Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 451–525

781 questions total · 11pages · All types, answers revealed

Page 6

Page 7 of 11

Page 8
451
MCQeasy

A user cannot access a directory '/data/projects' even though they are in the 'projects' group. The directory permissions are 'drwxr-x---' and the group owner is 'projects'. Which command should the administrator run to grant the group write permission?

A.chmod g+w /data/projects
B.chmod o+w /data/projects
C.chmod u+w /data/projects
D.chown :projects /data/projects
AnswerA

The directory's group owner is already 'projects', so only the group permission triad needs altering. Symbolic mode g+w adds write permission for that group without disturbing owner or other bits, directly satisfying the requirement that members of 'projects' gain write access to '/data/projects'.

Why this answer

The directory '/data/projects' has permissions 'drwxr-x---', meaning the group owner 'projects' currently has read and execute (r-x) but not write (w) access. Since the user is a member of the 'projects' group, the administrator needs to add write permission for the group using 'chmod g+w /data/projects'. This directly modifies the group permission bits to grant write access without affecting other permissions.

Exam trap

CompTIA often tests the distinction between changing ownership (chown) and changing permissions (chmod), and candidates mistakenly think that setting the group owner again will grant write access, when in fact only chmod modifies the permission bits.

How to eliminate wrong answers

Option B is wrong because 'chmod o+w' adds write permission for 'others' (users not the owner and not in the group), which is unnecessary and would over-permit the directory, violating the principle of least privilege. Option C is wrong because 'chmod u+w' adds write permission for the user owner, not the group; the user owner is typically 'root' or another user, not the 'projects' group. Option D is wrong because 'chown :projects /data/projects' changes the group owner to 'projects', but the group already owns the directory, so this command does nothing to change permissions; it does not grant write access.

452
MCQeasy

A Linux administrator needs to check the available disk space on all mounted filesystems in a human-readable format. Which command should the administrator use?

A.fdisk -l
B.du -h
C.lsblk
D.df -h
AnswerD

The df command reports filesystem disk space usage, and the -h flag displays sizes in human-readable units such as GB and MB. This directly answers the need to view available space on all mounted filesystems in an easily readable format. It is the standard tool for this task and is available on virtually all Linux distributions.

Why this answer

df -h is the correct command because it reports filesystem disk space usage and free space for all mounted filesystems in human-readable units. The -h flag converts sizes to GB, MB, or KB as appropriate, making the output easy to interpret. Other commands either show file sizes, partition tables, or block device topology, not free space.

Exam trap

The trap here is confusing disk usage reporting tools: df shows filesystem free space, while du shows how much space files and directories consume.

453
MCQmedium

A Linux administrator needs to create a new user account 'analyst' with a home directory at /home/analyst and the default shell set to /bin/bash. The user should also be added to the existing supplementary group 'research'. Which command will accomplish this in a single step?

A.useradd -m -s /bin/bash -G research analyst
B.groupadd research && useradd -m -s /bin/bash -g research analyst
C.usermod -m -s /bin/bash -G research analyst
D.adduser analyst -m -s /bin/bash -g research
AnswerA

The useradd command with -m creates the home directory, -s sets the login shell, and -G adds the user to the supplementary group 'research'. This single command fulfills all requirements without additional steps, making it the correct choice.

Why this answer

The useradd command with -m creates the home directory, -s specifies the shell, and -G adds the user to supplementary groups. This single command meets all specified conditions without extra steps, making it the correct solution.

Exam trap

The trap here is confusing the -g option (primary group) with -G (supplementary groups), which can lead to incorrect group membership.

454
MCQhard

After a kernel update, loading a proprietary kernel module fails with 'Invalid module format'. The module was built from source against the previous kernel. What is the most likely cause?

A.Module is not signed while Secure Boot is enabled
B.Module file permissions are incorrect
C.SELinux is blocking the module load
D.Module was not rebuilt for the new kernel version
AnswerD

Kernel modules are version-specific: the module was compiled against the previous kernel's headers and symbols. Loading it into the updated kernel fails because the vermagic and symbol versions no longer match, so it must be rebuilt.

Why this answer

The 'Invalid module format' error occurs when a kernel module's version magic string does not match the running kernel's version. Since the module was built against the previous kernel, it contains version information for that older kernel, and the new kernel rejects it as incompatible. Rebuilding the module against the new kernel's headers resolves this mismatch.

Exam trap

The trap here is that candidates confuse the 'Invalid module format' error with Secure Boot signing issues, but Secure Boot produces a different error message related to key verification, not format mismatch.

How to eliminate wrong answers

Option A is wrong because Secure Boot with unsigned modules typically produces a 'Required key not available' or 'Module verification failed' error, not 'Invalid module format'. Option B is wrong because incorrect file permissions would cause a 'Permission denied' error when trying to insmod, not a format error. Option C is wrong because SELinux denials generate AVC denial messages in the audit log and would prevent loading due to policy restrictions, not an 'Invalid module format' error.

455
MCQmedium

A Linux administrator notices that the system’s disk I/O performance has degraded significantly. Running 'iostat -x 1' shows high %util values on /dev/sda, but low await. Which of the following is the most likely issue?

A.The filesystem is nearly full.
B.The disk cable is loose or faulty.
C.There are many concurrent I/O requests (high queue depth).
D.The disk is failing and needs replacement.
AnswerC

High %util with low await indicates the device is saturated by request volume rather than slow individual operations. Many concurrent I/O requests queue up, keeping the disk busy; await stays low because each request completes quickly once serviced, so queue depth is the bottleneck.

Why this answer

High %util with low await indicates that the device is busy processing many concurrent I/O requests, but each request completes quickly. This is characteristic of a high queue depth where the disk is saturated with parallel requests, not that individual requests are slow. The low await confirms that the disk itself is responding fast, so the bottleneck is the volume of simultaneous I/O, not latency per request.

Exam trap

CompTIA often tests the misconception that high %util always means slow I/O, but the trap here is that %util measures busy time, not latency; candidates overlook the low await and incorrectly assume hardware failure or cable issues.

How to eliminate wrong answers

Option A is wrong because a nearly full filesystem affects metadata operations and may cause fragmentation, but it does not directly cause high %util with low await; it would more likely increase await due to slower allocation. Option B is wrong because a loose or faulty disk cable typically causes intermittent errors, timeouts, or complete disconnection, which would manifest as high await and possibly errors in iostat, not high %util with low await. Option D is wrong because a failing disk usually produces high await, increased error counts, and reallocated sectors, not a scenario where requests complete quickly (low await) while the device is busy.

456
MCQhard

A security policy requires that user passwords must expire after 90 days. The output in the exhibit shows the current configuration for the root user. Which command should the administrator run to enforce the policy for root?

A.sudo passwd -x 90 root
B.sudo chage -M 90 root
C.sudo chage -E 90 root
D.sudo usermod -e 90 root
AnswerB

`chage -M 90 root` sets the maximum password age to 90 days for the root account, directly satisfying the policy's expiry constraint. Unlike `passwd`, which only changes the password itself, `chage` manipulates account aging fields in `/etc/shadow`, so the password will expire 90 days after the last change.

Why this answer

The `chage -M 90 root` command sets the maximum number of days a password is valid for the root user to 90 days, which directly enforces the password expiration policy. The `-M` option modifies the `max_days` field in `/etc/shadow`, causing the password to expire after the specified period. This is the correct method to apply aging rules to the root account.

Exam trap

The trap here is that candidates confuse the `chage -M` (maximum password age) with `chage -E` (account expiration) or `usermod -e` (account expiration), leading them to select options that set account expiry instead of password expiry, which does not enforce the 90-day password change requirement.

How to eliminate wrong answers

Option A is wrong because `passwd -x 90 root` is not a valid syntax; the `passwd` command uses `-x` to set maximum password days but requires the option before the username (e.g., `passwd -x 90 root`), and even then it only works if the user is not root or if run as root without `sudo`; however, the primary issue is that the question asks for the command to enforce the policy, and `chage` is the standard tool for password aging policies. Option C is wrong because `chage -E 90 root` sets the account expiration date to a specific date (interpreted as days since epoch or a date string), not the password maximum age; `-E` controls account expiry, not password expiry. Option D is wrong because `usermod -e 90 root` sets the account expiration date (in YYYY-MM-DD format or days since epoch), not the password maximum age; `-e` is for account expiry, while `-f` or `-L` would be unrelated, and password aging is managed via `chage` or `passwd`.

457
Multi-Selectmedium

A Linux administrator is writing a Bash script that must safely process a list of filenames, some of which may contain spaces or special characters. The script reads each line from a file into a variable and then iterates over the entries. Which TWO practices should the administrator follow to avoid word-splitting and globbing issues? (Choose two.)

Select 2 answers
A.Disable globbing by running set -f at the start of the script and never re-enable it.
B.Quote the variable expansion, for example "$filename", whenever it is used in commands.
C.Set the IFS variable to a newline character globally at the top of the script before any commands run.
D.Use IFS= read -r line inside a while loop to read each line without stripping leading or trailing whitespace and without interpreting backslashes.
E.Use the eval command to expand the variable so that spaces are handled automatically.
AnswersB, D

Quoting the variable expansion prevents the shell from performing word splitting and pathname expansion on the value. If a filename contains spaces or wildcard characters, an unquoted expansion would break it into multiple arguments or expand globs, causing the command to operate on the wrong files. Quoting preserves the value as a single argument.

Why this answer

To safely handle filenames with spaces or special characters, the script should quote variable expansions so the shell treats each value as a single argument, and read lines with IFS= read -r to preserve whitespace and backslashes. These two practices together prevent word splitting and globbing from corrupting the data during iteration.

Exam trap

The trap here is believing that globally changing IFS or using eval will solve quoting problems, when scoped quoting and IFS= read -r are the correct targeted techniques.

458
Multi-Selecthard

A system administrator is investigating a slow website. The web server is responding but pages load slowly. Which THREE commands can help identify network latency or packet loss?

Select 3 answers
A.dig example.com
B.mtr example.com
C.ping -c 10 example.com
D.ss -tlnp
E.traceroute example.com
AnswersB, C, E

mtr combines ping and traceroute, continuously probing each hop between the host and example.com. It reports per-hop latency, jitter and packet loss, pinpointing whether slowness arises on the local network, an intermediate router or the destination itself.

Why this answer

Option B, mtr example.com, is correct because mtr combines ping and traceroute into a continuous, per-hop report showing packet loss percentages and latency (average/best/worst) at each router along the path, which directly exposes where latency or loss is introduced. Option C, ping -c 10 example.com, is correct because it sends 10 ICMP Echo Requests and reports round-trip time statistics plus packet loss percentage to the destination, giving a quick measure of latency and loss to the target host. Option E, traceroute example.com, is correct because it maps the hop-by-hop path to the destination using incrementing TTL values and reports per-hop RTTs, revealing which intermediate hop adds delay or drops packets.

Option A, dig example.com, is not correct here because it only queries DNS records and measures name-resolution behavior, not end-to-end network latency or packet loss. Option D, ss -tlnp, is not correct because it merely lists local listening TCP sockets and their owning processes, providing no path latency or loss measurements.

Exam trap

CompTIA often tests the distinction between `traceroute` (which shows a single snapshot of path latency) and `mtr` (which provides ongoing, aggregated statistics including packet loss per hop), leading candidates to overlook `mtr` as a superior tool for diagnosing intermittent or persistent network issues.

459
Multi-Selecteasy

An administrator is troubleshooting a server that is experiencing intermittent high load. The administrator wants to identify processes that are using excessive CPU. Which two of the following commands can provide real-time CPU usage per process? (Choose two.)

Select 2 answers
A.htop
B.top
C.iostat
D.ps -aux
E.vmstat
AnswersA, B

htop renders a continuously refreshing per-process view with CPU percentage and load averages, satisfying the requirement for real-time CPU usage per process. Its interactive interface lets the administrator sort by CPU to pinpoint the processes driving intermittent high load.

Why this answer

A is correct because `htop` is an interactive process viewer that displays real-time CPU usage per process, with a color-coded interface and the ability to sort by CPU consumption. B is correct because `top` is the standard real-time system monitor that shows a dynamic list of processes and their current CPU utilization, updating every few seconds by default.

Exam trap

CompTIA often tests the distinction between real-time monitoring commands and static snapshot commands; the trap here is that `ps -aux` shows CPU usage but only at the instant of execution, leading candidates to mistakenly think it provides real-time updates like `top` or `htop`.

460
MCQhard

A Linux administrator needs to ensure that only the root user can run commands in the /usr/local/bin/scripts directory. Which command should be used to set the appropriate permissions?

A.chmod 750 /usr/local/bin/scripts
B.chmod 700 /usr/local/bin/scripts
C.chmod 755 /usr/local/bin/scripts
D.chmod 770 /usr/local/bin/scripts
AnswerB

Mode 700 grants read, write and execute to the owner (root) while denying all access to group and others, satisfying the requirement that only root can run scripts in that directory. It also preserves the execute bit needed to traverse and run files.

Why this answer

The requirement is that only the root user can run commands in the directory. Permission 700 (owner: rwx, group: ---, others: ---) grants full access exclusively to the owner (root), while denying all access to the group and others. This matches the requirement precisely.

Exam trap

The trap here is that candidates often choose 755 or 750 as 'standard' permissions for directories, forgetting that the requirement explicitly restricts access to only root, not to any group or other users.

How to eliminate wrong answers

Option A (750) is wrong because it grants read and execute permissions to the group, allowing group members (other than root) to list and run scripts, which violates the 'only root' requirement. Option C (755) is wrong because it grants read and execute to both group and others, allowing any user on the system to list and execute scripts. Option D (770) is wrong because it grants full read, write, and execute to the group, allowing group members to modify and run scripts, which again violates the restriction to root only.

461
MCQhard

During peak hours, a web server experiences timeouts. The kernel log shows 'possible SYN flooding'. Which kernel parameter should be increased to mitigate this?

A.net.ipv4.tcp_syncookies
B.net.core.somaxconn
C.net.ipv4.tcp_max_syn_backlog
D.net.core.rmem_default
AnswerC

Raising `net.ipv4.tcp_max_syn_backlog` enlarges the queue holding half-open SYN_RECV connections awaiting the final ACK. Under peak load, that backlog overflows, so the kernel logs 'possible SYN flooding' and drops new handshakes. Increasing it lets the server absorb the burst, directly addressing the timeout constraint.

Why this answer

The kernel log message 'possible SYN flooding' indicates that the system's SYN backlog queue is full, causing new connection requests to be dropped. Increasing `net.ipv4.tcp_max_syn_backlog` expands the maximum number of SYN requests that can be queued before the kernel starts dropping them, directly mitigating the issue.

Exam trap

The trap here is confusing the SYN backlog queue (`tcp_max_syn_backlog`) with the completed connection backlog (`somaxconn`), leading candidates to choose `net.core.somaxconn` even though it only affects fully established connections, not the SYN flood protection mechanism.

How to eliminate wrong answers

Option A is wrong because `net.ipv4.tcp_syncookies` enables SYN cookies as a defense against SYN flood attacks, but it does not increase the queue size; it bypasses the backlog entirely, which can degrade performance for legitimate traffic. Option B is wrong because `net.core.somaxconn` limits the maximum number of connections that can be queued for a listening socket after the three-way handshake is complete, not the SYN backlog queue for half-open connections. Option D is wrong because `net.core.rmem_default` sets the default receive socket buffer size for data transfer, which has no effect on the SYN backlog or connection establishment.

462
Multi-Selecthard

A Linux administrator is reviewing an Ansible playbook that manages a fleet of servers. The playbook must run a task only on hosts in the group webservers and must notify a handler when a configuration file changes. Which TWO of the following are valid Ansible constructs that the administrator should use? (Choose two.)

Select 2 answers
A.serial: 1
B.notify: restart nginx
C.hosts: webservers
D.when: ansible_os_family == "Debian"
E.become: yes
AnswersB, C

The notify keyword on a task triggers a handler by name when the task reports a changed state. Pairing it with a handler named restart nginx, defined in the handlers section, ensures the service is restarted only when the configuration file actually changes, which is the intended behavior.

Why this answer

The hosts directive scopes the play to the webservers inventory group, and the notify keyword on a task causes a named handler to run when that task changes state. Together they ensure the play runs only on the intended hosts and that a service restart handler fires only when the configuration file is modified.

Exam trap

The trap here is assuming that become or when are required for targeting and notification, when in fact hosts and notify are the keywords that directly implement those behaviors.

463
MCQeasy

A Linux administrator writes a script that uses bash-specific features like arrays and process substitution. Which shebang should be used?

A.#!/bin/bash
B.#!/bin/sh
C.#!/usr/bin/python3
D.#!/bin/ksh
AnswerA

#!/bin/bash invokes the Bash interpreter directly, which is required because arrays and process substitution are Bash extensions absent from POSIX sh. The stem's constraint is the script's reliance on bash-specific syntax, so the shebang must name bash rather than a portable shell such as /bin/sh.

Why this answer

The correct shebang is #!/bin/bash because the script uses bash-specific features such as arrays and process substitution. The shebang line tells the system to execute the script with the specified interpreter; /bin/bash is the Bourne Again SHell, which supports these features, while /bin/sh may be a POSIX shell that lacks them.

Exam trap

The trap here is that candidates often assume /bin/sh is always bash or that any shell can run bash-specific syntax, but on many Linux distributions /bin/sh is a different shell (e.g., dash) that lacks these extensions.

How to eliminate wrong answers

Option B is wrong because /bin/sh is often a POSIX-compliant shell (like dash on Debian) that does not support bash-specific features such as arrays and process substitution, causing the script to fail. Option C is wrong because /usr/bin/python3 is the Python 3 interpreter, which cannot execute bash syntax. Option D is wrong because /bin/ksh is the Korn shell, which has its own syntax and may not support bash-specific features like process substitution in the same way.

464
Multi-Selectmedium

A system administrator wants to automate server configuration and management across multiple Linux hosts. Which TWO tools are configuration management solutions designed for this purpose? (Choose two.)

Select 2 answers
A.Docker
B.Nagios
C.Kubernetes
D.Puppet
E.Ansible
AnswersD, E

Puppet is a declarative configuration management tool using a master-agent architecture and its own DSL to enforce desired state across managed Linux hosts. This satisfies the stem's requirement for a configuration management solution by automating server configuration at scale.

Why this answer

Puppet (D) is a declarative configuration management tool that uses a master-agent architecture with manifests and modules to enforce desired state across many Linux hosts, making it a correct fit for automating server configuration and management. Ansible (E) is also a configuration management solution that uses agentless SSH connections and YAML playbooks to push configuration and orchestrate tasks across multiple hosts, so it is correct as well. Docker (A) is a containerization platform for packaging and running applications, not a configuration management tool for enforcing host configuration.

Nagios (B) is a monitoring and alerting system, not a configuration management solution. Kubernetes (C) is a container orchestration platform for deploying and managing containerized workloads, not a general Linux configuration management tool.

Exam trap

The trap here is that candidates confuse containerization (Docker) or orchestration (Kubernetes) with configuration management, or mistake monitoring (Nagios) for a tool that configures systems, when the question specifically asks for tools that automate server configuration and management across multiple hosts.

465
MCQeasy

Users report that a web application on a Linux server is unreachable from external clients. From the server itself, curl http://localhost works fine. The administrator wants to confirm whether the service is bound only to the loopback interface. Which command should the administrator run?

A.ss -tlnp
B.nmap -p 80 localhost
C.ip route show
D.tcpdump -i lo port 80
AnswerA

ss -tlnp lists TCP sockets in listening state with their local addresses and owning processes. If the web service shows 127.0.0.1:80 instead of 0.0.0.0:80 or the host address, it is bound only to loopback, explaining why remote clients fail while localhost succeeds.

Why this answer

The symptom pattern, local success plus remote failure, often means the daemon is bound to 127.0.0.1 rather than all interfaces. ss -tlnp displays each listening TCP socket's local address and process, making the bind scope explicit. Routing, loopback scanning, and loopback capture all miss the actual socket configuration.

Exam trap

The trap here is assuming the firewall is at fault when localhost works; a loopback-only bind produces the same symptom without any firewall rule.

466
MCQmedium

Scenario: A cloud hosting company uses SELinux in enforcing mode on all Linux servers. A developer reports that a custom web application running under Apache (httpd) is unable to write log files to /var/log/myapp/. The directory /var/log/myapp/ has permissions 755 and is owned by root:root. The httpd process runs as the 'apache' user. The administrator checks SELinux context: /var/log/myapp is labeled with default_t type. The administrator wants to allow httpd to write to this directory while maintaining security. Which command should the administrator run?

A.Change ownership with 'chown apache:apache /var/log/myapp'
B.Run 'setenforce 0' to disable SELinux
C.Run 'chcon -t httpd_log_t /var/log/myapp'
D.Run 'semanage fcontext -a -t httpd_log_t "/var/log/myapp(/.*)?"' and then 'restorecon -Rv /var/log/myapp'
AnswerD

Labeling the directory with the httpd_log_t type grants httpd write access under SELinux, satisfying the enforcing-mode constraint that default_t denies. The semanage fcontext command adds the persistent file-context rule, and restorecon applies it to the existing files.

Why this answer

It permanently relabels the directory with the httpd_log_t SELinux type, which is specifically designed to allow Apache (httpd) to write log files. The semanage fcontext command adds a file context mapping to the SELinux policy database, and restorecon applies that mapping to the filesystem. This approach maintains SELinux enforcing mode and does not rely on temporary changes like chcon or insecure workarounds like disabling SELinux.

Exam trap

The trap here is that candidates often choose chcon (Option C) because it works immediately, but they overlook that it is not persistent and will be overwritten by restorecon or policy updates, whereas semanage fcontext followed by restorecon is the correct persistent method.

How to eliminate wrong answers

Option A is wrong because changing ownership to apache:apache does not address SELinux type enforcement; the httpd process is still blocked by the default_t type on the directory, regardless of Unix permissions. Option B is wrong because running 'setenforce 0' disables SELinux entirely, which violates the company's security policy of running in enforcing mode and exposes the server to potential threats. Option C is wrong because 'chcon -t httpd_log_t /var/log/myapp' only makes a temporary label change that will be reverted on the next filesystem relabel (e.g., after a policy update or restorecon run), and it does not persist in the SELinux policy database.

467
MCQmedium

An administrator needs to check the kernel ring buffer for hardware error messages after a system crash. Which command should be used?

A.dmesg
B.journalctl -k
C.tail -f /var/log/messages
D.strace -e trace=open
AnswerA

dmesg reads the kernel ring buffer, which retains hardware detection, driver and error messages logged by the kernel. After a crash, this buffer holds the relevant hardware diagnostics, satisfying the requirement to inspect kernel-level error output.

Why this answer

dmesg shows kernel ring buffer messages including hardware errors. journalctl -k shows kernel messages from systemd journal, but dmesg is the direct command for the ring buffer.

468
Multi-Selectmedium

A Linux server is experiencing high CPU usage. Which TWO commands can be used to identify which processes are consuming the most CPU? (Choose two.)

Select 2 answers
A.ps aux --sort=-%cpu
B.top
C.iostat
D.vmstat
E.free
AnswersA, B

`ps aux --sort=-%cpu` lists every process with its CPU percentage, sorted descending by that column, so the heaviest consumers appear first. This directly satisfies the stem's requirement to identify which processes are consuming the most CPU on the Linux server, giving an immediate ranked snapshot without interactive monitoring.

Why this answer

Option A, `ps aux --sort=-%cpu`, is correct because it lists all processes with their CPU utilization and sorts them in descending order by the %CPU column, immediately revealing the top CPU consumers. Option B, `top`, is correct because it provides a real-time, dynamically refreshing view of running processes ranked by CPU usage, allowing an administrator to identify which processes are consuming the most CPU. Option C, `iostat`, is incorrect because it reports CPU and I/O statistics per device rather than per-process CPU consumption.

Option D, `vmstat`, is incorrect because it reports system-wide memory, paging, and CPU summary statistics, not individual process CPU usage. Option E, `free`, is incorrect because it only displays memory and swap usage, providing no per-process CPU information.

469
Multi-Selectmedium

A security audit identifies that the system's /etc/passwd file is world-readable. Which three security issues does this pose? (Select THREE.)

Select 3 answers
A.Attackers can read the encrypted passwords.
B.Attackers can obtain usernames easily.
C.Attackers can see home directory paths.
D.Attackers can see user ID mappings.
E.Attackers can read password hashes.
AnswersB, C, D

World-readable /etc/passwd lets any local user or attacker enumerate every account name on the host, providing a ready target list for password guessing, credential stuffing or brute-force attempts. Usernames alone are not secret, but their exposure materially aids account discovery.

Why this answer

Option B is correct because /etc/passwd contains one line per account with the username in the first colon-separated field, so a world-readable file lets attackers enumerate valid local usernames for brute-force or phishing attacks. Option C is correct because the sixth field of each /etc/passwd entry holds the user's home directory path, exposing directory layout that aids targeted attacks on user files or SSH keys. Option D is correct because the third field contains the numeric UID and the fourth field the primary GID, so attackers learn the UID-to-username mapping needed to craft privilege-escalation or file-ownership exploits.

Option A is not correct because modern /etc/passwd stores an 'x' placeholder in the password field, not the encrypted password itself. Option E is likewise not correct because password hashes are kept in the shadowed /etc/shadow file, which is not world-readable.

Exam trap

The trap here is that candidates often confuse the legacy practice of storing password hashes in /etc/passwd with the modern shadow password suite, and mistakenly select options A or E, not realizing that /etc/shadow is the actual hash store.

470
MCQeasy

Which command displays the current routing table on a Linux system?

A.ip neigh
B.ip addr
C.ip link
D.ip route
AnswerD

The ip route command queries the kernel's routing table via the iproute2 suite, listing destination networks, gateways and interfaces. It satisfies the requirement to display current routes, unlike legacy netstat -r or route, which are deprecated on modern Linux distributions.

Why this answer

ip route shows the routing table. The older route command is deprecated.

471
MCQeasy

A Linux administrator needs to add a new user named 'jdoe' with a home directory and bash shell. Which command accomplishes this?

A.groupadd -u jdoe -s /bin/bash
B.useradd -m -s /bin/bash jdoe
C.adduser -h /home/jdoe -s bash jdoe
D.usermod -m -s /bin/bash jdoe
AnswerB

useradd -m creates the home directory and -s /bin/bash sets the login shell, satisfying both stated requirements in a single command. Without -m, no home directory is created; without -s, the system default shell applies.

Why this answer

The useradd command creates a new user, and the -m flag creates the home directory, -s sets the shell. useradd -m -s /bin/bash jdoe is correct.

472
MCQhard

An administrator modified kernel parameters in /etc/sysctl.conf. Which command applies the changes without rebooting?

A.sysctl -p
B.sysctl -w
C.sysctl -r
D.sysctl -a
AnswerA

The sysctl -p command reloads settings from /etc/sysctl.conf into the running kernel, applying the modified parameters immediately without a reboot. This directly satisfies the requirement to activate the edited values on the live system rather than waiting for a restart.

Why this answer

The `sysctl -p` command reads the settings from `/etc/sysctl.conf` and applies them immediately to the running kernel without requiring a reboot. This is the standard method for reloading persistent kernel parameter changes on Linux systems.

Exam trap

The trap here is that candidates confuse `sysctl -p` (apply from file) with `sysctl -w` (set a single value), or assume a reboot is required, leading them to choose an incorrect option like `sysctl -w` or a non-existent flag.

How to eliminate wrong answers

Option B is wrong because `sysctl -w` is used to temporarily set a single kernel parameter at runtime, not to load changes from a configuration file. Option C is wrong because `sysctl -r` is not a valid sysctl option; the correct flag for reloading from a file is `-p`. Option D is wrong because `sysctl -a` displays all current kernel parameters and their values, but does not apply or reload any configuration changes.

473
MCQmedium

A Linux administrator needs to inspect the capabilities assigned to the /usr/bin/ping binary to verify it can open raw sockets without being setuid root. Which command should be used?

A.chacl -l /usr/bin/ping
B.getfacl /usr/bin/ping
C.lsattr /usr/bin/ping
D.getcap /usr/bin/ping
AnswerD

getcap reads and displays the file capabilities stored in the security.capability extended attribute of a binary. For /usr/bin/ping, it would report cap_net_raw=ep, confirming the binary can open raw sockets without setuid root. This is exactly the inspection the administrator needs to verify least-privilege configuration on the ping utility.

Why this answer

File capabilities allow a binary to perform privileged operations without being setuid root. The getcap command reads the security.capability extended attribute and reports capabilities such as cap_net_raw. Inspecting /usr/bin/ping with getcap confirms whether it can open raw sockets under least privilege, which is the goal of the administrator's verification.

Exam trap

The trap here is confusing file capabilities with POSIX ACLs or filesystem attributes, leading to tools like getfacl or lsattr instead of getcap.

474
Multi-Selectmedium

A Linux administrator is troubleshooting a service that fails to start. Which TWO commands can be used to view the last 20 lines of the systemd journal for the sshd unit?

Select 2 answers
A.journalctl -u sshd -n 20
B.journalctl -u sshd | tail -20
C.journalctl -k -n 20
D.journalctl -u sshd -p err
E.journalctl -b -u sshd
AnswersA, B

journalctl's -u flag filters entries to the sshd unit, and -n 20 limits output to the last 20 lines, satisfying both stem constraints in one invocation. This queries the systemd journal directly, showing recent sshd startup failures without piping to another utility.

Why this answer

Option A, `journalctl -u sshd -n 20`, is correct because `-u sshd` filters the journal to the sshd unit and `-n 20` limits the output to the last 20 lines, exactly matching the requirement. Option B, `journalctl -u sshd | tail -20`, is also correct because `journalctl -u sshd` produces the sshd unit's journal entries and piping them to `tail -20` displays only the final 20 lines. Option C, `journalctl -k -n 20`, is wrong because `-k` restricts output to kernel messages rather than the sshd unit.

Option D, `journalctl -u sshd -p err`, is wrong because `-p err` filters by priority level (error and above) instead of returning the last 20 lines. Option E, `journalctl -b -u sshd`, is wrong because `-b` limits output to the current boot but does not restrict the result to the last 20 lines.

475
MCQmedium

An administrator wants to start a long-running script in the background so that it continues running even after logging out. Which command should be used?

A.script.sh &
B.nohup script.sh &
C.nohup script.sh
D.bg script.sh
AnswerB

nohup makes the process immune to SIGHUP, so it survives terminal closure and logout, while the trailing & backgrounds it immediately. This satisfies the requirement that the script keeps running after the session ends, unlike a plain background job.

Why this answer

nohup (no hangup) makes the process immune to the SIGHUP signal that is sent to child processes when the controlling terminal closes on logout. Appending & backgrounds the job so the shell returns a prompt immediately. Combining both is required: nohup alone still runs in the foreground and blocks the terminal, while & alone leaves the process vulnerable to SIGHUP on logout.

Exam trap

The trap here is confusing backgrounding (&) with detaching from the terminal (nohup); candidates pick & alone and forget that SIGHUP kills the job on logout.

How to eliminate wrong answers

Option A is wrong because script.sh & only backgrounds the job; when the login shell exits it sends SIGHUP to its process group and the script is terminated. Option C is wrong because nohup script.sh runs the script in the foreground, so the administrator cannot continue using the shell and the terminal session is tied up. Option D is wrong because bg is a shell builtin that only resumes a stopped job in the background of the current shell; it does not detach the process from the terminal or protect it from SIGHUP at logout.

476
MCQeasy

Refer to the exhibit. A user wants to execute the script 'script.sh' but receives a 'Permission denied' error. Which action should be taken to allow execution?

A.Add execute permission with chmod +x script.sh
B.Change the owner to the user with chown
C.Change the group to the user's primary group
D.Set the permissions to 644 with chmod
AnswerA

The script lacks the execute bit, so the kernel refuses to run it despite read permission. chmod +x adds execute permission for owner, group and others, allowing direct invocation of script.sh without prefixing an interpreter.

Why this answer

The 'Permission denied' error indicates the script lacks the execute permission for the user. The `chmod +x script.sh` command adds the execute permission bit to the file's mode, allowing the user to run it as a program. This is the direct and correct fix for the issue.

Exam trap

CompTIA often tests the misconception that changing ownership or group alone resolves permission errors, when in fact the execute permission bit must be explicitly set for the file to be run as a script.

How to eliminate wrong answers

Option B is wrong because changing the owner with `chown` does not grant execute permission; it only changes file ownership, and the new owner still needs execute permission to run the script. Option C is wrong because changing the group to the user's primary group does not add execute permission; the group must have the execute bit set in the file's permissions for this to work. Option D is wrong because setting permissions to 644 (rw-r--r--) removes any execute bits, which would still prevent execution and is the opposite of what is needed.

477
MCQmedium

An administrator wants to change the priority of a running process with PID 1234 to a lower priority (nicer). The current nice value is 0. Which command will set the nice value to 10?

A.renice 10 -p 1234
B.nice -n 10 kill 1234
C.chrt -p 10 1234
D.kill -10 1234
AnswerA

renice alters the nice value of an already-running process identified by PID, so renice 10 -p 1234 raises niceness from 0 to 10, lowering scheduling priority. The -p flag specifies the target PID, satisfying the requirement to change a running process rather than launch a new one.

Why this answer

The `renice` command is used to alter the scheduling priority of an already running process. By default, a process starts with a nice value of 0. Running `renice 10 -p 1234` sets the nice value to 10, which is a lower priority (more 'nice') because the kernel adds this value to the dynamic priority calculation, giving the process less CPU time.

Exam trap

The Linux+ exam often tests the distinction between `renice` (for running processes) and `nice` (for launching a new process with a modified priority), and candidates may confuse `renice` with `nice` or think `kill` can change priority via signal numbers.

How to eliminate wrong answers

Option B is wrong because `nice -n 10 kill 1234` attempts to run the `kill` command with a nice value of 10, but `kill` does not change the priority of an existing process; it sends signals. Option C is wrong because `chrt -p 10 1234` sets the real-time scheduling policy and priority (via the `-p` flag with a priority value), not the nice value; `chrt` manipulates the SCHED_FIFO or SCHED_RR policy, not the conventional nice/renice mechanism. Option D is wrong because `kill -10 1234` sends signal 10 (SIGUSR1 by default on Linux) to the process, which has no effect on its nice value or scheduling priority.

478
MCQmedium

A Linux administrator is writing a bash script that accepts command-line options: -a for all, -f for file, and -o for output. Which of the following correctly uses getopts to parse these options?

A.while getopts "-a -f -o" opt; do ... done
B.while getopts "a:f:o" opt; do case $opt in a) ...;; f) ...;; o) ...;; esac; done
C.getopts "afo" opt; case $opt in a) ...;; f) ...;; o) ...;; esac
D.while getopts "afo" opt; do case $opt in a) ...;; f) ...;; o) ...;; esac; done
AnswerD

Correct. The option string 'afo' defines three boolean options without arguments.

Why this answer

getopts uses a string of option characters; a colon after an option indicates it requires an argument. The correct usage is 'a:f:o' where a and f require arguments, but the stem doesn't specify arguments. Assuming -a and -f don't require arguments, the string should be 'afo'.

479
MCQmedium

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The pipeline should build a Docker image, run unit tests, and if successful, push the image to a private registry. Which tool is best suited for orchestrating this pipeline?

A.Git
B.cron
C.Jenkins
D.Ansible
AnswerC

Jenkins orchestrates the full pipeline through declarative pipelines and its plugin ecosystem, chaining build, unit test and registry push stages with conditional promotion. It satisfies the stem's requirement to sequence these stages and gate the push on test success.

Why this answer

Jenkins is a widely adopted CI/CD automation server that excels at orchestrating complex pipelines, including building Docker images, running unit tests, and pushing images to a private registry. Its pipeline-as-code feature (Jenkinsfile) allows defining stages, triggers, and post-build actions, making it the best fit for this microservices CI/CD workflow.

Exam trap

CompTIA often tests the distinction between CI/CD orchestration tools and general automation or scheduling tools; the trap here is that candidates may confuse Ansible's automation capabilities with CI/CD pipeline orchestration, or think cron can handle complex multi-step workflows with conditional logic.

How to eliminate wrong answers

Option A is wrong because Git is a distributed version control system used for source code management, not for orchestrating CI/CD pipelines or executing build/test/deploy steps. Option B is wrong because cron is a time-based job scheduler in Unix/Linux that can only run simple scripts at fixed intervals; it lacks pipeline logic, dependency management, and integration with Docker registries or test frameworks. Option D is wrong because Ansible is a configuration management and automation tool primarily used for provisioning and infrastructure as code, not for continuous integration pipeline orchestration; it does not natively support event-driven CI/CD triggers or pipeline stages.

480
Drag & Dropmedium

Drag and drop the steps to set up a cron job that runs a script daily in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Setting up a cron job correctly involves first writing the script that will be executed, then making it executable with chmod +x, then adding a crontab entry using crontab -e with the correct time specification (e.g., '0 0 * * *' for daily at midnight), and finally verifying the job is listed with crontab -l. This order ensures the script is ready and permissions are set before cron attempts to run it, and verification confirms the entry is valid.

481
MCQmedium

A Linux administrator needs to locate all files in the /var directory that have been modified within the last 30 minutes and are larger than 10MB. Which command accomplishes this task?

A.find /var -mmin 30 -size +10M
B.find /var -mmin -30 -size +10M
C.locate /var -mmin -30 -size +10M
D.find /var -mtime -30 -size +10M
AnswerB

The -mmin -30 predicate matches files modified within the last 30 minutes, and -size +10M selects those larger than 10MB. Combining both in one find invocation over /var returns exactly the files meeting both constraints simultaneously.

Why this answer

The correct command is `find /var -mmin -30 -size +10M`. The `-mmin -30` option tells find to match files modified less than 30 minutes ago (the minus sign means 'less than'), and `-size +10M` matches files larger than 10 megabytes. This combination precisely meets the requirement of files modified within the last 30 minutes and larger than 10MB.

Exam trap

The trap here is confusing `-mmin` (minutes) with `-mtime` (days), and misinterpreting the minus sign: `-mmin -30` means less than 30 minutes ago, while `-mmin 30` means exactly 30 minutes ago. Candidates often mistakenly choose `-mtime -30` thinking it means minutes, or omit the minus sign.

How to eliminate wrong answers

Option A is wrong because `-mmin 30` matches files modified exactly 30 minutes ago, not within the last 30 minutes; it would miss files modified 5 or 20 minutes ago. Option C is wrong because `locate` does not support `-mmin` or `-size` options; locate searches a prebuilt database by filename and cannot filter by modification time or size. Option D is wrong because `-mtime -30` matches files modified within the last 30 days, not 30 minutes, so it would return far too many files.

482
MCQhard

A server is experiencing intermittent network connectivity issues. The administrator wants to run a continuous test that combines ping and traceroute to monitor the path and packet loss to a target host. Which command should be used?

A.mtr target
B.tcpdump -i any host target
C.ping -f target
D.traceroute -n target
AnswerA

`mtr target` continuously combines ping and traceroute, refreshing hop-by-hop latency and packet-loss statistics in real time. This satisfies the stem's requirement for an ongoing test monitoring both path and loss, unlike one-shot `traceroute` or plain `ping`, which cannot show per-hop loss across the route simultaneously.

Why this answer

The mtr command combines the functionality of ping and traceroute by continuously sending packets to a target and displaying per-hop latency and packet loss, making it ideal for monitoring intermittent network issues over time.

Exam trap

XK0-006 often tests the confusion between one-time diagnostic tools like traceroute and continuous monitoring tools like mtr, or the misconception that ping -f provides path analysis.

How to eliminate wrong answers

Option B is wrong because tcpdump captures packets but does not provide a continuous path analysis or packet loss per hop. Option C is wrong because ping -f floods the target with packets, which can cause network congestion and is not a combined ping/traceroute tool. Option D is wrong because traceroute -n only performs a one-time trace and does not continuously monitor or show packet loss over time.

483
Multi-Selectmedium

A Linux administrator needs to locate all files in the /etc directory that have been modified in the last 24 hours and are not owned by root. Which two commands can be combined to achieve this? (Select TWO.)

Select 2 answers
A.find /etc -mtime 0 -not -user root
B.find /etc -ctime 0 -not -group root
C.find /etc -mmin -1440 -not -user root
D.find /etc -mtime 0 -uid 0
E.find /etc -atime 0 -not -user root
AnswersA, C

-mtime 0 matches files modified within the last 24 hours, and -not -user root excludes root-owned files, meeting both stem constraints in one pass. The -mtime test counts whole 24-hour periods, so 0 covers the current day.

Why this answer

Option A is correct because 'find /etc -mtime 0 -not -user root' searches /etc for files whose modification time falls within the last 24 hours (-mtime 0 means modified less than 1 day ago) and excludes files owned by root via -not -user root. Option C is correct because 'find /etc -mmin -1440 -not -user root' uses -mmin -1440, which matches files modified less than 1440 minutes (24 hours) ago, and likewise filters out root-owned files with -not -user root. Option B is wrong because -ctime checks inode change time, not modification time, and -not -group root filters by group ownership rather than user ownership.

Option D is wrong because -uid 0 selects files owned by root, the opposite of what is required. Option E is wrong because -atime checks access time, not modification time, so it does not identify recently modified files.

Exam trap

The trap is confusing -mtime with -ctime and -atime, and mixing up -user with -group — candidates must remember that -mtime is content modification, -ctime is inode change, and -atime is access.

484
MCQhard

A server is secured with SELinux in enforcing mode. A custom web application needs to write logs to /var/log/webapp. The SELinux type for httpd is httpd_t. Which command sets the correct context for the log directory?

A.semanage fcontext -a -t httpd_log_t "/var/log/webapp(/.*)?" && restorecon -Rv /var/log/webapp
B.chcon -t httpd_sys_content_t /var/log/webapp
C.setsebool -P httpd_enable_homedirs on
D.chcon -t httpd_t /var/log/webapp
AnswerA

`httpd_log_t` is the type httpd_t domains are permitted to write, so labelling the directory with it satisfies the enforcing-mode constraint. `semanage fcontext -a` adds a persistent rule to the file-context policy, and `restorecon -Rv` applies that label recursively to existing files, which a plain `chcon` would not survive a relabel.

Why this answer

It uses `semanage fcontext` to add a persistent file context rule that assigns the `httpd_log_t` type to the `/var/log/webapp` directory and its contents, then applies it with `restorecon`. The `httpd_log_t` type is specifically designed for log files written by the httpd process, allowing Apache (running as `httpd_t`) to write logs while maintaining SELinux enforcement.

Exam trap

The trap here is that candidates confuse process domains (like `httpd_t`) with file types (like `httpd_log_t`) or mistakenly use `chcon` for a permanent context change, not realizing that `semanage fcontext` with `restorecon` is required for persistent labeling in enforcing mode.

How to eliminate wrong answers

Option B is wrong because `httpd_sys_content_t` is intended for static web content (e.g., HTML, scripts) served by httpd, not for log files; using it would not grant the necessary write permissions for logging and could cause AVC denials. Option C is wrong because `httpd_enable_homedirs` is a boolean that controls access to user home directories, not log directory labeling; it does not set any file context. Option D is wrong because `httpd_t` is a process domain type, not a file type; assigning a process type to a directory would break SELinux labeling and prevent proper access.

485
MCQmedium

The company password policy requires minimum length, complexity, and that passwords cannot be based on dictionary words. Which file should be edited to configure these settings via pam_pwquality?

A./etc/security/pwquality.conf
B./etc/login.defs
C./etc/pam.d/system-auth
D./etc/pam.d/password-auth
AnswerA

/etc/security/pwquality.conf is the pam_pwquality configuration file, holding directives such as minlen, minclass and dictcheck that enforce length, complexity and dictionary-word rejection. Editing it satisfies the stem's requirement to configure those three password policy settings centrally, rather than through PAM stack arguments in /etc/pam.d files.

Why this answer

The pam_pwquality module enforces password quality rules such as minimum length, complexity, and dictionary checks. Its configuration file is /etc/security/pwquality.conf, where parameters like minlen, dcredit, ucredit, lcredit, ocredit, and dictcheck are set. Editing this file directly controls the PAM module's behavior without modifying PAM service files.

Exam trap

The trap here is that candidates confuse the PAM service file (which invokes the module) with the module's configuration file, leading them to choose /etc/pam.d/system-auth or /etc/pam.d/password-auth instead of /etc/security/pwquality.conf.

How to eliminate wrong answers

Option B is wrong because /etc/login.defs controls shadow password suite parameters (e.g., PASS_MAX_DAYS, PASS_MIN_LEN) but does not configure pam_pwquality settings. Option C is wrong because /etc/pam.d/system-auth is a PAM service file that includes pam_pwquality via a 'password requisite pam_pwquality.so' line, but it does not contain the configuration parameters themselves. Option D is wrong because /etc/pam.d/password-auth is another PAM service file (often used for non-system logins) that similarly invokes pam_pwquality but is not the configuration file for its settings.

486
MCQeasy

A Linux administrator needs to view all current IPv4 addresses assigned to network interfaces on a system. Which command should be used?

A.ip link show
B.ifconfig -a
C.hostname -I
D.ip addr
AnswerD

`ip addr` queries the kernel's netlink interface and lists every network interface with its assigned IPv4 and IPv6 addresses, satisfying the requirement to view all current IPv4 addresses. Unlike `ifconfig`, it is part of the modern iproute2 suite and remains available on current distributions.

Why this answer

The 'ip addr' command displays all IP addresses assigned to network interfaces. 'ifconfig' is deprecated, 'ip link' shows link-layer info, and 'hostname -I' only shows primary IPs.

487
MCQhard

A Linux administrator is debugging a Bash script that uses a function to set a global counter. The function increments the variable, but after the function returns, the counter retains its original value. The script does not use subshells or pipelines around the function call. Which of the following is the MOST likely cause?

A.The counter variable was exported with export, which makes it read-only inside functions.
B.The function was defined with the function keyword instead of the POSIX name() syntax, which isolates its variables.
C.The script lacks a shebang line, so Bash runs it in POSIX mode where functions cannot modify global variables.
D.The variable was declared with the local keyword inside the function, creating a function-scoped copy that shadows the global variable.
AnswerD

When a variable is declared with local inside a function, Bash creates a new variable scoped to that function. Any modifications affect only the local copy, and when the function returns, the local variable is destroyed, leaving the global variable unchanged. Removing the local declaration or using a different variable name resolves the issue.

Why this answer

The local keyword inside a function creates a function-scoped variable that shadows any global variable of the same name. Assignments inside the function affect only the local copy, which disappears when the function returns, so the global counter appears unchanged. Removing the local declaration allows the function to modify the global variable directly.

Exam trap

The trap here is attributing the behavior to function definition syntax or export, when the actual cause is the local keyword creating a shadowed, function-scoped variable.

488
MCQmedium

A container is running and a technician needs to execute an interactive shell inside it. The container was started with 'docker run -d --name myapp myimage'. Which command will achieve this?

A.docker exec -it myapp /bin/bash
B.docker attach myapp
C.docker run -it --name myapp myimage /bin/bash
D.docker logs -f myapp
AnswerA

docker exec runs a new process inside an already-running container, and the -it flags allocate an interactive TTY plus stdin, giving a shell. Because the container was started detached with -d and named myapp, this satisfies the stem's requirement without restarting or replacing it.

Why this answer

'docker exec -it myapp /bin/bash' attaches a new interactive TTY session to the already-running container named myapp and launches /bin/bash inside it. The -i flag keeps STDIN open and -t allocates a pseudo-TTY, which is required for an interactive shell. Because the container is already running, exec is the correct tool rather than run.

Exam trap

The trap is confusing 'docker exec' (enter a running container) with 'docker attach' (connect to PID 1's stdio) or 'docker run' (create a new container) — candidates often pick attach or run when the container is already running.

How to eliminate wrong answers

Option B is wrong because 'docker attach' connects to the container's existing PID 1 STDIN/STDOUT — it does not spawn a new shell, and detaching can accidentally stop the container. Option C is wrong because 'docker run -it --name myapp myimage /bin/bash' attempts to create a new container with a duplicate name (myapp already exists), which fails, and it would start a new container rather than enter the running one. Option D is wrong because 'docker logs -f' only streams the container's log output; it provides no shell access.

489
MCQmedium

An administrator is hardening SSH and wants to disable root login and only allow users in the 'sshusers' group. Which two directives should be set in /etc/ssh/sshd_config?

A.DenyRootLogin yes and AllowGroups sshusers
B.PermitRootLogin prohibit-password and AllowGroups sshusers
C.PermitRootLogin no and AllowGroups sshusers
D.PermitRootLogin no and AllowUsers sshusers
AnswerC

PermitRootLogin no blocks direct superuser SSH access, forcing administrators to log in as themselves before elevating. AllowGroups sshusers restricts authentication to members of that group via the AllowGroups directive, satisfying both hardening constraints. DenyUsers or AllowUsers would not reference group membership.

Why this answer

The directive `PermitRootLogin no` explicitly disallows root login via SSH, and `AllowGroups sshusers` restricts SSH access to only members of the 'sshusers' group. This combination meets both requirements: disabling root login and limiting access to a specific group. The `AllowGroups` directive is group-based, unlike `AllowUsers`, which is user-based.

Exam trap

The trap here is confusing `AllowGroups` with `AllowUsers` — candidates often pick `AllowUsers sshusers` thinking it restricts to the group, but it actually restricts to a user named 'sshusers', not group membership.

How to eliminate wrong answers

Option A is wrong because `DenyRootLogin` is not a valid directive in sshd_config; the correct directive is `PermitRootLogin`. Option B is wrong because `PermitRootLogin prohibit-password` only disables password-based root login but still allows root login via public key authentication, which does not fully disable root login as required. Option D is wrong because `AllowUsers sshusers` would only allow a user literally named 'sshusers', not members of the 'sshusers' group; the correct group-based directive is `AllowGroups`.

490
Multi-Selectmedium

A user wants to create a hard link to a file. Which three conditions must be true for a hard link to be created successfully? (Choose three.)

Select 3 answers
A.The source file must have the SUID bit set.
B.The link must have the same name as the source.
C.The source and link must be on the same filesystem.
D.The source file must be a regular file, not a directory.
E.The source file must exist.
AnswersC, D, E

Hard links are directory entries pointing to the same inode, and inode numbers are unique only within a single filesystem. Cross-filesystem linking is therefore impossible, so source and link must reside on the same mounted filesystem.

Why this answer

Option C is correct because a hard link is simply a directory entry that points to the same inode, and inode numbers are only unique within a single filesystem, so the source and the new link must reside on the same filesystem (e.g., both under the same mount point). Option D is correct because hard links to directories are prohibited on Linux/Unix to prevent cycles in the directory tree, so the source must be a regular file (or another non-directory file type). Option E is correct because the link() system call requires an existing source pathname to resolve to an inode; you cannot create a hard link to a file that does not exist.

Option A is not required since the SUID bit is a permission attribute unrelated to link creation, and Option B is wrong because a hard link may have any name and is not required to match the source filename.

491
MCQeasy

A user reports that they receive 'Permission denied' when trying to run a script located in their home directory. The script has permissions -rw-rw-r-- and is owned by the user. Which command should the user run to resolve the issue?

A.chmod g-w script.sh
B.sudo chown user:user script.sh
C.chmod u+x script.sh
D.chmod a+x script.sh
AnswerC

The script lacks execute permission, shown by the absence of an x in the owner, group and other permission triads. Running chmod u+x script.sh adds execute permission for the owner, satisfying the requirement that the user be able to execute their own script without granting unnecessary rights to group or others.

Why this answer

The script has permissions -rw-rw-r--, meaning the owner (user) has read and write but not execute permission. To run it as a script, the execute bit must be set for the owner. The command chmod u+x script.sh adds execute permission for the user, allowing them to run the script directly.

Exam trap

The trap here is that candidates may think 'Permission denied' always means ownership or group issues, leading them to choose chown or group permission changes, when in fact the missing execute bit is the specific cause for script execution failures.

How to eliminate wrong answers

Option A is wrong because chmod g-w removes write permission from the group, which does not add execute permission and would not resolve the 'Permission denied' error. Option B is wrong because sudo chown user:user script.sh changes the owner and group to the user, but the script is already owned by the user, so this does nothing to add execute permission. Option D is wrong because chmod a+x adds execute permission for all (user, group, others), which would work but is overly permissive and not the minimal fix; the question asks which command the user should run, and the most appropriate and secure answer is to add execute only for the owner.

492
MCQmedium

A user is trying to log in to a Linux server via SSH but receives 'Permission denied (publickey,gssapi-keyex,gssapi-with-mic)'. The user's public key is in ~/.ssh/authorized_keys with proper permissions (600) and owned by the user. The server's sshd_config has 'PubkeyAuthentication yes' and 'PasswordAuthentication no'. What is the most likely additional cause?

A.The server's firewall is blocking port 22.
B.The user's home directory has incorrect permissions (e.g., group-writable).
C.SELinux is blocking the key authentication.
D.The SSH server is not running.
AnswerB

OpenSSH's StrictModes rejects authentication when the home directory is group- or world-writable, even if authorized_keys itself is 600. The server silently falls back to other methods, producing the publickey denial despite correct key file permissions and PubkeyAuthentication being enabled.

Why this answer

SSH server's `StrictModes` (enabled by default) checks that the user's home directory is not group-writable or world-writable. If the home directory has group-write permission (e.g., 775), SSH refuses to trust `~/.ssh/authorized_keys` even if the file itself has 600 permissions. This is a security measure to prevent other group members from modifying the authorized_keys file indirectly.

Exam trap

CompTIA often tests the subtlety that SSH's `StrictModes` checks parent directory permissions, not just the key file, leading candidates to overlook home directory permissions when the key file itself appears correct.

How to eliminate wrong answers

Option A is wrong because a firewall blocking port 22 would cause a connection timeout or 'Connection refused' error, not the specific 'Permission denied (publickey,...)' message. Option C is wrong because SELinux blocking key authentication would typically produce AVC denial messages in audit logs and a different error (e.g., 'Permission denied (publickey)' without the GSSAPI methods), and the default SELinux policy allows SSH key-based login. Option D is wrong because if the SSH server were not running, the client would receive 'Connection refused' immediately, not an SSH authentication failure message.

493
MCQhard

A Linux server is experiencing intermittent network connectivity issues. The administrator suspects that the network interface is dropping packets due to a duplex mismatch. Which command should be used to check the duplex setting and link status of the interface?

A.ifconfig eth0
B.ip link show eth0
C.netstat -i
D.ethtool eth0
AnswerD

The ethtool command queries and controls network driver and hardware settings. Running ethtool eth0 displays the link status, speed, duplex mode, and other low-level parameters. It directly shows whether the interface is running at full or half duplex, which is critical for diagnosing a duplex mismatch that can cause packet loss and intermittent connectivity.

Why this answer

The ethtool command is the standard tool for querying and modifying Ethernet device settings, including duplex and speed. It directly reports the negotiated duplex mode, allowing the administrator to verify if the interface is operating at half duplex when it should be full duplex. Other commands like ifconfig or ip link do not expose duplex information, and netstat only shows statistics, not configuration.

Exam trap

The trap here is assuming that basic interface commands like ifconfig or ip link show duplex settings; they do not, so ethtool is required.

494
MCQmedium

An administrator is writing a Bash script that must run a cleanup function when the script exits, whether it finishes normally or is interrupted. Which construct guarantees the function runs in both cases?

A.cleanup &
B.set -e; cleanup
C.alias cleanup='rm -rf /tmp/work'
D.trap 'cleanup' EXIT
AnswerD

The EXIT pseudo-signal fires whenever the shell terminates, including normal completion, explicit exit, and receipt of a termination signal that the shell handles. Registering cleanup with trap therefore guarantees the function runs on both paths, making it the standard idiom for resource teardown in scripts.

Why this answer

The trap facility lets a script associate a handler with a signal or with the EXIT pseudo-signal, which the shell raises on every termination path. Using trap 'cleanup' EXIT ensures the teardown function executes after normal completion and after interrupts, unlike aliases, backgrounding, or plain sequential execution, which have no exit semantics.

Exam trap

The trap here is confusing set -e, which controls when the shell aborts, with trap on EXIT, which actually runs cleanup at termination.

495
MCQeasy

Which file contains user password hashes and aging information on a Linux system?

A./etc/shadow
B./etc/group
C./etc/passwd
D./etc/gshadow
AnswerA

/etc/shadow stores the hashed passwords alongside ageing fields such as last change, minimum, maximum and warning days, which /etc/passwd does not hold. It is readable only by root, restricting hash exposure. This satisfies the requirement for both password hashes and ageing information in one file.

Why this answer

The /etc/shadow file stores user password hashes along with password aging information, such as the last password change date, minimum and maximum password age, warning period, and inactivity lockout. This file is readable only by root (or privileged processes) to protect the hashed passwords from unauthorized access, unlike /etc/passwd which is world-readable.

Exam trap

The trap here is that candidates often confuse /etc/passwd with /etc/shadow, mistakenly thinking that /etc/passwd still stores password hashes, but modern Linux systems store them only in /etc/shadow for security.

How to eliminate wrong answers

Option B is wrong because /etc/group stores group membership information, not password hashes or aging data. Option C is wrong because /etc/passwd contains user account details (like UID, GID, home directory) and traditionally held password hashes, but on modern Linux systems it uses an 'x' placeholder and defers to /etc/shadow for security. Option D is wrong because /etc/gshadow stores group password hashes and group administrator information, not user password hashes or aging data.

496
Multi-Selectmedium

A security policy requires that user passwords must be changed every 60 days, and users should be warned 7 days before expiration. Which two chage commands set these requirements for user 'jsmith'? (Choose TWO.)

Select 2 answers
A.chage -M 60 jsmith
B.chage -E 60 jsmith
C.chage -W 7 jsmith
D.chage -m 60 jsmith
E.chage -I 7 jsmith
AnswersA, C

`chage -M 60 jsmith` sets the maximum password age to 60 days, satisfying the policy's mandatory 60-day rotation. The `-M` flag defines the exact interval between required changes, after which the account forces a new password. It does not configure the 7-day warning, so a second command using `-W 7` is still needed.

Why this answer

Option A, `chage -M 60 jsmith`, is correct because the `-M` flag sets the maximum number of days a password remains valid before it must be changed, which directly enforces the 60-day password expiration requirement. Option C, `chage -W 7 jsmith`, is correct because the `-W` flag sets the number of days of advance warning before the password expires, satisfying the requirement to warn users 7 days ahead. Option B (`-E 60`) sets an account expiration date, not a password change interval, so it does not meet the policy.

Option D (`-m 60`) sets the minimum days between password changes, which would prevent users from changing passwords for 60 days rather than requiring a change every 60 days. Option E (`-I 7`) sets the number of inactive days after password expiration before the account is locked, which is unrelated to the warning requirement.

Exam trap

XK0-006 often tests the confusion between -m (minimum) and -M (maximum) — candidates frequently swap them, and the case sensitivity is the exact trap.

497
Multi-Selectmedium

Which TWO options are valid ways to pass environment variables to a Docker container?

Select 2 answers
A.--var VAR=value
B.--env-file file
C.-e VAR=value
D.--variable VAR=value
E.-v VAR=value
AnswersB, C

The --env-file flag reads a file containing VAR=value lines and injects each as an environment variable in the container. It satisfies the stem's requirement for a valid way to pass environment variables, allowing bulk configuration without repeating -e flags.

Why this answer

The `--env-file` flag allows you to pass a file containing environment variables to a Docker container, where each line in the file is in `KEY=value` format. Option C is correct because the `-e` (or `--env`) flag directly sets an environment variable inside the container, e.g., `-e VAR=value`. Both are standard Docker CLI methods for injecting environment variables at container runtime.

Exam trap

The trap here is that candidates confuse the `-v` flag (used for volumes) with environment variable flags, or assume `--var` or `--variable` are valid Docker options when they are not.

498
MCQmedium

After adding a new static route to a server, an administrator notices that traffic to 10.20.0.0/16 still leaves through the default gateway. The route appears in 'ip route' output but is not used. The administrator confirms the interface is up. Which command should be run to verify that the kernel is selecting the intended route for that destination?

A.ip neigh show
B.ip addr show
C.ip route get 10.20.5.10
D.ss -rn
AnswerC

ip route get performs a route lookup for a specific destination and reports which interface, source address, and gateway the kernel would actually use. This directly answers whether the new static route wins over the default gateway. Unlike listing the routing table, it shows the resolved decision, making it the right verification tool here.

Why this answer

The kernel consults the routing table using longest-prefix match, so a more specific static route should normally beat the default gateway. When behavior disagrees with the table, the fastest way to see the actual decision is a route lookup for a representative address with ip route get. It reports the chosen interface, gateway, and preferred source, exposing whether a conflicting or less-specific entry is winning.

Exam trap

The trap here is inspecting the routing table or interface list when the real question is which route the kernel resolves for a specific destination.

499
MCQmedium

Refer to the exhibit. A user reports that the /var directory is not accessible. The system administrator checks the logical volumes and notices that the 'var' logical volume is not activated. Which command should be used to activate it?

A.lvextend -L+10g vg0/var
B.lvchange -ay vg0/var
C.lvscan
D.lvcreate -a y vg0/var
AnswerB

The logical volume exists but is inactive, so it must be brought online. The -a flag activates all volumes in the volume group, and -y confirms activation without prompting. lvchange -ay vg0/var activates the var LV, restoring access to /var.

Why this answer

The `lvchange -ay vg0/var` command activates the specified logical volume by setting its activation flag to 'y' (yes). This is the correct way to bring an inactive LVM logical volume online so that it can be mounted and accessed.

Exam trap

CompTIA often tests the distinction between commands that modify LVM objects (like `lvextend`, `lvcreate`) versus commands that manage state (like `lvchange`), leading candidates to confuse activation with resizing or creation.

How to eliminate wrong answers

Option A is wrong because `lvextend` is used to increase the size of a logical volume, not to change its activation state. Option C is wrong because `lvscan` only scans and displays the status of all logical volumes; it does not modify their activation state. Option D is wrong because `lvcreate` is used to create a new logical volume, and the `-a y` flag would attempt to create a new volume named 'var' in volume group 'vg0' rather than activating an existing one.

500
MCQmedium

A Linux administrator is writing a Bash automation script that must continue processing the remaining entries in a loop even when an individual command returns a non-zero exit status. The script currently starts with `#!/bin/bash` and uses `set -e` for safety elsewhere. Which construct should the administrator use to run a command whose failure must be tolerated inside the loop?

A.Append `|| true` to the command so its non-zero exit status is masked.
B.Run the loop body inside a subshell wrapped with `set +e` before and after the command.
C.Prefix the command with `env -i` to isolate its environment and prevent exit propagation.
D.Redirect the command's stderr to `/dev/null` to prevent the shell from seeing the failure.
AnswerA

Under `set -e`, a failing command terminates the script unless its status is consumed by a conditional or an OR list. Appending `|| true` converts the failure into a successful status, allowing the loop to continue while other commands remain protected. This is the idiomatic, minimal fix for selectively tolerating a known-failing command without disabling error handling globally.

Why this answer

With `set -e` active, any simple command returning non-zero aborts the script unless its status is part of a condition or OR list. Appending `|| true` makes the overall list succeed, so the loop advances while errexit remains enabled for everything else. This preserves the safety net for unforeseen failures while deliberately tolerating the one command expected to fail.

Exam trap

The trap here is assuming that suppressing a command's error output also prevents `set -e` from acting on its exit status.

501
Multi-Selecthard

A storage administrator is troubleshooting high disk I/O latency. Which THREE tools can provide detailed block I/O statistics at the device level? (Choose three.)

Select 3 answers
A.dd
B.iostat
C.iotop
D.fstrim
E.blktrace
AnswersB, C, E

Reports I/O statistics per device and partition.

Why this answer

B (iostat) is correct because it reports CPU utilization and device I/O statistics, including metrics like await, svctm, and %util, which are essential for diagnosing high disk I/O latency at the device level. It reads data from /proc/diskstats and provides per-device block I/O statistics.

Exam trap

The Linux+ exam often tests the distinction between tools that show I/O statistics (iostat, iotop, blktrace) versus tools that perform I/O operations (dd, fstrim), leading candidates to mistakenly select dd because it involves disk activity.

502
Multi-Selecteasy

Which TWO commands are used to view a file page by page?

Select 2 answers
A.tail
B.more
C.cat
D.head
E.less
AnswersB, E

The `more` command displays file contents one screenful at a time, pausing after each page until the user presses Space to continue. This pagination directly satisfies the requirement to view a file page by page, making it one of the two valid commands alongside `less`.

Why this answer

Both 'more' (B) and 'less' (E) are pagers that display a file one screenful at a time, pausing so the user can scroll forward (and in less, backward) through the content, which is exactly what 'view a file page by page' means. 'more' shows the file page by page and advances with the spacebar, while 'less' is the more capable pager that also supports backward scrolling and searching. The other commands do not paginate: 'tail' (A) prints only the last lines (default 10), 'cat' (C) dumps the entire file to standard output at once, and 'head' (D) prints only the first lines (default 10).

Exam trap

The trap here is that candidates may confuse `more` and `less` as being mutually exclusive or think only one is correct, but the question asks for TWO commands, and both are valid pagers; also, some might mistakenly think `cat` with a pipe to `more` or `less` counts, but the question asks for commands used directly to view a file page by page.

503
MCQmedium

Which shebang ensures maximum portability across systems for a Python script?

A.#!/usr/bin/env python3
B.#!/bin/python
C.#!/usr/bin/python
D.#!/usr/local/bin/python3
AnswerA

Using env resolves python3 through the current PATH rather than hard-coding an absolute interpreter location, so the script runs wherever python3 is installed. This satisfies the portability constraint, unlike #!/usr/bin/python3, which fails on systems where Python sits elsewhere.

Why this answer

`#!/usr/bin/env python3` uses the `env` utility to locate the `python3` interpreter in the user's `PATH`, making the script portable across different Unix-like systems where Python 3 may be installed in various directories (e.g., `/usr/bin/python3`, `/usr/local/bin/python3`). This shebang avoids hardcoding an absolute path, which is the key to maximum portability.

Exam trap

CompTIA often tests the misconception that hardcoding a common path like `/usr/bin/python` is safe, but the trap is that this path may point to Python 2 on many systems, while the question explicitly requires Python 3 and maximum portability.

How to eliminate wrong answers

Option B is wrong because `/bin/python` is a hardcoded path that often points to Python 2 on many systems, not Python 3, and may not exist at all on modern distributions that have moved Python 3 to `/usr/bin/python3`. Option C is wrong because `#!/usr/bin/python` is a hardcoded path that typically refers to Python 2 on many systems (e.g., RHEL/CentOS 7) and may not be present or may point to a different version, reducing portability. Option D is wrong because `#!/usr/local/bin/python3` is a hardcoded path that assumes Python 3 is installed in `/usr/local/bin`, which is not the default location on most Linux distributions (e.g., Debian/Ubuntu use `/usr/bin/python3`), breaking portability.

504
MCQmedium

A system administrator is investigating high disk I/O on a server. Which command can provide disk utilization statistics, including average wait time (await) and percentage of CPU time during which I/O requests were issued (%util)?

A.free -h
B.sar -b 1 5
C.iostat -x 1
D.vmstat 1 5
AnswerC

`iostat -x 1` reports extended disk statistics per device, including await (average wait time in milliseconds) and %util (percentage of time the device had I/O in flight), refreshed every second. This directly satisfies the stem's requirement for both metrics, unlike `vmstat` or `top`, which omit per-device await and %util.

Why this answer

The `iostat` command reports disk I/O statistics including await and %util.

505
MCQmedium

A user reports that a specific process is consuming too much CPU. The administrator needs to change the priority of the process to a lower value (nicer). Which command sequence is appropriate?

A.nice -n -10 <PID>
B.kill -15 <PID>
C.chrt --idle <PID>
D.renice +10 -p <PID>
AnswerD

renice adjusts the nice value of an already-running process, and +10 raises it, lowering scheduling priority so the process yields CPU to others. The -p flag targets the given PID, satisfying the requirement to make the busy process nicer.

Why this answer

renice changes the priority of an already running process by PID.

506
MCQmedium

A Linux administrator is writing a Bash script that must read a file line by line and preserve leading whitespace in each line. The script currently uses `for line in $(cat file.txt)`. Which construct should replace the current loop to preserve whitespace and avoid word splitting?

A.while IFS= read -r line; do ... done < file.txt
B.cat file.txt | while read -r line; do ... done
C.for line in "$(cat file.txt)"; do ... done
D.while read line; do ... done < <(cat file.txt)
AnswerA

This is correct because setting IFS= for the read built-in disables field splitting, and the -r flag prevents backslash interpretation, so leading and trailing whitespace and backslashes in each line are preserved. Redirecting the file into the loop keeps the read in the current shell, unlike piping, which would run it in a subshell.

Why this answer

Reading a file line by line while preserving whitespace requires disabling field splitting with IFS= and preventing backslash processing with read -r, and the input must be redirected into the loop rather than piped so the loop runs in the current shell. The quoted command substitution approach collapses the file into one value, and the default read behavior strips leading whitespace.

Exam trap

The trap here is assuming that quoting a command substitution in a for loop preserves line structure and whitespace, when it actually collapses the entire file into one argument.

507
MCQmedium

A junior administrator needs to add a persistent mount entry for a new XFS filesystem on /dev/sdb1 at the /data directory so it is mounted automatically at every boot. The administrator opens /etc/fstab and must identify the correct field order for the entry. Which field order should be used in the /etc/fstab line?

A.mount point, device, filesystem type, dump, mount options, fsck pass
B.UUID, filesystem type, mount options, mount point, dump, fsck pass
C.device, mount point, filesystem type, mount options, dump, fsck pass
D.device, filesystem type, mount point, fsck pass, dump, mount options
AnswerC

The fstab file uses six whitespace-separated fields in this exact order: the block device or UUID, the mount point directory, the filesystem type (xfs here), the comma-separated mount options, the dump backup flag, and the fsck pass number. Writing them in this sequence lets systemd's mount units parse and mount /dev/sdb1 at /data on every boot.

Why this answer

The /etc/fstab format is strictly positional: source device, mount point, filesystem type, options, dump flag, and fsck pass. For an XFS volume on /dev/sdb1 mounted at /data, the entry must follow that order so systemd and mount can resolve the device and target correctly and apply options such as defaults or noatime. Misordering any field prevents the persistent mount from working at boot.

Exam trap

The trap here is assuming field order is flexible or that mount options come before the filesystem type, when fstab parsing is strictly positional.

508
MCQhard

An administrator is configuring a chroot jail for an SFTP user. Which directive in /etc/ssh/sshd_config is used for this purpose?

A.ChrootDirectory /home/%u
B.Subsystem sftp internal-sftp
C.ForceCommand internal-sftp
D.Match Group sftpusers
AnswerA

ChrootDirectory confines an SFTP session to the specified path, with %u expanding to the authenticated username, so each user is jailed in their own home directory. This satisfies the stem's requirement for a per-user chroot jail in sshd_config.

Why this answer

The ChrootDirectory directive in /etc/ssh/sshd_config specifies the path to the directory that will be used as a chroot jail for the user. When set to /home/%u, %u is replaced by the username, confining the SFTP user to their home directory. This is the standard way to restrict an SFTP user's file system access to a specific directory tree.

Exam trap

The trap here is that candidates confuse the directive that enables SFTP (Subsystem or ForceCommand) with the directive that actually creates the chroot jail (ChrootDirectory), leading them to select a functional but incomplete option.

How to eliminate wrong answers

Option B is wrong because Subsystem sftp internal-sftp enables the built-in SFTP subsystem but does not itself enforce a chroot jail; it must be combined with ChrootDirectory or other restrictions. Option C is wrong because ForceCommand internal-sftp forces the user to use only SFTP (not SSH shell), but it does not confine the user to a specific directory; chroot requires ChrootDirectory. Option D is wrong because Match Group sftpusers is a conditional block that applies settings to a group, but it is not a directive that sets the chroot path; ChrootDirectory must be placed inside or outside the Match block to actually define the jail.

509
MCQeasy

A Linux administrator needs to configure the system so that all users must use a minimum password length of 12 characters. The administrator edits /etc/security/pwquality.conf. Which line should be added or modified to enforce this requirement?

A.password requisite pam_pwquality.so minlen=12
B.min_password_length = 12
C.PASS_MIN_LEN 12
D.minlen = 12
AnswerD

In /etc/security/pwquality.conf, the minlen parameter specifies the minimum acceptable length for a new password. Setting minlen = 12 enforces that all new passwords are at least 12 characters long. This is the correct directive for the pwquality PAM module, which is commonly used on modern Linux distributions.

Why this answer

The pwquality.conf file uses the minlen directive to set the minimum password length. Adding minlen = 12 ensures that the pam_pwquality module enforces a 12-character minimum for new passwords, provided the module is enabled in the PAM configuration.

Exam trap

The trap here is mixing up parameters from different configuration files, such as PASS_MIN_LEN from login.defs, with the correct minlen from pwquality.conf.

510
MCQeasy

A Linux administrator needs to view the last 10 lines of a log file named 'syslog'. Which command should be used?

A.cat syslog
B.head -10 syslog
C.less syslog
D.tail -10 syslog
AnswerD

`tail -10 syslog` reads from the end of the file and prints exactly the final ten lines, satisfying the requirement to view the last 10 lines of `syslog`. Unlike `head`, which counts from the start, `tail` anchors to the file's end, making it the precise tool for recent log entries.

Why this answer

The 'tail' command outputs the last lines of a file; by default it shows 10 lines.

511
MCQmedium

A Linux administrator is writing a systemd unit file at /etc/systemd/system/backup.service that must execute /usr/local/bin/backup.sh only after the network is fully reachable and the /mnt/archive mount is active. The unit currently has no ordering directives. Which directive should be added to the [Unit] section to satisfy this requirement?

A.Wants=network-online.target local-fs.target
B.Requires=network-online.target local-fs.target
C.After=network-online.target local-fs.target
D.BindsTo=network-online.target local-fs.target
AnswerC

After= establishes ordering only: backup.service is queued to start after the listed targets finish activating, so the network is reachable and local filesystems including /mnt/archive are mounted first. This is exactly the ordering guarantee the scenario demands, and systemd will not begin the unit until those targets are active.

Why this answer

Ordering in systemd is expressed with After= and Before=, which control when a unit is queued relative to others without creating a dependency. To guarantee the backup script runs only once the network is up and /mnt/archive is mounted, the [Unit] section needs After=network-online.target local-fs.target. Dependency keywords such as Requires, Wants, and BindsTo pull units in or tie lifecycles together but never enforce start ordering on their own.

Exam trap

The trap here is assuming that Requires= or Wants= also controls start order, when systemd keeps dependency and ordering semantics completely separate.

512
MCQhard

A Linux engineer is troubleshooting a boot issue. The system boots to a command-line interface but does not start the graphical interface. Which systemd target should be set as default to boot into a graphical environment?

A.emergency.target
B.rescue.target
C.graphical.target
D.multi-user.target
AnswerC

Setting the default to graphical.target pulls in multi-user.target plus the display manager and graphical session units, satisfying the stem's requirement to boot into a graphical environment rather than the command-line interface. systemctl set-default graphical.target makes this persistent across reboots, resolving the boot issue.

Why this answer

graphical.target is the systemd target that starts the graphical login manager and desktop environment (it pulls in multi-user.target plus the display manager). Setting it as the default with 'systemctl set-default graphical.target' causes the system to boot into the GUI. The current default can be verified with 'systemctl get-default'.

Exam trap

XK0-006 often tests the mapping between systemd targets and old runlevels — candidates confuse multi-user.target (runlevel 3, CLI) with graphical.target (runlevel 5, GUI) and pick multi-user because it sounds more complete.

How to eliminate wrong answers

Option A is wrong because emergency.target starts only a minimal shell with the root filesystem mounted read-only, used for emergency recovery — no networking or GUI. Option B is wrong because rescue.target starts a single-user rescue shell with local filesystems mounted, used for repair, not a graphical session. Option D is wrong because multi-user.target starts a full multi-user command-line environment with networking but no graphical interface — this is exactly the state the system is currently in, so it would not fix the problem.

513
MCQhard

A server running Ubuntu 22.04 has AppArmor enabled. After installing a new application, the application is denied access to certain files even though the permissions are correct. The administrator checks the AppArmor profile and finds it is in enforce mode. Which command can be used to temporarily set the profile to complain mode to generate log entries for needed accesses?

A.systemctl restart apparmor
B.aa-enforce /usr/bin/application
C.aa-complain /usr/bin/application
D.apparmor_parser -r /etc/apparmor.d/usr.bin.application
AnswerC

Switches the AppArmor profile from enforce to complain mode, so denied file accesses are logged rather than blocked. This satisfies the requirement to generate audit entries revealing which paths the application needs, without permanently disabling confinement.

Why this answer

`aa-complain /usr/bin/application`, is correct because it sets the specified AppArmor profile to complain mode, which logs policy violations without blocking access. This allows the administrator to identify which accesses the application needs by reviewing the generated log entries, typically in `/var/log/syslog` or via `ausearch`, while the application continues to run.

Exam trap

The trap here is that candidates confuse `aa-complain` with `aa-enforce` or think that restarting the AppArmor service or reloading the profile will change the mode, when in fact only `aa-complain` or `aa-enforce` directly alter the profile's operational mode.

How to eliminate wrong answers

Option A is wrong because `systemctl restart apparmor` restarts the entire AppArmor service, which does not change the mode of an individual profile to complain mode; it only reloads all profiles in their current state. Option B is wrong because `aa-enforce /usr/bin/application` sets the profile to enforce mode, which is the opposite of what is needed—it would continue blocking access rather than logging. Option D is wrong because `apparmor_parser -r /etc/apparmor.d/usr.bin.application` reloads the profile from disk but does not change its mode; the profile remains in enforce mode if that is how it was defined.

514
MCQmedium

A Linux administrator needs to schedule a script at /opt/scripts/report.sh to run every Monday at 02:30 for the user svcacct, without editing the system-wide /etc/crontab. Which cron entry correctly accomplishes this when placed in svcacct's crontab via crontab -e?

A.2 30 * * 1 /opt/scripts/report.sh
B.30 2 * * 0 /opt/scripts/report.sh
C.30 2 1 * * /opt/scripts/report.sh
D.30 2 * * 1 /opt/scripts/report.sh
AnswerD

The five fields are minute, hour, day of month, month, and day of week. 30 2 * * 1 means minute 30, hour 2, any day of month, any month, and day-of-week 1, which is Monday, matching the requested Monday 02:30 schedule. Being in the user's crontab, it runs as svcacct automatically.

Why this answer

Cron's five fields are minute, hour, day of month, month, and day of week, in that order. The requirement of Monday at 02:30 maps to minute 30, hour 2, wildcard day of month, wildcard month, and day-of-week 1 for Monday. Placing the entry in svcacct's own crontab via crontab -e means it executes as that user without needing a username field or touching /etc/crontab.

Exam trap

The trap here is confusing the order of the minute and hour fields, or forgetting that cron day-of-week uses 0 or 7 for Sunday and 1 for Monday.

515
MCQmedium

A Linux administrator wants to search for all occurrences of the word 'ERROR' in log files under /var/log, ignoring case, and also print the line numbers. Which command should be used?

A.grep -vi 'ERROR' /var/log
B.grep -rin 'ERROR' /var/log
C.grep -rn 'ERROR' /var/log
D.find /var/log -name '*ERROR*'
AnswerB

The -r flag recurses through every file under /var/log, -i matches 'ERROR' case-insensitively, and -n prefixes each match with its line number. Together these satisfy all three requirements: recursive search, case-insensitive matching, and printed line numbers.

Why this answer

The command 'grep -rin ERROR /var/log' combines -r (recursive search through directories), -i (case-insensitive match), and -n (print line numbers). This searches every file under /var/log for 'ERROR' regardless of case and prefixes each match with its line number, exactly matching the requirement.

Exam trap

XK0-006 often tests grep flag combinations — candidates confuse -v (invert) with -i (ignore case) and -c (count) with -n (line number), or forget that -r is required to recurse into /var/log.

How to eliminate wrong answers

Option A is wrong because -v inverts the match (prints non-matching lines) and -i only makes it case-insensitive — it would print every line that does NOT contain ERROR, the opposite of the goal. Option C is wrong because it omits -i, so it would miss lowercase 'error' or mixed-case variants, failing the case-insensitive requirement. Option D is wrong because 'find' locates files by name matching '*ERROR*' rather than searching file contents for the string ERROR, so it does not perform a content search at all.

516
MCQhard

A Linux server has SELinux enforcing and a custom application needs to write to /var/log/app.log. The audit log shows 'avc: denied { write } for pid=1234'. After verifying that the application runs in the correct domain, which command should be used to allow the write access by generating a policy module?

A.ausearch -m avc | audit2allow -M myapp
B.chcon -t var_log_t /var/log/app.log
C.setsebool -P httpd_unified 1
D.restorecon -v /var/log/app.log
AnswerA

ausearch extracts the AVC denial records from the audit log and pipes them into audit2allow, which translates the denials into allow rules and compiles them into a loadable module named myapp. This satisfies the requirement to generate a policy module granting the write access.

Why this answer

The audit2allow workflow is the standard way to convert SELinux AVC denial messages into a loadable policy module. Piping ausearch output into audit2allow -M myapp generates a .te source file and compiles it into a myapp.pp module that can be installed with semodule -i, granting exactly the denied write permission.

Exam trap

XK0-006 often tests the distinction between labeling commands (chcon, restorecon), boolean toggles (setsebool), and policy generation (audit2allow), so candidates must recognize that only audit2allow produces a policy module.

How to eliminate wrong answers

Option B is wrong because chcon changes the SELinux context of a file, which alters labeling but does not generate a policy module and may not resolve a domain-level denial. Option C is wrong because setsebool toggles an existing boolean (httpd_unified) and is unrelated to a custom application's write denial. Option D is wrong because restorecon resets a file's context to its default policy value, which does not grant new write permissions to the application's domain.

517
MCQmedium

A company policy requires that only the root user can schedule cron jobs. Which configuration ensures this?

A.Create /etc/cron.allow with only 'root'
B.Add 'root' to /etc/crontab
C.Set /usr/bin/crontab permissions to 700
D.Add all non-root users to /etc/cron.deny
AnswerA

When /etc/cron.allow exists, only users listed within it may schedule cron jobs, and all others are denied regardless of /etc/cron.deny. Listing only root therefore enforces the policy that exclusively the root user can create cron entries.

Why this answer

The /etc/cron.allow file explicitly lists users who are permitted to schedule cron jobs. When this file exists, only users listed in it can use crontab, and all others are denied — even if /etc/cron.deny exists. By placing only 'root' in /etc/cron.allow, the policy that only root can schedule cron jobs is enforced.

Exam trap

The trap here is that candidates often think modifying file permissions on the crontab binary (Option C) is the correct way to restrict cron access, when the actual Linux standard is to use the /etc/cron.allow and /etc/cron.deny files for user-level access control.

How to eliminate wrong answers

Option B is wrong because /etc/crontab is the system-wide cron table used for system maintenance tasks, not a configuration file that restricts which users can schedule cron jobs; adding 'root' to it does nothing to prevent other users from using crontab. Option C is wrong because setting /usr/bin/crontab permissions to 700 would prevent all non-root users from executing the crontab command, but this is a blunt, non-standard approach that breaks expected behavior (e.g., cron jobs for system services) and is not the intended mechanism for user-based access control. Option D is wrong because adding all non-root users to /etc/cron.deny would deny them only if /etc/cron.allow does not exist; if /etc/cron.allow exists, it takes precedence and /etc/cron.deny is ignored — so this does not reliably ensure that only root can schedule cron jobs.

518
Matchingmedium

Match each Linux networking command to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Show/manipulate routing, devices, tunnels

Investigate sockets

Manage NetworkManager

Capture network packets

Network exploration/security scanning

Why these pairings

Ping tests connectivity, netstat shows network statistics, ifconfig configures interfaces, nslookup performs DNS queries. Traceroute traces paths, and system IP is better shown by ifconfig or hostname -I.

519
Multi-Selecthard

A system is running slowly and the administrator suspects a memory leak. Which THREE commands or tools can be used to analyze memory usage and identify processes consuming excessive memory? (Choose three.)

Select 3 answers
A.strace -p PID
B.ps aux --sort=-%mem
C.iostat -x
D.vmstat 1
E.free -h
AnswersB, D, E

`ps aux --sort=-%mem` lists every process with its resident memory percentage, sorted descending, so the heaviest consumer appears first. This directly satisfies the stem's need to identify processes consuming excessive memory, letting the administrator confirm a suspected leak by watching a process's RSS climb over successive samples.

Why this answer

Option B (ps aux --sort=-%mem) is correct because it lists all processes with their memory usage and sorts them in descending order by the %MEM column, directly revealing which processes consume the most memory. Option D (vmstat 1) is correct because it reports virtual memory statistics (swpd, free, buff, cache, si, so) every second, helping detect memory pressure and swapping indicative of a leak. Option E (free -h) is correct because it displays total, used, free, shared, buff/cache, and available memory in human-readable units, giving a quick overview of overall memory consumption.

Option A (strace -p PID) is not appropriate here because strace traces system calls of a single process and does not summarize memory usage across processes. Option C (iostat -x) is incorrect because it reports extended disk I/O statistics, not memory usage.

Exam trap

XK0-006 often tests the distinction between memory and I/O monitoring tools, tempting candidates to choose iostat or strace for memory analysis when they are not appropriate.

520
MCQeasy

A system administrator needs to ensure that only specific users can execute the 'sudo' command. Which configuration file should be modified?

A./etc/sudoers
B./etc/shadow
C./etc/passwd
D./etc/group
AnswerA

Editing /etc/sudoers lets you grant command privileges per user or group through User_Spec entries, satisfying the requirement that only named accounts may run sudo. Use visudo to edit it safely, since syntax errors can lock out all administrative access.

Why this answer

The /etc/sudoers file controls which users and groups can execute commands with elevated privileges via the sudo utility. It uses a specific syntax to define user privileges, such as 'username ALL=(ALL) ALL', and must be edited with the visudo command to prevent syntax errors that could lock out administrative access. Modifying this file is the standard method for granting or restricting sudo access on Linux systems.

Exam trap

CompTIA often tests the misconception that /etc/group or /etc/passwd controls sudo privileges, but only /etc/sudoers (or files in /etc/sudoers.d/) defines sudo access, and it must be edited with visudo to enforce syntax checking.

How to eliminate wrong answers

Option B is wrong because /etc/shadow stores encrypted user passwords and password aging information, not sudo permissions. Option C is wrong because /etc/passwd contains basic user account information (username, UID, GID, home directory, shell) but does not control sudo access. Option D is wrong because /etc/group defines user group memberships, but sudo privileges are not managed through this file; while groups can be referenced in /etc/sudoers, the file itself is not the configuration file for sudo permissions.

521
Multi-Selectmedium

A Linux administrator wants to search for the pattern 'ERROR' in all files under /var/log, ignoring case, and display line numbers. Which THREE options should be used with the grep command? (Select THREE).

Select 3 answers
A.-c
B.-i
C.-v
D.-n
E.-r
AnswersB, D, E

The `-i` flag makes grep match case-insensitively, so lines containing 'error', 'Error' or 'ERROR' are all returned. This directly satisfies the stem's requirement to search for the pattern 'ERROR' while ignoring case, rather than matching only uppercase occurrences.

Why this answer

Option B (-i) is correct because it makes grep perform a case-insensitive match, so 'ERROR', 'error', and 'Error' are all found as required. Option D (-n) is correct because it prefixes each matching line with its line number, satisfying the requirement to display line numbers. Option E (-r) is correct because it recursively searches all files under the /var/log directory tree, which is needed to cover 'all files under /var/log'.

Option A (-c) is not appropriate because it only counts matching lines instead of displaying them, and Option C (-v) is wrong because it inverts the match to show non-matching lines rather than the 'ERROR' pattern.

Exam trap

XK0-006 often tests grep flag selection in multi-select questions — candidates include -c or -v because they are common flags, but only -i, -n, and -r match the three stated requirements (case-insensitive, line numbers, recursive).

522
MCQeasy

A DevOps engineer needs to run a Docker container in the background with port mapping from host port 8080 to container port 80, and name the container 'webapp'. Which command accomplishes this?

A.docker start -d -p 8080:80 --name webapp nginx
B.docker create -d -p 8080:80 --name webapp nginx
C.docker run -d -p 8080:80 --name webapp nginx
D.docker compose up -d -p 8080:80 --name webapp nginx
AnswerC

The -d flag detaches the container to run in the background, -p 8080:80 maps host port 8080 to container port 80, and --name webapp assigns the required container name. The nginx image supplies the container workload, satisfying every constraint in the stem.

Why this answer

`docker run` is the command that creates AND starts a container in one step, and the `-d` flag detaches it to run in the background. The `-p 8080:80` flag maps host port 8080 to container port 80, and `--name webapp` assigns the container name. This is the canonical single-command way to launch a named, port-mapped, background container from the nginx image.

Exam trap

XK0-006 often tests the confusion between `docker run`, `docker create`, and `docker start` — candidates pick `create` or `start` thinking they launch a container, but only `run` both creates and starts it with the required flags.

How to eliminate wrong answers

Option A is wrong because `docker start` only starts an existing, already-created container — it does not accept `-p`, `--name`, or an image argument, so this syntax is invalid. Option B is wrong because `docker create` only creates the container without starting it, so it would not be running in the background as required. Option D is wrong because `docker compose up` operates on a compose file and does not accept `-p` port mapping or `--name` flags in that form — those are `docker run` options.

523
MCQhard

A script needs to iterate over all .txt files in a directory. Which loop structure correctly implements this?

A.while read line; do
B.select option; do
C.until condition; do
D.for f in *.txt; do
AnswerD

The glob *.txt expands to every matching filename in the current directory, and for iterates over that list, assigning each name to f in turn. This is the standard shell construct for processing a directory's .txt files without external commands.

Why this answer

The `for f in *.txt; do` loop is correct because it uses shell globbing to expand `*.txt` into a list of all .txt filenames in the current directory, then iterates over each filename. This is the standard and most efficient way to process a set of files matching a pattern in Bash and POSIX shell scripting.

Exam trap

The trap here is that candidates may confuse `while read` (which processes lines of text) with iterating over files, or think `select` is a general-purpose loop, when in fact only `for` with a glob pattern directly matches the requirement of iterating over all .txt files.

How to eliminate wrong answers

Option A is wrong because `while read line; do` reads lines from stdin or a file, not filenames matching a pattern, and would require piping `ls *.txt` or similar, which is fragile and not the intended loop for file iteration. Option B is wrong because `select option; do` is used to present a menu of choices to the user for interactive selection, not for iterating over files. Option C is wrong because `until condition; do` runs the loop until a condition becomes true, and does not inherently iterate over a list of files; it would need an explicit counter or file list to work.

524
MCQeasy

A user reports that they cannot run the command `sudo` to perform administrative tasks. The administrator checks and finds that the user is not listed in the `/etc/sudoers` file. Which command should the administrator use to safely edit the sudoers file and add the user?

A.echo 'username ALL=(ALL) ALL' >> /etc/sudoers
B.visudo
C.usermod -aG sudo username
D.nano /etc/sudoers
AnswerB

`visudo` is the recommended tool for editing the `/etc/sudoers` file because it locks the file to prevent concurrent edits and performs syntax checking before saving. This reduces the risk of introducing errors that could lock out sudo access. It is the safe and standard method for modifying sudoers.

Why this answer

Using `visudo` is the correct approach because it provides a safe editing environment with syntax validation and file locking. Directly editing the sudoers file or appending to it can introduce errors that break sudo. Adding a user to a group like sudo is an alternative but does not address the specific need to edit the sudoers file safely.

Exam trap

The trap here is assuming that any method of editing the sudoers file is acceptable, overlooking the critical safety features of visudo.

525
MCQhard

An administrator is troubleshooting a web server that is running under SELinux enforcing mode. The web content is located in a non-standard directory /webfiles. Using the standard SELinux context 'httpd_sys_content_t', the files are still inaccessible. Which command will properly set the context recursively and persist across relabels?

A.semanage fcontext -a -t httpd_sys_content_t '/webfiles(/.*)?' ; restorecon -Rv /webfiles
B.chcon -R -t httpd_sys_content_t /webfiles
C.setenforce 0
D.restorecon -Rv /webfiles
AnswerA

semanage fcontext writes a persistent mapping into the SELinux file-context policy for the /webfiles path, and restorecon applies it recursively to the files. This satisfies the stem's requirement that the context survive future relabels, which chcon alone cannot guarantee.

Why this answer

`semanage fcontext -a -t httpd_sys_content_t '/webfiles(/.*)?'` adds a file-context mapping to the SELinux policy database, ensuring the context survives a `restorecon` or filesystem relabel. The subsequent `restorecon -Rv /webfiles` applies that context recursively to the directory. Without the `semanage` entry, `restorecon` alone would revert to the default context (often `default_t`), which is not accessible by httpd.

Exam trap

The trap here is that candidates often think `restorecon` alone is sufficient to set a custom context, forgetting that it only applies the default policy mapping; without a prior `semanage fcontext` entry, the context will not persist across relabels.

How to eliminate wrong answers

Option B is wrong because `chcon -R -t httpd_sys_content_t /webfiles` sets the context temporarily in the extended attributes, but it does not persist across a `restorecon` or a full filesystem relabel (e.g., after `fixfiles` or `touch /.autorelabel`). Option C is wrong because `setenforce 0` disables SELinux entirely, which bypasses the problem rather than solving it, and is not a proper configuration for a production system requiring enforcing mode. Option D is wrong because `restorecon -Rv /webfiles` alone only resets the context to the default policy mapping; since `/webfiles` is non-standard and has no `semanage` entry, it would set the context to `default_t` (or `unlabeled_t`), which httpd cannot access.

Page 6

Page 7 of 11

Page 8

All pages