo chown -R devops:devops /home/devops/.ssh && sudo chmod 700 /home/devops/.ssh && sudo chmod 600 /home/devops/.ssh/authorized_keys`.
D.Regenerate the user's key pair with `ssh-keygen -t ed25519` and re-copy the public key.
AnswerC

OpenSSH's StrictModes (default yes) rejects authorized_keys if the .ssh directory or the file is group/world-writable, or if ownership is not the target user. Because the key was copied with sudo, the files are likely owned by root. Fixing ownership to devops:devops and tightening permissions to 700/600 directly addresses the cause and preserves the intended account.

Why this answer

When sudo is used to copy a public key into a user's home, the resulting authorized_keys and .ssh directory are typically owned by root and may be group- or world-writable. OpenSSH's StrictModes then refuses to use the key and reports 'Permission denied (publickey)'. Correcting ownership to the target user and setting directory mode 700 and file mode 600 satisfies StrictModes and restores key-based login without altering the account's shell or group membership.

Exam trap

The trap here is assuming any publickey denial means the key is wrong or the account is locked, when the usual cause after a sudo copy is wrong ownership or overly permissive modes on the .ssh path.

357
Multi-Selectmedium

A Linux administrator is automating container lifecycle tasks with a script and needs to ensure a specific container, named webapp, is stopped cleanly and removed, while also removing its anonymous volumes. Which TWO docker commands should be used to accomplish this? (Choose two.)

Select 2 answers
A.docker volume prune -a
B.docker rmi webapp
C.docker rm -v webapp
D.docker stop webapp
E.docker kill webapp
AnswersC, D

Removing the stopped container with the -v flag also deletes any anonymous volumes associated with it, satisfying the requirement to clean up volumes. The container must be stopped first, which the other selected command handles, so this completes the lifecycle cleanup for the webapp container.

Why this answer

A clean container teardown involves stopping the container so its main process receives SIGTERM and can exit gracefully, then removing the container with the -v flag to delete its anonymous volumes. Using SIGKILL or broad volume pruning bypasses graceful shutdown or affects unrelated resources, and removing an image does not address the container or its volumes.

Exam trap

The trap here is reaching for docker kill or global volume pruning, which act forcefully or system-wide instead of cleanly targeting the named container and only its volumes.

358
MCQmedium

A web server running on port 8080 must be accessible from external networks. The system uses firewalld. Which command opens port 8080/tcp permanently in the default zone?

A.firewall-cmd --zone=public --add-service=8080/tcp --permanent
B.firewall-cmd --permanent --add-port=8080/tcp
C.iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
D.firewall-cmd --add-port=8080/tcp
AnswerB

The --permanent flag writes the rule into firewalld's persistent configuration rather than only the runtime zone, meeting the requirement that the port stay open across reboots or reloads. The --add-port=8080/tcp argument specifies the exact port and protocol in the default zone.

Why this answer

The correct firewalld command is 'firewall-cmd --permanent --add-port=8080/tcp' followed by '--reload'.

359
MCQhard

A Linux server in a DMZ is experiencing intermittent SSH lockouts. The /var/log/secure shows repeated failed login attempts from multiple IP addresses, but then suddenly the administrator cannot SSH in even with correct credentials. The administrator suspects a brute-force protection mechanism. The server uses PAM with pam_tally2 for login counting. The administrator checks /etc/pam.d/sshd and sees: auth required pam_tally2.so deny=3 unlock_time=300 onerr=succeed file=/var/log/tallylog. What is the most likely reason the administrator is locked out even after 5 minutes?

A.The SSH server is not configured with UsePAM yes, so pam_tally2 is not applied
B.The tallylog file has incorrect permissions, preventing pam_tally2 from reading the count
C.The root account is not subject to pam_tally2 without the 'even_deny_root' option, so the lockout is from another mechanism
D.The DenyHosts service is running and blocks IPs after too many failures
AnswerC

Correct. pam_tally2 does not apply to the root account unless the 'even_deny_root' option is added. Since the administrator is likely logging in as root, the lockout is from another source like sshd's MaxAuthTries or fail2ban.

Why this answer

Pam_tally2 does not apply to the root account unless the 'even_deny_root' option is explicitly added to the pam_tally2 configuration line. Since the administrator is likely logging in as root (or the root account is being targeted), the lockout observed is not from pam_tally2 but from another mechanism such as sshd's own MaxAuthTries or a separate service like fail2ban. The configuration shown only denies regular users after 3 failures and unlocks after 300 seconds, but root remains unaffected by this rule.

Exam trap

The trap here is that candidates assume pam_tally2 applies equally to all users, including root, without realizing the default exemption for root and the need for the 'even_deny_root' option.

How to eliminate wrong answers

Option A is wrong because the question states the server uses PAM with pam_tally2, and the administrator is checking /etc/pam.d/sshd, which implies UsePAM yes is already set; otherwise, the pam_tally2 line would have no effect at all, and the lockout behavior would not be observed. Option B is wrong because incorrect permissions on /var/log/tallylog would cause pam_tally2 to fail (potentially with onerr=succeed allowing access), not cause a lockout; the lockout is still happening, so the file is readable. Option D is wrong because while DenyHosts could cause IP-based lockouts, the question specifically states the administrator suspects a brute-force protection mechanism and checks pam_tally2; the most likely reason given the pam_tally2 configuration is the root account exemption, not an unrelated service.

360
MCQhard

A system administrator is troubleshooting a network issue on a Linux server running CentOS 7. The server is unable to connect to the internet, but internal network connections work fine. The administrator checks the network configuration: the server has a static IP 192.168.1.100/24, default gateway 192.168.1.1, and DNS server 8.8.8.8. The administrator can ping the gateway but cannot ping 8.8.8.8. From the server, a traceroute to 8.8.8.8 stops at the gateway. The administrator also notices that the route table shows a default route via 192.168.1.1. What is the most likely cause?

A.The router is not performing NAT correctly
B.The DNS server is not responding
C.The default gateway is not reachable
D.The subnet mask is incorrectly configured
AnswerA

The gateway is reachable but external pings fail and traceroute halts there, meaning packets leave the host correctly but return traffic is not translated back. A faulty NAT configuration on the router prevents private 192.168.1.100 replies from reaching the internet.

Why this answer

The server can ping the gateway (192.168.1.1) but cannot reach 8.8.8.8, and traceroute stops at the gateway. This indicates that the server’s default route is correctly configured and the gateway is reachable, but the router is not forwarding traffic beyond the local subnet. Since internal connections work, the most likely cause is that the router is not performing Network Address Translation (NAT) correctly, which is required to translate private IP addresses (192.168.x.x) to a public IP for internet access.

Exam trap

The trap here is that candidates may think a reachable gateway and a default route guarantee internet connectivity, but they overlook the necessity of NAT for private-to-public IP translation in a typical SOHO or enterprise network.

How to eliminate wrong answers

Option B is wrong because the DNS server (8.8.8.8) is being tested via ICMP ping, not DNS resolution; a non-responding DNS server would not prevent a ping to that IP. Option C is wrong because the administrator can successfully ping the default gateway (192.168.1.1), confirming it is reachable. Option D is wrong because the subnet mask /24 is correct for the 192.168.1.0/24 network, and internal connections work, so there is no subnet mismatch.

361
MCQmedium

A user cannot access a website, but other websites work. The administrator wants to see the HTTP response headers from the web server. Which command is most appropriate?

A.wget --spider https://example.com
B.curl -I https://example.com
C.curl -v https://example.com
D.telnet example.com 80
AnswerB

The -I flag makes curl issue a HEAD request, returning only the HTTP response headers without the body. This directly satisfies the administrator's goal of inspecting server headers to diagnose why one site fails while others load.

Why this answer

The curl -I command sends a HEAD request to the server and displays only the HTTP response headers. This is the most appropriate way to quickly inspect headers like status codes, content-type, and server information without downloading the body. It directly addresses the administrator's need to see response headers.

Exam trap

XK0-006 often tests the difference between curl -I (headers only) and curl -v (verbose with body), or confuses wget --spider with header inspection, but the exam expects knowledge that -I is the precise tool for headers.

How to eliminate wrong answers

Option A is wrong because wget --spider only checks if the URL is accessible (like a link checker) and does not display response headers by default. Option C is wrong because curl -v provides verbose output including headers but also includes connection details and body data, making it less focused for just headers. Option D is wrong because telnet only establishes a raw TCP connection and requires manual HTTP request crafting; it does not automatically fetch or display headers.

362
Multi-Selecthard

A Linux administrator needs to identify which of the following filesystems are journaling filesystems commonly used in Linux. (Choose three.)

Select 3 answers
A.swap
B.ext4
C.FAT32
D.btrfs
E.xfs
AnswersB, D, E

ext4 is a journaling filesystem: it maintains a journal recording pending metadata changes, so it is commonly used on Linux and satisfies the requirement to identify journaling filesystems. Its predecessor ext3 also journals, but ext4 adds extents and larger volume support.

Why this answer

ext4 (B) is a journaling filesystem that maintains a journal to record metadata changes before committing them, enabling fast recovery after crashes, and it is the default on many Linux distributions. btrfs (D) is a copy-on-write filesystem with built-in journaling-like consistency via its COW transaction mechanism, widely used in Linux for snapshots and checksumming. xfs (E) is a high-performance journaling filesystem developed by SGI and commonly used in Linux for large files and parallel I/O. swap (A) is not a filesystem for storing files but a raw swap space used for virtual memory paging, and FAT32 (C) is a non-journaling filesystem from the FAT family that lacks journaling and metadata consistency features.

Exam trap

XK0-006 often tests the distinction between journaling filesystems and non-journaling ones (FAT32) or non-filesystems (swap), catching candidates who assume any Linux storage technology counts as a journaling filesystem.

363
MCQeasy

Which command will create a compressed tar archive of a directory?

A.tar -czf archive.tar.gz dir
B.tar -xzf archive.tar.gz
C.tar -cf archive.tar dir
D.tar -tf archive.tar
AnswerA

The -c flag creates the archive, -z pipes it through gzip for compression, and -f specifies the archive filename, so tar -czf archive.tar.gz dir compresses the whole directory into one gzip archive. Omitting -z would produce an uncompressed tar, failing the compression requirement.

Why this answer

The `-czf` flags combine `-c` (create archive), `-z` (compress with gzip), and `-f` (specify archive file name). This creates a compressed tar archive of the specified directory, outputting a `.tar.gz` file. The command `tar -czf archive.tar.gz dir` is the standard syntax for this operation.

Exam trap

CompTIA often tests the distinction between create (`-c`), extract (`-x`), and list (`-t`) flags, and the requirement of `-z` for gzip compression, causing candidates to confuse `-czf` with `-xzf` or omit `-z` entirely.

How to eliminate wrong answers

Option B is wrong because `-xzf` extracts (decompresses) an existing archive, not creates one; the `-x` flag stands for extract. Option C is wrong because `-cf` creates an uncompressed tar archive (`.tar` only), missing the `-z` flag for gzip compression. Option D is wrong because `-tf` lists the contents of an existing archive without creating or compressing anything.

364
MCQmedium

A Linux administrator needs to ensure that a custom application service, implemented as a oneshot systemd unit, runs only after the network is fully online and the /data filesystem is mounted. The unit file currently has no ordering directives. Which systemd directive should be added to the [Unit] section to define these ordering dependencies?

A.Wants=network-online.target data.mount
B.Requires=network-online.target data.mount
C.Before=network-online.target data.mount
D.After=network-online.target data.mount
AnswerD

After= establishes ordering: the listed units must be activated before this service starts. It does not pull them in, but if they are already scheduled to start (e.g., via Wants= or Requires= elsewhere), the service will wait. This matches the requirement to run only after the network and filesystem are online.

Why this answer

Ordering dependencies in systemd are expressed with After= or Before=. After= ensures that the units listed are fully activated before the service starts. While Requires= or Wants= pull units into the transaction, they do not delay activation.

For a oneshot service that must wait for network-online.target and data.mount, After= is the correct directive to add to the [Unit] section.

Exam trap

The trap here is confusing requirement dependencies (Requires=, Wants=) with ordering dependencies (After=, Before=), leading to a service that starts too early despite being configured to depend on network and storage.

365
MCQeasy

A user reports that they are unable to write to a USB drive mounted at /mnt/usb. The administrator checks the mount options and sees that the drive is mounted read-only. Which command should the administrator use to remount the filesystem as read-write without unmounting it?

A.mount -o remount,rw /mnt/usb
B.mount -o rw,remount /dev/sdb1
C.fsck -y /dev/sdb1 && mount -o remount,rw /mnt/usb
D.umount /mnt/usb && mount -o rw /dev/sdb1 /mnt/usb
AnswerA

mount -o remount,rw /mnt/usb remounts the filesystem at /mnt/usb with the read-write option, without unmounting. This is the standard way to change mount options on a live filesystem, assuming the underlying device supports it and there are no errors.

Why this answer

The administrator needs to change the mount options of a mounted filesystem from read-only to read-write without unmounting. The mount command with the remount option allows this. Specifying -o remount,rw along with the mount point performs the remount in place.

This is efficient and avoids disruption to processes using the filesystem.

Exam trap

The trap here is thinking that you must unmount to change mount options, or that specifying the device instead of the mount point is sufficient for remounting.

366
MCQmedium

After updating the kernel, the system fails to boot and displays 'Error 15: File not found' from GRUB. What is the most likely cause?

A.The GRUB configuration file is missing
B.The kernel image is missing or the path in grub.cfg is incorrect
C.The initramfs image is missing
D.The hard drive has failed
AnswerB

GRUB Error 15 means the file it was told to load does not exist at the specified location, so either the kernel image was removed or the path recorded in grub.cfg no longer matches the installed kernel.

Why this answer

GRUB error 15 indicates that the specified file path in the GRUB configuration (grub.cfg) cannot be found. Since the error occurs after a kernel update, the most likely cause is that the new kernel image file is missing from the boot partition or the path in grub.cfg does not match the actual file location, preventing GRUB from loading the kernel.

Exam trap

The trap here is that candidates often confuse GRUB error 15 with a missing initramfs, but error 15 occurs specifically when the kernel image path is invalid, while a missing initramfs causes a kernel panic after the kernel starts loading.

How to eliminate wrong answers

Option A is wrong because if the GRUB configuration file itself were missing, GRUB would typically drop to a rescue shell or display a different error (e.g., 'file not found' for /boot/grub/grub.cfg), not error 15 specifically. Option C is wrong because a missing initramfs image would cause a kernel panic during boot after the kernel loads, not a GRUB error 15, which occurs before the kernel is executed. Option D is wrong because a hard drive failure would likely produce hardware-related errors (e.g., 'disk read error' or 'drive not ready') rather than a specific GRUB 'file not found' error, and the system would not reach the GRUB menu stage.

367
MCQhard

A Linux administrator writes a Bash script that processes a list of hostnames read from a file and must continue processing remaining hosts even if an SSH command to one host fails. The script currently uses set -e and exits on the first failure. Which change allows the loop to keep running while still exiting on other unhandled errors?

A.Append || true to the SSH command inside the loop.
B.Wrap the SSH command in a subshell with parentheses.
C.Replace set -e with set +e globally.
D.Redirect stderr to /dev/null on the SSH command.
AnswerA

Under set -e, a command that is part of an OR list such as cmd || true is exempt from triggering exit, because the shell only aborts when the last command in the list returns non-zero. Appending || true lets the SSH failure be tolerated for that iteration while errexit still guards the rest of the script, which is precisely the requested behavior.

Why this answer

Bash's errexit option does not trigger on commands whose failure is consumed by a logical construct. Because the shell checks the exit status of the entire AND-OR list, appending || true to the SSH invocation means the list returns zero even when SSH fails, so the loop continues. Other commands in the script remain protected by set -e, preserving the desired fail-fast behavior elsewhere.

Exam trap

The trap here is assuming set -e applies uniformly, when commands inside conditionals, AND-OR lists, or negations are exempt from triggering the exit.

368
MCQmedium

A Linux server has SELinux enabled. An administrator wants to temporarily set the SELinux mode to permissive without rebooting, then confirm the change. Which command should be used?

A.setenforce 0
B.setsebool -P httpd_can_network_connect on
C.semanage permissive -a httpd_t
D.restorecon -R /
AnswerA

setenforce 0 switches SELinux from enforcing to permissive mode immediately in the running kernel. In permissive mode, policy violations are logged but not blocked, which is exactly the temporary change requested. The command takes effect without a reboot and does not alter the persistent configuration in /etc/selinux/config.

Why this answer

The setenforce command changes the SELinux mode at runtime. Passing 0 selects permissive mode, where denials are logged but not enforced. This satisfies the requirement to switch temporarily without rebooting.

Persistent changes require editing /etc/selinux/config, but the scenario explicitly asks for a runtime change.

Exam trap

The trap here is confusing a global runtime mode change with per-domain permissive settings or boolean toggles, which affect only specific policy components.

369
MCQeasy

A Linux administrator is writing a bash script that must exit immediately if any command fails. Which of the following should be included at the beginning of the script?

A.set -e
B.set -o pipefail
C.set -u
D.set -x
AnswerA

set -e makes bash terminate the script immediately when any command returns a non-zero exit status, matching the requirement to abort on failure. Placed at the top, it governs all subsequent commands in the script.

Why this answer

`set -e` (errexit) causes the shell to exit immediately when any command returns a non-zero exit status, which is exactly the requirement for a script that must stop on the first failure. It is the standard idiom placed at the top of defensive bash scripts.

Exam trap

XK0-006 often tests the confusion between `set -e` (exit on error), `set -u` (unset variable error), `set -x` (trace), and `pipefail` (pipeline exit status), so candidates must match the exact behavior described.

How to eliminate wrong answers

Option B is wrong because `set -o pipefail` only changes the exit status of a pipeline to reflect the last failing command in the pipe — it does not by itself cause the script to exit on failure. Option C is wrong because `set -u` (nounset) causes an error when an unset variable is referenced; it does not handle command failures. Option D is wrong because `set -x` enables trace output of each command for debugging, not fail-fast behavior.

370
MCQeasy

Which of the following directories is defined by the Filesystem Hierarchy Standard (FHS) as containing essential user command binaries that need to be available in single-user mode?

A./sbin
B./opt/bin
C./usr/bin
D./bin
AnswerD

/bin holds essential user command binaries required for single-user mode, such as ls, cp and sh. The FHS reserves it precisely for binaries needed before /usr is mounted, satisfying the single-user availability constraint. Other directories like /usr/bin hold non-essential binaries that may depend on separate mounts.

Why this answer

/bin contains essential command binaries required for booting and single-user mode.

371
Multi-Selecthard

A Linux administrator is troubleshooting a system that is running out of disk space on the root filesystem. The administrator needs to identify which directories are consuming the most space. Which TWO commands can be used to find the largest directories? (Choose two.)

Select 2 answers
A.ls -lR /
B.ncdu /
C.du -sh /* | sort -rh | head -n 10
D.df -h
E.find / -type d -size +100M
AnswersB, C

ncdu is an interactive disk usage analyzer that scans a directory and displays sizes in a navigable interface. Running ncdu / will analyze the entire root filesystem and allow the administrator to drill down into large directories, making it an excellent tool for this scenario.

Why this answer

The commands du -sh /* | sort -rh | head -n 10 and ncdu / are both effective for identifying the largest directories. The du pipeline provides a quick text-based summary, while ncdu offers an interactive interface for exploration. Both directly address the need to find space-consuming directories.

Exam trap

The trap here is assuming df -h shows directory sizes, but it only shows filesystem-level usage, not per-directory breakdown.

372
MCQeasy

A Linux administrator needs to ensure that user passwords meet a minimum length requirement of 12 characters. The system uses PAM and the pam_pwquality module. Which file should the administrator edit to set the minlen parameter?

A./etc/security/pwquality.conf
B./etc/pam.d/system-auth
C./etc/security/limits.conf
D./etc/login.defs
AnswerA

The pam_pwquality module reads its configuration from /etc/security/pwquality.conf, where parameters like minlen, dcredit, and ucredit are defined. Setting minlen = 12 in this file enforces a minimum password length of 12 characters for all users, assuming the PAM stack includes pam_pwquality.

Why this answer

The pam_pwquality module's parameters, including minlen, are configured in /etc/security/pwquality.conf. This centralized file is read by the module whenever a password is set or changed, provided the PAM stack includes pam_pwquality. Other files like login.defs may contain password aging settings but do not control PAM-based quality checks.

Exam trap

The trap here is assuming that PASS_MIN_LEN in /etc/login.defs controls password length for all changes, when it is only used by certain account creation tools.

373
MCQeasy

A system administrator notices that a Linux server is running low on disk space. Which command should be used to identify which directories are consuming the most space?

A.ls -laR
B.find / -size +100M
C.df -h
D.du -h /path | sort -rh
AnswerD

du -h reports per-directory disk usage in human-readable units, and piping to sort -rh orders results largest first, immediately revealing the biggest consumers. The stem asks which directories consume the most space, matching this output.

Why this answer

The `du -h /path | sort -rh` command recursively calculates disk usage for each directory under the specified path, displays sizes in human-readable format (`-h`), and then sorts the output in reverse numerical order (`-rh`), showing the largest directories first. This directly identifies which directories are consuming the most space, which is exactly what the system administrator needs.

Exam trap

The trap here is that candidates often pick `df -h` (Option C) because it shows disk space usage, but it only reports filesystem-level totals, not per-directory breakdowns, which fails to identify the specific directories consuming space.

How to eliminate wrong answers

Option A is wrong because `ls -laR` lists all files and directories recursively with details, but it does not sum or sort disk usage; it only shows file sizes individually, making it impractical for identifying the largest directories. Option B is wrong because `find / -size +100M` finds files larger than 100 MB, not directories, and it does not aggregate disk usage per directory; it also may miss smaller files that collectively consume significant space. Option C is wrong because `df -h` reports free and used disk space on mounted filesystems, not per-directory usage; it cannot show which directories are consuming space within a filesystem.

374
MCQeasy

A technician needs to ensure a service can listen on TCP port 8443 using firewalld. Which command permanently adds the port to the default zone?

A.firewall-cmd --add-port=8443/tcp --permanent
B.firewall-cmd --add-port=8443 --permanent
C.firewall-cmd --add-port=8443/tcp
D.firewall-cmd --add-service=8443/tcp --permanent
AnswerA

The `--permanent` flag writes the rule to firewalld's persistent configuration rather than only the runtime set, satisfying the requirement to add the port permanently. Without it, the change would vanish on reload or reboot. The command targets the default zone automatically, so no `--zone` argument is needed.

Why this answer

The correct syntax is firewall-cmd --add-port=8443/tcp --permanent. The other options either omit the protocol, use incorrect syntax, or forget --permanent.

375
MCQmedium

A web server in a remote data center logs timestamps in UTC, but the operations team wants all logs to reflect the local timezone (America/New_York). Which command changes the system timezone?

A.timedatectl set-time '2025-03-01 12:00:00'
B.timedatectl set-timezone America/New_York
C.timedatectl list-timezones
D.timedatectl set-ntp yes
AnswerB

The timedatectl utility controls systemd's clock settings, and set-timezone writes the named zone to /etc/localtime, so America/New_York offsets are applied to logged timestamps. This satisfies the requirement to convert the server's UTC logging to the operations team's local timezone.

Why this answer

The `timedatectl set-timezone` command is the correct way to change the system timezone on a Linux system using systemd. By specifying 'America/New_York', the system will adjust all timestamps to Eastern Time, including those generated by the web server, ensuring logs reflect the local timezone.

Exam trap

The trap here is that candidates confuse setting the timezone with setting the time or enabling NTP, leading them to choose options that adjust the clock rather than the timezone, which does not solve the requirement for local timestamps in logs.

How to eliminate wrong answers

Option A is wrong because `timedatectl set-time` sets the system date and time, not the timezone; it would change the clock to a specific moment but leave the timezone unchanged. Option C is wrong because `timedatectl list-timezones` only displays available timezones without modifying the system configuration. Option D is wrong because `timedatectl set-ntp yes` enables or disables NTP synchronization, which adjusts the clock automatically but does not alter the timezone setting.

Page 4

Page 5 of 11

Page 6

All pages