Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 376–450

781 questions total · 11pages · All types, answers revealed

Page 5

Page 6 of 11

Page 7
376
MCQmedium

A system administrator wants to find all files in /var/log that have been modified in the last 7 days and are larger than 100MB. Which command should be used?

A.find /var/log -mtime +7 -size +100M
B.find /var/log -atime -7 -size +100M
C.find /var/log -mtime -7 -size +100M
D.find /var/log -mtime -7 -size -100M
AnswerC

The `-mtime -7` predicate matches files modified within the last seven days, while `-size +100M` filters those exceeding 100MB, both applied to the `/var/log` path. Combining these tests with implicit AND logic satisfies the stem's dual constraints of recent modification and large size in a single traversal.

Why this answer

The find command with -mtime -7 matches files modified within the last 7 days (the minus sign means 'less than 7 days ago'), and -size +100M matches files larger than 100MB (the plus sign means 'greater than'). This combination precisely satisfies both conditions.

Exam trap

XK0-006 often tests the sign convention in find time and size predicates — candidates frequently invert -mtime -7 and -mtime +7 or confuse -atime with -mtime.

How to eliminate wrong answers

Option A is wrong because -mtime +7 matches files modified more than 7 days ago, which is the opposite of the requirement. Option B is wrong because -atime -7 checks access time, not modification time — reading a file updates atime, so it would return files that were merely read, not modified. Option D is wrong because -size -100M matches files smaller than 100MB, the reverse of what is needed.

377
Multi-Selectmedium

An administrator is managing a server using systemd and needs to control services and units. Which THREE of the following are valid systemd commands for service management? (Choose three.)

Select 3 answers
A.service start
B.systemctl mask
C.systemctl start
D.systemctl enable
E.chkconfig on
AnswersB, C, D

Masks a unit, preventing it from being started.

Why this answer

B is correct because 'systemctl mask' creates a symlink to /dev/null, making a unit completely unavailable and preventing it from being started manually or by dependencies. This is a valid systemd command for service management.

Exam trap

Candidates often confuse SysV init commands (service, chkconfig) with systemd commands (systemctl). On the Linux+ exam, remember that systemd uses systemctl for service management, not the legacy SysV commands.

378
Multi-Selectmedium

A Linux administrator is troubleshooting a server that intermittently loses network connectivity. They suspect duplicate IP address conflicts on the local subnet. Which TWO commands can be used to detect whether another host is using the same IP address as the server? (Choose two.)

Select 2 answers
A.ip neigh show
B.arping -D -I eth0 192.168.1.50
C.nmap -sn 192.168.1.0/24
D.ethtool eth0
E.tcpdump -i eth0 arp
AnswersB, E

`arping -D` sends ARP probes in duplicate address detection mode. If another host replies, a duplicate IP is present. Specifying the interface with `-I eth0` and the target IP checks that address on the local segment. This is a direct and reliable method to detect IP conflicts because ARP operates at layer 2 and will receive a response from any host claiming the same address.

Why this answer

Duplicate IP detection requires either actively probing with ARP, as `arping -D` does, or passively observing ARP traffic for conflicting MAC-to-IP mappings, which `tcpdump -i eth0 arp` provides. Both methods operate at layer 2 where the conflict manifests. Commands that merely list hosts or interface settings cannot reveal two hosts claiming the same address.

Exam trap

The trap here is assuming that a ping sweep or ARP cache listing will reveal an IP conflict, when only active ARP probing or capturing ARP frames can expose two hosts using the same address.

379
MCQmedium

A Bash script contains the following function: ```bash myfunc() { local result="$(( $1 + $2 ))" echo "$result" } ``` If the script calls `myfunc 5 10`, what is the output?

A.510
B.5+10
C.the function returns nothing
D.15
AnswerD

The function adds its two positional arguments, 5 and 10, storing the arithmetic result in a local variable, then echoes it. Bash arithmetic expansion evaluates the sum to 15, which is printed as the output.

Why this answer

The function uses arithmetic expansion $(( $1 + $2 )) with positional parameters 5 and 10, which evaluates to 15. The result is stored in a local variable and echoed to stdout, so calling myfunc 5 10 prints 15.

Exam trap

The trap is confusing a function's exit status (return) with its stdout output (echo), leading candidates to select 'the function returns nothing' even though echo clearly produces visible output.

How to eliminate wrong answers

Option A is wrong because 510 would result from string concatenation (e.g., echo "$1$2"), but the arithmetic expansion $(( )) forces numeric addition. Option B is wrong because 5+10 would only appear if the expression were echoed literally without arithmetic evaluation, which is not the case here. Option C is wrong because the function explicitly echoes $result, so it does produce output; the misconception likely stems from confusing return values with stdout output.

380
Multi-Selectmedium

In a bash script, a function is defined to calculate a value. Which TWO of the following are valid ways to return a value from the function to the caller? (Select TWO).

Select 2 answers
A.exit 42
B.echo 42
C.return 42
D.return 'value'
E.print 42
AnswersB, C

Prints 42 to stdout; caller can capture with result=$(function).

Why this answer

The return statement sets the exit status (0-255). echo outputs to stdout which can be captured via command substitution. Functions cannot return arbitrary integers directly via return if >255.

381
MCQeasy

A system administrator notices that a server's disk space is critically low. Which command should be used to identify the largest files or directories consuming space?

A.ls -la /
B.fdisk -l
C.df -h
D.du -sh /*
AnswerD

`du -sh /*` reports the apparent disk usage of each top-level directory, with `-s` summarising rather than listing every file and `-h` giving human-readable sizes. This directly satisfies the stem's need to pinpoint which directories consume the most space on the critically full server.

Why this answer

`du -sh /*` recursively calculates disk usage for each top-level directory and file under root, summarizing sizes in human-readable format. This directly identifies the largest space consumers, which is the stated goal. The `-s` flag provides a total per argument, and `/*` targets all immediate children of `/`.

Exam trap

The trap here is that candidates confuse `df -h` (filesystem-level usage) with `du` (directory-level usage), mistakenly thinking `df` can identify specific large files or directories when it only shows aggregate mount-point consumption.

How to eliminate wrong answers

Option A is wrong because `ls -la /` lists file names, permissions, and metadata but does not show disk usage or sort by size, making it useless for identifying largest consumers. Option B is wrong because `fdisk -l` displays partition table information (sectors, start/end blocks) and is used for disk partitioning, not for measuring file or directory sizes. Option C is wrong because `df -h` shows free and used space on mounted filesystems as a whole, not the breakdown of which files or directories are consuming that space.

382
MCQeasy

A Linux administrator needs a scheduled task to run a backup script at 02:30 every day of the week. The system uses cron, and the administrator is editing the crontab for the `backup` user. Which crontab entry accomplishes this?

A.30 2 * * * /usr/local/bin/backup.sh
B.2 30 * * * /usr/local/bin/backup.sh
C.30 2 1 * * /usr/local/bin/backup.sh
D.* 2 * * * /usr/local/bin/backup.sh
AnswerA

The five fields of a crontab entry are minute, hour, day of month, month, and day of week. `30 2 * * *` means minute 30 of hour 2 (02:30) on every day of every month and every day of the week. This matches the requirement to run the backup script daily at 02:30.

Why this answer

A standard crontab line places minute first, then hour, day-of-month, month, and day-of-week. The requested 02:30 daily schedule requires minute 30 and hour 2 with asterisks in the remaining fields. Transposing the time fields, restricting the day of month, or leaving the minute as a wildcard all produce schedules that do not run the backup once daily at the intended time.

Exam trap

The trap here is reversing the minute and hour fields, since the larger-looking number is often mistaken for the hour.

383
MCQeasy

A Linux administrator is troubleshooting a server that has lost network connectivity. The administrator runs `ip a` and sees that the interface `ens33` is in the DOWN state and has no IP address assigned. The administrator wants to bring the interface up and assign it an IP address of 192.168.1.50/24. Which command should the administrator use?

A.ip addr add 192.168.1.50/24 dev ens33
B.ifconfig ens33 192.168.1.50 netmask 255.255.255.0 up
C.ip link set ens33 up && ip addr add 192.168.1.50/24 dev ens33
D.ip route add 192.168.1.0/24 dev ens33
AnswerC

This command sequence first brings the interface `ens33` up using `ip link set ens33 up`, then assigns the IP address with `ip addr add`. This is the correct approach because the interface must be administratively up to pass traffic. The `&&` ensures the second command runs only if the first succeeds, which is good practice.

Why this answer

To restore connectivity, the administrator must both bring the interface up and assign an IP address. The `ip link set ens33 up` command changes the administrative state to UP, and `ip addr add` assigns the address. Combining them ensures the interface is operational with the correct IP, which is the most direct solution.

Exam trap

The trap here is thinking that assigning an IP address automatically brings the interface up; in reality, the link state must be set to UP separately.

384
Multi-Selectmedium

An administrator is creating an Ansible playbook to configure multiple web servers. Which of the following are valid ways to define variables for different groups of hosts? (Choose TWO.)

Select 2 answers
A.In a group_vars directory
B.In the inventory file using :vars
C.In a host_vars directory
D.In the playbook itself using vars_files
E.In the roles directory
AnswersA, B

Variables placed in a group_vars directory apply to all hosts in the group.

Why this answer

In Ansible, group variables can be defined in a group_vars directory (A) or directly in the inventory file using the :vars suffix, such as [webservers:vars] (B). The host_vars directory (C) is used for variables specific to individual hosts, not for groups of hosts. Since the question asks for two valid ways to define variables for groups, the correct answers are A and B.

385
Multi-Selecteasy

A security team wants to implement mandatory access control (MAC) on a Linux server to confine a potentially vulnerable daemon. Which TWO of the following technologies can be used for this purpose?

Select 2 answers
A.sudo
B.AppArmor
C.SELinux
D.TCP wrappers
E.iptables
AnswersB, C

AppArmor enforces mandatory access control by applying per-program path-based profiles that confine a daemon's file, network and capability usage, independently of discretionary permissions. This satisfies the requirement to confine a potentially vulnerable daemon on Linux.

Why this answer

AppArmor (B) is a Linux Security Module that enforces mandatory access control by applying per-program profiles that restrict a daemon's file, network, and capability access, so it directly confines a vulnerable service. SELinux (C) is likewise an LSM implementing MAC through type enforcement, roles, and security contexts, and it is commonly used to sandbox daemons on Linux servers. Both are kernel-level MAC frameworks, which is exactly what the scenario requires. sudo (A) is only a privilege-delegation tool for running commands as another user and does not enforce MAC confinement.

TCP wrappers (D) provide host-based access control for network services via hosts.allow/hosts.deny, not mandatory access control. iptables (E) is a packet-filtering firewall that controls network traffic, not process-level mandatory access control.

Exam trap

The trap here is that candidates may confuse network-level controls (TCP wrappers, iptables) or privilege escalation tools (sudo) with mandatory access control, which specifically restricts what a process can do on the local system regardless of the user running it.

386
MCQeasy

Which command can be used to display the current user's effective user ID and group memberships?

A.id
B.who
C.groups
D.whoami
AnswerA

The `id` command queries the kernel for the calling process's credentials, printing the effective user ID (EUID), primary group ID and supplementary group list. This directly satisfies the stem's requirement for effective UID plus group memberships, unlike `whoami`, which returns only the username.

Why this answer

The `id` command displays the current user's real and effective user ID (UID), group ID (GID), and supplementary group memberships. It provides a comprehensive view of identity and group associations, which is essential for understanding access rights in Linux security contexts.

Exam trap

CompTIA often tests the distinction between `whoami` (which shows only the effective username) and `id` (which shows both the effective user ID and group memberships), leading candidates to choose `whoami` when the question asks for the effective user ID and group memberships together.

How to eliminate wrong answers

Option B is wrong because `who` lists currently logged-in users with session details (e.g., login time, terminal), not the effective user ID or group memberships of the current user. Option C is wrong because `groups` only shows the group memberships of the current user (or a specified user) but does not display the effective user ID or the numeric UID/GID values. Option D is wrong because `whoami` prints only the current effective username, not the numeric user ID or any group membership information.

387
MCQmedium

A service named 'myapp' is currently running but should be disabled so it does not start automatically at boot. Which command accomplishes this?

A.systemctl disable myapp
B.systemctl kill myapp
C.systemctl mask myapp
D.systemctl stop myapp
AnswerA

systemctl disable removes the unit's symbolic links from the boot target's wants directory, preventing automatic start at boot while leaving the currently running process untouched. Stopping it now would require systemctl stop, which the stem does not ask for.

Why this answer

The correct command is `systemctl disable myapp` because it removes the symlinks that cause the service to start automatically at boot, while leaving the currently running service unaffected. This directly meets the requirement of disabling automatic startup without stopping the running process.

Exam trap

The trap here is that candidates confuse 'disable' with 'stop' or 'mask', mistakenly thinking that stopping a service also prevents it from starting at boot, or that masking is the same as disabling when it actually prevents all manual and automatic starts.

How to eliminate wrong answers

Option B is wrong because `systemctl kill myapp` sends a signal to the service's processes to terminate them, which stops the service but does not prevent it from starting at boot. Option C is wrong because `systemctl mask myapp` creates a strong symlink to `/dev/null`, making the service impossible to start manually or automatically, which goes beyond the requirement of simply disabling automatic startup. Option D is wrong because `systemctl stop myapp` immediately halts the running service but does not change its boot-time enablement status, so it would still start on the next reboot.

388
MCQhard

A Linux administrator is implementing mandatory access control using AppArmor on an Ubuntu server. A custom web application profile is loaded in enforce mode, but the application is failing to write to /var/log/myapp/. The administrator wants to temporarily switch the profile to complain mode to diagnose the issue without disabling AppArmor entirely. Which command should be used?

A.aa-complain /etc/apparmor.d/usr.bin.myapp
B.aa-disable /etc/apparmor.d/usr.bin.myapp
C.aa-status --enforce /etc/apparmor.d/usr.bin.myapp
D.apparmor_parser -R /etc/apparmor.d/usr.bin.myapp
AnswerA

The aa-complain command sets the specified AppArmor profile to complain mode, where violations are logged but not blocked. This allows the application to write to the log directory while generating audit entries that reveal which rules need adjustment. It is the correct tool for temporary diagnosis without unloading the profile.

Why this answer

Switching an AppArmor profile to complain mode is done with aa-complain, which changes the profile's mode so that policy violations are logged rather than denied. This allows the application to function while capturing the necessary audit data to refine the profile. The other commands either unload the profile, disable it permanently, or merely display status, none of which achieve temporary diagnostic logging.

Exam trap

The trap here is confusing complain mode with disabling the profile, when complain mode actually keeps the profile loaded and logs violations instead of blocking them.

389
MCQeasy

Which command is used to query the status of a service managed by systemd?

A.journalctl -u servicename
B.service servicename status
C.systemctl list-units --type=service
D.systemctl status servicename
AnswerD

systemctl is the control interface for systemd units, and its status subcommand reports whether the named service is active, inactive or failed, plus recent log lines. This directly satisfies the requirement to query a systemd-managed service's current state.

Why this answer

systemctl status shows whether a service is active, enabled, and recent log entries.

390
MCQhard

An administrator runs 'auditctl -w /etc/passwd -p wa -k passwd_changes' to monitor changes to /etc/passwd. Which command should be used to search the audit log for all events related to this watch?

A.ausearch -k passwd_changes
B.auditctl -l -k passwd_changes
C.tail -f /var/log/audit/audit.log | grep passwd_changes
D.aureport -k passwd_changes
AnswerA

ausearch with -k filters the audit log by the rule's key, returning every event tagged passwd_changes. Since the watch was loaded with that exact key, this is the precise selector for retrieving all related events.

Why this answer

The `ausearch -k passwd_changes` command is correct because it searches the audit log for events that were tagged with the key `passwd_changes` when the watch was created via `auditctl -w /etc/passwd -p wa -k passwd_changes`. The `-k` option in `auditctl` assigns a key to the rule, and `ausearch` uses that same key to filter and retrieve matching audit records from `/var/log/audit/audit.log`.

Exam trap

The trap here is that candidates confuse `ausearch` (for searching logs) with `aureport` (for generating summaries) or `auditctl -l` (for listing rules), leading them to pick a command that does not actually retrieve historical audit events.

How to eliminate wrong answers

Option B is wrong because `auditctl -l -k passwd_changes` lists currently loaded audit rules, not search results from the audit log; it would show the rule itself, not events. Option C is wrong because `tail -f /var/log/audit/audit.log | grep passwd_changes` is a raw log tail with grep, which is inefficient and unreliable for structured audit log searching, and it does not use the dedicated `ausearch` tool that properly parses audit records. Option D is wrong because `aureport -k passwd_changes` generates summary reports of audit events, not a detailed event listing; it aggregates data and does not output individual audit records like `ausearch` does.

391
MCQmedium

A script receives a JSON object where keys are user IDs. Which command extracts the 'status' of user id '123'?

A.echo "$json" | jq '.status'
B.echo "$json" | jq '. | select(.id=="123") | .status'
C.echo "$json" | jq '.[] | select(.id=="123") | .status'
D.echo "$json" | jq '.["123"].status'
AnswerD

Using jq's bracket notation with a quoted key handles numeric-looking keys correctly, since `.["123"]` treats "123" as a literal string rather than an array index. This directly satisfies the stem's requirement to extract the `status` field for user ID "123" from the JSON object.

Why this answer

The JSON object uses user IDs as keys, so `.["123"]` directly accesses the object property for user ID '123', and `.status` extracts the 'status' field from that nested object. The `jq` syntax `.["key"]` is the standard way to access a property by a string key in a JSON object.

Exam trap

The trap here is that candidates often default to using `select(.id=="123")` as if the JSON were an array of objects with an 'id' field, failing to recognize that the user IDs are the object keys themselves, requiring direct key access with `.["123"]`.

How to eliminate wrong answers

Option A is wrong because `.status` attempts to access a top-level 'status' key, but the JSON object's top-level keys are user IDs, not 'status'. Option B is wrong because `. | select(.id=="123")` assumes the JSON is an array of objects with an 'id' field, but the input is an object keyed by user IDs, not an array. Option C is wrong because `.[]` iterates over the values of the object, but then `select(.id=="123")` again incorrectly expects an 'id' field within each value, whereas the user ID is the key, not a field inside the value.

392
Multi-Selecteasy

Which TWO commands can be used to change the group ownership of a file? (Choose exactly two.)

Select 2 answers
A.chmod
B.chgrp
C.groupmod
D.chown
E.usermod
AnswersB, D

`chgrp` changes a file's group owner directly, satisfying the requirement to alter group ownership. It accepts either a group name or numeric GID, and supports recursive application with `-R` for directory trees. Unlike `chown`, which modifies user and group ownership together, `chgrp` targets only the group attribute, making it the precise tool here.

Why this answer

Option B (chgrp) is correct because chgrp is the dedicated command for changing a file's group ownership, e.g. 'chgrp developers file.txt' sets the group of file.txt to developers. Option D (chown) is correct because chown can also change group ownership using the ':group' or '.group' syntax, e.g. 'chown :developers file.txt' or 'chown user:developers file.txt'. Option A (chmod) is incorrect because it modifies read/write/execute permission bits (and special bits like setgid), not the owning group itself.

Option C (groupmod) is incorrect because it modifies attributes of an existing group in /etc/group, such as its name or GID, not a file's group ownership. Option E (usermod) is incorrect because it modifies user account attributes such as group membership, home directory, or shell, not file ownership.

Exam trap

The trap here is that candidates often forget `chown` can change group ownership using the colon syntax (e.g., `chown :group file`), leading them to select only `chgrp` or incorrectly choose `chmod` or `groupmod`.

393
MCQhard

A Linux administrator is using Git to manage a configuration repository. They need to undo a commit that has already been pushed to a shared remote repository, without rewriting history. Which command should they use?

A.git rebase -i <commit>
B.git reset --hard <commit>
C.git commit --amend
D.git revert <commit>
AnswerD

`git revert` creates a new commit that undoes the changes introduced by the specified commit. This is safe for shared repositories because it does not alter existing history; it adds a new commit that reverses the changes. It is the recommended way to undo changes that have been pushed, as it preserves the commit history for all collaborators.

Why this answer

To undo a commit that has already been pushed without rewriting history, `git revert` is the correct choice. It creates a new commit that reverses the changes, preserving the original commit in the history. This is safe for collaboration because it does not require force pushing.

Other commands like `reset`, `commit --amend`, or `rebase` rewrite history and should be avoided in shared repositories.

Exam trap

The trap here is thinking that any undo operation requires rewriting history, but `git revert` specifically adds a new commit to undo changes without altering past commits.

394
MCQmedium

A Linux administrator needs to ensure that a new service, myapp.service, starts automatically at boot and is currently running. The administrator runs 'systemctl enable --now myapp.service' and receives no errors, but after a reboot the service is not running. Which of the following is the most likely cause?

A.The systemctl daemon-reload command was not run after creating the unit file.
B.The service is masked by another unit with the same name in /etc/systemd/system.
C.The service was started with systemctl start instead of systemctl enable --now.
D.The service unit file is missing the [Install] section with WantedBy=multi-user.target.
AnswerD

Without an [Install] section specifying WantedBy, systemctl enable --now creates no symlink in the target's .wants directory. The service starts now but will not start at boot because systemd has no dependency link to multi-user.target, so the enable action is effectively a no-op for boot.

Why this answer

The [Install] section defines how a unit integrates with systemd's boot targets. WantedBy=multi-user.target is what allows enable to create the symlink that pulls the service into the boot transaction. Without it, enable --now starts the unit but does not configure it for automatic startup, so after reboot the service remains inactive.

Exam trap

The trap here is assuming that enable --now guarantees boot persistence even when the unit lacks an [Install] section, which silently makes enable ineffective for boot.

395
MCQhard

A system administrator is troubleshooting a Docker container that exits immediately after starting. The container is built from a minimal image that runs a short-lived command. Which change will keep the container running?

A.Modify the Dockerfile to use CMD ["sh"] instead of CMD ["echo", "hello"]
B.Use -d flag to run in detached mode
C.Restart the container with --restart=always
D.Allocate a pseudo-TTY with -t flag
AnswerA

Replacing the one-shot `echo` with an interactive shell gives the container a long-running foreground process (PID 1), so Docker does not treat it as exited. The stem's constraint — a minimal image whose command terminates immediately — is satisfied because `sh` blocks awaiting input, keeping the container alive.

Why this answer

The container exits immediately when its main process finishes. By changing the CMD from `["echo", "hello"]` (which prints a message and exits) to `["sh"]`, the container runs an interactive shell that waits for input, keeping the process alive and the container running. In Docker, a container lives only as long as its PID 1 process runs.

Exam trap

CompTIA often tests the misconception that detached mode (`-d`) or restart policies (`--restart=always`) can keep a container running indefinitely, but the core requirement is that the container's main process must not terminate.

How to eliminate wrong answers

Option B is wrong because the `-d` flag runs the container in detached mode, but it does not change the fact that the command inside the container is short-lived; the container will still exit immediately after the command finishes. Option C is wrong because `--restart=always` only restarts the container after it exits, but it does not prevent the immediate exit; the container will keep restarting in a loop rather than staying running continuously. Option D is wrong because allocating a pseudo-TTY with `-t` does not keep the container alive; it only provides a terminal interface, but if the command finishes, the container still exits.

396
Multi-Selectmedium

In an Ansible playbook, which THREE of the following are valid modules for managing files and packages? (Select THREE).

Select 3 answers
A.get_url
B.copy
C.apt
D.file
E.command
AnswersB, C, D

Copies files to remote hosts.

Why this answer

(copy) is correct because the copy module is a dedicated Ansible module for copying files from the local control node to remote hosts, supporting attributes like owner, permissions, and content. It is the standard idempotent way to manage file distribution in playbooks.

Exam trap

CompTIA Linux+ often tests the distinction between modules that manage state (copy, file, apt) versus modules that execute commands (command) or retrieve remote content (get_url), trapping candidates who think any module that touches a file is a 'file management' module.

397
MCQhard

A Linux system is using systemd and a service fails to start. The administrator checks the service journal and sees: 'Failed to start service: Unit not found'. However, the service file exists in /etc/systemd/system/. What is the most likely cause?

A.The service is masked
B.systemd has not been reloaded (systemctl daemon-reload)
C.The service file has incorrect permissions
D.The service is enabled but not started
AnswerB

systemd caches unit files; a newly created or edited unit in /etc/systemd/system/ remains unknown until systemctl daemon-reload regenerates the dependency tree. Without that reload, systemd reports 'Unit not found' even though the file exists on disk.

Why this answer

When a service file is added or modified in /etc/systemd/system/, systemd does not automatically re-read the unit files. The administrator must run 'systemctl daemon-reload' to instruct systemd to scan for new or changed unit files. Without this reload, systemd still references its cached list of units, resulting in 'Unit not found' even though the file exists on disk.

Exam trap

The trap here is that candidates assume systemd automatically detects new unit files in the filesystem, when in fact it requires an explicit 'daemon-reload' to refresh its unit cache.

How to eliminate wrong answers

Option A is wrong because a masked service would produce a different error message, such as 'Unit is masked', not 'Unit not found'. Option C is wrong because systemd unit files with incorrect permissions (e.g., not readable by root) would typically cause a 'Permission denied' error or a failure to load the unit, not a 'Unit not found' message. Option D is wrong because 'enabled but not started' describes a service that is configured to start at boot but is currently stopped; this would not cause a 'Unit not found' error when attempting to start it manually.

398
MCQmedium

A Linux administrator needs to allow members of the group 'developers' to run all commands as root without being prompted for a password, but only from the host 'build01'. The administrator adds the following line to /etc/sudoers: '%developers build01=(ALL) NOPASSWD: ALL'. After saving, users report that sudo still prompts for a password on build01. Which command should the administrator run to verify the syntax and placement of the rule?

A.visudo -c
B.grep developers /etc/sudoers
C.sudo -l -U developer1
D.sudo -V
AnswerA

Running visudo -c checks the sudoers file for syntax errors and reports the parsed result, confirming whether the rule is syntactically valid. It does not enforce placement, but it will reveal if the line was inserted in a way that breaks parsing or if an earlier conflicting rule exists. This is the standard validation step before troubleshooting further.

Why this answer

The correct command is visudo -c, which parses the sudoers file and reports syntax errors. Because the rule was added manually, a syntax mistake or misplacement could cause sudo to ignore it or fail. Validating with visudo -c ensures the file is well-formed before investigating effective privileges with sudo -l.

Exam trap

The trap here is assuming that listing a user's sudo privileges validates the sudoers file syntax, when only visudo -c performs that check.

399
MCQmedium

A process is consuming excessive CPU and needs to be stopped immediately. The process ID is 4582. Which command should be used?

A.kill -9 4582
B.kill -1 4582
C.kill -STOP 4582
D.kill -15 4582
AnswerA

SIGKILL (signal 9) cannot be caught, blocked, or ignored by the process, so the kernel terminates PID 4582 immediately without waiting for cleanup. This satisfies the stem's requirement to stop the runaway process at once, unlike SIGTERM, which the process may handle or defer.

Why this answer

The `kill -9 4582` command sends SIGKILL (signal 9) to process ID 4582, which forcibly terminates the process immediately without allowing it to clean up. This is the correct choice when a process is consuming excessive CPU and must be stopped immediately, as SIGKILL cannot be caught or ignored.

Exam trap

The trap is thinking SIGTERM (15) is immediate; candidates often pick `kill -15` as the default, but the question specifies 'immediately', which requires SIGKILL (9).

How to eliminate wrong answers

Option B is wrong because `kill -1` sends SIGHUP (signal 1), which typically causes a process to reload configuration or terminate, but it can be caught or ignored. Option C is wrong because `kill -STOP` sends SIGSTOP, which pauses the process but does not terminate it; it remains in memory. Option D is wrong because `kill -15` sends SIGTERM, the default termination signal, which allows the process to perform cleanup and can be caught or ignored, so it may not stop a runaway process immediately.

400
MCQhard

A Bash script uses getopts to parse command-line options. The script is invoked as: ./script -a -b value. Which getopts string should be used to correctly parse -a (no argument) and -b (requires an argument)?

A."ab:"
B.":ab"
C."ab"
D."a:b"
AnswerA

The trailing colon after b declares that -b consumes an argument, while the bare a marks -a as a flag taking none. This matches the invocation ./script -a -b value, where getopts assigns value to OPTARG for -b and leaves -a argument-free.

Why this answer

In getopts, a colon after a letter indicates that the option requires an argument. The string 'ab:' means -a takes no argument and -b requires an argument. This matches the invocation './script -a -b value'.

Exam trap

XK0-006 often tests the meaning of colons in getopts strings; candidates may reverse the requirement, thinking a colon means no argument, or forget that the colon must follow the option letter.

How to eliminate wrong answers

Option B is wrong because ':ab' means -a requires an argument and -b takes no argument, which is the opposite of what is needed. Option C is wrong because 'ab' means both -a and -b take no arguments, so -b would not consume 'value'. Option D is wrong because 'a:b' means -a requires an argument and -b takes no argument, again the opposite.

401
MCQeasy

A Linux administrator writes a Bash script and includes the line `#!/bin/bash` at the top. What is the purpose of this line?

A.It sets the script to run in the background.
B.It enables debugging mode.
C.It specifies the interpreter to execute the script.
D.It defines a variable for the script.
AnswerC

The shebang instructs the kernel to launch the named program, here `/bin/bash`, to interpret the script's contents when executed directly. This satisfies the stem's requirement that the line defines which interpreter runs the file, rather than the current shell or a compiled binary.

Why this answer

The `#!/bin/bash` line is a shebang that tells the operating system which interpreter to use when executing the script. When the script is run as an executable, the kernel reads this line and invokes `/bin/bash` to process the file.

Exam trap

XK0-006 often tests whether candidates confuse the shebang with runtime options like `set -x` or with shell invocation flags, so they must recognize it purely as interpreter selection.

How to eliminate wrong answers

Option A is wrong because background execution is controlled by appending `&` when invoking the script, not by the shebang line. Option B is wrong because debugging mode is enabled with `set -x` or by running `bash -x script.sh`, not by the shebang. Option D is wrong because variable definitions use `name=value` syntax; the shebang has no variable-assignment role.

402
Multi-Selectmedium

A security administrator is hardening a Linux web server and wants to reduce the attack surface of the SSH service. Which TWO actions should be taken in /etc/ssh/sshd_config to restrict access and authentication? (Choose two.)

Select 2 answers
A.Set MaxAuthTries to 10
B.Set UsePAM to no
C.Set X11Forwarding to yes
D.Set PermitRootLogin to no
E.Set PasswordAuthentication to no
AnswersD, E

Disabling direct root logins forces administrators to authenticate as a normal user and then escalate privileges, which adds accountability and reduces the impact of brute-force attacks against the root account. This is a standard SSH hardening measure and directly limits a high-value authentication path on the web server.

Why this answer

Disabling root login and password authentication are two widely recommended SSH hardening measures. They force administrators to use named accounts and key-based authentication, reducing the effectiveness of brute-force and credential-stuffing attacks. The other listed changes either increase exposure or weaken authentication controls, so they do not support the goal of reducing the SSH attack surface.

Exam trap

The trap here is assuming that increasing MaxAuthTries or enabling X11Forwarding improves security, when both actually expand the attack surface.

403
Multi-Selectmedium

An administrator needs to verify DNS resolution for a web server. Which TWO commands can be used to query DNS A records for a given hostname? (Choose two.)

Select 2 answers
A.traceroute
B.nslookup
C.ping
D.dig
E.curl -I
AnswersB, D

The `nslookup` utility queries DNS servers directly and returns A records mapping a hostname to its IPv4 address, satisfying the requirement to verify DNS resolution for the web server. It supports both interactive and non-interactive modes, letting the administrator specify the target hostname and confirm the resolved address.

Why this answer

Option B (nslookup) is correct because it is a dedicated DNS query tool that, by default, resolves a hostname to its A record (IPv4 address) by querying the configured DNS resolver, and it can also be used interactively to specify record types. Option D (dig) is correct because it is a DNS lookup utility that explicitly queries DNS records; running 'dig hostname A' returns the A record along with authoritative server and query details. Option A (traceroute) is incorrect because it maps the network path to a host using TTL-limited packets, not DNS record queries.

Option C (ping) is incorrect because although it resolves a hostname to an IP via the resolver, it is an ICMP reachability test rather than a DNS query tool and does not let you query specific record types. Option E (curl -I) is incorrect because it sends an HTTP HEAD request to fetch response headers, not a DNS A record query.

Exam trap

The trap is that ping and traceroute appear to 'use DNS' because they resolve hostnames, leading candidates to think they can query A records — but they only perform forward resolution as a side effect, not a queryable DNS lookup.

404
Multi-Selectmedium

A systems administrator wants to monitor system performance in real time. Which TWO commands can be used to display live updating information about processes, CPU, and memory usage? (Select TWO.)

Select 2 answers
A.top
B.htop
C.ps aux
D.sar -u 1 5
E.vmstat 1
AnswersA, B

`top` refreshes process, CPU and memory statistics continuously in the terminal, satisfying the real-time monitoring requirement. Unlike snapshot tools such as `ps`, it updates its display on an interval until quit, letting the administrator observe live resource consumption as it changes.

Why this answer

Option A, top, is correct because it launches an interactive, continuously refreshing view of running processes along with live CPU and memory utilization, updating by default every few seconds until you quit. Option B, htop, is also correct because it is an enhanced interactive process viewer that likewise refreshes in real time and displays per-process CPU and memory statistics in a full-screen, live-updating interface. Option C, ps aux, is not correct because ps produces a one-time static snapshot of current processes and exits immediately rather than updating live.

Option D, sar -u 1 5, is not correct because although it samples CPU utilization at one-second intervals for five iterations, it reports historical/interval statistics rather than an interactive live-updating display. Option E, vmstat 1, is not correct because it prints periodic one-second samples of virtual memory, CPU, and I/O statistics to standard output but does not provide the live, interactive process-level monitoring the scenario requires.

Exam trap

The trap here is that candidates often confuse static commands like `ps aux` with live monitoring tools, or they mistake `vmstat 1` for a process-level viewer when it actually provides aggregate system statistics without per-process details.

405
MCQhard

A server running a critical application needs to be rebooted. To ensure the application stops gracefully and data is not corrupted, which sequence of commands should the administrator use?

A.killall -9 application; reboot
B.reboot
C.systemctl stop application; sync; reboot
D.umount -a; reboot
AnswerC

Stopping the application first halts writes and flushes its buffers, then sync forces pending filesystem data to disk before reboot. This ordering prevents data corruption, satisfying the graceful shutdown and data-integrity constraint in the stem.

Why this answer

It first uses systemctl to send a SIGTERM to the application, allowing it to perform a graceful shutdown and flush its data. The sync command then forces any pending disk writes to complete, ensuring filesystem consistency before the reboot. This sequence minimizes the risk of data corruption by giving the application and kernel time to finalize all I/O operations.

Exam trap

CompTIA often tests the misconception that a simple reboot or killall -9 is sufficient for critical applications, but the trap here is that candidates overlook the need for a graceful stop and filesystem sync to prevent data corruption.

How to eliminate wrong answers

Option A is wrong because killall -9 sends SIGKILL, which immediately terminates the application without allowing it to clean up resources or flush data, potentially causing corruption. Option B is wrong because a plain reboot command does not explicitly stop the application or sync the filesystem, relying on the system's shutdown scripts which may not handle the critical application gracefully. Option D is wrong because umount -a attempts to unmount all filesystems, which will fail if any filesystem is busy (e.g., the application has open files), and it does not stop the application first, leading to forced unmounts or data loss.

406
MCQeasy

A security audit reveals a misconfiguration. Which file has insecure permissions that could allow unauthorized users to read password hashes?

A.Both files are misconfigured
B./etc/shadow
C.Neither file has a misconfiguration
D./etc/passwd
AnswerB

/etc/shadow stores password hashes and must be readable only by root, typically mode 000 or 640 with group shadow. Insecure permissions such as world-readable allow any local user to copy hashes for offline cracking. This directly satisfies the audit's requirement to identify the file exposing password hashes.

Why this answer

The /etc/shadow file stores password hashes and should be readable only by the root user (typically permissions 640 or 600). If its permissions are too permissive (e.g., world-readable), any local user could read the hashes and attempt offline cracking. This is the misconfiguration the audit would flag.

Exam trap

CompTIA often tests the misconception that /etc/passwd contains password hashes (as it did in older Unix systems), but modern Linux distributions use shadow passwords, so the hashes are exclusively in /etc/shadow.

How to eliminate wrong answers

Option A is wrong because only one file (the shadow file) is the typical target for insecure permissions on password hashes; both files being misconfigured is not the standard finding. Option C is wrong because a misconfiguration does exist in the shadow file, so 'neither file has a misconfiguration' is false. Option D is wrong because /etc/passwd traditionally stores user account information (UID, GID, home directory, shell) but not password hashes (which are stored in /etc/shadow on modern Linux systems using shadow passwords); even if /etc/passwd is world-readable by design, it does not contain the hashes, so its permissions are not the direct security concern for reading password hashes.

407
Multi-Selectmedium

An administrator is building a container image and needs to reduce its final size while keeping the build reproducible. Which TWO practices improve image efficiency and build reliability? (Choose two.)

Select 2 answers
A.Combine related RUN instructions and clean package caches within the same layer.
B.Add a .dockerignore file that excludes the local .git directory and build artifacts.
C.Use multiple FROM instructions to layer several base images into one final image.
D.Set the ENV HOME variable to a writable path so package managers cache downloads there.
E.Pin base image and package versions to specific tags or digests instead of using latest.
AnswersA, E

Each RUN creates a layer, and deleting files in a later layer only masks them, leaving their bytes in the image. Chaining commands with && and removing caches such as /var/lib/apt/lists in the same RUN prevents that bloat. This keeps the final image smaller and the build deterministic, which matches the stated goal.

Why this answer

Image efficiency hinges on layer mechanics: files removed in a later layer still occupy the earlier one, so cleanup must happen in the same RUN that created the mess. Reproducibility hinges on locked inputs, so base images and packages should be referenced by exact version or digest rather than a moving tag. Combining those two disciplines yields smaller, repeatable builds.

Exam trap

The trap here is believing that deleting a package cache in a separate RUN shrinks the image, when the earlier layer still carries those bytes.

408
MCQmedium

A Linux administrator needs to permanently set the system-wide umask to 027 for all users on a production server. The administrator edits /etc/profile and adds the line 'umask 027'. After rebooting, a user logs in and runs 'umask', which returns 0022. Which of the following is the most likely reason the setting did not take effect?

A.The user's shell configuration file, such as ~/.bashrc or ~/.profile, overrides the umask set in /etc/profile.
B.The umask command must be run with sudo to affect all users.
C.The umask value must be set in /etc/login.defs to apply system-wide.
D.The system needs to be rebooted for changes to /etc/profile to take effect.
AnswerA

User-specific shell initialization files like ~/.bashrc or ~/.profile are sourced after /etc/profile and can override the umask. If the user's file contains a umask command, it will take precedence. This is the most common reason a system-wide umask in /etc/profile appears ineffective, as the user's environment resets the value during login.

Why this answer

The umask is set per process and inherited. System-wide defaults in /etc/profile apply to login shells, but user-specific files like ~/.bashrc or ~/.profile are sourced later and can override the umask. Since the user's umask returned 0022, it indicates a user-level configuration is taking precedence.

To enforce a system-wide umask, administrators must ensure user files do not override it or use mechanisms like pam_umask.

Exam trap

The trap here is assuming that editing /etc/profile alone guarantees a system-wide umask, overlooking that per-user shell configuration files are sourced afterward and can override it.

409
MCQmedium

A developer is writing a Dockerfile. The application requires a configuration file that should be copied from the build context and the container should expose port 8080. Which combination of Dockerfile instructions is correct?

A.COPY config.txt /app/ and EXPOSE 8080
B.ADD config.txt /app/ and WORKDIR 8080
C.ADD config.txt /app/ and RUN expose 8080
D.COPY config.txt /app/ and CMD 8080
AnswerA

COPY transfers config.txt from the build context into the image at /app/, satisfying the file requirement, while EXPOSE 8080 documents the port the container listens on at runtime. Both instructions match the stem's constraints precisely, unlike ADD, which also handles remote URLs and archives unnecessarily here.

Why this answer

COPY adds files from the build context, and EXPOSE documents the port. Other instructions serve different purposes.

410
MCQmedium

An administrator wants to ensure a service starts automatically at boot on a systemd-based system. Which command should be used?

A.systemctl enable service
B.systemctl start service
C.systemctl status service
D.systemctl reload service
AnswerA

`systemctl enable service` creates the symlinks that pull the unit into the boot transaction, so the service starts automatically at every boot on a systemd-based host. It satisfies the stem's requirement directly; `start` only launches it for the current session and does not persist across reboots.

Why this answer

On systemd-based systems, 'systemctl enable <service>' creates the necessary symlinks (typically in /etc/systemd/system/) so that the service is started automatically at boot. It does not start the service immediately; it only configures it for future boots.

Exam trap

XK0-006 often tests whether candidates confuse 'enable' (boot persistence) with 'start' (immediate start), leading them to pick 'start' when the question asks for automatic startup at boot.

How to eliminate wrong answers

Option B is wrong because 'systemctl start <service>' starts the service immediately but does not configure it to start at boot. Option C is wrong because 'systemctl status <service>' only displays the current status of the service, it does not change its boot behavior. Option D is wrong because 'systemctl reload <service>' reloads the service's configuration without restarting it, and does not affect boot-time startup.

411
MCQhard

A Linux administrator notices that a server's clock is drifting and NTP synchronization is failing. The administrator runs 'chronyc sources' and sees that all sources are marked with a '?' character. Which command should be run next to diagnose why chronyd cannot reach the NTP servers?

A.chronyc ntpdata
B.chronyc tracking
C.chronyc activity
D.chronyc sourcestats
AnswerA

chronyc ntpdata displays detailed NTP packet information for each configured source, including the source address, mode, stratum, and whether packets are being received. When a source shows '?', it indicates that no valid packets have been received recently. ntpdata will reveal if packets are being sent but not returned, or if there are errors, helping diagnose firewall, routing, or server issues.

Why this answer

The '?' character in chronyc sources means the source is unreachable or has not provided a valid packet. To diagnose why, chronyc ntpdata shows per-source packet details, including whether NTP requests are being sent and responses received. This helps identify network blocks, incorrect server addresses, or firewall rules.

Other chronyc subcommands like tracking, activity, and sourcestats do not provide the packet-level view needed for this specific failure.

Exam trap

The trap here is confusing the '?' state with a simple lack of synchronization, when it actually indicates the source is unreachable and requires packet-level diagnosis.

412
MCQeasy

A system fails to boot after installing a new SATA disk. The BIOS recognizes the disk. What is the most likely cause?

A.GRUB configuration is corrupted
B.Boot order is incorrect
C.The new disk is not formatted
D.The new disk is not partitioned
AnswerB

The BIOS detects the disk, so hardware and cabling are functional. If the newly installed SATA disk sits ahead of the original boot disk in the firmware's boot priority list, the system attempts to boot from a disk lacking a bootloader, causing failure. Reordering boot priority restores startup.

Why this answer

The most likely cause is an incorrect boot order because the BIOS recognizes the new SATA disk but the system still fails to boot. When a new disk is installed, the BIOS may default to booting from it if it appears earlier in the boot sequence than the original boot device, and if the new disk lacks a bootable operating system, the system will hang or fail to boot. This is a common scenario where the BIOS sees the disk but the boot priority is misconfigured, not a corruption of GRUB or a lack of formatting/partitioning.

Exam trap

The trap here is that candidates often assume a new disk must be partitioned and formatted before it can cause boot issues, but the BIOS boot order is independent of filesystem state, and a blank disk can still be selected as the first boot device, leading to a 'No bootable device' error.

How to eliminate wrong answers

Option A is wrong because a corrupted GRUB configuration would typically produce a specific error message (e.g., 'GRUB rescue' or 'file not found') and would not be caused simply by installing a new disk; the BIOS would still attempt to boot from the original disk. Option C is wrong because a disk does not need to be formatted to be recognized by the BIOS or to affect boot order; formatting is a filesystem operation that occurs after partitioning and does not prevent the BIOS from listing the disk. Option D is wrong because an unpartitioned disk is still recognized by the BIOS and can be selected in the boot order; the lack of partitions does not cause a boot failure unless the system tries to boot from that disk, which is a boot order issue, not a partitioning issue.

413
MCQmedium

A Linux administrator needs to create a new user account named 'jsmith' with a home directory /home/jsmith and the default shell /bin/bash. Which command should the administrator use?

A.useradd -m -s /bin/bash jsmith
B.passwd jsmith
C.usermod -aG jsmith
D.adduser jsmith
AnswerA

useradd -m creates the user's home directory if it does not exist, and -s /bin/bash sets the login shell. This command creates the account with the specified home directory and shell. It is the standard low-level utility for adding users on most Linux distributions and meets all requirements in the scenario.

Why this answer

The correct command is useradd -m -s /bin/bash jsmith, which creates the user, makes the home directory, and sets the login shell to /bin/bash. This is the most direct and portable way to create a user with specific attributes. Other commands either modify existing users, set passwords, or are interactive and less precise.

Exam trap

The trap here is confusing useradd with adduser; adduser is interactive and may not allow specifying the shell directly, while useradd is scriptable and precise.

414
Multi-Selectmedium

An administrator wants to harden SSH access by implementing the following: disallow root login, disable password authentication, and limit the number of authentication attempts. Which three configuration directives should be set in /etc/ssh/sshd_config? (Choose THREE.)

Select 3 answers
A.PermitRootLogin no
B.Port 22
C.PermitEmptyPasswords no
D.PasswordAuthentication no
E.MaxAuthTries 3
AnswersA, D, E

PermitRootLogin no blocks direct root logins over SSH, satisfying the stem's first hardening requirement. Setting it to no forces administrators to authenticate as an unprivileged user first, typically escalating via sudo, which removes a high-value brute-force target.

Why this answer

Option A, PermitRootLogin no, is correct because it directly disallows direct root logins over SSH, forcing administrators to authenticate as a regular user and then escalate privileges, which is the stated hardening goal. Option D, PasswordAuthentication no, is correct because it disables password-based authentication, requiring key-based (or other non-password) authentication methods instead. Option E, MaxAuthTries 3, is correct because it limits the number of authentication attempts allowed per connection, throttling brute-force guessing as requested.

Option B, Port 22, is not correct because it merely sets the default SSH listening port and does not harden authentication. Option C, PermitEmptyPasswords no, is not correct here because it only prevents logins with blank passwords, which is unrelated to the three specific requirements of disallowing root login, disabling password authentication, and limiting authentication attempts.

415
MCQmedium

An administrator notices repeated failed login attempts in /var/log/secure. The company policy requires account lockout after 5 failed attempts within 15 minutes. Which PAM module and configuration can enforce this?

A.pam_unix.so with remember=5
B.pam_pwquality.so with minlen=5
C.pam_limits.so with maxlogins=5
D.pam_faillock.so with deny=5 unlock_time=900
AnswerD

pam_faillock.so tracks failed authentication attempts per account and enforces lockout once the threshold is crossed. Setting deny=5 satisfies the five-attempt policy, while unlock_time=900 locks the account for fifteen minutes, matching the required window. Unlike pam_tally2, it integrates with faillock and supports per-user tally files.

Why this answer

Pam_faillock.so is the PAM module specifically designed to track failed login attempts and enforce account lockout policies. The `deny=5` parameter sets the threshold to 5 failures, and `unlock_time=900` sets the lockout duration to 900 seconds (15 minutes), matching the policy requirement exactly.

Exam trap

The trap here is confusing password policy modules (pam_pwquality.so, pam_unix.so) or session limits (pam_limits.so) with the dedicated account lockout module pam_faillock.so, leading candidates to select options that address different security controls.

How to eliminate wrong answers

Option A is wrong because pam_unix.so with `remember=5` controls password history (preventing reuse of the last 5 passwords), not account lockout after failed logins. Option B is wrong because pam_pwquality.so with `minlen=5` enforces password complexity and minimum length, not failed login attempt tracking. Option C is wrong because pam_limits.so with `maxlogins=5` limits the maximum number of concurrent login sessions for a user, not the number of failed attempts before lockout.

416
Multi-Selectmedium

In a Bash script, which THREE of the following are valid ways to define a function? (Select THREE.)

Select 3 answers
A.function myfunc() { commands; }
B.myfunc = () { commands; }
C.function myfunc { commands; }
D.def myfunc { commands; }
E.myfunc() { commands; }
AnswersA, C, E

Bash accepts the hybrid syntax combining the function keyword with parentheses and braces. The shell parses function myfunc() { commands; } as a valid definition, so this form satisfies the stem's requirement for a legitimate function declaration alongside the other two accepted variants.

Why this answer

Option A, `function myfunc() { commands; }`, is correct because Bash accepts the `function` keyword combined with parentheses, a hybrid syntax that is valid in Bash (though not POSIX sh). Option C, `function myfunc { commands; }`, is correct because the `function` keyword alone followed by the name and a compound command body is a valid Bash function definition form. Option E, `myfunc() { commands; }`, is correct because the POSIX-standard form using the name, empty parentheses, and a brace-delimited body is fully supported by Bash.

Option B is invalid because `myfunc = () { commands; }` includes an illegal space and equals sign, which Bash would treat as a command assignment, not a function definition. Option D is invalid because `def` is not a Bash keyword; it is used in Python, so Bash would attempt to run `def` as a command and fail.

Exam trap

The trap here is that candidates may think the 'function' keyword requires parentheses or that parentheses alone are insufficient, but Bash accepts both with and without the keyword, leading to confusion about which combinations are valid.

417
MCQmedium

A cloud engineer needs to automate the deployment of a new virtual machine with a specific configuration using Ansible. Which file format is typically used for Ansible playbooks?

A.JSON
B.YAML
C.XML
D.INI
AnswerB

Ansible playbooks are written in YAML, which satisfies the stem's requirement for automating VM deployment with a specific configuration. YAML's human-readable, indentation-based structure maps directly to Ansible's task, module and variable syntax, letting the engineer declare the desired VM state in a single playbook file.

Why this answer

Ansible playbooks are written in YAML (YAML Ain't Markup Language) because it is human-readable, supports complex data structures like lists and dictionaries, and is designed for configuration management. YAML's indentation-based syntax aligns with Ansible's declarative approach, allowing tasks, variables, and handlers to be defined cleanly without the overhead of brackets or tags.

Exam trap

The trap here is that candidates confuse the file format for playbooks (YAML) with other Ansible file types, such as JSON for dynamic inventory or INI for static inventory, leading them to select a technically valid but incorrect format for the specific question context.

How to eliminate wrong answers

Option A is wrong because JSON, while valid for Ansible inventory files or dynamic inventory scripts, is not the standard format for playbooks; playbooks rely on YAML's readability and support for comments. Option C is wrong because XML is verbose, uses angle-bracket tags, and is not natively supported by Ansible for playbook definitions, making it impractical for automation workflows. Option D is wrong because INI files are used for Ansible inventory configuration (e.g., listing hosts and groups), not for defining the ordered tasks and logic within a playbook.

418
MCQeasy

A user reports that their system is unable to boot after a recent kernel update. The system displays a 'kernel panic' message. Which of the following is the MOST efficient way to boot into a previous kernel version?

A.Select an older kernel from the GRUB menu
B.Use the systemd rescue mode
C.Reinstall the operating system
D.Boot from a live CD and chroot
AnswerA

GRUB retains prior kernel entries, so selecting an older kernel at boot bypasses the panic without rescue media or reinstallation. This satisfies the efficiency constraint, restoring a working system in seconds while the faulty kernel remains available for later diagnosis.

Why this answer

The GRUB bootloader stores multiple kernel versions after an update, allowing you to select a previous kernel from its menu at boot time. Choosing an older kernel bypasses the faulty new kernel without requiring additional tools or recovery media, making it the most efficient method to resolve a kernel panic caused by a recent update.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing systemd rescue mode or chroot, not realizing that GRUB's menu provides the simplest and fastest way to revert to a working kernel without any additional recovery steps.

How to eliminate wrong answers

Option B is wrong because systemd rescue mode (or emergency mode) boots into a minimal environment but still uses the default (new) kernel, which will likely trigger the same kernel panic. Option C is wrong because reinstalling the operating system is a drastic, time-consuming step that is unnecessary when a previous kernel is available in GRUB. Option D is wrong because booting from a live CD and chrooting is a valid recovery method, but it is far less efficient than simply selecting an older kernel from the GRUB menu, as it requires external media and manual chroot steps.

419
MCQmedium

An administrator wants to find all files in /var/log that have been modified within the last 2 days and have a .log extension. Which command should be used?

A.find /var/log -mtime 2 -name *.log
B.find /var/log -type f -mtime -2 -name "*.log"
C.locate --mtime -2 *.log /var/log
D.ls -la /var/log | grep "\.log$" | head -20
AnswerB

The `-mtime -2` test matches files modified less than two days ago, satisfying the recency constraint, while `-name "*.log"` filters by extension and `-type f` excludes directories. Combining these predicates with `find` in `/var/log` returns exactly the required set in one pass.

Why this answer

The find command with -mtime -2 finds files modified less than 2 days ago, and -name '*.log' matches the extension.

420
MCQeasy

Which command is used to create a symbolic link named 'link' pointing to the file 'original'?

A.symlink original link
B.ln -s link original
C.ln original link
D.ln -s original link
AnswerD

The -s flag creates a symbolic link rather than a hard link, and the syntax places the target (original) before the link name (link). This produces a symlink named 'link' pointing to 'original' as required.

Why this answer

ln -s creates a symbolic link.

421
Multi-Selecthard

A Linux engineer is troubleshooting a server that fails to boot. The server displays a message indicating 'Kernel panic - not syncing: VFS: Unable to mount root fs on unknown-block(0,0)'. Which TWO actions should the engineer take to resolve this issue? (Choose TWO.)

Select 2 answers
A.Reinstall GRUB to the Master Boot Record
B.Boot from a rescue disk and rebuild the initramfs with the necessary filesystem modules
C.Run fsck on the root partition to check for filesystem corruption
D.Check the kernel command line in the bootloader configuration for the correct root= parameter
E.Disable SELinux by adding selinux=0 to the kernel command line
AnswersB, D

The panic occurs because the initramfs lacks the storage driver needed to mount the root filesystem. Booting a rescue disk lets the engineer rebuild the initramfs with the correct filesystem modules, restoring the kernel's ability to mount root at boot.

Why this answer

The error 'VFS: Unable to mount root fs on unknown-block(0,0)' means the kernel cannot locate or mount the root filesystem, which typically stems from a missing/incorrect root= kernel parameter or an initramfs lacking the driver for the root device. Option B is correct because booting from a rescue disk and rebuilding the initramfs (e.g., with dracut or mkinitramfs) restores the storage/filesystem modules the kernel needs to access the root device at early boot. Option D is correct because verifying and fixing the root= parameter in the bootloader configuration (e.g., GRUB's /etc/default/grub or grub.cfg) ensures the kernel is pointed at the actual root device (such as /dev/mapper/vg-root or UUID=...).

Option A is not appropriate because reinstalling GRUB to the MBR only fixes bootloader-stage problems, not a kernel that has already loaded but cannot mount root. Option C is not the primary fix here since fsck addresses filesystem corruption, not an unknown-block root device error. Option E is unrelated because disabling SELinux does not resolve the kernel's inability to mount the root filesystem.

Exam trap

The trap here is that candidates confuse a kernel panic about root filesystem mounting with a bootloader or filesystem corruption issue, leading them to choose GRUB reinstallation (A) or fsck (C) instead of addressing the initramfs or kernel command line.

422
MCQmedium

A system administrator notices that a web server is running but users cannot connect to port 443. Which ss command will show if the server is listening on that port?

A.ss -s
B.ss -tlnp
C.ss -tuln
D.ss -tan
AnswerB

Shows TCP listening sockets with process info.

Why this answer

The ss command with -tlnp shows TCP sockets (-t), in listening state (-l), with numeric ports (-n), and the owning process (-p). That combination directly answers whether anything is bound to TCP 443 and which process holds it. This is the standard diagnostic for a web server that is running but unreachable on its expected port.

Exam trap

The trap is picking a broader flag set like -tuln or -tan that shows sockets but omits either the process owner or the listening-only filter needed to pinpoint port 443.

How to eliminate wrong answers

Option A is wrong because 'ss -s' prints summary statistics of socket usage, not per-socket listening details. Option C is wrong because 'ss -tuln' adds UDP (-u) and omits the process (-p), so it shows listeners but not which process owns port 443, weakening the diagnosis. Option D is wrong because 'ss -tan' shows all TCP sockets in all states without restricting to listeners, producing a noisy list that includes established and time-wait connections.

423
Drag & Dropmedium

Drag and drop the steps to troubleshoot a network connectivity issue using common commands in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Troubleshooting network connectivity should follow a logical progression from local to remote: first verify your own IP address and subnet mask, then check the default gateway, then test DNS resolution, and finally test connectivity to a remote host. This systematic approach helps isolate the root cause efficiently.

424
MCQeasy

Based on the exhibit, how often does the healthcheck.sh script run?

A.Every 5 days
B.Every 5 minutes
C.Every 5 hours
D.Every 5 seconds
AnswerB

The crontab entry `*/5 * * * *` in the exhibit triggers healthcheck.sh at five-minute intervals, satisfying the stem's scheduling constraint. The `*/5` step value in the minute field means cron executes the job at minutes 0, 5, 10, and so on throughout every hour, giving twelve runs hourly.

Why this answer

The cron expression `*/5 * * * *` in the crontab file means the script runs every 5 minutes. The `*/5` in the minute field triggers execution every 5 minutes, while the asterisks in the hour, day, month, and weekday fields mean every hour, every day, every month, and every day of the week, respectively.

Exam trap

CompTIA often tests the distinction between cron fields: candidates confuse the minute field with the hour field, thinking `*/5` means every 5 hours instead of every 5 minutes, especially when the context is a health check that might logically run less frequently.

How to eliminate wrong answers

Option A is wrong because a cron expression with `*/5` in the minute field does not represent days; a 5-day interval would require `*/5` in the day-of-month field (e.g., `0 0 */5 * *`). Option C is wrong because every 5 hours would use `0 */5 * * *` (minute set to 0, hour field with `*/5`). Option D is wrong because cron does not support sub-minute intervals; the smallest unit is one minute, so every 5 seconds is impossible with standard cron.

425
MCQhard

A server is experiencing intermittent high load. The administrator suspects a memory leak in a service. Which sysfs file should the administrator monitor to track memory usage per cgroup?

A./sys/fs/cgroup/memory/memory.limit_in_bytes
B./proc/meminfo
C./sys/fs/cgroup/memory/memory.usage_in_bytes
D./sys/fs/cgroup/memory/memory.stat
AnswerC

Monitoring `/sys/fs/cgroup/memory/memory.usage_in_bytes` reports the current memory charge for a cgroup, letting the administrator watch a single service's consumption climb over time and confirm the suspected leak. It satisfies the per-cgroup constraint directly, unlike host-wide tools such as `free` or `/proc/meminfo`, which aggregate all processes.

Why this answer

Memory.usage_in_bytes in the cgroup v1 memory hierarchy shows the current memory consumption of processes within a specific cgroup, making it the direct metric to monitor for a suspected memory leak in a service. Unlike system-wide files, this per-cgroup file reflects only the memory used by the service's control group, allowing precise tracking of growth over time.

Exam trap

CompTIA often tests the distinction between 'limit' and 'usage' files, trapping candidates who confuse the configuration file (memory.limit_in_bytes) with the monitoring file (memory.usage_in_bytes).

How to eliminate wrong answers

Option A is wrong because memory.limit_in_bytes sets the maximum memory limit for a cgroup, not the current usage, so it cannot show a leak. Option B is wrong because /proc/meminfo provides system-wide memory statistics, not per-cgroup data, and cannot isolate a specific service's memory consumption. Option D is wrong because memory.stat contains detailed breakdowns (e.g., cache, RSS, swap) but not a single current usage value; it requires parsing multiple fields and is less direct for tracking a leak.

426
MCQeasy

A shared directory requires that any new files created within it are automatically writable by the group. What umask value should be set for users working in this directory?

A.0777
B.0027
C.0002
D.0022
AnswerC

This umask subtracts 0002, giving group write permission on new files.

Why this answer

(0002) is correct because the umask subtracts permissions from the default 0666 for files. A umask of 0002 removes the 'write' permission for others (o-w), leaving the group with read/write (rw) and the owner with read/write (rw). This ensures new files are group-writable, as required for a shared directory.

Exam trap

The trap here is that candidates often confuse umask with the final permission value, mistakenly thinking a higher umask like 0022 is safer, but it actually removes group write access, which is the opposite of what the question requires.

How to eliminate wrong answers

Option A (0777) is wrong because it would remove all permissions from the default, resulting in files with no permissions (000), which is not useful. Option B (0027) is wrong because it removes write permission from the group (g-w), making new files not group-writable, which contradicts the requirement. Option D (0022) is wrong because it removes write permission from the group (g-w) as well, leaving files with owner write only, not group-writable.

427
MCQmedium

An administrator wants to grant a specific user, 'jdoe', read and write access to a file that is owned by root:root with permissions 640. The administrator does not want to change the file's owner or group. Which approach should be used?

A.Use setfacl -m u:jdoe:rw file
B.Change file owner to jdoe
C.Use chmod o+rw file
D.Add jdoe to the root group
AnswerA

setfacl -m u:jdoe:rw adds a named user entry to the file's access control list, granting jdoe read and write access. This satisfies the constraint of not altering the file's owner or group, which chmod and chown would change.

Why this answer

POSIX ACLs allow granting permissions to specific users or groups without altering the file's owner or group. The command 'setfacl -m u:jdoe:rw file' adds an ACL entry giving jdoe read and write access while leaving root:root ownership and the 640 mode intact. This is the standard, least-disruptive approach for per-user access on a shared file.

Exam trap

XK0-006 often tests whether candidates reach for chmod or group membership when the requirement is per-user access without changing ownership — the trap is over-granting with 'o+rw' or 'add to root group'.

How to eliminate wrong answers

Option B is wrong because changing the file owner to jdoe removes root's ownership, which is a broader change than required and may break services or scripts that depend on root ownership. Option C is wrong because 'chmod o+rw' grants read/write to all other users on the system, not just jdoe — a serious security over-exposure. Option D is wrong because adding jdoe to the root group grants group-level access to every file owned by root:root with group permissions, which is far broader than needed and violates least privilege.

428
MCQmedium

A system administrator notices that the server is performing poorly. Running 'vmstat 1 5' shows high 'wa' values. Which subsystem is most likely experiencing a bottleneck?

A.Memory
B.Disk I/O
C.Network
D.CPU
AnswerB

The wa column in vmstat reports the percentage of CPU time spent idle while waiting for I/O completion. Persistently high wa values indicate processes blocked on storage operations, so the bottleneck lies in the disk I/O subsystem.

Why this answer

In vmstat output, the 'wa' column reports the percentage of CPU time spent waiting for I/O operations to complete. High 'wa' values indicate that the CPU is idle but blocked waiting on disk (or other block device) I/O, which points directly to a disk I/O bottleneck. This is distinct from high 'us' or 'sy' (user/system CPU) or high 'si'/'so' (swap), which would indicate CPU or memory pressure respectively.

Exam trap

The trap is that candidates see 'wa' and think 'wait' means CPU waiting, so they pick CPU; the exam expects you to know 'wa' is I/O wait, not CPU wait.

How to eliminate wrong answers

Option A is wrong because memory bottlenecks in vmstat show up as high 'si' and 'so' (swap in/out) or a growing 'free'/'buff'/'cache' imbalance, not as high 'wa'. Option C is wrong because network bottlenecks are not directly represented by 'wa'; they would typically be diagnosed with netstat, ss, sar -n DEV, or iftop, and may show up as high system CPU ('sy') from interrupt handling, not I/O wait. Option D is wrong because CPU bottlenecks manifest as high 'us' (user) or 'sy' (system) percentages, or high 'id' being low, not as high 'wa' — 'wa' specifically means the CPU is idle waiting on I/O.

429
Multi-Selecteasy

Which TWO characteristics apply to Docker containers compared to virtual machines? (Choose two.)

Select 2 answers
A.Containers share the host kernel
B.Containers have faster startup times
C.Containers provide stronger isolation
D.Containers include a full guest operating system
E.Containers require a hypervisor
AnswersA, B

Containers run as isolated processes on the host's kernel, sharing it rather than bundling a guest operating system. This architectural difference from hypervisor-based virtual machines eliminates per-instance OS duplication, which is the foundation for their smaller footprint and faster operation.

Why this answer

Option A is correct because Docker containers share the host operating system's kernel rather than booting their own, using namespaces and cgroups for process and resource isolation, which is why they are lightweight compared to VMs. Option B is correct because containers start in milliseconds to seconds since they launch a process directly on the shared kernel instead of booting a full guest OS through a hypervisor. Option C is incorrect because VMs provide stronger isolation via hardware-level virtualization boundaries, whereas containers share the kernel and thus have a weaker security boundary.

Option D is incorrect because including a full guest operating system is a characteristic of VMs, not containers. Option E is incorrect because containers run directly on the host kernel via a container runtime such as containerd or runc, not on a hypervisor.

Exam trap

CompTIA often tests the misconception that containers provide stronger isolation than VMs, but the correct understanding is that VMs offer hardware-level isolation via a hypervisor, while containers share the host kernel and thus have weaker isolation boundaries.

430
MCQmedium

In a Bash script, a variable is assigned the output of a command using: result=$(ls -l). What is the purpose of the $() syntax?

A.It runs the command and assigns its output to the variable
B.It expands the variable result
C.It checks if the command exists
D.It runs the command in a subshell and discards output
AnswerA

Command substitution executes the enclosed command in a subshell and replaces the expression with its standard output, which is then assigned to the variable. This lets result capture the directory listing text rather than the literal string, satisfying the script's intent.

Why this answer

The $() syntax is command substitution: Bash executes the command inside the parentheses in a subshell, captures its standard output, and substitutes that text into the assignment. So 'result=$(ls -l)' stores the directory listing in the variable result. This is the modern, nestable form of the older backtick syntax.

Exam trap

The trap is confusing command substitution $() with variable expansion ${}, causing candidates to pick the 'expands the variable' distractor.

How to eliminate wrong answers

Option B is wrong because variable expansion uses ${result} or $result, not $(); $() performs command substitution, not variable expansion. Option C is wrong because checking whether a command exists is done with 'command -v' or 'type', not $(). Option D is wrong because while $() does run the command in a subshell, it captures and returns the output rather than discarding it; discarding output would require redirecting to /dev/null.

431
MCQeasy

A systems administrator writes a Bash script named 'backup.sh' and wants it to run with the Bash shell. Which line should appear first in the script?

A.# This is a bash script
B.#!/bin/bash
C.#/bin/bash
D.#!/bin/sh
AnswerB

The shebang line `#!/bin/bash` must be the first line, as it tells the kernel to invoke `/bin/bash` as the interpreter for the script. This satisfies the stem's requirement that the script run specifically with the Bash shell, rather than the default shell or another interpreter.

Why this answer

The shebang line `#!/bin/bash` is required as the first line to instruct the operating system to execute the script using the Bash shell interpreter located at `/bin/bash`. Without this line, the script may be run by a different shell (e.g., `/bin/sh`), leading to syntax or behavior differences. The shebang must start with `#!` followed by the absolute path to the interpreter.

Exam trap

CompTIA often tests the distinction between a shebang (`#!`) and a comment (`#`), and the trap here is that candidates may confuse `#!/bin/sh` as equivalent to `#!/bin/bash` or forget the exclamation mark entirely, leading them to choose option C or D.

How to eliminate wrong answers

Option A is wrong because `# This is a bash script` is a comment, not a shebang; the kernel ignores it and may fall back to the default shell, which is not guaranteed to be Bash. Option C is wrong because `#/bin/bash` lacks the exclamation mark (`!`), so it is treated as a regular comment and does not invoke the Bash interpreter. Option D is wrong because `#!/bin/sh` points to the POSIX shell, which may be Dash or another shell on many Linux distributions, not Bash; Bash-specific features (e.g., `[[ ]]`, arrays) would fail.

432
MCQeasy

A technician has just performed system maintenance and wants to verify that the server has been running continuously for the past 30 days. Which command should the technician use?

A.uptime
B.systemctl status rsyslog
C.ps aux
D.date
AnswerA

`uptime` reads `/proc/uptime` and reports the current time, logged-in users, load averages and, crucially, the elapsed time since the last boot. That single figure directly satisfies the stem's requirement to confirm 30 days of continuous running, unlike `top` or `who`, which show current activity rather than boot duration.

Why this answer

The `uptime` command displays how long the system has been running since the last boot, including the current time, number of logged-in users, and load averages. By checking the output, the technician can verify if the server has been running continuously for the past 30 days (e.g., 'up 30 days'). This directly answers the question without querying logs or processes.

Exam trap

The trap here is that candidates might confuse `uptime` with commands that show service status (`systemctl`) or process lists (`ps`), thinking they can infer system uptime indirectly, but only `uptime` provides the exact boot-to-present duration.

How to eliminate wrong answers

Option B is wrong because `systemctl status rsyslog` shows the status of the rsyslog service (logging daemon), not the system's uptime; it only indicates if the service is running, not how long the server has been up. Option C is wrong because `ps aux` lists all running processes with their CPU/memory usage and start times, but it does not provide a single, consolidated uptime value for the entire system. Option D is wrong because `date` simply prints the current system date and time, offering no historical information about how long the server has been running.

433
MCQhard

A Linux server hosts a payroll database. The security policy states that the file /srv/payroll/ledger.db must be readable and writable only by members of the group payroll, and that no other user on the system may read it, even root. Which approach satisfies the requirement that even root cannot read the file contents?

A.Encrypt the file with a tool such as gpg or openssl enc using a key that is never stored on the server.
B.Set the file mode to 0660 and change its group owner to payroll.
C.Place the file on a filesystem mounted with the noexec and nodev options.
D.Apply the immutable attribute to the file with chattr +i /srv/payroll/ledger.db.
AnswerA

When the file is encrypted and the decryption key resides only off the server, possession of root on that host yields nothing but ciphertext. Access control is enforced by cryptography rather than by the kernel's permission model, so even the superuser cannot recover the ledger contents without the external key.

Why this answer

Traditional Unix permissions, including restrictive modes and special attributes, are enforced by the kernel, and root is deliberately exempt from those checks. The only way to guarantee that even root cannot read a file's contents is to encrypt it and keep the decryption key off the server, shifting enforcement from the permission model to cryptography that root cannot bypass.

Exam trap

The trap here is assuming that restrictive modes, chattr +i, or mount options can constrain root, when the kernel's discretionary access control always exempts UID 0 from read and write permission checks.

434
MCQmedium

A system administrator needs to update a configuration file on multiple servers using Ansible. The playbook must ensure the line 'MaxAuthTries 3' is present in /etc/ssh/sshd_config. Which Ansible module is most appropriate?

A.template
B.shell
C.copy
D.lineinfile
AnswerD

lineinfile manages individual lines within an existing file, adding 'MaxAuthTries 3' if absent and matching by regexp. This satisfies the requirement to ensure a specific configuration line is present across multiple servers without rewriting the whole file.

Why this answer

The lineinfile module ensures a specific line is present in a file, ideal for configuration management.

435
MCQhard

Which command will show the environment variables for a specific process?

A.cat /proc/$PID/environ
B.set
C.printenv
D.env
AnswerA

The /proc filesystem exposes each process's environment block as a NUL-separated file at /proc/$PID/environ, so cat reads the exact variables inherited by that process. This directly satisfies the stem's requirement to show environment variables for a specific process.

Why this answer

The `/proc/[PID]/environ` file contains the environment variables that were set when the process was started. Reading this file with `cat` displays the exact environment of a specific process, which is not possible with shell built-ins or user-level commands that only show the current shell's environment.

Exam trap

CompTIA often tests the distinction between commands that show the current shell's environment (`set`, `printenv`, `env`) versus the `/proc` filesystem method that targets a specific process, leading candidates to pick a shell command instead of the process-specific file.

How to eliminate wrong answers

Option B is wrong because `set` displays all shell variables (including environment and local variables) for the current shell session, not for a specific process. Option C is wrong because `printenv` prints the environment variables of the current shell, not of an arbitrary process. Option D is wrong because `env` lists or modifies the environment of the current shell, and cannot target a specific process by PID.

436
Multi-Selecthard

A Linux server is not accepting SSH connections. The administrator wants to troubleshoot the issue. Which THREE actions should be taken?

Select 3 answers
A.Reboot the server
B.Check /etc/ssh/sshd_config for configuration errors
C.Check if sshd service is running (systemctl status sshd)
D.Reinstall the SSH package (apt reinstall openssh-server)
E.Check firewall rules (iptables -L or ufw status)
AnswersB, C, E

Inspecting /etc/ssh/sshd_config verifies the daemon's own settings, such as PermitRootLogin, Port and AllowUsers, which directly govern whether sshd accepts connections. A malformed directive or invalid port binding prevents the service from starting or listening, satisfying the stem's requirement to troubleshoot why the Linux server refuses SSH connections.

Why this answer

Option B is correct because /etc/ssh/sshd_config is the primary configuration file for the OpenSSH daemon, and syntax errors, invalid directives, or a misconfigured ListenAddress/Port will prevent sshd from starting or accepting connections. Option C is correct because if the sshd service is not running, no process will be listening on TCP port 22, so verifying its state with systemctl status sshd (and starting it if needed) is a fundamental troubleshooting step. Option E is correct because firewall rules managed by iptables or ufw can silently drop or reject inbound TCP/22 traffic, so checking them with iptables -L or ufw status confirms whether the port is actually reachable.

Option A is not appropriate because rebooting is a disruptive, non-diagnostic action that does not identify the root cause and may mask the problem. Option D is not appropriate because reinstalling openssh-server is unnecessary when the issue is more likely configuration, service state, or firewall-related, and it does not address the actual fault.

Exam trap

CompTIA often tests the misconception that reinstalling a package or rebooting is a valid first troubleshooting step, when in reality, checking configuration files, service status, and firewall rules are the precise, targeted actions required.

437
MCQmedium

An administrator runs 'systemctl list-units' and sees that httpd.service is in a failed state. To quickly see the error message that caused the failure, which command should be used?

A.systemctl show httpd.service -p ExecMainStatus
B.journalctl -p err -u httpd.service
C.systemctl status httpd.service
D.systemd-analyze blame
AnswerC

systemctl status reports the unit's state plus the most recent log lines, including the exit code and error output that caused the failure. This surfaces the diagnostic message directly, unlike list-units, which shows only the failed state.

Why this answer

The `systemctl status httpd.service` command displays the current state of the service, including the most recent log entries from the journal that show the error messages causing the failure. This is the quickest way to see the failure reason without filtering or additional options, as it directly outputs the relevant error lines from the service's unit.

Exam trap

The trap here is that candidates often confuse `systemctl status` with `journalctl -u` or `systemctl show`, thinking they need a separate log-viewing command, but `systemctl status` already provides the most recent error output directly, making it the fastest diagnostic tool for a failed service.

How to eliminate wrong answers

Option A is wrong because `systemctl show httpd.service -p ExecMainStatus` only outputs the numeric exit code or signal of the main process (e.g., 0 for success, 1 for generic error), not the descriptive error message or log output that caused the failure. Option B is wrong because `journalctl -p err -u httpd.service` filters journal entries to only those with priority 'err' (error) for the httpd unit, which may miss critical failure messages logged at a different priority (e.g., 'crit' or 'alert') and requires an extra command compared to `systemctl status`. Option D is wrong because `systemd-analyze blame` shows the time each unit took to start during boot, not the error messages or failure reasons for a currently failed service.

438
Multi-Selecthard

A Linux administrator is troubleshooting a server that has lost network connectivity. They need to verify the current IP configuration and check the default gateway. Which TWO commands can be used to display the IP address and routing table? (Choose two.)

Select 2 answers
A.route -n
B.ip addr show
C.ip route show
D.ifconfig -a
E.netstat -rn
AnswersB, C

ip addr show displays all network interfaces and their assigned IP addresses, including subnet masks. It is the modern replacement for ifconfig and provides detailed information about interface state. In this scenario, it directly shows whether the interface has an IP, which is essential for diagnosing connectivity loss. It does not show the routing table, but it is one of the required commands.

Why this answer

The ip addr show command reveals interface IP addresses, and ip route show displays the routing table including the default gateway. Together they provide the necessary information to diagnose network connectivity loss. These are the modern, recommended tools for network configuration inspection on Linux.

Exam trap

The trap here is selecting deprecated commands like ifconfig or netstat instead of the current iproute2 utilities, or choosing commands that only cover half of the requirement.

439
MCQmedium

A database server is experiencing slow queries. The administrator wants to analyze system memory usage. Which command shows memory usage in megabytes and includes information about buffers and cache?

A.free -m
B.top -b
C.cat /proc/meminfo
D.vmstat
AnswerA

The -m flag makes free display values in mebibytes, and its default output includes the buffers and cache columns alongside total, used, and available memory. This satisfies the requirement to analyse memory usage in megabytes with buffer and cache detail.

Why this answer

The 'free -m' command displays system memory usage in megabytes, explicitly showing separate columns for buffers and cache, which are critical for diagnosing slow queries caused by memory pressure. This makes it the correct choice for the administrator's need to analyze memory usage with buffer/cache details in MB.

Exam trap

CompTIA often tests the distinction between commands that show memory in raw kernel units (like /proc/meminfo in kB) versus those that offer user-friendly output with specific columns (like free -m), leading candidates to choose /proc/meminfo for its detail while missing the explicit requirement for megabytes and buffer/cache breakdown.

How to eliminate wrong answers

Option B is wrong because 'top -b' runs top in batch mode, which shows real-time process-level memory and CPU usage but does not display memory in megabytes by default and lacks the dedicated buffers/cache breakdown that 'free -m' provides. Option C is wrong because 'cat /proc/meminfo' outputs raw memory statistics in kilobytes, not megabytes, and requires manual calculation to convert to MB, making it less convenient for the specified requirement. Option D is wrong because 'vmstat' reports virtual memory statistics including swap, I/O, and system events, but it does not show memory usage in megabytes and does not include explicit buffers and cache columns in its default output.

440
MCQhard

A Kubernetes pod has a container that fails with CrashLoopBackOff. The administrator runs 'kubectl logs pod-name' but sees no output. What is the most likely cause?

A.The container exited before writing to stdout, and logs need to be retrieved with 'kubectl logs --previous'.
B.The container has no logging driver configured.
C.The log file is rotated and deleted.
D.The pod is not scheduled on any node.
AnswerA

CrashLoopBackOff means the container starts and immediately exits, so the current instance has produced no stdout. The failing run's output sits in the previous container instance, retrieved using 'kubectl logs --previous' to reveal the crash cause.

Why this answer

When a container enters CrashLoopBackOff, it restarts repeatedly. If 'kubectl logs pod-name' shows no output, it means the current (restarted) container has not written anything to stdout yet. The previous instance of the container may have written logs before crashing, and those logs are accessible using 'kubectl logs --previous' to retrieve the output from the terminated container.

Exam trap

The trap here is that candidates assume 'no output' means logs are missing or misconfigured, when in fact the current container simply hasn't written anything yet, and the previous container's logs are still available via --previous.

How to eliminate wrong answers

Option B is wrong because Kubernetes does not require a separate logging driver configuration; it captures container stdout/stderr by default via the container runtime interface (CRI). Option C is wrong because log rotation and deletion would not cause an empty log output on a freshly restarted container; the current container simply hasn't produced logs yet. Option D is wrong because if the pod were not scheduled on any node, 'kubectl logs' would return an error like 'Error from server: pod is not scheduled', not an empty output.

441
MCQhard

In a bash script, a variable is set as follows: myvar='Hello World'. Which of the following correctly prints the first 5 characters of the variable?

A.echo ${myvar#?????}
B.echo ${myvar:0:5}
C.echo ${myvar:0-5}
D.echo ${myvar:5}
AnswerB

Bash substring expansion uses ${parameter:offset:length}, so ${myvar:0:5} extracts five characters starting at index zero, yielding "Hello". The offset is zero-based, and the length is explicit, which is exactly what printing the first five characters requires.

Why this answer

Bash parameter expansion supports substring extraction using the syntax ${variable:offset:length}. With myvar='Hello World', ${myvar:0:5} starts at index 0 and returns 5 characters, yielding 'Hello'. This is the standard, portable way to slice a string in Bash.

Exam trap

The trap is mixing up prefix/suffix pattern removal (# and %) with substring extraction (:offset:length); candidates often pick ${myvar#?????} thinking # means 'take' rather than 'strip'.

How to eliminate wrong answers

Option A is wrong because ${myvar#?????} uses pattern removal with the # operator, which strips the shortest matching prefix of five characters, leaving ' World' (the remainder), not the first five characters. Option C is wrong because ${myvar:0-5} is not valid Bash substring syntax; the offset/length form requires a colon between offset and length, and '0-5' would be interpreted as arithmetic yielding -5, which is not the intended slice. Option D is wrong because ${myvar:5} returns the substring starting at index 5 to the end (' World'), not the first five characters.

442
MCQhard

A Docker container using port 8080 fails to start with the error 'port is already allocated'. Which command should the administrator use to identify the process using that port?

A.ss -tan
B.ss -tln
C.ss -tlnp
D.ss -r
AnswerC

`ss -tlnp` lists TCP listening sockets with their owning process, directly satisfying the need to identify what holds port 8080. The `-p` flag exposes the PID and program name, while `-l` restricts output to listening sockets and `-n` avoids DNS resolution, pinpointing the conflicting process.

Why this answer

The `ss -tlnp` command lists TCP listening sockets (`-l`) with numeric addresses (`-n`) and shows the process identifier (PID) and process name (`-p`) that owns each socket. This directly identifies which process has bound port 8080, allowing the administrator to resolve the 'port is already allocated' error.

Exam trap

The trap here is that candidates may choose `ss -tln` (option B) because it shows listening ports, but they forget the `-p` flag is required to identify the process, leading to incomplete troubleshooting.

How to eliminate wrong answers

Option A is wrong because `ss -tan` lists all TCP sockets (including non-listening ones) without showing process ownership, so it cannot identify the process using port 8080. Option B is wrong because `ss -tln` lists TCP listening sockets but omits the `-p` flag, so it does not display the PID or process name, leaving the process unidentified. Option D is wrong because `ss -r` attempts to resolve hostnames and is not a valid flag combination for socket statistics; it does not list sockets or processes.

443
Multi-Selecthard

An administrator is debugging a Docker container that exits immediately after starting. Which THREE commands can help diagnose the issue? (Select THREE).

Select 3 answers
A.docker run --rm -it <image> sh
B.docker logs <container>
C.docker inspect <container>
D.docker exec -it <container> sh
E.docker ps
AnswersA, B, C

Overriding the image's default entrypoint with an interactive shell keeps the container running and exposes its filesystem, letting you inspect why the original command exited. This directly addresses the immediate-exit symptom by bypassing the failing startup command.

Why this answer

Option A (docker run --rm -it <image> sh) is correct because it overrides the image's default entrypoint/command with an interactive shell, letting you explore the filesystem and manually run the failing process to see errors directly. Option B (docker logs <container>) is correct because it retrieves stdout/stderr captured from the container's main process, which typically contains the crash message or stack trace explaining the immediate exit. Option C (docker inspect <container>) is correct because it reveals the container's ExitCode, State, Error, and the configured Entrypoint/Cmd, helping identify misconfigurations or non-zero exit reasons.

Option D (docker exec -it <container> sh) does not belong because exec requires a running container, and this container has already exited. Option E (docker ps) does not belong because it only lists running containers by default, so the exited container would not appear unless -a is used, and it provides no diagnostic detail.

Exam trap

The trap here is that candidates may select docker exec or docker ps, but exec requires a running container, and ps without -a does not show exited containers; the exam tests knowledge of which commands work on stopped containers.

444
MCQeasy

A junior administrator needs to check the disk usage of the /var filesystem to ensure it does not exceed 80% capacity. Which command should be used?

A.df -h /var
B.fdisk -l /var
C.du -sh /var
D.lsblk /var
AnswerA

The `df -h` command with the `/var` argument queries the kernel’s mounted-filesystem table for the `/var` mount point, reporting used blocks and inodes in human-readable units (e.g., GiB). The `-h` flag converts raw 1024-byte blocks into scaled output, enabling the junior administrator to compare the “Use%” column directly against the 80% capacity constraint specified in the stem.

Why this answer

The `df -h /var` command displays disk usage for the `/var` filesystem in human-readable format (e.g., GB, MB). This is the correct tool to check filesystem capacity and usage percentage, which directly answers whether usage exceeds 80%.

Exam trap

The trap here is that candidates confuse `du` (directory usage) with `df` (filesystem usage), leading them to pick `du -sh /var` when they need to check overall filesystem capacity, not just the size of the directory contents.

How to eliminate wrong answers

Option B is wrong because `fdisk -l` lists partition tables on block devices, not filesystem usage; it cannot show capacity percentages for a mounted filesystem like `/var`. Option C is wrong because `du -sh /var` shows the total size of the `/var` directory tree, not the filesystem's total capacity or usage percentage; it is used for directory-level disk usage, not filesystem-level capacity checks. Option D is wrong because `lsblk` lists block devices (e.g., disks, partitions) and their mount points, but does not report filesystem usage or capacity percentages.

445
Multi-Selecthard

A developer is writing a shell script that needs to handle errors. Which THREE of the following are best practices for robust script error handling?

Select 3 answers
A.Ignore errors to simplify the script
B.Check the exit code of commands using $?
C.Use set +e to allow the script to continue on error
D.Use set -e to exit on any command failure
E.Use trap to catch signals and clean up
AnswersB, D, E

Allows conditional handling.

Why this answer

Checking the exit code of commands using `$?` allows the script to conditionally handle failures based on the specific return value of each command. This is a fundamental error-handling technique in shell scripting, as every command returns an exit code (0 for success, non-zero for failure), and inspecting `$?` immediately after a command lets the developer decide how to respond to that specific error.

Exam trap

CompTIA often tests the distinction between `set -e` and `set +e` and the proper use of `$?` versus relying solely on `set -e`, where candidates may incorrectly think that `set +e` is a best practice for error handling when it actually disables automatic exit on error.

446
MCQhard

A Linux administrator is troubleshooting a Bash script that unexpectedly terminates when a command fails. The script uses `#!/bin/bash`. Which of the following commands, if placed at the beginning of the script, would cause it to exit on any command failure?

A.set -u
B.trap 'exit 1' ERR
C.set -e
D.set -o pipefail
AnswerC

`set -e` makes Bash exit immediately when any command returns a non-zero status, which is exactly the failure-termination behaviour described. The shebang already invokes Bash, so this shell option applies. It satisfies the requirement to exit on any command failure.

Why this answer

The `set -e` option makes the shell exit immediately if a command exits with a non-zero status.

447
MCQhard

A developer creates a hard link to a file and then deletes the original file. What happens to the hard link?

A.The hard link is broken and cannot be accessed.
B.The hard link still contains the data and is accessible.
C.The hard link is automatically converted to a copy of the file.
D.The hard link becomes a symbolic link.
AnswerB

Hard links share the same inode, so deleting the original filename only removes one directory entry; the inode's link count drops but data persists. The remaining hard link still resolves to that inode and remains fully readable.

Why this answer

Hard links share the same inode; deleting the original file removes one link, but the data remains accessible via the hard link until all links are removed.

448
Multi-Selectmedium

A user is unable to resolve hostnames on a Linux system. Which three configuration files should be checked? (Select THREE).

Select 3 answers
A./etc/hosts
B./etc/nsswitch.conf
C./etc/resolv.conf
D./etc/hostname
E./etc/sysconfig/network
AnswersA, B, C

/etc/hosts provides static hostname-to-IP mappings consulted before DNS, so a missing or malformed entry breaks local resolution. Since the stem describes failed hostname resolution, this file is a required check alongside /etc/resolv.conf and /etc/nsswitch.conf, which together govern the lookup order.

Why this answer

Option A, /etc/hosts, is correct because it provides static hostname-to-IP mappings that the resolver consults, and a missing or malformed entry there can break name resolution for local or manually defined hosts. Option B, /etc/nsswitch.conf, is correct because its 'hosts:' line determines the order and sources (e.g., files, dns, myhostname) used by the Name Service Switch, so a misconfigured entry can prevent DNS or /etc/hosts from being queried at all. Option C, /etc/resolv.conf, is correct because it defines the DNS nameservers, search domains, and resolver options used for hostname lookups; missing or unreachable nameserver entries directly cause resolution failures.

Option D, /etc/hostname, only sets the local system's own hostname and does not affect how the resolver looks up other hosts. Option E, /etc/sysconfig/network, is a Red Hat-style file for global network settings such as hostname and gateway, not a resolver configuration file, so it is not one of the three files to check for hostname resolution.

Exam trap

CompTIA often tests the misconception that /etc/hostname or /etc/sysconfig/network are involved in hostname resolution, when in fact they only affect the local system's identity, not the resolution of external hostnames.

449
MCQhard

A storage administrator needs to automate the expansion of an LVM volume group when free space drops below 10%. The script must add a new physical volume from a spare disk. Which of the following commands should be used in the script to add the new disk to the volume group?

A.pvcreate /dev/sdb1 && vgextend vg01 /dev/sdb1
B.vgcreate vg01 /dev/sdb
C.vgextend vg01 /dev/sdb1
D.lvresize -L +100G vg01
AnswerA

pvcreate initialises the partition as an LVM physical volume, then vgextend adds that PV to vg01, expanding the volume group. Both steps are required in sequence, directly satisfying the stem's need to add a spare disk to the volume group automatically.

Why this answer

It first uses `pvcreate` to initialize the spare disk partition `/dev/sdb1` as a physical volume, which is a prerequisite for adding it to an LVM volume group. Then `vgextend vg01 /dev/sdb1` adds that initialized physical volume to the existing volume group `vg01`, expanding its total capacity. This two-step process ensures the disk is properly prepared for LVM management before being incorporated into the volume group.

Exam trap

The trap here is that candidates often think `vgextend` alone is sufficient, forgetting that LVM requires the device to be initialized as a physical volume with `pvcreate` before it can be added to a volume group.

How to eliminate wrong answers

Option B is wrong because `vgcreate` creates a new volume group, but the requirement is to add a disk to an existing volume group, not create a new one. Option C is wrong because `vgextend` alone will fail if `/dev/sdb1` has not been initialized as a physical volume with `pvcreate` first; LVM requires the device to be marked as a PV before it can be added to a VG. Option D is wrong because `lvresize` resizes a logical volume, not a volume group, and the task is to expand the volume group by adding a new physical volume, not to resize a logical volume.

450
Multi-Selectmedium

A Linux administrator needs to schedule a backup script to run every day at 2:30 AM. Which TWO of the following methods can be used to achieve this? (Choose two.)

Select 2 answers
A.Create a systemd service with Restart=always and RestartSec=86400.
B.Use the 'at' command to schedule the script with 'at 02:30' and repeat it daily.
C.Create a cron job with the schedule '30 2 * * *' in the root crontab.
D.Add the script to /etc/cron.daily/ with a filename that starts with '02:30'.
E.Create a systemd timer unit with OnCalendar=*-*-* 02:30:00 and enable it.
AnswersC, E

A cron job with the schedule '30 2 * * *' will run the command every day at 2:30 AM. The fields represent minute, hour, day of month, month, and day of week. This is a standard and reliable method for scheduling recurring tasks on Linux. It is directly supported by the cron daemon and is easy to set up.

Why this answer

Both cron and systemd timers are valid methods for scheduling recurring tasks at specific times. A cron job with the schedule '30 2 * * *' runs daily at 2:30 AM. A systemd timer with OnCalendar=*-*-* 02:30:00 also triggers daily at that time when enabled.

These are the two correct approaches among the options.

Exam trap

The trap here is thinking that placing a script in /etc/cron.daily/ can control the exact execution time, but it cannot; the time is set by system crontab.

Page 5

Page 6 of 11

Page 7

All pages