Courseiva

CompTIA Linux+ (XK0-006) (XK0-006) — Questions 526–600

781 questions total · 11pages · All types, answers revealed

Page 7

Page 8 of 11

Page 9
526
MCQhard

A sysadmin is tasked with creating a script that will run only on weekdays at 9:00 AM using cron. The script should not run on holidays. Which approach best achieves this requirement?

A.Use systemd timers with a calendar specification that excludes holidays
B.Use cron to run at 9:00 on weekdays, and include a test in the script that checks a holiday list
C.Use cron to run at 9:00 every day, and include conditional logic to abort on weekends
D.Use `at` to schedule the job individually each weekday morning
AnswerB

Cron cannot natively exclude holidays, so scheduling weekdays at 09:00 and testing a holiday list inside the script is the only reliable approach. The script exits early on holidays, meeting both the weekday and holiday constraints.

Why this answer

Cron can schedule the script to run at 9:00 AM on weekdays using the day-of-week field (e.g., `0 9 * * 1-5`), and the script itself can check a holiday list (e.g., a file or API) to exit early on holidays. This approach cleanly separates scheduling from holiday logic, avoiding cron's lack of built-in holiday awareness.

Exam trap

CompTIA often tests the misconception that cron can directly handle holidays, when in fact cron has no concept of holidays and requires external logic (like a script check) to skip them.

How to eliminate wrong answers

Option A is wrong because systemd timers do not natively support excluding arbitrary holidays; they use calendar expressions that can only exclude fixed patterns (e.g., specific dates), not dynamic holiday lists. Option C is wrong because running the script every day and aborting on weekends wastes resources and adds unnecessary complexity; cron's weekday field already handles weekends efficiently. Option D is wrong because using `at` requires manual or scripted scheduling each morning, which is impractical for a recurring weekday job and lacks the built-in weekday filtering that cron provides.

527
MCQhard

An administrator manages a server with several systemd services. A service named reportgen.service must not start until another service named dbengine.service is fully active, and reportgen should be stopped automatically if dbengine stops. Which directive combination in the reportgen.service unit file achieves this ordering and dependency?

A.After=dbengine.service and Wants=dbengine.service
B.Before=dbengine.service and Wants=dbengine.service
C.Requires=dbengine.service and Before=dbengine.service
D.After=dbengine.service and Requires=dbengine.service
AnswerD

After= establishes ordering so reportgen starts only once dbengine has been activated, and Requires= creates a hard dependency so that if dbengine is stopped or fails, reportgen is also stopped. Together they express both the sequence and the lifecycle coupling the administrator described for these two units.

Why this answer

Ordering and dependency are separate concerns in systemd. After= controls sequence, ensuring reportgen starts once dbengine is active, while Requires= creates a hard dependency so reportgen stops if dbengine stops. Using After= with Requires= satisfies both requirements.

Wants= is too weak to force the stop behavior, and Before= would invert the required startup order.

Exam trap

The trap here is assuming a single directive like Requires handles both ordering and shutdown coupling, when systemd separates ordering from dependency semantics.

528
MCQhard

A technician suspects a process is leaking file descriptors. Which command can be used to list open files associated with a specific PID?

A.top -p PID
B.strace -p PID
C.ltrace -p PID
D.lsof -p PID
AnswerD

lsof lists open files, and the -p flag restricts output to the specified process ID, directly exposing the file descriptors that process holds. This satisfies the stem's constraint of listing open files tied to a specific PID, revealing leaked descriptors such as unclosed sockets or handles.

Why this answer

The lsof (list open files) command with the -p flag filters output to show all open files associated with a specific process ID. Since Linux treats file descriptors as open files (including sockets, pipes, and regular files), lsof -p PID is the canonical tool for diagnosing file descriptor leaks by revealing exactly what a process has open.

Exam trap

The trap here is confusing process-monitoring tools (top) or syscall tracers (strace, ltrace) with file-descriptor inspection tools; candidates must remember that only lsof enumerates open files by PID.

How to eliminate wrong answers

Option A is wrong because top -p PID only displays real-time CPU, memory, and process statistics for that PID — it does not enumerate open file descriptors. Option B is wrong because strace -p PID traces system calls made by the process, which shows syscall activity but does not produce a list of currently open file descriptors. Option C is wrong because ltrace -p PID traces library calls (such as libc function invocations) and likewise does not enumerate open files.

529
MCQhard

A Linux server intermittently loses its default route after several hours of uptime, and users cannot reach external networks until the route is manually restored. The administrator suspects that a second default route is being installed and removed by a network management daemon. Which command should the administrator use to monitor route changes in real time?

A.ip route show table main
B.ip -s link show
C.journalctl -u NetworkManager --since "1 hour ago"
D.ip monitor route
AnswerD

ip monitor route subscribes to kernel routing notifications and prints every route addition, deletion, or change as it happens. This directly captures the intermittent install and removal events the administrator suspects, including which prefix and gateway are affected, without polling or restarting services.

Why this answer

Intermittent route loss requires observing events as they happen rather than sampling the table. ip monitor route taps the kernel's routing netlink multicast group and prints each add, delete, and change with details, so the flapping default route and its timing become visible. A one-time table dump, interface counters, and indirect daemon logs cannot provide that event stream.

Exam trap

The trap here is using ip route show repeatedly and concluding the route is stable because each snapshot happens to look correct between flaps.

530
MCQhard

A DevOps team wants to automatically run tests before every commit in a local Git repository. Which Git hook should be used?

A.post-receive
B.pre-commit
C.post-commit
D.pre-push
AnswerB

The pre-commit hook executes client-side immediately before Git finalises a commit, so tests run against staged content and can abort the commit on failure. This satisfies the stem's requirement of running tests before every commit in a local repository.

Why this answer

The pre-commit hook runs before a commit is created, making it the correct choice for automatically running tests before every commit in a local Git repository. This hook can validate code quality, run unit tests, or check for syntax errors, and if it exits with a non-zero status, the commit is aborted.

Exam trap

The trap here is confusing the timing of Git hooks: candidates often pick pre-push because they think of 'testing before pushing,' but the question explicitly asks about 'before every commit,' which requires the pre-commit hook.

How to eliminate wrong answers

Option A is wrong because post-receive is a server-side hook that runs after updates are pushed to a remote repository, not before a local commit. Option C is wrong because post-commit runs after the commit has already been created, so it cannot prevent a commit from being made. Option D is wrong because pre-push runs before a push to a remote repository, not before a local commit, and it would not catch issues at the commit stage.

531
Multi-Selectmedium

A cloud engineer is using Ansible to manage configuration across multiple servers. The engineer needs to store variable data that is specific to each host and sensitive database passwords. Which two Ansible features should be used for these purposes? (Choose two.)

Select 2 answers
A.group_vars
B.ansible_facts
C.roles
D.Ansible Vault
E.host_vars
AnswersD, E

Ansible Vault encrypts sensitive variable files, such as the database passwords, using AES-256, so secrets remain unreadable at rest while still being decrypted at playbook runtime. This directly satisfies the stem's requirement to store sensitive credentials securely alongside host-specific data.

Why this answer

Option E, host_vars, is correct because host-specific variable data is stored in host_vars files (e.g., host_vars/<hostname>.yml), which Ansible automatically loads for the matching inventory host, making it the proper place for per-host values. Option D, Ansible Vault, is correct because it encrypts sensitive data such as database passwords, allowing vault-encrypted variables or files to be decrypted at runtime with the vault password, keeping secrets protected at rest. Option A, group_vars, applies variables to whole inventory groups rather than individual hosts, so it does not satisfy the host-specific requirement.

Option B, ansible_facts, holds automatically discovered system information gathered by setup, not user-defined sensitive credentials. Option C, roles, is a structural way to bundle tasks, handlers, and defaults for reuse, not a mechanism for storing host-specific or encrypted secret data.

Exam trap

The trap is selecting group_vars for host-specific data or forgetting that Ansible Vault is the only option for encrypting secrets; candidates must map 'per-host' to host_vars and 'sensitive' to Vault.

532
MCQmedium

A security policy requires that users cannot reuse any of their last 5 passwords. Which PAM module and configuration directive enforces this?

A.pam_faillock with deny=5
B.pam_pwhistory with remember=5
C.pam_tally2 with deny=5
D.pam_pwquality with remember=5
AnswerB

`pam_pwhistory` stores previous password hashes in `/etc/security/opasswd` and compares each new password against them, rejecting any match. The `remember=5` directive retains the last five hashes, directly satisfying the policy's no-reuse constraint for the previous five passwords.

Why this answer

The pam_pwhistory module records previous password hashes and enforces password reuse restrictions via the remember directive. Setting remember=5 prevents users from reusing any of their last five passwords, exactly matching the policy requirement.

Exam trap

XK0-006 often tests the confusion between account lockout modules (pam_faillock, pam_tally2) and password history modules (pam_pwhistory), so candidates must map 'reuse' to remember, not deny.

How to eliminate wrong answers

Option A is wrong because pam_faillock with deny=5 locks accounts after five failed login attempts; it has nothing to do with password history. Option C is wrong because pam_tally2 also counts failed login attempts (and is deprecated in favor of pam_faillock), not password reuse. Option D is wrong because pam_pwquality enforces complexity rules (length, character classes) and does not support a remember directive for password history.

533
MCQmedium

An administrator runs the command `ls -l file.txt` and sees the permissions `-rwsr-xr-x`. What special permission is set on this file?

A.SGID
B.Sticky bit
C.No special permission
D.SUID
AnswerD

The `s` in the owner execute position denotes SUID, satisfying the stem's `-rwsr-xr-x` string. When executed, the process runs with the file owner's effective UID rather than the invoking user's, granting elevated privileges. SGID would instead appear in the group execute position, and the sticky bit as `t` on others.

Why this answer

The 's' in the owner execute position indicates the SUID (Set User ID) permission is set.

534
MCQhard

An administrator needs to ensure that a script runs once at system initialization, before any network services start. Which systemd target should the script be associated with?

A.multi-user.target
B.basic.target
C.sysinit.target
D.network.target
AnswerC

sysinit.target is reached during early boot, before basic network services are started by network.target and multi-user.target. Associating the unit here guarantees the script executes once at initialisation, satisfying the requirement to run before any network services start.

Why this answer

The sysinit.target is the correct target because it is designed for early system initialization tasks that must complete before any network or multi-user services start. Scripts associated with this target run during the boot process, after the basic system is initialized but before network services are brought up, ensuring the script executes once at system initialization.

Exam trap

The trap here is that candidates often confuse sysinit.target with basic.target or multi-user.target, mistakenly thinking that 'basic' or 'multi-user' implies early execution, when in fact sysinit.target is the correct target for pre-network initialization tasks.

How to eliminate wrong answers

Option A is wrong because multi-user.target is the target for normal multi-user operation, which starts after network services and other system services are already running, not before them. Option B is wrong because basic.target is a synchronization point that pulls in mount points and sockets, but it does not guarantee execution before network services; it runs after sysinit.target but before multi-user.target. Option D is wrong because network.target is a passive target that indicates network services are available, but it does not define a specific execution order for scripts; scripts associated with it would run after network services start, not before.

535
MCQmedium

A cron job that runs a backup script at 2 AM has not been executing. The syslog shows no errors from cron. What is the most likely reason the job is not running?

A.The system time zone is incorrect
B.The filesystem is full
C.The cron daemon (crond) is not running
D.The script has incorrect permissions
AnswerC

With no cron entries in syslog at all, the scheduler never attempted the job, so the daemon itself is stopped. A missing crontab entry or syntax error would still produce log activity, making a dead crond the likeliest cause.

Why this answer

The most likely reason is that the cron daemon (crond) is not running. Cron jobs are executed by the cron daemon, which must be active in the background to read the crontab files and launch scheduled tasks. If crond is stopped or not started, no cron jobs will run, and syslog may not show cron-related errors because the daemon is not logging activity.

Exam trap

The trap here is that candidates assume cron errors must appear in syslog if a job fails, but if the daemon itself is not running, there is no process to generate logs, making the absence of errors a key clue.

How to eliminate wrong answers

Option A is wrong because an incorrect system time zone would cause the job to run at the wrong local time, not prevent execution entirely; cron uses the system's configured time zone. Option B is wrong because a full filesystem would typically cause the script to fail with disk write errors, not prevent the cron daemon from attempting to execute the job. Option D is wrong because incorrect script permissions would cause the script to fail when executed, but cron would still attempt to run it and log an error in syslog or mail to the user.

536
Multi-Selectmedium

Which THREE are valid methods to view logs in a systemd-based system?

Select 3 answers
A.cat /var/log/messages
B.journalctl
C.journalctl -u sshd
D.systemctl status sshd
E.dmesg
AnswersB, C, E

The journalctl utility queries the systemd journal directly, satisfying the requirement to view logs on a systemd-based system. It exposes both kernel and userspace messages, supports filtering by unit, priority, and time window, and reads persistent or volatile journal files without relying on legacy syslog text files.

Why this answer

Option B, journalctl, is correct because it is the native command-line utility for querying and displaying logs collected by the systemd journal, allowing filtering by time, unit, priority, and other fields. Option C, journalctl -u sshd, is correct because the -u (or --unit) flag restricts journal output to messages belonging to the specified systemd unit, here the sshd service, which is a standard way to inspect a single service's logs. Option E, dmesg, is correct because it reads and prints the kernel ring buffer, exposing boot and kernel-level messages that are also relevant log data on a systemd-based host.

Option A, cat /var/log/messages, is not a systemd-specific method and that file may not exist on many systemd distributions, since journald often stores logs in /var/log/journal or /run/log/journal rather than a plain messages file. Option D, systemctl status sshd, is not a log-viewing method per se; it shows unit state and only a short tail of recent journal entries as part of service status, so it does not qualify as a general method to view logs.

Exam trap

The trap here is that candidates confuse `systemctl status` (which shows a brief log snippet) with a full log viewing method, or they assume legacy syslog files like `/var/log/messages` are always present and authoritative on systemd-based systems.

537
MCQhard

Refer to the exhibit. A technician sees that the httpd service has failed. Which command was used to view the detailed error log shown in the exhibit?

A.systemctl status httpd
B.journalctl -u httpd
C.tail -f /var/log/messages
D.systemctl show httpd
AnswerB

The output format matches journalctl filtered by service unit.

Why this answer

The `journalctl -u httpd` command is correct because it queries the systemd journal for logs specifically associated with the `httpd` unit. The exhibit shows a detailed error log with timestamps, process IDs, and error messages, which is exactly the output format of `journalctl` when filtering by a unit. This command provides the most comprehensive view of the service's recent failures, including kernel and application-level errors.

Exam trap

The trap here is that candidates often confuse `systemctl status httpd` (which shows a brief log tail) with `journalctl -u httpd` (which shows the full journal history), leading them to choose A when the exhibit clearly shows a detailed, multi-line error log that only `journalctl` can provide.

How to eliminate wrong answers

Option A is wrong because `systemctl status httpd` shows the current state, recent log tail, and process information, but it does not display the full, detailed error log with multiple entries as shown in the exhibit; it only shows a few of the most recent log lines. Option C is wrong because `tail -f /var/log/messages` follows the system log file in real time, but it is not specific to the `httpd` service and does not filter by unit; it would show all system messages, not just those from httpd. Option D is wrong because `systemctl show httpd` displays the unit's properties and configuration parameters (e.g., environment, dependencies), not its runtime logs or error messages.

538
MCQmedium

A Linux administrator is writing a Bash script to back up a directory. The script must continue running even if a particular command fails, but the administrator wants to log the error and take corrective action. Which of the following should be used to handle the error condition?

A.Use `trap` to catch the ERR signal and exit the script.
B.Run the command in a subshell and ignore its exit status.
C.Check the exit status of the command using `$?` and conditionally execute recovery steps.
D.Use `set -e` at the beginning of the script.
AnswerC

After running a command, `$?` holds its exit status. By checking `$?` immediately, the script can detect failure, log the error, and run corrective actions without terminating. This allows the script to continue and meets the requirement of logging and handling the error. It is the standard way to implement custom error handling in Bash.

Why this answer

The requirement is to continue after a failure while logging and taking corrective action. Checking `$?` immediately after a command allows the script to branch based on success or failure, enabling custom error handling without terminating the script. This approach is flexible and standard for scenarios where fail-fast is not desired.

Other methods either exit prematurely or fail to provide error handling.

Exam trap

The trap here is assuming that `set -e` is always the best way to handle errors, but it forces an exit and prevents custom recovery logic.

539
MCQmedium

A system is experiencing high load average. The administrator runs 'vmstat 1 5' and sees a high 'wa' value. What does this indicate?

A.High disk I/O wait
B.High memory swapping activity
C.High CPU usage by user processes
D.High network I/O
AnswerA

The wa column in vmstat reports the percentage of CPU time spent idle while waiting for I/O operations to complete. A persistently high value therefore indicates processes blocked on disk I/O, identifying storage as the bottleneck causing the elevated load average.

Why this answer

The 'wa' column in vmstat output indicates the percentage of time the CPU is waiting for I/O operations to complete. A high 'wa' value means the CPU is idle because it is blocked waiting for disk I/O, which directly points to high disk I/O wait. This is a classic indicator of a storage bottleneck.

Exam trap

The trap here is that candidates confuse 'wa' with memory swapping or CPU usage, but vmstat columns are distinct: 'wa' is specifically I/O wait, while swapping is shown in 'si' and 'so', and CPU usage in 'us' and 'sy'.

How to eliminate wrong answers

Option B is wrong because high memory swapping activity is indicated by high 'si' (swap in) and 'so' (swap out) columns in vmstat, not the 'wa' column. Option C is wrong because high CPU usage by user processes is shown in the 'us' column, not 'wa'. Option D is wrong because high network I/O is not directly measured by vmstat; it would be diagnosed using tools like netstat or iftop, and 'wa' specifically reflects disk I/O wait, not network.

540
MCQeasy

Which command creates a symbolic link named 'link.txt' that points to 'original.txt'?

A.symlink original.txt link.txt
B.ln -s original.txt link.txt
C.ln original.txt link.txt
D.ln -s link.txt original.txt
AnswerB

The -s flag instructs ln to create a symbolic link rather than a hard link, and argument order matters: the target original.txt precedes the new link name link.txt. This satisfies the requirement for a symlink pointing to original.txt.

Why this answer

ln -s target link_name creates a symbolic link.

541
MCQeasy

A technician needs to identify the network interface configuration and IP address of a system. Which command provides the most comprehensive output for this task?

A.nmcli dev show
B.ip addr show
C.netstat -i
D.ifconfig
E.hostname -I
AnswerB

The ip addr show command displays every interface with its IPv4 and IPv6 addresses, MAC address, MTU and link state in one output, covering both configuration and addressing. Legacy ifconfig omits some modern interface detail, so ip addr show is the most comprehensive.

Why this answer

The `ip addr show` command is the most comprehensive because it displays all network interfaces along with their IP addresses (IPv4 and IPv6), MAC addresses, MTU, state (UP/DOWN), and additional flags. It is part of the modern `iproute2` suite, which is the standard for Linux network configuration and supersedes older tools like `ifconfig`.

Exam trap

The trap here is that candidates often choose `ifconfig` out of habit, not realizing it is deprecated and may not show all interfaces or IPv6 addresses, whereas `ip addr show` is the comprehensive, modern standard.

How to eliminate wrong answers

Option A is wrong because `nmcli dev show` focuses on NetworkManager-managed devices and shows detailed connection profiles, but it may not display raw interface state or all IP addresses if NetworkManager is not in use. Option C is wrong because `netstat -i` only shows a summary of interface statistics (packets, errors, drops) and does not list IP addresses or detailed configuration. Option D is wrong because `ifconfig` is deprecated and often does not show all interfaces (e.g., it may omit virtual or bridge interfaces) and lacks modern features like IPv6 address display without additional flags.

Option E is wrong because `hostname -I` only outputs the system's IP addresses (all configured addresses) without any interface names, flags, or additional configuration details.

542
MCQmedium

Refer to the exhibit. A Linux administrator created a systemd service file for a custom script. When starting the service, it fails with 'Unit myservice.service entered failed state.' Which of the following is the most likely cause?

A.The ExecStart path is relative
B.The service type should be forking
C.The service file lacks an [Install] section
D.The Requires directive is missing
AnswerA

systemd requires an absolute path in ExecStart; a relative path causes the unit to fail immediately with 'entered failed state', since systemd cannot resolve the executable. This directly matches the stem's symptom and the most likely cause.

Why this answer

The most likely cause is that the ExecStart path is relative. Systemd requires absolute paths for ExecStart directives; a relative path (e.g., `./script.sh` or just `script.sh`) will cause the unit to fail immediately because systemd cannot resolve the executable location. The error 'entered failed state' typically results from this path resolution failure.

Exam trap

CompTIA often tests the requirement for absolute paths in ExecStart, and the trap here is that candidates may assume relative paths are acceptable or that the [Install] section is mandatory for starting a service, when in fact it is only for enabling.

How to eliminate wrong answers

Option B is wrong because changing the service type to 'forking' would not fix a missing absolute path; forking is used for daemons that spawn child processes and requires a PIDFile, but the immediate failure here is due to the ExecStart path issue. Option C is wrong because the [Install] section is only needed for enabling the service to start at boot (via systemctl enable), not for starting the service manually; the service can start without it. Option D is wrong because the Requires directive is optional and used to declare dependency on other units; its absence does not cause a start failure—it simply means no hard dependency is enforced.

543
MCQeasy

A Bash script contains the following code: if [[ $# -eq 0 ]]; then echo 'No arguments'; fi. What does this code check?

A.Whether the first argument is empty
B.Whether the script was called with no arguments
C.Whether the script has any syntax errors
D.Whether the script is running as root
AnswerB

The `$#` variable holds the argument count passed to the script, and `-eq 0` tests whether it equals zero. When no arguments are supplied, the condition succeeds and prints 'No arguments', directly satisfying the scenario's requirement to detect an invocation with an empty argument list.

Why this answer

In Bash, $# is a special parameter that expands to the number of positional parameters (arguments) passed to the script. The test [[ $# -eq 0 ]] evaluates to true when zero arguments were supplied, so the script echoes 'No arguments' when called without any arguments.

Exam trap

The trap is confusing $# (argument count) with $1 (first argument) or $? (exit status); candidates must memorize that $# specifically returns the number of positional parameters.

How to eliminate wrong answers

Option A is wrong because checking whether the first argument is empty would use [[ -z $1 ]] or [[ -z "$1" ]], not $#. Option C is wrong because syntax errors are detected by the Bash parser at runtime or with bash -n, not by $#. Option D is wrong because checking for root privileges uses $EUID or $UID (e.g., [[ $EUID -ne 0 ]]), not $#.

544
MCQeasy

A Linux administrator needs a scheduled job on a production server to run the backup script /usr/local/bin/backup.sh every day at 02:30, and the job must run as the root user regardless of who is logged in. Which single entry in /etc/crontab accomplishes this?

A.@daily root /usr/local/bin/backup.sh
B.2 30 * * * root /usr/local/bin/backup.sh
C.30 2 * * * /usr/local/bin/backup.sh root
D.30 2 * * * root /usr/local/bin/backup.sh
AnswerD

The system crontab /etc/crontab uses a six-field format where field five is the user account that runs the command, followed by the command itself. Placing root in that field and the absolute path to backup.sh after it makes the job run daily at 02:30 as root, independent of any interactive login session.

Why this answer

System-wide cron entries in /etc/crontab carry an extra user field between the five time/date fields and the command, which is what allows a job to run as root without a login. The schedule fields must be ordered minute, hour, day-of-month, month, day-of-week, so 30 2 * * * is 02:30 and root names the executing account.

Exam trap

The trap here is forgetting that /etc/crontab needs a sixth user field while a per-user crontab edited with crontab -e must not contain one.

545
MCQhard

A DevOps engineer wants to reduce the size of a Docker image by combining build stages. Which Dockerfile feature should be used?

A.RUN --mount=type=cache
B.Layer caching
C.Multi-stage builds (multiple FROM statements)
D.Using a smaller base image like Alpine
AnswerC

Multi-stage builds let later stages copy only required artefacts from earlier stages, discarding build tools, caches and intermediate layers. This directly reduces the final image size, meeting the DevOps engineer's goal of combining build stages rather than shipping a single bloated stage.

Why this answer

Multi-stage builds, implemented by using multiple FROM statements in a single Dockerfile, allow a DevOps engineer to copy only the necessary artifacts from intermediate build stages into the final image. This eliminates build-time dependencies, tools, and intermediate layers from the final image, significantly reducing its size without sacrificing build functionality.

Exam trap

The trap here is that candidates confuse layer caching (a performance feature) with multi-stage builds (a size-reduction feature), or they assume using a smaller base image alone achieves the same result as eliminating entire build stages.

How to eliminate wrong answers

Option A is wrong because RUN --mount=type=cache is used to persist package manager caches across builds to speed up subsequent builds, not to reduce the final image size by combining build stages. Option B is wrong because layer caching is a performance optimization that reuses unchanged layers from previous builds to accelerate rebuilds, but it does not reduce the size of the final image by combining stages. Option D is wrong because using a smaller base image like Alpine reduces the starting size of the image, but it does not combine build stages or eliminate intermediate build artifacts; multi-stage builds are the specific feature for that purpose.

546
MCQeasy

A Linux administrator needs to run a recurring backup script located at /usr/local/bin/backup.sh every day at 02:30. The system uses systemd and the administrator wants the job scheduled through a systemd timer rather than cron. Which combination of unit files must be created and enabled?

A.A single .service unit containing OnCalendar=*-*-* 02:30:00 in its [Service] section, then enable and start that unit.
B.A .timer unit with OnCalendar=*-*-* 02:30:00 and a matching .service unit, then enable and start the .timer unit.
C.A .timer unit with OnCalendar=*-*-* 02:30:00 and a matching .service unit, then enable and start the .service unit.
D.A .timer unit with OnBootSec=02:30 and a matching .service unit, then enable and start the .timer unit.
AnswerB

A systemd timer is driven by the OnCalendar= expression, and systemd activates the same-named .service unit when the timer elapses. Enabling and starting the .timer unit registers the schedule with systemd. The .service unit contains the ExecStart= line that actually invokes /usr/local/bin/backup.sh, so this pairing correctly delivers a daily 02:30 execution.

Why this answer

A systemd timer requires two cooperating units: a .timer unit that defines the schedule via OnCalendar= and a same-named .service unit that defines what to execute. To activate the schedule you enable and start the .timer unit, not the service. At each matching calendar point systemd triggers the associated service, which runs the ExecStart= command pointing at the backup script.

Exam trap

The trap here is assuming the .service unit must be enabled to make the schedule work, when it is actually the .timer unit that must be enabled and started.

547
MCQeasy

A junior administrator accidentally modified the /etc/sudoers file and now users report not being able to use sudo. Which command should be used to safely edit the sudoers file?

A.visudo
B.chmod 400 /etc/sudoers
C.echo 'user ALL=(ALL) ALL' >> /etc/sudoers
D.usermod -aG wheel user
AnswerA

Editing /etc/sudoers directly risks a syntax error that locks out sudo entirely. visudo validates the file's syntax before saving and writes atomically, so a malformed edit is rejected rather than committed, satisfying the requirement to edit safely.

Why this answer

The `visudo` command is the correct and safe way to edit the `/etc/sudoers` file because it locks the file against concurrent edits, performs syntax validation before saving, and prevents saving a malformed configuration that could break sudo entirely. This ensures that even if the administrator makes a mistake, the original valid file is preserved, avoiding the exact scenario described where users lose sudo access.

Exam trap

The trap here is that candidates may think any method that writes to the file (like `echo` or `chmod`) can fix the issue, but only `visudo` provides the syntax validation and locking necessary to safely edit the sudoers file without breaking sudo.

How to eliminate wrong answers

Option B is wrong because `chmod 400 /etc/sudoers` sets the file to read-only for the owner, which does not repair syntax errors or restore functionality; it only changes permissions and may even prevent `visudo` from writing a corrected file. Option C is wrong because using `echo` with a redirect appends text without any syntax checking, and if the appended line is malformed or duplicates entries, it can corrupt the file and break sudo. Option D is wrong because `usermod -aG wheel user` adds a user to the wheel group, which is unrelated to fixing a broken sudoers file; it does not validate or repair the syntax of `/etc/sudoers`.

548
MCQhard

After a kernel upgrade, the system fails to boot. Which file should be edited to configure GRUB2 to boot into the previous kernel version by default?

A./etc/grub.d/40_custom
B./boot/grub/grub.conf
C./boot/grub2/grub.cfg
D./etc/default/grub
AnswerD

GRUB2 reads /etc/default/grub for persistent defaults, including GRUB_DEFAULT, which selects the boot entry. Editing it to point at the previous kernel's menu entry, then running update-grub, satisfies the requirement to boot the older kernel by default after the failed upgrade.

Why this answer

/etc/default/grub, because this file contains the GRUB2 configuration variables (such as GRUB_DEFAULT) that control which kernel is booted by default. After editing this file, you must run 'grub2-mkconfig -o /boot/grub2/grub.cfg' to regenerate the boot configuration, which sets the previous kernel as the default entry.

Exam trap

The trap here is that candidates confuse the manually editable configuration file (/etc/default/grub) with the generated boot file (/boot/grub2/grub.cfg), leading them to incorrectly edit the latter directly.

How to eliminate wrong answers

Option A is wrong because /etc/grub.d/40_custom is a script used to add custom menu entries, not to set the default boot kernel. Option B is wrong because /boot/grub/grub.conf is the configuration file for GRUB Legacy (version 0.97), not GRUB2, which is used in modern Linux distributions. Option C is wrong because /boot/grub2/grub.cfg is the generated boot configuration file that should not be edited manually; changes must be made via /etc/default/grub and regenerated with grub2-mkconfig.

549
MCQmedium

Refer to the exhibit. An administrator wants to optimize a server running a high-throughput database application. Which command should be used to apply the recommended profile?

A.sudo tuned-adm profile throughput-performance
B.sudo tuned-adm profile balanced
C.sudo tuned-adm off
D.sudo systemctl set-default tuned
AnswerA

`tuned-adm profile throughput-performance` activates the tuned daemon's throughput-performance profile, which raises kernel dirty-ratio thresholds, uses the performance CPU governor and disables power-saving states — directly satisfying the stem's high-throughput database requirement. The `sudo` prefix is needed because switching profiles modifies system-wide tuning state.

Why this answer

The tuned-adm recommend command suggests 'throughput-performance', which is suitable for database workloads. The correct command to apply it is 'tuned-adm profile throughput-performance'.

550
MCQmedium

A Linux administrator needs to schedule a backup script to run every day at 2:30 AM. The script is located at `/usr/local/bin/backup.sh` and must run as the user `backupuser`. Which entry in the crontab for `backupuser` will accomplish this?

A.30 2 * * 1 /usr/local/bin/backup.sh
B.30 2 1 * * /usr/local/bin/backup.sh
C.2 30 * * * /usr/local/bin/backup.sh
D.30 2 * * * /usr/local/bin/backup.sh
AnswerD

This cron entry specifies minute 30, hour 2, every day of month, every month, and every day of week, which translates to 2:30 AM daily. The command is the full path to the script. This is the correct syntax for scheduling a daily job at that time.

Why this answer

The correct cron syntax for 2:30 AM daily is `30 2 * * *`. The minute field is 30, hour is 2, and the remaining fields are wildcards to indicate every day. The other options either have invalid time values or restrict execution to specific days, failing the daily requirement.

Exam trap

The trap here is mixing up the order of minute and hour fields, or misplacing wildcards to unintentionally limit the schedule.

551
MCQhard

An administrator is tasked with creating a systemd service that runs a Python script after the network is available. The script must restart automatically if it fails. Which systemd service unit directive should be used to ensure restart on failure?

A.Restart=always
B.RemainAfterExit=yes
C.Restart=on-failure
D.RestartSec=5
AnswerC

Restart=on-failure instructs systemd to relaunch the unit only when the Python script exits with a non-zero status or is killed by a signal, meeting the stem's requirement for automatic restart after failure without restarting on clean exits.

Why this answer

The `Restart=on-failure` directive instructs systemd to restart the service unit only when the process exits with a non-zero exit code, is terminated by a signal (including SIGKILL), or times out. This is the correct choice because the requirement is to restart the script only if it fails, not unconditionally. Using `Restart=always` would restart the service even after a clean exit, which is unnecessary and could mask intentional stops.

Exam trap

CompTIA often tests the distinction between `Restart=always` and `Restart=on-failure`, trapping candidates who assume that 'always' is the safest choice without reading the exact failure condition requirement.

How to eliminate wrong answers

Option A is wrong because `Restart=always` causes the service to restart regardless of the exit status, including normal clean exits, which does not match the requirement to restart only on failure. Option B is wrong because `RemainAfterExit=yes` indicates that the service is considered active even after the main process exits, but it does not control restart behavior on failure. Option D is wrong because `RestartSec=5` specifies a delay (5 seconds) before attempting a restart, but it is not a restart condition directive; it only modifies the timing when used with a `Restart=` setting.

552
MCQmedium

A Linux administrator is configuring a server to use a centralized authentication service. The security policy requires that user credentials are never sent in clear text and that the authentication traffic is encrypted. The administrator decides to use LDAP with TLS. Which command should be used to verify that the LDAP server's certificate is valid and that the TLS handshake succeeds?

A.ss -tlnp | grep 636
B.nmap --script ssl-enum-ciphers -p 389 ldap.example.com
C.ldapsearch -H ldap://ldap.example.com -x -b '' -s base
D.openssl s_client -connect ldap.example.com:636 -showcerts
AnswerD

openssl s_client initiates a TLS connection to the specified host and port, displaying the server's certificate chain and the result of the handshake. Using port 636, the standard LDAPS port, this command verifies that the LDAP server presents a valid certificate and that TLS negotiation succeeds, directly addressing the requirement.

Why this answer

The openssl s_client command is designed to test TLS connections, making it ideal for verifying the LDAP server's certificate and handshake on the LDAPS port. It displays the certificate chain and any errors, ensuring that the encryption is correctly configured. Other commands either connect without encryption, check only for listening sockets, or do not validate the certificate in the LDAP context.

Exam trap

The trap here is using ldapsearch with an ldap:// URI and assuming it tests encryption, when it actually connects in clear text unless StartTLS is explicitly requested.

553
MCQhard

An administrator needs to ensure that only users from the 'ops' group can SSH into a server. Which configuration in /etc/ssh/sshd_config accomplishes this?

A.AllowGroups ops
B.Match Group ops DenyUsers *
C.AllowUsers ops
D.DenyUsers all
AnswerA

AllowGroups ops restricts SSH logins to members of the ops group, satisfying the requirement that only that group connects. When AllowGroups is set, all users outside the listed groups are denied, regardless of other account settings.

Why this answer

The `AllowGroups` directive in `/etc/ssh/sshd_config` restricts SSH access to only users who are members of the specified group. By setting `AllowGroups ops`, only users belonging to the 'ops' group will be permitted to log in via SSH, which directly meets the requirement.

Exam trap

The trap here is confusing `AllowUsers` (which matches usernames) with `AllowGroups` (which matches group membership), leading candidates to select option C when the requirement specifies group-based restriction.

How to eliminate wrong answers

Option B is wrong because `Match Group ops DenyUsers *` would deny all users (including those in 'ops') when the group matches, effectively blocking everyone. Option C is wrong because `AllowUsers ops` restricts access to a user named 'ops', not to members of the 'ops' group. Option D is wrong because `DenyUsers all` is invalid syntax (the correct directive is `DenyUsers` followed by specific usernames, not the keyword 'all'), and it would not achieve group-based restriction.

554
MCQeasy

A Linux administrator needs to view the kernel ring buffer messages to diagnose a hardware issue. Which command should the administrator use?

A.dmesg
B.cat /var/log/messages
C.tail -f /var/log/syslog
D.journalctl -k
AnswerA

dmesg displays the kernel ring buffer, which contains messages from the kernel, including hardware detection, driver initialization, and errors. This is the primary tool for diagnosing hardware issues at the kernel level. It provides detailed information about devices, interrupts, and other low-level events, making it ideal for the administrator's task.

Why this answer

dmesg is the direct command to view the kernel ring buffer, which contains hardware and driver messages. It is always available and does not depend on system logging services. While journalctl -k can show kernel messages on systemd systems, dmesg is the standard tool for this specific task.

Exam trap

The trap here is assuming that general system logs like /var/log/messages contain all kernel messages; they often do not, especially early boot messages.

555
MCQhard

An administrator notices that a custom application uses port 8443/TCP. To allow external access, which firewalld command permanently opens this port in the default zone?

A.firewall-cmd --add-port=8443/tcp --permanent
B.firewall-cmd --add-service=8443/tcp --zone=public --permanent
C.firewall-cmd --add-port=8443 --permanent
D.firewall-cmd --permanent --add-port=8443
AnswerA

--add-port=8443/tcp adds the port to the default zone's permanent configuration, and --permanent ensures it survives firewalld reloads and reboots. A runtime-only change would vanish on reload, so the permanent flag is essential to the stem's requirement.

Why this answer

The correct command is firewall-cmd --permanent --add-port=8443/tcp. The --permanent flag makes it persistent, --add-port opens the port, and the syntax includes protocol. --add-service is for predefined services, not port numbers.

556
Matchingmedium

Match each Linux access control mechanism to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Traditional file permissions (owner/group/other)

Fine-grained permissions for users/groups

Mandatory access control with policies

Path-based mandatory access control

Default permission mask for new files

Why these pairings

Correct matches: DAC relates to owner-set permissions; MAC involves system-wide policy enforcement; RBAC uses roles; ACLs extend permissions to multiple users/groups. Common confusions include swapping DAC and MAC definitions, or confusing DAC with RBAC.

557
MCQeasy

The backup script above always outputs 'Backup failed' even when the tar command succeeds. Which of the following is the cause?

A.The tar command should use -czvf
B.The if statement syntax is wrong
C.The variable &? is not defined
D.The correct variable is $? not &?
AnswerD

The script incorrectly uses &? instead of the correct $? variable.

Why this answer

The script uses `&?` to reference the exit status of the `tar` command, but the correct shell variable is `$?`. The `$?` variable holds the exit code of the last executed command (0 for success, non-zero for failure). Using `&?` is a syntax error that results in an empty or invalid value, causing the `if` statement to always evaluate to false (or treat the condition as non-zero), thus always printing 'Backup failed'.

Exam trap

CompTIA often tests the distinction between `$?` and common typos like `&?` or `?$`, exploiting the fact that candidates may overlook the exact syntax of shell special variables and assume any symbol before `?` works.

How to eliminate wrong answers

Option A is wrong because `-czvf` is a valid set of flags for `tar` (create, gzip, verbose, file) and would not cause the script to always output 'Backup failed' if the command succeeds; the issue is not with the tar flags. Option B is wrong because the `if` statement syntax (`if [ condition ]; then ... fi`) is correct; the problem lies in the variable name used inside the condition, not the structure of the if statement. Option C is wrong because `&?` is not a defined variable in bash; the shell does not have a built-in variable named `&?`, and using it does not trigger a special behavior—it simply evaluates to an empty string, which breaks the logic.

558
Multi-Selecthard

A server crashed with a kernel panic. After reboot, the administrator wants to analyze the crash dump. Which THREE actions should be taken to ensure a valid core dump is captured and accessible? (Choose THREE.)

Select 3 answers
A.Configure a dump target in /etc/kdump.conf.
B.Enable and start the kdump service.
C.Set crashkernel=auto in the boot loader.
D.Install kernel-debuginfo packages.
E.Ensure /var/crash has a vmcore file.
AnswersA, B, C

kdump needs a configured dump target in /etc/kdump.conf to know where to write the vmcore after a panic. Without a valid target path or device, the crash dump is discarded, so this action is required for later analysis.

Why this answer

Option A is correct because /etc/kdump.conf is the kdump configuration file where you must specify the dump target (e.g., a raw device, path, NFS, or SSH location) so the vmcore is written to a persistent, accessible location after the crash. Option B is correct because the kdump service (kdump.service) must be enabled and started so the kdump initramfs is loaded and the capture mechanism is armed for the next kernel panic. Option C is correct because the crashkernel=auto (or an explicit size like crashkernel=256M) kernel parameter in the boot loader reserves memory for the secondary kernel that performs the dump; without it, no dump can be captured.

Option D is not required to capture a dump; kernel-debuginfo is only needed later for analyzing the vmcore with tools like crash. Option E is incorrect because /var/crash/vmcore is the result of a successful capture, not an action taken to ensure one, and its presence cannot be guaranteed before a crash occurs.

Exam trap

The trap here is that candidates confuse post-crash verification (checking for a vmcore file) with pre-crash configuration steps, or they mistakenly think debuginfo packages are required for capturing the dump rather than for later analysis.

559
MCQeasy

A junior administrator is asked to verify that the integrity of a downloaded package file has not been altered in transit. The vendor publishes a SHA-256 checksum file alongside the package. Which command should the administrator run to compare the computed hash of the downloaded file against the published value?

A.sha256sum package.rpm
B.rpm --checksig package.rpm
C.md5sum package.rpm
D.gpg --verify package.rpm
AnswerA

sha256sum computes the SHA-256 hash of the specified file and prints it, which the administrator can compare against the vendor's published checksum. It is the standard coreutils tool for this purpose and directly fulfills the integrity verification task. A match confirms the file matches the expected content.

Why this answer

The sha256sum utility computes the SHA-256 digest of a file, allowing a direct comparison with the vendor's published checksum to confirm the download was not altered. The other commands either use a different algorithm, require signature artifacts not provided, or verify RPM signatures rather than a standalone hash file.

Exam trap

The trap here is choosing md5sum because it also produces a checksum, when the vendor published a SHA-256 value that must be matched with the same algorithm.

560
Multi-Selecthard

An administrator notices that a user's crontab file is not executing. Which two commands can the administrator use to verify the user's crontab configuration? (Select TWO.)

Select 2 answers
A.crontab -e -u username
B.crontab -l -u username
C.cat /var/spool/cron/crontabs/username
D.systemctl status cron
E.grep username /etc/crontab
AnswersB, C

Lists the contents of the specified user's crontab.

Why this answer

`crontab -l -u username` lists the current crontab entries for the specified user, allowing the administrator to verify the configured jobs. Option C is correct because on many Linux distributions, user crontab files are stored as plain text files under `/var/spool/cron/crontabs/username`, and reading that file directly shows the same content. Both commands let the administrator inspect the exact cron schedule and commands for that user.

Exam trap

The trap here is that candidates confuse commands that verify the cron daemon's status (like `systemctl status cron`) with commands that inspect the actual crontab content, or they mistakenly think editing (`-e`) is the same as listing (`-l`).

561
MCQhard

A Linux administrator is troubleshooting a service that fails to start. The service unit file is present and enabled, but systemctl status shows 'failed' with exit code 203. Which command should the administrator run to view the most recent log messages specific to this service?

A.dmesg | grep servicename
B.tail -f /var/log/messages
C.systemctl cat servicename.service
D.journalctl -u servicename.service -n 50
AnswerD

journalctl -u filters logs for a specific systemd unit. The -n 50 option shows the last 50 lines. This directly provides the recent log messages for the failing service, which is exactly what is needed. Exit code 203 often indicates an exec failure, and the logs will reveal the exact error.

Why this answer

The administrator should use journalctl -u servicename.service -n 50 to view the most recent log entries for that unit. This command queries the systemd journal, which captures stdout/stderr from the service and systemd's own messages about start failures. It is the most direct way to diagnose why the service failed with exit code 203.

Exam trap

The trap here is assuming that traditional log files like /var/log/messages contain all service logs, when systemd-based systems primarily use the journal.

562
MCQmedium

An Ansible playbook is being written to install the Nginx web server on a group of Ubuntu servers. Which module should be used in the playbook to install the package?

A.apt
B.command
C.package
D.yum
AnswerA

The apt module drives Ubuntu's native package manager, satisfying the stem's requirement to install Nginx on Debian-based hosts. It handles repository metadata, dependency resolution and idempotent state checks directly, unlike generic command or shell modules that would bypass package management and lose idempotence.

Why this answer

The apt module is used for package management on Debian/Ubuntu systems.

563
MCQeasy

A Linux administrator needs to check the amount of free disk space on all mounted filesystems in a human-readable format. Which command should be used?

A.lsblk -f
B.df -h
C.du -sh /*
D.fdisk -l
AnswerB

df -h displays disk space usage for all mounted filesystems in human-readable units (e.g., GB, MB). It shows total size, used space, available space, and mount point. This directly answers the need to check free disk space across all mounts in an easily readable format. It is the standard command for this purpose and is available on all Linux distributions.

Why this answer

df -h is the correct command to check free disk space on all mounted filesystems in human-readable format. It reads filesystem statistics and displays total, used, and available space along with mount points. The other commands serve different purposes: du estimates directory usage, lsblk shows block device and filesystem information without usage, and fdisk lists partitions.

Only df directly reports free space per filesystem.

Exam trap

The trap here is confusing du with df; du shows directory usage but not filesystem free space, which is what the scenario requires.

564
Drag & Dropmedium

Drag and drop the steps to recover a forgotten root password in single-user mode in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Root password recovery involves booting into single-user mode and remounting root as rw.

565
Multi-Selectmedium

Which two of the following are valid methods to pass environment variables to a Docker container at runtime? (Select TWO.)

Select 2 answers
A.Defining variables in a .env file and using --env-file
B.Using the -e option in docker run
C.Using the ENV instruction in the Dockerfile
D.Using the export command inside the container
E.Using the ARG instruction in the Dockerfile
AnswersA, B

Passing `--env-file` reads the named file and injects each key-value pair as an environment variable inside the container at start-up, satisfying the runtime requirement without baking values into the image. This differs from build-time `ARG`, which cannot populate container environment variables after the image is built.

Why this answer

Option A is correct because `docker run --env-file <file>` reads a file of KEY=VALUE lines (commonly named .env) and injects those variables into the container's environment at runtime. Option B is correct because `docker run -e KEY=VALUE` (or `--env`) sets an environment variable directly on the container when it starts. Option C is not a runtime method: the Dockerfile `ENV` instruction bakes variables into the image at build time, so they exist by default but are not passed at runtime.

Option D is invalid because `export` executed inside a running container only affects that shell session, not the container's startup environment. Option E is incorrect because the Dockerfile `ARG` instruction defines build-time variables, which are not automatically available as runtime environment variables.

Exam trap

CompTIA often tests the distinction between build-time instructions (`ENV`, `ARG`) and runtime options (`-e`, `--env-file`), so the trap here is confusing the `ENV` instruction in the Dockerfile (which sets variables at build time) with the `-e` option (which sets variables at runtime).

566
MCQhard

A Linux administrator is troubleshooting a service that fails to start. The service unit file contains 'User=appuser' and 'Group=appgroup'. The administrator runs 'systemctl start app.service' and sees the error 'Failed to determine user credentials: No such process'. Which of the following is the most likely cause?

A.The user appuser does not exist on the system.
B.The service unit file has a syntax error in the [Service] section.
C.The service binary does not have the execute permission for appuser.
D.The appgroup group exists but appuser is not a member of it.
AnswerA

The error 'Failed to determine user credentials: No such process' occurs when systemd cannot resolve the User= or Group= specified in the unit. If appuser is absent from /etc/passwd and the NSS databases, systemd cannot switch to that UID, so the service fails to start. Creating the user or correcting the unit resolves it.

Why this answer

systemd resolves User= and Group= before launching the process. If the specified account cannot be found in the user database, systemd aborts with a credential resolution error. The fix is to create the missing user or correct the unit file to reference an existing account, then reload systemd and restart the service.

Exam trap

The trap here is focusing on file permissions or group membership when the error text explicitly indicates that systemd cannot resolve the user account itself.

567
MCQhard

A developer needs to grant a colleague read and write access to a directory /project, but the colleague should not have permission to delete any files created by the developer. The developer wants to set the directory so that all new files created in it automatically belong to the group 'project' and are writable by group. Which combination of configuration should be used?

A.chmod g+s /project && setfacl -m default:g:project:rw /project
B.chmod 1770 /project && usermod -aG project colleague
C.chmod g+s /project && setfacl -m g:project:rwx /project
D.chown .project /project && chmod 2775 /project
AnswerA

Setgid ensures new files inherit project group; default ACL ensures new files have group rw permissions.

Why this answer

It combines the setgid bit (`chmod g+s`) on the directory, which ensures new files inherit the group 'project', with a default ACL (`setfacl -m default:g:project:rw`) that grants read and write permissions to the group on newly created files. This setup gives the colleague (who is a member of the 'project' group) read/write access without delete permission on files owned by the developer, as the colleague cannot delete files they do not own unless the directory's sticky bit is set (which is not configured here).

Exam trap

A common mistake is confusing a regular ACL applied to a directory with a default ACL. A regular ACL affects only the directory itself, not new files. Only default ACLs are inherited by newly created files.

How to eliminate wrong answers

Option B is wrong because `chmod 1770` sets the sticky bit, which prevents users from deleting files they do not own, but it does not ensure new files inherit the group 'project' or are automatically group-writable; additionally, `usermod -aG project colleague` only adds the colleague to the group, which is necessary but insufficient without the setgid bit and default ACL. Option C is wrong because `setfacl -m g:project:rwx /project` sets an ACL on the directory itself, not a default ACL, so new files created inside will not automatically inherit the group 'project' permissions; the `rwx` also grants execute permission, which is not required for read/write access. Option D is wrong because `chown .project /project` changes the group ownership of the directory to 'project', and `chmod 2775` sets the setgid bit and permissions (rwx for owner, rwx for group, r-x for others), but this does not grant the colleague write access to new files created by the developer unless a default ACL is applied; the 2775 mode gives group write permission on the directory but not on new files, and the colleague could still delete files they own or if the directory permissions allow.

568
MCQhard

A Linux server runs a critical service managed by a systemd service unit. The administrator needs to configure the service to automatically restart if it crashes, but only up to 3 times within a 30-second window. If the service restarts more than 3 times in 30 seconds, systemd should stop attempting to restart and leave the service in a failed state. Which set of directives should be added to the [Service] section of the unit file to achieve this behavior?

A.`Restart=on-abort` and `MaxStartups=3`
B.`Restart=on-failure` and `StartLimitBurst=5` and `StartLimitIntervalSec=60`
C.`Restart=always` and `RestartSec=10`
D.`Restart=on-failure` and `StartLimitBurst=3` and `StartLimitIntervalSec=30`
AnswerD

Restart=on-failure triggers restarts after abnormal exit. StartLimitBurst=3 caps restarts at three, while StartLimitIntervalSec=30 defines the 30-second window in which those restarts are counted. Exceeding the burst within that interval makes systemd stop restarting and leave the unit failed.

Why this answer

It uses `Restart=on-failure` to trigger a restart only when the service crashes (not on other stops), combined with `StartLimitBurst=3` and `StartLimitIntervalSec=30` to limit restarts to 3 attempts within a 30-second window. When the burst limit is exceeded, systemd automatically places the unit in a failed state, exactly matching the requirement.

Exam trap

The trap here is that candidates often confuse `Restart=always` (which restarts on any exit, including intentional stops) with `Restart=on-failure` (which only restarts on crashes), or they misremember the default values of `StartLimitBurst` and `StartLimitIntervalSec`, leading them to pick options with incorrect burst counts or intervals.

How to eliminate wrong answers

Option A is wrong because `Restart=on-abort` only restarts the service if it terminates due to a signal that is not caught (e.g., SIGABRT), not on general crashes, and `MaxStartups` is not a valid systemd directive (it is used in sshd configuration, not unit files). Option B is wrong because `StartLimitBurst=5` and `StartLimitIntervalSec=60` would allow up to 5 restarts in 60 seconds, not the required 3 in 30 seconds. Option C is wrong because `Restart=always` restarts the service regardless of exit reason (including manual stops), and `RestartSec=10` only sets a delay between restarts, with no limit on the number of restart attempts, so the service would keep restarting indefinitely.

569
MCQeasy

A user needs to view the first 15 lines of a large log file. Which command is most appropriate?

A.head -n 15 filename
B.cat filename | head -n 15
C.less -N 15 filename
D.tail -n 15 filename
AnswerA

head outputs the beginning of a file, and -n 15 limits that output to exactly 15 lines, directly satisfying the requirement to view the first 15 lines. tail would show the end, and cat would dump the entire large log.

Why this answer

The command 'head -n 15 filename' is the most appropriate and efficient way to view the first 15 lines of a file. The head command is designed for this purpose, and the -n option specifies the number of lines. This is a standard Linux command and is more direct than piping cat to head.

Exam trap

XK0-006 often tests the difference between head and tail, and the proper syntax for limiting lines; candidates may confuse -n with other options or choose cat | head unnecessarily.

How to eliminate wrong answers

Option B is wrong because while 'cat filename | head -n 15' works, it is less efficient as it invokes two processes and is considered a useless use of cat. Option C is wrong because 'less -N 15 filename' opens the file in a pager with line numbers, but the -N option is for line numbers, not for limiting to 15 lines; less will display the whole file. Option D is wrong because 'tail -n 15 filename' displays the last 15 lines, not the first 15.

570
MCQeasy

A developer wants to view the logs from a running Docker container named 'myapp'. Which docker command should be used?

A.docker logs myapp
B.docker ps myapp
C.docker exec myapp logs
D.docker inspect myapp
AnswerA

docker logs retrieves stdout and stderr captured from the container's main process, and naming the container filters output to that instance. This satisfies the requirement to view logs from the running container 'myapp' without attaching to or executing inside it.

Why this answer

The 'docker logs' command is specifically designed to fetch the logs from a container's stdout/stderr. Running 'docker logs myapp' will display the logs generated by the container named 'myapp'. This is the standard and correct way to view container logs.

Exam trap

The trap is confusing 'docker logs' with 'docker exec' or 'docker inspect'; candidates might think they need to enter the container to view logs, but Docker provides a direct command for that.

How to eliminate wrong answers

Option B is wrong because 'docker ps' lists running containers and does not accept a container name as an argument to show logs; it only shows container metadata. Option C is wrong because 'docker exec' is used to run a command inside a running container, and 'logs' is not a valid command inside the container; it would attempt to execute a binary named 'logs'. Option D is wrong because 'docker inspect' returns low-level JSON metadata about the container (e.g., configuration, network settings) but does not display the application logs.

571
Multi-Selectmedium

An administrator wants to gather information about disk usage for a specific directory and its subdirectories. Which TWO commands can be used for this purpose? (Choose two.)

Select 2 answers
A.du -sh /path
B.df -h /path
C.ls -lh /path
D.du -h /path
E.stat /path
AnswersA, D

The -s flag collapses output to a single summary total for the directory, while -h renders sizes in human-readable units. Together they report total disk usage for /path and everything beneath it, satisfying the requirement to gather usage across the directory and its subdirectories.

Why this answer

Option A (du -sh /path) is correct because du reports disk usage for the specified directory and, by default, recurses into its subdirectories, while -s summarizes the total into a single figure and -h presents it in human-readable units. Option D (du -h /path) is also correct because du -h /path likewise walks the directory tree and prints the disk usage of the directory and each subdirectory in human-readable form, satisfying the requirement to gather usage information for the directory and its subdirectories. Option B (df -h /path) is not correct because df reports filesystem-level free and used space for the mount point containing the path, not per-directory or per-subdirectory usage.

Option C (ls -lh /path) is not correct because ls only lists file and directory entries with their sizes, without recursively totaling the disk usage of subdirectory contents. Option E (stat /path) is not correct because stat displays metadata such as inode, permissions, and timestamps for a single file or directory, not aggregated disk usage across a directory tree.

Exam trap

XK0-006 often tests the du vs df distinction — candidates pick df because it also reports 'disk usage,' missing that df is filesystem-level and du is directory-level.

572
MCQmedium

A Linux server is configured to use systemd. The administrator wants to ensure that a custom service named 'app.service' starts automatically at boot, even if it has been manually stopped. Which command should be used?

A.systemctl enable app.service
B.systemctl start app.service
C.systemctl preset app.service
D.systemctl reenable app.service
AnswerA

This command creates a symbolic link from the systemd unit file in /etc/systemd/system to the appropriate target's .wants directory, ensuring the service starts at boot. It does not start the service immediately, but it ensures it will be started on subsequent boots. This is the correct way to configure automatic startup.

Why this answer

The correct answer is the command that creates the necessary symbolic links for the service to start automatically at boot. This is done with systemctl enable. The other commands either start the service now, reset enablement, or apply presets, none of which ensure persistent automatic startup.

Exam trap

The trap here is confusing starting a service with enabling it; starting only affects the current session, while enabling configures boot-time activation.

573
MCQmedium

A Kubernetes administrator needs to expose a deployment named 'webapp' as a service accessible externally on port 80. Which kubectl command should be used?

A.kubectl port-forward deployment/webapp 80:80
B.kubectl run webapp --port=80
C.kubectl expose deployment webapp --type=NodePort --port=80
D.kubectl create service clusterip webapp --port=80
AnswerC

NodePort opens a static port on every cluster node, routing external traffic to the deployment's pods, which satisfies the external-access requirement. However, it exposes the service on a high port (30000–32767) rather than port 80 directly, so clients must target the assigned node port unless a load balancer or ingress maps port 80.

Why this answer

The kubectl expose deployment command creates a Service from an existing Deployment. Specifying --type=NodePort makes the service externally reachable on each node's IP at a high port, and --port=80 sets the service port to 80. This is the standard imperative way to expose a deployment externally without writing a YAML manifest.

Exam trap

The trap is confusing port-forward (a temporary local tunnel) with expose (a persistent Service) — candidates often pick port-forward thinking it provides external access, but it only works from the machine running kubectl.

How to eliminate wrong answers

Option A is wrong because kubectl port-forward only creates a temporary local tunnel from the administrator's machine to the pod; it does not expose the service externally to other clients. Option B is wrong because kubectl run creates a new pod or deployment, not a service, and would conflict with the existing 'webapp' deployment. Option D is wrong because ClusterIP services are only reachable inside the cluster, not externally, so they do not satisfy the external-access requirement.

574
Multi-Selecthard

Which THREE of the following are valid methods to troubleshoot a service that fails to start?

Select 3 answers
A.Run the service executable manually from the command line to see error output.
B.Review the service logs using journalctl.
C.Check if the service's required dependencies are installed and running.
D.Run df -h to check disk space.
E.Reload the systemd daemon with systemctl daemon-reload.
AnswersA, B, C

Running the executable directly bypasses systemd's abstraction, exposing startup errors on stderr that the service manager may swallow. This satisfies the stem's need to troubleshoot a service that fails to start by revealing the actual failure reason, such as missing libraries or permission faults.

Why this answer

Option A is correct because running the service executable directly from the command line bypasses the service manager and surfaces stdout/stderr error messages that systemd may otherwise capture or suppress, making the actual failure reason visible. Option B is correct because journalctl queries the systemd journal, allowing you to inspect the unit's logged output and error messages (e.g., journalctl -u <service>) to identify why it failed to start. Option C is correct because a service often fails when its required dependencies (libraries, packages, or other units) are missing or not running, so verifying and starting those dependencies is a valid troubleshooting step.

Option D is not a targeted method for a service startup failure; df -h only reports filesystem disk usage and is not specific to diagnosing why a particular service won't start. Option E is not a troubleshooting method for a failing service; systemctl daemon-reload only reloads unit file definitions after they are edited and does not diagnose or fix a service that fails to start.

Exam trap

The trap here is that candidates often confuse general system health commands (like `df -h`) with service-specific troubleshooting methods, or they think `systemctl daemon-reload` is a diagnostic step when it only reloads configuration without providing error details.

575
Multi-Selectmedium

An administrator needs to update the package cache and upgrade all installed packages on a Debian-based system. Which TWO commands are appropriate for this task? (Select TWO.)

Select 2 answers
A.apt dist-upgrade
B.apt update
C.apt upgrade
D.dpkg --configure -a
E.apt list --upgradable
AnswersB, C

`apt update` refreshes the local package index from the repositories configured in `/etc/apt/sources.list`, so the system knows which upgraded versions are available. It satisfies the stem's "update the package cache" requirement, and must run before any upgrade command such as `apt upgrade` or `apt full-upgrade`.

Why this answer

Option B, `apt update`, is correct because it refreshes the local package index/cache from the repositories configured in /etc/apt/sources.list and sources.list.d, which is the required first step before any upgrade so APT knows the latest available versions. Option C, `apt upgrade`, is correct because it installs the newest versions of all currently installed packages using the refreshed cache, while safely holding back packages that would require removing or adding other packages. Together, `apt update` followed by `apt upgrade` accomplishes updating the package cache and upgrading installed packages on a Debian-based system.

Option A, `apt dist-upgrade`, is not one of the marked answers here; it performs a more aggressive upgrade that can add or remove packages to resolve dependencies, which goes beyond the stated task. Option D, `dpkg --configure -a`, only reconfigures packages left unconfigured after an interrupted installation and does not update the cache or upgrade packages. Option E, `apt list --upgradable`, merely lists packages with available upgrades and performs no cache refresh or installation.

576
MCQhard

A company uses a Linux server running Ubuntu 22.04 LTS as a file server to share documents via Samba. The server has been in operation for over a year without issues. Following a routine system update that included kernel patches and updated Samba packages, users began reporting that they could no longer access any shared folders. The administrator verifies that the smbd and nmbd services are running and have not failed. The Samba configuration has not been changed recently. The server uses ufw as its firewall. When the administrator runs 'ufw status', the output shows that only SSH (port 22) is allowed. The administrator checks for SELinux but finds it is not installed; however, AppArmor is active and the smbd profile is in enforce mode. The administrator examines the AppArmor logs and finds no denials related to smbd. Which of the following is the most likely reason for the connectivity failure?

A.The firewall is blocking Samba ports 137, 138, 139, and 445.
B.The Samba configuration file was corrupted during the update.
C.The kernel update changed the default file system mount options, restricting access.
D.The AppArmor profile is preventing smbd from binding to network interfaces.
AnswerA

ufw permits only port 22, so Samba's TCP 445 and 139 (plus UDP 137/138) are blocked at the firewall. Services running and AppArmor showing no denials confirm the traffic never reaches smbd, making the firewall the cause.

Why this answer

The firewall (ufw) is only allowing SSH (port 22), which means Samba ports 137/138 (NetBIOS), 139 (SMB over NetBIOS), and 445 (SMB over TCP) are blocked. Since the smbd and nmbd services are running and AppArmor shows no denials, the most likely cause is that the firewall rules were reset or not updated after the system update, preventing Samba traffic from reaching the server.

Exam trap

The trap here is that candidates may focus on AppArmor or SELinux because they are security modules, but the absence of denials in AppArmor logs and the explicit ufw output showing only SSH allowed points directly to the firewall as the culprit.

How to eliminate wrong answers

Option B is wrong because the administrator verified that the Samba configuration has not been changed recently, and the services are running without errors, so corruption is unlikely. Option C is wrong because kernel updates do not change default file system mount options; mount options are set in /etc/fstab or at mount time and are not altered by kernel patches. Option D is wrong because the administrator checked AppArmor logs and found no denials related to smbd, indicating the profile is not blocking network binding.

577
MCQeasy

A system administrator wants to enforce a password policy requiring a minimum length of 12 characters, at least one uppercase letter, and one digit. Which PAM module should be configured?

A.pam_pwquality
B.pam_unix
C.pam_faillock
D.pam_tally2
AnswerA

pam_pwquality enforces length, character-class and complexity checks through its minlen, ucredit and dcredit parameters, directly satisfying the 12-character minimum plus uppercase and digit requirements. It supersedes the older pam_cracklib module and integrates with the password stack.

Why this answer

pam_pwquality is the correct PAM module because it is specifically designed to enforce password complexity requirements, such as minimum length, uppercase letters, and digits, through configurable parameters like minlen, ucredit, and dcredit. It replaces the older pam_cracklib and is the standard module for password quality checks on modern Linux systems.

Exam trap

The trap here is that candidates confuse pam_unix (which handles authentication and password aging) with pam_pwquality (which enforces complexity), because both are commonly used together in password policies but serve distinct roles.

How to eliminate wrong answers

Option B (pam_unix) is wrong because it handles traditional Unix authentication (password hashing and verification) but does not enforce complexity rules like length or character classes. Option C (pam_faillock) is wrong because it is used for account lockout after failed login attempts, not for password composition policies. Option D (pam_tally2) is wrong because it also manages login failure counting and account locking, not password quality enforcement.

578
MCQhard

An administrator needs to deploy a set of microservices using Docker Compose. The services require configuration values that vary between development and production environments. Which approach allows the administrator to override values without modifying the docker-compose.yml file?

A.Define multiple services in one docker-compose.yml and use profiles.
B.Use environment variables in the Dockerfile and pass them via docker run -e.
C.Use the extends keyword in docker-compose.yml.
D.Use multiple compose files with the -f flag: docker-compose -f docker-compose.yml -f docker-compose.prod.yml up.
AnswerD

Layering multiple Compose files with the `-f` flag merges them at runtime, with later files overriding earlier values. This satisfies the requirement to vary configuration between development and production without editing `docker-compose.yml`, since the base file stays untouched and environment-specific overrides live in a separate file.

Why this answer

Docker Compose supports merging multiple compose files via the -f flag, where later files override or extend values from earlier ones. Running docker-compose -f docker-compose.yml -f docker-compose.prod.yml up applies the base configuration and then overlays production-specific values without editing the original file.

Exam trap

The trap is selecting extends or profiles for environment-specific overrides; candidates must remember that multi-file merging with -f is the canonical Docker Compose pattern for layering environment configurations.

How to eliminate wrong answers

Option A is wrong because profiles are used to selectively enable/disable groups of services within a single compose file, not to override configuration values between environments. Option B is wrong because environment variables in the Dockerfile and docker run -e apply to individual containers, not to Compose-managed multi-service deployments, and they do not override compose file values. Option C is wrong because the extends keyword allows a service to inherit configuration from another service or file, but it is designed for reuse within a single project, not for environment-specific overrides across multiple files.

579
MCQeasy

A system administrator needs to run a script every 15 minutes. Which systemd unit type is used to schedule this?

A.systemd timer
B.at job
C.anacron
D.cron job
AnswerA

A systemd timer unit triggers another unit on a schedule defined by OnCalendar, replacing cron for recurring jobs. Defining a timer with a 15-minute OnCalendar interval satisfies the requirement to run the script every 15 minutes.

Why this answer

Systemd timers are the native systemd unit type for scheduling tasks at specified intervals, such as every 15 minutes. They replace traditional cron jobs in systemd-based Linux distributions and are defined with a .timer unit file that triggers a corresponding .service unit. This makes option A correct because the question explicitly asks for the systemd unit type used for scheduling.

Exam trap

The trap here is that candidates familiar with traditional Linux scheduling immediately think of cron, but the question explicitly asks for a 'systemd unit type,' making cron a distractor despite its functional similarity.

How to eliminate wrong answers

Option B (at job) is wrong because the 'at' command schedules a one-time task at a specific time, not recurring every 15 minutes. Option C (anacron) is wrong because anacron is designed for tasks that need to run daily, weekly, or monthly, assuming the system may not be running continuously, and it does not support sub-daily intervals like 15 minutes. Option D (cron job) is wrong because while cron can schedule tasks every 15 minutes, the question specifically asks for a systemd unit type, and cron is a separate service, not a systemd unit.

580
MCQeasy

A developer writes a Python script that uses the `requests` library to fetch data from an API. The script works on the developer's workstation but fails on the server with an import error. What is the most likely cause?

A.The `requests` module is not installed on the server
B.The script uses an incorrect API endpoint
C.The server lacks internet connectivity
D.The script has a syntax error in the import statement
AnswerA

The `requests` library is a third-party package, not part of Python's standard library, so it is absent unless separately installed. The workstation already has it, but the server's interpreter lacks it, producing the ImportError. Installing it via pip into the server's environment resolves the failure.

Why this answer

The `requests` library is a third-party Python package that must be installed separately via `pip` or a package manager. The script works on the developer's workstation because `requests` is present there, but fails on the server with an import error, indicating the module is missing from the server's Python environment. This is the most likely cause because an import error specifically points to a missing module, not to network or syntax issues.

Exam trap

CompTIA often tests the distinction between runtime errors (e.g., network issues, bad endpoints) and import-time errors (e.g., missing modules), trapping candidates who confuse an ImportError with a connectivity or syntax problem.

How to eliminate wrong answers

Option B is wrong because an incorrect API endpoint would cause an HTTP error (e.g., 404 or 400) at runtime, not an import error when the script starts. Option C is wrong because lack of internet connectivity would cause a connection timeout or DNS resolution failure during the `requests.get()` call, not an import error when loading the module. Option D is wrong because a syntax error in the import statement would be caught by Python's parser before execution, producing a SyntaxError, not an ImportError; the script works on the workstation, so the import syntax is correct.

581
MCQmedium

A technician is troubleshooting a service that fails to start at boot. Which systemctl command should be used to ensure the service starts automatically on subsequent boots?

A.systemctl mask service
B.systemctl start service
C.systemctl enable service
D.systemctl reenable service
AnswerC

`systemctl enable` creates the symlinks under the systemd unit's `Wanted` directory, wiring the service into the boot target so systemd starts it automatically on every subsequent boot. It satisfies the stem's requirement for persistent automatic startup, unlike `start`, which only launches the unit for the current session.

Why this answer

systemctl enable creates symlinks so the service starts at boot. The status shown by is-enabled confirms if it is enabled.

582
MCQmedium

A pod in the Kubernetes cluster is in CrashLoopBackOff. Based on the exhibit, what is the most likely cause?

A.The application inside the container is crashing repeatedly.
B.The container failed to start because of a missing configuration file.
C.The image pull failed due to authentication issues.
D.The container image is not available in the registry.
AnswerA

CrashLoopBackOff means the container starts, exits, and Kubernetes restarts it with escalating backoff. The kubelet reports this state when the process itself terminates repeatedly, so the application's own crash, not scheduling or image pull failure, is the cause.

Why this answer

The CrashLoopBackOff status indicates that a container in a pod is repeatedly crashing after starting. Kubernetes attempts to restart the container, but the application inside exits with a non-zero exit code, causing the restart loop. This is most commonly caused by the application itself crashing due to a bug, misconfiguration, or resource issue.

Exam trap

CompTIA often tests the distinction between container startup failures (ImagePullBackOff, ErrImagePull) and runtime crashes (CrashLoopBackOff), so candidates must remember that CrashLoopBackOff implies the container started at least once before crashing.

How to eliminate wrong answers

Option B is wrong because a missing configuration file would typically cause an Init:Error or CreateContainerConfigError, not CrashLoopBackOff, as the container would fail to start at all. Option C is wrong because image pull failures due to authentication issues result in ImagePullBackOff or ErrImagePull, not CrashLoopBackOff. Option D is wrong because an unavailable container image also leads to ImagePullBackOff or ErrImagePull, as the container never starts to crash.

583
Multi-Selecthard

A Linux administrator is troubleshooting a systemd service named 'webapp.service' that fails to start. The administrator runs 'systemctl status webapp.service' and sees that the service is in a failed state. Which TWO commands will provide additional diagnostic information about why the service failed? (Choose two.)

Select 2 answers
A.journalctl -u webapp.service
B.journalctl -xe
C.systemctl show webapp.service
D.systemctl cat webapp.service
E.systemctl list-dependencies webapp.service
AnswersA, B

journalctl -u webapp.service displays all journal entries associated with that specific unit, including stdout/stderr from the service and systemd messages about its start attempts. This is a primary tool for diagnosing service failures, as it shows the exact error output and exit codes. It directly addresses the need for additional diagnostic information beyond the basic status output.

Why this answer

To diagnose why a systemd service failed, administrators need access to logs and error messages. journalctl -u webapp.service filters the journal for that unit, showing its output and systemd's messages. journalctl -xe shows recent system-wide errors with explanations, which often include the service failure. Commands like systemctl cat, show, and list-dependencies are for configuration and dependency inspection, not runtime diagnostics.

Exam trap

The trap here is confusing unit configuration inspection commands with log retrieval commands, and assuming that systemctl show or cat will reveal runtime errors when they only display static unit properties or file contents.

584
MCQhard

An administrator needs to view all current nftables rules. Which command should be used?

A.nft list ruleset
B.nft --list
C.nft show ruleset
D.iptables -L
AnswerA

nft list ruleset prints every table, chain and rule in the current nftables configuration, giving a complete view of loaded rules across all families. This satisfies the requirement to view all current rules without specifying a particular table.

Why this answer

nft list ruleset displays the entire ruleset. nft list table only shows a specific table.

585
MCQmedium

A server running RHEL 8 has intermittent network connectivity. The administrator wants to view the current DNS resolver configuration. Which file should be examined?

A./etc/sysconfig/network-scripts/ifcfg-eth0
B./etc/nsswitch.conf
C./etc/resolv.conf
D./etc/hosts
AnswerC

/etc/resolv.conf holds the active DNS resolver configuration, listing nameserver entries the system queries. On RHEL 8, NetworkManager or systemd-resolved may rewrite it dynamically, so it reflects the current resolver state rather than static intent. Examining it directly satisfies the administrator's need to view live DNS settings causing intermittent connectivity.

Why this answer

The /etc/resolv.conf file is the standard configuration file that lists the DNS nameservers (via 'nameserver' directives) and search domains used by the resolver. On RHEL 8, even when NetworkManager manages DNS, the effective resolver configuration is written to /etc/resolv.conf (often as a symlink to /run/NetworkManager/resolv.conf). Therefore, examining this file shows the current DNS resolver settings.

Exam trap

The trap here is confusing interface configuration files (like ifcfg-eth0) or name service switch files (nsswitch.conf) with the actual DNS resolver configuration, leading candidates to pick a file that only indirectly affects DNS.

How to eliminate wrong answers

Option A is wrong because /etc/sysconfig/network-scripts/ifcfg-eth0 contains interface configuration (IP address, netmask, gateway, and possibly DNS1/DNS2), but it is not the active resolver configuration file; it only defines what may be applied. Option B is wrong because /etc/nsswitch.conf controls the order of name service databases (e.g., files, dns, nis) but does not contain DNS server addresses or resolver options. Option D is wrong because /etc/hosts provides static hostname-to-IP mappings and is consulted before DNS, but it is not the DNS resolver configuration file.

586
Multi-Selectmedium

A Linux administrator is troubleshooting a server that is running out of disk space. Which TWO commands can be used to identify which directories or files are consuming the most space? (Choose two.)

Select 2 answers
A.iostat -d
B.ls -laR /
C.du -sh /*
D.find / -type f -size +100M -exec ls -lh {} \;
E.df -h
AnswersC, D

The du command estimates file space usage. The -s option summarizes each argument, and -h makes the output human-readable. Running du -sh /* shows the total size of each top-level directory, quickly identifying which directory is using the most space. This is a fast and effective way to pinpoint the largest consumers.

Why this answer

To identify space consumption, du -sh /* summarizes the size of top-level directories, quickly showing which are largest. The find command with -size +100M locates large individual files. Together, they help pinpoint both large directories and files. df only shows filesystem-level usage, ls -laR is too verbose, and iostat measures I/O performance, not space.

Exam trap

The trap here is confusing disk space usage with disk I/O performance, or using df alone which does not show directory-level details.

587
MCQmedium

A Linux server is experiencing slow boot times. The administrator wants to identify which systemd services are taking the longest to start. Which command should be used?

A.systemd-analyze time
B.journalctl -b -p 3
C.systemctl list-units --all
D.systemd-analyze blame
AnswerD

`systemd-analyze blame` lists each unit's initialisation duration, sorted longest first, directly exposing which services delay boot. It reads the timestamp data systemd records during startup, satisfying the administrator's need to pinpoint the slowest-starting services on this Linux server.

Why this answer

The `systemd-analyze blame` command prints a list of all running systemd units, sorted by the time they took to initialize during boot. This directly answers the administrator's need to identify which services are causing slow boot times by showing the exact startup duration for each unit.

Exam trap

The trap here is that candidates confuse `systemd-analyze time` (which gives a high-level summary) with `systemd-analyze blame` (which provides the per-service detail needed to identify the slowest service).

How to eliminate wrong answers

Option A is wrong because `systemd-analyze time` only shows the total boot time broken into firmware, kernel, and userspace segments, not a per-service breakdown. Option B is wrong because `journalctl -b -p 3` filters the systemd journal for error-level (priority 3) messages from the current boot, which is used for troubleshooting errors, not for measuring service startup durations. Option C is wrong because `systemctl list-units --all` lists all loaded units and their states (active, inactive, etc.), but does not provide any timing or performance data.

588
MCQhard

A Linux administrator uses Ansible to configure a fleet of web servers. A playbook task must copy a template file and then restart the nginx service only when the template content actually changes, avoiding needless restarts on every run. Which task construct enforces that behavior?

A.A template task with notify pointing to a handler that restarts nginx
B.A copy task with force: no followed by a shell task that runs systemctl restart nginx
C.A template task with a when clause that checks whether the nginx process is running
D.A template task followed by a service task with state: restarted and no conditional
AnswerA

The template module reports changed status only when the rendered file differs from the destination, and notify queues the named handler exclusively on that change. Handlers run once at the end of the play, so nginx restarts only after an actual template modification, which is exactly the idempotent behavior the scenario requires.

Why this answer

Ansible handlers are triggered only when a task reports a changed result, and the template module reports changed precisely when the rendered output differs from the file on the managed host. Wiring notify to a handler that restarts nginx therefore produces a restart only on genuine configuration changes, keeping repeated playbook runs idempotent and quiet.

Exam trap

The trap here is reaching for an unconditional service restart or a when condition, when only a notify-handler pair reacts to the change status of the template task.

589
MCQmedium

A system administrator is troubleshooting a service that fails to start. They want to see the recent logs for that specific service unit. Which journalctl command should be used?

A.journalctl -k
B.journalctl -u service_name
C.tail -f /var/log/syslog
D.journalctl -p err
AnswerB

The -u flag filters journalctl output to a single systemd unit, matching the requirement to see logs for one specific service. Without it, journalctl returns the full merged journal, which obscures the failing unit's recent entries.

Why this answer

The `-u` option in `journalctl` filters logs by the systemd unit name, allowing you to view recent logs specifically for a service. This is the correct approach when troubleshooting a service that fails to start, as it isolates the relevant log entries without noise from other system messages.

Exam trap

The trap here is that candidates may confuse `journalctl -u` with other common options like `-k` (kernel) or `-p` (priority), or fall back to legacy syslog commands like `tail -f /var/log/syslog`, which do not directly filter by systemd unit and may miss critical journal-only logs.

How to eliminate wrong answers

Option A is wrong because `journalctl -k` shows kernel messages only, not service-specific logs. Option C is wrong because `tail -f /var/log/syslog` is a traditional syslog command that does not filter by systemd unit and may not capture all journald entries, especially on systems using only journald. Option D is wrong because `journalctl -p err` filters by priority level (error and above), which may omit informational or debug messages that are crucial for diagnosing a startup failure.

590
Multi-Selecthard

An administrator is configuring iptables on a server. The requirements are: allow incoming SSH (port 22) from the 192.168.1.0/24 network, drop all other incoming traffic, and allow all outgoing traffic. Which three iptables rules achieve this? (Choose THREE.)

Select 3 answers
A.iptables -A INPUT -p tcp --dport 22 -s 192.168.1.0/24 -j ACCEPT
B.iptables -P OUTPUT ACCEPT
C.iptables -P FORWARD ACCEPT
D.iptables -A INPUT -p tcp --dport 22 -j ACCEPT
E.iptables -P INPUT DROP
AnswersA, B, E

This rule appends to the INPUT chain, matching TCP destination port 22 with source 192.168.1.0/24 and accepting it. It satisfies the requirement to permit SSH only from that subnet, and must precede the blanket INPUT drop so legitimate SSH is not discarded.

Why this answer

Option A is correct because it appends an INPUT rule that matches TCP packets destined for port 22 (--dport 22) with source address 192.168.1.0/24 (-s 192.168.1.0/24) and accepts them, exactly fulfilling the requirement to allow SSH only from that subnet. Option B is correct because setting the OUTPUT chain's default policy to ACCEPT (iptables -P OUTPUT ACCEPT) permits all outgoing traffic, matching the stated requirement. Option E is correct because setting the INPUT chain's default policy to DROP (iptables -P INPUT DROP) ensures that any incoming traffic not explicitly accepted by the earlier SSH rule is dropped, satisfying the 'drop all other incoming traffic' requirement.

Option C is not correct because FORWARD concerns traffic routed through the host, not traffic destined to the server itself, and the scenario does not require allowing forwarded packets. Option D is not correct because it accepts SSH from any source address, not restricted to 192.168.1.0/24 as required.

Exam trap

The trap is selecting a rule that allows SSH from any source (Option D) instead of restricting to the required subnet, or confusing FORWARD policy with INPUT/OUTPUT policies; candidates must read the source restriction carefully.

591
MCQeasy

A user reports that they cannot access a web server at 192.168.1.100. The administrator wants to check if the server is reachable and measure round-trip time. Which command is most appropriate?

A.nmap -sn 192.168.1.100
B.traceroute 192.168.1.100
C.ping 192.168.1.100
D.ss -tlnp | grep 192.168.1.100
AnswerC

`ping 192.168.1.100` sends ICMP echo requests to the target and reports whether replies return, satisfying the reachability check, while its summary displays minimum, average and maximum round-trip times in milliseconds, meeting the measurement requirement. It works directly against the IPv4 address without needing name resolution.

Why this answer

The `ping` command sends ICMP Echo Request packets to the target host and waits for ICMP Echo Reply packets, which directly tests reachability and measures round-trip time (RTT). This is the most appropriate tool for the administrator's stated goal of checking if the server is reachable and measuring RTT.

Exam trap

The trap here is that candidates confuse `nmap -sn` (host discovery) with connectivity testing and RTT measurement, or they think `traceroute` measures end-to-end RTT when it actually measures per-hop latency.

How to eliminate wrong answers

Option A is wrong because `nmap -sn` performs a ping sweep (ICMP, TCP SYN to port 443/80, or ARP) to discover live hosts, but it does not provide round-trip time measurements; it only reports whether the host is up. Option B is wrong because `traceroute` shows the path (hops) packets take to reach the destination and measures per-hop latency, not the end-to-end round-trip time to the server itself. Option D is wrong because `ss -tlnp` lists listening TCP sockets on the local system and cannot be used to test reachability to a remote host; it would not even accept an IP address as a filter in that syntax.

592
MCQmedium

A system administrator notices that the httpd service fails to start. Which command should be used to view the most recent log entries for that specific service?

A.systemctl status httpd
B.dmesg | grep httpd
C.journalctl -u httpd
D.tail -f /var/log/messages
AnswerC

`journalctl -u httpd` filters the systemd journal by unit, returning only entries belonging to the httpd service. This directly satisfies the stem's constraint of viewing recent logs for that specific service, rather than sifting through unrelated system-wide messages. On systemd-based distributions, it is the standard method for per-service troubleshooting.

Why this answer

C is correct because `journalctl -u httpd` queries the systemd journal for log entries specifically associated with the httpd service unit. This command shows the most recent log messages for that service, including startup failures, error codes, and dependency issues, making it the direct and precise tool for troubleshooting a service that fails to start.

Exam trap

The trap here is that candidates often choose `systemctl status httpd` (Option A) because it shows recent logs by default, but they overlook that it only displays a truncated snippet (usually the last 10–20 lines) and is not the command for viewing the most recent or complete log entries for a specific service.

How to eliminate wrong answers

Option A is wrong because `systemctl status httpd` shows the current state, recent log lines (usually the last 10–20), and process info, but it does not display the full or most recent log entries in a scrollable, filterable way; it truncates older messages and is not designed for deep log inspection. Option B is wrong because `dmesg | grep httpd` searches the kernel ring buffer, which contains kernel-level messages (hardware, drivers, kernel modules) and rarely includes application-level httpd logs unless the service writes to the kernel log, which it does not by default. Option D is wrong because `tail -f /var/log/messages` follows a general system log file that may contain httpd entries, but it is not service-specific, may not include all httpd log entries (especially if httpd logs to its own file like /var/log/httpd/error_log), and requires manual filtering; it also does not leverage the structured journald database.

593
MCQmedium

A system is running out of disk space in the /var/log directory. The administrator needs to temporarily free up space while preserving the latest log entries. Which approach is best?

A.Run logrotate with compression enabled
B.find /var/log -mtime +7 -delete
C.cat /dev/null > /var/log/messages
D.rm -rf /var/log/*
AnswerA

Compression shrinks rotated logs while retaining the most recent entries, freeing space in /var/log without deleting current data. Running logrotate satisfies the constraint of temporarily reclaiming disk space while preserving the latest log entries, unlike outright deletion.

Why this answer

Logrotate with compression is the best approach because it rotates, compresses, and optionally removes old log files while preserving the latest entries. It can be configured to keep a specific number of rotated logs, thus freeing disk space without deleting current logs. This matches the requirement to temporarily free up space while retaining the most recent log data.

Exam trap

CompTIA often tests the misconception that deleting old files with find or truncating a log file is a safe way to free space, but the correct approach is to use logrotate to manage log rotation and compression while preserving the latest entries.

How to eliminate wrong answers

Option B is wrong because 'find /var/log -mtime +7 -delete' deletes all log files older than 7 days, which may remove important historical logs and does not preserve the latest entries in a controlled manner. Option C is wrong because 'cat /dev/null > /var/log/messages' truncates the file, which destroys all existing log entries in that file, failing to preserve the latest entries. Option D is wrong because 'rm -rf /var/log/*' removes all files and subdirectories in /var/log, including current logs, which is destructive and does not preserve any entries.

594
MCQmedium

A security auditor notices that users can set weak passwords on a Linux system. The administrator wants to enforce password complexity requiring a minimum of 12 characters, at least one uppercase letter, and at least one digit. Which PAM module should be configured in /etc/pam.d/common-password?

A.pam_unix.so
B.pam_pwquality.so
C.pam_tally2.so
D.pam_faillock.so
AnswerB

Configuring pam_pwquality.so in /etc/pam.d/common-password enforces the auditor's complexity requirement directly, using parameters such as minlen=12, ucredit=-1 and dcredit=-1 to mandate twelve characters, one uppercase letter and one digit. Unlike pam_cracklib.so, it reads settings from /etc/security/pwquality.conf, centralising policy across services.

Why this answer

The pam_pwquality.so module is specifically designed to enforce password complexity policies, such as minimum length, required character classes (uppercase, lowercase, digits, special characters), and dictionary checks. Configuring it in /etc/pam.d/common-password allows the administrator to set parameters like minlen=12, ucredit=-1, and dcredit=-1 to meet the stated requirements. This module is the standard replacement for the older pam_cracklib.so.

Exam trap

XK0-006 often tests the specific PAM module for password complexity; candidates may confuse pam_pwquality with pam_unix or lockout modules like pam_tally2 or pam_faillock, but the key is that only pam_pwquality provides the granular complexity controls required.

How to eliminate wrong answers

Option A is wrong because pam_unix.so handles traditional Unix password authentication and can enforce some password policies via arguments like minlen, but it is limited and does not support the full range of complexity requirements (e.g., requiring uppercase and digits) as flexibly as pam_pwquality. Option C is wrong because pam_tally2.so is used for account lockout after failed login attempts, not for password complexity. Option D is wrong because pam_faillock.so is also for account lockout and failed login tracking, not for setting password policies.

595
MCQmedium

A Linux server is experiencing intermittent network connectivity issues. The administrator suspects that packets are being dropped due to a misconfigured firewall rule. Which command should the administrator use to view the current iptables rules and their packet counters?

A.tcpdump -i eth0
B.iptables -F
C.netstat -tuln
D.iptables -L -v -n
AnswerD

The `iptables -L -v -n` command lists all rules in the current chains with verbose output (`-v`) showing packet and byte counters, and `-n` displays IP addresses and ports numerically to avoid DNS lookups. This allows the administrator to see which rules are matching traffic and potentially dropping packets. The counters are essential for identifying if a specific rule is blocking legitimate traffic.

Why this answer

To diagnose firewall-related packet drops, the administrator needs to see the iptables rules along with their match counters. The `iptables -L -v -n` command provides a verbose listing with packet and byte counts, and numeric output. This reveals which rules are being hit and can indicate if a drop rule is matching traffic.

Other commands either modify the firewall or show unrelated information.

Exam trap

The trap here is assuming that network capture tools like tcpdump can show firewall rule counters; they capture packets but do not display iptables rule statistics.

596
Multi-Selecthard

A system administrator is working with compressed files. Which THREE commands can be used to view their contents? (Select THREE).

Select 3 answers
A.zgrep
B.cat
C.zcat
D.less
E.zless
AnswersA, C, E

zgrep decompresses the file in memory and searches it for a pattern, printing matching lines to standard output. This lets the administrator view relevant compressed content without extracting the archive first, satisfying the viewing requirement.

Why this answer

Option A, zgrep, is correct because it searches inside gzip-compressed files directly, decompressing the stream on the fly and printing matching lines without requiring manual extraction. Option C, zcat, is correct because it decompresses gzip files to standard output, allowing their contents to be viewed (often piped to a pager). Option E, zless, is correct because it is a pager wrapper that decompresses gzip files and displays them page by page, making it ideal for viewing compressed content interactively.

Options B (cat) and D (less) are not marked correct because they operate on plain uncompressed files and would output raw binary garbage when applied directly to a gzip-compressed file.

Exam trap

The trap here is assuming that standard text utilities like cat and less automatically handle gzip-compressed files; the exam expects you to know the z-prefixed variants are required for transparent decompression.

597
Multi-Selecthard

An administrator is troubleshooting a slow system. Which two commands can be used to identify processes consuming excessive CPU or memory? (Choose two.)

Select 2 answers
A.free -m
B.iostat -x
C.ps aux --sort=-%mem
D.df -h
E.top
AnswersC, E

The ps aux --sort=-%mem invocation lists all processes sorted descending by memory percentage, placing the heaviest consumers at the top. This directly satisfies the stem's need to identify processes consuming excessive memory, complementing a CPU-sorted counterpart.

Why this answer

Option C, `ps aux --sort=-%mem`, is correct because it lists all processes with their CPU and memory usage and sorts them in descending order by memory percentage, immediately revealing the top memory consumers. Option E, `top`, is correct because it provides a real-time, dynamically refreshing view of running processes ranked by CPU usage (and can be toggled to sort by memory with Shift+M), making it ideal for spotting processes consuming excessive CPU or memory. Option A, `free -m`, only reports total, used, and available system memory in megabytes; it shows overall memory pressure but not which processes are responsible.

Option B, `iostat -x`, reports extended disk I/O statistics per device, which is useful for storage bottlenecks but not for identifying CPU- or memory-hungry processes. Option D, `df -h`, displays filesystem disk space usage in human-readable form, which is unrelated to per-process CPU or memory consumption.

Exam trap

CompTIA often tests the distinction between system-level resource commands (like `free`, `df`, `iostat`) and process-level monitoring commands (`ps`, `top`), leading candidates to choose commands that show overall usage rather than per-process details.

598
MCQhard

A Linux server experiences a kernel panic after a recent driver update. The system is still operational but unstable. Which command should be used to gather detailed information about the kernel modules currently loaded?

A.modinfo
B.lsmod
C.dmesg
D.modprobe -l
AnswerB

lsmod reads /proc/modules and lists every kernel module currently loaded, with size and dependency information. This gives the detailed module inventory needed to identify the suspect driver after the panic, without altering the unstable running system.

Why this answer

B is correct because `lsmod` lists all currently loaded kernel modules by reading the `/proc/modules` file, showing their size, usage count, and dependencies. In a kernel panic scenario after a driver update, this command quickly reveals which modules are active, helping identify the problematic driver without further destabilizing the system.

Exam trap

The trap here is that candidates confuse `lsmod` (runtime loaded modules) with `modinfo` (module metadata) or `dmesg` (kernel logs), or mistakenly think `modprobe -l` lists loaded modules when it actually lists available modules (and is deprecated).

How to eliminate wrong answers

Option A is wrong because `modinfo` displays detailed metadata about a specific kernel module (e.g., author, description, parameters), but it does not list currently loaded modules; it requires the module name as an argument and reads the module file, not runtime state. Option C is wrong because `dmesg` prints the kernel ring buffer messages, which can show panic logs and driver errors, but it does not list currently loaded modules; it is useful for post-mortem analysis but not for a real-time inventory of loaded modules. Option D is wrong because `modprobe -l` is not a valid option in modern Linux; `modprobe` is used to load or unload modules, and listing available modules is done with `modprobe -l` only in older versions (deprecated), but it lists all installable modules, not those currently loaded.

599
MCQhard

Given an ACL entry 'u:john:rwx' on a file, which command would remove only the ACL entry for user john without affecting other ACL entries?

A.setfacl -k /path/to/file
B.setfacl -m u:john:- /path/to/file
C.setfacl -x u:john /path/to/file
D.setfacl -b /path/to/file
AnswerC

setfacl -x removes the specified ACL entry only, leaving other entries intact. Targeting u:john deletes just john's entry, satisfying the requirement to remove that single entry without disturbing the remaining access ACL or default ACL entries on the file.

Why this answer

The setfacl -x u:john /path/to/file command removes only the ACL entry for user john while leaving all other ACL entries (group entries, mask, other users) intact. The -x flag specifically deletes the named entry, which is exactly what the question requires. This is the surgical removal operation in the setfacl toolkit.

Exam trap

XK0-006 often tests the distinction between modifying an ACL entry to zero permissions (-m u:user:-) and actually deleting the entry (-x u:user) — candidates pick -m because it looks like it removes access, but the entry remains.

How to eliminate wrong answers

Option A is wrong because setfacl -k removes the default ACL entries on a directory, not a specific named user entry, and it does not target john. Option B is wrong because setfacl -m u:john:- modifies john's entry to have no permissions but leaves the entry present in the ACL, so the entry still exists rather than being removed. Option D is wrong because setfacl -b removes ALL extended ACL entries, wiping out every user and group entry, not just john's.

600
Matchingmedium

Match each Linux filesystem to its typical use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

General-purpose Linux filesystem

High-performance, scalable filesystem

Copy-on-write with snapshots

Temporary filesystem in RAM

Advanced filesystem with volume management

Why these pairings

Correct matches: ext4 for general use, XFS for large files, Btrfs for advanced features. Common confusions: swap vs tmpfs where swap is disk-based virtual memory and tmpfs is RAM-based temporary storage.

Page 7

Page 8 of 11

Page 9

All pages